Discovery Message Encryption
Patent Information
- Application Number
- JP2024541864
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-02-06
- Filing Date
- 2023-02-07
- Publication Date
- 2026-02-16
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] (CROSS REFERENCE TO RELATED APPLICATIONS) This application claims the benefit of and priority to U.S. Provisional Application No. 63 / 267,664, entitled "ENCRYPTING DISCOVERY MESSAGES," filed February 7, 2022, and U.S. Nonprovisional Application No. 18 / 165,269, entitled "ENCRYPTING DISCOVERY MESSAGES," filed February 6, 2023, which are expressly incorporated by reference in their entireties.
[0002] The present disclosure relates generally to communication systems, and more particularly, to wireless communication systems with proximity services (ProSe).
[0003] introduction Wireless communication systems have been widely deployed to provide various telecommunication services such as telephone, video, data, messaging, and broadcast. A typical wireless communication system may employ multiple access technologies capable of supporting communication with multiple users by sharing available system resources. Examples of such multiple access technologies include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single-carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems.
[0004] These multiple access technologies have been adopted in various telecommunications standards to provide a common protocol that allows different wireless devices to communicate at a city, country, region, or even global level. An exemplary telecommunications standard is 5G New Radio (NR). 5G NR is part of the continuing mobile broadband evolution promulgated by the Third Generation Partnership Project (3GPP) to meet new requirements associated with latency, reliability, security, scalability (e.g., for the Internet of Things (IoT)), and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine type communications (mMTC), and ultra-reliable low latency communications (URLLC). Some aspects of 5G NR may be based on the 4G Long Term Evolution (LTE) standard. Further improvements are needed in 5G NR technology. These improvements may also be applicable to other multiple access technologies and telecommunication standards employing these technologies. Some characteristics of wireless communication systems may present challenges with respect to security. Furthermore, any advances in wireless communication systems may present corresponding security challenges. Summary of the Invention
[0005] SUMMARY OF THE DISCLOSURE The following presents a simplified summary of one or more aspects in order to provide a basic understanding of such aspects. This summary is not an extensive overview of all contemplated aspects, nor is it intended to identify key or critical elements of all aspects or to delineate the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that is presented later.
[0006] In one aspect of the disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a user equipment (UE). The apparatus may also include a memory and at least one processor coupled to the memory. The apparatus may send a discovery request message comprising a restricted proximity service (ProSe) application user identifier (RPAUID) associated with the UE to a network entity prior to obtaining the discovery message, where the discovery request message further comprises a sidelink UE security capability representing a list of supported encryption algorithms including an encryption algorithm. The apparatus may also receive a discovery response message including a ProSe code from the network entity prior to obtaining the discovery message, where the discovery response message further comprises a selected encryption algorithm in the list of supported encryption algorithms associated with the UE. The apparatus may also obtain a mask (e.g., a bit mask) from the network entity prior to obtaining the discovery message, where a first portion of the discovery message is indicated by the mask (e.g., a bit mask). The apparatus may also obtain an indication of a scrambling algorithm and a scrambling key prior to obtaining the discovery message, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. Further, the apparatus may obtain an indication of an encryption algorithm and a security key prior to obtaining the discovery message, and derive the encryption key based on at least one of the security key or a first set of time parameters. The apparatus may also obtain an encrypted discovery message based on at least one of the encryption key, the encryption algorithm, and / or the first set of time parameters, where the discovery message is scrambled based on at least one of the scrambling key, the scrambling algorithm, or a second set of time parameters. The apparatus may also descramble the discovery message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters.Further, the apparatus may decrypt the discovery message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters. The apparatus may also encrypt the response message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters before transmitting the response message, and scramble the response message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters after encrypting the response message before transmitting the response message. The apparatus may also transmit a response message to the second UE in response to the discovery message, where the response message is a second discovery message including at least the response code.
[0007] In one aspect of the disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a network entity. The apparatus may also include a memory and at least one processor coupled to the memory. The apparatus may be configured to receive a first discovery request message including a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID), where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). The apparatus may also be configured to transmit a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The apparatus may also be configured to transmit a mask for the first UE, where a first portion of the discovery message is indicated by the mask. Furthermore, the apparatus may be configured to transmit an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. The apparatus may also perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. The apparatus may also receive a second discovery request message from a second network entity after sending the first discovery response message, the second discovery request message further including a sidelink UE security capability representing a second list of supported encryption algorithms associated with the second UE.The apparatus may also send a second discovery response message including the ProSe code and the selected encryption algorithm for a second network entity after receiving the second discovery request message, where the first network entity is a first direct discovery name management function (DDNMF) in a home public land mobile network (HPLMN) and the second network entity is a second DDNMF in the HPLMN.
[0008] To the accomplishment of the foregoing and related ends, the one or more aspects comprise the features hereinafter fully described and particularly pointed out in the claims. The following description and the annexed drawings set forth in detail certain illustrative features of the one or more aspects. These features are indicative, however, of but a few of the various ways in which the principles of the various aspects may be employed and the description is intended to include all such aspects and their equivalents. [Brief description of the drawings]
[0009] [Figure 1] FIG. 1 illustrates an example of a wireless communication system and an access network in accordance with various aspects of the present disclosure. [Figure 2A] FIG. 2 illustrates an example of a first frame in accordance with various aspects of the present disclosure. [Figure 2B] FIG. 1 illustrates an example of a downlink (DL) channel in a subframe, in accordance with various aspects of the present disclosure. [Figure 2C] FIG. 2 illustrates an example of a second frame, according to various aspects of the present disclosure. [Figure 2D] FIG. 1 illustrates an example of an uplink (UL) channel in a subframe, in accordance with various aspects of the present disclosure. [Diagram 3]FIG. 2 illustrates an example of a base station and user equipment (UE) in an access network, in accordance with various aspects of the present disclosure. [Figure 4] FIG. 1 illustrates an example discovery message protection process in accordance with various aspects of the present disclosure. [Diagram 5] FIG. 2 illustrates an exemplary encryption of data according to various aspects of the present disclosure. [Figure 6] FIG. 1 illustrates an example restricted discovery security procedure in accordance with various aspects of the present disclosure. [Figure 7] FIG. 1 illustrates an example restricted discovery security procedure in accordance with various aspects of the present disclosure. [Figure 8] FIG. 1 is a communication flow diagram illustrating example communications between a UE and a network entity, in accordance with various aspects of the present disclosure. [Figure 9] 1 is a flowchart of a method of wireless communication in accordance with various aspects of the present disclosure. [Figure 10] 1 is a flowchart of a method of wireless communication in accordance with various aspects of the present disclosure. [Figure 11] 1 is a flowchart of a method of wireless communication in accordance with various aspects of the present disclosure. [Figure 12] 1 is a flowchart of a method of wireless communication in accordance with various aspects of the present disclosure. [Figure 13] FIG. 2 illustrates an example of a hardware implementation for an exemplary device and / or network entity in accordance with certain aspects of the present disclosure. [Figure 14] FIG. 2 illustrates an example of a hardware implementation for an exemplary network entity, in accordance with various aspects of the present disclosure. [Figure 15] FIG. 2 illustrates an example of a hardware implementation for an exemplary network entity, in accordance with various aspects of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] The Detailed Description of the Invention described below in conjunction with the accompanying drawings illustrates various configurations and does not represent the only configurations in which the concepts described herein may be practiced. The Detailed Description of the Invention includes specific details intended to provide a thorough understanding of the various concepts. However, these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form to avoid obscuring such concepts.
[0011] Several aspects of a telecommunications system are presented with reference to various apparatus and methods that are described in the Detailed Description below and illustrated in the accompanying drawings by various blocks, components, circuits, processes, algorithms, etc. (collectively referred to as "elements"). These elements may be implemented using electronic hardware, computer software, or any combination thereof. Whether such elements are implemented as hardware or software depends on the particular application and design constraints imposed on the overall system.
[0012] As an example, the elements, or any portion of the elements, or any combination of the elements, may be implemented as a "processing system" including one or more processors. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, systems on a chip (SoC), baseband processors, field programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gate logic, discrete hardware circuits, and other suitable hardware configured to perform various functions described throughout this disclosure. One or more processors in a processing system may execute software. Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software components, applications, software applications, software packages, routines, subroutines, objects, executables, threads of execution, procedures, functions, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.
[0013] Thus, in one or more exemplary aspects, implementations, and / or use cases, the functions described may be implemented in hardware, software, or any combination thereof. If implemented in software, the functions may be stored or encoded as one or more instructions or code on a computer-readable medium. Computer-readable media includes computer storage media. A storage medium may be any available medium that can be accessed by a computer. By way of example, such computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage, other magnetic storage devices, combinations of types of computer-readable media, or any other medium that can be used to store computer-executable code in the form of instructions or data structures that can be accessed by a computer.
[0014] Although aspects, implementations, and / or use cases are described in this application by way of example for some embodiments, additional or different aspects, implementations, and / or use cases may occur in many different configurations and scenarios. The aspects, implementations, and / or use cases described herein may be implemented across many different platform types, devices, systems, shapes, sizes, and packaging configurations. For example, the aspects, implementations, and / or use cases may occur via integrated chip implementations and other non-modular component-based devices (e.g., end user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, artificial intelligence (AI)-enabled devices, etc.). Although some embodiments may or may not be specifically targeted to a use case or application, a wide variety of combination applicability of the described embodiments may occur. The aspects, implementations, and / or use cases may range from chip-level or modular components to non-modular, non-chip-level implementations, and even aggregated, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more of the techniques herein. In some practical settings, devices incorporating the described aspects and features may also include additional components and features for the implementation and practice of the claimed and described aspects. For example, the transmission and reception of wireless signals necessarily includes a number of components for analog and digital purposes (e.g., hardware components including antennas, RF chains, power amplifiers, modulators, buffers, processor(s), interleavers, summers / analog summers, etc.). The techniques described herein may be practiced in a wide variety of devices, chip-level components, systems, distributed configurations, aggregated or non-aggregated components, end-user devices, etc., of various sizes, shapes, and configurations.
[0015] The deployment of a communication system such as a 5G NR system can be configured in multiple ways with various components or parts. In a 5G NR system, or network, a network node, a network entity, a mobility element of the network, a radio access network (RAN) node, a core network node, a network element, or a network equipment such as a base station (BS), or one or more units (or one or more components) performing a base station function can be implemented in an aggregated or non-aggregated architecture. For example, a BS (such as a Node B (NB), evolved NB (eNB), NR BS, 5G NB, access point (AP), transmit / receive point (TRP), or cell) can be implemented as an aggregated base station (also known as a standalone BS or monolithic BS) or a non-aggregated base station.
[0016] An aggregated base station may be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. A non-aggregated base station may be configured to utilize a protocol stack that is physically or logically distributed among two or more units (such as one or more centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs)). In some aspects, a CU may be implemented within a RAN node, and one or more DUs may be co-located with the CU or alternatively geographically or virtually distributed across one or more other RAN nodes. A DU may be implemented to communicate with one or more RUs. Each of the CU, DU, and RU may be implemented as a virtual unit, i.e., a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).
[0017] Base station operation or network design may take into account the aggregated nature of base station functions. For example, disaggregated base stations may be utilized in an integrated access backhaul (IAB) network, an open radio access network (O-RAN, such as a network configuration supported by the O-RAN alliance), or a virtualized radio access network (vRAN, also known as a cloud radio access network (C-RAN)). Disaggregation may include distributing functions across two or more units in different physical locations, as well as distributing functions virtually for at least one unit, which may allow flexibility in network design. Various units of a disaggregated base station, or a disaggregated RAN architecture, may be configured for wired or wireless communication with at least one other unit.
[0018] In some wireless communication systems, protection of discovery messages over a PC5 interface may follow a defined protection mechanism. For example, security mechanisms for scrambling protection and message-specific confidentiality may have limitations on the size of discovery messages because the key stream may depend on the output of a key derivation function (KDF). However, discovery messages may include metadata information elements (IEs) with variable lengths. In addition, discovery messages for group member discovery may include an application layer group ID whose length may be between 2 and 256 bytes. Thus, such mechanisms for scrambling and message-specific confidentiality may not be applied if the size of a message to be protected is larger than 256 bits due to the metadata IEs or the application layer group ID. Aspects presented herein may provide message-specific confidentiality using an encryption algorithm and scrambling protection using a scrambling algorithm. Furthermore, aspects presented herein may enable the entire discovery message to be confidential without size limitations. The discovery message may be a message used in a discovery procedure. The discovery message may include several information elements (IEs) (e.g., a metadata IE with a variable length).
[0019] Aspects of the present disclosure may include several benefits or advantages. For example, the aspects presented herein may provide security protection for different types of messages. Also, the aspects presented herein may provide confidentiality protection for discovery messages. The aspects presented herein may provide message-specific confidentiality protection using an encryption algorithm. Furthermore, the aspects presented herein may provide scrambling protection for messages using a scrambling algorithm. Furthermore, the aspects presented herein may allow the entire discovery message to be confidential without any restrictions, such as size restrictions or information restrictions.
[0020] FIG. 1 is a diagram 100 illustrating an example of a wireless communication system and access network. The illustrated wireless communication system includes a disaggregated base station architecture. The disaggregated base station architecture may include one or more CUs 110 that may communicate directly with a core network 120 via a backhaul link or indirectly with the core network 120 through one or more disaggregated base station units (such as a near real-time (near RT) RAN intelligent controller (RIC) 125 via an E2 link, or a non-real-time (non-RT) RIC 115 associated with a service management and orchestration (SMO) framework 105, or both). The CUs 110 may communicate with one or more DUs 130 via respective midhaul links, such as an F1 interface. The DUs 130 may communicate with one or more RUs 140 via respective fronthaul links. The RUs 140 may communicate with respective UEs 104 via one or more radio frequency (RF) access links. In some implementations, the UEs 104 may be served by multiple RUs 140 simultaneously.
[0021] Each of the units, i.e., CU 110, DU 130, RU 140, and quasi-RT RIC 125, non-RT RIC 115, and SMO framework 105, may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) over a wired or wireless transmission medium. Each of the units, or an associated processor or controller that provides instructions to the unit's communication interface, may be configured to communicate with one or more of the other units over a transmission medium. For example, a unit may include a wired interface configured to receive or transmit signals to one or more of the other units over a wired transmission medium. Additionally, a unit may include a wireless interface, which may include a receiver, a transmitter, or a transceiver (such as an RF transceiver), configured to receive and / or transmit signals to one or more of the other units over a wireless transmission medium.
[0022] In some aspects, the CU 110 may host one or more upper layer control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptation Protocol (SDAP), and the like. Each control function may be implemented with an interface configured to communicate signals with other control functions hosted by the CU 110. The CU 110 may be configured to handle user plane functions (i.e., Central Unit-User Plane (CU-UP)), control plane functions (i.e., Central Unit-Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 110 may be logically divided into one or more CU-UP units and one or more CU-CP units. The CU-UP units, when implemented in an O-RAN configuration, may communicate bidirectionally with the CU-CP units via an interface, such as an E1 interface. The CU 110 may be implemented to communicate with the DU 130, as necessary, for network control and signaling.
[0023] The DU 130 may correspond to a logical unit including one or more base station functions for controlling the operation of one or more RUs 140. In some aspects, the DU 130 may host one or more of a radio link control (RLC) layer, a medium access control (MAC) layer, and one or more upper physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation, demodulation, etc.), at least in part according to a functional division such as that defined by 3GPP. In some aspects, the DU 130 may further host one or more lower PHY layers. Each layer (or module) may be implemented with an interface configured to communicate signals with other layers (and modules) hosted by the DU 130 or with a control function hosted by the CU 110.
[0024] The lower layer functions may be implemented by one or more RUs 140. In some deployments, the RUs 140 controlled by the DUs 130 may correspond to logical nodes hosting RF processing functions, or low PHY layer functions (such as performing fast Fourier transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.), or both, based at least in part on a functional division, such as a lower layer functional division. In such an architecture, the RU(s) 140 may be implemented to handle over-the-air (OTA) communications with one or more UEs 104. In some implementations, real-time and non-real-time aspects of control and user plane communications with the RU(s) 140 may be controlled by the corresponding DUs 130. In some scenarios, this configuration may enable the DU(s) 130 and the CU 110 to be implemented in a cloud-based RAN architecture, such as a vRAN architecture.
[0025] The SMO framework 105 may be configured to support RAN deployment and provisioning of non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 105 may be configured to support deployment of dedicated physical resources for RAN coverage requirements that may be managed via an operation and maintenance interface (such as an O1 interface). For virtualized network elements, the SMO framework 105 may be configured to interact with a cloud computing platform (such as an open cloud (O-cloud) 190) to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface (such as an O2 interface). Such virtualized network elements may include, but are not limited to, the CU 110, the DU 130, the RU 140, and the quasi-RT RIC 125. In some implementations, the SMO framework 105 may communicate with hardware aspects of a 4G RAN, such as an open eNB (O-eNB) 111, via an O1 interface. Additionally, in some implementations, the SMO framework 105 can communicate directly with one or more RUs 140 over the O1 interface. The SMO framework 105 can also include a non-RT RIC 115 configured to support the functionality of the SMO framework 105.
[0026] The non-RT RIC 115 may be configured to include logic functions that enable non-real-time control and optimization of RAN elements and resources, artificial intelligence (AI) / machine learning (ML) (AI / ML) workflows including model training and updates, or policy-based guidance of applications / features in the quasi-RT RIC 125. The non-RT RIC 115 may be coupled to the quasi-RT RIC 125 or may communicate with the quasi-RT RIC 125 (e.g., via an A1 interface). The quasi-RT RIC 125 may be configured to include logic functions that enable near real-time control and optimization of RAN elements and resources through data collection and action via one or more CUs 110, one or more DUs 130, or both, and an interface connecting the O-eNB to the quasi-RT RIC 125 (e.g., via an E2 interface).
[0027] In some implementations, the non-RT RIC 115 may receive parameters or external enrichment information from an external server to generate the AI / ML models deployed to the quasi-RT RIC 125. Such information may be utilized by the quasi-RT RIC 125 or may be received at the SMO framework 105 or the non-RT RIC 115 from non-network data sources or from network functions. In some examples, the non-RT RIC 115 or the quasi-RT RIC 125 may be configured to adjust RAN behavior or performance. For example, the non-RT RIC 115 may employ the AI / ML models to monitor long-term trends and patterns regarding performance and take corrective action through the SMO framework 105 (e.g., reconfiguration via O1) or through the creation of RAN management policies (e.g., A1 policies).
[0028] At least one of the CU 110, the DU 130, and the RU 140 may be referred to as a base station 102. Thus, the base station 102 may include one or more of the CU 110, the DU 130, and the RU 140 (each component is shown with a dotted line to indicate that each component may or may not be included in the base station 102). The base station 102 provides an access point to the core network 120 for the UE 104. The base station 102 may include a macro cell (high-power cellular base station) and / or a small cell (low-power cellular base station). Small cells include femto cells, pico cells, and micro cells. A network including both small cells and macro cells may be known as a heterogeneous network. A heterogeneous network may also include home evolved Node Bs (eNBs) (HeNBs) that may serve restricted groups known as closed subscriber groups (CSGs). The communication link between the RU 140 and the UE 104 may include uplink (UL) (also referred to as reverse link) transmissions from the UE 104 to the RU 140, and / or downlink (DL) (also referred to as forward link) transmissions from the RU 140 to the UE 104. The communication link may use multiple-input multiple-output (MIMO) antenna technology including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be through one or more carriers. The base station 102 / UE 104 may use spectrum with a bandwidth of up to YMHz (e.g., 5, 10, 15, 20, 100, 400 MHz, etc.) per carrier, allocated in a carrier aggregation of up to YxMHz (x component carriers) in total, used for transmission in each direction. The carriers may be adjacent or non-adjacent to each other. The carrier allocation may be asymmetric for DL and UL (e.g., more or fewer carriers may be allocated for DL than UL). The component carriers may include a primary component carrier and one or more secondary component carriers.The primary component carrier may be referred to as a primary cell (PCell), and the secondary component carrier may be referred to as a secondary cell (SCell).
[0029] Particular UEs 104 may communicate with each other using device-to-device (D2D) communication links 158. The D2D communication links 158 may use DL / UL wireless wide area network (WWAN) spectrum. The D2D communication links 158 may use one or more sidelink channels, such as a physical sidelink broadcast channel (PSBCH), a physical sidelink discovery channel (PSDCH), a physical sidelink shared channel (PSSCH), and a physical sidelink control channel (PSCCH). The D2D communication may be via various wireless D2D communication systems, such as Bluetooth, Wi-Fi based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, LTE, or NR.
[0030] The wireless communication system may further include a Wi-Fi AP 150 that communicates with the UEs 104 (also referred to as Wi-Fi stations (STAs)) via communication links 154, such as in the 5 GHz unlicensed frequency spectrum. When communicating in the unlicensed frequency spectrum, the UEs 104 / APs 150 may perform clear channel assessment (CCA) before communicating to determine if a channel is available.
[0031] The electromagnetic spectrum is often divided into various classes, bands, channels, etc. based on frequency / wavelength. For 5G NR, two initial operating bands have been identified with frequency range designations FR1 (410 MHz-7.125 GHz) and FR2 (24.25 GHz-52.6 GHz). Although a portion of FR1 is higher than 6 GHz, FR1 is often referred to (interchangeably) as the "sub-6 GHz" band in various documents and papers. Similar nomenclature issues may arise with respect to FR2, which is often referred to (interchangeably) as the "millimeter wave" band in documents and papers, even though it is different from the extremely high frequency (EHF) band (30 GHz-300 GHz) identified as the "millimeter wave" band by the International Telecommunications Union (ITU).
[0032] Frequencies between FR1 and FR2 are often referred to as mid-band frequencies. Recent 5G NR studies have identified operating bands for these mid-band frequencies as a frequency range designated FR3 (7.125 GHz to 24.25 GHz). Frequency bands that fall within FR3 may inherit FR1 and / or FR2 characteristics, and thus may in effect extend the characteristics of FR1 and / or FR2 to the mid-band frequencies. In addition, higher frequency bands are currently being explored to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as frequency ranges designated FR2-2 (52.6 GHz to 71 GHz), FR4 (71 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands falls within the EHF band.
[0033] With the above aspects in mind, unless otherwise indicated, as used herein, terms such as "sub-6 GHz" may broadly refer to frequencies that may be below 6 GHz, may be within FR1, or may include mid-band frequencies. Additionally, as used herein, unless otherwise indicated, terms such as "millimeter wave" may broadly refer to frequencies that may include mid-band frequencies, may be within FR2, FR4, FR2-2, and / or FR5, or may be within the EHF band.
[0034] The base station 102 and the UE 104 may each include multiple antennas, such as antenna elements, antenna panels, and / or antenna arrays, to facilitate beamforming. The base station 102 may transmit a beamformed signal 182 to the UE 104 in one or more transmit directions. The UE 104 may receive the beamformed signal from the base station 102 in one or more receive directions. The UE 104 may also transmit a beamformed signal 184 to the base station 102 in one or more transmit directions. The base station 102 may receive the beamformed signal from the UE 104 in one or more receive directions. The base station 102 / UE 104 may perform beam training to determine the best receive and transmit directions for each of the base station 102 / UE 104. The transmit and receive directions for the base station 102 may or may not be the same. The transmit and receive directions for the UE 104 may or may not be the same.
[0035] The base station 102 may include and / or be referred to as a gNB, Node B, eNB, access point, base transceiver station, radio base station, radio transceiver, transceiver function, basic service set (BSS), extended service set (ESS), TRP, network node, network entity, network equipment, or some other suitable terminology. The base station 102 may be implemented as an aggregated (monolithic) base station having an integrated access and backhaul (IAB) node, a relay node, a sidelink node, a baseband unit (BBU) (including CU and DU) and a RU, or as a disaggregated base station including one or more of a CU, a DU, and / or a RU. The set of base stations, which may include disaggregated base stations and / or aggregated base stations, may be referred to as a next generation (NG)RAN (NG-RAN).
[0036] The core network 120 may include an Access and Mobility Management Function (AMF) 161, a Session Management Function (SMF) 162, a User Plane Function (UPF) 163, a Unified Data Management (UDM) 164, one or more location servers 168, and other functional entities. The AMF 161 is a control node that handles signaling between the UE 104 and the core network 120. The AMF 161 supports registration management, connection management, mobility management, and other functions. The SMF 162 supports session management and other functions. The UPF 163 supports packet routing, packet forwarding, and other functions. The UDM 164 supports authentication and key agreement (AKA) credential generation, user identity handling, access authorization, and subscription management. The one or more location servers 168 are shown to include a Gateway Mobile Location Center (GMLC) 165 and a Location Management Function (LMF) 166. In general, however, the one or more location servers 168 may include one or more location / positioning servers, which may include one or more of the GMLC 165, the LMF 166, a position determination entity (PDE), a serving mobile location center (SMLC), a mobile positioning center (MPC), etc. The GMLC 165 and the LMF 166 support UE location services. The GMLC 165 provides an interface for clients / applications (e.g., emergency services) to access UE positioning information. The LMF 166 receives measurement and assistance information from the NG-RAN and the UE 104 via the AMF 161 to calculate the position of the UE 104. The NG-RAN may utilize one or more positioning methods to determine the position of the UE 104. Positioning the UE 104 may include signal measurements, position estimation, and optional velocity calculations based on these measurements. The signal measurements may be performed by the UE 104 and / or the base station 102 serving the UE 104.The signals measured may include one or more of a satellite positioning system (SPS) 170 (e.g., one or more of a Global Navigation Satellite System (GNSS), a global position system (GPS), a non-terrestrial network (NTN), or other satellite position / location system), LTE signals, wireless local area network (WLAN) signals, Bluetooth signals, a terrestrial beacon system (TBS), sensor-based information (e.g., barometric pressure sensors, motion sensors), NR enhanced cell ID (NR E-CID) methods, NR signals (e.g., multiple round trip time, multiple RTT), DL angle-of-departure (DL-AoD), DL time difference of arrival (DL-TDOA), UL time difference of arrival (UL-TDOA), and UL angle-of-arrival (UL-AR) signals. The positioning may be based on one or more of: UL-AoA (angle-of-arrival), UL-AoA (ultrasonic-based) positioning, and / or other systems / signals / sensors.
[0037] Examples of UEs 104 include a cellular phone, a smartphone, a session initiation protocol (SIP) phone, a laptop, a personal digital assistant (PDA), a satellite radio, a global positioning system, a multimedia device, a video device, a digital audio player (e.g., MP3 player), a camera, a game console, a tablet, a smart device, a wearable device, a vehicle, an electric meter, a gas pump, a large or small cooking appliance, a healthcare device, an implant, a sensor / actuator, a display, or any other similarly functional device. Some of the UEs 104 may be referred to as IoT devices (e.g., a parking meter, a gas pump, a toaster, a vehicle, a heart monitor, etc.). The UEs 104 may also be referred to as a station, a mobile station, a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, or some other suitable terminology. In some scenarios, the term UE may also apply to one or more companion devices, such as in a device constellation configuration, one or more of these devices may collectively access the network and / or may individually access the network.
[0038] Referring again to FIG. 1 , in some aspects, the UE 104 may have a discovery component 198 that may be configured to send a discovery request message comprising a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID) associated with the UE to a network entity prior to obtaining the discovery message, where the discovery request message further comprises a sidelink UE security capability representing a list of supported encryption algorithms including an encryption algorithm. The discovery component 198 may also be configured to receive a discovery response message including a ProSe code from the network entity prior to obtaining the discovery message, where the discovery response message further comprises a selected encryption algorithm in the list of supported encryption algorithms associated with the UE. The discovery component 198 may also be configured to obtain a mask from the network entity prior to obtaining the discovery message, where a first portion of the discovery message is indicated by the mask. The discovery component 198 may also be configured to obtain an indication of a scrambling algorithm and a scrambling key prior to obtaining the discovery message, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. The discovery component 198 may also be configured to obtain an indication of an encryption algorithm and a security key prior to obtaining the discovery message, and to derive an encryption key based on at least one of the security key or a first set of time parameters. The discovery component 198 may also be configured to obtain an encrypted discovery message based on at least one of the encryption key, encryption algorithm, and / or first set of time parameters, where the discovery message is scrambled based on at least one of the scrambling key, scrambling algorithm, or a second set of time parameters. Encryption may be encoding or encryption of a message, the purpose of which is to encrypt a designated portion of the message.Encryption may utilize an encryption key (i.e., a key used to encrypt a message) or an encryption algorithm (i.e., an algorithm used to encrypt a message). Deciphering may be the process of un-ciphering or decoding a message. Scrambling may be the encoding or encryption of a message, the purpose of which is to encrypt a limited portion of the message. Scrambling may utilize a scrambling key (i.e., a key used to scramble a message) or a scrambling algorithm (i.e., an algorithm used to scramble a message). Descrambling may be the process of descrambling or decoding a message. In some aspects, the time parameter may be the same as the freshness parameter. For example, the time parameter may be used as the freshness parameter. For example, the freshness parameter may be a counter value or a Coordinated Universal Time (UTC)-based time counter maintained among the UEs. The discovery component 198 may also be configured to descramble the discovery message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters. The discovery component 198 may also be configured to decrypt the discovery message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters. The discovery component 198 may also be configured to encrypt the response message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters before transmitting the response message, and to scramble the response message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters after encrypting the response message before transmitting the response message. The discovery component 198 may also be configured to transmit a response message to the second UE in response to the discovery message, where the response message is a second discovery message including at least the response code.
[0039] In some aspects, the base station 102 and / or the core network 120 may include a discovery component 199 that may be configured to receive a first discovery request message including a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID), where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). The discovery component 199 may also be configured to transmit a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The discovery component 199 may also be configured to transmit a mask for the first UE, where the first portion of the discovery message is indicated by the mask. The discovery component 199 may also be configured to transmit an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. The discovery component 199 may also be configured to perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. The discovery component 199 may also be configured to receive from the second network entity after transmitting the first discovery response message a second discovery request message further including a security capability of the sidelink UE representing a second list of supported encryption algorithms associated with the second UE.The discovery component 199 may also be configured to send a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. The following description may focus on 5G NR, but the concepts described herein may be applicable to other similar fields, such as LTE, LTE-A, CDMA, GSM, and other wireless technologies.
[0040] FIG. 2A is a diagram 200 illustrating an example of a first subframe in a 5G NR frame structure. FIG. 2B is a diagram 230 illustrating an example of a DL channel in a 5G NR subframe. FIG. 2C is a diagram 250 illustrating an example of a second subframe in a 5G NR frame structure. FIG. 2D is a diagram 280 illustrating an example of a UL channel in a 5G NR subframe. The 5G NR frame structure may be frequency division duplexed (FDD) where for a particular set of subcarriers (carrier system bandwidth), subframes within the set of subcarriers are dedicated to either DL or UL, or time division duplexed (TDD) where for a particular set of subcarriers (carrier system bandwidth), subframes within the set of subcarriers are dedicated to both DL and UL. In the example provided by FIG. 2A, FIG. 2C, the 5G NR frame structure is assumed to be TDD, subframe 4 is configured with slot format 28 (mostly DL), where D is DL, U is UL, and F is flexible for DL / UL use, and subframe 3 is configured with slot format 1 (all UL). Subframes 3 and 4 are shown with slot formats 1 and 28, respectively, but any particular subframe can be configured with any of the various available slot formats 0-61. Slot formats 0 and 1 are all DL and UL, respectively. The other slot formats 2-61 include a mix of DL symbols, UL symbols, and flexible symbols. The UE is configured with the slot format through a received slot format indicator (SFI) (dynamically through DL control information (DCI) or semi-statically / statically through Radio Resource Control (RRC) signaling). Note that the following description also applies to the 5G NR frame structure, which is TDD.
[0041] 2A-2D show a frame structure, and aspects of the present disclosure may be applicable to other wireless communication technologies, which may have different frame structures and / or different channels. A frame (10 ms) may be divided into 10 subframes (1 ms) of equal size. Each subframe may include one or more time slots. A subframe may also include a minislot, which may include 7, 4, or 2 symbols. Each slot may include 14 or 12 symbols depending on whether the cyclic prefix (CP) is normal or extended. For normal CP, each slot may include 14 symbols, and for extended CP, each slot may include 12 symbols. The symbols on the DL may be CP orthogonal frequency division multiplexing (CP-OFDM) symbols. The symbols on the UL can be CP-OFDM symbols (for high throughput scenarios) or Discrete Fourier Transform (DFT) Spread OFDM (DFT-s-OFDM) symbols (for power limited scenarios; limited to single stream transmission). The number of slots in a subframe is based on the CP and numerology. The numerology defines the subcarrier spacing (SCS) (see Table 1). The symbol length / duration can be scaled by 1 / SCS.
[0042] [Table 1]
[0043] For normal CP (14 symbols / slot), the different number logics μ0-4 allow 1, 2, 4, 8, and 16 slots per subframe, respectively. For extended CP, number logic 2 allows 4 slots per subframe. Thus, for normal CP and number logic μ, 14 symbols / slot and 2 μ There are slots / subframes. The subcarrier spacing is 2 μ*15 kHz, where μ is a number logic 0-4. Therefore, number logic μ=0 has a subcarrier spacing of 15 kHz, and number logic μ=4 has a subcarrier spacing of 240 kHz. The symbol length / period is inversely proportional to the subcarrier spacing. Figures 2A-2D provide an example of a normal CP with 14 symbols per slot and number logic μ=2 with 4 slots per subframe. The slot duration is 0.25 ms, the subcarrier spacing is 60 kHz, and the symbol duration is about 16.67 μs. Within a set of frames, there may be one or more different Bandwidth Parts (BWPs) (see Figure 2B), which are frequency division multiplexed. Each BWP may have a specific number logic and CP (normal or extended).
[0044] A resource grid may be used to represent the frame structure. Each time slot contains resource blocks (RBs) (also called physical RBs (PRBs)), spanning 12 consecutive subcarriers. The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.
[0045] As shown in Figure 2A, some of the REs carry reference (pilot) signals (RS) for the UE. The RS may include demodulation RS (DM-RS) (shown as R for one particular configuration, but other DM-RS configurations are possible) and channel state information reference signal (CSI-RS) for channel estimation at the UE. The RS may also include beam measurement RS (BRS), beam refinement RS (BRRS), and phase tracking RS (PT-RS).
[0046] FIG. 2B shows an example of various DL channels in a subframe of a frame. A physical downlink control channel (PDCCH) carries DCI in one or more control channel elements (CCEs) (e.g., 1, 2, 4, 8, or 16 CCEs), where each CCE includes 6 RE groups (REGs), and each REG includes 12 consecutive REs in an OFDM symbol of an RB. The PDCCHs in one BWP may be referred to as a control resource set (CORESET). During a PDCCH monitoring occasion on the CORESET, the UE is configured to monitor PDCCH candidates in a PDCCH search space (e.g., common search space, UE-specific search space), where the PDCCH candidates have different DCI formats and different aggregation levels. Additional BWPs may be deployed at higher and / or lower frequencies across the channel bandwidth. A primary synchronization signal (PSS) may be present in symbol 2 of a particular subframe of a frame. The PSS is used by the UE 104 to determine the subframe / symbol timing and the physical layer identity. A secondary synchronization signal (SSS) may be present in symbol 4 of a particular subframe of a frame. The SSS is used by the UE to determine the physical layer cell identity group number and the timing of the radio frame. Based on the physical layer identity and the physical layer cell identity group number, the UE can determine a Physical Cell Identifier (PCI). Based on the PCI, the UE can determine the location of the DM-RS.The physical broadcast channel (PBCH), which carries the master information block (MIB), may be logically grouped with the PSS and SSS to form a synchronization signal (SS) / PBCH block (also called an SS block (SSB)). The MIB provides the number of RBs in the system bandwidth and the system frame number (SFN). The physical downlink shared channel (PDSCH) carries user data, broadcast system information not transmitted over the PBCH, such as system information blocks (SIBs), and paging messages.
[0047] As shown in FIG. 2C , some of the REs carry DM-RS (depicted as R for one particular configuration, but other DM-RS configurations are possible) for channel estimation at the base station. The UE may transmit DM-RS for the physical uplink control channel (PUCCH) and DM-RS for the physical uplink shared channel (PUSCH). The PUSCH DM-RS may be transmitted in the first one or two symbols of the PUSCH. The PUCCH DM-RS may be transmitted in different configurations depending on whether a short or long PUCCH is transmitted and depending on the specific PUCCH format used. The UE may transmit sounding reference signals (SRS). The SRS may be transmitted in the last symbol of a subframe. The SRS may have a comb structure, and the UE may transmit the SRS in one of the combs. The SRS may be used by the base station for channel quality estimation to enable frequency-dependent scheduling on the UL.
[0048] 2D shows an example of various UL channels within a subframe of a frame. The PUCCH may be arranged as shown in one configuration. The PUCCH carries uplink control information (UCI) such as scheduling requests, channel quality indicators (CQI), precoding matrix indicators (PMI), rank indicators (RI), and hybrid automatic repeat request (HARQ) acknowledgment (ACK) (i.e., one or more HARQ ACK bits indicating one or more ACKs and / or negative ACKs (NACKs)). The PUSCH carries data and may additionally be used to carry buffer status reports (BSRs), power headroom reports (PHRs), and / or UCIs.
[0049] 3 is a block diagram of a base station 310 communicating with a UE 350 in an access network. In the DL, internet protocol (IP) packets may be provided to a controller / processor 375. The controller / processor 375 implements layer 3 and layer 2 functions. Layer 3 includes a radio resource control (RRC) layer, and layer 2 includes a service data adaptation protocol (SDAP) layer, a packet data convergence protocol (PDCP) layer, a radio link control (RLC) layer, and a medium access control (MAC) layer. The controller / processor 375 is responsible for RRC layer functions associated with broadcasting system information (e.g., MIBs, SIBs), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), mobility between radio access technologies (RATs), and measurement configuration for UE measurement reporting; PDCP layer functions associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functions associated with forwarding higher layer packet data units (PDUs), error correction via ARQ, concatenation, segmentation, and reassembly of RLC service data units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and mapping of logical channels to transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), MAC SDUs from TBs, and MAC SDUs from TBs. It provides the MAC layer functions associated with demultiplexing of SDUs, scheduling information reporting, error correction via HARQ, priority handling, and logical channel prioritization.
[0050] The transmit (TX) processor 316 and receive (RX) processor 370 implement Layer 1 functionality associated with various signal processing functions. Layer 1, including the physical (PHY) layer, may include error detection on transport channels, forward error correction (FEC) encoding / decoding of transport channels, interleaving, rate matching, mapping onto physical channels, modulation / demodulation of physical channels, and MIMO antenna processing. The TX processor 316 processes mapping to signal constellations based on various modulation schemes (e.g., binary phase-shift keying (BPSK), quadrature phase-shift keying (QPSK), M-phase-shift keying (M-PSK), M-quadrature amplitude modulation (M-QAM)). The coded and modulated symbols may then be split into parallel streams. Each stream can then be mapped to an OFDM subcarrier, multiplexed with a reference signal (e.g., pilot) in the time and / or frequency domain, and then combined together using an Inverse Fast Fourier Transform (IFFT) to generate a physical channel carrying a time-domain OFDM symbol stream. This OFDM stream is spatially precoded to generate multiple spatial streams. Channel estimates from a channel estimator 374 can be used to determine the coding and modulation schemes as well as for spatial processing. The channel estimates can be derived from a reference signal and / or channel condition feedback transmitted by the UE 350. Each spatial stream can then be provided to a different antenna 320 via a separate transmitter 318Tx. Each transmitter 318Tx can modulate a radio frequency (RF) carrier with the respective spatial stream for transmission.
[0051] At the UE 350, each receiver 354Rx receives a signal through its respective antenna 352. Each receiver 354Rx recovers information modulated onto an RF carrier and provides the information to a receive (RX) processor 356. The TX processor 368 and the RX processor 356 implement Layer 1 functionality associated with various signal processing functions. The RX processor 356 can perform spatial processing on the information to recover any spatial streams destined for the UE 350. If multiple spatial streams are destined for the UE 350, they can be combined by the RX processor 356 into a single OFDM symbol stream. The RX processor 356 then converts the OFDM symbol stream from the time domain to the frequency domain using a Fast Fourier Transform (FFT). The frequency domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, as well as the reference signal, are recovered and demodulated by determining the most likely signal constellation point transmitted by the base station 310. These soft decisions may be based on channel estimates calculated by a channel estimator 358. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally transmitted by the base station 310 on the physical channel. The data and control signals are then provided to a controller / processor 359, which implements Layer 3 and Layer 2 functions.
[0052] The controller / processor 359 may be associated with a memory 360 that stores program codes and data. The memory 360 may be referred to as a computer-readable medium. In the UL, the controller / processor 359 performs demultiplexing between transport and logical channels, packet reassembly, decoding, header decompression, and control signal processing to recover IP packets. The controller / processor 359 is also responsible for error detection using an ACK and / or NACK protocol to support HARQ operations.
[0053] Similar to the functionality described in connection with DL transmission by the base station 310, the controller / processor 359 provides RRC layer functionality associated with system information (e.g., MIB, SIB) acquisition, RRC connection, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with forwarding of higher layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping of logical channels to transport channels, multiplexing of MAC SDUs onto the TB, demultiplexing of MAC SDUs from the TB, scheduling information reporting, error correction via HARQ, priority handling, and logical channel prioritization.
[0054] Channel estimates derived by the channel estimator 358 from a reference signal or feedback transmitted by the base station 310 may be used by the TX processor 368 to select an appropriate coding and modulation scheme as well as to facilitate spatial processing. The spatial streams generated by the TX processor 368 may be provided to different antennas 352 via separate transmitters 354Tx. Each transmitter 354Tx may modulate an RF carrier with a respective spatial stream for transmission.
[0055] The UL transmissions are processed at the base station 310 in a manner similar to that described with respect to the receiver functions at the UE 350. Each receiver 318Rx receives a signal through its corresponding antenna 320. Each receiver 318Rx recovers the information modulated onto the RF carrier and provides the information to the RX processor 370.
[0056] The controller / processor 375 may be associated with a memory 376 that stores program codes and data. The memory 376 may be referred to as a computer-readable medium. In the UL, the controller / processor 375 performs demultiplexing between transport and logical channels, packet reassembly, decoding, header decompression, and control signal processing to recover IP packets. The controller / processor 375 is also responsible for error detection using an ACK and / or NACK protocol to support HARQ operations.
[0057] At least one of the TX processor 368, the RX processor 356, and the controller / processor 359 may be configured to implement aspects associated with component 198 of FIG.
[0058] At least one of the TX processor 316, the RX processor 370, and the controller / processor 375 may be configured to implement aspects associated with component 199 of FIG.
[0059] Aspects of wireless communications may include communication systems associated with Proximity Services (ProSe). ProSe may be a device-to-device (D2D) technology that allows devices to discover each other and communicate directly with each other. For example, ProSe may enable direct communication between UEs over a sidelink interface (e.g., PC5 interface). ProSe may also provide discovery and communication capabilities. Direct discovery may be classified as open discovery or restricted discovery. In open discovery, explicit permission from the UE being discovered may not be used. However, integrity protection and replay protection may be applied. In restricted discovery, explicit permission from the UE being discovered may be used. Also, integrity protection, replay protection, scrambling protection, and message specific confidentiality protection may be applied. The UE may be provided with security parameters from a network entity (e.g., a Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN)). In some aspects of wireless communications, the UE and the network entity may utilize security keys to encrypt information. Additionally, security keys may be utilized to protect transmissions between multiple devices, such as a first device and a second device.
[0060] In some wireless communication systems, protection of discovery messages over the PC5 interface may follow a defined protection mechanism. For example, security mechanisms for scrambling protection and message-specific confidentiality protection may have limitations on the size of discovery messages since the key stream may rely on the output of a key derivation function (KDF). The key stream may be a stream of characters (e.g., random or pseudorandom characters) that are combined with a message (e.g., a plaintext message) to generate a coded or encrypted message. The KDF may be an algorithm (e.g., a cryptographic algorithm) that derives one or more keys (e.g., secret keys) from a value (e.g., a key, a master key, or a password). In some cases, the maximum output bit length of the KDF may be 256 bits. The discovery message may be a message used in a discovery procedure. However, the discovery message may include a metadata information element (IE) having a variable length. In addition, the discovery message for group member discovery may include an application layer group ID whose length may be between 2 bytes and 256 bytes. Thus, if the size of the message to be protected is larger than 256 bits due to metadata IEs or application layer group IDs, such mechanisms for scrambling and message-specific confidentiality may not be applied. Aspects presented herein may provide message-specific confidentiality using an encryption algorithm and scrambling protection using a scrambling algorithm. Furthermore, aspects presented herein may allow the entire discovery message to be confidential without any type of restriction (e.g., size restriction or information restriction).
[0061] FIG. 4 is a diagram 400 illustrating an example of an exemplary discovery message protection process. More specifically, FIG. 4 illustrates that scrambling protection may be applied up to a certain number of bits (e.g., 256 bits) of the discovery message. As shown in FIG. 4, diagram 400 includes discovery message protection 410, which includes encryption algorithm 412, keystream generation 422, message 440, and keystream generation 462. In step 420, a discovery user confidentiality key (DUCK) or encryption algorithm 412 may undergo keystream generation 422. The encryption algorithm 412 may generate a variable-sized keystream that may encrypt the entire message. An encrypted bitmask (Encrypted_bits_mask) may further determine portions of the message that may require encryption. Also, in step 430, the keystream may be run for message-specific confidentiality protection. Based on these steps, the encrypted portion of the message 440 and the scrambled portion of the message 440 may be determined. As shown in FIG. 4, the message 440 may include a type, a Coordinated Universal Time (UTC) time, a message integrity check (MIC), and several information elements (IEs) (e.g., IE1, IE2, ..., IEn). DUCK may be a secret key to apply confidentiality to certain parts of the discovery message. MIC may be a code to check the integrity of the discovery message. Also, in step 460, DUCK or the KDF may undergo keystream generation 462, which may result in a keystream for scrambling in step 470. Furthermore, the KDF may have a fixed / limited output size (e.g., 256 bits), and thus the message 440 may be scrambled up to the output size of the KDF.
[0062] As shown in FIG. 4, all information to be scrambled may be included in less than the first number of bits (e.g., 256 bits) of the discovery message, so scrambling up to the first number of bits (e.g., 256 bits) of the discovery message may meet the purpose of protecting the information. If the discovery message size is larger than 256 bits, the unscrambled part of the message may carry a metadata IE that is protected using a message-specific confidentiality mechanism. The message-specific confidentiality may be handled in various ways. In some aspects, in a discovery request procedure, the UE may provide its security capability representing a list of supported encryption algorithms (e.g., provided to the DDNMF) and may be provisioned with an encryption algorithm for message-specific confidentiality (e.g., protected by the DDNMF). The key stream for confidentiality may be generated using a selected encryption algorithm with the following input parameters: KEY: The 128 least significant bits (LSBs) of the output of the KDF (Discovery User Secret Key (DUCK), a UTC-based counter, and a Message Integrity Check (MIC)). COUNT: UTC-based counter BEARER:0x00 DIRECTION:0x00 LENGTH: Length of discovery message - message type, UTC-based counter LSB and length of MIC
[0063] KEY may be set to a value to generate a message-specific keystream. MIC may be set to a 32-bit random string if a discovery user integrity key (DUIK) is not provisioned. The output keystream (output_keystream) of the encryption algorithm may then be masked with an encrypted bitmask to generate a final keystream (KEYSTREAM) for message-specific confidentiality. In some aspects, KEYSTREAM=output_keystream and (Encrypted_bits_mask 0xFF..FF), where the length of Encrypted_bits_mask may be set to a minimum of (length of discovery message-48, 224).
[0064] FIG. 5 is a diagram 500 illustrating an example encryption of data. More specifically, FIG. 5 illustrates encryption of data using the NR encryption algorithm (NEA). As shown in FIG. 5, diagram 500 includes a transmitter 510 and a receiver 550. The transmitter 510 includes multiple inputs to the NEA 520 (e.g., count 522, bearer 524, direction 526, length 528, and key 530). After the NEA 520, the transmitter 510 combines a keystream block 532 with a plaintext block 534. This may result in a ciphertext block 540. The receiver 550 includes multiple inputs to the NEA 560 (e.g., count 562, bearer 564, direction 566, length 568, and key 570). After the NEA 560, the receiver 550 combines a keystream block 572 with a ciphertext block 540. This may result in a plaintext block 574.
[0065] Furthermore, security for both models of the restricted discovery security procedure (Model A restricted discovery security procedure and Model B restricted discovery security procedure) may be similar to that of open discovery. Both models may also use a time-based counter (e.g., a Coordinated Universal Time (UTC)-based counter) to provide freshness protection for restricted discovery messages on the PC5 interface. Some parameters (e.g., a current time parameter (CURRENT_TIME) and a maximum offset parameter (MAX_OFFSET)) may also be provided to the UE from the DDNMF in its HPLMN to ensure that the obtained UTC-based counter is close enough to real time to protect against replay. In some aspects, restricted discovery may use confidentiality protection of discovery messages (e.g., to ensure that the UE is not discovered or tracked by unauthorized parties due to constantly sending the same ProSe restriction / response code in the clear), and a MIC check may be performed by the receiving UE (if allowed by the DDNMF).
[0066] The security parameters used by the transmitting UE (i.e., the announcing UE in model A discovery, and the discovering UE sending the ProSe query code and the discovered UE sending the ProSe response code in model B discovery) to protect the discovery message may be provided in the code transmission security parameters. Similarly, the security parameters utilized by the UE receiving the discovery message (i.e., the monitoring UE in model A discovery, and the discovering UE receiving the ProSe response code and the discovered UE receiving the ProSe query code in model B discovery) may be provided in the code reception security parameters. During the discovery request procedure, the DDNMF may provide the PC5 security policy to the UE. The encryption algorithm for message-specific confidentiality may be configured in the UE during the discovery request procedure.
[0067] FIG. 6 is a diagram 600 illustrating an example restricted discovery security procedure. More specifically, FIG. 6 illustrates an example model A restricted discovery security procedure. In the model A restricted discovery security procedure, an announcing UE may broadcast information about itself in a discovery message. For example, in the model A restricted discovery security procedure, the announcing UE may correspond to a transmitting UE, and the monitoring UE may correspond to a receiving UE. As shown in FIG. 6, the diagram 600 includes a monitoring UE 601, an announcing UE 602, a DDNMF 603 (e.g., a DDNMF in the HPLMN of the monitoring UE), a DDNMF 604 (e.g., a DDNMF in the Visited Public Land Mobile Network (VPLMN) of the announcing UE), a DDNMF 605 (e.g., a DDNMF in the HPLMN of the announcing UE), and a ProSe application server 606.
[0068] In 611, the announcing UE 602 may send a discovery request to the DDNMF 605 (e.g., the DDNMF in the HPLMN of the announcing UE). In 612, the DDNMF 605 may perform an authorization procedure with the ProSe application server 606 (e.g., exchange an authorization (Auth) request and an Auth response). In 613, the DDNMF 605 may perform an authorization procedure with the DDNMF 604 (e.g., exchange an announcement authorization (Auth) for a discovery request acknowledgement (ACK) and a discovery response ACK). In 614, the DDNMF 605 may send a discovery response to the announcing UE 602. The discovery response may include code send security parameters (Code-Send-SecParams), a current time parameter (CURRENT_TIME), a maximum offset parameter (MAX_OFFSET), and / or a set of selected PC5 encryption algorithms.
[0069] As shown in FIG. 6, steps 611-614 refer to the announcing UE 602 performing a discovery request procedure. In steps 611-614, the announcing UE can send a discovery request message including a restricted ProSe application user identifier (RPAUID) to the DDNMF in the HPLMN of the announcing UE to obtain a ProSe code to be announced and to obtain related security materials. The ProSe code may be a code or information associated with the ProSe application for discovery. In addition, the announcing UE can include its PC5 UE security capability, including a list of supported encryption algorithms, in the discovery request message. The DDNMF can check the announcement authorization with the ProSe application server 606. If the announcing UE is roaming, the DDNMF in the HPLMN of the announcing UE and the visiting PLMN (VPLMN) can exchange an announcement authorization (Auth) request and response. The DDNMF in the HPLMN of the announcing UE can return the ProSe code and the corresponding code transmission security parameters together with the CURRENT_TIME and MAX_OFFSET parameters. The code transmission security parameter may provide information for the announcing UE to protect the transmission of the ProSe code and may be stored together with the ProSe code. The DDNMF in the HPLMN of the announcing UE may include the selected PC5 encryption algorithm in a discovery response message. The discovery response message may be a message sent in response to the discovery message. In addition, the DDNMF in the HPLMN of the announcing UE may include the PC5 security policy in the discovery response message. The DDNMF may obtain the PC5 security policy in different ways (e.g., from a Policy Control Function (PCF), from a ProSe application server, or based on a local configuration).
[0070] In 615, the monitoring UE 601 may send a discovery request to the DDNMF 603 (e.g., the DDNMF in the HPLMN of the monitoring UE). In 616, the DDNMF 603 may perform an authorization procedure with the ProSe application server 606 (e.g., exchange an authorization (Auth) request and an Auth response). In step 617, the DDNMF 603 may send a management request to the DDNMF 605. In 618, the DDNMF 605 may perform an authorization procedure with the ProSe application server 606 (e.g., exchange an advertisement authorization (Auth) request and a response). In 619, the DDNMF 605 may send a monitoring response message to the DDNMF 603. The monitoring response may include code-received security parameters (Code-Rcv-SecParams), a discovery user integrity key (DUIK), and / or a set of selected PC5 encryption algorithms. At 620, the DDNMF 603 may send a discovery response to the monitoring UE 601. The discovery response may include a set of code send security parameters (Code-Send-SecParams), a current time (CURRENT_TIME) parameter, a maximum offset (MAX_OFFSET) parameter, and / or a selected PC5 encryption algorithm.
[0071] As shown in FIG. 6, steps 615-620 may refer to the monitoring UE 601 performing a discovery request procedure. In steps 615-620, the monitoring UE may send a discovery request message including the RPAUID and the security capability of the PC5 UE to the DDNMF in the HPLMN of the monitoring UE to be enabled to monitor one or more restricted ProSe application user IDs. The DDNMF in the HPLMN of the monitoring UE may send an authorization request to the ProSe application server. If the RPAUID is enabled to discover at least one of the target RPAUIDs included in the application level container based on the permission setting, the ProSe application server 606 may return an authorization response. If the discovery request is allowed and the PLMN ID in the target RPAUID indicates a different PLMN, the DDNMF in the HPLMN of the monitoring UE may contact the DDNMF of the indicated PLMN (i.e., the DDNMF in the HPLMN of the announcing UE) by sending a monitoring request message. And the DDNMF in the HPLMN of the monitoring UE may exchange an authorization message with the ProSe application server. The DDNMF in the HPLMN of the announcing UE may respond to the DDNMF in the HPLMN of the monitoring UE with a monitor response message including the ProSe code, the corresponding code reception security parameters, a discovery user integrity key (DUIK), and the selected PC5 encryption algorithm. The code reception security parameters may provide information that may be used by the monitoring UE to cancel the protection applied by the announcing UE. If the code reception security parameters indicate that the monitoring UE uses a match report for MIC check, the DUIK may be included as a separate parameter. The DDNMF in the HPLMN of the monitoring UE may store the ProSe code and the DUIK (e.g., the DDNMF may store the DUIK if it is received outside the code reception security parameters). The DDNMF in the HPLMN of the announcing UE may send a PC5 security policy to the DDNMF in the HPLMN of the monitoring UE.In some aspects, there may be two configurations possible for the consistency check: (1) MIC checked by DDNMF and (2) MIC checked at UE side. The configuration used may be determined by the DDNMF that assigned the ProSe code being monitored and may be signaled to the monitoring UE in the code reception security parameters. The DDNMF 603 in the HPLMN of the monitoring UE may return the discovery filter and the code reception security parameters along with the CURRENT_TIME and MAX_OFFSET parameters and the selected PC5 encryption algorithm. The monitoring UE 601 may take the same action with the CURRENT_TIME and MAX_OFFSET parameters as described for the monitoring UE. The monitoring UE may also store the discovery filter, the code reception security parameters and the selected PC5 encryption algorithm. If the DDNMF 603 in the HPLMN of the monitoring UE receives the PC5 security policy, the DDNMF of the monitoring UE may forward the PC5 security policy to the monitoring UE.
[0072] As shown in Fig. 6, steps 621-622 may refer to transmitting and receiving a code on a PC5 interface. In 621, the notifying UE 602 may notify a code (e.g., a ProSe code). In 622, after notifying the code, the monitoring UE 601 may receive the code (e.g., the ProSe code).
[0073] As further shown in FIG. 6, steps 623-626 may refer to the monitoring UE 601 performing a match report procedure for MIC check. In step 623, the monitoring UE 601 may send a match report to the DDNMF 603. The match report may include a time parameter, a MIC, etc. In 624, the DDNMF 603 may perform an authorization procedure (e.g., an optional authorization procedure) with the ProSe application server 606 (e.g., exchange an authorization (Auth) request and an Auth response). In step 625, the DDNMF 603 may send a match report ACK to the monitoring UE 601. The match report ACK may include a match report refresh timer. Furthermore, in 626, the DDNMF 603 may send monitoring report information (i.e., optional monitoring report information) to the DDNMF 605.
[0074] FIG. 7 is a diagram 700 illustrating an example restricted discovery security procedure. More specifically, FIG. 7 illustrates an example Model B restricted discovery security procedure. In the Model B restricted discovery security procedure, a discovering UE can send a request including specific information about what it may be interested in discovering, and a discovered UE can receive the request message and respond with some information related to the request. For example, in the Model B restricted discovery security procedure, the discovered UE can correspond to the transmitting UE, and the discovering UE can correspond to the receiving UE. As shown in FIG. 7, the diagram 700 includes a discovering UE 701, a discovered UE 702, a DDNMF 703 (e.g., DDNMF in the discovering UE's HPLMN), a DDNMF 704 (e.g., DDNMF in the visiting public land mobile network (VPLMN) of the discovering UE / discovered UE), a DDNMF 705 (e.g., DDNMF in the discovered UE's HPLMN), and a ProSe application server 706.
[0075] At 711, the discoveree UE 702 may send a discovery request to the DDNMF 705 (e.g., the DDNMF in the HPLMN of the discoveree UE). At 712, the DDNMF 705 may perform an authorization procedure with the ProSe application server 706 (e.g., exchange an authorization (Auth) request and an Auth response). At 713, the DDNMF 705 may perform an authorization procedure with the DDNMF 704 (e.g., exchange an announcement authorization (Auth) request acknowledgement (ACK) and an announcement Auth response ACK). At 714, the DDNMF 705 may send a discovery response to the discoveree UE 702. The discovery response may include a set of code send security parameters (Code-Send-SecParams), a set of code receive security parameters (Code-Rcv-SecParams), a current time parameter (CURRENT_TIME), a maximum offset parameter (MAX_OFFSET), and / or a selected PC5 encryption algorithm.
[0076] As shown in FIG. 7, steps 711-714 refer to the discoveree UE 702 performing a discovery request procedure. The discoveree UE may send a discovery request message including RPAUID to the DDNMF in the HPLMN of the discoveree UE to obtain discovery query filter(s) for monitoring queries, ProSe response code for advertising, and related security materials. The command may indicate that this is for a ProSe response (model B) operation (i.e., for the discoveree UE). In addition, the discoveree UE may include its PC5 UE security capabilities in the discovery request message, including a list of encryption algorithms supported by the UE. The DDNMF may check the advertising authorization with the ProSe application server (depending on the DDNMF configuration). Also, the DDNMF in the HPLMN and VPLMN of the discoveree UE may exchange advertising authorization (Auth) messages. If the discoveree UE is not roaming, the advertising Auth messages may not be exchanged. The DDNMF in the HPLMN of the discovered UE may return a ProSe response code and code transmission security parameters, discovery query filter(s), code reception security parameters corresponding to each discovery filter, along with the CURRENT_TIME and MAX_OFFSET parameters and the selected PC5 encryption algorithm. The code transmission security parameters may provide information for the discovered UE to protect the transmission of the ProSe response code and may be stored with the ProSe response code. The code reception security parameters may provide information utilized by the discovered UE to cancel the protection applied to the ProSe query code by the discovering UE. The code reception security parameters may indicate that the match report is not used for MIC check. The UE may store each discovery filter with its associated code reception security parameter. The discovered UE may take action using the CURRENT_TIME and MAX_OFFSET parameters.The DDNMF in the HPLMN of the discovered UE may include the selected PC5 encryption algorithm in the discovery response message. In addition, the DDNMF in the HPLMN of the discovered UE may include the PC5 security policy in the discovery response message. The DDNMF may obtain the PC5 security policy in different ways (e.g., from the PCF, from the ProSe application server, or based on a local configuration).
[0077] At 715, the discovering UE 701 may send a discovery request to the DDNMF 703 (e.g., the DDNMF in the discovering UE's HPLMN). At 716, the DDNMF 703 may perform an authorization procedure with the ProSe application server 706 (e.g., exchange authorization (Auth) requests and responses). At 717, the DDNMF 703 may send a discovery request to the DDNMF 705. At 718, the DDNMF 705 may perform an authorization procedure with the ProSe application server 706 (e.g., exchange advertisement authorization (Auth) requests and responses). At 719, the DDNMF 705 may send a discovery response message to the DDNMF 703. The discovery response may include a set of code send security parameters (Code-Send-SecParams), a set of code receive security parameters (Code-Rcv-SecParams), a discovery user integrity key (DUIK), and / or a selected PC5 encryption algorithm. At 720, the DDNMF 703 may perform an authorization procedure with the DDNMF 704 (e.g., exchange an advertised authorization (Auth) request and an advertised Auth response). At 721, the DDNMF 703 may send a discovery response to the discovering UE 701. The discovery response may include a set of code send security parameters (Code-Send-SecParams), a set of code receive security parameters (Code-Rcv-SecParams), a current time parameter (CURRENT_TIME), a maximum offset parameter (MAX_OFFSET), and / or a selected PC5 encryption algorithm.
[0078] As shown in FIG. 7, steps 715-721 refer to the discovering UE 701 performing a discovery request procedure. In steps 715-721, the discovering UE 701 may send a discovery request message including the RPAUID and the security capability of the PC5 UE to the DDNMF 703 in the HPLMN of the discovering UE to be enabled to discover one or more restricted ProSe application user IDs. The DDNMF 703 in the HPLMN of the discovering UE may send an authorization request to the ProSe application server 706. If the RPAUID is enabled to discover at least one of the target RPAUIDs included in the application level container, the ProSe application server 706 may return an authorization response. In some aspects, if the discovery request is allowed and the PLMN ID in the target RPAUID indicates a different PLMN, the DDNMF in the HPLMN of the discovering UE may contact the DDNMF of the indicated PLMN (i.e., the DDNMF in the HPLMN of the discovered UE) by sending a discovery request message. The DDNMF 705 in the HPLMN of the discovered UE may exchange authorization messages with the ProSe application server 706. The DDNMF 705 in the HPLMN of the discovered UE may respond to the DDNMF 703 in the HPLMN of the discovering UE with a discovery response message that may include a ProSe query code(s) and associated code transmission security parameters, a ProSe response code and its associated code reception security parameters, a discovery user integrity key (DUIK) for the ProSe response code, and a selected PC5 encryption algorithm. The code reception security parameters may provide information used by the discovering UE 701 to cancel the protection applied by the discovered UE 702. If the code reception security parameters indicate that the discovering UE uses match reporting for MIC checking, the DUIK may be included as a separate parameter.The DDNMF 703 in the HPLMN of the discovering UE can store the ProSe response code (if received outside the code reception security parameters) and the discovery user integrity key. The code transmission security parameters can provide information utilized by the discovering UE to protect the ProSe query code. The DDNMF 705 in the HPLMN of the discovered UE can send a PC5 security policy to the DDNMF 703 in the HPLMN of the discovering UE. In some aspects, there may be two configurations possible for the integrity check: (1) MIC checked by the DDNMF and (2) MIC checked at the UE side. The configuration may be determined by the DDNMF that assigned the ProSe code being monitored and signaled to the discovering UE in the code reception security parameters. The DDNMF 703 in the HPLMN of the discovering UE and the DDNMF 704 in the VPLMN of the discovering UE can exchange Announce Auth messages. If the discovering UE is not roaming, the Announce Auth messages may not be exchanged. The DDNMF 703 in the discovering UE's HPLMN can return a discovery response filter and code reception security parameters, a ProSe query code, a code transmission security parameter, along with the CURRENT_TIME and MAX_OFFSET parameters and the selected PC5 encryption algorithm. The discovering UE 701 can take the same action using the CURRENT_TIME and MAX_OFFSET. The discovering UE can also store the discovery response filter and its code reception security parameters, the ProSe query code and its code transmission security parameters, and the selected PC5 encryption algorithm. If the DDNMF 703 in the discovering UE's HPLMN receives the PC5 security policy, the DDNMF of the discovering UE can forward the PC5 security policy to the discovering UE 701.
[0079] As shown in FIG. 7, steps 722-725 may refer to transmitting and receiving codes over a PC5 interface. At 722, the discovering UE 701 may send a query code to the discovered UE 702. At 723, the discovered UE 702 may process the query code. The query code may be a code or information that queries a response. At 724, the discovered UE 702 may send a response code to the discovering UE 701. At 725, the discovering UE 701 may process the response code. The response code may be a code or information that is sent in response to the query.
[0080] As further shown in FIG. 7, steps 726-729 may refer to the discovering UE 701 performing a match report procedure for a MIC check. In step 726, the discovering UE 701 may send a match report to the DDNMF 703. The match report may include a set of time parameters, a MIC, etc. In some aspects, the time parameters may be the same as the freshness parameters. For example, the time parameters may be used as the freshness parameters. For example, the freshness parameters may be a counter value maintained between UEs or a UTC-based time-based counter. In 727, the DDNMF 703 may perform an authorization procedure (e.g., an optional authorization procedure) with the ProSe application server 706 (e.g., exchange an authorization (Auth) request and an Auth response). In step 728, the DDNMF 703 may send a match report ACK to the discovering UE 701. The match report ACK may include a match report refresh timer. At 729, the DDNMF 703 may send monitoring report information (ie, optional monitoring report information) to the DDNMF 705.
[0081] In some aspects, there may be three types of security used to protect restricted discovery messages over the PC5 interface: integrity protection, scrambling protection, and message-specific confidentiality. In some aspects, the protection mechanisms may be as follows: Message-specific confidentiality may be provided by the ProSe layer between ProSe UEs. The use and operation mode of the 128-NR encryption algorithm (NEA) algorithm may be based on configuration. The input parameters to the 128-NEA algorithm are as follows: KEY: 128 Least Significant Bits (LSBs) of the output of the KDF (DUSK, UTC-based counter, MIC) COUNT: UTC-based counter BEARER:0x00 DIRECTION:0x00 LENGTH: Length of discovery message - message type, UTC-based counter LSB and length of MIC
[0082] KEY may be set to a value to generate a message-specific keystream. The output keystream (output_keystream) of the encryption algorithm may then be masked with an encrypted bitmask to generate a final keystream (KEYSTREAM) for message-specific confidentiality. In some aspects, KEYSTREAM=output_keystream and (Encrypted_bits_mask 0xFF..FF), where the length of Encrypted_bits_mask is set to the minimum of (length of discovery message-48, 224). KEYSTREAM may be XORed with the discovery message for message-specific confidentiality. The time hash bit sequence keystream may be set to the L least significant bits of the output of the KDF, where L is the bit length of the discovery message to be scrambled, and is set to the minimum of (length of discovery message-16, 256). MIC may be set to a 32-bit random string if no DUIK is provisioned. The maximum length of the discovery message to be scrambled may be limited to 256 bits.
[0083] The 128-NEA algorithms may include 128-NEA1, 128-NEA2, and 128-NEA3. 128-NEA1 may be based on a particular algorithm (e.g., the SNOW 3G algorithm). 128-NEA2 may be based on the Advanced Encryption Standard (AES) (e.g., 128-bit AES). 128-NEA3 may be based on a particular algorithm (e.g., the ZUC algorithm). In some aspects, the time hash bit sequence may be replaced by a scrambling key stream. The scrambling key may also be a discovery user scrambling key (DUSK). For example, DUSK may be a scrambling key for applying scrambling protection to a portion of the discovery message. The scrambling key stream may be a KEYSTREAM block calculated by a selected encryption algorithm having at least the following inputs: KEY: 128 Least Significant Bits (LSBs) of the output of the KDF (DUSK, UTC-based counter, MIC) COUNT: UTC-based counter BEARER:0x00 DIRECTION:0x00 LENGTH: Length of discovery message - length of message type and counter LSB in UTC
[0084] In some aspects, the discovery message to be encrypted and / or scrambled may be less than a defined size (e.g., 256 bits) by replacing the application layer group identifier (ID) with an application layer group ID code. The application layer group ID may be a group ID for the application layer. The application layer group ID code may be a code corresponding to the application layer group ID. In some aspects, the application layer group ID code representing the application layer group ID may be a hash of the application layer group ID. Encryption may be the encoding or encryption of a message, the purpose of which is to encrypt a specified portion of the message. Encryption may utilize an encryption key (i.e., a key used to encrypt the message) or an encryption algorithm (i.e., an algorithm used to encrypt the message). Deciphering may be the process of un-ciphering or decoding a message. Scrambling may be the encoding or encryption of a message, the purpose of which is to encrypt a limited portion of the message. Scrambling may utilize a scrambling key (i.e., a key used to scramble the message) or a scrambling algorithm (i.e., an algorithm used to scramble the message). Descrambling can be the process of descrambling or decoding a message.
[0085] Aspects of the present disclosure may include several benefits or advantages. For example, the aspects presented herein may provide security protection for different types of messages. Also, the aspects presented herein may provide confidentiality protection for discovery messages. The aspects presented herein may provide message-specific confidentiality protection using an encryption algorithm. Furthermore, the aspects presented herein may provide scrambling protection for messages using a scrambling algorithm. Furthermore, the aspects presented herein may allow the entire discovery message to be confidential without any restrictions, such as size restrictions or information restrictions.
[0086] 8 is a communication flow diagram 800 of wireless communication in accordance with one or more techniques of the present disclosure. As shown in FIG. 8, diagram 800 includes example communication between a UE 802 and a network entity 804 in accordance with one or more techniques of the present disclosure. In some aspects, the UE 802 may be a first wireless device and the network entity 804 may be a second wireless device. The UE 802 may correspond to the Monitoring UE 601 or the Announcing UE 602 in FIG. 6 and / or the Discovering UE 701 or the Discoveree UE 702 in FIG. 7.
[0087] At 810, the UE 802 may send a discovery request message including a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID) associated with the UE to a network entity prior to obtaining the discovery message (e.g., the UE 802 may send message 814 to the network entity 804), where the discovery request message further includes the sidelink UE's security capabilities indicating a list of supported encryption algorithms including an encryption algorithm.
[0088] Also, at 810, the UE 802 may receive a discovery response message including the ProSe code from the network entity prior to obtaining the discovery message (e.g., the UE 802 may receive message 818 from the network entity 804), where the discovery response message further includes a selected encryption algorithm in a list of supported encryption algorithms associated with the UE. The discovery response message may further include at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value.
[0089] At 812, the network entity 804 may receive a first discovery request message (e.g., the network entity 804 may receive message 814 from the UE 802) including a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID), where the first discovery request message further includes sidelink UE security capabilities representing a first list of supported encryption algorithms associated with the first user equipment (UE). In some aspects, to receive the first discovery request message, the network entity may receive the first discovery request message via at least one of a transceiver or an antenna.
[0090] At 816, the network entity 804 may send a first discovery response message including the ProSe code (e.g., the network entity 804 may send message 818 to the UE 802), where the first discovery response message further includes a selected encryption algorithm in a first list of supported encryption algorithms associated with the first UE.
[0091] At 820, the network entity 804 may send a mask for the first UE (e.g., the network entity 804 may send a mask 824 to the UE 802), where a first portion of the discovery message is indicated by the mask.
[0092] At 822, the UE 802 may obtain a mask from a network entity prior to obtaining the discovery message (e.g., the UE 802 may receive a mask 824 from the network entity 804), where a first portion of the discovery message is indicated by the mask.
[0093] At 830, the network entity 804 may send an indication of a scrambling algorithm and a scrambling key for the first UE (e.g., the network entity 804 may send an indication 834 to the UE 802), where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key.
[0094] At 832, the UE 802 may obtain an indication of a scrambling algorithm and a scrambling key prior to obtaining the discovery message (e.g., the UE 802 may receive an indication 834 from a network entity 804), where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. In some aspects, to obtain the indication of the scrambling algorithm and the scrambling key, the UE may receive the indication of the scrambling algorithm and the scrambling key from a network entity. Thus, the UE may receive the indication of the scrambling algorithm and the scrambling key from the network entity. Also, the network entity may be a Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN). The scrambling key may be a Discovery User Scrambling Key (DUSK). The DUSK may be a scrambling key for the user in the discovery procedure.
[0095] At 840, the UE 802 may obtain an indication of an encryption algorithm and a security key prior to obtaining the discovery message and derive the encryption key based on at least one of the security key or the first set of time parameters. In some aspects, to obtain the indication of the encryption algorithm and the security key, the UE may receive the indication of the encryption algorithm and the security key from a network entity. The UE may also retrieve the indication of the encryption algorithm and the security key from a memory or a database. For example, the UE may download the encryption algorithm and the security key from the database. As indicated above, the UE and the network entity may utilize a security key to encrypt information. Furthermore, the security key may be utilized to protect transmissions between multiple devices, such as a first device and a second device. Also, the network entity may be a Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN). Furthermore, the encryption key may be based on a discovery user secret key (DUCK), a first set of time parameters, or a message-specific parameter, and the message-specific parameter may be a message integrity check (MIC) or a random string.
[0096] At 850, the network entity 804 may perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message.
[0097] At 860, the network entity 804 may receive a second discovery request message from the second network entity after sending the first discovery response message, the second discovery request message further including sidelink UE security capabilities representing a second list of supported encryption algorithms associated with the second UE.
[0098] Also, at 860, the network entity 804 may send a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. The first discovery response message may further include at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value, and the second discovery response message may further include at least one of the first set of security parameters, the second set of security parameters, a current time value, or a maximum time offset value.
[0099] At 870, the UE 802 may obtain an encrypted discovery message based on at least one of an encryption key, an encryption algorithm, and / or a first set of time parameters, where the discovery message is scrambled based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters. In some aspects, a first portion of the discovery message may be encrypted based on the first set of encryption key, encryption algorithm, or time parameters. A second portion of the discovery message may be scrambled based on the second set of scrambling key, scrambling algorithm, or time parameters, where the second portion may be different from the first portion. Also, the second portion may overlap with the first portion, where a size of the second portion may be less than or equal to a size of a key derivation function associated with the scrambling key. Furthermore, a third portion of the discovery message may not be scrambled, and the third portion may be different from the first portion and the second portion. The discovery message may be less than a defined size, and the discovery message may include an application layer group ID code representing an application layer group identifier (ID), where the application layer group ID code may be a hash of the application layer group ID. Furthermore, the first set of time parameters may include a counter associated with a first time instance, and the second set of time parameters may include a counter associated with a second time instance. Also, the first set of time parameters may be a first set of freshness parameters, the second set of time parameters may be a second set of freshness parameters, and the counter may be a Coordinated Universal Time (UTC)-based counter. Furthermore, to obtain the discovery message, the UE may receive a discovery message from a second UE via at least one of the transceiver or antenna.
[0100] At 880, the UE 802 may descramble the discovery message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters.
[0101] At 882, the UE 802 may decrypt the discovery message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters.
[0102] Further, the UE 802 may encrypt the response message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters before transmitting the response message. The UE 802 may also scramble the response message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters after encrypting the response message before transmitting the response message.
[0103] At 890, the UE 802 may send a response message to the second UE in response to the discovery message, where the response message is a second discovery message including at least a response code. The response message may correspond to the response code of Figure 7. Thus, step 890 of Figure 8 may correspond to step 724 of Figure 7.
[0104] 9 is a flowchart 900 of a method of wireless communication. The method may be performed by a UE (e.g., UE 104, monitoring UE 601, announcing UE 602, discoverer UE 701, discovered UE 702, device 1304). The UE may be a receiving UE (e.g., a monitoring UE receiving a discovery message from an announcing UE in a Model A restricted discovery security procedure and / or a discovered UE receiving a discovery message from a discoverer UE in a Model B restricted discovery security procedure). The methods described herein may provide several benefits, such as improved resource utilization and / or power savings.
[0105] At 910, the UE may obtain a discovery message encrypted based on at least one of an encryption key, an encryption algorithm, and / or a first set of time parameters, as described with respect to the examples of FIGS. 1-8, where the discovery message is scrambled based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters. For example, as described at 870 of FIG. 8, the UE 802 may obtain a discovery message encrypted based on at least one of an encryption key, an encryption algorithm, and / or a first set of time parameters, where the discovery message is scrambled based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters. Furthermore, step 910 may be performed by component 198 of FIG. 1. In some aspects, the first portion of the discovery message may be encrypted based on an encryption key, an encryption algorithm, or a first set of time parameters. A second portion of the discovery message may be scrambled based on a scrambling key, a scrambling algorithm, or a second set of time parameters, where the second portion may be different from the first portion. Also, the second portion may overlap with the first portion, where a size of the second portion may be less than or equal to a size of a key derivation function associated with the scrambling key. Furthermore, a third portion of the discovery message may not be scrambled, and the third portion may be different from the first and second portions. The discovery message may be less than a defined size, and the discovery message may include an application layer group ID code representing an application layer group identifier (ID), where the application layer group ID code may be a hash of the application layer group ID. Furthermore, the first set of time parameters may include a counter associated with the first time instance, and the second set of time parameters may include a counter associated with the second time instance.Additionally, the first set of time parameters may be a first set of freshness parameters, the second set of time parameters may be a second set of freshness parameters, and the counter may be a Coordinated Universal Time (UTC) based counter. Further, to obtain the discovery message, the UE may receive a discovery message from a second UE via at least one of the transceiver or the antenna.
[0106] At 912, the UE may descramble the discovery message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters, as described with respect to the examples of Figures 1-8. For example, as described at 880 of Figure 8, the UE 802 may descramble the discovery message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters. Additionally, step 912 may be performed by component 198 of Figure 1.
[0107] At 914, the UE may decrypt the discovery message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters, as described with respect to the examples of Figures 1-8. For example, as described at 882 of Figure 8, the UE 802 may decrypt the discovery message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters. Additionally, step 914 may be performed by component 198 of Figure 1.
[0108] In some aspects, the UE may send a response message to the second UE in response to the discovery. In some aspects, the encryption key may be derived based on a key obtained from a network function (e.g., DDNMF). In some aspects, the encryption algorithm may be obtained from a network function (e.g., DDNMF). In some aspects, the scrambling algorithm may be configured by the system, and the scrambling algorithm may be different from the encryption algorithm. In some aspects, the first part of the discovery message may be encrypted based on an encryption key, an encryption algorithm, or a first set of freshness parameters. In some aspects, the first part of the discovery message may be determined by a mask. In some aspects, the mask may be obtained from a network function or may be configured by a network function (e.g., DDNMF). In some aspects, the second UE may be a transmitting UE (announcer UE that sends a discovery message to a monitoring UE in model A, or a discoverer UE that sends a discovery message to a discovered UE, which replies in response).
[0109] In some aspects, the second portion of the discovery message may be scrambled based on a scrambling key, a scrambling algorithm, or a second set of freshness parameters, and the third portion of the discovery message may not be scrambled. In some aspects, the second portion may overlap with the first portion. In some aspects, a size of the second portion may be less than or equal to a size of a key derivation function associated with the scrambling key. In some aspects, the scrambling key may be a discovery user scrambling key (DUSK). In some aspects, the encryption key may be based at least on a discovery user secret key (DUCK), a first set of freshness parameters, or a message-specific parameter. In some aspects, the message-specific parameter may be a message integrity check (MIC). In some aspects, the discovery message may be less than a defined size, and the discovery message may include an application layer group ID code representing an application layer group identifier (ID). In some aspects, the application layer group ID code representing the application layer group ID may be a hash of the application layer group ID. In some aspects, the UE may send a discovery request message to a Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) including a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID) associated with the UE, the discovery request message further including a sidelink UE security capability representing a list of supported encryption algorithms including an encryption algorithm. In some aspects, the UE may receive a discovery response message from the DDNMF including a ProSe code, the discovery response message further including a selected encryption algorithm in the list of supported encryption algorithms associated with the UE. In some aspects, the first set of freshness parameters may include a first time-based counter and the second set of freshness parameters may include a second time-based counter.
[0110] 10 is a flowchart 1000 of a method of wireless communication. The method may be performed by a UE (e.g., UE 104, monitoring UE 601, announcing UE 602, discoverer UE 701, discovered UE 702, device 1304). The UE may be a receiving UE (e.g., a monitoring UE receiving a discovery message from an announcing UE in a Model A restricted discovery security procedure and / or a discovered UE receiving a discovery message from a discoverer UE in a Model B restricted discovery security procedure). The methods described herein may provide several benefits, such as improved resource utilization and / or power savings.
[0111] At 1002, the UE may perform the following before obtaining the discovery message: sending a discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID) associated with the UE to a network entity, as described with respect to the examples of Figures 1-8, where the discovery request message further includes a sidelink UE security capability representing a list of supported encryption algorithms including an encryption algorithm. For example, as described at 810 of Figure 8, the UE 802 may perform the following before obtaining the discovery message: sending a discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID) associated with the UE to a network entity, where the discovery request message further includes a sidelink UE security capability representing a list of supported encryption algorithms including an encryption algorithm. Furthermore, step 1002 may be performed by component 198 of Figure 1.
[0112] Also, in 1002, the UE may receive a discovery response message including a ProSe code from a network entity prior to obtaining the discovery message, as described with respect to the examples of Figures 1-8, where the discovery response message further includes a selected encryption algorithm in a list of supported encryption algorithms associated with the UE. For example, as described in 810 of Figure 8, the UE 802 may receive a discovery response message including a ProSe code from a network entity prior to obtaining the discovery message, where the discovery response message further includes a selected encryption algorithm in a list of supported encryption algorithms associated with the UE. Furthermore, step 1002 may be performed by component 198 of Figure 1. The discovery response message may further include at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value.
[0113] At 1004, the UE may perform prior to obtaining a mask from a network entity, as described with respect to the examples of Figures 1-8, where a first portion of the discovery message is indicated by the mask. For example, as described at 822 of Figure 8, the UE 802 may perform prior to obtaining a mask from a network entity, where a first portion of the discovery message is indicated by the mask. Furthermore, step 1004 may be performed by component 198 of Figure 1.
[0114] At 1006, the UE may obtain an indication of a scrambling algorithm and a scrambling key before obtaining the discovery message, as described with respect to the examples of FIG. 1-FIG. 8, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. For example, as described at 832 of FIG. 8, the UE 802 may obtain an indication of a scrambling algorithm and a scrambling key before obtaining the discovery message, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. Furthermore, step 1006 may be performed by component 198 of FIG. 1. In some aspects, to obtain the indication of the scrambling algorithm and the scrambling key, the UE may receive the indication of the scrambling algorithm and the scrambling key from a network entity. Thus, the UE may receive the indication of the scrambling algorithm and the scrambling key from the network entity. Also, the network entity may be a Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN). The scrambling key may be a discovery user scrambling key (DUSK).
[0115] At 1008, the UE may obtain an indication of an encryption algorithm and a security key before obtaining the discovery message and derive the encryption key based on at least one of the security key or the first set of time parameters, as described with respect to the examples of FIG. 1-FIG. 8. For example, as described at 840 of FIG. 8, the UE 802 may obtain an indication of an encryption algorithm and a security key before obtaining the discovery message and derive the encryption key based on at least one of the security key or the first set of time parameters. Furthermore, step 1008 may be performed by component 198 of FIG. 1. In some aspects, to obtain the indication of the encryption algorithm and the security key, the UE may receive the indication of the encryption algorithm and the security key from a network entity. Thus, the UE may receive the indication of the encryption algorithm and the security key from the network entity. Also, the network entity may be a Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN). Additionally, the encryption key may be based on a discovery user secret key (DUCK), a first set of time parameters, or a message-specific parameter, which may be a message integrity check (MIC) or a random string.
[0116] At 1010, the UE may obtain a discovery message encrypted based on at least one of an encryption key, an encryption algorithm, and / or a first set of time parameters, as described with respect to the examples of FIGS. 1-8, where the discovery message is scrambled based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters. For example, as described at 870 of FIG. 8, the UE 802 may obtain a discovery message encrypted based on at least one of an encryption key, an encryption algorithm, and / or a first set of time parameters, where the discovery message is scrambled based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters. Furthermore, step 1010 may be performed by component 198 of FIG. 1. In some aspects, the first portion of the discovery message may be encrypted based on the encryption key, the encryption algorithm, or the first set of time parameters. A second portion of the discovery message may be scrambled based on a scrambling key, a scrambling algorithm, or a second set of time parameters, where the second portion may be different from the first portion. Also, the second portion may overlap with the first portion, where a size of the second portion may be less than or equal to a size of a key derivation function associated with the scrambling key. Furthermore, a third portion of the discovery message may not be scrambled, and the third portion may be different from the first and second portions. The discovery message may be less than a defined size, and the discovery message may include an application layer group ID code representing an application layer group identifier (ID), where the application layer group ID code may be a hash of the application layer group ID. Furthermore, the first set of time parameters may include a counter associated with the first time instance, and the second set of time parameters may include a counter associated with the second time instance.Additionally, the first set of time parameters may be a first set of freshness parameters, the second set of time parameters may be a second set of freshness parameters, and the counter may be a Coordinated Universal Time (UTC) based counter. Further, to obtain the discovery message, the UE may receive a discovery message from a second UE via at least one of the transceiver or the antenna.
[0117] At 1012, the UE may descramble the discovery message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters, as described with respect to the examples of Figures 1-8. For example, as described at 880 of Figure 8, the UE 802 may descramble the discovery message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters. Furthermore, step 1012 may be performed by component 198 of Figure 1.
[0118] At 1014, the UE may decrypt the discovery message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters, as described with respect to the examples of Figures 1-8. For example, as described at 882 of Figure 8, the UE 802 may decrypt the discovery message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters. Additionally, step 1014 may be performed by component 198 of Figure 1.
[0119] Further, the UE may encrypt the response message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters before transmitting the response message. The UE 802 may also scramble the response message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters after encrypting the response message before transmitting the response message.
[0120] At 1016, the UE may perform sending a response message to the second UE in response to the discovery message, as described with respect to the examples of Figures 1-8, where the response message is a second discovery message including at least a response code. For example, as described at 890 of Figure 8, the UE 802 may perform sending a response message to the second UE in response to the discovery message, where the response message is a second discovery message including at least a response code. Furthermore, step 1016 may be performed by component 198 of Figure 1.
[0121] 11 is a flowchart 1100 of a method of wireless communication. The method may be performed by a network entity such as a DDNMF or a base station (e.g., base station 102, DDNMF 603, DDNMF 604, DDNMF 605, DDNMF 703, DDNMF 704, DDNMF 705, network entity 1302, network entity 1402, network entity 1560). The methods described herein may provide several benefits, such as improved resource utilization and / or power conservation.
[0122] At 1102, the network entity may perform receiving a first discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID), as described with respect to the examples of FIG. 1-8, where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). For example, as described at 812 of FIG. 8, the network entity 804 may perform receiving a first discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID), where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). Furthermore, step 1102 may be performed by the discovery component 199 of FIG. 1. In some aspects, to receive the first discovery request message, the network entity may receive the first discovery request message via at least one of a transceiver or an antenna.
[0123] In 1104, the network entity may perform transmitting a first discovery response message including a ProSe code, as described with respect to the examples of Figures 1-8, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. For example, as described in 816 of Figure 8, the network entity 804 may perform transmitting a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. Furthermore, step 1104 may be performed by the discovery component 199 of Figure 1.
[0124] In some aspects, a network entity may receive a first discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID), the first discovery request message further including a security capability of a sidelink user equipment (UE) representing a first list of supported encryption algorithms associated with the first UE. The network entity may also transmit a first discovery response message including a ProSe code, the first discovery response message further including a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The network entity may also receive a second discovery request message from a second DDNMF, the second discovery response message further including a security capability of a sidelink UE representing a second list of supported encryption algorithms associated with the second UE. The network entity may also transmit a second discovery response message including the ProSe code and the selected encryption algorithm to the second DDNMF.
[0125] 12 is a flowchart 1200 of a method of wireless communication. The method may be performed by a network entity such as a DDNMF or a base station (e.g., base station 102, DDNMF 603, DDNMF 604, DDNMF 605, DDNMF 703, DDNMF 704, DDNMF 705, network entity 1302, network entity 1402, network entity 1560). The methods described herein may provide several benefits, such as improved resource utilization and / or power conservation.
[0126] At 1202, the network entity may perform receiving a first discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID), as described with respect to the examples of FIG. 1-8, where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). For example, as described at 812 of FIG. 8, the network entity 804 may perform receiving a first discovery request message including a restricted proximity service (ProSe) application user identifier (RPAUID), where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). Furthermore, step 1202 may be performed by the discovery component 199 of FIG. 1. In some aspects, to receive the first discovery request message, the network entity may receive the first discovery request message via at least one of a transceiver or an antenna.
[0127] In 1204, the network entity may perform transmitting a first discovery response message including a ProSe code, as described with respect to the examples of Figures 1-8, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. For example, as described in 816 of Figure 8, the network entity 804 may perform transmitting a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. Furthermore, step 1204 may be performed by the discovery component 199 of Figure 1.
[0128] At 1206, the network entity may perform transmitting a mask for the first UE, as described with respect to the examples of Figures 1-8, where the first portion of the discovery message is indicated by the mask. For example, as described at 820 of Figure 8, the network entity 804 may perform transmitting a mask for the first UE, where the first portion of the discovery message is indicated by the mask. Furthermore, step 1206 may be performed by the discovery component 199 of Figure 1.
[0129] At 1208, the network entity may send an indication of a scrambling algorithm and a scrambling key for the first UE, as described with respect to the examples of Figures 1-8, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. For example, as described at 830 of Figure 8, the network entity 804 may send an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. Furthermore, step 1208 may be performed by the discovery component 199 of Figure 1.
[0130] In 1210, the network entity may perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message, as described with respect to the examples of Figures 1-8. For example, as described in 850 of Figure 8, the network entity 804 may perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. Furthermore, step 1210 may be performed by the discovery component 199 of Figure 1.
[0131] At 1212, the network entity may receive from the second network entity after transmitting the first discovery response message a second discovery request message further including sidelink UE security capabilities representing a second list of supported encryption algorithms associated with the second UE, as described with respect to the examples of Figures 1-8. For example, as described at 860 of Figure 8, the network entity 804 may receive from the second network entity a second discovery request message further including sidelink UE security capabilities representing a second list of supported encryption algorithms associated with the second UE, as described with respect to the examples of Figures 1-8.
[0132] Also, in 1212, the network entity may perform sending a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, as described with respect to the examples of Figures 1-8, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in the Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. For example, as described in 860 of Figure 8, the network entity 804 may perform sending a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in the Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. Furthermore, step 1212 may be performed by the discovery component 199 of Figure 1. The first discovery response message may further include at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value, and the second discovery response message may further include at least one of the first set of security parameters, the second set of security parameters, a current time value, or a maximum time offset value.
[0133] FIG. 13 is a diagram 1300 illustrating an example of a hardware implementation for an apparatus 1304. The apparatus 1304 may be a UE, may be a component of a UE, or may implement UE functionality. In some aspects, the apparatus 1304 may include a cellular baseband processor 1324 (also referred to as a modem) coupled to one or more transceivers 1322 (e.g., cellular RF transceivers). The cellular baseband processor 1324 may include an on-chip memory 1324′. In some aspects, the apparatus 1304 may further include an application processor 1306 coupled to one or more subscriber identity module (SIM) cards 1320, a secure digital (SD) card 1308, and a screen 1310. The application processor 1306 may include an on-chip memory 1306′. In some aspects, the device 1304 may further include a Bluetooth module 1312, a WLAN module 1314, an SPS module 1316 (e.g., a GNSS module), one or more sensor modules 1318 (e.g., a barometric sensor / altimeter, an inertial measurement unit (IMU), a motion sensor such as a gyroscope, and / or accelerometer(s), light detection and ranging (LIDAR), radio assisted detection and ranging (RADAR), sound navigation and ranging (SONAR), a magnetometer, audio, and / or other technologies used for positioning), an additional memory module 1326, a power source 1330, and / or a camera 1332. The Bluetooth module 1312, the WLAN module 1314, and the SPS module 1316 may include an on-chip transceiver (TRX) (or in some cases simply a receiver (RX)).The Bluetooth module 1312, the WLAN module 1314, and the SPS module 1316 may include their own dedicated antennas and / or utilize an antenna 1380 for communication. The cellular baseband processor 1324 communicates with the UE 104 and / or RUs associated with the network entity 1302 through the transceiver(s) 1322 via one or more antennas 1380. The cellular baseband processor 1324 and the application processor 1306 may each include a computer-readable medium / memory 1324', 1306', respectively. The additional memory module 1326 may also be considered a computer-readable medium / memory. Each computer-readable medium / memory 1324', 1306', 1326 may be non-transitory. The cellular baseband processor 1324 and the application processor 1306 are each responsible for general processing, including the execution of software stored in the computer-readable medium / memory. The software, when executed by the cellular baseband processor 1324 / application processor 1306, causes the cellular baseband processor 1324 / application processor 1306 to perform various functions as described above. The computer-readable medium / memory may also be used to store data that is manipulated by the cellular baseband processor 1324 / application processor 1306 when executing the software. The cellular baseband processor 1324 / application processor 1306 may be a component of the UE 350 and may include the memory 360 and / or at least one of the TX processor 368, the RX processor 356, and the controller / processor 359. In one configuration, the device 1304 may be a processor chip (modem and / or application) and may include only the cellular baseband processor 1324 and / or the application processor 1306, while in another configuration, the device 1304 may be an entire UE (e.g., see UE 350 in FIG. 3) and may include additional modules of the device 1304.
[0134] As described above, the discovery component 198 may be configured to obtain an encrypted discovery message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters, where the discovery message is scrambled based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters. The discovery component 198 may also be configured to descramble the discovery message based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters. The discovery component 198 may also be configured to decrypt the discovery message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters. The discovery component 198 may also be configured to transmit a response message to the second UE in response to the discovery message, where the response message is a second discovery message including at least a response code. The discovery component 198 may also be configured to encrypt the response message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters before transmitting the response message. The discovery component 198 may also be configured to scramble the response message before encrypting the response message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters and then transmitting the response message. The discovery component 198 may also be configured to obtain an indication of the encryption algorithm and the security key prior to obtaining the discovery message. The discovery component 198 may also be configured to derive the encryption key based on at least one of the security key or the first set of time parameters. The discovery component 198 may also be configured to obtain an indication of the scrambling algorithm and the scrambling key prior to obtaining the discovery message, where the scrambling algorithm is different from the encryption algorithm and where the scrambling key is different from the encryption key.The discovery component 198 may also be configured to obtain a mask from a network entity prior to obtaining the discovery message, where a first portion of the discovery message is indicated by the mask. The discovery component 198 may also be configured to send a discovery request message comprising a restricted proximity service (ProSe) application user identifier (RPAUID) associated with the UE to the network entity prior to obtaining the discovery message, where the discovery request message further comprises a security capability of the sidelink UE representing a list of supported encryption algorithms including an encryption algorithm. The discovery component 198 may also be configured to receive a discovery response message comprising a ProSe code from the network entity prior to obtaining the discovery message, where the discovery response message further comprises a selected encryption algorithm in a list of supported encryption algorithms associated with the UE. The component 198 may be within the cellular baseband processor 1324, the application processor 1306, or both the cellular baseband processor 1324 and the application processor 1306. The components 198 may be one or more hardware components specifically configured to perform the described processes / algorithms, may be implemented by one or more processors configured to execute the described processes / algorithms, may be stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. As shown, the device 1304 may include various components configured for various functions. In one configuration, the device 1304, particularly the cellular baseband processor 1324 and / or the application processor 1306, may include means for obtaining a discovery message encrypted based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters, where the discovery message is scrambled based on at least one of a scrambling key, an encryption algorithm, or a second set of time parameters.The apparatus 1304 may also include means for descrambling the discovery message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters. The apparatus 1304 may also include means for decrypting the discovery message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters. The apparatus 1304 may also include means for transmitting a response message to the second UE in response to the discovery message, where the response message is a second discovery message including at least the response code. The apparatus 1304 may also include means for encrypting the response message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters before transmitting the response message. The apparatus 1304 may also include means for scrambling the response message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters after encrypting the response message before transmitting the response message. The apparatus 1304 may also include means for obtaining an indication of the encryption algorithm and the security key prior to obtaining the discovery message. The apparatus 1304 may also include means for deriving an encryption key based on at least one of the first set of security keys or the time parameters. The apparatus 1304 may also include means for obtaining an indication of a scrambling algorithm and a scrambling key prior to obtaining the discovery message, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. The apparatus 1304 may also include means for obtaining a mask prior to obtaining the discovery message from the network entity, where the first portion of the discovery message is indicated by the mask. The apparatus 1304 may also include means for sending a discovery request message to the network entity prior to obtaining the discovery message, the discovery request message comprising a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID) associated with the UE, where the discovery request message further includes a security capability of the sidelink UE indicating a list of supported encryption algorithms including the encryption algorithm.The apparatus 1304 may also include means for receiving a discovery response message including the ProSe code from the network entity prior to obtaining the discovery message, where the discovery response message further includes a selected encryption algorithm in a list of supported encryption algorithms associated with the UE. The means may be a component 198 of the apparatus 1304 configured to perform the functions recited by the means. As described above, the apparatus 1304 may include a TX processor 368, a RX processor 356, and a controller / processor 359. Thus, in one configuration, the means may be the TX processor 368, the RX processor 356, and / or the controller / processor 359 configured to perform the functions recited by the means.
[0135] FIG. 14 is a diagram 1400 illustrating an example of a hardware implementation for a network entity 1402. The network entity 1402 may be a BS, may be a component of a BS, or may implement BS functions. The network entity 1402 may include at least one of a CU 1410, a DU 1430, or a RU 1440. For example, depending on the layer functions processed by the component 199, the network entity 1402 may include a CU 1410, both the CU 1410 and the DU 1430, each of the CU 1410, the DU 1430, and the RU 1440, both the DU 1430, the DU 1430, and the RU 1440, or a RU 1440. The CU 1410 may include a CU processor 1412. The CU processor 1412 may include an on-chip memory 1412′. In some aspects, the CU 1410 may further include an additional memory module 1414 and a communication interface 1418. The CU 1410 communicates with the DU 1430 via a midhaul link, such as an F1 interface. The DU 1430 may include a DU processor 1432. The DU processor 1432 may include an on-chip memory 1432'. In some aspects, the DU 1430 may further include an additional memory module 1434 and a communication interface 1438. The DU 1430 communicates with the RU 1440 via a fronthaul link. The RU 1440 may include a RU processor 1442. The RU processor 1442 may include an on-chip memory 1442'. In some aspects, the RU 1440 may further include an additional memory module 1444, one or more transceivers 1446, an antenna 1480, and a communication interface 1448. The RU 1440 communicates with the UE 104. The on-chip memories 1412', 1432', 1442' and the additional memory modules 1414, 1434, 1444 may each be considered a computer-readable medium / memory. Each computer-readable medium / memory may be non-transitory. Each of the processors 1412, 1432, 1442 is responsible for general processing, including the execution of software stored in the computer-readable medium / memory.The software, when executed by a corresponding processor(s), causes the processor(s) to perform the various functions described above. The computer-readable medium / memory may also be used to store data that is manipulated by the processor(s) when executing the software.
[0136] As described above, the discovery component 199 may be configured to receive a first discovery request message including a restricted proximity services (ProSe) application user identifier (RPAUID), where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). The discovery component 199 may also be configured to transmit a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The discovery component 199 may also be configured to receive a second discovery request message from the second network entity after transmitting the first discovery response message, where the second discovery request message further includes a sidelink UE security capability representing a second list of supported encryption algorithms associated with the second UE. The discovery component 199 may also be configured to send a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. The discovery component 199 may also be configured to send a mask for the first UE, where the first portion of the discovery message is indicated by the mask. The discovery component 199 may also be configured to send an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key.The discovery component 199 may also be configured to perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. The component 199 may be in one or more processors of one or more of the CU 1410, the DU 1430, and the RU 1440. The component 199 may be one or more hardware components specifically configured to perform the described processes / algorithms, may be implemented by one or more processors configured to perform the described processes / algorithms, may be stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. The network entity 1402 may include various components configured for various functions. In one configuration, the network entity 1402 may include means for receiving a first discovery request message including a restricted proximity services (ProSe) application user identifier (RPAUID), where the first discovery request message further includes security capabilities of a sidelink user equipment (UE) representing a first list of supported encryption algorithms associated with the first UE. The network entity 1402 may include means for transmitting a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The network entity 1402 may include means for receiving a second discovery request message from the second network entity after transmitting the first discovery response message, where the second discovery request message further includes security capabilities of a sidelink UE representing a second list of supported encryption algorithms associated with the second UE.The network entity 1402 may include means for sending a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. The network entity 1402 may include means for sending a mask for the first UE, where a first portion of the discovery message is indicated by the mask. The network entity 1402 may include means for sending an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. The network entity 1402 may include means for performing at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. The means may be a component 199 of the network entity 1402 configured to perform the functions recited by the means. As described above, the network entity 1402 may include a TX processor 316, a RX processor 370, and a controller / processor 375. Thus, in one configuration, the means may be the TX processor 316, the RX processor 370, and / or the controller / processor 375 configured to perform the functions recited by the means.
[0137] FIG. 15 is a diagram 1500 illustrating an example of a hardware implementation for a network entity 1560. In one example, the network entity 1560 may be in the core network 120. The network entity 1560 may include a network processor 1512. The network processor 1512 may include an on-chip memory 1512′. In some aspects, the network entity 1560 may further include an additional memory module 1514. The network entity 1560 communicates with the CU 1502 via a network interface 1580, either directly (e.g., a backhaul link) or indirectly (e.g., through a RIC). The on-chip memory 1512′ and the additional memory module 1514 may each be considered a computer-readable medium / memory. Each computer-readable medium / memory may be non-transitory. The processor 1512 is responsible for the overall processing, including the execution of software stored on the computer-readable medium / memory. The software, when executed by a corresponding processor(s), causes the processor(s) to perform various functions described above. The computer-readable medium / memory may also be used for storing data that is manipulated by the processor(s) when executing software.
[0138] As described above, the discovery component 199 may be configured to receive a first discovery request message including a restricted proximity services (ProSe) application user identifier (RPAUID), where the first discovery request message further includes a sidelink UE security capability representing a first list of supported encryption algorithms associated with the first user equipment (UE). The discovery component 199 may also be configured to transmit a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The discovery component 199 may also be configured to receive a second discovery request message from the second network entity after transmitting the first discovery response message, where the second discovery request message further includes a sidelink UE security capability representing a second list of supported encryption algorithms associated with the second UE. The discovery component 199 may also be configured to send a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. The discovery component 199 may also be configured to send a mask for the first UE, where the first portion of the discovery message is indicated by the mask. The discovery component 199 may also be configured to send an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key.The discovery component 199 may also be configured to perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. The component 199 may be within the processor 1512. The component 199 may be one or more hardware components specifically configured to perform the described processes / algorithms, may be implemented by one or more processors configured to perform the described processes / algorithms, may be stored in a computer-readable medium for implementation by one or more processors, or some combination thereof. The network entity 1560 may include various components configured for various functions. In one configuration, the network entity 1560 may include means for receiving a first discovery request message including a restricted proximity services (ProSe) application user identifier (RPAUID), where the first discovery request message further includes a security capability of a sidelink user equipment (UE) representing a first list of supported encryption algorithms associated with the first UE. The network entity 1560 may also include means for transmitting a first discovery response message including a ProSe code, where the first discovery response message further includes a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE. The network entity 1560 may also include means for receiving a second discovery request message from the second network entity after transmitting the first discovery response message, where the second discovery request message further includes a security capability of a sidelink UE representing a second list of supported encryption algorithms associated with the second UE.The network entity 1560 may also include means for sending a second discovery response message including the ProSe code and the selected encryption algorithm for the second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN. The network entity 1560 may also include means for sending a mask for the first UE, where the first portion of the discovery message is indicated by the mask. The network entity 1560 may also include means for sending an indication of a scrambling algorithm and a scrambling key for the first UE, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key. The network entity 1560 may also include means for performing at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message. The means may be a component 199 of the network entity 1560 configured to perform the functions recited by the means.
[0139] It should be understood that the particular order or hierarchy of the blocks in the disclosed processes / flow charts is an example of an example approach. It should be understood that the particular order or hierarchy of the blocks in those processes / flow charts can be rearranged based on design preferences. Further, some blocks can be combined or omitted. The accompanying method claims present elements of the various blocks in an example order and are not limited to the particular order or hierarchy presented.
[0140] The foregoing description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Thus, the claims are not limited to the aspects described herein, but are to be accorded the full scope consistent with the language of the claims. Reference to an element in the singular is not intended to mean "only one" unless so expressly stated, but rather "one or more." Terms such as "if," "when," and "while" do not imply an immediate temporal relationship or reaction. That is, these phrases, such as "when," do not imply an immediate action in response to or during the occurrence of an action, but simply mean that an action will occur if a condition is met, but do not require any specific or immediate temporal constraint for the action to occur. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other aspects. Unless expressly stated otherwise, the term "some" refers to one or more. Combinations such as "at least one of A, B, or C," "one or more of A, B, or C," "at least one of A, B, and C," "one or more of A, B, and C," and "A, B, C, or any combination thereof" include any combination of A, B, and / or C, and may include multiple As, multiple Bs, or multiple Cs.Specifically, combinations such as "at least one of A, B, or C", "one or more of A, B, or C", "at least one of A, B, and C", "one or more of A, B, and C", and "A, B, C, or any combination thereof" can be A only, B only, C only, A and B, A and C, B and C, or A and B and C, and any such combination can include one or more elements of A, B, or C. A set should be interpreted as a set of elements, the number of elements being one or more. Thus, for a set of X, X will include one or more elements. When a first device receives data from or transmits data to a second device, the data can be received / transmitted directly between the first device and the second device, or indirectly between the first device and the second device via a set of devices. A device configured to "output" data, such as a transmission, signal, or message, may transmit the data, for example, using a transceiver, or may send the data to a device that transmits the data. A device configured to "receive" data, such as a transmission, signal, or message, may receive the data, for example, using a transceiver, or may obtain the data from a device that receives the data. All structural and functional equivalents to the elements of the various aspects described throughout this disclosure that are known or later become known to those of skill in the art are expressly incorporated herein by reference and are encompassed by the claims. Furthermore, nothing disclosed herein is intended to be made public, regardless of whether such disclosure is expressly recited in the claims. Words such as "module," "mechanism," "element," "device," and the like may not be substitutes for the word "means." Thus, no element of a claim should be construed as a means-plus-function unless the element is expressly recited using the phrase "means."
[0141] As used herein, the phrase "based on" should not be construed as a reference to a closed set of information, condition(s), factor(s), etc. In other words, the phrase "based on A" (where "A" can be information, condition, factor, etc.) is to be construed as "based on at least A," unless expressly stated otherwise.
[0142] The following aspects are exemplary only and can be combined with other aspects or teachings described herein without limitation.
[0143] Aspect 1 is an apparatus for wireless communication in a first user equipment (UE), the apparatus including: a memory; and at least one processor coupled to the memory, where the at least one processor is configured to: based at least in part on information stored in the memory, obtain a discovery message encrypted based on at least one of an encryption key, encryption algorithm, or a first set of time parameters, where the discovery message is scrambled based on at least one of a second set of scrambling key, scrambling algorithm, or time parameters; descramble the discovery message based on the at least one of the scrambling key, scrambling algorithm, or second set of time parameters; and decrypt the discovery message based on the at least one of the first set of encryption key, encryption algorithm, or time parameters.
[0144] Example 2 is the apparatus of example 1, where the at least one processor is further configured to transmit a response message to the second UE in response to the discovery message, the response message being a second discovery message including at least a response code.
[0145] Example 3 is the apparatus of example 2, where the at least one processor is further configured to encrypt the response message prior to transmission of the response message based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters, and scramble the response message prior to transmission of the response message based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters.
[0146] Aspect 4 is the device of any of aspects 1-3, where the at least one processor is further configured to obtain an indication of an encryption algorithm and a security key prior to obtaining the discovery message, and to derive the encryption key based on at least one of the first set of security keys or time parameters.
[0147] Example 5 is the apparatus of example 4, wherein to obtain an indication of an encryption algorithm and a security key, the at least one processor is configured to receive an indication of the encryption algorithm and the security key from a network entity, the network entity being a Directly Discovered Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN).
[0148] Aspect 6 is the device of any of aspects 4 to 5, wherein the encryption key is based on a discovery user secret key (DUCK), a first set of time parameters, or a message-specific parameter, and the message-specific parameter is a message integrity check (MIC) or a random string.
[0149] Example 7 is the apparatus of any of Examples 1-6, where the at least one processor is further configured to obtain an indication of a scrambling algorithm and a scrambling key prior to obtaining the discovery message, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key.
[0150] Example 8 is the apparatus of example 7, where to obtain the indication of the scrambling algorithm and the scrambling key, the at least one processor is configured to receive the indication of the scrambling algorithm and the scrambling key from a network entity, the network entity being a Directly Discovered Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN).
[0151] A ninth aspect is the device of any one of the seventh to eighth aspects, wherein the scrambling key is a discovery user scrambling key (DUSK).
[0152] Example 10 is the apparatus of any of Examples 1-9, wherein the first portion of the discovery message is encrypted based on a first set of an encryption key, an encryption algorithm, or a time parameter.
[0153] Example 11 is the apparatus of example 10, where the at least one processor is further configured to obtain a mask from the network entity prior to obtaining the discovery message, where a first portion of the discovery message is indicated by the mask.
[0154] Example 12 is the device of any of Examples 10 to 11, wherein a second portion of the discovery message is scrambled based on a second set of a scrambling key, a scrambling algorithm, or time parameters, the second portion being different from the first portion.
[0155] Example 13 is the apparatus of example 12, wherein the second portion overlaps with the first portion, and a size of the second portion is less than or equal to a size of a key derivation function associated with the scrambling key.
[0156] Example 14 is the device of any of Examples 12 to 13, wherein a third portion of the discovery message is not scrambled, and the third portion is different from the first portion and the second portion.
[0157] Example 15 is the device of any of examples 1 to 14, wherein the discovery message is less than a defined size, the discovery message includes an application layer group ID code representing an application layer group identifier (ID), and the application layer group ID code is a hash of the application layer group ID.
[0158] Example 16 is the apparatus of any of Examples 1-15, where the at least one processor is further configured to: send a discovery request message to a network entity prior to obtaining the discovery message, the discovery request message comprising a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID) associated with the UE, the discovery request message further comprising sidelink UE security capabilities representing a list of supported encryption algorithms including an encryption algorithm; and receive a discovery response message from the network entity prior to obtaining the discovery message, the discovery response message comprising a ProSe code, the discovery response message further comprising a selected encryption algorithm in the list of supported encryption algorithms associated with the UE.
[0159] Example 17 is the apparatus of example 16, where the discovery response message further includes at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value.
[0160] Example 18 is the apparatus of any of examples 1-17, where the first set of time parameters includes a counter associated with a first time instance, and the second set of time parameters includes a counter associated with a second time instance.
[0161] Example 19 is the device of any of Examples 1 to 18, wherein the first set of time parameters is a first set of freshness parameters, the second set of time parameters is a second set of freshness parameters, and the counter is a Coordinated Universal Time (UTC) based counter.
[0162] Example 20 is the apparatus of any of Examples 1-19, where the apparatus is a wireless communication device and further includes at least one of a transceiver or an antenna coupled to the at least one processor, and to obtain the discovery message, the at least one processor is configured to receive a discovery message from a second UE via the at least one of the transceiver or antenna.
[0163] Aspect 21 is an apparatus for wireless communication in a first network entity, the apparatus including: a memory; and at least one processor coupled to the memory, wherein based at least in part on information stored in the memory, the at least one processor is configured to: receive a first discovery request message including a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID), the first discovery request message further including a security capability of a sidelink UE representing a first list of supported encryption algorithms associated with the first user equipment (UE); and transmit a first discovery response message including a ProSe code, the first discovery response message further including a selected encryption algorithm in the first list of supported encryption algorithms associated with the first UE.
[0164] Example 22 is the apparatus of example 21, where the at least one processor is further configured to receive, after transmitting the first discovery response message, from a second network entity, a second discovery request message further including a sidelink UE security capability representing a second list of supported encryption algorithms associated with the second UE.
[0165] Example 23 is the apparatus of example 22, where the at least one processor is further configured to send a second discovery response message including the ProSe code and the selected encryption algorithm for a second network entity after receiving the second discovery request message, where the first network entity is a first Direct Discovery Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN) and the second network entity is a second DDNMF in the HPLMN.
[0166] Example 24 is the apparatus of example 23, where the first discovery response message further includes at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value, and the second discovery response message further includes at least one of the first set of security parameters, the second set of security parameters, a current time value, or a maximum time offset value.
[0167] Example 25 is the device of any of Examples 23 to 24, where the at least one processor is further configured to perform at least one of (1) a first authorization procedure based on at least one of the first discovery request message or the first discovery response message, or (2) a second authorization procedure based on at least one of the second discovery request message or the second discovery response message.
[0168] Example 26 is the apparatus of any of Examples 21-25, wherein the at least one processor is further configured to transmit a mask for the first UE, where the first portion of the discovery message is indicated by the mask.
[0169] Example 27 is the apparatus of example 26, where the at least one processor is further configured to transmit an indication of a scrambling algorithm and a scrambling key for the first UE, where the discovery message is associated with at least one of the scrambling algorithm, the scrambling key, an encryption algorithm, or an encryption key, where the scrambling algorithm is different from the encryption algorithm and the scrambling key is different from the encryption key.
[0170] Example 28 is the apparatus of any of Examples 21 to 27, where the apparatus is a wireless communications device and further includes at least one of a transceiver or an antenna coupled to the at least one processor, and to receive the first discovery request message, the at least one processor is configured to receive the first discovery request message via the at least one of the transceiver or antenna.
[0171] Example 29 is a method of wireless communication implementing any of Examples 1-19.
[0172] Example 30 is a method of wireless communication implementing any of examples 21-27.
[0173]
[0023] Aspect 31 is an apparatus for wireless communication including means for implementing any of aspects 1 to 19.
[0174]
[0032] Aspect 32 is an apparatus for wireless communication including means for implementing any of aspects 21 to 27.
[0175] Aspect 33 is a computer-readable medium (e.g., a non-transitory computer-readable medium) storing computer-executable code that, when executed by at least one processor, causes the at least one processor to implement any of aspects 1 to 19.
[0176] Aspect 34 is a computer-readable medium (e.g., a non-transitory computer-readable medium) storing computer-executable code that, when executed by at least one processor, causes the at least one processor to implement any of aspects 21 to 27.
Claims
1. 1. An apparatus for wireless communication in a first user equipment (UE), comprising: Memory and at least one processor coupled to the memory; and wherein, based at least in part on information stored in the memory, the at least one processor: obtaining a discovery message, wherein a first portion of the discovery message is encrypted based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters, and a second portion of the discovery message is scrambled based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters, the second portion being different from the first portion; descrambling the discovery message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters; decrypting the discovery message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters; The apparatus is configured to:
2. the at least one processor: sending a response message to a second UE in response to the discovery message, the response message being a second discovery message including at least a response code. The apparatus of claim 1 , further configured to:
3. the at least one processor: encrypting the response message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters; scrambling the response message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters; The apparatus of claim 2 , further configured to:
4. the at least one processor: obtaining an indication of the encryption algorithm and security key; deriving the encryption key based on at least one of the security key or the first set of time parameters; The apparatus of claim 1 , further configured to:
5. To obtain the indication of the encryption algorithm and the security key, the at least one processor is configured to receive the indication of the encryption algorithm and the security key from a network entity, the network entity being a Directly Discovered Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN); or 5. The apparatus of claim 4, wherein the encryption key is based on a discovery user secret key (DUCK), the first set of time parameters, or a message-specific parameter, the message-specific parameter being a message integrity check (MIC) or a random string.
6. the at least one processor: obtaining an indication of the scrambling algorithm and the scrambling key, the scrambling algorithm being different from the encryption algorithm and the scrambling key being different from the encryption key; The apparatus of claim 1 , further configured to:
7. To obtain the indication of the scrambling algorithm and the scrambling key, the at least one processor is configured to receive the indication of the scrambling algorithm and the scrambling key from a network entity, the network entity being a Directly Discovered Name Management Function (DDNMF) in a Home Public Land Mobile Network (HPLMN); or The apparatus of claim 6 , wherein the scrambling key is a discovery user scrambling key (DUSK).
8. the at least one processor: obtaining a mask from a network entity, the first portion of the discovery message being indicated by the mask; The apparatus of claim 1 , further configured to:
9. the second portion overlaps with the first portion, and the size of the second portion is less than or equal to the size of a key derivation function associated with a scrambling key; or The apparatus of claim 1 , wherein a third portion of the discovery message is not scrambled, and wherein the third portion is different from the first portion and the second portion.
10. 2. The apparatus of claim 1, wherein the discovery message is less than a defined size, the discovery message comprises an application layer group ID code representing an application layer group identifier (ID), the application layer group ID code being a hash of the application layer group ID.
11. the at least one processor: sending a discovery request message to a network entity, the discovery request message comprising a Restricted Proximity Services (ProSe) Application User Identifier (RPAUID) associated with the UE, the discovery request message further comprising sidelink UE security capabilities indicating a list of supported encryption algorithms comprising the encryption algorithm; receiving a discovery response message from the network entity, the discovery response message comprising a ProSe code, the discovery response message further comprising a selected encryption algorithm in the list of supported encryption algorithms associated with the UE; The apparatus of claim 1 , further configured to:
12. 12. The apparatus of claim 11, wherein the discovery response message further comprises at least one of a first set of security parameters, a second set of security parameters, a current time value, or a maximum time offset value.
13. the first set of time parameters comprises a counter associated with a first time instance, and the second set of time parameters comprises the counter associated with a second time instance; 2. The apparatus of claim 1, wherein the first set of time parameters are a first set of freshness parameters, the second set of time parameters are a second set of freshness parameters, and the counter is a Coordinated Universal Time (UTC)-based counter.
14. 10. The apparatus of claim 1, wherein the apparatus is a wireless communication device and further comprises at least one of a transceiver or an antenna coupled to the at least one processor, wherein the at least one processor is configured to receive the discovery message from a second UE via the transceiver or the at least one of the antenna to obtain the discovery message.
15. 1. A method of wireless communication for a first user equipment (UE), comprising: obtaining a discovery message, wherein a first portion of the discovery message is encrypted based on at least one of an encryption key, an encryption algorithm, or a first set of time parameters, and a second portion of the discovery message is scrambled based on at least one of a scrambling key, a scrambling algorithm, or a second set of time parameters, the second portion being different from the first portion; descrambling the discovery message based on at least one of the scrambling key, the scrambling algorithm, or the second set of time parameters; decrypting the discovery message based on at least one of the encryption key, the encryption algorithm, or the first set of time parameters; A method comprising: