Method and apparatus for reliable time acquisition in wireless networks - Patents.com
Patent Information
- Application Number
- JP2024500574
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-07-27
- Filing Date
- 2022-06-06
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-06-06
AI Technical Summary
Existing wireless communication systems face challenges in providing accurate and reliable time acquisition, particularly in the absence of Global Navigation Satellite System (GNSS) signals due to spoofing or jamming, which is critical for various infrastructure and sectors.
A method and apparatus for obtaining accurate time through wireless networks by encrypting a portion of the time broadcast from a base station, determining the propagation delay between the UE and the base station, and using digital signatures to authenticate the time, enabling reliable time correction.
Ensures accurate and reliable time acquisition by detecting spoofing and jamming, ensuring the authenticity and precision of time information, even in environments where GNSS is unavailable.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Claiming priority
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims the benefit of U.S. Non-Provisional Patent Application No. 17 / 386,325, entitled "METHOD AND APPARATUS FOR ACQUISITION OF RELIABLE TIME IN A WIRELESS NETWORK," filed on July 27, 2021, which is assigned to the assignee of this application and is expressly incorporated by reference in its entirety into this specification. [Technical field]
[0002] Field
[0002] The present disclosure relates generally to the field of wireless communications in networks, and more specifically to broadcasting and reliable acquisition of time over wireless networks. [Background technology]
[0003] information
[0003] Wireless communication systems are widely deployed to provide various types of communication content, such as voice, video, packet data, messaging, broadcasts, and the like. These systems may be capable of supporting communication with multiple users by sharing available system resources (e.g., time, frequency, and power). Examples of such multiple-access systems include Code Division Multiple Access (CDMA) systems, Time Division Multiple Access (TDMA) systems, Frequency Division Multiple Access (FDMA) systems, and Orthogonal Frequency Division Multiple Access (OFDMA) systems. A wireless multiple-access communication system may include several base stations, each simultaneously supporting communication for multiple communication devices, each of which may be referred to as User Equipment (UE).
[0004]
[0004] These multiple access technologies are adopted in various telecommunications standards to provide a common protocol that allows various wireless devices to communicate at city, national, regional, and even global levels. One example of an emerging telecommunications standard is New Radio (NR), e.g., 5G radio access. NR is a set of improvements to the LTE mobile standard promulgated by the Third Generation Partnership Project (3GPP). NR is designed to support mobile broadband Internet access more powerfully by increasing spectral efficiency, reducing costs, improving services, utilizing new spectrum, and better integration with other open standards using OFDMA with cyclic prefix (CP) on the downlink (DL) and uplink (UL), as well as supporting beamforming, multiple-input multiple-output (MIMO) antenna technology, and carrier aggregation.
[0005]
[0005] As part of providing 4G or 5G wireless access to a UE, the wireless network may provide the UE with a current time (e.g., UTC time or GPS time), which may be very accurate (e.g., accurate to within 1 microsecond (μs)) or less accurate (e.g., accurate to within 1 second). For example, this may be useful when other timing sources (e.g., timing from a GNSS constellation) are unavailable (e.g., in the case of GNSS, due to GNSS system failure, unavailability of GNSS signals, or jamming or spoofing). However, such timing support may itself be unreliable, e.g., due to spoofing. Summary of the Invention
[0006]
[0006] Accurate and reliable time is obtained by a user equipment (UE) from a base station in a wireless network. The base station may obtain the time, for example, Coordinated Universal Time (UTC) time or Global Navigation Satellite System (GNSS) time, and encrypts at least a portion of the time before broadcasting it. The UE determines a propagation delay between the UE and the base station based on a timing advance, a known location of the UE and the base station, or a measured round trip propagation time (RTT) between the UE and the base station. A corrected time can be determined based on the time and the propagation delay received from the base station. A digital signature included in the time broadcast by the base station increases reliability. Spoofing of the broadcasted time by an attacking device can be detected by the UE based on the propagation delay being outside of an expected range.
[0007]
[0007] In one implementation, a method performed by a user equipment (UE) to support time acquisition in a wireless network includes receiving a message broadcast from a base station, where the message includes a current time, at least a portion of the current time being encrypted, obtaining a plaintext current time by decrypting at least a portion of the current time, determining a propagation delay between the base station and the UE, and determining a corrected current time based on the plaintext current time and the propagation delay.
[0008]
[0008] In one implementation, a user equipment (UE) configured to support time acquisition in a wireless network comprises a wireless transceiver configured to communicate wirelessly with a base station in the wireless network, at least one memory, and at least one processor coupled to the wireless transceiver and the at least one memory, wherein the at least one processor is configured to: receive a message broadcast from the base station via the wireless transceiver, the message including a current time, at least a portion of the current time being encrypted, obtain a plaintext current time by decrypting at least a portion of the current time, determine a propagation delay between the base station and the UE, and determine a corrected current time based on the plaintext current time and the propagation delay.
[0009]
[0009] In one implementation, a user equipment (UE) configured to support time acquisition in a wireless network comprises: means for receiving a message broadcasted from a base station, where the message includes a current time, at least a portion of the current time being encrypted; means for obtaining a plaintext current time by decrypting at least a portion of the current time; means for determining a propagation delay between the base station and the UE; and means for determining a corrected current time based on the plaintext current time and the propagation delay.
[0010]
[0010] In one implementation, a non-transitory computer-readable storage medium having program code stored thereon is operable to configure at least one processor in a user equipment (UE) to support obtaining time in a wireless network, the program code including instructions for receiving a message broadcasted from a base station, the message including a current time, at least a portion of the current time being encrypted, obtaining a clear current time by decrypting at least a portion of the current time, determining a propagation delay between the base station and the UE, and determining a corrected current time based on the clear current time and the propagation delay.
[0011]
[0011] In one implementation, a method performed by a base station to support time acquisition by user equipment (UE) in a wireless network includes acquiring a current time, encrypting at least a portion of the current time, and broadcasting a message including the current time, wherein the UE receives the message and obtains a plaintext current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE, and the UE determines a corrected current time based on the plaintext current time and the propagation delay.
[0012]
[0012] In one implementation, a base station configured to support time acquisition by user equipment (UE) in a wireless network includes an external interface configured to communicate wirelessly with entities in the wireless network, at least one memory, and at least one processor coupled to the external interface and the at least one memory, wherein the at least one processor is configured to acquire a current time, encrypt at least a portion of the current time, and broadcast a message including the current time, the UE receives the message and acquires a plaintext current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE, and the UE determines a corrected current time based on the plaintext current time and the propagation delay.
[0013]
[0013] In one implementation, a base station configured to support time acquisition by a user equipment (UE) in a wireless network includes means for acquiring a current time, means for encrypting at least a portion of the current time, and means for broadcasting a message including the current time, wherein the UE receives the message and obtains a plaintext current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE, and the UE determines a corrected current time based on the plaintext current time and the propagation delay.
[0014]
[0014] In one implementation, a non-transitory computer-readable storage medium including program code stored thereon, the program code operable to configure at least one processor in a base station to support acquisition of time by user equipment (UE) in a wireless network, the program code including instructions for acquiring a current time, encrypting at least a portion of the current time, and broadcasting a message including the current time, the UE receiving the message and acquiring a plaintext current time by decrypting at least a portion of the current time and determining a propagation delay between the base station and the UE, and the UE determining a corrected current time based on the plaintext current time and the propagation delay. [Brief description of the drawings]
[0015]
[0015] The accompanying drawings are presented to aid in the explanation of various aspects of the present disclosure and are provided for illustration only and not as a limitation of the aspects. [Figure 1]
[0016] 1 illustrates a high-level system architecture of a wireless communication system according to one aspect of the present disclosure. [Figure 2A]
[0017] 4 indicates the format of the current time that may be broadcast in messages from the base station. [Figure 2B]
[0018] 1 shows an encryption of the current time that may be broadcast from a base station. [Figure 2C] 1 shows an encryption of the current time that may be broadcast from a base station. [Figure 2D] 1 shows an encryption of the current time that may be broadcast from a base station. [Figure 2E]
[0019] Indicates additional information about the current time that may be broadcast from the base station. [Figure 3A]
[0020] 1 illustrates a signaling flow for broadcasting and acquiring time in a wireless network. [Figure 3B]
[0021] 1 illustrates a signaling flow for broadcasting and acquiring time in a wireless network and determining propagation delay between a base station and a UE. [Figure 4A]
[0022] 1 illustrates a signaling flow for broadcasting and acquiring time in a wireless network in which an attacking device is present and performing a replay attack. [Figure 4B]
[0023] 1 illustrates an improved reliability signaling flow for broadcasting and acquiring time in a wireless network and determining propagation delay between a base station and a UE in the presence of replay attacks. [Diagram 5]
[0024] 1 illustrates a signaling flow for broadcasting and acquiring time in a wireless network and detecting replay attacks by attacking devices. [Figure 6]
[0025] FIG. 1 shows a schematic block diagram illustrating certain example features of a UE configured to support obtaining current time from a wireless network. [Figure 7]
[0026] FIG. 1 shows a schematic block diagram illustrating certain exemplary features of a base station configured to support obtaining current time from a wireless network. [Figure 8]
[0027] 1 illustrates a flowchart of an example UE-implemented method for supporting UE acquisition of time in a wireless network. [Figure 9]
[0028] 4 illustrates a flowchart of an example method implemented by a base station for supporting time acquisition by a UE in a wireless network.
[0016]
[0029] Elements, phases, steps, and / or actions having the same reference label in different drawings may correspond to one another (e.g., may be similar or identical to one another). Furthermore, some elements in various drawings are labeled using a numeric prefix followed by an alphabetic or numeric suffix. Elements with the same numeric prefix but different suffixes may be different instances of the same type of element. A numeric prefix without a suffix is used herein to refer to any element that is labeled with that numeric prefix. For example, different instances of base stations 110-1, 110-2, 110-3 are shown in FIG. 1. In this case, a reference to base station 110 refers to any of base stations 110-1, 110-2, 110-3. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0017]
[0030] Aspects of the present disclosure are provided in the following description and associated drawings, which are directed to various examples provided for illustrative purposes. Alternative aspects may be devised without departing from the scope of the present disclosure. Additionally, well-known elements of the present disclosure have not been described in detail or have been omitted so as not to obscure the relevant details of the present disclosure.
[0018]
[0031] The words "exemplary" and / or "example" are used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" and / or "example" is not necessarily to be construed as preferred or advantageous over other aspects. Similarly, the term "aspects of the present disclosure" does not require that all aspects of the present disclosure include the discussed feature, advantage or mode of operation.
[0019]
[0032] Those skilled in the art will appreciate that the information and signals described below may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the following description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof, depending in part on the particular application, desired design, corresponding technology, etc.
[0020]
[0033] Further, many aspects are described as a series of actions performed by, for example, elements of a computing device. It will be appreciated that various actions described herein may be performed by specific circuitry (e.g., an Application Specific Integrated Circuit (ASIC), by program instructions executed by one or more processors, or by a combination of both. In addition, a series or series of actions described herein may be considered to be embodied entirely within any form of non-transitory computer-readable storage medium storing a corresponding set of computer instructions that, when executed, cause or instruct a processor associated with the device to perform the functionality described herein. Thus, various aspects of the present disclosure may be embodied in a number of different forms, all of which are contemplated to be within the scope of the claimed subject matter. In addition, for each of the aspects described herein, the corresponding form of any such aspect may be described herein, for example, as "logic configured to" perform the described actions.
[0021]
[0034] The terms "User Equipment (UE)" and "base station" as used herein are not intended to be specific or limited to any particular Radio Access Technology (RAT) unless otherwise specified. In general, a UE may be any wireless communication device used by a user to communicate over a wireless communication network (e.g., a mobile phone, a router, a tablet computer, a laptop computer, a consumer tracking device for tracking consumer items, packages, assets or entities such as individuals or pets, a wearable (e.g., a smart watch, glasses, Augmented Reality (AR) / Virtual Reality (VR) headsets, etc.), a vehicle (e.g., an automobile, a motorcycle, a bicycle, etc.), an Internet of Things (IoT) device, etc.). A UE may be mobile or may be stationary (e.g., at certain times) and may communicate with a Radio Access Network (RAN). The term "UE" as used herein may be referred to interchangeably as an "access terminal" or "AT", "client device", "wireless device", "subscriber device", "subscriber terminal", "subscriber station", "user terminal" or "UT", "mobile terminal", "mobile station", "mobile device", or variations thereof. A UE may typically communicate with a core network via a RAN, through which the UE may be connected to external networks, such as the Internet, and other UEs. Of course, other mechanisms for connecting to the core network and / or the Internet are also possible for a UE, such as via a wired access network, a Wireless Local Area Network (WLAN) network (e.g., based on IEEE 802.11, etc.), etc.
[0022]
[0035] A base station may operate according to one of several RATs in communication with a UE depending on the network in which it is deployed and may alternatively be referred to as an Access Point (AP), network node, NodeB, evolved NodeB (eNB), new radio (NR) NodeB (also referred to as gNB), etc. Additionally, in some systems, the base station may simply provide edge node signaling functionality, while in other systems, the base station may provide additional control and / or network management functionality. A communication link through which a UE may transmit signals to a base station is referred to as an uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). A communication link through which a base station may transmit signals to a UE is referred to as a downlink (DL) channel or forward link channel (e.g., paging channel, control channel, broadcast channel, forward traffic channel, etc.). As used herein, the term Traffic Channel (TCH) may refer to either a UL / reverse traffic channel or a DL / forward traffic channel.
[0023]
[0036] The term "base station" may refer to a single physical transmission point or multiple physical transmission points that may or may not be co-located. For example, when the term "base station" refers to a single physical transmission point, the physical transmission point may be an antenna of the base station corresponding to the base station's cell. When the term "base station" refers to multiple co-located physical transmission points, the physical transmission point may be an array of base station antennas (e.g., as in a Multiple Input Multiple Output (MIMO) system or when the base station employs beamforming). When the term "base station" refers to multiple non-co-located physical transmission points, the physical transmission points may be a Distributed Antenna System (DAS) (a network of spatially separated antennas connected to a common source via a carrier medium) or a Remote Radio Head (RRH) (a remote base station connected to a serving base station). Alternatively, the non-co-located physical transmission points may be a serving base station that receives measurement reports from the UE and a neighboring base station whose reference RF signal the UE is measuring.
[0024]
[0037] Obtaining accurate and reliable time, such as Coordinated Universal Time (UTC), can be essential for many critical infrastructures and sectors of the modern economy, such as power generation and distribution, telecommunications, transportation, stock trading time stamps, and many other critical and non-critical use cases. For example, highly accurate time is often obtained from Global Navigation Satellite System (GNSS) signals. However, GNSS may be unavailable in some locations, e.g., indoors, or may fail, e.g., due to spoofing or jamming.
[0025]
[0038] Supporting reliable timing provision over wireless networks as a fallback to Global Navigation Satellite System (GNSS) failures (e.g., spoofing or jamming) is becoming an area of importance in 3GPP and other Standards Development Organizations (SDOs). Besides overcoming GNSS timing failures, the use of timing acquisition over wireless networks can also be used indoors where GNSS is sometimes unavailable. Key factors for timing provision over wireless networks are high accuracy and reliability, e.g., to avoid timing spoofing and to allow the receiver to know if the received timing is correct and accurate.
[0026]
[0039] As described herein, accurate and reliable time may be obtained via a wireless network in which a base station broadcasts a message including at least a portion of an encrypted current time. The current time may be, for example, Coordinated Universal Time (UTC), Global Positioning System (GPS), GLONASS, Beidou, Galileo, Global Navigation Satellite System (GNSS), or a local regional time (e.g., Eastern Standard Time (EST) or Pacific Daylight Time (PDT) in the United States). A receiving entity, for example, a UE, may decrypt the current time. However, due to the propagation time of the broadcast message, the clear current time obtained by the UE may not be accurate. Thus, the UE may determine a propagation delay between the base station and itself, for example, based on a timing advance obtained from the base station, the known locations of the UE and the base station, or the measured round trip propagation time (RTT) between the UE and the base station. A corrected current time may then be determined based on the clear current time and the propagation delay. The authenticity of the current time may be authenticated, for example, using a digital signature of the base station included in the broadcast message. Furthermore, the UE may further verify the authenticity of the current time by determining that the message having the current time was received directly from the base station, without an attacking device, e.g., without a replay attack. For example, the UE and the base station may perform an RTT measurement procedure to determine the propagation delay, and the UE may verify that there are no attacking devices using a replay attack, for example, by comparing the actual measured RTT with an expected range of RTT based on the expected distance to the base station.
[0027]
[0040] It should be noted that a wireless network may use various known techniques for obtaining an accurate current time, which may include a reference device or network that can determine accurate time from one or more GNSS constellations, one or more internal clock sources of the wireless network (e.g., atomic clocks), or an external server clock source that may provide time using, for example, the Network Time Protocol (NTP).
[0028]
[0041] 1 illustrates a non-roaming 5G NR network based architecture supporting reliable time acquisition over a wireless network by a UE as described herein. FIG. 1 illustrates a communication system 100 comprising a UE 102 and components of a Fifth Generation (5G) network including a Next Generation Radio Access Network (NG-RAN) 112, Base Stations (BS), also referred to as new radio (NR) NodeBs or gNBs 110-1, 110-2, 110-3, next generation evolved NodeBs (ng-eNBs) 114, and a 5G Core Network (5GCN) 150 in communication with an external client 130. The architecture of the gNB 110 may be divided into functional parts including, for example, one or more of a gNB Central Unit (gNB-CU), one or more gNB Distributed Units (gNB-DU), and one or more gNB Remote Units (gNB-RU), any of which may be physically co-located with other parts of the gNB 110 or may be physically separate. The 5G network may also be referred to as a New Radio (NR) network. The NG-RAN 112 may also be referred to as an NR RAN or a 5G RAN, and the 5GCN 150 may also be referred to as a Next Generation (NG) Core network (NGC). The communication system 100 may further utilize information from a Space Vehicle (SV) 190 for a Global Navigation Satellite System (GNSS) such as GPS, GLONASS, Galileo or Beidou, or any other local or regional Satellite Positioning System (SPS) such as IRNSS, EGNOS or WAAS.Additional components of the communication system 100 are described below. The communication system 100 may include additional or alternative components.
[0029]
[0042] 1 shows a serving gNB 110-1 for a UE 102, neighboring gNBs 110-2, 110-3, and an ng-eNB 114. The neighboring gNBs may be gNBs that are capable of receiving and measuring uplink (UL) signals transmitted by the UE 102 and / or transmitting downlink (DL) reference signals (RS), e.g., positioning reference signals (PRS), that may be received and measured by the UE 102 to support location determination of the UE 102.
[0030]
[0043] It should be noted that FIG. 1 provides only a generalized illustration of the various components, and that any or all of the components may be utilized as appropriate, and each of them may be duplicated or omitted as necessary. In particular, while only one UE 102 is illustrated, it will be understood that many UEs (e.g., hundreds, thousands, millions, etc.) may utilize the communication system 100. Similarly, the communication system 100 may include more or fewer SV190, gNBs 110-1, 110-2, external clients 130, and / or other components. The illustrated connections connecting the various components in the communication system 100 include data and signaling connections, which may include additional (intermediate) components, direct or indirect physical and / or wireless connections, and / or additional networks. Furthermore, the components may be rearranged, combined, separated, substituted, and / or omitted depending on the desired functionality.
[0031]
[0044] Although FIG. 1 illustrates a 5G-based network, similar network implementations and configurations may be used for other communication technologies such as 3G, Long Term Evolution (LTE), also referred to as 4G, and IEEE 802.11 WiFi. For example, if a Wireless Local Area Network (WLAN), e.g., an IEEE 802.11 air interface, is used, the UE 102 may communicate with an Access Network (AN) rather than an NG-RAN, and thus the component 112 may be represented herein by the terms "RAN," "(R)AN," or "(R)AN 112" and referred to as an AN or RAN. In the case of an AN (e.g., an IEEE 802.11 AN), the AN may be connected to a Non-3GPP Interworking Function (N3IWF) that is connected to the AMF 154 (e.g., in the 5GCN 150) (not shown in FIG. 1).
[0032]
[0045] The UE 102 may be any electronic device and may be referred to as a device, a mobile device, a wireless device, a mobile terminal, a terminal, a Mobile Station (MS), a Secure User Plane Location (SUPL) Enabled Terminal (SET), or some other name. The UE 102 may be a standalone device or may be embedded within another device that is to be monitored or tracked, e.g., a factory tool. Moreover, the UE 102 may correspond to a smart watch, digital glasses, a fitness monitor, a smart car, a smart appliance, a cell phone, a smartphone, a laptop, a tablet, a PDA, a consumer tracking device for tracking entities such as consumer items, packages, assets, or individuals and pets, a control device, or some other portable or movable device. The UE 102 may include a single entity or may include multiple entities, such as in a personal area network, where, for example, a user may utilize audio, video, and / or data I / O devices, and / or body sensors and a separate wireline or wireless modem. Although not necessarily, the UE 102 may typically support wireless communications using one or more radio access technologies (RATs), such as GSM, Code Division Multiple Access (CDMA), Wideband CDMA (WCDMA), LTE, High Rate Packet Data (HRPD), IEEE 802.11 WiFi (also known as Wi-Fi), Bluetooth (BT), Worldwide Interoperability for Microwave Access (WiMAX), 5G New Radio (NR) (e.g., using NG-RAN 112 and 5GC 150), etc.The UE 102 may also support wireless communications using a Wireless Local Area Network (WLAN), which may connect to other networks (e.g., the Internet) using, for example, a Digital Subscriber Line (DSL) or packet cable. Use of one or more of these RATs may enable the UE 102 to communicate with external clients 130 (e.g., via elements of the 5GCN 150 not shown in FIG. 1, or possibly via a Gateway Mobile Location Center (GMLC) 160) and / or enable the external clients 130 to receive location information regarding the UE 102 (e.g., via the GMLC 160).
[0033]
[0046] The UE 102 may enter into a connection with a wireless communication network that may include the NG-RAN 112. In one example, the UE 102 may communicate with the cellular communication network by transmitting wireless signals to or receiving wireless signals from a cellular transceiver in the NG-RAN 112, such as the gNB 110-1. The transceiver provides user plane and control plane protocol termination towards the UE 102 and may be referred to as a base station, base transceiver station, radio base station, radio transceiver, radio network controller, transceiver function, Base Station Subsystem (BSS), Extended Service Set (ESS), or some other suitable terminology.
[0034]
[0047] In certain implementations, the UE 102 may have circuitry and processing resources capable of obtaining location-related measurements. The location-related measurements obtained by the UE 102 may include signal measurements received from a satellite vehicle (SV) 190 belonging to a satellite positioning system (SPS) or global navigation satellite system (GNSS), such as GPS, GLONASS, Galileo, or Beidou, and / or may include signal measurements received from terrestrial transmitters fixed at known locations (e.g., gNBs). The UE 102, or the gNB 110-1, which may be the destination of the UE 102's measurements, may then obtain a location estimate for the UE 102 based on these location-related measurements using any one of a number of positioning methods, such as, for example, GNSS, Assisted GNSS (A-GNSS), Advanced Forward Link Trilateration (AFLT), Angle of Departure (AOD), Time Difference Of Arrival (TDOA), Round Trip Time (RTT), WLAN (also called WiFi) positioning, or Enhanced Cell ID (ECID), or a combination thereof. In some of these techniques (e.g., A-GNSS, AFLT, AOD and TDOA), pseudoranges or timing differences may be measured at the UE 102 relative to three or more terrestrial transmitters (e.g., gNBs) fixed at known locations, or relative to four or more SV190s with precisely known orbit data, or a combination thereof, based at least in part on pilots, positioning reference signals (PRS), or other positioning-related signals transmitted by transmitters or satellites and received at the UE 102.
[0035]
[0048] 1 may correspond, for example, to a Location Management Function (LMF) 152 or a Secure User Plane Location (SUPL) Location Platform (SLP) 162 and may provide positioning assistance data to the UE 102 including, for example, information about the signals to be measured (e.g., expected signal timing, signal coding, signal frequency, signal Doppler), terrestrial transmitter (e.g., gNB) location and identification information, and / or GNSS SV signal, timing and orbit information to facilitate positioning techniques such as A-GNSS, AFLT, AOD, TDOA, RTT and ECID. This facilitation may include improving signal collection and measurement accuracy by the UE 102 and, in some cases, enabling the UE 102 to calculate its estimated location based on the location measurements. For example, a location server (e.g., LMF 152 or SLP 162) may include an almanac, also referred to as a Base Station Almanac (BSA), that indicates the locations and identification information of cellular and / or local transceivers in one or more particular areas, such as a particular event venue, and may provide information describing signals transmitted by cellular base stations or APs (e.g., gNBs), such as transmit power and signal timing.The UE 102 may obtain signal strength (e.g., Received Signal Strength Indication (RSSI)) measurements for signals received from the cellular transceiver and / or the local transceiver, and / or may obtain the signal to noise ratio (S / N), Reference Signal Received Power (RSRP), Reference Signal Received Quality (RSRQ), Time Of Arrival (TOA), Angle Of Arrival (AOA), Angle of Radiation (AOD), Receive time-Transmission time difference (Rx-Tx), or round trip signal propagation time (RTT) between the UE 102 and the cellular transceiver (e.g., gNB) or the local transceiver (e.g., WiFi Access Point (AP)). The UE 102 may use these measurements along with assistance data (e.g., terrestrial almanac data or GNSS satellite data such as GNSS almanac and / or GNSS ephemeris information) received from a location server (e.g., LMF 152 or SLP 162) or broadcast by a base station (e.g., gNBs 110-1, 110-2) in the NG-RAN 112 to determine a location for the UE 102.
[0036]
[0049] In some implementations, a network entity is used to assist in locating the UE 102. For example, an entity in the network, such as gNBs 110-1, 110-2, may measure UL signals transmitted by the UE 102. The UL signals may include or comprise UL reference signals, such as UL Positioning Reference Signals (PRS) or UL Sounding Reference Signals (SRS). The entity that obtains the location measurements (e.g., gNBs 110-1, 110-2) may then forward the location measurements to the UE 102 or the LMF 152, which may use the measurements to determine Real Time Differences (RTD) for multiple transceiver pairs. Examples of location measurements that may use UL signals may include RSSI, RSRP, RSRQ, TOA, Rx-Tx, AOA, and RTT.
[0037]
[0050] An estimate of the location of the UE 102 may also be referred to as a location, location estimate, location fix, fix, position, position estimate, or position fix, and provides location coordinates (e.g., latitude and longitude) of the UE 102 that may or may not include an altitude component (e.g., altitude and height or depth above ground, floor, or basement). Alternatively, the location of the UE 102 may be expressed as a civic location (e.g., as an address or designation of some point or small area within a building, such as a particular room or floor).
[0038]
[0051] As shown in FIG. 1, pairs of gNBs in the NG-RAN 112 may be connected to each other, for example, directly as shown in FIG. 1 or indirectly via other gNBs 110-1, 110-2. Access to the 5G network is provided to the UE 102 via wireless communication between the UE 102 and one or more of the gNBs 110-1, 110-2, where the gNBs 110-1, 110-2 may provide wireless communication access to the 5GCN 150 for the UE 102 using 5G (e.g., NR). In FIG. 1, the serving gNB for the UE 102 is assumed to be the gNB 110-1, while other gNBs (e.g., gNBs 110-2, 110-3, or ng-eNB 114) may act as a serving gNB when the UE 102 moves to another location or as a secondary gNB to provide additional through-out and bandwidth to the UE 102.
[0039]
[0052] As noted above, while FIG. 1 illustrates nodes configured to communicate according to a 5G communication protocol, nodes configured to communicate according to other communication protocols, such as, for example, an LTE protocol, may also be used. Such nodes configured to communicate using another protocol may be controlled, at least in part, by the 5GCN 150. Thus, the NG-RAN 112 may include any combination of gNBs, evolved Node Bs (eNBs) supporting LTE, or other types of base stations or access points. As an example, the NG-RAN 112 may include one or more ng-eNBs 114 that may provide LTE wireless access to the UE 102 and connect to entities in the 5GC 150, such as the AMF 154.
[0040]
[0053] The gNBs 110-1, 110-2, 110-3, and ng-eNB 114 may communicate with an Access and Mobility Management Function (AMF) 154, which may communicate with a Location Management Function (LMF) 152 for positioning functionality. The AMF 154 may support the mobility of the UE 102, including cell changes and handovers, and may be responsible for supporting signaling connections to the UE 102 and possibly helping to establish and release Protocol Data Unit (PDU) sessions for the UE 102 supported by the UPF 158. Other functions of the AMF 154 may include: termination of the Control Plane (CP) interface from the NG-RAN 112, termination of Non-Access Stratum (NAS) signaling connections from UEs such as the UE 102, NAS encryption and integrity protection, registration management, connection management, reachability management, mobility management, access authentication and authorization.
[0041]
[0054] The gNB 110-1 may support positioning of the UE 102 when the UE 102 accesses the NG-RAN 112. The gNB 110-1 may also process location service requests for the UE 102, e.g., received directly or indirectly from the GMLC 160. In some embodiments, a node / system implementing the gNB 110-1 may additionally or instead implement other types of location determination support modules, such as an Enhanced Serving Mobile Location Center (E-SMLC) or a Secure User Plane Location (SUPL) Location Platform (SLP) 162. It should be noted that in some embodiments, at least a portion of the positioning functionality (including derivation of the location of the UE 102) may be performed in the UE 102 (e.g., using signal measurements on signals transmitted by wireless nodes and assistance data provided to the UE 102).
[0042]
[0055] The GMLC 160 may support location information requests for the UE 102 received from the external client 130 and may forward such location information requests to the serving AMF 154 for the UE 102. The AMF 154 may then forward the location information request to either the gNB 110-1 or the LMF 152, which may obtain one or more location estimates for the UE 102 (e.g., according to a request from the external client 130) and return the location estimate(s) to the AMF 154, which may return the location estimate(s) to the external client 130 via the GMLC 160. The GMLC 160 may contain subscription information of the external client 130 and may authenticate and authorize location information requests for the UE 102 from the external client 130. GMLC160 may further initiate a location session for UE102 by sending a location information request for UE102 to AMF154, and may include identification information for UE102 and the type of location being requested (e.g., a current location, or a periodic or triggered location sequence) in the location information request.
[0043]
[0056] As shown, a Unified Data Management (UDM) 161 may be connected to the GMLC 160. The UDM 161 is similar to a Home Subscriber Server (HSS) for LTE access, and if necessary, the UDM 161 may be combined with the HSS. The UDM 161 is a central database containing user-related and subscription-related information for the UE 102 and may perform the following functions: UE authentication, UE identification, access authorization, registration and mobility management, subscription management, and short message service management.
[0044]
[0057] 1, external clients 130 may be connected to the core network 150 via the GMLC 160 and / or the SLP 162. External clients 130 may optionally be connected to the core network 150 via the Internet 175 and / or to an SLP 164 that is external to the 5GCN 150. External clients 130 may be a server, a web server, or a user device such as a personal computer, UE, etc.
[0045]
[0058] A Network Exposure Function (NEF) 163 may be connected to the GMLC 160 and the AMF 154. In some implementations, the NEF 163 may be connected to communicate directly with the external client 130 or the Application Function (AF) 132. The NEF 163 may support secure exposure of capabilities and events related to the 5GCN 150 and the UE 102 to the external client 130 or the AF 132, and may enable secure provision of information from the external client 130 or the AF 132 to the 5GCN 150. For example, the NEF 163 may also function to obtain the current or last known location of the UE 102, and may obtain an indication of a change in the location of the UE 102, or when the UE 102 becomes available (or reachable). The external client 130 or the AF 132 may access the NEF 163 to obtain location information related to the UE 102.
[0046]
[0059] The LMF 152 and the gNB 110-1 may communicate using the New Radio Position Protocol A (NRPPa), which may be defined in 3GPP TS 38.455, with NRPPa messages being forwarded between the gNB 110-1 and the LMF 152. Additionally, the LMF 152 and the UE 102 may communicate using the LTE Positioning Protocol (LPP), which is defined in 3GPP TS 37.355, with LPP messages being forwarded between the UE 102 and the LMF 152 via the serving AMF 154 for the UE 102 and the serving gNB 110-1. The LPP protocol may be used to support positioning of the UE 102 using UE-assisted and / or UE-based location methods, such as Assisted GNSS (A-GNSS), Real Time Kinematic (RTK), Wireless Local Area Network (WLAN), Angle of Arrival (AOA), Time Difference of Arrival (TDOA), Round Trip Time (RTT), and / or Extended Cell Identity (ECID). The NRPPa protocol may be used to support positioning of the UE 102 using network-based positioning methods, such as ECID (when used in conjunction with measurements obtained by or received from the gNBs 110-1, 110-2, 110-3, or ng-eNB 114), and / or may be used by the LMF 152 to obtain location related information from the gNBs 110, such as parameters defining positioning reference signal (PRS) transmissions from the gNBs for support of TDOA.
[0047]
[0060] The gNBs 110-1, 110-2, 110-3, or ng-eNB 114 may communicate with the AMF 154 using a Next Generation Application Protocol (NGAP), for example, as defined in 3GPP Technical Specification (TS) 38.413. The NGAP may enable the AMF 154 to request the location of the UE 102 from the gNB 110-1 for the UE 102, and may enable the gNB 110-1 to return a location for the UE 102 to the AMF 154.
[0048]
[0061] The gNBs 110-1, 110-2, 110-3, or ng-eNB 114 may communicate with each other using the Xn Application Protocol (XNaP), for example, as defined in 3GPP TS 38.423. The XnAP may allow one gNB 110 to request another gNB 110 to obtain UL location measurements for the UE 102 and return the UL location measurements. The XnAP may also allow a gNB 110 to request another gNB 110 to transmit a downlink (DL) RS or PRS, allowing the UE 102 to obtain DL location measurements of the transmitted DL RS or PRS.
[0049]
[0062] A gNB (e.g., gNB 110-1) may communicate with UE 102 using a Radio Resource Control (RRC) protocol, e.g., as defined in 3GPP TS 38.331. RRC may enable a gNB (e.g., gNB 110-1) to request location measurements of DL RS or DL PRS transmitted by gNB 110-1 and / or by other gNBs 110-2, 110-3, or ng-eNB 114 from UE 102 and return some or all of those location measurements. RRC may also enable a gNB (e.g., gNB 110-1) to request UE 102 to transmit UL RS or PRS to enable gNB 110-1 or other gNBs 110-2, 110-3, or ng-eNB 114 to obtain UL location measurements of the transmitted UL RS or PRS.
[0050]
[0063] As shown, a Session Management Function (SMF) 156 interfaces between the AMF 154 and the UPF 158. The SMF 156 may manage the establishment, modification, and release of PDU sessions for the UE 102, perform IP address allocation and management for the UE 102, act as a Dynamic Host Configuration Protocol (DHCP) server for the UE 102, and select and control the UPF 158 for the UE 102.
[0051]
[0064] The User Plane Function (UPF) 158 may support voice and data bearers for the UE 102 and enable voice and data access of the UE 102 to other networks such as the Internet 175. The functions of the UPF 158 may include external PDU session points of interconnection to data networks, routing and forwarding of packets (e.g., Internet Protocol (IP)), user plane portion of packet inspection and policy rule application, handling of user plane Quality of Service (QoS), as well as buffering of downlink packets and triggering of downlink data notifications. The UPF 158 may be connected to the SLP 162 to enable support of the location of the UE 102 using the SUPL location solution defined in the Open Mobile Alliance (OMA). The SLP 162 may further be connected to or accessible from the external client 130.
[0052]
[0065] To support reliable time acquisition by the UE 102, one or more of the gNB 110 and / or ng-eNB 114 may include a GNSS receiver that can receive, decode, and process signals from space vehicles (SVs) belonging to one or more GNSS constellations. For example, the signals may be navigation signals and may indicate precise time (e.g., GPS time or UTC time). In some other cases, the gNB 110 may be connected to a GNSS reference network that can provide precise GNSS time to the gNB 110. Further, the gNBs 110 (and / or ng-eNBs 114) may exchange timing information to (i) provide precise time to gNBs 110 or ng-eNBs 114 that do not have a GNSS receiver and are not connected to a GNSS reference network, or that have a GNSS receiver but are not currently able to receive signals from a GNSS SV, (ii) compare time information to detect whether a time determination by one or more gNBs 110 (or ng-eNBs 114) may be incorrect (e.g., due to external jamming or spoofing), and / or (iii) increase timing accuracy by combining (e.g., averaging) time determinations from multiple gNBs 110. Additionally or alternatively, one or more gNBs 110 and / or ng-eNBs 114 may receive precise timing information from the AMF 154 or UPF 158 (e.g., using NTP). In turn, the AMF 154 and / or UPF 158 may receive precise timing from some other entity, such as the UDM 161 or NEF 163, which may also contain or be connected to a source of precise time (e.g., an atomic clock) or may receive time from some external time source (e.g., a GNSS reference network or a secure server owned and operated by a government agency).The timing information obtained by the gNB 110 or ng-eNB 114 (e.g., received from the UDM 161 or NEF 163 via the AMF 154 or UPF 158) may include an identification of the source of the time (e.g., which may identify a government-operated atomic clock source or a GNSS reference network) and may indicate a level of accuracy (e.g., may indicate that the time is accurate to one microsecond, one millisecond (ms), or one second). Determining an accurate current time by or providing the accurate current time to the gNB 110 or ng-eNB 114 may enable the gNB or ng-eNB to provide accurate time to the UE 102, as described herein.
[0053]
[0066] Although FIG. 1 illustrates a network architecture for a non-roaming UE, it will be appreciated that a corresponding network architecture with suitable well-known modifications may be provided for a roaming UE.
[0054]
[0067] As discussed above, obtaining accurate and reliable time may be essential for many critical infrastructures and sectors of the modern economy, as well as many other critical and non-critical use cases. For example, highly accurate time may be received by a UE, such as UE 102, from GNSS signals from SV190. However, in some situations, signals from SV190 may be unavailable, such as indoor or urban canyon locations. Additionally, signals from SV190 may be unavailable due to attacks such as spoofing or jamming.
[0055]
[0068] The current time may be obtained by the UE 102 via the wireless system 100. For example, the gNB 110 may broadcast a message that may be received by the UE 102 and may include the current time. The gNB 110 may obtain the current time, for example, from a signal from the SV 190 or from a signal from an entity such as the AMF 154 or UPF 158 in the core network 150, as previously described. By way of example, the current time may be UTC time, GPS time, GLONASS time, Beidou time, Galileo time, GNSS time, or a local time (e.g., EST or PDT). The gNB 110 may periodically provide the current time to the UE 102 in one or more messages, for example, in a System Information Block (SIB).
[0056]
[0069] FIG. 2A illustrates, by way of example, a format of a current time 200 that may be broadcast in a message from the gNB 110. The current time 200 may be UTC time, GPS time, GLONASS time, Beidou time, Galileo time, GNSS time, or a local time (e.g., EST or PDT), etc. The current time 200 may be represented according to ISO8601 or any other desired format. As illustrated in FIG. 2A, for UTC time, the current time 200 may include the year (yyyy), month (MM), week (ww), day (D), hour (hh), minute (mm), second (ss), and fraction of a second (f...). The fraction of a second (f...) may be a decimal and may include as many decimal places as necessary. UTC time may accommodate the addition or subtraction of leap seconds by including a "60" value or omitting a "59" value, respectively, for the seconds (ss) field, as is well known. Of course, other formats may be used if desired, e.g., omitting the week and using two digits for the day (DD). For GPS, Galileo, or Beidou times, the time may be expressed as the number of seconds elapsed since some starting time (e.g., for GPS, 00:00 UTC (midnight) on January 5-6, 1980). Additionally, in some cases, the current time 200 may be provided as a time interval from a previously provided time.
[0057]
[0070] The timing information broadcast by the gNB 110 may be fully encrypted or a portion of the timing information may be encrypted. A UE 102 with a subscription to receive the encrypted time may receive an encryption key from the gNB 110 or from an entity in the 5GCN 150 (e.g., the AMF 154), which may be provided (e.g., by the AMF 154) when the UE 102 performs registration with the 5GCN 150. The UE 102 may use the encryption key to decrypt the encrypted timing information or a portion of the encrypted timing information. The encryption may use any encryption algorithm, such as one of the Advanced Encryption Standard (AES) algorithms defined by the United States National Institute of Standards and Technology (NIST). For example, in one embodiment, an AES counter mode algorithm may be used. In this case, a different counter may be used in each broadcast message (or SIB) that carries the current time. Because the number of encrypted bits in a broadcast message may be smaller than the number of bits in the encryption key (e.g., for the variations described below for Figures 2C and 2D), in some cases it may be easier, more convenient, or more secure to encrypt successive broadcast messages (or portions of successive broadcast messages) with a common ciphertext stream (e.g., for AES Counter Mode) and indicate the portion of the ciphertext stream used for each broadcast message.
[0058]
[0071] Encryption by the gNB 110 can, for example, enable subscription-based service of very accurate timing information and help ensure the reliability of the timing information. In some implementations, only the lower bits or fields may be encrypted, which allows a UE 102 without an encryption key to obtain an approximate time (e.g., time accurate to one second if only fractional seconds are encrypted), while a UE 102 with an encryption key can obtain a more accurate time (e.g., time accurate to one microsecond).
[0059]
[0072] 2B, 2C, and 2D show, by way of example, the format of the current UTC time 200 broadcast in a message from the gNB 110, with the shading representing the encrypted portion of the current time 200. As shown in FIG. 2B, all of the current time 200 may be encrypted. On the other hand, as shown by the shading in FIG. 2C, only fractions of a second may be encrypted, which allows any UE 102 to obtain the current time with an accuracy of one second, but a UE 102 with an encryption key may obtain a more accurate time. FIG. 2D shows an expanded format of the current time 200 showing individual units of fractions of a second, such as tenths, hundredths, thousandths, etc., with the shading indicating that some fractions (e.g., tenths and hundredths) may not be encrypted and lower digits (e.g., thousandths and below) may be encrypted.
[0060]
[0073] 2E illustrates additional information that may be included by the gNB 110 along with the current time in a message (e.g., SIB) broadcast to the UE 102. The information may include the current time (e.g., UTC as in any of FIGS. 2A-2D), a local transmit time at the gNB 110 (as described below, this may be used to more precisely indicate the current time, and its inclusion or indication may be implicit if the message transmission is associated with or part of the local transmit time frame and / or subframe structure of the gNB 110), the source of the current time (e.g., GPS, Galileo, GLONASS, Beidou, GNSS, local atomic clock, external server with atomic clock, GNSS reference network, local clock of the gNB 110), and / or the precision or uncertainty of the current time (e.g., 1 second, 1 ms, or 1 μs), and possibly a digital signature (DigSig). The purpose of the digital signature (DigSig) may be to improve the reliability of the current time received by the UE 102, which may be an important consideration, especially for critical use cases. To make the current time information more reliable, the UE 102 connected to a wireless network (e.g., 5GCN 150) may first authenticate the wireless network using existing (e.g., 3GPP) security mechanisms and establish a secure (e.g., encrypted) connection to the wireless network (e.g., to the serving gNB 110-1 and / or the serving AMF 154). The network entity (e.g., the serving AMF 154 or the serving gNB 110-1) may then provide the UE 102 with a public encryption key (also referred to as a public key) applicable to one gNB 110 (e.g., the serving gNB 110-1) or many or all of the gNBs 110.The gNB 110 may then broadcast the current time (e.g., in a SIB message) and include a digital signature (DigSig) to authenticate the current time based on a corresponding secret encryption key (also called a private key) known only to the network. Authentication may be performed only infrequently (e.g., by including a DigSig once every minute or five minutes) to reduce extra signaling and processing. If the digital signature is authenticated by the UE 102 using a public key, the UE 102 can trust the received current time. The network and UE may use any standardized type of digital signature, such as one based on the RSA algorithm or the Digital Signature Algorithm (DSA).
[0061]
[0074] It should be noted that public-private key style authentication using digital signatures as described above may be more reliable than authentication based on encryption of all or part of the current time (as shown in FIGS. 2B-2D). This is because the encryption is typically based on a single encryption key known to both the gNB 110 and the UE 102, which can be easily obtained by an attacking device (e.g., from the wireless network or from the UE 102). However, with a public-private key pair, the private key is not disclosed to the UE 102 and is only known within the wireless network.
[0062]
[0075] FIG. 3A illustrates a signaling flow 300 for reliable time broadcasting and acquisition in a wireless network including a gNB 110 and a UE 102, where the vertical axis represents time (time proceeds downwards) and the horizontal axis represents distance between the entities. FIG. 3A is provided as a non-limiting example. For example, FIG. 3A illustrates the use of 5G network entities, i.e., gNB 110 or ng-eNB 114, but other types of networks may be used, such as an LTE network where an eNB may be used instead of gNB 110, if desired. Additionally, it will be understood that there may be additional signaling and processes, and that messages transmitted by gNB 110 may include additional components.
[0063]
[0076] As shown, at or near (within 1 μs or 1 ms of) a current time T, the gNB 110 broadcasts a message 302 that is received by the UE 102 at time T+Δ. The message 302 may be included in a system information block (SIB) and may include the current time T and an implicit or explicit indication of an associated local transmission time t at the gNB 110 (e.g., the start of the next subframe or the end of the current subframe, etc.). The association may be such that the current time is exactly T when the local time is exactly t. The implicit local time t may be one defined in 3GPP TS (for example) and may not be explicitly included in the message 302. The local time t may enable more precise communication of the current time T and does not necessarily require the gNB 110 to broadcast the message 302 at exactly time T. Without a local time t, the gNB 110 may need to broadcast the message 302 at time T or as close to time T as possible, and the UE 102 may need to timestamp the arrival of the message 302. The current time T may be, for example, UTC time, GPS time, GLONASS time, Beidou time, Galileo time, GNSS time, or a local regional time (e.g., EST or PDT). For example, the gNB 110 may obtain the current time T as previously described, may obtain T periodically from another network entity, such as the SV 190 or the AMF 154 shown in FIG. 1, and may maintain time T using a local clock in the short period between updates from the SV 190 or other network entity. The local clock may also maintain, for example, a local transmission time t of the gNB 110 in the NG-RAN 112. As described above, at least a portion of the current time T may be encrypted by the gNB 110, as described with respect to FIGS. 2B-2D.
[0064]
[0077] In some implementations, the message 302 may include additional information, e.g., as described with respect to FIG. 2E. In one example, the message 302 may include or reference a local time t (e.g., as described above), which may indicate an alignment (or association) of the current time T with a subframe or slot boundary transmitted by the gNB 110. In one example, the message 302 may include an uncertainty of the current time T. In one example, the message 302 may include a source of the current time T, e.g., whether the current time T was obtained from an SV or a network entity, and whether the current time is UTC time, GPS time, GLONASS time, Beidou time, Galileo time, GNSS time, etc. The message 302 may include further additional information (e.g., a digital signature, as described with respect to FIG. 2E) and / or any combination of the above.
[0065]
[0078] Since the broadcast message 302 having a current time T arrives at the UE 102 after a signal propagation delay Δ from the gNB 110, the current time T in the message 302 acquired by the UE 102 at time T+Δ may not be accurate enough for some use cases. This may apply whether the message 302 includes an implicit or explicit local time t. When the local time t is not included (implicitly or explicitly), the UE 102 may only assume that the current time T corresponds to the reception time of the message 302 at T+Δ (e.g., the reception time of the start of the message 302 or the end of the message 302). Thus, it may have an error equal to Δ. When the local time t is included or indicated (implicitly or explicitly), the UE 102 may associate the current time T with a particular transmission time t received from the gNB 110, such as the start or end of the current or next subframe or slot. This association is normally correct for transmissions at the gNB 110, but is delayed by a time Δ when a local transmission time t indication (e.g., the start or end of a subframe or slot) arrives at the UE 102. This again introduces an error of Δ.
[0066]
[0079] Thus, providing a highly accurate current time, T, may require the ability for the UE 102 to determine the propagation delay, Δ, between itself and the gNB 110. With knowledge of the propagation delay, Δ, the UE 102 may add the propagation delay, Δ, to the received current time, T, to obtain the correct current time, T+Δ, either at the time of receipt by the UE 102 of the broadcast message 302 or at the time of receipt by the UE 102 of an implicit or explicit local time, t.
[0067]
[0080] The UE 102 may determine the propagation delay Δ between the broadcast gNB 110 and itself in various ways. For example, the UE 102 may obtain a Timing Advance (TA) from the gNB 110 in another message (not shown in FIG. 3A), such as a message of a Radio Resource Control (RRC) protocol or a Medium Access Control (MAC) protocol of the NR air interface. The TA may indicate a time interval by which the UE 102's transmission to the gNB 110 should precede the transmission timing received from the gNB 110. For example, if the UE 102 receives a start of a new subframe from the gNB 110 at local UE time T1, the UE 102 may support the transmission timing towards the gNB 110 such that the UE 102 transmits the start of the new subframe towards the gNB 110 at local UE time T1-TA. The TA value may be individual for each UE 102 and may be used by the gNB 110 to ensure that transmissions from all supported UEs 102 are received in a synchronized manner by the gNB 110 (e.g., the gNB 110 receives the start of a new subframe from all supported UEs 102 at the same time). In some cases, a timing advance offset may be added to the TA value by all UEs 102 without affecting its use to synchronize the arrival times of transmissions from different UEs 102 at the gNB 110. Typically (as is well known), the TA value is equal to the round trip signal propagation time (RTT) between the UE 102 and the gNB 110. Thus, the one-way propagation delay may be taken as half the TA value (hence, Δ=TA / 2). A limitation of using the timing advance is that the UE 102 typically needs to be in an RRC CONNECTED state and have an RRC signaling connection to the gNB 110. Therefore, the use of timing advance may not be suitable for a UE 102 in an RRC IDLE or RRC INACTIVE state receiving a current time T from the gNB 110.
[0068]
[0081] In another implementation, the UE 102 can use known positioning techniques to determine the range, e.g., distance, to the gNB 110 and convert the range to a propagation delay Δ based on the speed of the wireless signal (Δ=range / c, where c is the speed of light).
[0069]
[0082] For example, in some implementations, the UE 102 may obtain its location in a positioning session with a location server (e.g., LMF 152 or SLP 162) using known positioning techniques, such as, for example, A-GNSS, WiFi, DL-TDOA, DL-AOD, multi-cell RTT, ECID, etc., in a UE-based positioning technique, and may obtain the location of the broadcast gNB 110. The UE 102 may determine a range to the gNB 110 based on a distance between the location of the UE 102 and the location of the gNB 110. In some implementations, the location of the gNB 110 may be obtained by the UE 102 from a broadcast SIB message from the gNB 110 including the location of the gNB 110, or from an LPP Assistance Data message including the location of the gNB 110 received from a location server (e.g., LMF 152 or SLP 162) via the gNB 110 during a positioning session. The location of the UE 102 may be determined by a location server, e.g., the LMF 152 or the SLP 162, in response to a Mobile Originated Location Request (MO-LR), e.g., in a UE-assisted positioning technique, using known positioning techniques such as A-GNSS, WiFi, DL-TDOA, DL-AOD, multi-cell RTT, ECID, etc., and the location server may then send the location to the UE 102 in an MO-LR response message. The location of the UE 102 may also be determined by the UE 102 without interacting with a location server, in a UE-based or standalone positioning technique, using known positioning techniques such as GNSS, A-GNSS, WiFi, DL-TDOA, DL-AOD, multi-cell RTT, ECID, etc.
[0070]
[0083] In another example, the UE 102 may determine the range to the gNB 110 based on a round trip propagation time (RTT) between the UE 102 and the gNB 110 (e.g., the propagation delay Δ is half the RTT). The RTT, and therefore the propagation delay Δ, may be measured, for example, using a Random Access Channel (RACH). To limit the RACH procedure to only UEs that have a subscription to the high-precision current time T, encryption of the gNB RACH response message may be performed using an encryption key known only to UEs that have a subscription to the high-precision current time. For example, the same encryption key may be used both to encrypt some or all of the current time as in Figures 2B-2D and to encrypt some or all of the gNB RACH response message. This may limit the load on the gNB 110 to support the RTT determination.
[0071]
[0084] FIG. 3B is similar to FIG. 3A and shows a signaling flow 350 for reliable time broadcast and acquisition in a wireless network, including an RTT procedure for determining a propagation delay Δ between the gNB 110 and the UE 102. FIG. 3B is given as a non-limiting example. For example, it will be understood that there may be additional signaling and processes, and that messages transmitted between the gNB 110 and the UE 102 may include additional components. An advantage of the procedure shown in FIG. 3B is that it may be used by a UE 102 that is in an RRC IDLE or RRC INACTIVE state, where timing advance may not be available.
[0072]
[0085] As shown, at or near a current time T, similar to message 302 shown in FIG. 3A, gNB 110 broadcasts message 352, which is received by UE 102 at time T+Δ. Message 352 may be the same as or similar to message 302 of FIG. 3A. Thus, message 352 may be included in a SIB, at least a portion of current time T may be encrypted, and message 352 may include additional information, such as an implicit or explicit local NR transmission time t at gNB 110, an implicit or explicit indication of alignment of current time T to a base station subframe or slot boundary, uncertainty of current time T, source of current time T, or a combination thereof. UE 102 may decrypt current time T, and the additional information, if encrypted, based on a previously obtained encryption key to obtain cleartext current time T (and the cleartext additional information).
[0073]
[0086] The gNB 110 may transmit a message or signal 354 to the UE 102 at a local time t at the gNB 110. The message or signal 354 may be, for example, a Synchronization Signal Block (SSB) or a Channel State Information Reference Signal (CSI-RS). The message or signal 354 may include or indicate a local time of transmission t. The UE 102 may associate a local timing at the UE, e.g., an internal timing source or internal clock of the UE 102, to the local transmission time of the gNB 110 based on the received local transmission time t and a local reception time at the UE 102 of the message or signal 354.
[0074]
[0087] In response to the message or signal 354, the UE 102 may send a message 356 to the gNB 110, which may be, for example, an RRC message that is a RACH request message. The message 356 may be transmitted by the UE 102 on the RACH for the gNB 110. The UE 102 may include a random bit string including a random variable (RV), for example, 8-16 bits, in the message 356. The message 356 is transmitted at a first time (which may correspond, for example, to a time of transmission of the start or end of the message 356), which may be either a local time of the UE or an associated local transmission time of the gNB 110. The message 356 is received by the gNB 110 at a second time, for example, local time t+2Δ. Note that FIG. 3B illustrates the first time as occurring upon receipt of the message or signal 354 at the UE 102, and thus the first time corresponds to a local time t included or indicated by the message or signal 354. However, it is also possible that the first time occurs shortly (e.g., 1-100 ms later) after arrival of the message or signal 354 at the UE 102, in which case the first time may correspond to some local transmission time of the gNB 110 that is known by the UE 102 and that is greater than t.
[0075]
[0088] The gNB 110 obtains (e.g., measures) the arrival time of the message 356 (e.g., the arrival time of the start or end of the message 356) and returns a response message 358 to the UE 102 in response to the message 356. The response message 358 may be, for example, an RRC message transmitted on a Common Control CHannel (CCCH) for the gNB 110. As explained above, to restrict the RACH procedure to only UEs that have a subscription to the high precision current time T, the response message 358 may be encrypted using an encryption key known only to UEs that have a subscription to the high precision current time. Thus, the UE 102 may decrypt some or all of the response message 358 if encrypted. The response message 358 may include a random variable (RV) from the message 356 and may include a second time, for example, the local time of receipt of the message 356 at the gNB 110 (t+2Δ in this example). Note that the send and receive times need to be measured consistently in all procedures described herein so that times of the same message fall on the same part of the message, e.g., the start or end of the message. Thus, the first and second times described here may both fall on the start of a message 356 or both fall on the end of a message 356.
[0076]
[0089] The UE 102 receives the response message 358 and knows the random variable (RV). The UE 102 can then obtain the propagation delay Δ based on the first time (e.g., the known value of t) and the second time (e.g., t+2Δ in this example) obtained from the response message 358. With the information of the propagation delay Δ, the UE 102 can add the propagation delay Δ to the current time T received in the message 352 at either the time of reception of the broadcast message 352 or the associated local time t if implicitly or explicitly included or indicated in the message 352 to obtain the correct current time T+Δ. It should be understood that the RTT procedure indicated by the messages 354, 356, and 358 (as well as any positioning procedure for determining the location of the UE 102) does not necessarily take place after the reception of the message 352. For example, the RTT procedure (or positioning procedure) is performed to obtain the propagation delay Δ, which may take place before or after the reception of the current time T. Furthermore, the RTT procedure (or positioning procedure) does not necessarily need to be performed close in time to receipt of the current time T if the UE 102 is not moving or is moving slowly.
[0077]
[0090] If the UE 102 does not receive the response message 358 (e.g., after some maximum expected response time has elapsed after transmitting the message 356), the UE 102 may retransmit the message 356 (not shown in FIG. 3B) at a later time t′ and wait to receive a response message (not shown in FIG. 3B) similar to the response message 358. This may occur if the gNB 110 does not receive the message 356 correctly, for example, due to interference or due to a transmit power from the UE 102 that is too low for the transmission of the message 356. Assuming that the gNB 110 transmits a response message similar to the response message 358 for the retransmission of the message 356, the UE 102 may use the time t′ instead of the time t to obtain the propagation delay Δ as described above.
[0078]
[0091] The reliability of the current time T received by the UE 102 may be an important consideration, especially for critical use cases. To make the current time information reliable, the UE 102 connected to the wireless network may first authenticate the wireless network using existing security mechanisms. Then, the network entity (e.g., the AMF 154 or the gNB 110) may provide the UE 102 with a public encryption key applicable to one gNB 110 (e.g., the serving gNB 110-1) or many or all of the gNBs 110. The gNB 110 may then broadcast the current time T, for example, in a SIB message 302 or 352, and include a digital signature (DigSig) to authenticate the current time T based on a corresponding private key known only to the network. The authentication may be performed only infrequently (e.g., once every minute or every five minutes) to reduce extra signaling and processing. The UE 102 may trust the received current time T if the digital signature is authenticated using a public key.
[0079]
[0092] Thus, the use of a digital signature included with the current time T may improve the reliability of the current time T. The digital signature may prevent any attacking entity from spoofing the current time T, except for, for example, a replay attack, because the attacking entity cannot include a correct digital signature in a message similar to message 302 or message 352 sent by the attacking entity toward the UE 102 if the included current time T is a future time not yet transmitted by the gNB 110. However, in a replay attack, the attacking entity may obtain the current time T broadcast from the gNB 110 and retransmit the current time T and the digital signature to the UE 102 at a later (delayed) time, thereby inducing an incorrect time in the UE 102 that is earlier than the correct current time. As an example, in FIG. 1, the attacking device 108 may receive a broadcast message including the current time T (e.g., with a digital signature) from the gNB 110-1 and send the message to the UE 102 during a replay attack. The digital signature alone cannot detect a replay attack because the digital signature is included in the message being replayed. Thus, when the UE 102 receives the replayed message from the attacking device 108, the UE 102 may believe that the current time is T+Δ, when in fact the current time may be a later time due to delays.
[0080]
[0093] FIG. 4A is similar to FIG. 3A and shows a signaling flow 400 for broadcasting and acquiring trusted time in a wireless network including a gNB 110 and a UE 102 in which an attacking device 108 is present and performing a replay attack.
[0081]
[0094] As shown, at or near (within 1 μs or 1 ms of) the current time T, the gNB 110 broadcasts a message 402 that is received by the UE 102 at or near time T+Δ. The message 402 may be the same as or similar to the messages 302 and 352 described for FIG. 3A and FIG. 3B. Thus, the message 402 may be a SIB message and may include the current time T, an optional implicit or explicit local time t, and a digital signature (DigSig). The message 402 may further include or indicate an alignment of the current time T to a base station subframe or slot boundary, an uncertainty of the current time, a source of the current time, or a combination thereof. The attacking device 108 may receive the message 402 and, after a delay Δ1, send a message 403 that is received by the UE 102 at time T+Δ+Δ1 during a replay attack. The delay Δ may include the sum of the propagation time from the gNB 110 to the attacking device 108 and the propagation time from the attacking device 108 to the UE 102. The delay Δ1 may include the delay between the receipt (e.g., initiation) of the message 402 at the attacking device 108 and the transmission (e.g., initiation) of the message 403. The message 403 may be a copy of the message 402 and thus may include the current time T (which may be at least partially encrypted by the gNB 110), as well as a digital signature (DigSig) for the gNB 110. The UE 102 may decrypt at least a portion of the current time to obtain the cleartext current time.
[0082]
[0095] In the absence of detection of the attacking device 108 by the UE 102, the UE 102 may improperly rely on the current time T received in message 403, which may have an error of at least Δ1. Thus, it may be desirable for the UE 102 to verify the authenticity of the current time T by determining that a message having the current time T was received directly from the gNB 110 rather than received via the attacking device 108, e.g., during a replay attack.
[0083]
[0096] Verification of the authenticity of the current time T may be performed by the UE 102 by periodically verifying that the propagation delay between the UE 102 and the gNB 110 is within an expected range or equal to an expected value. When the UE 102 is in an RRC CONNECTED state, the UE 102 may periodically receive a timing advance (TA) from the gNB 110, which may be used to determine the propagation delay (as half of the TA) as previously described. Because communications between the gNB 110 and the UE 102 in RRC CONNECTED may be encrypted in a manner that is impossible (or very difficult) for the attacking device 108 to decrypt or modify, the attacking device 108 may not be able to forge or spoof the timing advance, and thus, when a replay attack is performed, the UE 102 may receive the timing advance, which the UE 102 may then process as described further below to determine whether an attacking device 108 may be present.
[0084]
[0097] However, when the UE 102 is in RRC IDLE or RRC INACTIVE state, the UE 102 may not have received a timing advance from the gNB 110 and may need to measure the propagation delay to and from the gNB 110 using a procedure similar to that described for FIG. 3B, but with some additions to enable detection of the attacking device 108 when it is present. The UE 102 may then use a RACH procedure similar to that shown in FIG. 3B to periodically obtain the propagation delay Δ from the gNB 110 to the UE 102. If the attacking device 108 blocks the RACH procedure or returns an incorrect RACH response, the UE 102 may detect this (e.g., using a digital signature or lack of a RACH response) and determine the presence of the attacking device 108. For example, the gNB 110 may digitally sign, i.e., include a digital signature (DigSig), both the RACH response message and the broadcast message having the current time. Thus, for an effective attack, the attacking device 108 needs to enable the RACH procedure by acting as a man-in-the-middle. If the attacking device 108 is able to successfully perform a man-in-the-middle replay attack, the error inserted by the attacking device 108 in the propagation delay will necessarily be small, e.g., less than 100 μs or less than 10 μs, limited by the maximum possible range from the UE 102 to the gNB 110. Moreover, the UE 102 may detect spoofing even when the current time error is very small by comparing the expected propagation delay with the actual measured propagation delay, which may further reduce any possible error, e.g., to less than 1 μs. This technique is described in further detail below.
[0085]
[0098] FIG. 4B is similar to FIG. 4A and shows a signaling flow 450 for broadcast and reliable time acquisition in a wireless network in which an attacking device 108 is present and performing a replay attack, and for detecting a replay attack using an RTT procedure. FIG. 4B is given as a non-limiting example. For example, it will be understood that there may be additional signaling and processes, and that messages transmitted between the gNB 110 and the UE 102 may include additional components. The procedure in FIG. 4B for determining the RTT and propagation delay may be the same as that described for FIG. 3B from the perspective of the UE 102 and the gNB 110, except that typically in FIG. 4B there is an attacking device 108 present that affects the time and timing measurements obtained by the UE 102. An advantage of the procedure shown in FIG. 4B is that it may be used by a UE 102 that is in an RRC IDLE or RRC INACTIVE state and may not have a timing advance available.
[0086]
[0099] As shown in FIG. 4B, similar to messages 402 and 403 shown in FIG. 4A, at or near a current time T, gNB 110 broadcasts message 452, which is received by attacking device 108, copied, and transmitted to UE 102 as message 453 after delay Δ1 during a replay attack, such that UE 102 receives current time T in copied message 453 at time T+Δ+Δ1. Message 452 (and thus message 453) includes current time T, a portion of which may be encrypted, as well as an optional explicit or implicit local NR transmission time t at gNB 110, and a digital signature (DigSig). Message 452 (and thus message 453) may further include an implicit or explicit indication of alignment of current time T to a base station subframe or slot boundary, an uncertainty in current time T, a source of current time T, or a combination thereof. The UE 102 may decrypt at least a portion of the current time T to obtain the current time T in the clear.
[0087]
[0100] Similar to the RTT procedure described in FIG. 3B, the gNB 110 may transmit a message or signal 454 (e.g., an SSB message or a CSI-RS signal) to the UE 102 at a local time t at the gNB 110. The message or signal 454 is received by the attacking device 108, copied, and transmitted to the UE 102 as a message or signal 455 after a delay Δ1. The message or signal 454, and thus the message or signal 455, may include or indicate a local time t of transmission by the gNB 110, and the UE 102 may set its internal timing to match the time t from the gNB 110. It should be noted that the attacking device 108 cannot change the delay Δ1 in transmitting the message or signal 455 relative to the delay Δ1 in transmitting the message 453 and the message 459 (described below) without being detected by the UE 102, and thus the UE may infer the presence of the attacking device 108 or at least some significant error in the transmission from the gNB 110. If the attacking device 108 varies the delay Δ1, the UE 102 can detect a corresponding variation in the local transmission time t at the gNB 110 (typically conveyed implicitly or explicitly in message or signal 455 and messages 453 and 459) compared to a local time source within the UE 102. The local time source within the UE 102 may not be as accurate as the local time t in the gNB 110, but may be accurate enough to detect a significant (e.g., 10 μs or more) change in the local time t of the gNB 110 that may occur from the perspective of the UE 102 if the attacking device 108 varies the delay Δ1.
[0088]
[0101] In response to the message or signal 455, the UE 102 may send a message 456 to the gNB 110, which may be, for example, an RRC message that is a RACH request message. The message 456 may be transmitted by the UE 102 on the RACH for the gNB 110. The UE 102 may include a random bit string including a random variable (RV), for example, 8-16 bits, in the message 456. The message 456 is transmitted at a first time, which may be either a local time of the UE or an associated local transmission time of the gNB 110. The attacking device 108 may receive the message 456 and transmit a copied message 457 to the gNB 110 after a delay Δ2. Thus, the gNB 110 receives the copied message 457 at a local time t+2Δ+Δ1+Δ2, referred to herein as a second time. If the delay Δ2 is equal to the delay Δ1, then the total propagation delay Δ+Δ1 of the reception of the signal 453, including the delay 2×Δ1 inserted by the aggressor device 108, may be determined by the UE 102 based on the round trip time (RTT) between the UE 102 and the gNB 110. Thus, the delay Δ2 may be estimated to be different from Δ1. Note also that FIG. 4B (similar to FIG. 3B) illustrates the first time as occurring upon receipt of the message or signal 455 at the UE 102, and thus the first time corresponds to a time t included in or indicated by the message or signal 455. However, it is also possible that the first time occurs shortly (e.g., 1-100 ms later) after the arrival of the message or signal 455 at the UE 102, in which case the first time may correspond to some local transmission time of the gNB 110 that is known by the UE 102 and that is greater than t.
[0089]
[0102] The gNB 110 obtains (e.g., measures) the arrival time of the copied message 457 (i.e., measures a second time) and returns a response message 458, e.g., an RRC message transmitted on a CCCH for the gNB 110, to the UE 102. The response message 458 includes a random variable (RV), a digital signature (DigSig), and a second time, which in FIG. 4B is the local reception time t+2Δ+Δ1+Δ2 at the gNB 110 of the copied message 457. The response message 458 may be encrypted by the gNB 110. The attacking device 108 receives the response message 458 and transmits a message 459, which is a copy of the response message 458, to the UE 102, e.g., after a delay Δ1. By including the digital signature (DigSig) in the response message 458, it is verified that the gNB 110 originated the response message 458. Thus, the attacking device 108 cannot modify the response message 458 because the UE 102 detects the modification of the message 459 when the digital signature verification fails. Furthermore, the attacking device 108 cannot block the response message 458 because the UE 102 detects the attack because there is no response message. Thus, the UE 102 receives the copied response message 459 having a random variable (RV) and a second time (corresponding to the local time of receipt of the copied message 457 at the gNB 110, t+2Δ+Δ1+Δ2 in FIG. 4B). The UE 102 may obtain the propagation delay as Δ+(Δ1+Δ2) / 2.
[0090]
[0103] Similar to the signaling flow 350 of FIG. 3B, if the UE 102 has not received the copied response message 459 (e.g., after some maximum expected response time has elapsed after transmitting the message 456), the UE 102 may retransmit the message 456 (not shown in FIG. 4B) at a later time t′ and wait to receive a response message (not shown in FIG. 4B) similar to the copied response message 459. This may occur, for example, if the gNB 110 does not receive the copied message 457 correctly due to interference or low transmit power of either the transmission of the message 457 by the UE 102 or the transmission of the copied message 456 by the attacking device 108. Assuming that the gNB 110 transmits a response message similar to the response message 458 for the retransmission of the message 456, the UE 102 may obtain the propagation delay Δ+(Δ1+Δ2) / 2 as described above, using time t′ instead of time t.
[0091]
[0104] If the attacking device 108 inserts too large delays Δ1 and / or Δ2 into the propagation delay, the UE 102 can detect the attack. For example, wireless cells have a limited size that limits the possible amount of propagation time. The maximum possible range between the UE 102 and the gNB 110 without relays may be, for example, 30 km based on a large cell size, which translates to a propagation delay of about 100 μs. When relays are present, which may typically only occur in rural areas, the maximum possible range may increase (e.g., to 100 km), in which case the UE 102 can adjust its expectation of the maximum possible range based on the known environment (e.g., urban, suburban, or rural) or the approximate known location of the UE 102, which may be configured for the UE 102 by the network operator or UE vendor. Thus, if the UE 102 detects a total propagation delay greater than 100 μs and no relays are present, the UE 102 can infer that the attacking device may have inserted additional delays into the propagation delay and therefore the current time T received in message 453 is unreliable and should be discarded. The UE 102 may further use a smaller or larger threshold to detect the attack, e.g., 10 μs in an urban or suburban environment, or 1 ms in a rural environment where relays may be present. Thus, to avoid detection, the attacking device 108 cannot block the procedure shown in FIG. 4B or spoof the response message 458, so that the amount of error that the attacking device 108 can insert into the propagation delay is limited to less than the threshold used by the UE 102 to verify the propagation delay, which may be 10-100 μs in most environments.
[0092]
[0105] In addition, if the UE 102 knows its own location, e.g., from a previous position estimate, and knows the location of the gNB 110, the UE 102 can independently determine an expected propagation delay Δ based on the distance between the two locations. The UE 102 can then detect spoofing by the attacking device 108 based on a discrepancy between the expected value of the propagation delay Δ and the actual value of the propagation delay Δ (obtained, e.g., according to the procedure of FIG. 4B or using a timing advance). If the discrepancy is greater than a threshold, e.g., 1 μs, the UE 102 can determine that the attacking device may have inserted an additional delay in the propagation delay, and thus the current time T received in the message 453 is unreliable and should be discarded. With this additional location-based verification, the UE 102 can verify the presence or absence of the attacking device 108 with a high probability, since the delay added by the attacking device 108 (due to a replay or man-in-the-middle attack) is typically much greater than the threshold (e.g., 1 μs) used by the UE 102 to verify the actual measured propagation delay.
[0093]
[0106] As previously explained, when the propagation delay is obtained by the UE 102 using the timing advance value provided by the gNB 110 to the UE 102 when the UE 102 is in the RRC CONNECTED state, the comparison between the measured propagation delay and the expected propagation delay as described above may also be performed by the UE 102. If the attacking device is performing a man-in-the-middle attack against the UE 102, the timing advance provided by the gNB 110 to the UE 102 also includes the delays Δ1 and Δ2, since all signaling between the UE 102 and the gNB 110 is received, copied, and forwarded by the attacking device 108 (e.g., as shown in FIG. 4B ) and the timing advance decision by the gNB 110 includes the delay added by the attacking device 108. The UE 102 can then obtain the propagation delay as half the timing advance and compare this to an expected value based on the maximum possible range between the UE 102 and the gNB 110, or a calculated range between the UE 102 and the gNB 110 based on the known locations of the UE 102 and the gNB 110. The inference of the presence of an attacking device 108 can then be exactly the same as previously described for the RTT procedure of FIG.
[0094]
[0107] It should be noted that the UE 102 can use the RTT between the UE 102 and the gNB 110 (e.g., for the procedure of FIG. 4B) instead of the propagation delay as a means for determining the presence or absence of an attacking device 108. The RTT is twice the propagation delay and therefore may be measured or obtained by the UE 102 similar to the propagation delay. Similarly, the expected range of the RTT is twice the expected range of the propagation delay. Thus, various statements herein regarding the use of propagation delay to detect the presence of an attacking device 108 may also be applied to the use of the RTT.
[0095]
[0108] FIG. 5 shows a signaling flow 500 for broadcasting and acquiring trusted time in a wireless network including a UE 102, a gNB 110, and an LMF 152, as well as detection of replay attacks by an attacking device 108.
[0096]
[0109] In stage 1, the UE 102 determines an expected range between the UE 102 and the gNB 110. The expected range determination may be based on known locations of the UE 102 and the gNB 110, for example. The location of the UE 102 may be determined by the UE 102 using a positioning session between the UE 102 and the LMF 152 (or the SLP 162, not shown in FIG. 5), using known positioning techniques such as DL-TDOA, DL-AOD, multi-cell RTT, A-GNSS, WiFi, ECID, etc., or by the LMF 152 (which may then provide the location to the UE 102). The UE 102 may obtain the location of the gNB 110 from the LMF 152 (or from the SLP 162), from the gNB 110 (e.g., if included by the gNB 110 in a message containing the current time T or other broadcast message), or from information available from an Internet web server for the PLMN for which the gNB location has been approximately determined. Thereby, in some implementations, the UE 102 may determine the expected range between the UE 102 and the gNB 110. In other implementations, the LMF 152 may determine the expected range and provide the expected range to the UE 102.
[0097]
[0110] In stage 2, the gNB110 broadcasts the current time T along with an implicit or explicit indication of the local transmission time t at the gNB110 and a digital signature (DigSig), for example in a SIB message, which may be received and stored by the attacking device 108.
[0098]
[0111] In stage 3, the attacking device 108 sends a copy of the SIB message having a current time T to the UE 102 after a delay Δ1, along with an implicit or explicit indication of the local transmission time t and a digital signature (DigSig).
[0099]
[0112] In stage 4, the UE 102 obtains the total propagation delay between the UE 102 and the gNB 110, including the delay inserted by the aggressor device (e.g., Δ+(Δ1+Δ2) / 2). The total propagation delay may, for example, be measured as described in FIG. 4B (e.g., when the UE 102 is in an RRC IDLE or RRC INACTIVE state) or may be determined by the UE 102 from the timing advance provided by the gNB 110 (e.g., when the UE 102 is in an RRC CONNECTED state).
[0100]
[0113] In stage 5, the UE 102 may detect the presence of the attacking device 108 based on the expected range obtained in stage 1 and the total propagation delay (e.g., Δ+(Δ1+Δ2) / 2) measured in stage 4. For example, the expected propagation delay may be determined based on the expected range between the UE 102 and the gNB 110, and the expected propagation delay may be compared to the actual propagation delay from stage 4. A discrepancy greater than a threshold (e.g., 100 μs, 10 μs, or 1 μs) may indicate the presence of the attacking device and unreliability of the current time received in stage 2. In another example, the actual range may be determined based on the total propagation delay measured in stage 4 and compared to the expected range between the UE 102 and the gNB 110. A discrepancy greater than a threshold distance (e.g., 30 km, 3 km, or 300 meters) may indicate the presence of the attacking device and unreliability of the current time received in stage 2.
[0101]
[0114] Thus, the UE 102 may receive an accurate current time in the wireless network and may verify that the current time is reliable. If spoofing occurs, the UE 102 may detect the spoofing and thus know that the received current time is unreliable, or the amount of error successfully inserted by the spoofing may be minimal (e.g., less than 100 μs, 10 μs, or 1 μs) and may not significantly impair the current time obtained by the UE 102.
[0102]
[0115] FIG. 6 illustrates a schematic block diagram illustrating certain example features of a UE 600, which may be, for example, the UE 102 illustrated in FIGS. 1, 3A, 3B, 4A, 4B, and 5, configured to support obtaining current time from a wireless network as described herein. The UE 600 may execute, for example, the signal flows illustrated in FIGS. 3A, 3B, 4A, 4B, and 5, the process flows illustrated in FIG. 8, and the algorithms disclosed herein. The UE 600 may include, for example, one or more processors 602, memory 604, an external interface such as at least one wireless transceiver (e.g., wireless network interface) illustrated as a WWAN transceiver 610 and a WLAN transceiver 612, an SPS receiver 615, and one or more sensors 613, which may be operatively coupled to a non-transitory computer-readable medium 620 and memory 604 with one or more connections 606 (e.g., buses, wires, fibers, links, etc.). The SPS receiver 615 may receive and process SPS signals, for example, from the SV190 shown in FIG. 1. The one or more sensors 613 may be, for example, an Inertial Measurement Unit (IMU), which may include one or more accelerometers, one or more gyroscopes, magnetometers, etc. The UE 600 may further include additional items not shown, such as a user interface, which may include a display, a keypad, or other input devices, such as a virtual keypad on a display, through which a user may interface with the UE. In certain example implementations, all or a portion of the UE 600 may be in the form of a chipset and / or the like.
[0103]
[0116] The at least one wireless transceiver may be a transceiver 610 for a WWAN communication system and a transceiver 612 for a WLAN communication system, or may be a combined transceiver for both WWAN and WLAN. The WWAN transceiver 610 may include a transmitter 610t and a receiver 610r coupled to one or more antennas 611 to transmit (e.g., on one or more uplink channels and / or one or more sidelink channels) and / or receive (e.g., on one or more downlink channels and / or one or more sidelink channels) wireless signals and convert signals from wireless signals to wired (e.g., electrical and / or optical) signals and from wired (e.g., electrical and / or optical) signals to wireless signals. The WLAN transceiver 612 may include a transmitter 612t and a receiver 612r coupled to one or more antennas 611 or separate antennas to transmit (e.g., on one or more uplink channels and / or one or more sidelink channels) and / or receive (e.g., on one or more downlink channels and / or one or more sidelink channels) wireless signals and convert signals from wireless to wired (e.g., electrical and / or optical) signals and from wired (e.g., electrical and / or optical) signals to wireless signals. The transmitters 610t and 612t may include multiple transmitters, which may be separate components or combined / integrated components, and / or the receivers 610r and 612r may include multiple receivers, which may be separate components or combined / integrated components.The WWAN transceiver 610 may be configured to communicate signals (e.g., with base stations and / or one or more other devices) in accordance with various radio access technologies (RATs), such as 6G New Radio (NR), Global System for Mobiles (GSM), Universal Mobile Telecommunications System (UMTS), Advanced Mobile Phone System (AMPS), Code Division Multiple Access (CDMA), Wideband CDMA (WCDMA), Long-Term Evolution (LTE), LTE Direct (LTE-D), 3GPP LTE-V2X (PC5), etc. New Radio (NR) may use mmWave and / or sub-6 GHz frequencies. The WLAN transceiver 612 may be configured to communicate signals (e.g., with an access point and / or one or more other devices) in accordance with various radio access technologies (RATs), such as 3GPP LTE-V2X (PC5), IEEE 802.11 (including IEEE 802.11p), WiFi, WiFi Direct (WiFi-D), Bluetooth, Zigbee, etc. The transceivers 610 and 612 may be communicatively coupled to a transceiver interface, e.g., by an optical connection and / or an electrical connection, which may be at least partially integrated with the transceivers 610 and 612.
[0104]
[0117] In some embodiments, the UE 600 may include an antenna 611, which may be internal or external. The UE antenna 611 may be used to transmit and / or receive signals that are processed by the wireless transceivers 610 and 612. In some embodiments, the UE antenna 611 may be coupled to the wireless transceivers 610 and 612. In some embodiments, measurements of signals received (transmitted) by the UE 600 may be performed at the connection point between the UE antenna 611 and the wireless transceivers 610 and 612. For example, the measurement reference points of the received (transmitted) RF signals may be the input (output) terminal of the receiver 610r (transmitter 610t) and the output (input) terminal of the UE antenna 611. In a UE 600 equipped with multiple UE antennas 611 or an antenna array, the antenna connectors may be considered as virtual points representing the aggregate output (input) of the multiple UE antennas. In some embodiments, the UE 600 may measure the received signals, including signal strength and TOA measurements, and the raw measurements may be processed by one or more processors 602.
[0105]
[0118] The one or more processors 602 may be implemented using a combination of hardware, firmware, and software. For example, the one or more processors 602 may be configured to perform functions described herein by implementing one or more instructions or program code 608 on a non-transitory computer-readable medium, such as the medium 620 and / or the memory 604. In some embodiments, the one or more processors 602 may represent one or more circuits configurable to perform at least a portion of a data signal computation procedure or process associated with the operation of the UE 600.
[0106]
[0119] The medium 620 and / or memory 604 may store instructions or program code 608, including executable code or software instructions that, when executed by the one or more processors 602, cause the one or more processors 602 to operate as a special purpose computer programmed to perform the techniques disclosed herein. As shown in the UE 600, the medium 620 and / or memory 604 may include one or more components or modules that may be implemented by the one or more processors 602 to perform the methods described herein. Although the components or modules are shown as software in the medium 620 executable by the one or more processors 602, it should be understood that the components or modules may be stored in the memory 604 or may be dedicated hardware either within or external to the one or more processors 602.
[0107]
[0120] A number of software modules and data tables may reside in the medium 620 and / or memory 604 and be utilized by the one or more processors 602 to manage both the communications and functionality described herein. It should be understood that the organization of the contents of the medium 620 and / or memory 604 as shown in the UE 600 is merely exemplary, and thus the functionality of the modules and / or data structures may be combined, separated, and / or structured in different ways depending on the implementation of the UE 600.
[0108]
[0121] The medium 620 and / or memory 604 may include a current time module 622 that, when executed by the one or more processors 602, configures the one or more processors 602 to receive, for example, via the wireless transceiver 610, a current time in a message, such as a SIB message broadcast by the base station. The one or more processors 602 may be further configured to determine a corrected current time based on the received current time and the determined propagation delay. At least a portion of the current time may be encrypted. The current time may be, for example, UTC time, GPS time, GLONASS time, Beidou time, Galileo time, GNSS time. The message may further include a local transmission time for the base station. The one or more processors 602 may be further configured to receive additional information in the message, such as at least one of an alignment of the current time to a base station subframe or slot boundary, an uncertainty of the current time, a source of the current time, or a combination thereof. The one or more processors 602 may be further configured to receive a digital signature of the base station in the message.
[0109]
[0122] The medium 620 and / or memory 604 may include a security module 624 that, when executed by the one or more processors 602, configures the one or more processors 602 to decrypt a message from the base station including at least a portion of the current time to obtain a cleartext current time and / or to decrypt a message received from the base station to determine a propagation delay between the UE and the base station. The one or more processors 602 may be further configured to authenticate a message sent from the base station based on a digital signature for the base station included in the message. The one or more processors 602 may be configured to receive a public encryption key for the base station from the wireless network, e.g., via the wireless transceiver 610, after, e.g., connecting to and authenticating the wireless network, the public encryption key may be used to decrypt the message and the digital signature.
[0110]
[0123] The medium 620 and / or the memory 604 may include a propagation delay module 626 that, when executed by the one or more processors 602, configures the one or more processors 602 to determine a propagation delay between a base station and a UE. For example, the one or more processors 602 may be configured to receive a timing advance from a base station over the air and use the timing advance as a propagation delay, i.e., the propagation delay is equal to the timing advance. In another example, the one or more processors 602 may obtain the UE location and the base station location, for example, from a positioning session and determine the propagation delay based on a distance between the UE location and the base station location. The one or more processors 602 may be configured to obtain the UE location and the base station location by being configured to receive a broadcast from the base station in a SIB having the base station location, receive an LPP assistance data message including the base station location, receive an MO-LR response message including the UE location, perform a positioning session to determine the UE location, or a combination thereof. In another example, the one or more processors 602 may be configured to measure an RTT between the UE and the base station and determine the propagation delay based on half the RTT. For example, the one or more processors 602 may be configured to perform the RTT procedures shown in Figures 3B and 4B. The one or more processors 602 may be configured to receive, via the transceiver 610, a first message from the base station including a local transmit time for the base station, and may associate a local timing at the UE with the local transmit time for the base station, e.g., based on the received local transmit time for the base station and a local time of receipt of the message at the UE. The one or more processors 602 may be configured to transmit, via the transceiver 610, a second message, such as a RACH request message including a random variable, to the base station, and in response, receive, via the transceiver 610, a third message, e.g., a RACH response message, from the base station including the random variable and the local transmit time for the base station at which the request message was received at the base station.The third message may be encrypted and may include a digital signature for the base station. The one or more processors 602 may be configured to determine the RTT based on the first time and the time provided by the base station in the third message.
[0111]
[0124] The medium 620 and / or the memory 604 may include a positioning session module 628 that, when executed by the one or more processors 602, configures the one or more processors 602 to engage in a positioning session including receiving a positioning capability request message through a serving base station, e.g., with a location server via the wireless transceiver 610, receiving positioning assistance data and / or broadcast location information from the base station, receiving a request for location information, and performing positioning measurements of PRS signals, such as TDOA, AOD, multi-RTT, ECID, etc., received from one or more base stations, and reporting location information, e.g., positioning measurements for a UE-assisted positioning process or determining a position estimate for a UE-based positioning process.
[0112]
[0125] The medium 620 and / or memory 604 may include an attack detection module 630 that, when executed by the one or more processors 602, configures the one or more processors 602 to detect a presence of an attacking device in a wireless network. The presence of the attacking device may be detected based on a measured RTT where the propagation delay is determined to be outside of an expected range. The expected range may be, for example, a maximum RTT value based on a maximum expected distance to a base station. The expected range may be determined, for example, based on a determined distance between an estimated location of the UE, e.g., determined in a positioning session, and the location of the base station.
[0113]
[0126] The methods described herein may be implemented by various means depending on the application. For example, the methods may be implemented in hardware, firmware, software, or any combination thereof. In the case of a hardware implementation, the one or more processors 602 may be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described herein, or combinations thereof.
[0114]
[0127] For firmware and / or software implementations, the methods may be implemented with modules (e.g., procedures, functions, etc.) that perform the functions described herein. Any machine-readable medium tangibly embodying instructions may be used to implement the methods described herein. For example, software code may be stored in a non-transitory computer-readable medium 620 or memory 604 coupled to and executed by one or more processors 602. The memory may be implemented within the one or more processors or external to the one or more processors. The term "memory" as used herein refers to any type of long-term memory, short-term memory, volatile memory, non-volatile memory, or other memory, and is not limited to a particular type or number of memories, or to a particular type of medium on which the memory is stored.
[0115]
[0128] If implemented in firmware and / or software, the functions may be stored as one or more instructions or program code 608 on a non-transitory computer readable medium, such as the medium 620 and / or memory 604. Examples include computer readable media encoded with data structures and computer readable media encoded with computer program code 608. For example, a non-transitory computer readable medium with program code 608 stored thereon may include program code 608 for supporting a UE obtaining a current time from a wireless network using methods consistent with the disclosed embodiments. The non-transitory computer readable medium 620 includes physical computer storage media. A storage medium may be any available medium that can be accessed by a computer. By way of example and not limitation, such non-transitory computer readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code 608 in the form of instructions or data structures and that can be accessed by a computer. As used herein, "disk" and "disc" include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, although a "disk" typically reproduces data magnetically and a "disc" reproduces data optically using a laser. Combinations of the above are also intended to be included within the scope of computer-readable media.
[0116]
[0129] In addition to being stored on the computer-readable medium 620, the instructions and / or data may be provided as signals on a transmission medium contained within a communications device. For example, a communications device may include a wireless transceiver 610 having signals indicative of the instructions and data. The instructions and data are configured to cause one or more processors to perform functions outlined in the claims. That is, the communications device includes a transmission medium having signals indicative of information to perform the disclosed functions.
[0117]
[0130] Memory 604 may represent any data storage mechanism. Memory 604 may include, for example, primary memory and / or secondary memory. Primary memory may include, for example, random access memory, read-only memory, etc. Although shown in this example as separate from one or more processors 602, it should be understood that all or a portion of the primary memory may be provided within one or more processors 602 or may otherwise be co-located / coupled thereto. Secondary memory may include, for example, the same or similar type of memory as the primary memory, and / or one or more data storage devices or systems, such as, for example, disk drives, optical disk drives, tape drives, solid-state memory drives, etc.
[0118]
[0131] In certain implementations, the secondary memory may operably receive or be otherwise configurable to couple to a non-transitory computer-readable medium 620. Thus, in certain example implementations, the methods and / or apparatuses presented herein may take the form of a computer-readable medium 620 that may include computer-implementable program code 608 stored thereon, in whole or in part, which when executed by one or more processors 602 may be operably enabled to perform all or a portion of the example operations as described herein. The computer-readable medium 620 may be part of the memory 604.
[0119]
[0132] FIG. 7 shows a schematic block diagram illustrating certain example features of a base station 700, which may be a gNB, ng-eNB (e.g., an eNB (e.g., ng-eNB 114) or an eNB, e.g., the gNB 110 shown in FIGS. 1, 3A, 3B, 4A, 4B, and 5. The base station 700 is configured to support broadcasting of a current time and acquisition of the current time by a UE, e.g., as described herein. The base station 700 may be ... 9 and the algorithms disclosed herein. The base station 700 may be operatively coupled to a non-transitory computer-readable medium 720 and memory 704 with one or more connections 706 (e.g., a bus, a line, a fiber, a link, etc.), such as one or more processors 702, memory 704, a transceiver 710 (e.g., a wireless network interface), and an external interface 716 (e.g., to other base stations and / or a core network). The base station 700 may further include additional items not shown, such as a user interface, which may include a display, a keypad, or other input device, such as a virtual keypad on a display, through which a user may interface with a UE. In certain exemplary implementations, all or a portion of the base station 700 may be in the form of a chipset and / or the like. The transceiver 710 may include, for example, a transmitter 712 enabled to transmit one or more signals over one or more types of wireless communication networks, and a receiver 714 for receiving one or more signals transmitted over one or more types of wireless communication networks. The external interface 716 may be a wired or wireless interface connectable to other base stations in the RAN or network entities, such as the AMF 154 and LMF 152 shown in FIG. 1.The SPS receiver 715 may receive and process SPS signals, for example, from the SV 190 shown in FIG. 1, to obtain a current time, such as, for example, UTC time, GPS time, GLONASS time, Beidou time, Galileo time, and GNSS time.
[0120]
[0133] In some embodiments, the base station 700 may include an antenna 711, which may be internal or external. The antenna 711 may be used to transmit and / or receive signals that are processed by the transceiver 710. In some embodiments, the antenna 711 may be coupled to the transceiver 710. In some embodiments, measurements of signals received (transmitted) by the base station 700 may be performed at the connection point of the antenna 711 and the transceiver 710. For example, the measurement reference points of the received (transmitted) RF signal may be the input (output) terminal of the receiver 714 (transmitter 712) and the output (input) terminal of the antenna 711. In a base station 700 equipped with multiple antennas 711 or an antenna array, the antenna connector may be considered to be a virtual point representing the aggregate output (input) of the multiple antennas. In some embodiments, the base station 700 may measure the received signals, including signal strength and TOA measurements, and the raw measurements may be processed by one or more processors 702.
[0121]
[0134] The one or more processors 702 may be implemented using a combination of hardware, firmware, and software. For example, the one or more processors 702 may be configured to perform functions described herein by implementing one or more instructions or program code 708 on a non-transitory computer-readable medium, such as the medium 720 and / or the memory 704. In some embodiments, the one or more processors 702 may represent one or more circuits configurable to perform at least a portion of a data signal computation procedure or process associated with the operation of the base station 700.
[0122]
[0135] The medium 720 and / or memory 704 may store instructions or program code 708, including executable code or software instructions that, when executed by the one or more processors 702, cause the one or more processors 702 to operate as a special-purpose computer programmed to perform the techniques disclosed herein. As shown in the base station 700, the medium 720 and / or memory 704 may include one or more components or modules that may be implemented by the one or more processors 702 to perform the methods described herein. Although the components or modules are shown as software in the medium 720 executable by the one or more processors 702, it should be understood that the components or modules may be stored in the memory 704 or may be dedicated hardware either within or external to the one or more processors 702.
[0123]
[0136] A number of software modules and data tables may reside in the medium 720 and / or memory 704 and be utilized by the one or more processors 702 to manage both the communications and functionality described herein. It should be understood that the organization of the contents of the medium 720 and / or memory 704 as shown in the base station 700 is merely exemplary, and thus the functionality of the modules and / or data structures may be combined, separated, and / or structured in different manners depending on the implementation of the base station 700.
[0124]
[0137] The medium 720 and / or memory 704 may include a current time module 722 that, when executed by the one or more processors 702, configures the one or more processors 702 to obtain a current time, for example, from the SV 190 via the SPS receiver 715 or from a network entity such as the AMF 154 via the external interface 716. The current time may be, for example, UTC time, GPS time, GLONASS time, Beidou time, Galileo time, GNSS time. The one or more processors 702 may be further configured to broadcast the current time in a message, such as a SIB message, for example, via the wireless transceiver 710. At least a portion of the current time may be encrypted. The broadcast message may further include a local transmit time for the base station. The one or more processors 702 may be further configured to broadcast additional information in the message, such as at least one of an alignment of the current time to a subframe or slot boundary, an uncertainty of the current time, a source of the current time, or a combination thereof. The one or more processors 702 may be further configured to broadcast a message having a digital signature for the base station.
[0125]
[0138] The medium 720 and / or memory 704 may include a security module 724 that, when executed by the one or more processors 702, configures the one or more processors 702 to encrypt a message from the base station including at least a portion of a current time and / or a message transmitted to the UE to determine a propagation delay between the UE and the base station. The one or more processors 702 may be further configured to include a digital signature for the base station in the one or more messages to the UE. The one or more processors 702 may be further configured to transmit, via the transceiver 710, a public encryption key for the base station to the UE, the digital signature being based on a private encryption key corresponding to the public encryption key.
[0126]
[0139] The medium 720 and / or the memory 704 may include a propagation delay module 726 that, when executed by the one or more processors 702, configures the one or more processors 702 to assist the UE in determining a propagation delay. For example, the one or more processors 702 may be configured to obtain and transmit a timing advance via wireless to the UE, where the propagation delay is equal to the timing advance. In another example, the one or more processors 702 may send a message to the UE including at least one of the location of the UE and the location of the base station, where the propagation delay may be determined based on a distance between the location of the UE and the location of the base station. The one or more processors 702 may be configured, for example, to broadcast the location of the base station in a SIB, forward an LPP assistance data message including the location of the base station, send an MO-LR response message to the UE including the location of the UE, pass an LPP message between the UE and a location execution for the UE to determine the location of the UE, or a combination thereof. In another example, the one or more processors 702 may be configured to assist the UE in measuring an RTT between the UE and the base station, where the propagation delay is equal to half the RTT. For example, the one or more processors 702 may be configured to perform the RTT procedures shown in Figures 3B and 4B. The one or more processors 702 may be configured to transmit, via the transceiver 710, a first message to the UE having a local transmission time for the base station. The one or more processors 702 may be configured to receive, via the transceiver 710, a second message from the UE, such as a RACH request message including a random variable, and in response, transmit, via the transceiver 710, a third message, e.g., a RACH response message, to the UE, including the random variable and the local transmission time at which the base station received the request message. The third message may be encrypted and may include a digital signature for the base station.
[0127]
[0140] The medium 720 and / or memory 704 may include a positioning session module 728 that, when executed by the one or more processors 702, configures the one or more processors 702 to engage in a positioning session with a UE and a location server, e.g., via the wireless transceiver 710 and the external interface 716. The positioning session may include, e.g., forwarding LPP positioning messages, sending PRS signals to the UE for measurement and / or receiving and measuring uplink PRS signals from the UE, and forwarding UL measurements to the location server via the external interface 716 or to the UE via the transceiver 710.
[0128]
[0141] The methods described herein may be implemented by various means depending on the application. For example, the methods may be implemented in hardware, firmware, software, or any combination thereof. In the case of a hardware implementation, the one or more processors 702 may be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described herein, or combinations thereof.
[0129]
[0142] For firmware and / or software implementations, the methods may be implemented with modules (e.g., procedures, functions, etc.) that perform the functions described herein. Any machine-readable medium tangibly embodying instructions may be used to implement the methods described herein. For example, software code may be stored in a non-transitory computer-readable medium 720 or memory 704 coupled to and executed by one or more processors 702. The memory may be implemented within the one or more processors or external to the one or more processors. The term "memory" as used herein refers to any type of long-term memory, short-term memory, volatile memory, non-volatile memory, or other memory, and is not limited to a particular type or number of memories, or to a particular type of medium on which the memory is stored.
[0130]
[0143] If implemented in firmware and / or software, the functions may be stored as one or more instructions or program code 708 on a non-transitory computer readable medium, such as the medium 720 and / or memory 704. Examples include computer readable media encoded with data structures and computer readable media encoded with computer program code 708. For example, a non-transitory computer readable medium with program code 708 stored thereon may include program code 708 for supporting broadcasting of a current time and informing a UE of the current time using methods consistent with the disclosed embodiments. The non-transitory computer readable medium 720 includes physical computer storage media. The storage media may be any available medium that can be accessed by a computer. By way of example and not limitation, such non-transitory computer readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code 708 in the form of instructions or data structures and that can be accessed by a computer. As used herein, "disk" and "disc" include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, although a "disk" typically reproduces data magnetically and a "disc" reproduces data optically using a laser. Combinations of the above are also intended to be included within the scope of computer-readable media.
[0131]
[0144] In addition to being stored on the computer-readable medium 720, the instructions and / or data may be provided as signals on a transmission medium contained within a communications device. For example, a communications device may include a transceiver 710 having signals indicative of the instructions and data. The instructions and data are configured to cause one or more processors to perform the functions outlined in the claims. That is, the communications device includes a transmission medium having signals indicative of information to perform the disclosed functions.
[0132]
[0145] Memory 704 may represent any data storage mechanism. Memory 704 may include, for example, primary memory and / or secondary memory. Primary memory may include, for example, random access memory, read-only memory, etc. Although shown in this example as separate from one or more processors 702, it should be understood that all or a portion of the primary memory may be provided within one or more processors 702 or may otherwise be co-located / coupled thereto. Secondary memory may include, for example, the same or similar type of memory as the primary memory, and / or one or more data storage devices or systems, such as, for example, disk drives, optical disk drives, tape drives, solid-state memory drives, etc.
[0133]
[0146] In certain implementations, the secondary memory may operably receive or be otherwise configurable to couple to a non-transitory computer-readable medium 720. Thus, in certain example implementations, the methods and / or apparatuses presented herein may take the form of a computer-readable medium 720 that may include computer-implementable program code 708 stored thereon, in whole or in part, which when executed by one or more processors 702 may be operably enabled to perform all or a portion of the example operations as described herein. The computer-readable medium 720 may be part of the memory 704.
[0134]
[0147] FIG. 8 illustrates a flowchart of an example method 800 for supporting reliable time acquisition by a user equipment (UE) in a wireless network, such as user equipment (UE) 102 shown in FIGS. 1, 3A, 3B, 4A, 4B, 5, and 6, performed by a UE using a method consistent with the disclosed implementations.
[0135]
[0148] In block 802, the UE receives a message broadcast from a base station (e.g., gNB 110 or ng-eNB 114), the message including a current time, with at least a portion of the current time being encrypted, as shown, for example, in message 302 of FIG. 3A, message 352 of FIG. 3B, messages 402 and 403 of FIG. 4A, and messages 452 and 453 of FIG. 4B. The current time may include, for example, a Coordinated Universal Time (UTC) time, a Global Positioning System (GPS) time, a GLONASS time, a Beidou time, a Galileo time, a Global Navigation Satellite System (GNSS) time, or a local regional time. The message may further include at least one of an implicit or explicit alignment of the current time to a base station subframe or slot boundary, an uncertainty of the current time, a source of the current time, or a combination thereof, as described, for example, for FIG. 2E. A means for receiving a message broadcasted from a base station, where the message includes a current time and where at least a portion of the current time is encrypted, may include, for example, a wireless transceiver 610 and one or more processors 602 in a UE 600, as shown in FIG. 6, which may include dedicated hardware or execute executable code or software instructions in a memory 604 and / or a medium 620, for example, in a current time module 622.
[0136]
[0149] In block 804, the UE obtains the cleartext current time by decrypting at least a portion of the current time, e.g., as described in Figures 2B-2E, 3A, 3B, 4A, and 4B. Means for obtaining the cleartext current time by decrypting at least a portion of the current time may comprise dedicated hardware or include one or more processors 602 executing executable code or software instructions in memory 604 and / or medium 620, e.g., in security module 624, e.g., in the UE 600, as shown in Figure 6.
[0137]
[0150] In block 806, the UE determines a propagation delay between the base station and the UE, e.g., as described in Figures 3A, 3B, 4A and 4B. Means for determining a propagation delay between the base station and the UE may include, e.g., as shown in Figure 6, in the UE 600, a wireless transceiver 610 and one or more processors 602 with dedicated hardware or executing executable code or software instructions in the memory 604 and / or medium 620, e.g., in a propagation delay module 626.
[0138]
[0151] In block 808, the UE determines a corrected current time based on the plaintext current time and the propagation delay, for example, as described in Figures 3A, 3B, 4A, and 4B. Means for determining a corrected current time based on the plaintext current time and the propagation delay may comprise dedicated hardware or include one or more processors 602 executing executable code or software instructions in memory 604 and / or medium 620, for example, in security module 624, in UE 600, as shown in Figure 6.
[0139]
[0152] In one implementation, the UE may determine the propagation delay by obtaining a timing advance from a base station, where the propagation delay is determined from the timing advance (e.g., determined as half the value of the timing advance), as described in, for example, Figures 3A and 3B. Means for obtaining a timing advance from a base station, where the propagation delay is determined from the timing advance, may include, for example, a wireless transceiver 610 and one or more processors 602 in the UE 600, as shown in Figure 6, with dedicated hardware or executing executable code or software instructions in the memory 604 and / or medium 620, for example, in a propagation delay module 626.
[0140]
[0153] In one implementation, the UE may determine the propagation delay by obtaining the UE location and the base station location, where the propagation delay is determined based on the distance between the UE location and the base station location, for example, as described in Figures 3A, 3B, 4A, and 4B. Means for obtaining the UE location and the base station location, where the propagation delay is determined based on the distance between the UE location and the base station location, may include, for example, in the UE 600, a wireless transceiver 610 and one or more processors 602 that have dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in a propagation delay module 626, as shown in Figure 6. As described with respect to FIG. 3A, the UE may obtain the UE location and the base station location by at least one of receiving a broadcast of the base station location in a system information block (SIB) from the base station, receiving a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the base station location, receiving a Mobile Originated Location Information Request (MO-LR) Response message including the UE location, or performing a positioning session to determine the UE location. Means for receiving a broadcast of the base station location in a system information block (SIB) from the base station may include, for example, a wireless transceiver 610 and one or more processors 602 in the UE 600, which may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in a positioning session module 628, as shown in FIG. 6.Means for receiving a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station may include, for example, in the UE 600, a wireless transceiver 610 and one or more processors 602 that comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in the positioning session module 628, as shown in FIG. 6. Means for receiving a Mobile Originated Location Information Request (MO-LR) Response message including the location of the UE may include, for example, in the UE 600, a wireless transceiver 610 and one or more processors 602 that comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in the positioning session module 628, as shown in FIG. 6. A means for performing a positioning session to determine a location of the UE may include, for example, as shown in FIG. 6, in the UE 600, a wireless transceiver 610 and one or more processors 602 that may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or medium 620, for example, in a positioning session module 628.
[0141]
[0154] In one implementation, the UE may determine the propagation delay by measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT, for example, as described in Figures 3A, 3B, 4A and 4B. A means for measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT, may include, for example, a wireless transceiver 610 and one or more processors 602 in the UE 600, as shown in Figure 6, which may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in a propagation delay module 626.
[0142]
[0155] In one implementation, the UE may measure the RTT by receiving a first message from the base station indicating a first local transmission time for the base station, for example, as illustrated by message 354 in FIG. 3B and message 455 in FIG. 4B. Means for receiving a first message from the base station indicating a first local transmission time for the base station may include, for example, a wireless transceiver 610 and one or more processors 602 in the UE 600, which may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in the propagation delay module 626, as illustrated in FIG. 6. The UE may associate a local timing at the UE to a local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE, for example, as described in FIG. 3B and FIG. 4B. Means for associating a local timing at the UE with a local transmit time for the base station based on a first local transmit time for the base station and a local time of receipt of the first message at the UE may include, for example, in the UE 600, a wireless transceiver 610 and one or more processors 602 with dedicated hardware or executing executable code or software instructions in the memory 604 and / or medium 620, for example, in a propagation delay module 626, as shown in Figure 6. The UE may transmit a second message to the base station on a random access channel (RACH), the second message including a random variable, the second message transmitted at a first time, the first time being either the local time at the UE or the associated local transmit time for the base station, for example, as shown by message 356 in Figure 3B and message 456 in Figure 4B.Means for transmitting a second message to a base station on a random access channel (RACH), where the second message includes a random variable and is transmitted at a first time, where the first time is either a local time at the UE or an associated local transmit time for the base station, may include, for example, a wireless transceiver 610 and one or more processors 602, including dedicated hardware or executing executable code or software instructions in the memory 604 and / or medium 620, for example, in a propagation delay module 626, in a UE 600, as shown in FIG. 6. The UE may receive a third message from the base station in response to the second message, where the third message includes a second time and the random variable, where the second time is a local transmit time for the base station at which the second message was received at the base station, for example, as shown by message 358 in FIG. 3B and message 459 in FIG. 4B. Means for receiving a third message from the base station in response to the second message, the third message including a second time and a random variable, the second time being a local transmission time for the base station at which the second message was received at the base station, may include, for example, a wireless transceiver 610 and one or more processors 602 in the UE 600, which may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in the propagation delay module 626, as shown in FIG. 6. The UE may determine an RTT based on the first time and the second time, as described in FIG. 3B and FIG. 4B, for example. Means for determining an RTT based on the first time and the second time may include, for example, a wireless transceiver 610 and one or more processors 602 in the UE 600, which may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in the propagation delay module 626, as shown in FIG. 6.
[0143]
[0156] In some implementations, the third message may be encrypted, for example, as described in Figures 3B and 4B. The third message may further include a digital signature for the base station, and the UE may authenticate the third message based on the digital signature for the base station, for example, as described in Figures 3B and 4B. The means for authenticating the third message based on the digital signature for the base station may comprise dedicated hardware, for example, in the UE 600, as shown in Figure 6, or may include one or more processors 602 executing executable code or software instructions in the memory 604 and / or the medium 620, for example, in the security module 624.
[0144]
[0157] An attacking device may be present in a wireless network between the UE and the base station, and a message is received via the attacking device during a replay attack, e.g., as shown in Figures 4A, 4B, and 5. The UE may determine the propagation delay from the timing advance or by measuring the RTT (as previously described), and may detect the presence of the attacking device based on the propagation delay being outside of an expected range, e.g., as described in Figures 4B and 5. The means for determining the propagation delay from the timing advance or by measuring the RTT may comprise dedicated hardware, e.g., in the UE 600, as shown in Figure 6, or may include one or more processors 602 executing executable code or software instructions in the memory 604 and / or the medium 620, e.g., in a propagation delay module 626. The means for detecting the presence of an attacking device based on a propagation delay being outside of an expected range may comprise dedicated hardware or may include one or more processors 602 executing executable code or software instructions in the memory 604 and / or medium 620, e.g., in the attack detection module 630, e.g., in the UE 600, as shown in FIG. 6. The expected range may include, e.g., a maximum propagation delay based on a maximum expected distance to a base station. The UE may obtain an estimated location of the UE and a location of the base station, e.g., as described in stage 1 of FIG. 5. The UE may determine a distance estimate between the estimated location of the UE and the location of the base station, e.g., as described in stage 1 of FIG. 5. The UE may determine the expected range based on the distance estimate, e.g., as described in stage 1 of FIG. 5. The means for obtaining an estimated location of the UE and the location of the base station may include, for example, as shown in FIG. 6, in the UE 600, a wireless transceiver 610 and one or more processors 602 that may comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or medium 620, for example, in a positioning session module 628.Means for determining a distance estimate between an estimated location of the UE and a location of the base station may include, for example, in the UE 600, a wireless transceiver 610 and one or more processors 602 that comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in a propagation delay module 626, as shown in FIG 6. Means for determining an expected range based on a distance estimate may include, for example, in the UE 600, a wireless transceiver 610 and one or more processors 602 that comprise dedicated hardware or execute executable code or software instructions in the memory 604 and / or the medium 620, for example, in a propagation delay module 626, as shown in FIG 6.
[0145]
[0158] In one implementation, the message further includes a digital signature for the base station, for example, as shown in message 302 of FIG. 3A, message 352 of FIG. 3B, message 402 of FIG. 4A, and messages 452 and 453 of FIG. 4B. The UE may authenticate the current time in the message based on the digital signature for the base station, for example, as described in FIG. 3B. The means for authenticating the current time in the message based on the digital signature for the base station may comprise dedicated hardware, for example, in the UE 600, as shown in FIG. 6, or may include one or more processors 602 executing executable code or software instructions in the memory 604 and / or the medium 620, for example, in the security module 624. The UE may receive, for example, a public encryption key for the base station from a wireless network, the digital signature being based on a private encryption key corresponding to the public encryption key, and authenticating the current time using the public encryption key, for example, as described in FIG. 3A, FIG. 3B, FIG. 4A, and FIG. 4B. The means for receiving a public encryption key for the base station from the wireless network, where the digital signature is based on a private encryption key corresponding to the public encryption key, and where authenticating the current time uses the public encryption key, may comprise dedicated hardware, for example, in the UE 600 as shown in FIG. 6 , or may include one or more processors 602 executing executable code or software instructions in the memory 604 and / or the medium 620, for example, in a security module 624.
[0146]
[0159] FIG. 9 illustrates a flowchart of an example method 900 for supporting reliable time acquisition by user equipment (UE) in a wireless network, performed by a base station such as the gNB 110 shown in FIGS. 1, 3A, 3B, 4A, 4B, 5, and 7, using a method consistent with the disclosed implementations.
[0147]
[0160] In block 902, the base station may obtain a current time, for example, as described in connection with Figures 1 and 3A. The current time may include, for example, Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time. The means for obtaining the current time may include, for example, an SPS receiver 715 or an external transceiver 716 and one or more processors 702 that may comprise dedicated hardware or execute executable code or software instructions in the memory 704 and / or medium 720, for example, in a current time module 722, in the base station 700, as shown in Figure 7.
[0148]
[0161] In block 904, the base station encrypts at least a portion of the current time, e.g., as described for message 302 of Figure 3A and message 352 of Figure 3B. The means for encrypting at least a portion of the current time may comprise dedicated hardware or may include one or more processors 702 executing executable code or software instructions in memory 704 and / or medium 720, e.g., in security module 724, e.g., in base station 700 as shown in Figure 7.
[0149]
[0162] In block 906, the base station broadcasts a message including the current time, the UE receives the message and obtains a clear current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE, and the UE determines a corrected current time based on the clear current time and the propagation delay, e.g., as described for message 302 of Figure 3A, message 352 of Figure 3B, message 402 of Figure 4A, and message 452 of Figure 4B. In some implementations, the base station may include in the message at least one of an implicit or explicit alignment of the current time to a subframe or slot boundary for the base station, an uncertainty in the current time, a source from which the current time is obtained, or a combination thereof. The means for broadcasting a message including the current time, and for including in the message at least one of an alignment of the current time to a subframe or slot boundary for the base station, an uncertainty in the current time, a source from which the current time is obtained, or a combination thereof, may include, for example, as shown in FIG. 7 , in a base station 700, a transceiver 710 and one or more processors 702 with dedicated hardware or executing executable code or software instructions in a memory 704 and / or a medium 720, for example, in a current time module 722.
[0150]
[0163] In one implementation, the base station may assist the UE in determining the propagation delay by transmitting a timing advance to the UE, the timing advance enabling the UE to determine the propagation delay (e.g., the propagation delay is obtained as half the timing advance), e.g., as described in Figures 3A and 4A. Means for transmitting a timing advance to the UE, the timing advance enabling the UE to determine the propagation delay, may include, e.g., a transceiver 710 and one or more processors 702, with dedicated hardware or executing executable code or software instructions in the memory 704 and / or the medium 720, e.g., in a propagation delay module 726, e.g., in the base station 700, as shown in Figure 7.
[0151]
[0164] In one implementation, the base station may assist the UE in determining the propagation delay by sending a message to the UE including at least one of the UE's location and the base station's location, where the propagation delay is determined by the UE based on a distance between the UE's location and the base station's location, for example, as described for Figure 3A. Means for sending a message to the UE including at least one of the UE's location and the base station's location, where the propagation delay is determined by the UE based on a distance between the UE's location and the base station's location, may include, for example, a transceiver 710 and one or more processors 702 in a base station 700, with dedicated hardware or executing executable code or software instructions in a memory 704 and / or a medium 720, for example, in a propagation delay module 726, as shown in Figure 7. As described with respect to FIG. 3A, the base station may send a message to the UE including at least one of the UE location and the base station location by, for example, broadcasting the base station location in a system information block (SIB), forwarding a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the base station location to the UE, sending a Mobile Originated Location Information Request (MO-LR) Response message including the UE location to the UE, or routing the LPP message between the UE and a location server (e.g., LMF 152 or SLP 162) for the UE to determine the UE location, or any combination thereof. Means for broadcasting the base station location in a system information block (SIB) may include, for example, a transceiver 710 and one or more processors 702 in the base station 700, with dedicated hardware or executing executable code or software instructions in the memory 704 and / or the medium 720, for example, in a positioning session module 728, as shown in FIG.Means for forwarding a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station to the UE may include, for example, in the base station 700, a transceiver 710 and one or more processors 702 that comprise dedicated hardware or execute executable code or software instructions in the memory 704 and / or the medium 720, for example, in the positioning session module 728, as shown in FIG 7. Means for transmitting a Mobile Originated Location Information Request (MO-LR) Response message including the location of the UE to the UE may include, for example, in the base station 700, a transceiver 710 and one or more processors 702 that comprise dedicated hardware or execute executable code or software instructions in the memory 704 and / or the medium 720, for example, in the positioning session module 728, as shown in FIG 7. A means for forwarding LPP messages between the UE and a location server for the UE to determine the location of the UE may include, for example, as shown in FIG. 7, in a base station 700, a transceiver 710 and one or more processors 702 that may comprise dedicated hardware or execute executable code or software instructions in the memory 704 and / or medium 720, for example in a positioning session module 728.
[0152]
[0165] In one implementation, the base station may assist the UE in determining the propagation delay by assisting the UE in measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT, for example, as described in Figures 3B and 4B. Means for assisting the UE in measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT, may include, for example, a transceiver 710 and one or more processors 702 in a base station 700, as shown in Figure 7, with dedicated hardware or executing executable code or software instructions in a memory 704 and / or a medium 720, for example, in a propagation delay module 726.
[0153]
[0166] In one implementation, the base station may assist the UE in measuring the RTT by transmitting a first message to the UE indicating a first local transmission time for the base station, and the UE associates a local timing at the UE with a local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE, e.g., as shown by message 354 in FIG. 3B and message 454 in FIG. 4B. Means for transmitting a first message to the UE indicating a first local transmission time for the base station, where the UE associates a local timing at the UE with a local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE, may include, e.g., a transceiver 710 and one or more processors 702 in a base station 700, with dedicated hardware or executing executable code or software instructions in a memory 704 and / or a medium 720, e.g., a propagation delay module 726, as shown in FIG. 7. The base station may receive a second message from the UE on a random access channel (RACH), where the second message includes a random variable and where the second message is transmitted at a first time, where the first time is either a local time at the UE or an associated local transmission time for the base station, for example, as shown by message 356 in Figure 3B and message 457 in Figure 4B. Means for receiving a second message from the UE on a random access channel (RACH), where the second message includes a random variable and where the second message is transmitted at a first time, where the first time is either a local time in the UE or an associated local transmission time for the base station, may include, for example, a transceiver 710 and one or more processors 702 in a base station 700, as shown in Figure 7, with dedicated hardware or executing executable code or software instructions in a memory 704 and / or a medium 720, for example, in a propagation delay module 726.The base station may measure a second time, the second time being a local transmission time for the base station at which the second message was received at the base station, for example, as shown by message 356 in FIG. 3B and message 457 in FIG. 4B. The means for measuring the second time, the second time being a local transmission time for the base station at which the second message was received at the base station, may include, for example, a transceiver 710 and one or more processors 702 in the base station 700, with dedicated hardware or executing executable code or software instructions in the memory 704 and / or the medium 720, for example, in the propagation delay module 726, as shown in FIG. 7. The base station may send a third message to the UE in response to the second message, the third message including the second time and a random variable, and the UE determines the RTT based on the first time and the second time, for example, as shown by message 358 in FIG. 3B and messages 458 and 459 in FIG. 4B. A means for transmitting a third message to the UE in response to the second message, the third message including the second time and the random variable, may include, for example, as shown in FIG. 7 , in a base station 700, a transceiver 710 and one or more processors 702 that have dedicated hardware or execute executable code or software instructions in the memory 704 and / or the medium 720, for example in a propagation delay module 726.
[0154]
[0167] In some implementations, the base station may encrypt the third message, for example, as described in FIG. 3B and FIG. 4B. The means for encrypting the third message may include, for example, a transceiver 710 and one or more processors 702 with dedicated hardware or executing executable code or software instructions in the memory 704 and / or the medium 720, for example, in the security module 724, in the base station 700, as shown in FIG. 7. The base station may include a digital signature for the base station in the third message, and the UE authenticates the third message based on the digital signature for the base station, for example, as described in FIG. 3B and FIG. 4B. The means for including a digital signature for the base station in the third message, where the UE authenticates the third message based on the digital signature for the base station, may include, for example, a transceiver 710 and one or more processors 702 with dedicated hardware or executing executable code or software instructions in the memory 704 and / or the medium 720, for example, in the security module 724, in the base station 700, as shown in FIG. 7.
[0155]
[0168] In some implementations, an attacking device may be present in a wireless network between the UE and a base station, and a message is received by the UE via the attacking device during a replay attack, e.g., as shown in Figures 4A and 4B. The UE may determine the propagation delay from the timing advance or by measuring the RTT (as described above), and may detect the presence of the attacking device based on the propagation delay being outside of an expected range, e.g., as shown in Figures 4B and 5. The expected range may be, e.g., a maximum propagation delay based on a maximum expected distance between the UE and the base station. The expected range may be, e.g., based on an estimated location of the UE and the location of the base station obtained by the UE.
[0156]
[0169] In one implementation, the base station may include a digital signature for the base station in the message, and the UE authenticates the current time in the message based on the digital signature for the base station, for example, as shown in message 302 in FIG. 3A, message 352 in FIG. 3B, message 402 in FIG. 4A, and messages 452 and 453 in FIG. 4B. Means for including a digital signature for the base station in the message, where the UE authenticates the current time in the message based on the digital signature for the base station, may include, for example, a transceiver 710 and one or more processors 702 in the base station 700, with dedicated hardware or executing executable code or software instructions in the memory 704 and / or the medium 720, for example, in a current time module 722, as shown in FIG. 7. The base station may send a public encryption key for the base station to the UE, and the digital signature is based on a private encryption key corresponding to the public encryption key, and the UE authenticates the current time using the public encryption key, for example, as described in FIG. 3A and FIG. 3B. A means for transmitting a public encryption key for the base station to a UE, where the digital signature is based on a private encryption key corresponding to the public encryption key, and where the UE authenticates the current time using the public encryption key, may include, for example, as shown in FIG. 7, in a base station 700, a transceiver 710 and one or more processors 702 that have dedicated hardware or execute executable code or software instructions in a memory 704 and / or a medium 720, for example in a security module 724.
[0157]
[0170] References throughout this specification to "in one example," "an example," "particular example," or "exemplary implementation" mean that a particular feature, structure, or characteristic described in a feature and / or example may be included in at least one feature and / or example of the claimed subject matter. Thus, the appearances of the phrases "in one example," "an example," "particular example," or "in a particular implementation" or other similar phrases in various places throughout this specification are not necessarily all referring to the same features, examples, and / or limitations. Furthermore, particular features, structures, or characteristics may be combined in one or more examples and / or characteristics.
[0158]
[0171] Some portions of the detailed description contained herein are presented in terms of algorithms or symbolic representations of operations on binary digital signals stored in memory of a specific apparatus or special purpose computing device or platform. In the context of this particular specification, the term specific apparatus or the like includes a general purpose computer that, when programmed, performs specific operations pursuant to instructions from program software. Algorithmic descriptions or symbolic representations are examples of techniques used by those skilled in the signal processing or related arts to convey the substance of their work to others skilled in the art. An algorithm, as used herein, is generally considered to be a self-consistent sequence of operations or similar signal processing that leads to a desired result. In this context, operations or processing involve physical manipulations of physical quantities. Usually, though not necessarily, such quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, or otherwise manipulated. It has proven convenient at times, primarily for reasons of common usage, to refer to such signals as bits, data, values, elements, symbols, characters, terms, numbers, values, or the like. It should be understood, however, that all of these or similar terms are merely convenient labels and must be associated with the appropriate physical quantities. Unless otherwise indicated, and as will be apparent from the discussion herein, it will be understood that throughout this specification, discussions utilizing terms such as "processing," "computing," "calculating," "determining," and the like refer to the actions or processes of a particular apparatus, such as a special purpose computer, a special purpose computing apparatus, or a similar special purpose electronic computing device. Thus, in the context of this specification, a special purpose computer or a similar special purpose electronic computing device is typically capable of manipulating or transforming signals that are represented as physical electronic or magnetic quantities within the memory, registers, or other information storage, transmission, or display devices of the special purpose computer or similar special purpose electronic computing device.
[0159]
[0172] In the above detailed description, numerous specific details are set forth to provide a thorough understanding of the claimed subject matter. However, it will be understood by those skilled in the art that the claimed subject matter may be practiced without these specific details. In other instances, methods and apparatuses that would be known by those skilled in the art have not been described in detail so as not to obscure the claimed subject matter.
[0160]
[0173] The terms "and," "or," and "and / or" as used herein may include a variety of meanings that are also expected to depend, at least in part, on the context in which such terms are used. Typically, when "or" is used to link a list such as A, B, or C, it is intended that it is used herein in the inclusive sense of A, B, and C, and that it is used herein in the exclusive sense of A, B, or C. In addition, the term "one or more" as used herein may be used to describe any feature, structure, or characteristic in the singular, or may be used to describe a plurality of features, structures, or characteristics, or some other combination of features, structures, or characteristics. However, it should be noted that this is merely an example and that claimed subject matter is not limited to this example.
[0161]
[0174] While what are presently considered to be exemplary features have been illustrated and described, it would be recognized by those skilled in the art that various other modifications could be made and equivalents substituted without departing from the claimed subject matter. Additionally, many modifications may be made to adapt a particular situation to the teachings of the claimed subject matter without departing from the central concept described herein.
[0162]
[0175] In view of this specification, embodiments may include various combinations of features. Example implementations are described in the following numbered clauses.
[0163]
[0176] Clause 1. A method performed by a user equipment (UE) to support time acquisition in a wireless network, the method including: receiving a message broadcasted from a base station, the message including a current time, where at least a portion of the current time is encrypted; obtaining a clear current time by decrypting at least a portion of the current time; determining a propagation delay between the base station and the UE; and determining a corrected current time based on the clear current time and the propagation delay.
[0164]
[0177] Clause 2. The method of clause 1, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0165]
[0178] Clause 3. The method of any one of clauses 1 or 2, wherein determining the propagation delay includes one of: obtaining a timing advance from a base station, where the propagation delay is determined from the timing advance; obtaining a location of the UE and a location of the base station, where the propagation delay is determined based on a distance between the location of the UE and the location of the base station; or measuring a round trip time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT.
[0166]
[0179] Clause 4. The method of clause 3, wherein obtaining the location of the UE and the location of the base station includes at least one of receiving a broadcast of the location of the base station in a System Information Block (SIB) from the base station, receiving a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station, receiving a Mobile Originated Location Information Request (MO-LR) Response message including the location of the UE, or performing a positioning session to determine the location of the UE.
[0167]
[0180] Clause 5. The method of any one of clauses 3 or 4, wherein measuring the RTT includes receiving a first message from the base station indicating a first local transmit time for the base station, associating a local timing at the UE to a local transmit time for the base station based on the first local transmit time for the base station and a local time of receipt of the first message at the UE, transmitting a second message to the base station on a random access channel (RACH), the second message including a random variable, the second message being transmitted at a first time, the first time being either the local time at the UE or the associated local transmit time for the base station, receiving a third message from the base station in response to the second message, the third message including the second time and the random variable, the second time being the local transmit time for the base station at which the second message was received at the base station, and determining the RTT based on the first time and the second time.
[0168]
[0181] Clause 6. The method of clause 5, wherein the third message is encrypted.
[0169]
[0182] Clause 7. The method of any one of clauses 5 or 6, wherein the third message further includes a digital signature for the base station, the method further including authenticating the third message based on the digital signature for the base station.
[0170]
[0183] Clause 8. The method of any one of clauses 3-7, wherein the attacking device is present in a wireless network between the UE and the base station, and the message is received via the attacking device during a replay attack, the method further comprising determining a propagation delay from a timing advance or by measuring an RTT, and detecting the presence of the attacking device based on the propagation delay being outside an expected range.
[0171]
[0184] Clause 9. The method of clause 8, wherein the expected range includes a maximum propagation delay based on a maximum expected distance to a base station.
[0172]
[0185] Clause 10. The method of any one of clauses 8 or 9, further comprising obtaining an estimated location of the UE and a location of the base station, determining a distance estimate between the estimated location of the UE and the location of the base station, and determining an expected range based on the distance estimate.
[0173]
[0186] Clause 11. The method of any one of clauses 1-10, wherein the message further includes at least one of an implicit or explicit alignment of the current time to a base station subframe or slot boundary, an uncertainty in the current time, a source of the current time, or a combination thereof.
[0174]
[0187] Clause 12. The method of any one of clauses 1 to 11, wherein the message further includes a digital signature for the base station, the method further including authenticating a current time in the message based on the digital signature for the base station.
[0175]
[0188] Clause 13. The method of clause 12, further comprising receiving a public encryption key for the base station from the wireless network, the digital signature being based on a private encryption key that corresponds to the public encryption key, and authenticating the current time using the public encryption key.
[0176]
[0189] Clause 14. A user equipment (UE) configured to support obtaining time in a wireless network, the user equipment (UE) comprising: a wireless transceiver configured to wirelessly communicate with a base station in the wireless network; at least one memory; and at least one processor coupled to the wireless transceiver and the at least one memory, wherein the at least one processor is configured to: receive, via the wireless transceiver, a message broadcast from the base station, the message including a current time, at least a portion of the current time being encrypted, obtain a clear current time by decrypting at least a portion of the current time, determine a propagation delay between the base station and the UE, and determine a corrected current time based on the clear current time and the propagation delay.
[0177]
[0190] Clause 15. The UE of clause 14, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0178]
[0191] Clause 16. The UE of any one of clauses 14 or 15, wherein the at least one processor is configured to determine the propagation delay by one of: obtaining a timing advance from a base station via a wireless transceiver, where the propagation delay is determined from the timing advance; obtaining a location of the UE and a location of the base station, where the propagation delay is determined based on a distance between the location of the UE and the location of the base station; or measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT.
[0179]
[0192] Clause 17. The UE of clause 16, wherein at least one processor is configured to obtain a location of the UE and a location of the base station by at least one of: receiving, via the wireless transceiver, a broadcast of the location of the base station in a system information block (SIB) from the base station, receiving, via the wireless transceiver, a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station, receiving, via the wireless transceiver, a Mobile Originated Location Information Request (MO-LR) Response message including the location of the UE, or performing a positioning session to determine a location of the UE.
[0180]
[0193] Clause 18. The UE of any one of clauses 16 or 17, configured to measure the RTT by having at least one processor configured to: receive, via the wireless transceiver, from the base station, a first message indicating a first local transmission time for the base station, associate a local timing at the UE to the local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE, transmit, via the wireless transceiver, a second message on a random access channel (RACH) to the base station, the second message including a random variable, the second message being transmitted at a first time, the first time being one of the local time at the UE or the associated local transmission time for the base station, receive, via the wireless transceiver, a third message from the base station in response to the second message, the third message including the second time and the random variable, the second time being the local transmission time for the base station at which the second message was received at the base station, and determine the RTT based on the first time and the second time.
[0181]
[0194] Clause 19. The UE of clause 18, wherein the third message is encrypted.
[0182]
[0195] Clause 20. The UE of any one of clauses 18 or 19, wherein the third message further includes a digital signature for the base station, and the at least one processor is further configured to authenticate the third message based on the digital signature for the base station.
[0183]
[0196] Clause 21. The UE of any one of clauses 16-20, further configured to: detect the presence of the attacking device based on the attacking device being present in a wireless network between the UE and a base station, the message being received via the attacking device during a replay attack, and the at least one processor determining a propagation delay from a timing advance or by measuring an RTT, and the propagation delay being outside an expected range.
[0184]
[0197] Clause 22. The UE of clause 21, wherein the expected range includes a maximum propagation delay based on a maximum expected distance to a base station.
[0185]
[0198] Clause 23. The UE of any one of clauses 21 or 22, further configured with at least one processor to obtain an estimated location of the UE and a location of the base station, determine a distance estimate between the estimated location of the UE and the location of the base station, and determine an expected range based on the distance estimate.
[0186]
[0199] Clause 24. The UE of any one of clauses 14-23, wherein the message further includes at least one of an implicit or explicit alignment of the current time to a base station subframe or slot boundary, an uncertainty of the current time, a source of the current time, or a combination thereof.
[0187]
[0200] Clause 25. The UE of any one of clauses 14-24, wherein the message further includes a digital signature for the base station, and wherein the at least one processor is further configured to authenticate a current time in the message based on the digital signature for the base station.
[0188]
[0201] Clause 26. The UE of clause 25, further configured to: receive a public encryption key for the base station from the wireless network; the digital signature is based on a private encryption key corresponding to the public encryption key; and authenticate the current time using the public encryption key.
[0189]
[0202] Clause 27. A user equipment (UE) configured to support obtaining time in a wireless network, comprising: means for receiving a message broadcasted from a base station, the message including a current time, at least a portion of the current time being encrypted; means for obtaining a clear current time by decrypting at least a portion of the current time; means for determining a propagation delay between the base station and the UE; and means for determining a corrected current time based on the clear current time and the propagation delay.
[0190]
[0203] Clause 28. The UE of clause 27, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0191]
[0204] Clause 29. The UE of any one of clauses 27 or 28, wherein the means for determining a propagation delay comprises one of: means for obtaining a timing advance from a base station, where the propagation delay is determined from the timing advance; means for obtaining a location of the UE and a location of the base station, where the propagation delay is determined based on a distance between the location of the UE and the location of the base station; or means for measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT.
[0192]
[0205] Clause 30. The UE of clause 29, wherein the means for acquiring the UE location and the base station location includes at least one of: means for receiving a broadcast of the base station location in a System Information Block (SIB) from the base station, means for receiving a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the base station location, means for receiving a Mobile Originated Location Information Request (MO-LR) Response message including the UE location, or means for performing a positioning session to determine the UE location.
[0193]
[0206] Clause 31. The UE of any one of clauses 29 or 30, wherein the means for measuring the RTT comprises: means for receiving a first message from the base station indicating a first local transmission time for the base station, means for associating a local timing at the UE to a local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE, means for transmitting a second message to the base station on a random access channel (RACH), the second message including a random variable, the second message being transmitted at a first time, the first time being either a local time at the UE or an associated local transmission time for the base station, means for receiving a third message from the base station in response to the second message, the third message including a second time and the random variable, the second time being a local transmission time for the base station at which the second message was received at the base station, and means for determining the RTT based on the first time and the second time.
[0194]
[0207] Clause 32. The UE of clause 31, wherein the third message is encrypted.
[0195]
[0208] Clause 33. The UE of any one of clauses 31 or 32, wherein the third message further includes a digital signature for the base station, the UE further comprising means for authenticating the third message based on the digital signature for the base station.
[0196]
[0209] Clause 34. The UE of any one of clauses 29-33, wherein the attacking device is present in a wireless network between the UE and the base station, and a message is received via the attacking device during a replay attack, the UE further comprising means for determining a propagation delay from a timing advance or by measuring an RTT, and means for detecting the presence of the attacking device based on the propagation delay being outside an expected range.
[0197]
[0210] Clause 35. The UE of clause 34, wherein the expected range includes a maximum propagation delay based on a maximum expected distance to a base station.
[0198]
[0211] Clause 36. The UE of any one of clauses 34 or 35, further comprising means for obtaining an estimated location of the UE and a location of the base station, means for determining a distance estimate between the estimated location of the UE and the location of the base station, and means for determining an expected range based on the distance estimate.
[0199]
[0212] Clause 37. The UE of any one of clauses 27-36, wherein the message further includes at least one of an implicit or explicit alignment of the current time to a base station subframe or slot boundary, an uncertainty in the current time, a source of the current time, or a combination thereof.
[0200]
[0213] Clause 38. The UE of any one of clauses 27 to 37, wherein the message further includes a digital signature for the base station, the UE further comprising means for authenticating a current time in the message based on the digital signature for the base station.
[0201]
[0214] Clause 39. The UE of clause 38, further comprising means for receiving a public encryption key for the base station from the wireless network, where the digital signature is based on a private encryption key corresponding to the public encryption key, and where authenticating the current time uses the public encryption key.
[0202]
[0215] Clause 40. A non-transitory computer-readable storage medium having program code stored thereon, the program code operable to configure at least one processor in a user equipment (UE) to support obtaining time in a wireless network, the program code including instructions for receiving a message broadcasted from a base station, the message including a current time, at least a portion of the current time being encrypted, obtaining a clear current time by decrypting at least a portion of the current time, determining a propagation delay between the base station and the UE, and determining a corrected current time based on the clear current time and the propagation delay.
[0203]
[0216] Clause 41. The non-transitory computer-readable storage medium of clause 40, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0204]
[0217] Clause 42. The non-transitory computer-readable storage medium of any one of clauses 40 or 41, wherein the instructions for determining a propagation delay include instructions for one of: obtaining a timing advance from a base station, where the propagation delay is determined from the timing advance; obtaining a location of the UE and a location of the base station, where the propagation delay is determined based on a distance between the location of the UE and the location of the base station; or measuring a round trip propagation time (RTT) between the UE and the base station, where the propagation delay is equal to half the RTT.
[0205]
[0218] Clause 43. The non-transitory computer-readable storage medium of clause 42, wherein the instructions for obtaining the location of the UE and the location of the base station include instructions for at least one of receiving a broadcast of the location of the base station in a System Information Block (SIB) from the base station, receiving a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station, receiving a Mobile Originated Location Information Request (MO-LR) Response message including the location of the UE, or performing a positioning session to determine the location of the UE.
[0206]
[0219] Clause 44. The non-transitory computer-readable storage medium of any one of clauses 42 or 43, wherein the instructions for measuring the RTT include instructions for receiving a first message from the base station indicating a first local transmit time for the base station, associating a local timing at the UE to the local transmit time for the base station based on the first local transmit time for the base station and a local time of receipt of the first message at the UE, transmitting a second message to the base station on a random access channel (RACH), the second message including a random variable, the second message being transmitted at a first time, the first time being either the local time at the UE or the associated local transmit time for the base station, receiving a third message from the base station in response to the second message, the third message including a second time and the random variable, the second time being the local transmit time for the base station at which the second message was received at the base station, and determining the RTT based on the first time and the second time.
[0207]
[0220] Clause 45. The non-transitory computer-readable storage medium of clause 44, wherein the third message is encrypted.
[0208]
[0221] Clause 46. The non-transitory computer-readable storage medium of any one of clauses 44 or 45, wherein the third message further includes a digital signature for the base station, and the program code further includes instructions for authenticating the third message based on the digital signature for the base station.
[0209]
[0222] Clause 47. The non-transitory computer-readable storage medium of any one of clauses 42-46, wherein the attacking device is present in a wireless network between the UE and the base station, and the message is received via the attacking device during a replay attack, the program code further comprising instructions for determining a propagation delay from a timing advance or by measuring an RTT, and detecting the presence of the attacking device based on the propagation delay being outside an expected range.
[0210]
[0223] Clause 48. The non-transitory computer-readable storage medium of clause 47, wherein the expected range includes a maximum propagation delay based on a maximum expected distance to a base station.
[0211]
[0224] Clause 49. The non-transitory computer-readable storage medium of any one of clauses 47 or 48, wherein the program code further comprises instructions for obtaining an estimated location of the UE and a location of the base station, determining a distance estimate between the estimated location of the UE and the location of the base station, and determining an expected range based on the distance estimate.
[0212]
[0225] Clause 50. The non-transitory computer-readable storage medium of any one of clauses 40-49, wherein the message further includes at least one of an implicit or explicit alignment of the current time to a base station subframe or slot boundary, an uncertainty in the current time, a source of the current time, or a combination thereof.
[0213]
[0226] Clause 51. The non-transitory computer-readable storage medium of any one of clauses 40-50, wherein the message further includes a digital signature for the base station, and the program code further includes instructions for authenticating a current time in the message based on the digital signature for the base station.
[0214]
[0227] Clause 52. The non-transitory computer-readable storage medium of clause 51, further comprising instructions for program code to receive a public encryption key for the base station from the wireless network, the digital signature being based on a private encryption key corresponding to the public encryption key, and authenticating the current time using the public encryption key.
[0215]
[0228] Clause 53. A method performed by a base station to support acquisition of time by a user equipment (UE) in a wireless network, the method comprising: acquiring a current time; encrypting at least a portion of the current time; and broadcasting a message including the current time, wherein the UE receives the message and obtains a clear current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE, and the UE determines a corrected current time based on the clear current time and the propagation delay.
[0216]
[0229] Clause 54. The method of clause 53, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0217]
[0230] Clause 55. The method of any one of clauses 53 or 54, further comprising assisting the UE in determining a propagation delay by performing one of: transmitting a timing advance to the UE, the timing advance enabling the UE to determine a propagation delay; transmitting a message to the UE including at least one of a location of the UE and a location of the base station, the propagation delay being determined by the UE based on a distance between the location of the UE and a location of the base station; or assisting the UE in measuring a round trip propagation time (RTT) between the UE and the base station, the propagation delay being equal to half the RTT.
[0218]
[0231] Clause 56. The method of clause 55, wherein sending the message including at least one of the UE location and the base station location to the UE includes at least one of: broadcasting the base station location in a system information block (SIB), forwarding a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the base station location to the UE, sending a Mobile Originated Location Information Request (MO-LR) Response message including the UE location to the UE, or routing the LPP message between the UE and a location server for the UE to determine the UE location.
[0219]
[0232] Clause 57. The method of any one of clauses 55 or 56, wherein assisting the UE in measuring the RTT comprises: transmitting a first message to the UE indicating a first local transmission time for the base station, where the UE associates a local timing at the UE with the local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE; receiving a second message from the UE on a random access channel (RACH), where the second message includes a random variable and the second message is transmitted at a first time, where the first time is either the local time at the UE or the associated local transmission time for the base station; measuring the second time, where the second time is the local transmission time for the base station at which the second message was received at the base station; and transmitting a third message to the UE in response to the second message, where the third message includes the second time and the random variable, where the UE determines the RTT based on the first time and the second time.
[0220]
[0233] Clause 58. The method of clause 57, further comprising encrypting the third message.
[0221]
[0234] Clause 59. The method of any one of clauses 57 or 58, further comprising including a digital signature for the base station in the third message, the UE authenticating the third message based on the digital signature for the base station.
[0222]
[0235] Clause 60. The method of any one of clauses 55 to 59, wherein an attacking device is present in a wireless network between the UE and a base station, a message is received by the UE via the attacking device during a replay attack, the UE determines a propagation delay from a timing advance or by measuring an RTT, and the UE detects the presence of the attacking device based on the propagation delay being outside an expected range.
[0223]
[0236] Clause 61. The method of clause 60, wherein the expected range includes a maximum propagation delay based on a maximum expected distance between the UE and the base station.
[0224]
[0237] Clause 62. The method of any one of clauses 60 or 61, wherein the predicted range is based on an estimated location of the UE and locations of base stations acquired by the UE.
[0225]
[0238] Clause 63. The method of any one of clauses 53-62, further comprising including in the message at least one of an implicit or explicit alignment of the current time to a subframe or slot boundary for the base station, an uncertainty in the current time, a source from which the current time is obtained, or a combination thereof.
[0226]
[0239] Clause 64. The method of any one of clauses 53 to 63, further comprising including in the message a digital signature for the base station, wherein the UE authenticates the current time in the message based on the digital signature for the base station.
[0227]
[0240] Clause 65. The method of clause 64, further comprising: transmitting a public encryption key for the base station to the UE, the digital signature being based on a private encryption key corresponding to the public encryption key, and the UE authenticating a current time using the public encryption key.
[0228]
[0241] Clause 66. A base station configured to support acquisition of time by a user equipment (UE) in a wireless network, the base station comprising: an external interface configured to wirelessly communicate with an entity in the wireless network; at least one memory; and at least one processor coupled to the external interface and the at least one memory, the at least one processor configured to: acquire a current time, encrypt at least a portion of the current time, and broadcast a message including the current time; the UE receives the message and obtains a clear current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE; and the UE determines a corrected current time based on the clear current time and the propagation delay.
[0229]
[0242] Clause 67. The base station of clause 66, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0230]
[0243] Clause 68. The base station of any one of clauses 66 or 67, further configured to assist the UE in determining the propagation delay by being configured to do one of: sending a timing advance to the UE, the timing advance enabling the UE to determine a propagation delay; sending a message to the UE including at least one of a location of the UE and a location of the base station, the propagation delay being determined by the UE based on a distance between the location of the UE and a location of the base station; or assisting the UE in measuring a round trip propagation time (RTT) between the UE and the base station, the propagation delay being equal to half the RTT.
[0231]
[0244] Clause 69. The base station of clause 68, further configured to send a message to the UE including at least one of the location of the UE and the location of the base station by the at least one processor configured to at least one of: broadcast the location of the base station in a system information block (SIB), forward a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message to the UE including the location of the base station, send a Mobile Originated Location Information Request (MO-LR) Response message to the UE including the location of the UE, or route the LPP message between the UE and a location server for the UE to determine the location of the UE.
[0232]
[0245] Clause 70. The base station of any one of clauses 68 or 69, further configured to assist the UE in measuring the RTT by being configured to: send a first message to the UE indicating a first local transmission time for the base station; the UE associates a local timing at the UE with a local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE; receive a second message from the UE on a random access channel (RACH) where the second message includes a random variable, the second message is sent at a first time, the first time being either the local time at the UE or the associated local transmission time for the base station, measure a second time, the second time being a local transmission time for the base station at which the second message was received at the base station; send a third message to the UE in response to the second message, the third message including the second time and the random variable, and the UE determines the RTT based on the first time and the second time.
[0233]
[0246] Clause 71. The base station of clause 70, wherein the at least one processor is further configured to encrypt the third message.
[0234]
[0247] Clause 72. The base station of any one of clauses 70 or 71, further configured: the at least one processor includes a digital signature for the base station in the third message, and the UE authenticates the third message based on the digital signature for the base station.
[0235]
[0248] Clause 73. The base station of any one of clauses 68-72, wherein the attacking device is present in a wireless network between the UE and the base station, a message is received by the UE via the attacking device during a replay attack, the UE determines a propagation delay from a timing advance or by measuring an RTT, and the UE detects the presence of the attacking device based on the propagation delay being outside an expected range.
[0236]
[0249] Clause 74. The base station of clause 73, wherein the expected range includes a maximum propagation delay based on a maximum expected distance between the UE and the base station.
[0237]
[0250] Clause 75. The base station of any one of clauses 73 or 74, wherein the predicted range is based on an estimated location of the UE and a location of the base station acquired by the UE.
[0238]
[0251] Clause 76. The base station of any one of clauses 66-75, wherein the at least one processor is further configured to include in the message at least one of an implicit or explicit alignment of the current time to a subframe or slot boundary for the base station, an uncertainty in the current time, a source from which the current time is obtained, or a combination thereof.
[0239]
[0252] Clause 77. The base station of any one of clauses 66-76, further configured: wherein the at least one processor includes a digital signature for the base station in the message; and wherein the UE authenticates the current time in the message based on the digital signature for the base station.
[0240]
[0253] Clause 78. The base station of clause 77, further configured: the at least one processor sends a public encryption key for the base station to the UE, the digital signature is based on a private encryption key corresponding to the public encryption key, and the UE authenticates the current time using the public encryption key.
[0241]
[0254] Clause 79. A base station configured to support acquisition of time by a user equipment (UE) in a wireless network, comprising: means for acquiring a current time; means for encrypting at least a portion of the current time; and means for broadcasting a message including the current time, wherein the UE receives the message and obtains a clear current time by decrypting at least a portion of the current time and determines a propagation delay between the base station and the UE, and the UE determines a corrected current time based on the clear current time and the propagation delay.
[0242]
[0255] Clause 80. The base station of clause 79, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0243]
[0256] Clause 81. The base station of any one of clauses 79 or 80, further comprising means for assisting the UE in determining a propagation delay including one of: means for transmitting a timing advance to the UE, the timing advance enabling the UE to determine a propagation delay; means for transmitting a message to the UE including at least one of a location of the UE and a location of the base station, the propagation delay being determined by the UE based on a distance between the location of the UE and a location of the base station; or means for assisting the UE in measuring a round trip propagation time (RTT) between the UE and the base station, the propagation delay being equal to half the RTT.
[0244]
[0257] Clause 82. The base station of clause 81, wherein the means for transmitting a message including at least one of the UE location and the base station location to the UE includes at least one of: means for broadcasting the base station location in a system information block (SIB), means for forwarding a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the base station location to the UE, means for transmitting a Mobile Originated Location Information Request (MO-LR) Response message including the UE location to the UE, or means for routing the LPP message between the UE and a location server for the UE to determine the UE location.
[0245]
[0258] Article 83. 83. The base station of any one of clauses 81 or 82, wherein the means for assisting the UE in measuring the RTT include means for transmitting a first message to the UE indicating a first local transmission time for the base station, where the UE associates the local timing at the UE with the local transmission time for the base station based on the first local transmission time for the base station and a local time of receipt of the first message at the UE; means for receiving a second message from the UE on a random access channel (RACH), where the second message includes a random variable and the second message is transmitted at a first time, where the first time is either the local time at the UE or the associated local transmission time for the base station; means for measuring the second time, where the second time is a local transmission time for the base station at which the second message was received at the base station; and means for transmitting a third message to the UE in response to the second message, where the third message includes the second time and the random variable, and where the UE determines the RTT based on the first time and the second time.
[0246]
[0259] Clause 84. The base station of clause 83, further comprising means for encrypting the third message.
[0247]
[0260] Clause 85. The base station of any one of clauses 83 or 84, further comprising means for including in the third message a digital signature for the base station, the UE authenticating the third message based on the digital signature for the base station.
[0248]
[0261] Clause 86. The base station according to any one of clauses 81 to 85, wherein the attacking device is present in a wireless network between the UE and the base station, a message is received by the UE via the attacking device during a replay attack, the UE determines a propagation delay from a timing advance or by measuring an RTT, and the UE detects the presence of the attacking device based on the propagation delay being outside an expected range.
[0249]
[0262] Clause 87. The base station of clause 86, wherein the expected range includes a maximum propagation delay based on a maximum expected distance between the UE and the base station.
[0250]
[0263] Clause 88. The base station of any one of clauses 86 or 87, wherein the predicted range is based on an estimated location of the UE and a location of the base station acquired by the UE.
[0251]
[0264] Clause 89. The base station of any one of clauses 79-88, further comprising means for including in the message at least one of an implicit or explicit alignment of the current time to a subframe or slot boundary for the base station, an uncertainty in the current time, a source from which the current time is obtained, or a combination thereof.
[0252]
[0265] Clause 90. The base station according to any one of clauses 79 to 89, further comprising means for including in the message a digital signature for the base station, the UE authenticating the current time in the message based on the digital signature for the base station.
[0253]
[0266] Clause 91. The base station of clause 90, further comprising means for transmitting a public encryption key for the base station to the UE, the digital signature being based on a private encryption key corresponding to the public encryption key, and the UE authenticating a current time using the public encryption key.
[0254]
[0267] Clause 92. A non-transitory computer-readable storage medium including program code stored thereon, the program code operable to configure at least one processor in a base station to support acquisition of time by a user equipment (UE) in a wireless network, the program code including instructions for acquiring a current time, encrypting at least a portion of the current time, and broadcasting a message including the current time, the UE receiving the message and acquiring a clear current time by decrypting at least a portion of the current time and determining a propagation delay between the base station and the UE, and the UE determining a corrected current time based on the clear current time and the propagation delay.
[0255]
[0268] Clause 93. The non-transitory computer-readable storage medium of clause 92, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
[0256]
[0269] Clause 94. The non-transitory computer-readable storage medium of any one of clauses 92 or 93, further comprising instructions for assisting the UE in determining a propagation delay, including instructions to do one of: transmitting a timing advance to the UE, the timing advance enabling the UE to determine a propagation delay; transmitting a message to the UE including at least one of a location of the UE and a location of the base station, the propagation delay being determined by the UE based on a distance between the location of the UE and a location of the base station; or assisting the UE in measuring a round trip propagation time (RTT) between the UE and the base station, the propagation delay being equal to half the RTT.
[0257]
[0270] Clause 95. The non-transitory computer-readable storage medium of clause 94, wherein the instructions for sending a message to the UE including at least one of a location of the UE and a location of the base station include instructions for at least one of: broadcasting the location of the base station in a system information block (SIB), forwarding a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station to the UE, sending a Mobile Originated Location Information Request (MO-LR) Response message to the UE including the location of the UE, or routing the LPP message between the UE and a location server for the UE to determine a location of the UE.
[0258]
[0271] Clause 96. The non-transitory computer-readable storage medium of any one of clauses 94 or 95, wherein the instructions for assisting the UE in measuring the RTT include instructions for: transmitting a first message to the UE indicating a first local transmit time for the base station; the UE associating a local timing at the UE with a local transmit time for the base station based on the first local transmit time for the base station and a local time of receipt of the first message at the UE; receiving a second message from the UE on a random access channel (RACH) where the second message includes a random variable, the second message is transmitted at a first time, the first time being one of the local time at the UE or the associated local transmit time for the base station, measuring a second time, the second time being a local transmit time for the base station at which the second message was received at the base station; transmitting a third message to the UE in response to the second message, the third message including the second time and the random variable; and the UE determining the RTT based on the first time and the second time.
[0259]
[0272] Clause 97. The non-transitory computer-readable storage medium of clause 96, wherein the program code further comprises instructions for encrypting the third message.
[0260]
[0273] Clause 98. The non-transitory computer-readable storage medium of any one of clauses 96 or 97, wherein the program code further comprises instructions for: including a digital signature for the base station in the third message; and the UE authenticating the third message based on the digital signature for the base station.
[0261]
[0274] Clause 99. The non-transitory computer-readable storage medium of any one of clauses 94-98, wherein the attacking device is present in a wireless network between the UE and a base station, a message is received by the UE via the attacking device during a replay attack, the UE determines a propagation delay from a timing advance or by measuring an RTT, and the UE detects the presence of the attacking device based on the propagation delay being outside an expected range.
[0262]
[0275] Clause 100. The non-transitory computer-readable storage medium of clause 99, wherein the expected range includes a maximum propagation delay based on a maximum expected distance between the UE and the base station.
[0263]
[0276] Clause 101. The non-transitory computer-readable storage medium of any one of clauses 99 or 100, wherein the predicted range is based on an estimated location of the UE and a location of the base station acquired by the UE.
[0264]
[0277] Clause 102. The non-transitory computer-readable storage medium of any one of clauses 92-101, wherein the program code further comprises instructions for including in the message at least one of an implicit or explicit alignment of the current time to a subframe or slot boundary for the base station, an uncertainty in the current time, a source from which the current time is obtained, or a combination thereof.
[0265]
[0278] Clause 103. The non-transitory computer-readable storage medium of any one of clauses 92-102, wherein the program code further comprises instructions for including a digital signature for the base station in the message, and for the UE to authenticate a current time in the message based on the digital signature for the base station.
[0266]
[0279] Clause 104. The non-transitory computer-readable storage medium of clause 103, further comprising program code instructions for: sending a public encryption key for the base station to the UE, the digital signature being based on a private encryption key corresponding to the public encryption key, and the UE authenticating a current time using the public encryption key.
[0267]
[0280] It is therefore intended that the claimed subject matter not be limited to the particular examples disclosed, but that such claimed subject matter include all embodiments falling within the scope of the appended claims and equivalents thereof.
Claims
1. 1. A method performed by a user equipment (UE) for supporting time acquisition in a wireless network, comprising: receiving a message broadcast from a base station, the message including a current time, at least a portion of the current time being encrypted; decrypting the at least the portion of the current time to obtain a cleartext current time; determining a propagation delay between the base station and the UE; determining a corrected current time based on the plaintext current time and the propagation delay; A method comprising:
2. 2. The method of claim 1, wherein the current time comprises Coordinated Universal Time (UTC) time, Global Positioning System (GPS) time, GLONASS time, Beidou time, Galileo time, Global Navigation Satellite System (GNSS) time, or a local regional time.
3. Determining the propagation delay obtaining a timing advance from the base station; and the propagation delay being determined from the timing advance. obtaining a location of the UE and a location of the base station, the propagation delay being determined based on a distance between the location of the UE and the location of the base station; or measuring a round trip time (RTT) between the UE and the base station, the propagation delay being equal to half the RTT; The method of claim 1 , comprising one of:
4. Obtaining the location of the UE and the location of the base station receiving from the base station a broadcast of the location of the base station in a system information block (SIB); receiving a Long Term Evolution (LTE) Positioning Protocol (LPP) Assistance Data message including the location of the base station; receiving a Mobile Originated Location Information Request (MO-LR) response message including the location of the UE; or performing a positioning session to determine the location of the UE; The method of claim 3 , comprising at least one of:
5. Measuring the RTT receiving a first message from the base station indicating a first local transmission time for the base station; relating a local timing at the UE to a local transmit time for the base station based on the first local transmit time for the base station and a local time of receipt of the first message at the UE; transmitting a second message to the base station on a random access channel (RACH); the second message comprises a random variable, and the second message is transmitted at a first time, the first time being one of a local time at the UE or an associated local transmission time for the base station. receiving a third message from the base station in response to the second message, the third message comprising a second time and the random variable, the second time being the local transmission time for the base station at which the second message was received at the base station; determining the round trip time based on the first time and the second time; The method of claim 3 comprising:
6. The method of claim 5 , wherein the third message is encrypted.
7. the third message further comprises a digital signature for the base station, and the method further comprises: authenticating the third message based on the digital signature for the base station; The method of claim 5 further comprising:
8. an attacking device is present in the wireless network between the UE and the base station, and the message is received via the attacking device during a replay attack, the method comprising: determining the propagation delay from the timing advance or by measuring the RTT; detecting the presence of the attacking device based on the propagation delay being outside an expected range; and The method of claim 3 further comprising:
9. The method of claim 8 , wherein the expected range comprises a maximum propagation delay based on a maximum expected distance to the base station.
10. obtaining an estimated location of the UE and the location of the base station; determining a distance estimate between the estimated location of the UE and the location of the base station; The method of claim 8 , further comprising: determining the expected range based on the distance estimate.
11. 2. The method of claim 1, wherein the message further comprises at least one of an implicit or explicit alignment of the current time to a base station subframe or slot boundary, an uncertainty of the current time, a source of the current time, or a combination thereof.
12. the message further comprises a digital signature for the base station, the method comprising: authenticating the current time in the message based on the digital signature for the base station; and optionally, receiving a public encryption key for the base station from the wireless network, the digital signature being based on a private encryption key corresponding to the public encryption key, and authenticating the current time using the public encryption key. The method of claim 1 further comprising:
13. 1. A user equipment (UE) configured to support time acquisition in a wireless network, comprising: a wireless transceiver configured to wirelessly communicate with a base station in the wireless network; At least one memory; at least one processor coupled to the wireless transceiver and the at least one memory, the at least one processor comprising: receiving a message broadcast from a base station via the wireless transceiver, the message including a current time, at least a portion of the current time being encrypted; decrypting the at least the portion of the current time to obtain a cleartext current time; determining a propagation delay between the base station and the UE; determining a corrected current time based on the plaintext current time and the propagation delay; A user equipment (UE) configured to:
14. The UE of claim 13, wherein the at least one processor is further configured to perform a method according to any one of claims 2 to 12.
15. 13. A non-transitory computer readable storage medium comprising program code stored thereon, the program code operable to configure at least one processor in a user equipment (UE) for supporting time acquisition in a wireless network to perform a method according to any one of claims 1 to 12.