Out-of-band key for ranging

CN122536094APending Publication Date: 2026-08-07QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
QUALCOMM INC
Filing Date
2024-12-04
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

然而,与在基本速率(BR)和/或增强数据速率(EDR)物理层上操作的蓝牙通信相关联的功耗可能会使WPAN通信在某些应用中不切实际

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a first device can obtain an out-of-band (OOB) key that is shared OOB with respect to a ranging session defined in-band between the first device and a second device. The first device can generate, using the OOB key itself or in conjunction with information used in-band, one or more first inputs to a first scrambling sequence used in the ranging session during the ranging session. The first device can transmit a first message to the second device using the first scrambling sequence during the ranging session. Numerous other aspects are described.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-reference to related applications

[0001] This patent application claims priority to U.S. Patent Application No. 18 / 401,232, filed December 29, 2023, entitled “OUT-OF-BAND KEY FORRANGING,” which is assigned to the assignee of this application. The disclosure of the earlier application is considered part of this patent application and is incorporated herein by reference. Technical Field

[0002] All aspects of this disclosure relate to wireless communication in general, and more particularly to techniques, apparatus and methods for out-of-band keys for ranging sessions between wireless devices. Background Technology

[0003] Wireless communication systems are widely deployed to provide a variety of services, including voice, text, messaging, video, data, and / or other services. Services may include unicast, multicast, and / or broadcast services, etc. Typical wireless communication systems employ multiple access radio access technologies (RATs) capable of supporting communication with multiple users by sharing available system resources (e.g., time-domain resources, frequency-domain resources, spatial-domain resources, and / or device transmit power, etc.). Examples of such multiple access RATs include Code Division Multiple Access (CDMA) systems, Time Division Multiple Access (TDMA) systems, Frequency Division Multiple Access (FDMA) systems, Orthogonal Frequency Division Multiple Access (OFDMA) systems, Single-Carrier Frequency Division Multiple Access (SC-FDMA) systems, and Time Division Synchronous Code Division Multiple Access (TD-SCDMA) systems.

[0004] The aforementioned Multiple Access RATs have been adopted in various telecommunications standards to provide a common protocol enabling different wireless communication devices to communicate at the city, national, regional, or global level. An example telecommunications standard is New Radio (NR). NR (also known as 5G) is part of the continuous evolution of mobile broadband announced by the 3rd Generation Partnership Project (3GPP). NR (and other mobile broadband evolutions beyond NR) can be designed to better support the Internet of Things (IoT) and reduced-capacity device deployments, industrial connectivity, millimeter-wave (mmWave) expansion, licensed and unlicensed spectrum access, non-terrestrial network (NTN) deployments, sidelinks and other device-to-device direct communication technologies (e.g., cellular vehicle-to-everything (CV2X) communications), massive MIMO, decomposed network architectures and network topology expansion, multi-subscriber implementations, high-precision positioning and / or radio frequency (RF) sensing, and more. As the demand for mobile broadband access continues to grow, further improvements to NR can be implemented, and other radio access technologies (such as 6G) can be introduced to further advance mobile broadband evolution.

[0005] A Wireless Personal Area Network (WPAN) is a short-range wireless network typically established by a user to interconnect various personal devices, sensors, and / or appliances located within a certain distance or area of ​​the user. For example, based on communication protocols such as Bluetooth... ® (BT) protocol, Bluetooth Low Energy protocol or Zigbee ® WPAN (Wireless PAN Protocol) can provide wireless connectivity to peripheral devices within a specific distance (e.g., 5 meters, 10 meters, 20 meters, 100 meters) from each other. Bluetooth is a short-range wireless communication protocol that supports WPAN between a central device (such as a host device or source device) and at least one peripheral device (such as a client device or destination device). However, the power consumption associated with Bluetooth communication, which operates at the Basic Rate (BR) and / or Enhanced Data Rate (EDR) physical layers, may make WPAN communication impractical in some applications.

[0006] Therefore, to address the power consumption challenges associated with Bluetooth BR / EDR (sometimes referred to as Bluetooth Classic or Bluetooth Legacy), Bluetooth Low Energy (BLE) (also referred to herein as WPAN LE) was developed and is used in a variety of applications where data transmission is relatively infrequent and / or to implement WPAN communication with low power consumption. For example, BLE saves power by utilizing infrequent data transmissions through low duty cycle operation and by putting one or both of the central and peripheral devices into sleep mode between data transmissions. Example applications using BLE include battery-powered sensors and actuators in various medical, industrial, consumer, and fitness applications. BLE can be used for remotely controlling locks. BLE can also be used to connect devices such as BLE-enabled smartphones, tablets, laptops, earphones, etc. Summary of the Invention

[0007] Some aspects described herein relate to a method of wireless communication performed by a first device. The method may include obtaining an out-of-band (OOB) key, which is shared OOB-wise with respect to a ranging session defined in-band (IB) between the first and second devices. The method may include using the OOB key itself, or in combination with information used in-band, during the ranging session to generate one or more first inputs to a first scrambling sequence used in the ranging session. The method may include using the first scrambling sequence to transmit a first message to the second device during the ranging session.

[0008] Some aspects described herein relate to a method of wireless communication performed by a second device. The method may include receiving an OOB key from a first device or network entity, the OOB key being shared OOB-wise with respect to an in-band ranging session defined between the first and second devices. The method may include generating one or more inputs, either using the OOB key itself or in combination with information used in-band, to a first scrambling sequence used in the ranging session. The method may include receiving a first message from the first device using the first scrambling sequence.

[0009] Some aspects described herein relate to a method for wireless communication performed by a network entity. The method may include receiving from a first device a request for an OOB key associated with a ranging session at the first device. The method may also include sending the OOB key OOB-wise to the first device upon successful authentication to the network entity.

[0010] Some aspects described herein relate to an apparatus for wireless communication at a first device. The apparatus may include one or more memories and one or more processors coupled to the one or more memories. The one or more processors may be individually or collectively configured to obtain an OOB key, which is shared OOB-wise relative to a ranging session defined in-band between the first device and a second device. The one or more processors may be individually or collectively configured to generate one or more first inputs to a first scrambling sequence used in the ranging session, either using the OOB key itself or in combination with information used in-band. The one or more processors may be individually or collectively configured to transmit a first message to the second device using the first scrambling sequence during the ranging session.

[0011] Some aspects described herein relate to an apparatus for wireless communication at a second device. The apparatus may include one or more memories and one or more processors coupled to the one or more memories. The one or more processors may be individually or collectively configured to receive an OOB key from a first device or network entity, the OOB key being shared OOB-wise with respect to an in-band ranging session defined between the first device and the second device. The one or more processors may be individually or collectively configured to generate one or more inputs in-band to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band. The one or more processors may be individually or collectively configured to receive a first message using the first scrambling sequence from the first device.

[0012] Some aspects described herein relate to an apparatus for wireless communication at a network entity. The apparatus may include one or more memories and one or more processors coupled to the one or more memories. The one or more processors may be individually or collectively configured to receive from a first device a request for an OOB key associated with a ranging session at the first device. The one or more processors may be individually or collectively configured to send the OOB key OOB-wise to the first device upon successful authentication by the first device to the network entity.

[0013] Some aspects described herein relate to a non-transitory computer-readable medium storing a set of instructions for wireless communication performed by a first device. When executed by one or more processors of the first device, the set of instructions enables the first device to obtain an OOB key, which is shared OOB-wise relative to a ranging session defined in-band between the first device and a second device. When executed by one or more processors of the first device, the set of instructions enables the first device to generate one or more first inputs to a first scrambling sequence used in the ranging session, either using the OOB key itself or in combination with information used in-band. When executed by one or more processors of the first device, the set of instructions enables the first device to transmit a first message to the second device using the first scrambling sequence during the ranging session.

[0014] Some aspects described herein relate to a non-transitory computer-readable medium storing a set of instructions for wireless communication performed by a second device. When executed by one or more processors of the second device, the set of instructions enables the second device to receive an OOB key from a first device or network entity, the OOB key being shared OOB-wise with respect to an in-band ranging session defined between the first and second devices. When executed by one or more processors of the second device, the set of instructions enables the second device to generate one or more inputs in-band to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band. When executed by one or more processors of the second device, the set of instructions enables the second device to receive a first message from the first device using the first scrambling sequence.

[0015] Some aspects described herein relate to a non-transitory computer-readable medium storing a set of instructions for wireless communication by a network entity. When executed by one or more processors of the network entity, the set of instructions enables the network entity to receive from a first device a request for an OOB key associated with a ranging session at the first device. When executed by one or more processors of the network entity, the set of instructions enables the network entity to send the OOB key OOB-wise to the first device upon successful authentication by the first device.

[0016] Some aspects described herein relate to a first apparatus for wireless communication. The first apparatus may include components for obtaining an OOB key, the OOB key being shared OOB-wise with respect to a ranging session defined in-band between the first apparatus and a second apparatus. The first apparatus may include components for generating one or more first inputs to a first scrambling sequence used in the ranging session, either using the OOB key itself or in combination with information used in-band. The apparatus may include components for transmitting a first message to the second apparatus using the first scrambling sequence during the ranging session.

[0017] Some aspects described herein relate to a second apparatus for wireless communication. The second apparatus may include components for receiving an OOB key from a first apparatus or network entity, the OOB key being shared OOB-wise with respect to an in-band ranging session defined between the first and second apparatuses. The second apparatus may include components for generating one or more inputs in-band to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band. The second apparatus may include components for receiving a first message from the first apparatus using the first scrambling sequence.

[0018] Some aspects described herein relate to an apparatus for wireless communication. The apparatus may include components for receiving from a first device a request for an OOB key associated with a ranging session at the first device. The apparatus may also include components for sending the OOB key OOB-wise to the first device upon successful authentication to a network entity by the first device.

[0019] Various aspects of this disclosure may be implemented or be implemented as described in whole by or embodied in the methods, apparatus, systems, computer program products, non-transitory computer-readable media, user equipment, base stations, network nodes, network entities, wireless communication devices and / or processing systems as fully described in the specification and drawings and illustrated in the specification and drawings.

[0020] The preceding paragraphs of this section have broadly summarized some aspects of this disclosure. These and additional aspects and their associated advantages will be described below. The disclosed aspects can serve as the basis for modifying or designing other aspects for performing the same or similar purposes of this disclosure. Such equivalent aspects do not depart from the scope of the appended claims. The characteristics of the aspects disclosed herein, their organization and operation, and their associated advantages will be better understood from the following description taken in conjunction with the accompanying drawings. Attached Figure Description

[0021] The accompanying drawings illustrate some aspects of this disclosure but do not limit its scope, as other aspects can be achieved by this description. Each drawing in the drawings is provided for illustrative and descriptive purposes and not as a definition of limitation of the claims. Identical or similar reference numerals in different drawings may identify identical or similar elements.

[0022] Figure 1 is a diagram illustrating an example of a wireless communication network according to the present disclosure.

[0023] Figure 2 is an illustration of an example network node communicating with an example user equipment (UE) in a wireless network according to the present disclosure.

[0024] Figure 3 is a diagram illustrating an example decomposed base station architecture according to this disclosure.

[0025] Figure 4 is a diagram illustrating an example of central equipment and peripheral equipment.

[0026] Figure 5 is a diagram illustrating an example of a wireless communication device according to the present disclosure.

[0027] Figure 6 is a diagram illustrating an example of a protocol stack according to this disclosure.

[0028] Figure 7 is an illustration of an example of a remotely accessed vehicle according to the present disclosure.

[0029] Figure 8 is a diagram illustrating an example of a prepared channel probe message according to the present disclosure.

[0030] Figure 9 is a diagram illustrating an example of using an out-of-band (OOB) key according to this disclosure.

[0031] Figure 10 is a diagram illustrating an example of sharing an OOB key OOB prior to a ranging session according to this disclosure.

[0032] Figure 11 is a diagram illustrating an example of a ranging session according to this disclosure.

[0033] Figure 12 is a diagram illustrating an example process performed, for example, at a first device or a device of the first device, according to the present disclosure.

[0034] Figure 13 is a diagram illustrating an example process performed, for example, at a second device or a device of the second device, according to the present disclosure.

[0035] Figure 14 is a diagram illustrating an example process performed, for example, at a network entity or a device of a network entity, according to the present disclosure.

[0036] Figure 15 is a diagram of an example device for wireless communication according to the present disclosure.

[0037] Figure 16 is a diagram of an example device for wireless communication according to the present disclosure. Detailed Implementation

[0038] Various aspects of this disclosure are described below with reference to the accompanying drawings. However, aspects of this disclosure may be embodied in many different forms and should not be construed as limited to any specific aspect illustrated or described with reference to the drawings or otherwise presented in this disclosure. Rather, these aspects are provided so that this disclosure will be comprehensive and complete, and will fully convey the scope of protection of this disclosure to those skilled in the art. Those skilled in the art will understand that the scope of this disclosure is intended to cover any aspect of this disclosure disclosed herein, whether implemented independently of or in combination with any other aspect of this disclosure. For example, various combinations or numbers of aspects set forth herein may be used to implement an apparatus or a practice. Furthermore, the scope of this disclosure is intended to cover apparatuses having structures and / or functionalities other than those available for practicing the various aspects of this disclosure set forth herein, or methods practiced using these other structures and / or functionalities. Any aspect of this disclosure disclosed herein may be embodied by one or more elements of the claims.

[0039] Various methods, operations, apparatuses, and techniques will now be presented with reference to them. These methods, operations, apparatuses, and techniques will be described in detail below and illustrated in the accompanying drawings by various boxes, modules, components, circuits, steps, processes, or algorithms (collectively, “elements”). These elements may be implemented using hardware, software, or a combination of hardware and software. Whether such elements are implemented as hardware or software depends on the specific application and the design constraints imposed on the system as a whole.

[0040] (Such as in a Bluetooth (BT) network or a Bluetooth Low Energy (BLE) network) A first device using a low-power protocol can send messages to a second device. The first and second devices can operate as part of a ranging session, where the second device can perform actions based on the range or distance between the devices.

[0041] Ranging sessions can include BT channel probing (BCS) sessions. BCS can involve distance assessment between two devices, including measuring the propagation of a scrambled sequence. A deterministic bit random generator (DRBG) can be used to scramble the sequence. The DRBG can use an initialization vector IV (re-speculative) value exchanged by the two devices via a Bluetooth connection. The integrity of the ranging sequence relies on the confidentiality of the IV. The confidentiality of the IV relies on the confidentiality of the peer-to-peer binding long-term key (LTK). The LTK is exchanged in plaintext via a serial connection between the host and controller of the BLE devices. Because the LTK is exchanged in plaintext, an unauthorized party could obtain or deduce the LTK and impersonate an authorized recipient of the message.

[0042] The overall scope of this discussion concerns secure communication between two wireless devices. Some aspects are more specifically related to the two devices acquiring an out-of-band (OOB) key, which is shared OOB relative to the target protocol (such as a ranging session, e.g., a BCS session). The two devices may use the OOB key individually or combine it with other information shared within the in-band to derive an input scrambling sequence. The scrambling sequence protects messages transmitted during iterations of the ranging session.

[0043] Specific aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some examples, by using an OOB key obtained OOB-wise relative to the in-band ranging session, two devices can provide greater security for ranging messages sent during the ranging session. If an unauthorized party obtains some key material exchanged over the air during the ranging session, the unauthorized party will be unable to successfully decode the ranging message because the unauthorized party will not have the OOB key shared OOB-wise prior to the ranging session. This increased security saves device resources wasted or consumed due to security vulnerabilities.

[0044] Multiple access radio access technology (RAT) has been adopted in various telecommunications standards to provide a common protocol that enables wireless communication devices to communicate at the city, enterprise, national, regional, or global level. For example, 5G New Radio (NR) is part of the continuous mobile broadband evolution announced by the 3rd Generation Partnership Project (3GPP). 5G NR supports a variety of technologies and use cases, including enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), massive machine-type communication (mMTC), millimeter wave (mmWave) technology, beamforming, network slicing, edge computing, Internet of Things (IoT) connectivity and management, and network function virtualization (NFV).

[0045] With increasing demand for broadband access and the technological evolution supported by wireless communication networks, further technological improvements can be adopted or implemented in 5G NR or future RATs (such as 6G) to further advance the evolution of wireless communication and adapt to a variety of existing and new use cases and applications. Such technological improvements can be associated with new frequency band extensions, licensed and unlicensed spectrum access, overlapping spectrum use, small cell deployments, non-terrestrial network (NTN) deployments, decomposed network architectures and network topology extensions, device aggregation, advanced duplex communication, sidelinks and other device-to-device direct communication, IoT (including passive or environmental IoT) networks, reduced-capacity (RedCap) UE functionality, industrial connectivity, multi-subscriber implementations, high-precision positioning, radio frequency (RF) sensing and / or artificial intelligence or machine learning (AI / ML), and more. These technological improvements can support use cases such as wireless backhaul, wireless data centers, extended reality (XR) and metaverse applications, meta-services for supporting vehicle connectivity, holographic and mixed reality communications, autonomous and collaborative robots, vehicle platooning and collaborative maneuvering, sensor networks, posture monitoring, brain-computer interfaces, digital twin applications, asset management, and general coverage applications using off-ground and / or aerial platforms. The methods, operations, apparatuses, and techniques described herein can implement one or more of the foregoing technologies and / or support one or more of the foregoing use cases.

[0046] Figure 1 is a diagram illustrating an example of a wireless communication network 100 according to the present disclosure. The wireless communication network 100 may be a 5G (or NR) network or a 6G network, or may include elements of a 5G (or NR) network or a 6G network, etc. The wireless communication network 100 may include a plurality of network nodes 110, shown as network node (NN) 110a, network node 110b, network node 110c, and network node 110d. Network nodes 110 may support communication with a plurality of UEs 120 (shown as UE 120a, UE 120b, UE 120c, UE 120d, and UE 120e).

[0047] Network nodes 110 and UEs 120 of wireless communication network 100 can communicate using the electromagnetic spectrum, which can be subdivided into various categories, frequency bands, carriers, and / or channels according to frequency or wavelength. For example, devices of wireless communication network 100 can communicate using one or more operating frequency bands. In some aspects, multiple wireless networks 100 can be deployed in a given geographical area. Each wireless communication network 100 can support a specific RAT (which may also be referred to as an air interface) and can operate on one or more carrier frequencies in one or more frequency ranges. Examples of RATs include 4G RATs, 5G / NRRATs, and / or 6G RATs, etc. In some examples, when multiple RATs are deployed in a given geographical area, each RAT in that geographical area can operate on a different frequency to avoid interference with each other.

[0048] Various operating frequency bands have been defined as frequency ranges designated FR1 (410 MHz to 7.125 GHz), FR2 (24.25 GHz to 52.6 GHz), FR3 (7.125 GHz to 24.25 GHz), FR4a or FR4-1 (52.6 GHz to 71 GHz), FR4 (52.6 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Although a portion of FR1 is greater than 6 GHz, in some documents and articles, FR1 is often (interchangeably) referred to as the “sub-6 GHz” band. Similarly, in some documents and articles, FR2 is often (interchangeably) referred to as the “millimeter wave” band, but this is different from the Very High Frequency (EHF) band (30 GHz to 300 GHz) identified as the “millimeter wave” band by the International Telecommunication Union (ITU). The frequencies between FR1 and FR2 are often referred to as the mid-band frequencies, including FR3. Frequency bands falling within FR3 can inherit FR1 or FR2 characteristics, thereby effectively extending the characteristics of FR1 or FR2 into mid-band frequencies. Therefore, "below 6 GHz" (if used herein) can broadly refer to frequencies less than 6 GHz, within FR1, and / or included in mid-band frequencies. Similarly, the term "millimeter wave" (if used herein) can broadly refer to frequencies included in mid-band frequencies, within FR2, FR4, FR4-a, FR4-1, or FR5, and / or within the EHF band. Higher frequency bands can extend 5G NR operation, 6G operation, and / or other RATs above 52.6 GHz. For example, each of FR4a, FR4-1, FR4, and FR5 falls within the EHF band. In some examples, the wireless communication network 100 can implement dynamic spectrum sharing (DSS), where multiple RATs (e.g., 4G / LTE and 5G / NR) are implemented within a single frequency band using dynamic bandwidth allocation (e.g., based on user demand). It is conceivable that the frequencies included in these operating frequency bands (e.g., FR1, FR2, FR3, FR4, FR4-a, FR4-1 and / or FR5) can be modified, and the techniques described herein are applicable to those modified frequency ranges.

[0049] Network node 110 may include one or more devices, components, or systems that enable communication between UE 120 and one or more devices, components, or systems of wireless communication network 100. Network node 110 may be, may include, or may be referred to as an NR network node, 5G network node, 6G network node, node B, eNB, gNB, access point (AP), transmit / receive point (TRP), mobility element, core, network entity, network element, network equipment, and / or another type of device, component, or system included in a radio access network (RAN).

[0050] Network node 110 may be implemented as a single physical node (e.g., a single physical structure) or as two or more physical nodes (e.g., two or more different physical structures). For example, network node 110 may be a device or system implementing a portion of a radio protocol stack, a device or system implementing a complete radio protocol stack (such as a complete gNB protocol stack), or a collection of devices or systems collectively implementing a complete radio protocol stack. For example, and as shown, network node 110 may be an aggregated network node (with an aggregated architecture), meaning that network node 110 can implement a complete radio protocol stack physically and logically integrated within a single node (e.g., a single physical structure) in the wireless communication network 100. For example, aggregated network node 110 may consist of a single standalone base station or a single TRP that uses the complete radio protocol stack to implement or facilitate communication between UE 120 and the core network of wireless communication network 100.

[0051] Alternatively, and also as shown in the figure, network node 110 can be a decomposed network node (sometimes referred to as a decomposed base station), meaning that network node 110 can realize a radio protocol stack that is physically distributed and / or logically distributed among two or more nodes in the same or different geographical locations. For example, a decomposed network node may have a decomposed architecture. In some deployments, decomposed network node 110 may be used in integrated access and backhaul (IAB) networks, in open radio access networks (O-RAN) (such as network configurations conforming to O-RAN Alliance standards), or in virtualized radio access networks (vRAN) (also referred to as cloud radio access networks (C-RAN)) to facilitate scaling by decomposing base station functionality into multiple units that can be deployed independently.

[0052] Network nodes 110 of the wireless communication network 100 may include one or more central units (CUs), one or more distributed units (DUs), and / or one or more radio units (RUs). CUs may host one or more higher-layer control functions, such as Radio Resource Control (RRC) functions, Packet Data Convergence Protocol (PDCP) functions, and / or Service Data Adaptation Protocol (SDAP) functions, etc. DUs may host one or more of the Radio Link Control (RLC) layer, Media Access Control (MAC) layer, and / or one or more higher physical (PHY) layers, at least in part, according to functional splits (such as functional splits defined by 3GPP). In some examples, DUs may also host one or more lower PHY layer functions, such as Fast Fourier Transform (FFT), Inverse FFT (iFFT), beamforming, Physical Random Access Channel (PRACH) extraction and filtering, and / or scheduling of resources for one or more UEs 120, etc. RUs may host RF processing functions or lower PHY layer functions, such as FFT, iFFT, beamforming, or PRACH extraction and filtering, etc., according to functional splits (such as lower-layer functional splits). In this type of architecture, each RU can be operated to handle over-the-air (OTA) communications with one or more UE 120s.

[0053] In some aspects, network node 110 may include a combination of one or more CUs, one or more DUs, and / or one or more RUs. Additionally or alternatively, network node 110 may include one or more near real-time (near RT) RAN Intelligent Controllers (RICs) and / or one or more non-real-time (non-RT) RICs. In some examples, CUs, DUs, and / or RUs may be implemented as virtual units, such as Virtual Central Units (VCUs), Virtual Distributed Units (VDUs), or Virtual Radio Units (VRUs), etc. Virtual units may be implemented as virtual network functions, such as those associated with cloud deployments.

[0054] Some network nodes 110 (e.g., base stations, RUs, or TRPs) can provide communication coverage for specific geographic areas. In 3GPP, the term "cell" can refer to the coverage area of ​​network node 110 or to network node 110 itself, depending on the context in which the term is used. Network node 110 can support one or more (e.g., three) cells. In some examples, network node 110 can provide communication coverage for macrocells, picocells, femtocells, or another type of cell. A macrocell can cover a relatively large geographic area (e.g., with a radius of several kilometers) and can allow unrestricted access by UE 120 with a service subscription. A picocell can cover a relatively small geographic area and can allow unrestricted access by UE 120 with a service subscription. A femtocell can cover a relatively small geographic area (e.g., a residential area) and can allow restricted access by UE 120 associated with that femtocell (e.g., UE 120 in a Closed Subscriber Group (CSG)). A network node 110 used for a macrocell may be referred to as a macro network node. Network node 110 used for a picocell may be referred to as a pico network node. Network node 110 used for a femtocell may be referred to as a femto network node or a home network node. In some examples, the cell may not necessarily be stationary. For example, the geographical area of ​​the cell may move depending on the location of the associated mobile network node 110 (e.g., a train, satellite base station, drone, or NTN network node).

[0055] The wireless communication network 100 can be a heterogeneous network, comprising different types of network nodes 110, such as macro network nodes, pico network nodes, femto network nodes, relay network nodes, aggregation network nodes, and / or decomposition network nodes, etc. In the example shown in Figure 1, network node 110a can be a macro network node for macro cell 130a, network node 110b can be a pico network node for pico cell 130b, and network node 110c can be a femto network node for femto cell 130c. These various types of network nodes 110 can typically transmit at different power levels, serve different coverage areas, and / or have different effects on interference in the wireless communication network 100 compared to other types of network nodes 110. For example, macro network nodes can have high transmit power levels (e.g., 5 watts to 40 watts), while pico network nodes, femto network nodes, and relay network nodes can have lower transmit power levels (e.g., 0.1 watts to 2 watts).

[0056] In some examples, network node 110 may be, may include, or operate as a RU, TRP, or base station communicating with one or more UEs 120 via a radio access link (which may be referred to as a "Uu" link). The radio access link may include a downlink and an uplink. A "downlink" (or "DL") refers to the communication direction from network node 110 to UE 120, and an "uplink" (or "UL") refers to the communication direction from UE 120 to network node 110. Downlink channels may include one or more control channels and one or more data channels. Downlink control channels may be used to transmit downlink control information (DCI) (e.g., scheduling information, reference signals, and / or configuration information) from network node 110 to UE 120. Downlink data channels may be used to transmit downlink data (e.g., user data associated with UE 120) from network node 110 to UE 120. Downlink control channels may include one or more physical downlink control channels (PDCCH), and downlink data channels may include one or more physical downlink shared channels (PDSCH). The uplink channel may similarly include one or more control channels and one or more data channels. The uplink control channel can be used to transmit uplink control information (UCI) from UE 120 to network node 110 (e.g., transmitting corresponding reference signals and / or feedback with one or more downlinks). The uplink data channel can be used to transmit uplink data (e.g., user data associated with UE 120) from UE 120 to network node 110. The uplink control channel may include one or more physical uplink control channels (PUCCH), and the uplink data channel may include one or more physical uplink shared channels (PUSCH). The downlink and uplink may each include a set of resources on which network node 110 and UE 120 can communicate.

[0057] Downlink and uplink resources may include time-domain resources (frames, subframes, time slots, and / or symbols), frequency-domain resources (bands, component carriers, subcarriers, resource blocks, and / or resource elements), and / or spatial-domain resources (specific transmission directions and / or beam parameters). Frequency-domain resources in some bands may be subdivided into bandwidth portions (BWPs). A BWP may be a contiguous block of frequency-domain resources allocated to one or more UEs 120 (e.g., a contiguous block of resource blocks). A UE 120 may be configured with both an uplink BWP and a downlink BWP (where the uplink BWP and downlink BWP may be the same BWP or different BWPs). BWPs may be dynamically configured and / or reconfigured (e.g., by sending DCI configuration to one or more UEs 120 via network node 110), meaning that BWPs may be adjusted in real-time (or near real-time) based on changing network conditions in the wireless communication network 100 and / or based on the specific requirements of one or more UEs 120. This allows for more efficient use of available frequency domain resources in the wireless communication network 100, as fewer frequency domain resources can be allocated to the BWP for UE 120 (which reduces the number of frequency domain resources that UE 120 needs to monitor), thus allowing more frequency domain resources to be distributed across multiple UE 120s. Therefore, the BWP can also assist in the implementation of such UE 120s by facilitating the configuration of smaller bandwidths for communications performed by lower-capacity UE 120s.

[0058] As described above, in some aspects, the wireless communication network 100 may be an IAB network, may include an IAB network, or may be included in an IAB network. In an IAB network, at least one network node 110 is an anchor network node communicating with a core network. The anchor network node 110 may also be referred to as an IAB donor (or "IAB donor"). The anchor network node 110 may be connected to the core network via a wired backhaul link. For example, the Ng interface of the anchor network node 110 may terminate at the core network. Additionally or alternatively, the anchor network node 110 may be connected to one or more devices in the core network that provide core access and mobility management functions (AMF). An IAB network typically also includes multiple non-anchor network nodes 110, which may also be referred to as relay network nodes or simply IAB nodes (or "IAB-nodes"). Each non-anchor network node 110 can directly communicate with the anchor network node 110 via a wireless backhaul link to access the core network, or can indirectly communicate with the anchor network node 110 via one or more other non-anchor network nodes 110 and an associated wireless backhaul link forming a backhaul path to the core network. Some anchor network nodes 110 or other non-anchor network nodes 110 can also directly communicate with one or more UEs 120 via a wireless access link carrying access services. For example, network resources used for wireless communication (such as time resources, frequency resources, and / or spatial resources) can be shared between the access link and the backhaul link.

[0059] In some examples, any network node 110 relaying communication may be referred to as a relay network node, a relay station, or simply a repeater. A repeater may receive transmissions of communication from an upstream station (e.g., another network node 110 or UE 120) and transmit communication to a downstream station (e.g., UE 120 or another network node 110). In this case, the wireless communication network 100 may include or be referred to as a “multi-hop network.” In the example shown in Figure 1, network node 110d (e.g., a relay network node) may communicate with network node 110a (e.g., a macro network node) and UE 120d to facilitate communication between network node 110a and UE 120d. Additionally or alternatively, UE 120 may be a relay station capable of relaying transmissions to or from other UE 120s, or may operate as such a relay station. UE 120 relaying communication may be referred to as a UE repeater or relay UE, etc.

[0060] UE 120 may be physically distributed throughout the wireless communication network 100, and each UE 120 may be stationary or mobile. UE 120 may be, may include, an access terminal, another terminal, a mobile station, or a subscriber unit, or may be included in an access terminal, another terminal, a mobile station, or a subscriber unit. UE 120 may be, or may include, a cellular phone (e.g., a smartphone), a personal digital assistant (PDA), a wireless modem, a wireless communication device, a handheld device, a laptop computer, a cordless phone, a wireless local loop (WLL) station, a tablet computer, a camera, a gaming device, a netbook, a smartbook, an ultrabook, a medical device, a biometric device, a wearable device (e.g., a smartwatch, smart clothing, smart glasses, a smart wristband and / or smart jewelry (such as a smart ring or smart bracelet)), an entertainment device (e.g., a music device, a video device and / or a satellite radio), an XR device, a vehicle component or sensor, a smart meter or sensor, industrial manufacturing equipment, a Global Navigation Satellite System (GNSS) device (such as a Global Positioning System device or another type of positioning device), a UE function of a network node, and / or any other suitable device or function that can communicate via a wireless medium, or may be coupled to them.

[0061] UE 120 and / or network node 110 may include one or more chips, system-on-a-chip (SoC), chipsets, packages, or devices that individually or collectively constitute or include a processing system. The processing system includes processor (or “processing”) circuitry in the form of one or more processors, microprocessors, processing units (such as central processing units (CPUs), graphics processing units (GPUs), neural processing units (NPUs), and / or digital signal processors (DSPs)), processing blocks, application-specific integrated circuits (ASICs), programmable logic devices (PLDs) (such as field-programmable gate arrays (FPGAs)), or other discrete gate or transistor logic components or circuits (all of which are generally referred to herein individually as “processors” or collectively as “processors” or “processor circuitry”). One or more of these processors may be individually or collectively configured to perform the various functions or operations described herein. A processor group that can be configured or configured to perform a set of functions may include a first processor that can be configured or configured to perform a first function in the set, and a second processor that can be configured or configured to perform a second function in the set, or may include the entire processor group that is configured or configured to perform the set of functions.

[0062] The processing system may also include memory circuitry in the form of one or more memory devices, memory blocks, memory elements, or other discrete gate or transistor logic components or circuits, each of which may include tangible storage media such as random access memory (RAM) or read-only memory (ROM) or combinations thereof (all of which are generally referred to herein individually as "memory" or collectively as "memory" or "memory circuitry"). One or more of these memories may be coupled to one or more processors in the processor (e.g., operatively coupled, communicatively coupled, electronically coupled, or electrically coupled) and may store processor-executable code (such as software) individually or collectively, which, when executed by one or more processors in the processor, may configure one or more processors in the processor to perform the various functions or operations described herein. Additionally or alternatively, in some examples, one or more processors in the processor may be pre-configured to perform the various functions or operations described herein without being configured by software. The processing system may also include or be coupled to one or more modems (such as Wi-Fi (e.g., IEEE compliant) modems or cellular (e.g., 3GPP 4G LTE, 5G, or 6G compliant) modems). In some embodiments, one or more processors of the processing system include or implement one or more modems among the modems. The processing system may also include, or be coupled to, multiple radio components (collectively, “radio components”), multiple RF chains, or multiple transceivers, each of which may in turn be coupled to one or more antennas among multiple antennas. In some embodiments, one or more processors of the processing system include or implement one or more of the radio components, RF chains, or transceivers. UE 120 may be included or may be contained in a housing that houses components associated with UE 120, including the processing system.

[0063] Some UEs 120 may be considered Machine Type Communication (MTC) UEs, Evolved or Enhanced Machine Type Communication (eMTC) UEs, Further Enhanced eMTC (feMTC) UEs, or Enhanced feMTC (efeMTC) UEs, or further evolutions thereof, all of which may be referred to simply as "MTC UEs". MTC UEs may be, may include, or may be included in or coupled with the following: robots, unmanned aerial vehicles, remote devices, sensors, instruments, monitors, and / or location tags. Some UEs 120 may be considered IoT devices and / or may be implemented as NB-IoT (Narrowband IoT) devices. IoT UEs or NB-IoT devices may be, may include, or may be included in or coupled with the following: industrial machines, appliances, refrigerators, doorbell camera devices, home automation devices, and / or lighting fixtures, etc. Some UEs 120 may be considered customer premises equipment, which may include telecommunications equipment installed at a customer location (such as a home or office) to enable access to a service provider’s network (such as being included in or communicating with the wireless communication network 100).

[0064] Some UEs 120 can be categorized according to different categories associated with varying levels of complexity and / or capabilities. UEs 120 in the first category facilitate large-scale IoT within the wireless communication network 100 and offer lower complexity and / or cost compared to UEs 120 in the second category. UEs 120 in the second category may include mission-critical IoT devices capable of URLLC, enhanced mobile broadband (eMBB), and / or precise positioning within the wireless communication network 100, legacy UEs, baseline UEs, high-level UEs, advanced UEs, full-capability UEs, and / or premium UEs. UEs 120 in the third category may have intermediate-level complexity and / or capabilities (e.g., capabilities between first-category UEs 120 and second-capability UEs 120). UEs 120 in the third category may be referred to as reduced-capability UEs (“RedCap UEs”), intermediate-level UEs, NR lightweight UEs, and / or NR-Lite UEs, etc. RedCap UEs bridge the gap in capabilities and complexity between NB-IoT devices and / or eMTC UEs and mission-critical IoT devices and / or premium UEs. RedCap UEs can include, for example, wearable devices, IoT devices, industrial sensors, and / or cameras associated with limited bandwidth, power capacity, and / or transmission range. RedCap UEs can support healthcare environments, building automation, power distribution, process automation, transportation and logistics, and / or smart city deployments, among others.

[0065] In some examples, two or more UEs 120 (e.g., shown as UE 120a and UE 120e) can communicate directly with each other using sidelink communication (e.g., without communication through a network node 110 acting as an intermediary). As an example, UE 120a can send data, control information, or other signaling directly to UE 120e as sidelink communication. This contrasts with, for example, UE 120a first sending data to network node 110 in UL communication, and then that network node sending data to UE 120e in DL communication. In various examples, UE 120 can use peer-to-peer (P2P) communication protocols, device-to-device (D2D) communication protocols, vehicle-to-everything (V2X) communication protocols (which may include vehicle-to-vehicle (V2V) protocols, vehicle-to-infrastructure (V2I) protocols, and / or vehicle-to-pedestrian (V2P) protocols), and / or mesh network communication protocols to send and receive sidelink communication. In some deployments and configurations, network node 110 may schedule and / or allocate resources for sidelink communication between UEs 120 in the wireless communication network 100. In some other deployments and configurations, UE 120 (instead of network node 110) may perform or cooperate with or negotiate with one or more other UEs to perform scheduling operations, resource selection operations, and / or other operations for sidelink communication.

[0066] In various examples, in addition to half-duplex operation, some network nodes and UEs in the wireless communication network 100, including network node 110 and UE 120, can also be configured for full-duplex operation. Network node 110 or UE 120 operating in half-duplex mode can perform only one of transmission or reception during a specific time resource period (such as a specific time slot, symbol, or other time period). Half-duplex operation may involve time division duplex (TDD), where the DL transmission of network node 110 and the UL transmission of UE 120 do not occur in the same time resource (i.e., the transmissions do not overlap in time). In contrast, network node 110 or UE 120 operating in full-duplex mode can transmit and receive communications concurrently (e.g., within the same time resource). By operating in full-duplex mode, network node 110 and / or UE 120 can generally increase the capacity of the network and radio access links. In some examples, full-duplex operation may involve frequency division duplex (FDD), in which network node 110 performs DL transmission in a first frequency band or on a first component carrier, and UE 120 performs transmission in a second frequency band or on a second component carrier, the second frequency band or the second component carrier being different from the first frequency band or the first component carrier, respectively. In some examples, full-duplex operation may be enabled for UE 120 but not for network node 110. For example, UE 120 may simultaneously transmit UL to the first network node 110 and receive DL transmissions from the second network node 110 in the same time resources. In some other examples, full-duplex operation may be enabled for network node 110 but not for UE 120. For example, network node 110 may simultaneously transmit DL to the first UE 120 and receive UL transmissions from the second UE 120 in the same time resources. In some other examples, full-duplex operation may be enabled for both network node 110 and UE 120.

[0067] In some examples, UE 120 and network node 110 can perform MIMO communication. "MIMO" generally refers to the simultaneous transmission or reception of multiple signals (such as multiple layers or multiple data streams) using the same time and frequency resources. MIMO techniques typically utilize multipath propagation. MIMO can be implemented using various spatial processing or spatial multiplexing operations. In some examples, MIMO can support simultaneous transmission to multiple receivers, which is called multi-user MIMO (MU-MIMO). Some RATs can employ advanced MIMO techniques such as mTRP operations (including redundant transmission or reception on multiple TRPs), reciprocity in the time or frequency domain, single-frequency network (SFN) transmission, or noncoherent joint transmission (NC-JT).

[0068] In some aspects, the first device (e.g., UE 120) may include a communication manager 140. As described in more detail elsewhere herein, the communication manager 140 may obtain an OOB key that is shared OOB-wise relative to an in-band ranging session defined between the first and second devices. The communication manager 140 may generate one or more first inputs to a first scrambling sequence used in the ranging session, either using the OOB key itself or in combination with information used in-band. The communication manager 140 may send a first message to the second device using the first scrambling sequence during the ranging session. Additionally or alternatively, the communication manager 140 may perform one or more other operations described herein.

[0069] In some aspects, the second device (e.g., UE 120) may include a communication manager 140. As described in more detail elsewhere herein, the communication manager 140 may receive an OOB key from the first device or network entity, which is shared OOB-wise relative to a ranging session defined in-band between the first and second devices. The communication manager 140 may use the OOB key itself or in combination with information used in-band to generate one or more inputs to a first scrambling sequence used in the ranging session in-band. The communication manager 140 may receive a first message using the first scrambling sequence from the first device. Additionally or alternatively, the communication manager 140 may perform one or more other operations described herein. The first and second devices may be two different UEs (such as those shown in FIG. 1), or the first and second devices may be a UE such as in FIG. 1 (e.g., UE 120a) and a device in a LAN such as in FIG. 4. In other words, the second device (such as the earphone 412 shown in FIG. 4) may not have WAN connectivity at all. The communication manager used to receive the OOB key may not be limited to a WAN communication manager and may be a more general WAN or LAN communication manager.

[0070] In some aspects, a network entity (e.g., network node 110) may include a communication manager 150. As described in more detail elsewhere herein, the communication manager 150 may receive a request from a first device for an OOB key associated with a ranging session at the first device. The communication manager 150 may send the OOB key OOB-wise to the first device upon successful authentication to the network entity by the first device. Additionally or alternatively, the communication manager 150 may perform one or more other operations described herein.

[0071] As indicated above, Figure 1 is provided as an example. Other examples may differ from those described with respect to Figure 1.

[0072] Figure 2 is a diagram illustrating communication between an example network node 110 and an example UE 120 in a wireless network according to the present disclosure.

[0073] As shown in Figure 2, network node 110 may include a data source 212, a transmit processor 214, a transmit (TX) MIMO processor 216, a set of modems 232 (shown as 232a to 232t, where t≥1), a set of antennas 234 (shown as 234a to 234v, where v≥1), a MIMO detector 236, a receive processor 238, a data sink 239, a controller / processor 240, a memory 242, a communication unit 244, a scheduler 246, and / or a communication manager 150, etc. In some configurations, one or a combination of antennas 234, modems 232, MIMO detectors 236, receive processors 238, transmit processors 214, and / or TX MIMO processors 216 may be included in the transceiver of network node 110. The transceiver may be under the control of and used by one or more processors (such as controller / processor 240), and in some respects, may perform aspects of the methods, procedures and / or operations described herein in conjunction with processor-readable code stored in memory 242. In some respects, network node 110 may include one or more interfaces, communication components and / or other components that facilitate communication with UE 120 or another network node.

[0074] The terms “processor,” “controller,” or “controller / processor” can refer to one or more controllers and / or one or more processors. For example, references to “processor,” “controller / processor,” etc. (in the singular) should be understood to refer to any one or more processors described in conjunction with FIG. 2, such as a single processor or a combination of multiple different processors. References to “one or more processors” should be understood to refer to any one or more processors described in conjunction with FIG. 2. For example, one or more processors of network node 110 may include transmit processor 214, TX MIMO processor 216, MIMO detector 236, receive processor 238, and / or controller / processor 240. Similarly, one or more processors of UE 120 may include MIMO detector 256, receive processor 258, transmit processor 264, TX MIMO processor 266, and / or controller / processor 280.

[0075] In some aspects, a single processor can perform all operations described as being performed by one or more processors. In some aspects, a first set of processors(s) of one or more processors can perform a first operation described as being performed by that one or more processors, and a second set of processors(s) of one or more processors can perform a second operation described as being performed by that one or more processors. The processors in the first set and the processors in the second set can be the same set of processors or can be different sets of processors. The reference to “one or more memories” should be understood to refer to any one or more memories of the corresponding device, such as the memories described in conjunction with Figure 2. For example, an operation described as being performed by one or more memories can be performed by the same subset of one or more memories or a different subset of one or more memories.

[0076] For downlink communication from network node 110 to UE 120, transmitting processor 214 may receive data (“downlink data”) intended for use by UE 120 (or a set of UEs including UE 120) from data source 212 (such as a data pipeline or data queue). In some examples, transmitting processor 214 may select one or more MCSs for UE 120 based on one or more Channel Quality Indicators (CQIs) received from UE 120. Network node 110 may process the data (e.g., including encoding the data) based on the MCS selected for UE 120 for transmission to UE 120 on the downlink, thereby generating data symbols. Transmitting processor 214 may process system information (e.g., semi-static resource partitioning information (SRPI)) and / or control information (e.g., CQI requests, grants, and / or upper-layer signaling) and provide overhead symbols and / or control symbols. The transmitting processor 214 can generate reference symbols for reference signals (e.g., cell-specific reference signals (CRS), demodulation reference signals (DMRS), or channel state information (CSI) reference signals (CSI-RS)) and / or synchronization signals (e.g., primary synchronization signal (PSS) or secondary synchronization signal (SSS)).

[0077] The TX MIMO processor 216 can perform space processing (e.g., pre-decoding) on ​​data symbols, control symbols, overhead symbols, and / or reference symbols where applicable, and can output a set of symbol streams (e.g., TA set of output symbol streams is provided to modem 232. For example, each output symbol stream may be provided to a corresponding modulator component (shown as MOD) of modem 232. Each modem 232 may use the corresponding modulator component to process (e.g., modulate) the corresponding output symbol stream (e.g., for orthogonal frequency division multiplexing (OFDM)) to obtain an output sample stream. Each modem 232 may further use the corresponding modulator component to process (e.g., convert to analog, amplify, filter, and / or upconvert) the output sample stream to obtain a time-domain downlink signal. Modems 232a to 232t may transmit the set of downlink signals (e.g., via a set of corresponding antennas 234) together. T (One downlink signal).

[0078] Downlink signals may include DCI communication, MAC control element (MAC-CE) communication, RRC communication, downlink reference signals, or another type of downlink communication. Downlink signals may be transmitted on the PDCCH, PDSCH, and / or on another downlink channel. Downlink signals may carry one or more transport blocks (TBs) of data. A TB may be a data unit transmitted via the air interface in the wireless communication network 100. A data stream (e.g., from data source 212) may be encoded into multiple TBs for transmission via the air interface. The number of TBs used to carry data associated with a particular data stream may be associated with a TB size shared by multiple TBs. The TB size may be based on the radio channel conditions of the air interface, the MCS used to encode the data, downlink resources allocated for transmitting data, and / or other parameters, or otherwise associated with them. Generally, a larger TB size allows for a larger amount of data to be transmitted in a single transmission, reducing signaling overhead. However, a larger TB size may be more prone to transmission and / or reception errors than a smaller TB size, but such errors can be mitigated through more robust error correction techniques.

[0079] For uplink communication from UE 120 to network node 110, the uplink signal from UE 120 may be received by antenna 234, processed by modem 232 (e.g., demodulator component of modem 232, shown as DEMOD), detected where applicable by MIMO detector 236 (e.g., receive (Rx) MIMO processor), and / or further processed by receive processor 238 to obtain decoded data and / or control information. Receive processor 238 may provide the decoded data to data sink 239 (which may be a data pipeline, data queue, and / or another type of data sink) and provide the decoded control information to processors such as controller / processor 240.

[0080] Network node 110 may use scheduler 246 to schedule one or more UEs 120 for downlink or uplink communication. In some aspects, scheduler 246 may use DCI to dynamically schedule DL transmissions to and / or UL transmissions from UE 120. In some examples, scheduler 246 may allocate repetitive time-domain and / or frequency-domain resources that UE 120 may use to transmit and / or receive communication using RRC configuration (e.g., semi-static configuration), for example, to perform semi-persistent scheduling (SPS) or to configure configuration grant (CG) for UE 120.

[0081] One or more of the following may be included in the RF chain of network node 110: transmit processor 214, TX MIMO processor 216, modem 232, antenna 234, MIMO detector 236, receive processor 238, and / or controller / processor 240. The RF chain may include one or more filters, mixers, oscillators, amplifiers, analog-to-digital converters (ADCs), and / or other devices for converting analog signals (such as those used for transmission or reception via an air interface) to digital signals (such as those used for processing by one or more processors of network node 110). In some aspects, the RF chain may be a transceiver of network node 110, or may be included in such a transceiver.

[0082] In some examples, network node 110 may use communication unit 244 to communicate with the core network and / or other network nodes. Communication unit 244 may support wired and / or wireless communication protocols and / or connections, such as Ethernet, fiber optic, Common Public Radio Interface (CPRI), and / or wired or wireless backhaul, etc. Network node 110 may use communication unit 244 to send and / or receive data associated with UE 120, or to perform network control signaling transmission, etc. Communication unit 244 may include transceivers and / or interfaces, such as network interfaces.

[0083] UE 120 may include a collection of antennas 252 (shown as antennas 252a to 252r, where r ≥ 1), a collection of modems 254 (shown as modems 254a to 254u, where u ≥ 1), a MIMO detector 256, a receive processor 258, a data sink 260, a data source 262, a transmit processor 264, a TX MIMO processor 266, a controller / processor 280, a memory 282, and / or a communication manager 140, etc. One or more components of UE 120 may be included in housing 284. In some aspects, one or a combination of antenna 252, modem 254, MIMO detector 256, receive processor 258, transmit processor 264, or TX MIMO processor 266 may be included in a transceiver included in UE 120. The transceiver may be under the control of and used by one or more processors (such as controller / processor 280), and in some respects, may perform aspects of the methods, procedures, or operations described herein in conjunction with processor-readable code stored in memory 282. In some respects, UE 120 may include another interface, another communication component, and / or another component that facilitates communication with network node 110 and / or another UE 120.

[0084] For downlink communication from network node 110 to UE 120, the set of antennas 252 can receive downlink communication or signals from network node 110, and can receive the set of downlink signals (e.g., R Each received signal is provided to a set of modems 254. For example, each received signal may be provided to a corresponding demodulator component (shown as DEMOD) of modem 254. Each modem 254 may use the corresponding demodulator component to condition (e.g., filter, amplify, down-convert, and / or digitize) the received signal to obtain an input sample. Each modem 254 may use the corresponding demodulator component to further demodulate or process the input sample (e.g., for OFDM) to obtain a received symbol. MIMO detector 256 may obtain the received symbols from the set of modems 254, may perform MIMO detection on the received symbols where applicable, and may provide the detected symbols. Receiver processor 258 may process (e.g., decode) the detected symbols, may provide the decoded data for UE 120 to data sink 260 (which may include data pipelines, data queues, and / or applications executed on UE 120), and may provide the decoded control information and system information to controller / processor 280.

[0085] For uplink communication from UE 120 to network node 110, the transmitting processor 264 may receive and process data (“uplink data”) from data source 262 (such as data pipelines, data queues, and / or applications running on UE 120) and control information from controller / processor 280. The control information may include one or more parameters, feedback, one or more signal measurements, and / or other types of control information. In some aspects, the receiving processor 258 and / or controller / processor 280 may determine one or more parameters related to the transmission of uplink communication for received signals (such as those received from network node 110 or another UE). One or more parameters may include a Reference Signal Received Power (RSRP) parameter, a Received Signal Strength Indicator (RSSI) parameter, a Reference Signal Received Quality (RSRQ) parameter, a CQI parameter, or a Transmit Power Control (TPC) parameter, etc. The control information may include indications of the RSRP parameter, RSSI parameter, RSRQ parameter, CQI parameter, TPC parameter, and / or another parameter. Control information can facilitate parameter selection and / or scheduling for UE 120 by network node 110.

[0086] Transmit processor 264 can generate reference symbols for one or more reference signals, such as uplink DMRS, uplink sounding reference signal (SRS), and / or another type of reference signal. Symbols from transmit processor 264 can be pre-decoded by TX MIMO processor 266 (where applicable) and further processed by an assembly of modems 254 (e.g., for DFT-s-OFDM or CP-OFDM). TX MIMO processor 266 can perform spatial processing (e.g., pre-decoding) on ​​data symbols, control symbols, overhead symbols, and / or reference symbols (where applicable) and can provide an assembly of output symbol streams to the assembly of modems 254 (e.g., ...). U Each output symbol stream may be provided to a corresponding modulator component (shown as MOD) of modem 254. Each modem 254 may use the corresponding modulator component to process (e.g., modulate) the corresponding output symbol stream (e.g., for OFDM) to obtain an output sample stream. Each modem 254 may further use the corresponding modulator component to process (e.g., convert to analog, amplify, filter, and / or upconvert) the output sample stream to obtain an uplink signal.

[0087] Modems 254a to 254u can transmit a set of uplink signals (e.g., via a set of corresponding antennas 252) R One uplink signal or UUplink signals may include UCI communication, MAC-CE communication, RRC communication, or another type of uplink communication. Uplink signals may be transmitted on PUSCH, PUCCH, and / or another type of uplink channel. Uplink signals may carry one or more TBs of data. Sidelink data and control transmission (i.e., transmission directly between two or more UEs 120) may typically use techniques similar to those described for uplink data and control transmission, and may use sidelink-specific channels such as the Physical Sidelink Shared Channel (PSSCH), Physical Sidelink Control Channel (PSCCH), and / or Physical Sidelink Feedback Channel (PSFCH).

[0088] One or more antennas in the set of antennas 252 or the set of antennas 234 may include one or more antenna panels, one or more antenna groups, one or more sets of antenna elements, or one or more antenna arrays, etc., or may be included in one or more antenna panels, one or more antenna groups, one or more sets of antenna elements, or one or more antenna arrays, etc. Antenna panels, antenna groups, sets of antenna elements, or antenna arrays may include one or more antenna elements (within a single housing or multiple housings), a set of coplanar antenna elements, a set of non-coplanar antenna elements, or one or more antenna elements coupled to one or more transmitting or receiving components (such as one or more components of FIG. 2). As used herein, “antenna” may refer to one or more antennas, one or more antenna panels, one or more antenna groups, one or more sets of antenna elements, or one or more antenna arrays. “Antenna panel” may refer to a set of antennas (such as antenna elements) arranged in an array or panel that can facilitate beamforming by manipulating the parameters of that set of antennas. “Antenna module” may refer to circuitry that includes one or more antennas, and may also include one or more other components (such as filters, amplifiers, or processors) associated with integrating the antenna module into a wireless communication device.

[0089] In some examples, each antenna element of antenna 234 or antenna 252 may include one or more sub-elements for radiating or receiving radio frequency signals. For example, a single antenna element may include a first sub-element cross-polarized with a second sub-element that can be used to independently transmit the cross-polarized signal. Antenna elements may include patch antennas, dipole antennas, and / or other types of antennas arranged in a linear pattern, a two-dimensional pattern, or another pattern. The spacing between antenna elements can allow signals with a desired wavelength transmitted individually by the antenna elements to interact or interfere (e.g., to form a desired beam) in various directions. For example, given a desired wavelength or frequency range, the spacing may provide a quarter wavelength, half a wavelength, or another fraction of the wavelength between adjacent antenna elements to allow desired constructive and destructive interference modes of signals transmitted by individual antenna elements within that desired range.

[0090] The amplitude and / or phase of signals transmitted via antenna elements and / or sub-elements can be modulated and (e.g., by manipulating phase shifts, phase offsets, and / or amplitudes) shifted relative to each other to generate one or more beams; this is known as beamforming. The term "beam" can refer to the directional transmission of a wireless signal toward a receiving device or otherwise in a desired direction. "Beam" can also generally refer to the direction associated with such directional signal transmission, the set of directional resources associated with the signal transmission (e.g., angle of arrival, horizontal direction, and / or vertical direction), and / or a set of parameters indicating one or more aspects of the directional signal, the direction associated with the signal, and / or the set of directional resources associated with the signal. In some implementations, antenna elements can be individually selected or deselected for the directional transmission of a signal (or multiple signals) by controlling the amplitude of one or more corresponding amplifiers and / or the phase of the signal to form one or more beams. The shape of the beam (such as amplitude, width, and / or the presence of sidelobes) and / or the direction of the beam (such as the angle of the beam relative to the surface of the antenna array) can be dynamically controlled by modifying the phase shifts, phase offsets, and / or amplitudes of multiple signals relative to each other.

[0091] Different UEs 120 or network nodes 110 may include different numbers of antenna elements. For example, UE 120 may include a single antenna element, two antenna elements, four antenna elements, eight antenna elements, or different numbers of antenna elements. As another example, network node 110 may include eight antenna elements, 24 antenna elements, 64 antenna elements, 128 antenna elements, or different numbers of antenna elements. Generally speaking, a larger number of antenna elements provides increased control over the parameters used for beamforming compared to a smaller number of antenna elements, while a smaller number of antenna elements may be less complex to implement and can use less power. Multiple antenna elements can support multi-layer transmission, in which the same time and frequency resources are used to utilize spatial multiplexing to transmit a first layer of communication (which may include a first data stream) and a second layer of communication (which may include a second data stream).

[0092] Although the boxes in Figure 2 are illustrated as different components, the functions described above with respect to these boxes may be implemented in a single hardware, software, or combined component, or in various combinations of components. For example, the functions described with respect to transmit processor 264, receive processor 258, and / or TX MIMO processor 266 may be performed by or under the control of controller / processor 280.

[0093] Figure 3 is a diagram illustrating an example disaggregated base station architecture 300 according to the present disclosure. One or more components of the example disaggregated base station architecture 300 may be one or more network nodes (such as one or more network nodes 110), may include, or may be included in one or more network nodes. The disaggregated base station architecture 300 may include a CU 310, which may communicate directly with the core network 320 via a backhaul link, or may communicate indirectly with the core network 320 via one or more disaggregated control units (such as non-RT RIC 350 and / or near-RT RIC 370 associated with a Service Management and Orchestration (SMO) framework 360 (e.g., via an E2 link)). The CU 310 may communicate with one or more DU 330 via a corresponding midhaul link (such as via an F1 interface). Each DU 330 may communicate with one or more RU 340 via a corresponding fronthaul link. Each RU 340 may communicate with one or more UE 120 via a corresponding RF access link. In some deployments, UE 120 can be served by multiple RU 340s simultaneously.

[0094] Each component of the disassembled base station architecture 300 (including CU 310, DU 330, RU 340, near-RT RIC 370, non-RT RIC 350, and SMO frame 360) may include one or more interfaces or may be coupled to one or more interfaces for receiving or transmitting signals, such as data or information, via wired or wireless transmission media.

[0095] In some respects, the CU 310 can be logically divided into one or more CU user plane (CU-UP) units and one or more CU control plane (CU-CP) units. When implemented in an O-RAN configuration, the CU-UP units can communicate bidirectionally with the CU-CP units via an interface such as an E1 interface. The CU 310 can be deployed to communicate with one or more DU 330s for network control and signaling, as needed. Each DU 330 may correspond to a logical unit that includes one or more base station functions for controlling the operation of one or more RU 340s. For example, the DU 330 may host various layers, such as the RLC layer, MAC layer, or one or more PHY layers (such as one or more high PHY layers or one or more low PHY layers). Each layer (which may also be referred to as a module) can be implemented using an interface for signaling to other layers (and modules) hosted by the DU 330, or for signaling to control functions hosted by the CU 310. Each RU 340 may implement lower-layer functionality. In some respects, the real-time and non-real-time aspects of communication with the control plane and user plane of the RU 340 can be controlled by the corresponding DU 330.

[0096] The SMO framework 360 supports RAN deployment and provisioning of both non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 360 supports the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via operation and maintenance interfaces such as the O1 interface. For virtualized network elements, the SMO framework 360 can interact with cloud computing platforms such as the Open Cloud (O-Cloud) platform 390 to perform network element lifecycle management (such as instantiating virtualized network elements) via cloud computing platform interfaces such as the O2 interface. Virtualized network elements may include, but are not limited to, CU 310, DU 330, RU 340, non-RT RIC 350, and / or near-RT RIC 370. In some aspects, the SMO framework 360 can communicate with hardware aspects of 4G RAN, 5G NR RAN, and / or 6G RAN (such as the Open eNB (O-eNB) 380) via the O1 interface. Additionally or alternatively, the SMO framework 360 can communicate directly with each of one or more RUs 340 via the corresponding O1 interface. In some deployments, this configuration enables each DU 330 and CU 310 to be implemented in a cloud-based RAN architecture, such as a vRAN architecture.

[0097] The non-RT RIC 350 may include or implement logic functions that enable non-real-time control and optimization of RAN elements and resources, including AI / ML workflows for model training and updates, and / or policy-based guidance of applications and / or features in the near-RT RIC 370. The non-RT RIC 350 may be coupled to or communicate with the near-RT RIC 370, such as via an A1 interface. The near-RT RIC 370 may include or implement logic functions that enable near real-time control and optimization of RAN elements and resources via an interface, such as an E2 interface, through data collection and action, connecting one or more CU 310s, one or more DU 330s, and / or O-eNBs to the near-RT RIC 370.

[0098] In some aspects, to generate AI / ML models to be deployed in the near-RT RIC 370, the non-RT RIC 350 may receive parameters or external enrichment information from an external server. This information can be utilized by the near-RT RIC 370 and can be received from non-network data sources or network functions at the SMO framework 360 or the non-RT RIC 350. In some examples, the non-RT RIC 350 or near-RT RIC 370 may modulate RAN behavior or performance. For example, the non-RT RIC 350 may monitor long-term trends and patterns in performance and may perform corrective actions using AI / ML models via the SMO framework 360 (such as reconfiguration via the O1 interface) or via the creation of RAN management policies (such as A1 interface policies).

[0099] As indicated above, Figure 3 is provided as an example. Other examples may differ from those described with respect to Figure 3.

[0100] The network node 110, the controller / processor 240 of the network node 110, the UE 120, the controller / processor 280 of the UE 120, the CU 310, the DU 330, the RU 340, or any other component of Figures 1, 2, or 3 may implement one or more technologies associated with operating a wireless device using an OOB key or perform one or more operations associated with operating a wireless device using an OOB key, as described in more detail elsewhere herein. The first and / or second device described herein may include, or may be, components of the UE 120. For example, the controller / processor 240 of the network node 110, the controller / processor 280 of the UE 120, any other component of Figure 2, the CU 310, the DU 330, or the RU 340 may (alone or in combination with one or more other processors) perform or direct the operation of processes such as process 1200 of Figure 12, process 1300 of Figure 13, process 1400 of Figure 14, or other processes as described herein. Memory 242 may store data and program code for network node 110, CU 310, DU 330, or RU 340. Memory 282 may store data and program code for UE 120. In some examples, memory 242 or memory 282 may include a non-transitory computer-readable medium storing instruction sets (e.g., code or program code) for wireless communication. Memory 242 may include one or more memories, such as a single memory or multiple different memories (of the same or different types). Memory 282 may include one or more memories, such as a single memory or multiple different memories (of the same or different types). For example, when the instruction set is executed by one or more processors of network node 110, UE 120, CU 310, DU 330, or RU 340 (e.g., directly, or after compilation, transformation, or interpretation), it may cause the one or more processors to perform process 1200 of FIG. 12, process 1300 of FIG. 13, process 1400 of FIG. 14, or other processes as described herein. In some examples, execution instructions may include run instructions, transformation instructions, compilation instructions, and / or interpretation instructions, etc.

[0101] In some aspects, the first device (e.g., UE 120) includes: components for obtaining an OOB key, which is shared OOB-wise with respect to a ranging session defined in-band between the first device and the second device; components for generating one or more first inputs to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band; and / or components for sending a first message to the second device using the first scrambling sequence during the ranging session. In some aspects, components for the first device to perform the operations described herein may include, for example, one or more of a communication manager 140, an antenna 252, a modem 254, a MIMO detector 256, a receive processor 258, a transmit processor 264, a TX MIMO processor 266, a controller / processor 280, or a memory 282.

[0102] In some aspects, the second device (e.g., UE 120) includes: components for receiving an OOB key from the first device or network entity, the OOB key being shared OOB-wise with respect to a ranging session defined in-band between the first and second devices; components for generating one or more inputs in-band to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band; and / or components for receiving a first message using the first scrambling sequence from the first device. In some aspects, components for the second device to perform the operations described herein may include, for example, one or more of a communication manager 140, an antenna 252, a modem 254, a MIMO detector 256, a receive processor 258, a transmit processor 264, a TX MIMO processor 266, a controller / processor 280, or a memory 282.

[0103] In some aspects, the network entity (e.g., network node 110) includes components for receiving a request from the first device for an OOB key associated with a ranging session at the first device; and / or components for sending the OOB key OOB-wise to the first device upon successful authentication by the first device to the network entity. In some aspects, components for the network entity to perform the operations described herein may include, for example, one or more of the following: a communication manager 150, a transmit processor 214, a TX MIMO processor 216, a modem 232, an antenna 234, a MIMO detector 236, a receive processor 238, a controller / processor 240, a memory 242, or a scheduler 246.

[0104] As indicated above, Figure 3 is provided as an example. Other examples may differ from those described with respect to Figure 3.

[0105] Figure 4 is an illustration of an example of a first device that operates as a central device 402 and can connect to a second device (such as a peripheral device) using the BLE protocol or a modified BLE protocol, establishing a communication link 416 with the second device. Peripheral devices may include a smartwatch 404, a BT portable speaker 406, a wireless headset 408, a headphone 410, wireless earbuds 412, a smart appliance 414 (which may be referred to herein as a receiver device or other suitable terminology), and / or a locking mechanism (e.g., a building door, a vehicle door). The BLE protocol is part of the BT core specification and enables radio frequency communication operating within the globally accepted 2.4 GHz Industrial, Scientific, and Medical (ISM) band.

[0106] In some aspects, as described herein, the central device 402 may include components (e.g., shown in FIG. 2) or suitable logic, circuitry, interfaces, processors, and / or code that can be used to communicate with one or more peripheral devices 404, 406, 408, 410, 412, and / or 414 using the BLE protocol or a modified BLE protocol. In some aspects, the central device 402 may operate as an initiator to request the establishment of a link layer (LL) connection with the intended peripheral device 404, 406, 408, 410, 412, and / or 414. In some aspects, a link manager may be used to control the operation between the WPAN application controller in the central device 402 and the WPAN application controller in each of the intended peripheral devices 404, 406, 408, 410, 412, and / or 414.

[0107] In some respects, after establishing the requested LL connection, the central device 402 can become the master device, and the selected or anticipated peripheral devices 404, 406, 408, 410, 412, and / or 414 can become paired with the central device 402 through the established LL connection. As the master device, the central device 402 can support multiple simultaneous LL connections with various peripheral devices 404, 406, 408, 410, 412, and / or 414 operating as user terminal devices. For example, the central device 402 can manage various aspects of data packet communication in LL connections with one or more associated peripheral devices 404, 406, 408, 410, 412, and / or 414. For example, the central device 402 can determine the operation scheduling in LL connections with one or more peripheral devices 404, 406, 408, 410, 412, and / or 414. The central device 402 can also initiate LL Protocol Data Unit (PDU) exchange sequences through the LL connection. The LL connection can be configured to operate periodic connection events in a dedicated data channel. LL data PDU transmissions between the central device 402 and one or more peripheral devices 404, 406, 408, 410, 412, and / or 414 can occur within the connection event.

[0108] In some aspects, the central device 402 may be configured to send a first LL data PDU to the intended peripheral devices 404, 406, 408, 410, 412, and / or 414 in each connection event. Additionally or alternatively, in some aspects, the central device 402 may use a polling scheme to poll the intended peripheral devices 404, 406, 408, 410, 412, and / or 414 for LL data PDU transmission during a connection event. The intended peripheral devices 404, 406, 408, 410, 412, and / or 414 may transmit the LL data PDU upon receiving a packet carrying the LL data PDU from the central device 402. In some other aspects, the peripheral devices 404, 406, 408, 410, 412, and / or 414 may transmit the LL data PDU to the central device 402 without first receiving the LL data PDU from the central device 402.

[0109] Examples of central devices 402 may include cellular phones, smartphones, Session Initiation Protocol (SIP) phones, mobile stations (STAs), laptops, personal computers (PCs), desktop computers, personal digital assistants (PDAs), satellite radios, global positioning systems, multimedia devices, video devices, digital audio players, cameras, game consoles, tablets, smart devices, wearable devices (such as smartwatches or wireless headphones), vehicles, vehicle infotainment systems or in-vehicle kits, vehicle remote keys, electricity meters, gas pumps, ovens, thermostats, hearing aids, wearable blood glucose units, Internet of Things (IoT) devices, etc.

[0110] Examples of one or more peripheral devices 404, 406, 408, 410, 412 and / or 414 may include cellular phones, smartphones, SIP phones, STAs, laptops, PCs, desktop computers, PDAs, satellite radios, GPS devices, multimedia devices, video devices, digital audio players, cameras, game consoles, tablets, smart devices, wearable devices (e.g., smartwatches, wireless headphones or wireless earbuds), vehicles, vehicle infotainment systems or in-vehicle kits, remote-controlled locks, electricity meters, gas pumps, ovens, thermostats, hearing aids, wearable blood glucose meters, IoT devices, etc. While central device 402 is illustrated in Figure 4 as communicating with six peripheral devices 404, 406, 408, 410, 412 and 414 in WPAN 400, it should be understood that central device 402 may communicate with more than six or fewer peripheral devices within WPAN 400 without departing from the scope of this disclosure.

[0111] In some aspects, a device implementing the BT protocol (e.g., central device 402) may operate according to a first radio mode (e.g., a Basic Rate (BR) / Enhanced Data Rate (EDR) radio mode), and a device implementing the BLE protocol may operate according to a second radio mode (e.g., a BLE radio mode). In some aspects, central device 402 may be configured to utilize dual radio modes, and thus may be able to operate according to either the BR / EDR mode or the BLE mode, for example, based on the type of short-range wireless communication that central device 402 may participate in.

[0112] For example, in some aspects, the central device 402 may operate according to BR / EDR mode for continuous streaming of data, for broadcast networks, for mesh networks, and / or for some other applications where relatively higher data rates may be more suitable. Additionally or alternatively, the central device 402 may operate according to BLE mode for short burst data transmission (such as for some other applications where power savings and / or relatively lower data rates may be acceptable). Additionally or alternatively, in some aspects, the central device 402 may operate according to one or more other radio modes, such as proprietary radio modes. Examples of other radio modes may include high-speed radio modes, low-power radio modes, and / or isochronous radio modes, etc.

[0113] In some respects, as described in more detail elsewhere herein, the auxiliary wireless device (e.g., among peripheral devices 404, 406, 408, 410, 412, and 414) can track a first retransmission metric based on the number of retransmission packets received by the auxiliary wireless device from a source device (such as central device 402). The auxiliary wireless device can receive an acknowledgment assistance request from the destination wireless device (e.g., among peripheral devices 404, 406, 408, 410, 412, and 414) indicating a second retransmission metric for the destination wireless device. The auxiliary wireless device can send a response to the acknowledgment assistance request to the destination wireless device based on the corresponding values ​​of the first and second retransmission metrics. Additionally or alternatively, the auxiliary wireless device can perform one or more other operations described herein.

[0114] In some respects, as described in more detail elsewhere herein, the destination wireless device (e.g., one of peripheral devices 404, 406, 408, 410, 412, and 414) may track a first retransmission metric based on the number of retransmission packets received by the destination wireless device from a source device (such as central device 402). The destination wireless device may send an acknowledgment assistance request to an auxiliary wireless device (e.g., one of peripheral devices 404, 406, 408, 410, 412, and 414) indicating the first retransmission metric tracked by the destination wireless device. The destination wireless device may receive a response to the acknowledgment assistance request from the auxiliary wireless device based on the corresponding values ​​of the first retransmission metric tracked by the destination wireless device and the second retransmission metric tracked by the auxiliary wireless device. Additionally or alternatively, the destination wireless device may perform one or more other operations described herein.

[0115] Communication between the central device 402 and peripheral devices can be achieved through various short-range radio technologies. For example, the earphone 412 and the central device 402 can be connected simultaneously via WiFi, BT / BLE, or both. Communication may involve BCS extended discovery, where the discovery of BLE extended services can occur via the WiFi protocol, and not necessarily via the WAN or BT protocol.

[0116] As indicated above, Figure 4 is provided as an example. Other examples may differ from those described with respect to Figure 4.

[0117] Figure 5 is a diagram illustrating an example of a wireless communication device 500 according to the present disclosure. The wireless communication device may be a UE or may include components for operating using different RATs (e.g., BLE). In some aspects, the wireless communication device 500 may be an example of the central device 402 illustrated in Figure 4. Additionally or alternatively, the wireless communication device 500 may be an example of one or more peripheral devices among the peripheral devices 404, 406, 408, 410, 412, or 414 illustrated in Figure 4. In some aspects, the wireless communication device 500 may be a Bluetooth-enabled device (such as a BLE device).

[0118] As shown in Figure 5, the wireless communication device 500 may include processing elements, such as a processor 502 capable of executing program instructions for the wireless communication device 500. The wireless communication device 500 may also include a display 542 capable of performing graphics processing and presenting information to a user. The processor 502 may also be coupled to a memory management unit (MMU) 540, which may be configured to receive addresses from the processor 502 and translate these addresses into address locations in memory (such as memory 506, ROM 508, or flash memory 510) and / or other circuitry or devices (such as display circuitry 504, radio components 530, connector interface 520, and / or display 542). The MMU 540 may also be configured to perform memory protection and page table translation or creation. In some aspects, the MMU 540 may be included as part of the processor 502. It should be noted that the WPAN controller 552 may be implemented in a separate chip, including its own processor 502, memory 506, ROM 508, and / or flash memory 510, and may communicate with the first chip using serial lines.

[0119] Processor 502 may be coupled to other circuitry of wireless communication device 500. For example, wireless communication device 500 may include various memory types, a connector interface 520 through which wireless communication device 500 can communicate with a computer system, and a wireless communication subsystem capable of sending data to and receiving data from other devices based on one or more wireless communication standards or protocols. For example, in some aspects, the wireless communication subsystem may include (but is not limited to) a wireless local area network (WLAN) subsystem, a WPAN subsystem, and / or a cellular subsystem (such as a Long Term Evolution (LTE) or New Radio (NR) subsystem). Wireless communication device 500 may include multiple antennas 535a, 535b, 535c, and / or 535d for performing wireless communication with wireless communication devices, such as those in a WPAN. In some aspects, the WPAN may be an extended PAN (XPAN).

[0120] The wireless communication device 500 may be configured to implement some or all of the techniques described herein by executing program instructions stored on a memory medium (such as a non-transitory computer-readable memory medium) and / or by hardware or firmware operation. In other embodiments, the techniques described herein may be implemented at least in part by programmable hardware elements such as FPGAs and / or application-specific integrated circuits (ASICs).

[0121] In some aspects, radio component 530 may include separate controllers configured to control communications of various corresponding RAT protocols. For example, as shown in FIG5, radio component 530 may include a WLAN controller 550 for managing WLAN communications, a WPAN controller 552 for managing Bluetooth, BLE, and / or other suitable WPAN communications, and a WWAN controller 556 for managing wide area network (WWAN) communications. In some aspects, wireless communication device 500 may store and execute WLAN software drivers for controlling WLAN operations performed by WLAN controller 550, WPAN software drivers for controlling WPAN operations performed by WPAN controller 552, and / or WWAN software drivers for controlling WWAN operations performed by WWAN controller 556.

[0122] In some aspects, a first coexistence interface 554 (such as a wired interface) may be used to transmit information between the WLAN controller 550 and the WPAN controller 552. Additionally or alternatively, in some aspects, a second coexistence interface 558 may be used to transmit information between the WLAN controller 550 and the WWAN controller 556. Additionally or alternatively, in some aspects, a third coexistence interface 560 may be used to transmit information between the WPAN controller 552 and the WWAN controller 556.

[0123] In some respects, one or more of the WLAN controller 550, WPAN controller 552, and / or WWAN controller 556 may be implemented as hardware, software, firmware, or any suitable combination thereof. The WPAN controller 552 may be implemented in a separate chip, including its own processor 502, memory 506, ROM 508, and / or flash memory 510.

[0124] In some aspects, the WLAN controller 550 can be configured to use one or more, some, or all of the antennas 535a, 535b, 535c, and 535d to communicate with a second device in the WPAN using a WLAN link. In other configurations, the WPAN controller 552 can be configured to use one or more, some, or all of the antennas 535a, 535b, 535c, and 535d to communicate with at least one second device in the WPAN. In other configurations, the WWAN controller 556 can be configured to use one or more, some, or all of the antennas 535a, 535b, 535c, and 535d to communicate with a second device in the WPAN. The WLAN controller 550, WPAN controller 552, and / or WWAN controller 556 can be configured to adjust the wake-up interval and downtime of the wireless communication device 500.

[0125] In some aspects, the wireless communication device 500 may include a hardware (HW) root of trust 562, which may include an isolated hardware subsystem of the wireless communication device 500 and may be implemented by a processor. One of the main functionalities provided is key management. The wireless communication device 500 may include a secure element 564. The secure element 564 may be a secure portion of the wireless communication device 500 similar to the root of trust, but at a higher level of security assurance. The secure element 564 may also provide key management services.

[0126] Short-range wireless communication protocols (such as BT, BLE, and / or BR / EDR) may include and / or use one or more other communication protocols, for example, to establish and maintain communication links. Referring also to FIG1, wireless communication device 500 may establish a communication link 416 with one or more peripheral devices (such as wireless headset 410) according to at least one communication protocol for short-range wireless communication. In some aspects, communication link 416 may include communication links conforming to protocols included in and / or used with BT, BLE, BR / EDR, etc. In one aspect, communication link 416 may include asynchronous connection-oriented logic (ACL) transmission, sometimes referred to as an ACL link. When operating as an ACL link, communication link 416 may allow a central device 402 (e.g., a source device) to connect or "pair" with a peripheral device (such as earphone 412). This connection is asynchronous because the two devices may not need to synchronize their data communication with each other in time to allow data packet communication via communication link 416.

[0127] In some respects, the Logical Link Control and Adaptation Protocol (L2CAP) can be used within the BT protocol stack (not shown in Figure 2 for simplicity). An L2CAP connection can be established after the ACL link has been established. References to L2CAP in this disclosure can be further applied to Enhanced L2CAP (EL2CAP), which can be an enhanced version of the L2CAP protocol that allows multiple logical data channels to be multiplexed over a single radio connection.

[0128] In some respects, communication link 416 may include an Advanced Audio Distribution Profile (A2DP) link. For example, an A2DP link may provide a point-to-point link between a source device (such as central device 402) and a destination device (such as earphone 412). Using an A2DP link, data packets, including audio packets, can be transmitted on an ACL channel, and other information (e.g., for controlling the audio stream) can be transmitted on a separate control channel. Data packets may occur non-periodically.

[0129] In some aspects, communication link 416 may support synchronous logical transmission mechanisms between source devices (such as central device 402) and peripheral devices (such as earphones 412). For example, communication link 416 may include a Synchronous Connection-Oriented (SCO) link, which uses time slots reserved for BT communication to provide a symmetrical point-to-point link between the source device and the peripheral device. In some aspects, the SCO link may not support retransmission of data packets, which may be unsatisfactory in audio streaming and / or voice call use cases where dropped audio or voice packets can degrade the user experience quality.

[0130] In some aspects, communication link 416 may include an extended SCO (eSCO) link. An eSCO link can provide a symmetric or asymmetric point-to-point link between the source device and peripheral devices using time slots reserved for BT communication, and can also provide a retransmission window after the reserved time slots. Because a retransmission window can be used to facilitate retransmission, an eSCO link is suitable for audio streaming and / or voice call use cases, as dropped audio or voice packets can be retransmitted, thus increasing the probability of successfully receiving data packets.

[0131] In some respects, the communication link 416 shown in Figure 4 may include an isochronous (ISO) link. When operating as an ISO link, communication link 416 may combine some features of both synchronous and asynchronous links. For example, a stream on an ISO link can begin with a start packet, and then data packets can be sent asynchronously. On an ISO link, the number of retransmission attempts by the transmitting device can be limited. Therefore, if the receiving device cannot decode a data packet within a limited number of retransmission attempts, the data packet can be discarded, and the receiving device can continue receiving the stream without any data from the discarded data packet.

[0132] In some aspects, the first device (e.g., wireless communication device 500) includes: components for obtaining an OOB key, the OOB key being shared OOB-wise with respect to a ranging session defined in-band between the first device and the second device; components for generating one or more first inputs to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band; and / or components for transmitting a first message to the second device using the first scrambling sequence during the ranging session. In some aspects, components for causing the first device to perform the operations described herein may include one or more of, for example, antennas 535a to 535d, a WPAN controller 552, a radio component 530, and / or a processor 502.

[0133] In some aspects, the second device (e.g., wireless communication device 500) includes: components for receiving an OOB key from the first device or network entity, the OOB key being shared OOB-wise with respect to a ranging session defined in-band between the first and second devices; components for generating one or more inputs to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band; and / or components for receiving a first message using the first scrambling sequence from the first device. In some aspects, components for causing the second device to perform the operations described herein may include one or more of, for example, antennas 535a to 535d, a WPAN controller 552, a radio component 530, and / or a processor 502.

[0134] As indicated above, Figure 5 is provided as an example. Other examples may differ from those described with respect to Figure 5.

[0135] Figure 6 is a diagram illustrating example 600 of a protocol stack (e.g., a WPAN and / or BT protocol stack) according to this disclosure. In some aspects, protocol stack 600 may be implemented in a wireless communication device (such as one or more of the central device 402 or peripheral devices 404, 406, 408, 410, 412, or 414 of Figure 4). For example, protocol stack 600 may be implemented by one or more of the processor 502, memory 506, flash memory 510, ROM 508, radio component 530, and / or WPAN controller 552 illustrated in Figure 5. In some aspects, protocol stack 600 may be organized into three layers, including an application layer 610, a host layer 620, and a controller layer 630.

[0136] In some aspects, application layer 610 may be a user application layer that interfaces with other blocks and / or layers of protocol stack 600. In some aspects, application layer 610 may include one or more applications 612 and one or more BT profiles 614 that allow one or more applications 612 to use BT and / or BLE communication. Host layer 620 may include an upper layer of protocol stack 600 and may communicate with a controller in a wireless communication device (such as the WPAN controller 552 of FIG. 5) using host controller interface (HCI) 640. In some aspects, host layer 620 may include host stack 621, which may be used for application layer interface management to allow applications 612 to access WPAN communication.

[0137] Controller layer 630 may include lower layers of protocol stack 600. In some aspects, controller layer 630 may be used for hardware interface management, link establishment, and link management. As shown in Figure 6, controller layer 630 may include link manager 632, link layer 634, and PHY layer 636. PHY layer 636 may include, for example, radio components and / or baseband processor. In some aspects, PHY layer 636 may define mechanisms for transmitting bit streams via physical links or channels connecting WPAN devices. Bit streams may be encoded into codewords or symbols and may be converted into data packets for transmission over a wireless transmission medium. PHY layer 636 may provide electrical, mechanical, and / or procedural interfaces to the wireless transmission medium. PHY layer 636 may be responsible for modulating and demodulating data into RF signals for over-the-air transmission. PHY layer 636 may describe the physical characteristics of transmitters / receivers (or transceivers) included in wireless communication devices. Physical characteristics may include modulation characteristics, RF tolerance, and / or sensitivity levels, etc.

[0138] In some aspects, link layer 634 is responsible for low-level communication on top of PHY layer 636. Link layer 634 manages the sequence and timing of data packets for sending and receiving, and communicates with other devices using the LL protocol regarding connection parameters and data flow control. Link layer 634 also provides gatekeeping functionality for restricting exposure and data exchange with other devices. If filtering is configured, link layer 634 maintains a list of allowed devices and can ignore all requests for data exchange from devices not on the allowed list. Link layer 634 also reduces power consumption. In some aspects, link layer 634 may include proprietary LLs that can be used to discover peer devices and establish secure communication channels with them. In some aspects, link layer 634 may be responsible for transmitting data packets between devices in a WPAN. Each data packet may include an access address that specifies the type of logical transport used to carry the data packet. Logical transports can exist between master and slave devices. Additionally, some logical transports may carry multiple logical links.

[0139] The link manager 632 is responsible for establishing and configuring links, as well as managing power change requests and other tasks. Each type of logical link (such as ACL links, A2DP links, SCO links, eSCO links, ISO links, etc.) can be associated with a specific packet type. For example, an SCO link can provide reserved channel bandwidth for communication between a central device and a peripheral device, and can support periodic exchange of data packets without retransmissions. An eSCO link can provide reserved channel bandwidth for communication between a source device and a peripheral device, and can support periodic exchange of data packets with retransmissions. An ACL link can exist between a source device and a peripheral device from the beginning of establishing a connection, and the data packets of an ACL link can include encoded information in addition to the payload.

[0140] Link Manager 632 can communicate with Host Layer 620 using HCI 640. In some respects, Link Manager 632 can translate commands associated with HCI 640 into controller-level operations, such as baseband-level operations. HCI 640 can act as a boundary between lower layers, such as between Controller Layer 630, Host Layer 620, and Application Layer 610. The BT specification can define a standard HCI to support BT systems implemented across two independent processors. For example, a BT system on a computer can use the processor of the BT system to implement the lower layers of Protocol Stack 600 (such as PHY Layer 636, Link Layer 634, and / or Link Manager 632), and can use the processor of the BT components to implement the other layers of Protocol Stack 600 (such as Host Layer 620 and Application Layer 610).

[0141] In Figure 6, the host layer 620 is shown as including a Generic Access Profile (GAP) 622, a Generic Attribute Protocol (GATT) 624, a Security Manager (SM) 626, an Attribute Protocol (ATT) 628, and an L2CAP layer 629. GAP 622 provides an interface for application 612 to initiate, establish, and manage connections with other WPAN (e.g., BT or BLE) devices. GATT 624 provides a service framework for using the Attribute Protocol to discover services and to read and write attribute values ​​on peer devices. GATT 624 can interface with application 612, for example, through a profile that can define sets of attributes and any permitted attributes required for use in BT or BLE communication.

[0142] Security Manager 626 is responsible for device pairing and key distribution. The Security Manager protocol implemented by Security Manager 626 defines how communication with the corresponding BLE device's Security Manager is performed. Security Manager 626 provides additional cryptographic functions that can be used by other components of Protocol Stack 600. The architecture of Security Manager 626 used in WPAN communication is designed to minimize traceability requirements to peripheral devices by offloading work to a potentially more robust central device. BLE uses a pairing mechanism for key distribution. Security Manager 626 provides mechanisms for encrypting data and for providing data authentication.

[0143] The ATT 628 includes a client / server protocol based on attributes associated with BLE devices configured for a specific purpose. Examples may include monitoring heart rate, temperature, broadcasting advertisements, remotely controlling locks, etc. Attributes can be discovered, read, and written by peer devices. The set of operations performed on the ATT 628 may include error handling, server configuration, finding information, read operations, write operations, and / or queuing writes. The ATT 628 can form the basis for data exchange between BT devices and BLE devices.

[0144] L2CAP layer 629 can be implemented above HCI 640 and can communicate with controller layer 630 via HCI 640. L2CAP layer 629 can be responsible for establishing connections across one or more existing logical links and for requesting additional links (if none exist). L2CAP layer 629 can also enable multiplexing between different higher-layer protocols, for example to allow different applications to use a single link, such as a logical link (including ACL links). In some implementations, L2CAP layer 629 can encapsulate multiple protocols from the upper layers into a data packet format (and vice versa). L2CAP layer 629 can also decompose packets from the upper layers with large data payloads into multiple packets with data payloads segmented into smaller data payloads that fit the maximum payload size on the sending side (e.g., twenty-seven (27) bytes).

[0145] In some standards and protocols (such as BLE and / or BR / EDR), the central device 402 can detect errors and / or dropped / missing / unreceived packets by using Cyclic Redundancy Check (CRC) verification and by using Message Integrity Code (MIC) verification. MIC verification can be used when packets are encrypted. For example, a CRC verification failure can indicate one or more errors in a received packet, and a MIC verification failure can indicate that another packet has not yet been received (but a CRC verification failure can also indicate that another packet has not yet been received, and / or a MIC verification failure can also indicate one or more errors in a received packet).

[0146] CRC verification and MIC verification can be based on: generating CRC values ​​and MICs respectively based on the received packets, and comparing these generated CRC values ​​and MICs respectively with the CRC values ​​and MICs included in the received packets. Specifically, a receiving device (such as headset 110) receiving packets can first generate a CRC value or CRC checksum based on the received packets (such as based on the payload and (if applicable) MIC included in the received packets). The receiving device can compare the generated CRC value with the CRC value included in the received packets. If the generated CRC value matches the CRC value included in the received packets, the received packets can be verified against the CRC. The CRC-verified received packets can then be decrypted. However, if the generated CRC value does not match the CRC value included in the received packets, the receiving device can determine that the received packets failed CRC verification. If the receiving device determines that the received packets failed CRC verification, the received packets may contain errors and / or may be corrupted. In one configuration, the receiving device can discard received packets that failed CRC verification. Alternatively, in another configuration, the receiving device may attempt to recover the received packets, for example, using one or more error correction techniques.

[0147] If the received packet is encrypted and verified by CRC, the receiving device can decrypt the received packet to obtain the decrypted payload and the decrypted MIC. For MIC verification, the receiving device can generate a MIC based on the decrypted payload and compare the generated MIC with the MIC obtained from the decrypted received packet. If the generated MIC matches the decrypted MIC, the receiving device can determine that the received packet has been successfully decrypted. When the received packet is successfully decrypted, the decoded and decrypted payload of the received packet can be provided to another layer of the receiving device, such as the receiving device's decoder-decoder (decoder-decoder), which can output the payload data of the received packet as, for example, audio by the receiving device through the speaker of the headset 112.

[0148] If the generated MIC does not match the decryption MIC of the received packet, the receiving device can determine that the received packet has not been successfully decrypted. When a received packet is not successfully decrypted, it may be that a different packet is missing, or that the received packet may be erroneous or otherwise corrupted. In one configuration, the receiving device may discard received packets that failed MIC verification. Alternatively, in another configuration, the receiving device may attempt to recover the received packets.

[0149] As indicated above, Figure 6 is provided as an example. Other examples may differ from those described with respect to Figure 6.

[0150] Figure 7 is an illustration of example 700 of a remotely accessed vehicle according to the present disclosure.

[0151] Two devices can exchange messages in a ranging session. A ranging session can involve two devices determining the distance between each other and performing actions based on distances that meet thresholds. The two devices can use channel sounding (CS) to accurately determine the distance. CS is more accurate than using signal strength (e.g., RSSI) measurements alone. CS uses additional information such as angle of arrival, angle of departure, phase data, and / or antenna properties.

[0152] CS can be used for various operations. One operation may involve the security of a locking mechanism, such as a door lock on a vehicle. Example 700 illustrates a vehicle 702 that can be locked by an owner 704. The vehicle 702 may have an operating system (OS) that hosts the applications and functionality of the vehicle 702. When the owner 704 closes, leaves, and locks the vehicle 702, the OS may enter a low-power mode. The low-power mode can operate with less power than the power mode when the OS is fully active, and / or may operate below a threshold power level. In some scenarios, the OS of the vehicle 702 may wake up and unlock the vehicle 702 or start the vehicle 702 via a message using short-range wireless technologies, such as BT messages, ultra-wideband (UWB) messages, or Wi-Fi messages. This message may be part of a ranging session between a first device 706 (e.g., UE 120) of the owner 704 and a second device 708 (e.g., UE 120) associated with the OS of the vehicle 702. In some respects, the first device 706 may be a BLE central device (e.g., a smartphone), and the second device 708 may be a BLE peripheral device (such as a lock on vehicle 702). The ranging session may use channel sensing and security keys to attempt to prevent an unauthorized party 710 from unlocking vehicle 702 using a third device 712.

[0153] As indicated above, Figure 7 is provided as an example. Other examples may differ from those described with respect to Figure 7.

[0154] Figure 8 is an illustration of Example 800 of preparing a CS message according to this disclosure.

[0155] The ranging session may include a BT Channel Probe (BCS) session. The BCS may involve distance assessment between two connected devices (e.g., first device 706, second device 708), including measuring the propagation of a scrambled burst sequence. The scrambled sequence can be scrambled using a scrambling sequence component that may include a DRBG. The DRBG may use an IV (re)seeding value exchanged by the two devices via a Bluetooth connection. Regarding the DRBG reseeding value, after IV-based initialization, the ranging session key and random number are rotated at low frequencies (e.g., 1 Hz, 10 Hz). The integrity of the ranging sequence is based on the confidentiality of the IV. The confidentiality of the IV is based on the confidentiality of the peer-to-peer binding long-term key (LTK). The secure storage of the LTK extends beyond the BCS and is delegated to the host. In a managed solution, the LTK is exchanged in plaintext via a serial connection.

[0156] Example 800 illustrates the generation of a scrambled sequence for ranging messages at a first device 706 based on one or more inputs. Using LTK, the first device 706 and the second device 708 can share derived diversification factors via an encrypted link. These derived diversification factors are used to diversify information fragments of the scrambled sequence. The derived diversification factors may include initialization vectors, tags, or random numbers. For example, the first device 706 and the second device 708 may share two halves (each device contributes half of the vector) of three vectors used to seed the ranging session key 810 and the IV (e.g., a random number 812). These three vectors may be: a CS initialization vector (CS_IV) 802 as a random number, an instantiated random number (CS_IN) 804 as a random number, and a personalization vector (CS_PV) 806 (CCS_PV_P || CS_PV_C). Each of CS_PV_P and CS_PV_C may be a 64-bit value. The personalization vector may not be a security parameter. The purpose of the personalization vector may be to introduce additional input into the DRBG instantiation function. Personalized vectors can be generated from cryptographic modules or from other pseudo-random sources.

[0157] As shown by reference numeral 825, the first device 706 can use three vectors as input to generate an instantiation function 808. As shown by reference numeral 830, the first device 706 can generate a key 810 and a random number 812 from the instantiation function 808. The CS process counter 814 and the update function 816 continuously track the seed and reseed values ​​of the key 810 and the random number 812 for different iterations of the ranging session, along with the CS steps and transaction IDs. As shown by reference numeral 835, the first device 706 can use the key 810 and the random number 812 to generate a scrambling sequence 820 (e.g., random bits) using a scrambling sequence generator block (e.g., CS DRBG 818). The first device 706 can send a ranging message encoded or scrambled using the scrambling sequence 820. The second device 708 can receive and decode the ranging message using the scrambling sequence generated at the second device 708 in the same manner as that generated by the first device 706.

[0158] The security of the ranging session relies on an IV exchange protected by the LTK or another key exchanged in-band between the host and controller of the device. As shown in Figure 6, a BT / BLE device can be implemented as a collection of host and controller components, and the host and controller can communicate using the HCI protocol defined by the BT standard (e.g., HCI 640 in Figure 6). The host and controller can be physically implemented in two different chips, and the HCI protocol can be transmitted via a physical interface such as a serial connection. The HCI protocol does not provide confidentiality for information transferred between the host and controller (e.g., there is no encryption between the host and controller). The host can provide long-term storage services for the LTK, which the controller intends to use to reconnect to the paired device. This service can be provided, for example, by application 612 in Figure 6. When a reconnection is established between two different BT / BLE devices, the controller on the device can request its host to provide the LTK for the given paired device, and the host can retrieve it from memory and forward it to the controller via HCI. Therefore, if both are implemented in separate chips, the LTK can be sent in plaintext between the two chips via a serial connection. In other words, messages exchanged within the band during a ranging session can use the same radio technology and key materials available during the ranging session. If an unauthorized party obtains the key materials within the band during the ranging session, the ranging session messages may be compromised. Compromised messages may result in wasted resources.

[0159] As indicated above, Figure 8 is provided as an example. Other examples may differ from those described with respect to Figure 8.

[0160] Figure 9 is an illustration of example 900 using an OOB key according to this disclosure.

[0161] Based on the various aspects described herein, two devices can acquire an OOB key that is shared OOB-wise relative to the target protocol within the band (such as a ranging session, e.g., a BCS session). The two devices can use the OOB key individually or combine it with other information shared within the band to derive the input to a scrambling sequence. The scrambling sequence protects messages sent during iterations of the ranging session. By using the OOB key obtained relative to the in-band ranging session OOB, the two devices can provide greater security for ranging messages sent during the ranging session. If an unauthorized party obtains some key material exchanged over the air within the band during the ranging session, the unauthorized party will be unable to successfully decode the ranging message because it will not have the OOB key shared OOB-wise prior to the ranging session. This enhanced security saves device resources that would otherwise be wasted or consumed due to security vulnerabilities.

[0162] There are various ways in which OOB keys can be shared OOB. In some aspects, OOB keys for lower BT layers can be delivered to each device using a higher BT application layer over an end-to-end encrypted channel between the two devices. The higher layer may not rely on the same key material used to protect the lower layer. In some aspects, the key process and / or material used to obtain the OOB key may differ from the key process and / or material used to protect or bind the two devices (e.g., LTK). The key process and / or material used to obtain the OOB key can protect information exchanged before the ranging session begins. In some aspects, the OOB key can be obtained using a completely different RAT (e.g., the BT protocol of the WiFi protocol). The key material for the OOB key may be supported by a dedicated GATT discovery service. The discovery service may involve different RATs (e.g., WLAN).

[0163] In some aspects, the first device (e.g., first device 706) can use an OOB key to generate a new derivation diversification factor, which is another input to the key and random number used to derive the scrambled sequence. Example 900 shows that after establishing a ranging session, the first device 706 can use an OOB key 902 as another input to generate an OOB input, such as OOB IV 904 as indicated by reference numeral 905. OOB IV 904 can be a function of the OOB key 902 and other derivation diversification factors (e.g., a set of three vectors). As indicated by reference numeral 910, the first device 706 can use a set of three vectors as input to generate an instantiation function 912. As indicated by reference numeral 915, the first device 706 can generate a key 914 and a random number 916 based on the instantiation function 912. As indicated by reference numeral 920, the first device 706 can use the key 914 and the random number 916 to generate a scrambled sequence 922 using CS DRBG 818. The first device 706 can send a ranging message encoded using a scrambling sequence 922. The second device 708 can receive and decode the ranging message using a scrambling sequence generated in the same manner as that generated by the first device 706.

[0164] In some aspects, the first device 706 may receive an OOB key 902 from a network entity (e.g., an edge service) in an OOB manner, which proves the state of the first device 706 (e.g., fault detection disabled, secure boot enabled, firmware version), or authenticate a specific instance of the first device 706 using a hardware root of trust of the first device 706 (e.g., an isolated hardware subsystem of the device, which may be a processor-implemented device, and one of its main functionalities is to provide key management services). In some aspects, the first device 706 may use a secure dispatch channel (e.g., encrypted and mutually authenticated) to receive the key. The secure channel may be terminated by the root of trust of the first device 706.

[0165] In some respects, a secure element can be used to authenticate or verify the first device 706. The secure element can be a secure portion of the first device 706 similar to the root of trust, but at a higher level of security assurance. The root of trust and / or secure element can be associated with key management. That is, a set of derived diversification factors can be transmitted in-band, and their confidentiality during transmission can optionally rely on the LTK used for authentication and / or protection of the confidentiality of information exchanged between the two devices. The derived diversification factors can be used to derive new keys from the root key managed by the HW root of trust or the secure element (SE). The root key can be device-specific, can be part of the root of trust or SE HW, can be provided in the HW root of trust or SE during device manufacturing, or can be securely provided in the field using an end-to-end encrypted communication channel between the network entity and the HW root of trust or SE.

[0166] In some aspects, the network entity may also use the root of trust of the second device 708, the secure element of the second device 708, and / or the secure dispatch channel to authenticate the second device 708. In some aspects, the first device 706 and / or the second device 708 may receive the OOB key 902 from another device having a connection to the network entity via an opaque relay.

[0167] In some respects, the first device 706 and the second device 708 may securely store the OOB key 902. Each device may store the OOB key 902 in a secure memory managed by a root of trust or a secure element.

[0168] As indicated above, Figure 9 is provided as an example. Other examples may differ from those described with respect to Figure 9.

[0169] Figure 10 is a diagram illustrating example 1000 of sharing an OOB key prior to a ranging session according to this disclosure. A first device 1020 (e.g., UE 120, first device 706) associated with the owner of the vehicle may communicate with a second device 1030 (e.g., UE 120, second device 708) at the vehicle. The first device 1020 and / or the second device 1030 may communicate with a network entity 1010 (e.g., network node 110).

[0170] As shown by reference numeral 1032 in the attached figure, the first device 1020 and the second device 1030 can pair, derive the LTK, and establish an encrypted BLE connection. As shown by reference numeral 1034 in the attached figure, the first device 1020 can discover support for the BCS extension, enabling the first device 1020 and the second device 1030 to perform BCS during the ranging session with added OOB key protection.

[0171] As shown by reference numeral 1036, the first device 1020 may request network entity 1010 to authenticate the second device 1030. As shown by reference numeral 1038, network entity 1010 may authenticate the first device 1020. This may be a preparatory step before requesting authentication of the second device 1030. As shown by reference numeral 1040, network entity 1010 may authenticate the second device 1030 by a request and response sent directly to the second device 1030 or opaquely relayed by the first device 1020.

[0172] As shown by reference numeral 1042, the first device 1020 can request an OOB key. As shown by reference numeral 1044, the network entity 1010 can select an OOB key. As shown by reference numeral 1046, the network entity 1010 can send the OOB key. As shown by reference numeral 1048, the first device 1020 can securely store the OOB key. As shown by reference numeral 1050, the first device 1020 can send (or opaquely relay) the OOB key to the second device 1030. Alternatively, as shown by reference numeral 1055, the network entity 1010 can send the OOB key of the second device 1030. As shown by reference numeral 1060, the first device 1020 can forward the OOB key to the second device 1030. As shown by reference numeral 1065, the second device 1030 can securely store the OOB key.

[0173] In some respects, network entity 1010 may send the OOB key to the second device 1030. In other respects, network entity 1010 may send the OOB key to the second device 1030 via the first device 1020 or another connected device. The connected device may use secure key approximation packets to receive and forward the OOB key (e.g., the connected device cannot access the information within the packet).

[0174] In some aspects, no device connects to network entity 1010 and obtains the OOB key from the network entity. In this scenario, the first device 1020 may choose and / or generate the OOB key and provide it to the second device 1030. The first device 1020 may use a peer-to-peer (P2P) secure communication channel that is OOB compared to the ranging session. The P2P secure communication channel may be terminated at each device by an HW root of trust or a secure element.

[0175] In some scenarios, devices can connect to network entity 1010 to initiate OOB key exchange. A first device 1020 may choose to generate an OOB key. In other scenarios, a second device 1030 may choose to generate an OOB key. Both devices can also be considered as a source device providing the OOB key and a destination device receiving the OOB key. The source device may send key materials (secure communication channel key materials) necessary to establish a secure communication channel between the two devices to network entity 1010. For example, a temporary public key can be used in a Diffie-Hellman session establishment protocol with other devices.

[0176] Network entity 1010 may establish the conditions for OOB key exchange. For example, to exchange OOB keys, network entity 1010 may prove the status of the two devices. However, network entity 1010 may not select an OOB key. Network entity 1010 may authorize OOB key exchange (i.e., exchange between the two devices is not permitted unless approved by network entity 1010). Network entity 1010 may charge for the occurrence of this event. Network entity 1010 may sign secure communication channel key material from the source device and / or the source device's certified statement. Network entity 1010 may forward the optional authorized secure communication channel key material to the destination device. The destination device may verify the optional authorization to continue and use the secure communication channel key material from the source device to advance the establishment of the P2P secure communication channel. For example, the source device may choose other key sets required to complete the Diffie-Helman exchange.

[0177] In some respects, the source and destination devices can begin exchanging packets opaquely relayed by network entity 1010, thereby establishing a secure communication channel between the two devices. Through this now established P2P secure communication channel (opaquely relayed by the network entity), the source device can forward the OOB key to the destination device.

[0178] As indicated above, Figure 10 is provided as an example. Other examples may differ from those described with respect to Figure 10.

[0179] Figure 11 is a diagram illustrating an example 1100 of a ranging session according to this disclosure. The ranging session can be considered in-band and can be one of multiple ranging sessions that may occur after the OOB key is shared. The OOB key may only need to be shared once.

[0180] As shown by reference numeral 1102, the first device 1020 and the second device 1030 can exchange inputs in-band during a ranging session. The input may include a BCS IV (e.g., a set of three vectors described in conjunction with Figures 8 and 9). As shown by reference numeral 1104, the first device 1020 can compute the OOB IV from the set of three vectors and the OOB key. As shown by reference numeral 1106, the first device 1020 can compute a first key and a first random number. This computation may include generating an instantiation function from the set of three vectors and the OOB IV, and then generating the first key and the first random number from the instantiation function using a CS process counter and / or an update function. As shown by reference numeral 1108, the first device 1020 can use a CS DRBG to generate a first scrambling sequence using the first key and the first random number as input.

[0181] The second device 1030 can perform the same or similar actions to generate the same first scrambling sequence for decoding the ranging message encoded using the first scrambling sequence. As shown by reference numeral 1110, the second device can use the OOB key and a set of three vectors to compute the OOB IV. As shown by reference numeral 1112, the second device 1030 can use the OOB IV and a set of three vectors to compute the first key and a first random number. As shown by reference numeral 1114, the second device 1030 can use the first key and the first random number to generate the first scrambling sequence.

[0182] As shown by reference numeral 1116 in the accompanying drawings, the first device 1020 and the second device 1030 can perform a first BCS ranging iteration. This may include the first device 1020 encoding or scrambling the ranging message using a first scrambling sequence and sending the ranging message to the second device 1030. The second device 1030 can receive the ranging message and use the first scrambling sequence to decode or descramble the ranging message. The second device 1030 can use BCS to determine the distance between the first device 1020 and the second device 1030. The second device 1030 can send a response message as part of the first BCS ranging iteration.

[0183] The first device 1020 can update its CS process and prepare to replant the input into the first scrambling sequence for use in the second BCS ranging iteration. As shown by reference numeral 1118, the first device 1020 can use a set of three vectors and the OOB IV to replant and compute the second key and the second random number. As shown by reference numeral 1120, the first device 1020 can use the second key and the second random number to generate the second scrambling sequence. The second device 1030 can do the same. As shown by reference numeral 1122, the second device 1030 can replant and compute the second key and the second random number. As shown by reference numeral 1124, the second device 1030 can generate the second scrambling sequence.

[0184] As shown by reference numeral 1126 in the attached figure, the first device 1020 and the second device 1030 may use a second scrambling sequence for the ranging message in the second BCS ranging iteration. When the owner approaches the vehicle, the first device 1020 may be approaching the second device 1030. The second device 1030 may determine a new distance shorter than a previously determined distance. If the new distance meets a distance threshold, the second device 1030 may cause the OS to unlock the vehicle for the owner. If the distance to the first device 1020 is not short enough, the first device 1020 and the second device 1030 may continue with additional BCS ranging iterations as needed to perform secure unlocking of the vehicle.

[0185] By using the OOB key, BCS ranging iterations can utilize scrambled sequences that are made more secure by the OOB key. With more secure BCS ranging iterations, ranging messages cannot be spoofed, and the owner cannot suffer property loss or damage due to unauthorized entry and / or theft of the vehicle. While Examples 700, 800, 900, 1000, and 1100 involve using secure BCS ranging for unlocking vehicles, the OOB key can be used for ranging discovery and other in-band operations relative to the OOB key.

[0186] As indicated above, Figure 11 is provided as an example. Other examples may differ from those described with respect to Figure 11.

[0187] Figure 12 is a diagram illustrating an example process 1200 performed, for example, at a first device or a device of the first device, according to the present disclosure. Example process 1200 is an example in which a device or the first device (e.g., UE 120, first device 1020) performs operations associated with obtaining and using an OOB key for ranging.

[0188] As shown in Figure 12, in some aspects, process 1200 may include obtaining an OOB key that is shared OOB with respect to an in-band ranging session defined between the first and second devices (box 1210). For example, the first device (e.g., using the receiving component 1502 and / or communication manager 1506 depicted in Figure 15) may obtain an OOB key that is shared OOB with respect to an in-band ranging session defined between the first and second devices, as described above.

[0189] As further shown in Figure 12, in some aspects, process 1200 may include generating one or more first inputs (block 1220) to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in the band. For example, a first device (e.g., using the communication manager 1506 depicted in Figure 15) may generate one or more first inputs to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in the band, as described above.

[0190] As further shown in Figure 12, in some aspects, process 1200 may include sending a first message to a second device (block 1230) using a first scrambling sequence during a ranging session. For example, the first device (e.g., using the transmitting component 1504 and / or communication manager 1506 depicted in Figure 15) may send the first message to the second device using the first scrambling sequence during a ranging session, as described above.

[0191] Process 1200 may include additional aspects, such as any single aspect or any combination of aspects described below and / or in conjunction with one or more other processes described elsewhere in this document.

[0192] In the first aspect, obtaining the OOB key includes receiving the OOB key from a network entity or peer device (e.g., another UE or wireless communication device without the assistance of a network entity).

[0193] In a second aspect, either alone or in combination with the first aspect, process 1200 includes sending the OOB key OOB to the second device.

[0194] In the third aspect, either alone or in combination with one or more aspects of the first and second aspects, obtaining the OOB key includes receiving the OOB key from the network entity OOB using a communication technology different from the communication technology used in the band during the ranging session.

[0195] In the fourth aspect, obtaining the OOB key, either alone or in combination with one or more aspects of the first to third aspects, includes receiving the OOB key from a network entity over a secure dispatch channel.

[0196] In the fifth aspect, either alone or in combination with one or more aspects of the first to fourth aspects, the secure allocation channel is terminated by a root of trust associated with key management of the first device, or by a secure element of the first device with a high level of security assurance.

[0197] In the sixth aspect, either alone or in combination with one or more aspects from the first to the fifth aspects, process 1200 includes securely storing the OOB key at a first device before initiating the ranging session.

[0198] In the seventh aspect, securely storing the OOB key, either alone or in combination with one or more aspects of the first to sixth aspects, includes storing the OOB key at the root of trust of the first device or in the secure element of the first device.

[0199] In the eighth aspect, either alone or in combination with one or more aspects from the first to the seventh aspects, the ranging session is associated with a short-range wireless protocol, and the first device is a central device and the second device is a peripheral device.

[0200] In the ninth aspect, either alone or in combination with one or more aspects of the first to eighth aspects, the ranging session is associated with a short-range radio protocol, and the first device is a UE and the second device is associated with a locking mechanism.

[0201] In the tenth aspect, either alone or in combination with one or more aspects from the first to the ninth aspects, the information used in the band includes a set of derivation diversification factors, and generating one or more first inputs includes using the OOB key and the set of derivation diversification factors to generate one or more first inputs.

[0202] In the eleventh aspect, alone or in combination with one or more aspects from the first to the tenth aspects, the set of derived diversification factors are associated with the long-term key and include an initialization vector, an initialization random number, and a personalization vector.

[0203] In the twelfth aspect, generating one or more first inputs, either alone or in combination with one or more aspects from the first to the eleventh aspects, includes generating an OOB IV.

[0204] In the thirteenth aspect, either alone or in combination with one or more aspects from the first to the twelfth aspects, one or more first inputs to the first scrambling sequence include generating a first key and a first random number using the OOB IV and the set of derived diversification factors for a first ranging iteration of the ranging session with the second device.

[0205] In the fourteenth aspect, alone or in combination with one or more aspects of the first to thirteenth aspects, process 1200 includes generating a second key and a second random number for the second ranging iteration as a second input to the second scrambling sequence, and using the second scrambling sequence to send a second message to a second device as part of the second ranging iteration.

[0206] Although Figure 12 shows example blocks of process 1200, in some respects process 1200 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently compared to those depicted in Figure 12. Additionally or alternatively, two or more blocks in the process 1200 may be executed in parallel.

[0207] Figure 13 is a diagram illustrating an example process 1300 performed, for example, at a second device or a device of a second device, according to the present disclosure. Example process 1300 is an example in which a device or a second device (e.g., UE 120, second device 1030) performs operations associated with obtaining and using an OOB key for ranging.

[0208] As shown in Figure 13, in some aspects, process 1300 may include receiving an OOB key from a first device or network entity, the OOB key being shared OOB-wise relative to an in-band ranging session defined between the first and second devices (box 1310). For example, the second device (e.g., using the receiving component 1502 and / or communication manager 1506 depicted in Figure 15) may receive the OOB key from the first device or network entity, the OOB key being shared OOB-wise relative to an in-band ranging session defined between the first and second devices, as described above.

[0209] As further shown in Figure 13, in some aspects, process 1300 may include one or more inputs (box 1320) used in-band to generate a first scrambling sequence used in the ranging session, either using the OOB key itself or in combination with information used in-band. For example, a second device (e.g., using the communication manager 1506 depicted in Figure 15) may use the OOB key itself or in combination with information used in-band to generate one or more inputs in-band to the first scrambling sequence used in the ranging session, as described above.

[0210] As further shown in FIG13, in some aspects, process 1300 may include receiving a first message using a first scrambling sequence from a first device (block 1330). For example, a second device (e.g., using the receiving component 1502 and / or communication manager 1506 depicted in FIG15) may receive the first message using the first scrambling sequence from the first device, as described above.

[0211] Process 1300 may include additional aspects, such as any single aspect or any combination of aspects described below and / or in conjunction with one or more other processes described elsewhere in this document.

[0212] In the first aspect, process 1300 includes using a first scrambling sequence to decode the first message.

[0213] In a second aspect, either alone or in combination with the first aspect, process 1300 securely stores the OOB key at a second device before the ranging session begins.

[0214] Although Figure 13 shows example blocks of process 1300, in some respects process 1300 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently compared to those depicted in Figure 13. Additionally or alternatively, two or more blocks of process 1300 may be executed in parallel.

[0215] Figure 14 is a diagram illustrating an example process 1400 performed, for example, at a network entity or a device of a network entity according to the present disclosure. Example process 1400 is an example in which a device or network entity (e.g., network node 110, network entity 1010) performs operations associated with a shared OOB key for ranging.

[0216] As shown in Figure 14, in some aspects, process 1400 may receive a request from the first device for an OOB key associated with the ranging session at the first device (box 1410). For example, a network entity (e.g., using the receiving component 1602 and / or communication manager 1606 depicted in Figure 16) may receive a request from the first device for an OOB key associated with the ranging session at the first device, as described above.

[0217] As further shown in Figure 14, in some aspects, process 1400 may include sending the OOB key OOB-wise to the first device when the first device successfully authenticates to the network entity (box 1420). For example, the network entity (e.g., using the sending component 1604 and / or communication manager 1606 depicted in Figure 16) may send the OOB key OOB-wise to the first device when the first device successfully authenticates to the network entity, as described above.

[0218] As further shown in Figure 14, in some aspects, process 1400 may include sending the OOB key OOB-wise to the second device upon successful authentication to the network entity (box 1430). For example, the network entity (e.g., using the sending component 1604 and / or communication manager 1606 depicted in Figure 16) may send the OOB key OOB-wise to the second device upon successful authentication to the network entity, as described above.

[0219] Process 1400 may include additional aspects, such as any single aspect or any combination of aspects described below and / or in conjunction with one or more other processes described elsewhere in this document.

[0220] In the first aspect, the successful authentication of the first device, the successful authentication of the second device, and / or the transmission of the OOB key are associated with the root of trust of the network entity.

[0221] In the second aspect, either alone or in combination with the first aspect, sending the OOB key includes sending the OOB key over a secure allocation channel.

[0222] Although Figure 14 shows example blocks of process 1400, in some respects process 1400 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently compared to those depicted in Figure 14. Additionally or alternatively, two or more blocks in the blocks of process 1400 may be executed in parallel.

[0223] Figure 15 is a diagram of an example device 1500 for wireless communication according to the present disclosure. Device 1500 may be a first device or a second device, or a first device or a second device may include device 1500. In some aspects, device 1500 includes a receiving component 1502, a transmitting component 1504, and / or a communication manager 1506 that can communicate with each other (e.g., via one or more buses and / or one or more other components). In some aspects, communication manager 1506 is a communication manager 140 described in conjunction with Figure 1 or a WPAN controller 552 described in conjunction with Figure 5. As shown, device 1500 can use the receiving component 1502 and the transmitting component 1504 to communicate with another device 1508 (such as a UE or a network node (such as a CU, DU, RU, or base station)).

[0224] In some aspects, apparatus 1500 may be configured to perform one or more operations described herein in conjunction with Figures 1 through 11. Additionally or alternatively, apparatus 1500 may be configured to perform one or more processes described herein, such as process 1200 of Figure 12, process 1300 of Figure 13, or combinations thereof. In some aspects, apparatus 1500 and / or one or more components shown in Figure 15 may include one or more components of the first device described in conjunction with Figures 2 or 5. Additionally or alternatively, one or more components shown in Figure 15 may be implemented within one or more components described in conjunction with Figures 2 or 5. Additionally or alternatively, one or more components in the set of components may be at least partially implemented as software stored in one or more memories. For example, a component (or a portion of a component) may be implemented as instructions or code stored in a non-transitory computer-readable medium and executable by one or more controllers or one or more processors to perform the function or operation of that component.

[0225] Receiver 1502 may receive communications from device 1508, such as reference signals, control information, data communications, or combinations thereof. Receiver 1502 may provide the received communications to one or more other components of device 1500. In some aspects, receiver 1502 may perform signal processing (such as filtering, amplification, demodulation, analog-to-digital conversion, demultiplexing, deinterleaving, demapping, equalization, interference cancellation, or decoding) on ​​the received communications and may provide the processed signals to one or more other components of device 1500. In some aspects, receiver 1502 may include one or more antennas, one or more modems, one or more demodulators, one or more MIMO detectors, one or more receiver processors, one or more controllers / processors, one or more memories, or combinations thereof, in conjunction with the first device described in connection with FIG. 2 or FIG. 5.

[0226] Transmitting component 1504 may transmit communications, such as reference signals, control information, data communications, or combinations thereof, to device 1508. In some aspects, one or more other components of device 1500 may generate communications and provide the generated communications to transmitting component 1504 for transmission to device 1508. In some aspects, transmitting component 1504 may perform signal processing (such as filtering, amplification, modulation, digital-to-analog conversion, multiplexing, interleaving, mapping, or encoding, etc.) on the generated communications and may transmit the processed signals to device 1508. In some aspects, transmitting component 1504 may include one or more antennas, one or more modems, one or more modulators, one or more transmit MIMO processors, one or more transmit processors, one or more controllers / processors, one or more memories, or combinations thereof, in conjunction with the first device described in connection with FIG. 2 or FIG. 5. In some aspects, transmitting component 1504 may co-located with receiving component 1502 in one or more transceivers.

[0227] The communication manager 1506 may support the operation of the receiving component 1502 and / or the transmitting component 1504. For example, the communication manager 1506 may receive information associated with configuring the reception of communications by the receiving component 1502 and / or the transmission of communications by the transmitting component 1504. Additionally or alternatively, the communication manager 1506 may generate control information and / or provide control information to the receiving component 1502 and / or the transmitting component 1504 to control the reception and / or transmission of communications.

[0228] In some aspects associated with the first device, the receiving component 1502 may obtain an OOB key, which is shared OOB-wise relative to the ranging session defined in-band between the first and second devices. The communication manager 1506 may generate one or more first inputs to the first scrambling sequence used in the ranging session, either using the OOB key itself or in combination with information used in-band. The transmitting component 1504 may transmit a first message to the second device using the first scrambling sequence during the ranging session.

[0229] The transmitting component 1504 can transmit the OOB key to the second device in an OOB manner. The communication manager 1506 can securely store the OOB key at the first device before starting the ranging session. The communication manager 1506 can generate a second key and a second random number for the second ranging iteration as a second input to the second scrambling sequence. The transmitting component 1504 can use the second scrambling sequence to send a second message to the second device as part of the second ranging iteration.

[0230] In some aspects associated with the second device, the receiving component 1502 may receive an OOB key from the first device or network entity, which is shared OOB-wise relative to the in-band ranging session defined between the first and second devices. The communication manager 1506 may use the OOB key itself, or in combination with information used in-band, to generate one or more inputs to a first scrambling sequence used in the ranging session in-band. The receiving component 1502 may receive a first message using the first scrambling sequence from the first device.

[0231] The communication manager 1506 can use the first scrambling sequence to decode the first message. The communication manager 1506 can securely store the OOB key at a second device before starting the ranging session.

[0232] The number and arrangement of components shown in Figure 15 are provided as examples. In practice, there may be additional components, fewer components, different components, or components arranged differently compared to those shown in Figure 15. Furthermore, the two or more components shown in Figure 15 may be implemented within a single component, or the single component shown in Figure 15 may be implemented as multiple distributed components. Additionally or alternatively, the set of components(one or more) shown in Figure 15 may perform one or more functions described as being performed by another set of components shown in Figure 15.

[0233] Figure 16 is a diagram of an example device 1600 for wireless communication according to the present disclosure. Device 1600 may be a network entity, or a network entity may include device 1600. In some aspects, device 1600 includes a receiving component 1602, a transmitting component 1604, and / or a communication manager 1606 that can communicate with each other (e.g., via one or more buses and / or one or more other components). In some aspects, communication manager 1606 is communication manager 150 as described in conjunction with Figure 1. As shown, device 1600 can use the receiving component 1602 and the transmitting component 1604 to communicate with another device 1608 (such as a UE or a network node (such as a CU, DU, RU, or base station)).

[0234] In some aspects, apparatus 1600 may be configured to perform one or more operations described herein in conjunction with Figures 1 through 11. Additionally or alternatively, apparatus 1600 may be configured to perform one or more processes described herein, such as process 1400 of Figure 14. In some aspects, apparatus 1600 and / or one or more components shown in Figure 16 may include one or more components of the network entity described in conjunction with Figure 2. Additionally or alternatively, one or more components shown in Figure 16 may be implemented within one or more components described in conjunction with Figure 2. Additionally or alternatively, one or more components in the set of components may be at least partially implemented as software stored in one or more memories. For example, a component (or a portion of a component) may be implemented as instructions or code stored in a non-transitory computer-readable medium and executable by one or more controllers or one or more processors to perform the function or operation of that component.

[0235] Receiver 1602 may receive communications from device 1608, such as reference signals, control information, data communications, or combinations thereof. Receiver 1602 may provide the received communications to one or more other components of device 1600. In some aspects, receiver 1602 may perform signal processing on the received communications (such as filtering, amplification, demodulation, analog-to-digital conversion, demultiplexing, deinterleaving, demapping, equalization, interference cancellation, or decoding), and may provide the processed signals to one or more other components of device 1600. In some aspects, receiver 1602 may include one or more antennas, one or more modems, one or more demodulators, one or more MIMO detectors, one or more receiver processors, one or more controllers / processors, one or more memories, or combinations thereof, in conjunction with the network entities described in FIG. 2.

[0236] Transmitting component 1604 may transmit communications, such as reference signals, control information, data communications, or combinations thereof, to device 1608. In some aspects, one or more other components of device 1600 may generate communications and provide the generated communications to transmitting component 1604 for transmission to device 1608. In some aspects, transmitting component 1604 may perform signal processing (such as filtering, amplification, modulation, digital-to-analog conversion, multiplexing, interleaving, mapping, or encoding, etc.) on the generated communications and may transmit the processed signals to device 1608. In some aspects, transmitting component 1604 may include one or more antennas, one or more modems, one or more modulators, one or more transmit MIMO processors, one or more transmit processors, one or more controllers / processors, one or more memories, or combinations thereof, in conjunction with the network entities described in FIG. 2. In some aspects, transmitting component 1604 may co-located with receiving component 1602 in one or more transceivers.

[0237] The communication manager 1606 may support the operation of the receiving component 1602 and / or the transmitting component 1604. For example, the communication manager 1606 may receive information associated with configuring the reception of communications by the receiving component 1602 and / or the transmission of communications by the transmitting component 1604. Additionally or alternatively, the communication manager 1606 may generate control information and / or provide control information to the receiving component 1602 and / or the transmitting component 1604 to control the reception and / or transmission of communications.

[0238] The receiving component 1602 can receive from the first device a request for an OOB key associated with the ranging session at the first device. The sending component 1604 can send the OOB key to the first device in an OOB manner upon the first device successfully authenticating to the network entity.

[0239] The number and arrangement of components shown in Figure 16 are provided as examples. In practice, there may be additional components, fewer components, different components, or components arranged differently compared to those shown in Figure 16. Furthermore, the two or more components shown in Figure 16 may be implemented within a single component, or the single component shown in Figure 16 may be implemented as multiple distributed components. Additionally or alternatively, the set of one or more components shown in Figure 16 may perform one or more functions described as being performed by another set of components shown in Figure 16.

[0240] The following provides an overview of some aspects of this disclosure: Aspect 1: A method for wireless communication performed by a first device, the method comprising: obtaining an out-of-band (OOB) key, the OOB key being shared OOBly with respect to a ranging session defined in-band between the first device and a second device; generating one or more first inputs to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band; and transmitting a first message to the second device using the first scrambling sequence during the ranging session.

[0241] Aspect 2: According to the method of aspect 1, obtaining the OOB key includes receiving the OOB key from a network entity or peer device.

[0242] Aspect 3: The method according to any one of aspects 1 to 2, the method further includes sending the OOB key OOB to the second device.

[0243] Aspect 4: The method according to any one of Aspects 1 to 3, wherein obtaining the OOB key includes receiving the OOB key from the network entity OOB using a communication technology different from the communication technology used in the band during the ranging session.

[0244] Aspect 5: The method according to any one of Aspects 1 to 4, wherein obtaining the OOB key includes receiving the OOB key from a network entity on a secure dispatch channel.

[0245] Aspect 6: According to the method of aspect 5, the secure allocation channel is terminated by a root of trust associated with key management of the first device, or by a secure element of the first device having a high level of security assurance.

[0246] Aspect 7: The method according to any one of aspects 1 to 6, the method further comprising securely storing the OOB key at the first device before starting the ranging session.

[0247] Aspect 8: According to the method of aspect 7, securely storing the OOB key includes storing the OOB key at the root of trust of the first device or in the secure element of the first device.

[0248] Aspect 9: The method according to any one of Aspects 1 to 8, wherein the ranging session is associated with a short-range wireless protocol, and wherein the first device is a central device and the second device is a peripheral device.

[0249] Aspect 10: The method according to any one of Aspects 1 to 9, wherein the ranging session is associated with a short-range radio protocol, and wherein the first device is a user equipment (UE) and the second device is associated with a locking mechanism.

[0250] Aspect 11: The method according to any one of Aspects 1 to 10, wherein the information used in the band includes a set of derivation diversification factors, and wherein generating the one or more first inputs includes generating the one or more first inputs using the OOB key and the set of derivation diversification factors.

[0251] Aspect 12: According to the method of aspect 11, wherein the set of derived diversification factors is associated with a long-term key and includes an initialization vector, an initialization random number, and a personalization vector.

[0252] Aspect 13: According to the method of aspect 11, generating the one or more first inputs includes generating an OOB initialization vector (IV).

[0253] Aspect 14: According to the method of aspect 13, wherein the one or more first inputs generated to the first scrambling sequence include generating a first key and a first random number using the OOB IV and the set of derived diversification factors for a first ranging iteration of the ranging session with the second device.

[0254] Aspect 15: The method according to aspect 14, the method further comprising: generating a second key and a second random number for a second ranging iteration as a second input to a second scrambling sequence; and sending a second message to the second device using the second scrambling sequence as part of the second ranging iteration.

[0255] Aspect 16: A method of wireless communication performed by a second device, the method comprising: receiving an out-of-band (OOB) key from a first device or network entity, the OOB key being shared OOBly with respect to a ranging session defined in-band between the first device and the second device; generating one or more inputs in-band to a first scrambling sequence used in the ranging session using the OOB key itself or in combination with information used in-band; and receiving a first message from the first device using the first scrambling sequence.

[0256] Aspect 17: The method according to aspect 16 further includes using the first scrambling sequence to decode the first message.

[0257] Aspect 18: The method according to any one of Aspects 16 to 17, the method further comprising securely storing the OOB key at the second device before initiating the ranging session.

[0258] Aspect 19: A method of wireless communication performed by a network entity, the method comprising: receiving from a first device a request for an out-of-band (OOB) key associated with a ranging session at the first device; and sending the OOB key OOB to the first device upon successful authentication by the first device to the network entity.

[0259] Aspect 20: According to the method of aspect 19, wherein the success proof of the first device and the transmission of the OOB key are associated with the root of trust of the network entity.

[0260] Aspect 21: The method according to any one of Aspects 19 to 20, wherein sending the OOB key includes sending the OOB key over a secure dispatch channel.

[0261] Aspect 22: An apparatus for wireless communication at a device, the apparatus comprising: one or more processors; one or more memories coupled to the one or more processors; and instructions stored in the one or more memories and executable by the one or more processors to cause the apparatus to perform the method according to one or more aspects of aspects 1 to 21.

[0262] Aspect 23: An apparatus for wireless communication at a device, the apparatus comprising: one or more memories; and one or more processors coupled to the one or more memories, the one or more processors being configured to cause the device to perform the method according to one or more of aspects 1 to 21.

[0263] Aspect 24: An apparatus for wireless communication, the apparatus comprising at least one component for performing the method according to one or more of aspects 1 to 21.

[0264] Aspect 25: A non-transitory computer-readable medium storing code for wireless communication, the code including instructions executable by one or more processors to perform the method according to one or more aspects 1 to 21.

[0265] Aspect 26: A non-transitory computer-readable medium storing a set of instructions for wireless communication, the set of instructions comprising one or more instructions which, when executed by one or more processors of a device, cause the device to perform the method according to one or more aspects of aspects 1 to 21.

[0266] Aspect 27: A device for wireless communication, the device including a processing system comprising: one or more processors; and one or more memories coupled to the one or more processors, the processing system being configured to cause the device to perform the method according to one or more aspects 1 to 21.

[0267] Aspect 28: An apparatus for wireless communication at a device, the apparatus comprising: one or more memories; and one or more processors coupled to the one or more memories, the one or more processors being individually or collectively configured to cause the device to perform the method according to one or more aspects of aspects 1 to 21.

[0268] While the foregoing disclosure provides examples and descriptions, it is not intended to be exhaustive or to limit the aspects to the precise form disclosed. Modifications and variations may be made based on the foregoing disclosure, or from various forms of practice.

[0269] As used herein, the term "component" is intended to be broadly interpreted as hardware or a combination of hardware and at least one of software or firmware. "Software" should be broadly interpreted as instructions, instruction sets, code, code segments, program code, programs, subroutines, software modules, applications, software applications, software packages, routines, subroutines, objects, executable programs, threads of execution, procedures, or functions, whether referred to as software, firmware, middleware, microcode, hardware description languages, or other terms. As used herein, a "processor" is implemented in hardware or a combination of hardware and software. It will be apparent that the systems or methods described herein may be implemented in various forms of hardware or combinations of hardware and software. The actual dedicated control hardware or software code used to implement these systems or methods is not limited in any way. Therefore, the operation and behavior of these systems or methods are described herein without reference to specific software code, as those skilled in the art will understand that the software and hardware can be designed to implement these systems or methods, at least in part, based on the description herein. Unless otherwise stated, a component configured to perform a function means that the component has the capability to perform that function, but it is not necessary for the component to actually perform that function.

[0270] As used in this article, depending on the context, "meeting the threshold" can mean a value greater than the threshold, greater than or equal to the threshold, less than the threshold, less than or equal to the threshold, equal to the threshold, not equal to the threshold, etc.

[0271] As used in this article, the phrase “at least one of the items” in a list of items refers to any combination of these items, including a single member. As an example, “at least one of a, b, or c” is intended to cover: a, b, c, a+b, a+c, b+c, and a+b+c, as well as any combination with multiple identical elements (e.g., a+a, a+a+a, a+a+b, a+a+c, a+b+b, a+c+c, b+b, b+b+b, b+b+c, c+c, and c+c+c, or any other ordering of a, b, and c).

[0272] No element, action, or instruction used herein should be construed as essential or necessary unless explicitly stated otherwise. Furthermore, as used herein, the articles “a” and “an” are intended to include one or more items and are used interchangeably with “one or more.” Similarly, as used herein, the article “described” is intended to include one or more items mentioned in connection with the article “described” and is used interchangeably with “one or more.” Furthermore, as used herein, the terms “set” and “group” are intended to include one or more items and are used interchangeably with “one or more.” If only one item is desired, the phrase “only one” or similar terminology will be used. Moreover, as used herein, the terms “having” and similar terms are intended as open-ended terms that do not limit the elements they modify (e.g., “having” A may also have B). Additionally, the phrase “based on” is intended to mean “based on or otherwise related to” unless otherwise explicitly stated. Furthermore, as used herein, the term “or” is intended to be inclusive when used consecutively and is interchangeable with “and / or” unless otherwise explicitly stated (e.g., if used in conjunction with “either of the two” or “only one of them”). It should be understood that “one or more” is equivalent to “at least one”.

[0273] Although specific combinations of features are set forth in the claims or disclosed in the description, these combinations are not intended to limit the disclosure of various aspects. Many of these features may be combined in ways not specifically stated in the claims or disclosed in the description. The disclosure of various aspects includes each dependent claim in combination with each other claim in the claim set.

Claims

1. An apparatus for wireless communication at a first device, the apparatus comprising: One or more memory units; and One or more processors, said one or more processors coupled to said one or more memories, said one or more processors individually or collectively configured to cause the first device to: Obtain an out-of-band (OOB) key, which is shared OOB relative to the ranging session defined in-band between the first device and the second device; During the ranging session, one or more first inputs to the first scrambling sequence used in the ranging session are generated using the OOB key itself or in combination with information used in-band. as well as During the ranging session, the first scrambling sequence is used to send the first message to the second device.

2. The apparatus of claim 1, wherein, in order to obtain the OOB key, the one or more processors are individually or jointly configured to cause the first device to receive the OOB key from a network entity or a peer device.

3. The apparatus of claim 1, wherein the one or more processors are individually or collectively configured to cause the first device to send the OOB key OOB to the second device.

4. The apparatus of claim 1, wherein, in order to obtain the OOB key, the one or more processors are individually or collectively configured to cause the first device to receive the OOB key from the network entity OOB-wise using a communication technology different from the communication technology used in-band during the ranging session.

5. The apparatus of claim 1, wherein, in order to obtain the OOB key, the one or more processors are individually or jointly configured to cause the first device to receive the OOB key from a network entity on a secure dispatch channel.

6. The apparatus of claim 5, wherein the secure allocation channel is terminated by a root of trust associated with key management of the first device, or by a secure element of the first device having a high level of security assurance.

7. The apparatus of claim 1, wherein the one or more processors are individually or collectively configured to cause the first device to securely store the OOB key at the first device before initiating the ranging session.

8. The apparatus of claim 7, wherein, for secure storage of the OOB key, the one or more processors are individually or collectively configured to cause the first device to store the OOB key at the root of trust of the first device or in the secure element of the first device.

9. The apparatus of claim 1, wherein the ranging session is associated with a short-range wireless protocol, and wherein the first device is a central device and the second device is a peripheral device.

10. The apparatus of claim 1, wherein the ranging session is associated with a short-range radio protocol, and wherein the first device is a user equipment (UE) and the second device is associated with a locking mechanism.

11. The apparatus of claim 1, wherein the information used in-band includes a set of derivation diversification factors, and wherein, in order to generate the one or more first inputs, the one or more processors are individually or collectively configured to cause the first device to use the OOB key and the set of derivation diversification factors to generate the one or more first inputs.

12. The apparatus of claim 11, wherein the set of derived diversification factors is associated with a long-term key and includes an initialization vector, an initialization random number, and a personalization vector.

13. The apparatus of claim 11, wherein in order to generate the one or more first inputs, the first device is configured to generate an OOB initialization vector (IV).

14. The apparatus of claim 13, wherein, in order for the first device to generate the one or more first inputs to the first scrambling sequence, the one or more processors are configured to cause the first device to use the OOB IV and the set of derived diversification factors to generate a first key and a first random number for a first ranging iteration of the ranging session with the second device.

15. The apparatus of claim 14, wherein the one or more processors are individually or collectively configured to cause the first device to: The second ranging iteration generates a second key and a second random number, which are used as the second input to the second scrambling sequence; and The second message is sent to the second device using the second scrambling sequence as part of the second ranging iteration.

16. An apparatus for wireless communication at a second device, the apparatus comprising: One or more memory units; and One or more processors, said one or more processors coupled to said one or more memories, said one or more processors individually or collectively configured to enable the second device: Receive an out-of-band (OOB) key from a first device or network entity, the out-of-band (OOB) key being shared OOB relative to a ranging session defined in-band between the first device and the second device; One or more inputs to the first scrambling sequence used in the ranging session are generated in-band using the OOB key itself or in combination with information used in-band. as well as Receive a first message using the first scrambling sequence from the first device.

17. The apparatus of claim 16, wherein the one or more processors are individually or collectively configured to cause the second device to decode the first message using the first scrambling sequence.

18. The apparatus of claim 16, wherein the one or more processors are individually or collectively configured to cause the second device to securely store the OOB key at the second device prior to initiating the ranging session.

19. An apparatus for wireless communication at a network entity, the apparatus comprising: One or more memory units; and One or more processors, coupled to one or more memories, wherein the one or more processors are individually or collectively configured to enable the network entity to: Receive a request from the first device for an out-of-band (OOB) key associated with the ranging session at the first device; as well as The OOB key is sent to the first device in an OOB manner when the first device successfully authenticates to the network entity.

20. The apparatus of claim 19, wherein, in order to transmit the OOB key, the one or more processors are configured to cause the network entity to transmit the OOB key on a secure dispatch channel.