Reporting hashed expected channel measurements

JP2025514613A5Pending Publication Date: 2026-01-14QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024556579
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-04-06
Filing Date
2023-02-01
Publication Date
2026-01-14

AI Technical Summary

Technical Problem

Current wireless communication systems face challenges in accurately detecting positioning reference signal (PRS) attacks, which can compromise the integrity of location-based services.

Method used

A method implemented by a network node that involves receiving a set of hash values based on hash operations applied to predicted measurements of PRS resources, and comparing them with actual measurements to determine if they fall within tolerance limits, thereby detecting potential PRS attacks.

Benefits of technology

This approach effectively enhances the security of wireless communication systems by accurately identifying and mitigating PRS attacks, thereby ensuring the reliability of location-based services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

In one aspect, a network node may receive a first set of one or more hash values ​​based on one or more hash operations applied to expected measurements of positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs). The network node may measure the PRS resources to obtain actual measurements. The network node may determine whether the actual measurements of the PRS resources are within tolerance limits of the expected measurements based on a comparison of a second set of hash values ​​to the first set of hash values, the second set of hash values ​​being based on application of the one or more hash operations to the actual measurements.
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] 1. Field of disclosure Aspects of the present disclosure relate generally to wireless communications.

[0002] 2. Description of Related Technology

[0002] Wireless communication systems have evolved through various generations, including first-generation analog wireless telephone service (1G), second-generation (2G) digital wireless telephone service (including interim 2.5G and 2.75G networks), third-generation (3G) high-speed data, Internet-enabled wireless service, and fourth-generation (4G) service (e.g., Long-Term Evolution (LTE) or WiMax). Currently, many different types of wireless communication systems are in use, including cellular systems and personal communications service (PCS) systems. Examples of known cellular systems include the cellular analog advanced mobile phone system (AMPS) and digital cellular systems based on code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), Global System for Mobile communications (GSM), etc.

[0003]

[0003] The fifth generation (5G) wireless standard, called New Radio (NR), will enable higher data rates, more connections, and better coverage, among other improvements. The 5G standard is designed to provide higher data rates, more accurate positioning (e.g., based on a reference signal for positioning (RS-P), such as a downlink, uplink, or sidelink positioning reference signal (PRS)), and other technical enhancements compared to previous standards, according to the Next Generation Mobile Network Alliance. These enhancements, as well as the use of higher frequency bands, advances in PRS processes and technologies, and dense deployment for 5G, will enable highly accurate 5G-based positioning. Summary of the Invention

[0004]

[0004] The following provides a simplified summary of one or more aspects disclosed herein. Therefore, the following summary should not be considered as an extensive overview of all contemplated aspects, nor should it be considered as identifying key or critical elements of all contemplated aspects or as defining the scope of any particular aspect. Thus, the sole purpose of the following summary is to present certain concepts of one or more aspects of the mechanisms disclosed herein in a simplified form prior to the detailed description presented below.

[0005]

[0005] In one aspect, a method of wireless communications implemented by a network node includes receiving a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more expected measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmit / receive points (TRPs), measuring the one or more PRS resources to obtain one or more actual measurement values, and determining whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​being based on the application of the one or more hash operations to the one or more actual measurement values.

[0006]

[0006] In one aspect, a method of wireless communications implemented by a network node includes receiving from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session, and using the first set of one or more hash values ​​for PRS attack detection.

[0007]

[0007] In one aspect, a network node comprises a memory, at least one transceiver, and at least one processor communicatively coupled to the memory and the at least one transceiver, the at least one processor being configured to: receive via the at least one transceiver a first set of one or more hash values, the first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs); measure the one or more PRS resources to obtain one or more actual measurement values; and determine whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​based on the application of the one or more hash operations to the one or more actual measurement values.

[0008]

[0008] In one aspect, a network node comprises a memory, at least one transceiver, and at least one processor communicatively coupled to the memory and the at least one transceiver, the at least one processor configured to receive from a location server via the at least one transceiver a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session, and to use the first set of one or more hash values ​​for PRS attack detection.

[0009]

[0009] In one aspect, a network node includes means for receiving a first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs), means for measuring the one or more PRS resources to obtain one or more actual measurement values, and means for determining whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values ​​based on the application of the one or more hash operations to the one or more actual measurement values.

[0010]

[0010] In one aspect, a network node includes means for receiving from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session, and means for using the first set of one or more hash values ​​for PRS attack detection.

[0011]

[0011] In one aspect, a non-transitory computer readable medium storing computer-executable instructions, when executed by a network node, causes the network node to receive a first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs), measure the one or more PRS resources to obtain one or more actual measurement values, and determine whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​being based on the application of the one or more hash operations to the one or more actual measurement values.

[0012]

[0012] In one aspect, a non-transitory computer-readable medium storing computer-executable instructions which, when executed by a network node, cause the network node to receive from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session, and to use the first set of one or more hash values ​​for PRS attack detection.

[0013]

[0013] Other objects and advantages associated with the embodiments disclosed herein will become apparent to those skilled in the art based on the accompanying drawings and detailed description. [Brief description of the drawings]

[0014]

[0014] The accompanying drawings are presented to aid in the description of various aspects of the present disclosure and are provided only to illustrate the aspects and not to limit the aspects. [Figure 1]

[0015] FIG. 1 illustrates an example wireless communication system according to an aspect of the present disclosure. [Figure 2A]

[0016] 1 illustrates an exemplary wireless network structure in accordance with an aspect of the present disclosure. [Figure 2B] 1 illustrates an exemplary wireless network structure in accordance with an aspect of the present disclosure. [Figure 3A]

[0017] 1 is a simplified block diagram of several sample aspects of components that may be employed in a user equipment (UE) and configured to support communications as taught herein; [Figure 3B] 1 is a simplified block diagram of several sample aspects of components that may be employed in a base station and configured to support communications as taught herein. [Figure 3C] 1 is a simplified block diagram of several sample aspects of components that may be employed in a network node and configured to support communications as taught herein; [Figure 4]

[0018] 1 illustrates an example Long Term Evolution (LTE) positioning protocol (LPP) call flow between a UE and a location server for performing a positioning operation. [Diagram 5]

[0019] FIG. 2 illustrates an example frame structure according to an aspect of the present disclosure. [Figure 6]

[0020] 1 illustrates examples of various positioning methods supported in New Radio (NR) according to an embodiment of the present disclosure. [Figure 7]

[0021] 1 illustrates a Time Difference of Arrival (TDOA) based positioning procedure in an exemplary wireless communication system, in accordance with an aspect of the present disclosure. [Figure 8]

[0022] FIG. 2 illustrates an exemplary base station communicating with an exemplary UE, in accordance with an aspect of the present disclosure. [Figure 9]

[0023] 1 illustrates an example of a network node location service procedure, according to an aspect of the present disclosure. [Figure 10]

[0024] 1 is a graph illustrating a radio frequency (RF) channel impulse response over time, in accordance with an aspect of the present disclosure. [Figure 11]

[0025] FIG. 1 illustrates an example method of wireless communication implemented by a network node according to an aspect of the present disclosure. [Figure 12]

[0026] FIG. 1 illustrates an example method of wireless communication implemented by a network node according to an aspect of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0015]

[0027] Aspects of the present disclosure are provided in the following description and associated drawings, directed to various examples provided for illustrative purposes. Alternative aspects may be devised without departing from the scope of the present disclosure. Additionally, well-known elements of the present disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of the present disclosure.

[0016]

[0028] The words "exemplary" and / or "example" are used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" and / or "example" is not necessarily to be construed as preferred or advantageous over other aspects. Likewise, the term "aspects of the present disclosure" does not require that all aspects of the present disclosure include the discussed feature, advantage or mode of operation.

[0017]

[0029] Those skilled in the art will appreciate that the information and signals described below may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the following description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof, depending in part on the particular application, desired design, corresponding technology, etc.

[0018]

[0030] Further, many aspects are described in terms of sequences of actions to be performed by, for example, elements of a computing device. It will be appreciated that various actions described herein can be performed by specific circuitry (e.g., application specific integrated circuits (ASICs)), by program instructions executed by one or more processors, or by a combination of both. In addition, the sequence or sequences of actions described herein can be considered to be fully embodied in any form of non-transitory computer-readable storage medium storing a corresponding set of computer instructions that, when executed, cause or instruct an associated processor of a device to perform the functionality described herein. Thus, various aspects of the present disclosure may be embodied in a number of different forms, all of which are contemplated to be within the scope of the claimed subject matter. In addition, for each of the aspects described herein, the corresponding form of any such aspect may be described herein, for example, as "logic configured to" perform the described actions.

[0019]

[0031] The terms "user equipment" (UE) and "base station" as used herein are not intended to be specific or limited to any particular radio access technology (RAT) unless otherwise specified. In general, a UE may be any wireless communication device (e.g., a mobile phone, a router, a tablet computer, a laptop computer, a consumer location device, a wearable (e.g., a smart watch, glasses, augmented reality (AR) / virtual reality (VR) headset, etc.), a vehicle (e.g., a car, a motorcycle, a bicycle, etc.), an Internet of Things (IoT) device, etc.) used by a user to communicate over a wireless communication network. A UE may be mobile or may be stationary (e.g., at a given time) and may communicate with a radio access network (RAN). As used herein, the term "UE" may be referred to interchangeably as an "access terminal" or "AT", "client device", "wireless device", "subscriber device", "subscriber terminal", "subscriber station", "user terminal" or "UT", "mobile device", "mobile terminal", "mobile station", or variations thereof. In general, a UE may communicate with a core network via a RAN, through which the UE may be connected to external networks, such as the Internet, and to other UEs. Of course, other mechanisms for connecting to the core network and / or the Internet are also possible for a UE, such as via a wired access network, a wireless local area network (WLAN) network (e.g., based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 specifications, etc.).

[0020]

[0032] A base station may operate according to one of several RATs in communication with UEs depending on the network in which the base station is deployed and may alternatively be referred to as an access point (AP), network node, Node B, evolved Node B (eNB), next generation eNB (ng-eNB), new radio (NR) Node B (also referred to as gNB or gNode B), etc. A base station may be used primarily to support wireless access by UEs, including supporting data, voice, and / or signaling connections for supported UEs. In some systems, a base station may provide only edge node signaling functions, while in other systems, a base station may provide additional control and / or network management functions. The communication link through which a UE can send signals to a base station is referred to as an uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). The communication links through which a base station may transmit signals to a UE are referred to as downlink (DL) channels or forward link channels (e.g., paging channels, control channels, broadcast channels, forward traffic channels, etc.). As used herein, the term traffic channel (TCH) can refer to either an uplink / reverse traffic channel or a downlink / forward traffic channel.

[0021]

[0033] The term "base station" may refer to a single physical transmission-reception point (TRP) or multiple physical TRPs that may or may not be collocated. For example, when the term "base station" refers to a single physical TRP, the physical TRP may be an antenna of the base station that corresponds to a cell (or several cell sectors) of the base station. When the term "base station" refers to multiple collocated physical TRPs, the physical TRP may be an array of antennas of the base station (e.g., as in a multiple-input multiple-output (MIMO) system or when the base station employs beamforming). When the term "base station" refers to multiple non-collocated physical TRPs, the physical TRP may be a distributed antenna system (DAS) (a network of spatially separated antennas connected to a common source via a transport medium) or a remote radio head (RRH) (a remote base station connected to a serving base station). Instead, non-co-located physical TRPs may be serving base stations that receive measurement reports from the UE and neighboring base stations whose reference radio frequency (RF) signals the UE is measuring. Since a TRP is a point from which a base station transmits and receives wireless signals, as used herein, references to transmission from or reception at a base station should be understood as referring to a particular TRP of the base station.

[0022]

[0034] In some implementations that support positioning of UEs, a base station may not support wireless access by the UE (e.g., may not support data, voice, and / or signaling connections for the UE) but may instead transmit reference signals to the UE to be measured by the UE and / or receive and measure signals transmitted by the UE. Such a base station may be referred to as a positioning beacon (e.g., if it transmits signals to the UE) and / or a location measurement unit (e.g., if it receives and measures signals from the UE).

[0023]

[0035] An "RF signal" includes electromagnetic waves of a given frequency that propagate information through space between a transmitter and a receiver. As used herein, a transmitter may transmit a single "RF signal" or multiple "RF signals" to a receiver. However, the receiver may receive multiple "RF signals" corresponding to each transmitted RF signal due to the propagation characteristics of RF signals through multipath channels. The same RF signal transmitted over different paths between a transmitter and a receiver may be referred to as a "multipath" RF signal. As used herein, an RF signal may also be referred to as a "wireless signal" or simply a "signal" when it is clear from the context that the term "signal" refers to a wireless signal or an RF signal.

[0024]

[0036] 1 illustrates an example wireless communication system 100 according to aspects of the disclosure. The wireless communication system 100 (sometimes referred to as a wireless wide area network (WWAN)) may include various base stations 102 (labeled "BS") and various UEs 104. The base stations 102 may include macrocell base stations (high-power cellular base stations) and / or small cell base stations (low-power cellular base stations). In an aspect, the macrocell base stations may include eNBs and / or ng-eNBs where the wireless communication system 100 corresponds to an LTE network, or gNBs where the wireless communication system 100 corresponds to an NR network, or a combination of both, and the small cell base stations may include femtocells, picocells, microcells, etc.

[0025]

[0037] The base stations 102 may collectively form a RAN and may interface with a core network 170 (e.g., evolved packet core (EPC) or 5G core (5GC)) through the backhaul links 122 and with one or more location servers 172 (e.g., location management function (LMF) or secure user plane location (SUPL) location platform (SLP)) through the core network 170. The location server(s) 172 may be part of the core network 170 or may be external to the core network 170. The location server 172 may be integrated with the base station 102. The UE 104 may communicate with the location server 172 directly or indirectly. For example, the UE 104 may communicate with the location server 172 via the base station 102 currently serving the UE 104. The UE 104 may also communicate with the location server 172 via another path, such as through an application server (not shown), such as through another network, such as through a WLAN access point (AP) (e.g., AP 150 described below). For purposes of signaling, communication between the UE 104 and the location server 172 may be represented as an indirect connection (e.g., through the core network 170), or a direct connection (e.g., as shown via direct connection 128), with intervening nodes (if any) omitted from the signaling diagrams for clarity.

[0026]

[0038] In addition to other functions, the base stations 102 may perform functions related to one or more of the following: forwarding user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection setup and release, load balancing, non-access stratum (NAS) message delivery, NAS node selection, synchronization, RAN sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracing, RAN information management (RIM), paging, positioning, and alert message delivery. The base stations 102 may communicate with each other directly or indirectly (e.g., through EPC / 5GC) via backhaul links 134, which may be wired or wireless.

[0027]

[0039] The base stations 102 may wirelessly communicate with the UEs 104. Each of the base stations 102 may provide communication coverage for a respective geographic coverage area 110. In an aspect, one or more cells may be supported by the base stations 102 in each geographic coverage area 110. A "cell" is a logical communication entity used for communication with a base station (e.g., over some frequency resources, referred to as a carrier frequency, component carrier, carrier, band, etc.) and may be associated with an identifier (e.g., a physical cell identifier (PCI), an enhanced cell identifier (ECI), a virtual cell identifier (VCI), a cell global identifier (CGI), etc.) to distinguish cells operating over the same or different carrier frequencies. In some cases, different cells may be configured according to different protocol types (e.g., machine-type communication (MTC), narrowband IoT (NB-IoT), enhanced mobile broadband (eMBB), or others) that may provide access to different types of UEs. Since a cell is supported by a particular base station, the term "cell" may refer to one or both of the logical communication entity and the base station that supports it, depending on the context. In addition, since a TRP is typically a physical transmission point of a cell, the terms "cell" and "TRP" may be used interchangeably. In some cases, the term "cell" may also refer to the geographic coverage area (e.g., sector) of a base station, as long as the carrier frequency can be detected and used for communication within a portion of the geographic coverage area 110.

[0028]

[0040] The geographic coverage areas 110 of neighboring macrocell base stations 102 may overlap partially (e.g., in handover regions) and some of the geographic coverage areas 110 may be significantly overlapped by larger geographic coverage areas 110. For example, a small cell base station 102' (labeled "SC" for "small cell") may have a geographic coverage area 110' that significantly overlaps with the geographic coverage area 110 of one or more macrocell base stations 102. A network including both small cell base stations and macrocell base stations may be known as a heterogeneous network. A heterogeneous network may also include home eNBs (HeNBs), which may serve closed groups known as closed subscriber groups (CSGs).

[0029]

[0041] The communication link 120 between the base station 102 and the UE 104 may include uplink (also referred to as reverse link) transmissions from the UE 104 to the base station 102, and / or downlink (DL) (also referred to as forward link) transmissions from the base station 102 to the UE 104. The communication link 120 may use MIMO antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link 120 may be over one or more carrier frequencies. The allocation of carriers may be asymmetric with respect to the downlink and uplink (e.g., more or fewer carriers may be allocated for the downlink than for the uplink).

[0030]

[0042] The wireless communication system 100 may further include a WLAN access point (AP) 150 in communication with a WLAN station (STA) 152 over a communication link 154 in an unlicensed frequency spectrum (e.g., 5 GHz). When communicating in the unlicensed frequency spectrum, the WLAN STA 152 and / or the WLAN AP 150 may perform a clear channel assessment (CCA) or listen before talk (LBT) procedure before communicating to determine if a channel is available.

[0031]

[0043] The small cell base station 102' may operate in a licensed and / or unlicensed frequency spectrum. When operating in an unlicensed frequency spectrum, the small cell base station 102' may utilize LTE or NR technology and use the same 5 GHz unlicensed frequency spectrum used by the WLAN AP 150. A small cell base station 102' employing LTE / 5G in an unlicensed frequency spectrum may extend coverage to and / or increase capacity of an access network. NR in an unlicensed spectrum may be referred to as NR-U. LTE in an unlicensed spectrum may be referred to as LTE-U, licensed assisted access (LAA), or MulteFire.

[0032]

[0044] The wireless communication system 100 may further include a mmW base station 180 that may operate at millimeter wave (mmW) frequencies and / or sub-mmW in communication with the UE 182. Extremely high frequency (EHF) is a portion of RF in the electromagnetic spectrum. EHF has a range of 30 GHz to 300 GHz and a wavelength of 1 millimeter to 10 millimeters. Radio waves in this band may be referred to as millimeter waves. Sub-mmW may go down to frequencies of 3 GHz with a wavelength of 100 millimeters. The super high frequency (SHF) band ranges from 3 GHz to 30 GHz and is also referred to as centimeter wave. Communications using the mmW / sub-mmW RF bands have high path loss and relatively short range. The mmW base station 180 and the UE 182 may utilize beamforming (transmit and / or receive) over the mmW communication link 184 to compensate for the extremely high path loss and short range. It will be further understood that in alternative configurations, one or more base stations 102 may also transmit using mmW or quasi-mmW and beamforming. Accordingly, it will be understood that the above illustrations are merely examples and should not be construed as limiting various aspects disclosed herein.

[0033]

[0045] Transmit beamforming is a technique for concentrating an RF signal in a particular direction. Traditionally, when a network node (e.g., a base station) broadcasts an RF signal, it broadcasts it in all directions (omnidirectional). With transmit beamforming, the network node determines where a given target device (e.g., UE) is located (relative to the transmitting network node) and launches a stronger downlink RF signal in that particular direction, thereby providing a faster and more powerful RF signal (in terms of data rate) to the receiving device(s). To change the directionality of the RF signal when transmitting, the network node can control the phase and relative amplitude of the RF signal at each of the one or more transmitters broadcasting the RF signal. For example, the network node may use an array of antennas (also called a "phased array" or "antenna array") that creates beams of RF waves that can be "steered" to point in different directions without actually moving the antennas. Specifically, RF currents from the transmitters are fed to the individual antennas with the proper phase relationship so that the radio waves from the separate antennas are combined to cancel and suppress radiation in undesired directions while simultaneously enhancing radiation in desired directions.

[0034]

[0046] A transmit beam may be quasi-co-located, meaning that the transmit beam appears to a receiver (e.g., UE) to have the same parameters regardless of whether the network node's own transmit antenna is physically co-located or not. In NR, there are four types of quasi-co-location (QCL) relationships. Specifically, a QCL relationship of a given type means that some parameters for a second reference RF signal on a second beam can be derived from information about a source reference RF signal on a source beam. Thus, if the source reference RF signal is QCL type A, the receiver can use the source reference RF signal to estimate the Doppler shift, Doppler spread, average delay, and delay spread of the second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL type B, the receiver can use the source reference RF signal to estimate the Doppler shift and Doppler spread of the second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL Type C, the receiver can use the source reference RF signal to estimate the Doppler shift and average delay of a second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL Type D, the receiver can use the source reference RF signal to estimate spatial reception parameters of a second reference RF signal transmitted on the same channel.

[0035]

[0047] In receive beamforming, a receiver uses receive beams to amplify RF signals detected on a given channel. For example, the receiver can increase the gain setting and / or adjust the phase setting of an array of antennas in a particular direction to amplify (e.g., increase its gain level) an RF signal received from that direction. Thus, when a receiver is said to beamform in a direction, it means that the beam gain in that direction is higher than the beam gains along other directions, or that the beam gain in that direction is the highest compared to the beam gains in that direction of all other receive beams available to the receiver. This results in a stronger received signal strength (e.g., reference signal received power (RSRP), reference signal received quality (RSRQ), signal-to-interference-plus-noise ratio (SINR), etc.) of the RF signal received from that direction.

[0036]

[0048] The transmit beam and the receive beam may be spatially related. The spatial relationship means that the parameters for the second beam (e.g., transmit beam or receive beam) for the second reference signal may be derived from information about the first beam (e.g., receive beam or transmit beam) for the first reference signal. For example, the UE may use a particular receive beam to receive a reference downlink reference signal (e.g., synchronization signal block (SSB)) from a base station. The UE may then form a transmit beam for sending an uplink reference signal (e.g., sounding reference signal (SRS)) to that base station based on the parameters of the receive beam.

[0037]

[0049] Note that a "downlink" beam can be either a transmit beam or a receive beam, depending on the entity that forms it. For example, if the base station forms a downlink beam to transmit a reference signal to the UE, then the downlink beam is a transmit beam. However, if the UE forms a downlink beam, then it is a receive beam to receive a downlink reference signal. Similarly, an "uplink" beam can be either a transmit beam or a receive beam, depending on the entity that forms it. For example, if the base station forms an uplink beam, then it is an uplink receive beam, and if the UE forms an uplink beam, then it is an uplink transmit beam.

[0038]

[0050] The electromagnetic spectrum is often subdivided into various classes, bands, channels, etc. based on frequency / wavelength. In 5G NR, two initial operating bands have been identified as frequency range designations FR1 (410 MHz-7.125 GHz) and FR2 (24.25 GHz-52.6 GHz). It should be understood that FR1 is often referred to (interchangeably) as the "sub-6 GHz" band in various documents and papers, although a portion of FR1 is above 6 GHz. A similar nomenclature issue may arise with respect to FR2, which is often referred to (interchangeably) as the "millimeter wave" band in documents and papers, even though it is different from the EHF band (30 GHz-300 GHz) identified as the "millimeter wave" band by the International Telecommunications Union (ITU).

[0039]

[0051] Frequencies between FR1 and FR2 are often referred to as mid-band frequencies. Recent 5G NR studies have identified operating bands for these mid-band frequencies as frequency range designation FR3 (7.125 GHz to 24.25 GHz). Frequency bands included within FR3 may inherit FR1 and / or FR2 characteristics, and thus may in effect extend the features of FR1 and / or FR2 to the mid-band frequencies. In addition, higher frequency bands are currently being explored to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as frequency range designations FR4a or FR4-1 (52.6 GHz to 71 GHz), FR4 (52.6 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands is included within the EHF band.

[0040]

[0052] With the above aspects in mind, it should be understood that unless specifically stated otherwise, terms such as "sub-6 GHz" as used herein may broadly refer to frequencies that may be below 6 GHz, may be within FR1, or may include mid-band frequencies. Furthermore, unless specifically stated otherwise, it should be understood that terms such as "mmWave" as used herein may broadly refer to frequencies that may include mid-band frequencies, may be within the ranges of FR2, FR4, FR4-a or FR4-1, and / or FR5, or may be within the EHF band.

[0041]

[0053] In a multi-carrier system such as 5G, one of the carrier frequencies is called the "primary carrier" or "anchor carrier" or "primary serving cell" or "PCell", and the remaining carrier frequencies are called the "secondary carrier" or "secondary serving cell" or "SCell". In carrier aggregation, the anchor carrier is a carrier operating on a primary frequency (e.g., FR1) utilized by the UE 104 / 182 and the cell in which the UE 104 / 182 performs an initial radio resource control (RRC) connection establishment procedure or initiates an RRC connection re-establishment procedure. The primary carrier carries all common control channels and UE-specific control channels and may (but is not always) be a carrier among licensed frequencies. The secondary carrier is a carrier operating on a second frequency (e.g., FR2) that may be configured once an RRC connection is established between the UE 104 and the anchor carrier and may be used to provide additional radio resources. In some cases, the secondary carrier may be a carrier among unlicensed frequencies. Since both the primary uplink carrier and the primary downlink carrier are typically UE specific, the secondary carrier shall contain only the necessary signaling information and signals, e.g., there should be no UE specific signaling information and signals in the secondary carrier. This means that different UEs 104 / 182 in a cell may have different downlink primary carriers. The same applies to the uplink primary carrier. The network may change the primary carrier of any UE 104 / 182 at any time. This is done, for example, to balance the load on different carriers. Since a "serving cell" (whether PCell or SCell) corresponds to a carrier frequency / component carrier over which several base stations are communicating, terms such as "cell", "serving cell", "component carrier", "carrier frequency" and the like may be used interchangeably.

[0042]

[0054] For example, still referring to FIG. 1, one of the frequencies utilized by the macrocell base station 102 may be an anchor carrier (or "PCell"), and the other frequencies utilized by the macrocell base station 102 and / or the mmW base station 180 may be secondary carriers ("SCells"). Simultaneous transmission and / or reception of multiple carriers allows the UE 104 / 182 to significantly increase its data transmission and / or reception rates. For example, two 20 MHz carriers aggregated in a multi-carrier system would theoretically provide a two-fold increase in data rate (i.e., 40 MHz) compared to the data rate achieved by a single 20 MHz carrier.

[0043]

[0055] The wireless communications system 100 may further include a UE 164, which may communicate with the macrocell base station 102 via communications link 120 and / or with the mmW base station 180 via an mmW communications link 184. For example, the macrocell base station 102 may support a PCell and one or more SCells for the UE 164, and the mmW base station 180 may support one or more SCells for the UE 164.

[0044]

[0056] In some cases, the UE 164 and the UE 182 may be capable of sidelink communications. A sidelink-enabled UE (SL-UE) can communicate with the base station 102 over a communication link 120 that uses a Uu interface (i.e., an air interface between the UE and the base station). The SL-UEs (e.g., UE 164, UE 182) may also communicate directly with each other over a wireless sidelink 160 that uses a PC5 interface (i.e., an air interface between sidelink-enabled UEs). Wireless sidelink (or simply "sidelink") is an adaptation of the core cellular (e.g., LTE, NR) standard that allows direct communication between two or more UEs without the communication having to go through a base station. Sidelink communications may be unicast or multicast and may be used for device-to-device (D2D) medium sharing, vehicle-to-vehicle (V2V) communications, vehicle-to-everything (V2X) communications (e.g., cellular V2X (cV2X) communications, enhanced V2X (eV2X) communications, etc.), emergency rescue applications, etc. One or more of the groups of SL-UEs utilizing sidelink communications may be within the geographic coverage area 110 of the base station 102. Other SL-UEs in such a group may be outside the geographic coverage area 110 of the base station 102 or may not be able to receive transmissions from the base station 102. In some cases, a group of SL-UEs communicating via sidelink communications may utilize a one-to-many (1:M) system in which each SL-UE transmits to all other SL-UEs in the group. In some cases, the base station 102 facilitates scheduling of resources for sidelink communications. In other cases, sidelink communications are performed between SL-UEs without the involvement of the base station 102.

[0045]

[0057] In one aspect, the sidelink 160 may operate on a subject wireless communication medium, which may be shared with other vehicular and / or infrastructure access points, as well as other wireless communications between other RATs. The "medium" may consist of one or more time, frequency, and / or spatial communication resources (e.g., encompassing one or more channels across one or more carriers) associated with wireless communications between one or more transmitter / receiver pairs. In one aspect, the subject medium may correspond to at least a portion of an unlicensed frequency band shared between various RATs. Although different licensed frequency bands have been reserved for some communication systems (e.g., by government agencies such as the Federal Communications Commission (FCC) in the United States), these systems, particularly those employing small cell access points, have recently extended operation to unlicensed frequency bands such as the Unlicensed National Information Infrastructure (U-NII) bands used by WLAN technologies, most notably the IEEE 802.11x WLAN technology commonly referred to as "Wi-Fi". Exemplary systems of this type include CDMA systems, TDMA systems, FDMA systems, orthogonal FDMA (OFDMA) systems, single-carrier FDMA (SC-FDMA) systems, and various variations thereof.

[0046]

[0058] It should be noted that while FIG. 1 illustrates only two of the UEs as SL-UEs (i.e., UE 164 and 182), any of the illustrated UEs may be SL-UEs. Additionally, while only UE 182 has been described as being beamforming capable, any of the illustrated UEs may be beamforming capable, including UE 164. If SL-UEs are beamforming capable, they may beamform toward each other (i.e., toward other SL-UEs), toward other UEs (e.g., UE 104), toward base stations (e.g., base stations 102, 180, small cell 102′, access point 150), and so forth. Thus, in some cases, UE 164 and UE 182 may utilize beamforming over sidelink 160.

[0047]

[0059] In the example of FIG. 1, any of the illustrated UEs (shown in FIG. 1 as a single UE 104 for simplicity) may receive signals 124 from one or more Earth-orbiting space vehicles (SVs) 112 (e.g., satellites). In one aspect, the SVs 112 may be part of a satellite positioning system that the UEs 104 may use as an independent source of location information. A satellite positioning system typically includes a system of transmitters (e.g., SVs 112) positioned to enable receivers (e.g., UEs 104) to determine their location on or above the Earth based at least in part on positioning signals (e.g., signals 124) received from the transmitters. Such transmitters typically transmit signals marked with a repeating pseudo-random noise (PN) code of a set number of chips. Although typically located within the SVs 112, transmitters may sometimes be located on ground-based control stations, base stations 102, and / or other UEs 104. The UE 104 may include one or more dedicated receivers specifically designed to receive the signals 124 from the SV 112 to derive geolocation information.

[0048]

[0060] In a satellite positioning system, the use of the signals 124 may be augmented by various satellite-based augmentation systems (SBAS) that may be associated with or otherwise enabled for use with one or more global and / or regional navigation satellite systems. For example, the SBAS may include augmentation systems that provide integrity information, error correction, and the like, such as the Wide Area Augmentation System (WAAS), the European Geostationary Navigation Overlay Service (EGNOS), the Multi-functional Satellite Augmentation System (MSAS), the Global Positioning System (GPS)-aided Geo-augmented navigation, or the GPS and Geo Augmented Navigation system (GAGAN). Thus, as used herein, a satellite positioning system may include any combination of one or more global and / or regional navigation satellites associated with such one or more satellite positioning systems.

[0049]

[0061] In one aspect, the SV 112 may additionally or alternatively be part of one or more non-terrestrial networks (NTNs). In an NTN, the SV 112 is connected to an earth station (also called a ground station, NTN gateway, or gateway), which in turn is connected to an element in a 5G network, such as a modified base station 102 (without a terrestrial antenna) or a network node in a 5G network. This element will then provide access to other elements in the 5G network and ultimately to entities outside the 5G network, such as Internet web servers and other user devices. In this way, the UE 104 may receive communication signals (e.g., signal 124) from the SV 112 instead of or in addition to communication signals from the terrestrial base station 102.

[0050]

[0062] The wireless communication system 100 may further include one or more UEs, such as UE 190, that indirectly connect to one or more communication networks via one or more device-to-device (D2D) peer-to-peer (P2P) links (referred to as "sidelinks"). In the example of FIG. 1, the UE 190 has a D2D P2P link 192 (e.g., through which the UE 190 may indirectly obtain cellular connectivity) with one of the UEs 104 connected to one of the base stations 102, and a D2D P2P link 194 (through which the UE 190 may indirectly obtain WLAN-based Internet connectivity) with a WLAN STA 152 connected to a WLAN AP 150. In one example, the D2D P2P links 192 and 194 may be supported using any well-known D2D RAT, such as LTE Direct (LTE-D), WiFi Direct (WiFi-D), Bluetooth, etc.

[0051]

[0063] 2A illustrates an exemplary wireless network structure 200. For example, a 5GC 210 (also referred to as Next Generation Core (NGC)) may be considered functionally as a control plane (C-plane) function 214 (e.g., UE registration, authentication, network access, gateway selection, etc.) and a user plane (U-plane) function 212 (e.g., UE gateway function, access to data network, Internet protocol (IP) routing, etc.) that operate cooperatively to form a core network. A user plane interface (NG-U) 213 and a control plane interface (NG-C) 215 connect the gNB 222 to the 5GC 210, specifically to the user plane function 212 and the control plane function 214, respectively. In an additional configuration, the ng-eNB 224 may also be connected to the 5GC 210 via the NG-C 215 to the control plane function 214 and the NG-U 213 to the user plane function 212. Additionally, the ng-eNB 224 may communicate directly with the gNB 222 via a backhaul connection 223. In some configurations, the Next Generation RAN (NG-RAN) 220 may have one or more gNBs 222, while other configurations include one or more of both the ng-eNB 224 and the gNB 222. Either the gNB 222 or the ng-eNB 224 (or both) may communicate with one or more UEs 204 (e.g., any of the UEs described herein).

[0052]

[0064] Another optional aspect may include a location server 230, which may be in communication with the 5GC 210 to provide location assistance to the UE(s) 204. The location servers 230 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules across multiple physical servers, etc.), or alternatively, each may correspond to a single server. The location servers 230 may be configured to support one or more location services for the UEs 204 that may connect to the location server 230 via the core network, the 5GC 210, and / or via the Internet (not shown). Furthermore, the location server 230 may be incorporated into a component of the core network, or may alternatively be external to the core network (e.g., a third-party server, such as an original equipment manufacturer (OEM) server or a service server).

[0053]

[0065] 2B illustrates another exemplary wireless network structure 250. A 5GC 260 (which may correspond to 5GC 210 in FIG. 2A) may be considered functionally as control plane functions provided by an access and mobility management function (AMF) 264 and user plane functions provided by a user plane function (UPF) 262, which operate cooperatively to form a core network (i.e., 5GC 260). The functions of the AMF 264 include registration management, connection management, reachability management, mobility management, lawful interception, transport for session management (SM) messages between one or more UEs 204 (e.g., any of the UEs described herein) and a session management function (SMF) 266, transparent proxy services for routing SM messages, access authentication and access authorization, transport for short message service (SMS) messages between the UE 204 and a short message service function (SMSF) (not shown), and security anchor functionality (SEAF). The AMF 264 also interacts with an authentication server function (AUSF) (not shown) and the UE 204 to receive intermediate keys established as a result of the UE 204 authentication process. In case of UMTS (universal mobile telecommunications system) subscriber identity module (USIM) based authentication, the AMF 264 retrieves security material from the AUSF. The AMF 264 functionality also includes security context management (SCM). The SCM receives keys from the SEAF that the SCM uses to derive access network specific keys.The AMF 264 functions also include location service management for regulated services, transport for location service messages between the UE 204 and the LMF 270 (acting as the location server 230), transport for location service messages between the NG-RAN 220 and the LMF 270, EPS bearer identifier allocation for interworking with evolved packet system (EPS), and UE 204 mobility event notification. In addition, the AMF 264 also supports functions for non-3GPP (Third Generation Partnership Project) access networks.

[0054]

[0066] The functions of the UPF 262 include acting as an anchor point for intra / inter-RAT mobility (when applicable), acting as an external protocol data unit (PDU) session point for interconnection to a data network (not shown), routing and forwarding of packets, packet inspection, user plane policy rule enforcement (e.g., gating, redirection, traffic steering), lawful interception (user plane collection), traffic usage reporting, Quality of Service (QoS) handling for the user plane (e.g., uplink / downlink rate enforcement, reflective QoS marking in the downlink), uplink traffic validation (Service Data Flow (SDF) to QoS flow mapping), transport level packet marking in the uplink and downlink, downlink packet buffering and downlink data notification triggering, and sending and forwarding one or more "end markers" to the source RAN node. The UPF 262 may also support forwarding of location service messages on the user plane between the UE 204 and a location server such as the SLP 272.

[0055]

[0067] The functions of the SMF 266 include session management, UE IP address allocation and management, selection and control of user plane functions, configuration of traffic steering in the UPF 262 to route traffic to the appropriate destination, control of policy enforcement and parts of QoS, and downlink data notification. The interface through which the SMF 266 communicates with the AMF 264 is called the N11 interface.

[0056]

[0068] Another optional aspect may include an LMF 270, which may be in communication with the 5GC 260 to provide location assistance to the UE 204. The LMF 270 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules across multiple physical servers, etc.), or alternatively, each may represent a single server. The LMF 270 may be configured to support one or more location services for UEs 204 that may connect to the LMF 270 via a core network, the 5GC 260, and / or via the Internet (not shown). The SLP 272 may support similar functions as the LMF 270, while the LMF 270 may communicate with the AMF 264, the NG-RAN 220, and the UE 204 via the control plane (e.g., using interfaces and protocols intended to convey signaling messages rather than voice or data) and the SLP 272 may communicate with the UE 204 and external clients (e.g., third-party servers 274) via the user plane (e.g., using protocols intended to carry voice and / or data, such as Transmission Control Protocol (TCP) and / or IP).

[0057]

[0069] Yet another optional aspect may include a third party server 274, which may be in communication with the LMF 270, the SLP 272, the 5GC 260 (e.g., via the AMF 264 and / or the UPF 262), the NG-RAN 220, and / or the UE 204 to obtain location information (e.g., a location estimate) for the UE 204. Thus, in some cases, the third party server 274 may be referred to as a location services (LCS) client or an external client. The third party servers 274 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules spread across multiple physical servers, etc.) or, alternatively, each may correspond to a single server.

[0058]

[0070] The user plane interface 263 and the control plane interface 265 connect the 5GC 260, and in particular the UPF 262 and the AMF 264, respectively, to one or more gNBs 222 and / or ng-eNBs 224 in the NG-RAN 220. The interface between the gNB(s) 222 and / or ng-eNB(s) 224 and the AMF 264 is referred to as the “N2” interface, and the interface between the gNB(s) 222 and / or ng-eNB(s) 224 and the UPF 262 is referred to as the “N3” interface. The gNB(s) 222 and / or ng-eNB(s) 224 of the NG-RAN 220 may communicate directly with each other via a backhaul connection 223 referred to as the “Xn-C” interface. One or more of the gNBs 222 and / or ng-eNBs 224 may communicate with one or more UEs 204 via a wireless interface referred to as a “Uu” interface.

[0059]

[0071] The functionality of the gNB 222 may be divided between a gNB Central Unit (gNB-CU) 226, one or more gNB Distributed Units (gNB-DU) 228, and one or more gNB Radio Units (gNB-RU) 229. The gNB-CU 226 is a logical node that includes base station functions such as forwarding user data, mobility control, RAN sharing, positioning, session management, etc., except for those functions exclusively assigned to the gNB-DU(s) 228. More specifically, the gNB-CU 226 typically hosts the RRC, Service Data Adaptation Protocol (SDAP), and Packet Data Convergence Protocol (PDCP) protocols of the gNB 222. The gNB-DU 228 is a logical node that typically hosts the Radio Link Control (RLC), Medium Access Control (MAC) layers of the gNB 222. Its operation is controlled by the gNB-CU 226. One gNB-DU 228 can support one or multiple cells, and one cell is supported by only one gNB-DU 228. The interface 232 between the gNB-CU 226 and one or more gNB-DUs 228 is referred to as the "F1" interface. The physical (PHY) layer functionality of the gNB 222 is generally hosted by one or more standalone gNB-RUs 229, which perform functions such as power amplification and signal transmission / reception. The interface between the gNB-DU 228 and the gNB-RU 229 is referred to as the "Fx" interface. Thus, the UE 204 communicates with the gNB-CU 226 via the RRC, SDAP, and PDCP layers, with the gNB-DU 228 via the RLC and MAC layers, and with the gNB-RU 229 via the PHY layer.

[0060]

[0072] 3A, 3B, and 3C illustrate several example components (represented by corresponding blocks) that may be incorporated in a UE 302 (which may correspond to any of the UEs described herein), a base station 304 (which may correspond to any of the base stations described herein), and a network entity 306 (which may correspond to or embody any of the network functions described herein, including a location server 230 and an LMF 270, or alternatively may be independent of the NG-RAN 220 and / or 5GC 210 / 260 infrastructure depicted in FIGS. 2A and 2B, such as a private network) to support the operations described herein. It will be understood that these components may be implemented in different types of devices in different implementations (e.g., in an ASIC, in a system-on-chip (SoC), etc.). The illustrated components may also be incorporated in other devices in a communication system. For example, other devices in the system may include components similar to the described components to provide similar functionality. Also, a given device may include one or more of the components. For example, a device may contain multiple transceiver components that enable the device to operate on multiple carriers and / or communicate via different technologies.

[0061]

[0073] The UE 302 and base station 304 each include one or more WWAN transceivers 310 and 350, respectively, providing means for communicating (e.g., means for transmitting, means for receiving, means for measuring, means for tuning, means for refraining from transmitting, etc.) over one or more wireless communications networks (not shown), such as an NR network, an LTE network, a GSM network, etc. The WWAN transceivers 310 and 350 may each be connected to one or more antennas 316 and 356, respectively, for communicating with other network nodes, such as other UEs, access points, base stations (e.g., eNBs, gNBs), etc., over at least one designated RAT (e.g., NR, LTE, GSM, etc.) over a wireless communications medium of interest (e.g., some set of time / frequency resources in a particular frequency spectrum). The WWAN transceivers 310 and 350 may be variously configured to transmit and encode signals 318 and 358 (e.g., messages, instructions, information, etc.), respectively, and conversely, to receive and decode signals 318 and 358 (e.g., messages, instructions, information, pilots, etc.), respectively, in accordance with a designated RAT. Specifically, the WWAN transceivers 310 and 350 include one or more transmitters 314 and 354, respectively, for transmitting and encoding signals 318 and 358, respectively, and include one or more receivers 312 and 352, respectively, for receiving and decoding signals 318 and 358, respectively.

[0062]

[0074] The UE 302 and base station 304 also each, at least in some cases, include one or more short-range wireless transceivers 320 and 360, respectively. The short-range wireless transceivers 320 and 360 may be connected to one or more antennas 326 and 366, respectively, and may provide means for communicating (e.g., means for transmitting, means for receiving, means for measuring, means for tuning, means for refraining from transmitting, etc.) with other network nodes, such as other UEs, access points, base stations, etc., via at least one designated RAT (e.g., WiFi, LTE-D, Bluetooth, Zigbee, Z-Wave, PC5, dedicated short-range communications (DSRC), wireless access for vehicular environments (WAVE), near-field communication (NFC), ultra-wideband (UWB) communications, etc.) over the wireless communication medium. The short-range wireless transceivers 320 and 360 may be variously configured to transmit and encode signals 328 and 368 (e.g., messages, instructions, information, etc.), respectively, and conversely, to receive and decode signals 328 and 368 (e.g., messages, instructions, information, pilots, etc.), respectively, in accordance with a specified RAT. Specifically, the short-range wireless transceivers 320 and 360 include one or more transmitters 324 and 364, respectively, to transmit and encode signals 328 and 368, respectively, and include one or more receivers 322 and 362, respectively, to receive and decode signals 328 and 368, respectively. As specific examples, the short-range wireless transceivers 320 and 360 may be WiFi transceivers, Bluetooth® transceivers, Zigbee® and / or Z-Wave® transceivers, NFC transceivers, or vehicle-to-vehicle (V2V) and / or vehicle-to-everything (V2X) transceivers.

[0063]

[0075] The UE 302 and the base station 304 also, at least in some cases, include satellite signal receivers 330 and 370. The satellite signal receivers 330 and 370 may be connected to one or more antennas 336 and 376, respectively, and may provide a means for receiving and / or measuring satellite positioning / communication signals 338 and 378, respectively. If the satellite signal receivers 330 and 370 are satellite positioning system receivers, the satellite positioning / communication signals 338 and 378 may be GPS signals, Global Navigation Satellite System (GLONASS) signals, Galileo signals, Beidou signals, Navigation Satellite System of India (NAVIC), Quasi-Zenith Satellite System (QZSS), etc. If the satellite signal receivers 330 and 370 are NTN receivers, the satellite positioning / communication signals 338 and 378 may be communication signals (e.g., carrying control and / or user data) originating from a 5G network. Satellite signal receivers 330 and 370 may comprise any suitable hardware and / or software for receiving and processing satellite positioning / communications signals 338 and 378, respectively. Satellite signal receivers 330 and 370 may request information and action from other systems as appropriate and, at least in some cases, perform calculations using acquired measurements with any suitable satellite positioning system algorithms to determine the locations of UE 302 and base station 304, respectively.

[0064]

[0076] The base station 304 and the network entity 306 each include one or more network transceivers 380 and 390, respectively, that provide a means for communicating (e.g., a means for transmitting, a means for receiving, etc.) with other network entities (e.g., other base stations 304, other network entities 306). For example, the base station 304 may employ one or more network transceivers 380 to communicate with other base stations 304 or network entities 306 over one or more wired or wireless backhaul links. As another example, the network entity 306 may employ one or more network transceivers 390 to communicate with one or more base stations 304 over one or more wired or wireless backhaul links or with other network entities 306 over one or more wired or wireless core network interfaces.

[0065]

[0077] A transceiver may be configured to communicate over a wired link or a wireless link. A transceiver (whether a wired transceiver or a wireless transceiver) includes transmitter circuitry (e.g., transmitters 314, 324, 354, 364) and receiver circuitry (e.g., receivers 312, 322, 352, 362). A transceiver may be an integrated device (e.g., embodying transmitter and receiver circuitry in a single device) in some implementations, may comprise separate transmitter circuitry and separate receiver circuitry in some implementations, or may be embodied in other ways in other implementations. The transmitter and receiver circuitry of a wired transceiver (e.g., network transceivers 380 and 390 in some implementations) may be coupled to one or more wired network interface ports. The wireless transmitter circuitry (e.g., transmitters 314, 324, 354, 364) may include or be coupled to multiple antennas (e.g., antennas 316, 326, 356, 366), such as an antenna array that enables the respective device (e.g., UE 302, base station 304) to perform transmit "beamforming" as described herein. Similarly, the wireless receiver circuitry (e.g., receivers 312, 322, 352, 362) may include or be coupled to multiple antennas (e.g., antennas 316, 326, 356, 366), such as an antenna array that enables the respective device (e.g., UE 302, base station 304) to perform receive beamforming, as described herein. In one aspect, the transmitter circuitry and receiver circuitry may share multiple identical antennas (e.g., antennas 316, 326, 356, 366), such that the respective device can only receive or transmit at a given time, but not both at the same time. The wireless transceivers (eg, WWAN transceivers 310 and 350, short range wireless transceivers 320 and 360) may also include network listen modules (NLMs) and the like for performing various measurements.

[0066]

[0078] As used herein, various wireless transceivers (e.g., transceivers 310, 320, 350, and 360, and network transceivers 380 and 390, in some implementations) and wired transceivers (e.g., network transceivers 380 and 390, in some implementations) may be generally characterized as a "transceiver," "at least one transceiver," or "one or more transceivers." Thus, whether a particular transceiver is a wired or wireless transceiver may be inferred from the type of communication being performed. For example, backhaul communications between network devices or servers generally involve signaling via wired transceivers, while wireless communications between a UE (e.g., UE 302) and a base station (e.g., base station 304) generally involve signaling via wireless transceivers.

[0067]

[0079] The UE 302, base station 304, and network entity 306 also include other components that may be used in conjunction with operations as disclosed herein. The UE 302, base station 304, and network entity 306 each include one or more processors 332, 384, and 394, for example, to provide functionality related to wireless communications and to provide other processing functionality. Thus, the processors 332, 384, and 394 may comprise processing means, such as means for determining, means for calculating, means for receiving, means for transmitting, means for indicating, etc. In one aspect, the processors 332, 384, and 394 may include, for example, one or more general purpose processors, multi-core processors, central processing units (CPUs), ASICs, digital signal processors (DSPs), field programmable gate arrays (FPGAs), other programmable logic devices or processing circuits, or various combinations thereof.

[0068]

[0080] The UE 302, the base station 304, and the network entity 306 include memory circuitry implementing memories 340, 386, and 396, respectively (e.g., each including a memory device) for maintaining information (e.g., information indicating reserved resources, thresholds, parameters, etc.). Thus, the memories 340, 386, and 396 may comprise storage means, retrieval means, maintaining means, etc. In some cases, the UE 302, the base station 304, and the network entity 306 may include positioning components 342, 388, and 398, respectively. The positioning components 342, 388, and 398 may be hardware circuits that are part of or coupled to the processors 332, 384, and 394, respectively, that, when executed, cause the UE 302, the base station 304, and the network entity 306 to perform the functions described herein. In other aspects, the positioning components 342, 388, and 398 may be external to the processors 332, 384, and 394 (e.g., part of a modem processing system, integrated with another processing system, etc.). Alternatively, the positioning components 342, 388, and 398 may be memory modules stored in the memories 340, 386, and 396, respectively, that when executed by the processors 332, 384, and 394 (or modem processing system, another processing system, etc.) cause the UE 302, the base station 304, and the network entity 306 to perform the functions described herein. FIG. 3A illustrates possible locations of the positioning component 342, which may be part of, for example, one or more WWAN transceivers 310, the memory 340, the one or more processors 332, or any combination thereof, or may be a stand-alone component. FIG. 3B shows possible locations of a positioning component 388, which may be, for example, part of one or more WWAN transceivers 350, memory 386, one or more processors 384, or any combination thereof, or may be a stand-alone component.FIG. 3C illustrates possible locations of a positioning component 398, which may be, for example, part of one or more network transceivers 390, memory 396, one or more processors 394, or any combination thereof, or may be a stand-alone component.

[0069]

[0081] The UE 302 may include one or more sensors 344 coupled to the one or more processors 332 to provide a means for sensing or detecting movement and / or orientation information that is independent of movement data derived from signals received by the one or more WWAN transceivers 310, the one or more short-range wireless transceivers 320, and / or the satellite signal receiver 330. By way of example, the sensor(s) 344 may include an accelerometer (e.g., a micro-electrical mechanical systems (MEMS) device), a gyroscope, a geomagnetic sensor (e.g., a compass), an altimeter (e.g., a barometric altimeter), and / or any other type of movement detection sensor. Additionally, the sensor(s) 344 may include multiple different types of devices and combine their outputs to provide movement information. For example, the sensor(s) 344 may use a combination of a multi-axis accelerometer and an orientation sensor to provide the ability to calculate position in a two-dimensional (2D) and / or three-dimensional (3D) coordinate system.

[0070]

[0082] Additionally, the UE 302 includes a user interface 346 that provides a means for providing indications to a user (e.g., audio and / or visual indications) and / or receiving user input (e.g., upon user actuation of a sensing device, such as a keypad, touch screen, microphone, etc.). Although not shown, the base station 304 and the network entity 306 may also include user interfaces.

[0071]

[0083] Turning more particularly to the one or more processors 384, on the downlink, IP packets from the network entity 306 may be provided to the processor 384. The one or more processors 384 may implement functionality of an RRC layer, a PDCP layer, an RLC layer, and a MAC layer. The one or more processors 384 may provide RRC layer functions associated with broadcast of system information (e.g., master information block (MIB), system information block (SIB)), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-RAT mobility, and measurement configuration for UE measurement reporting; PDCP layer functions associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functions associated with transfer of higher layer PDUs, error correction with automatic repeat request (ARQ), concatenation, segmentation, and reassembly of RLC service data units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, scheduling information reporting, error correction, priority handling, and logical channel prioritization.

[0072]

[0084] The transmitter 354 and receiver 352 may implement Layer-1 (L1) functions associated with various signal processing functions. Layer-1, including the physical (PHY) layer, may include error detection on the transport channel, forward error correction (FEC) coding / decoding of the transport channel, interleaving, rate matching, mapping onto the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. The transmitter 354 handles mapping onto signal constellations based on various modulation schemes (e.g., binary phase-shift keying (BPSK), quadrature phase-shift keying (QPSK), M-phase-shift keying (M-PSK), M-quadrature amplitude modulation (M-QAM)). The coded and modulated symbols may then be split into parallel streams. Each stream may then be mapped to orthogonal frequency division multiplexing (OFDM) subcarriers, multiplexed with a reference signal (e.g., pilot) in the time and / or frequency domain, and then combined together using an inverse fast Fourier transform (IFFT) to generate a physical channel carrying a time-domain OFDM symbol stream. The OFDM symbol streams are spatially precoded to generate multiple spatial streams. Channel estimates from a channel estimator may be used to determine the coding and modulation scheme, as well as for spatial processing. The channel estimates may be derived from a reference signal and / or channel condition feedback transmitted by the UE 302. Each spatial stream may then be provided to one or more different antennas 356. The transmitter 354 may modulate an RF carrier with the individual spatial streams for transmission.

[0073]

[0085] At the UE 302, the receiver 312 receives signals through its respective antenna(s) 316. The receiver 312 recovers the information modulated onto the RF carriers and provides the information to one or more processors 332. The transmitter 314 and the receiver 312 perform layer 1 functions associated with various signal processing functions. The receiver 312 may perform spatial processing on the information to recover any spatial streams destined for the UE 302. If multiple spatial streams are destined for the UE 302, they may be combined by the receiver 312 into a single OFDM symbol stream. The receiver 312 then converts the OFDM symbol stream from the time domain to the frequency domain using a Fast Fourier Transform (FFT). The frequency domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, as well as the reference signal, are recovered and demodulated by determining the most likely signal constellation point transmitted by the base station 304. These soft decisions may be based on channel estimates calculated by a channel estimator. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally transmitted on the physical channel by the base station 304. The data and control signals are then provided to one or more processors 332 that implement Layer 3 (L3) and Layer 2 (L2) functions.

[0074]

[0086] In the uplink, one or more processors 332 provide demultiplexing between transport and logical channels, packet reassembly, decryption, header recovery, and control signal processing to recover IP packets from the core network. The one or more processors 332 are also responsible for error detection.

[0075]

[0087] Similar to the functionality described in connection with downlink transmissions by the base station 304, the one or more processors 332 provide RRC layer functionality related to system information (e.g., MIB, SIB) acquisition, RRC connection, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with forwarding of upper layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via hybrid automatic repeat request (HARQ), priority handling, and logical channel prioritization.

[0076]

[0088] Channel estimates derived by the channel estimator from a reference signal or feedback transmitted by the base station 304 may be used by the transmitter 314 to select an appropriate coding and modulation scheme and to facilitate spatial processing. The spatial streams generated by the transmitter 314 may be provided to different antenna(s) 316. The transmitter 314 may modulate an RF carrier with the individual spatial streams for transmission.

[0077]

[0089] Uplink transmissions are processed at the base station 304 in a manner similar to that described with respect to the receiver function at the UE 302. The receiver 352 receives signals via its respective antenna(s) 356. The receiver 352 recovers information modulated onto an RF carrier and provides the information to one or more processors 384.

[0078]

[0090] In the uplink, the one or more processors 384 provide demultiplexing between transport and logical channels, packet reassembly, decryption, header recovery, and control signal processing to recover IP packets from the UE 302. The IP packets from the one or more processors 384 may be provided to a core network. The one or more processors 384 are also responsible for error detection.

[0079]

[0091] For convenience, the UE 302, base station 304, and / or network entity 306 are illustrated in Figures 3A, 3B, and 3C as including various components that may be configured according to various examples described herein. However, it will be understood that the illustrated components may have different functions in different designs. In particular, various components in Figures 3A-3C are optional in alternative configurations, and various aspects include configurations that may vary due to design choice, cost, device use, or other considerations. For example, in the case of Figure 3A, a particular implementation of the UE 302 may omit the WWAN transceiver(s) 310 (e.g., a wearable device or tablet computer or PC or laptop may have Wi-Fi and / or Bluetooth capabilities without cellular capabilities), or may omit the short-range wireless transceiver(s) 320 (e.g., cellular only, etc.), or may omit the satellite signal receiver 330, or may omit the sensor(s) 344, etc. 3B, a particular implementation of base station 304 may omit WWAN transceiver(s) 350 (e.g., a Wi-Fi “hotspot” access point without cellular capability), or may omit short-range wireless transceiver(s) 360 (e.g., cellular only), or may omit satellite receiver 370, etc. For brevity, examples of various alternative configurations are not provided herein, but should be readily apparent to one of ordinary skill in the art.

[0080]

[0092] The various components of the UE 302, base station 304, and network entity 306 may be communicatively coupled to one another via data buses 334, 382, ​​and 392, respectively. In an aspect, the data buses 334, 382, ​​and 392 may form or be part of communication interfaces of the UE 302, base station 304, and network entity 306, respectively. For example, when different logical entities are embodied within the same device (e.g., gNB and location server functionality integrated within the same base station 304), the data buses 334, 382, ​​and 392 may provide communication between them.

[0081]

[0093] The components of Figures 3A, 3B, and 3C may be implemented in a variety of ways. In some implementations, the components of Figures 3A, 3B, and 3C may be implemented in one or more circuits, such as, for example, one or more processors and / or one or more ASICs (which may include one or more processors), where each circuit may use and / or incorporate at least one memory component for storing information or executable code used by the circuit to provide this functionality. For example, some or all of the functionality represented by blocks 310-346 may be implemented by the processor and memory component(s) of the UE 302 (e.g., by execution of appropriate code and / or by appropriate configuration of the processor components). Similarly, some or all of the functionality represented by blocks 350-388 may be implemented by the processor and memory component(s) of the base station 304 (e.g., by execution of appropriate code and / or by appropriate configuration of the processor components). Also, some or all of the functionality represented by blocks 390-398 may be implemented by the processor and memory component(s) of the network entity 306 (e.g., by execution of appropriate code and / or by appropriate configuration of the processor components). For simplicity, various operations, actions, and / or functions are described herein as being performed "by the UE," "by the base station," "by the network entity," etc. However, it will be understood that such operations, actions, and / or functions may actually be performed by a particular component or combination of components of the UE 302, base station 304, network entity 306, etc., such as the processors 332, 384, 394, transceivers 310, 320, 350, and 360, memories 340, 386, and 396, positioning components 342, 388, and 398, etc.

[0082]

[0094] In some designs, the network entity 306 may be implemented as a core network component. In other designs, the network entity 306 may be separate from the network operator or operation of the cellular network infrastructure (e.g., the NG-RAN 220 and / or the 5GC 210 / 260). For example, the network entity 306 may be a component of a private network that may be configured to communicate with the UE 302 via the base station 304 or independently of the base station 304 (e.g., via a non-cellular communication link such as WiFi).

[0083]

[0095] 4 illustrates an example Long Term Evolution (LTE) Positioning Protocol (LPP) procedure 400 between a UE 404 and a location server (shown as LMF 470) for performing a positioning operation. As shown in FIG. 4, positioning of the UE 404 is supported via an exchange of LPP messages between the UE 404 and the LMF 470. The LPP messages may be exchanged between the UE 404 and the LMF 470 via a serving base station (shown as a serving gNB 402) of the UE 404 and a core network (not shown). The LPP procedure 400 may be used to position the UE 404 to support various location-related services, such as navigation for the UE 404 (or for a user of the UE 404), or for routing or providing a precise location to a public serving access point (PSAP) in connection with an emergency call from the UE 404 to the PSAP, or for any other reason. The LPP procedure 400 may also be referred to as a positioning session, and there may be multiple positioning sessions for different types of positioning methods (e.g., downlink time difference of arrival (DL-TDOA), round trip time (RTT), enhanced cell identity (E-CID), etc.).

[0084]

[0096] Initially, the UE 404 may receive a request for its positioning capabilities from the LMF 470 at stage 410 (e.g., an LPP Request Capabilities message). At stage 420, the UE 404 provides its positioning capabilities to the LMF 470 in terms of the LPP protocol by sending an LPP Provide Capabilities message to the LMF 470 indicating the positioning methods and characteristics of these positioning methods supported by the UE 404 using LPP. The capabilities indicated in the LPP Provide Capabilities message may, in some aspects, indicate the types of positioning that the UE 404 supports (e.g., DL-TDOA, RTT, E-CID, etc.) and may indicate the capabilities of the UE 404 to support those types of positioning.

[0085]

[0097] Upon receipt of the LPP capability provision message in stage 420, the LMF 470 determines to use a particular type of positioning method (e.g., DL-TDOA, RTT, E-CID, etc.) based on the indicated type(s) of positioning supported by the UE 404 and determines a set of one or more TRPs from which the UE 404 will measure downlink positioning reference signals or to which the UE 404 will transmit uplink positioning reference signals. In stage 430, the LMF 470 sends an LPP Provide Assistance Data message to the UE 404 identifying the set of TRPs.

[0086]

[0098] In some implementations, the Provide LPP Assistance Data message in stage 430 may be sent by the LMF 470 to the UE 404 in response to an LPP Assistance Data Request (not shown in FIG. 4) sent by the UE 404 to the LMF 470. The LPP Assistance Data Request message may include an identifier of the serving TRP of the UE 404 and a request for Positioning Reference Signal (PRS) configuration of the neighboring TRP.

[0087]

[0099] At stage 440, the LMF 470 sends a request for location information to the UE 404. The request may be an LPP Request Location Information message. This message typically includes information elements that specify the location information type, the desired accuracy of the location estimate, and the response time (i.e., the desired latency). Note that a low latency requirement allows for a longer response time, while a high latency requirement requires a shorter response time. However, a long response time is referred to as a high latency, and a short response time is referred to as a low latency.

[0088]

[0100] It should be noted that in some implementations, for example, if the UE 404 sends a request for assistance data to the LMF 470 (e.g., in an LPP assistance data provision not shown in FIG. 4) after receiving a request for location information in stage 440, the LPP assistance data provision sent in stage 430 may be sent after the LPP location information request message in 440.

[0089]

[0101] In step 450, the UE 404 performs a positioning operation (e.g., measuring DL-PRS, transmitting UL-PRS, etc.) for the selected positioning method using the assistance information received in step 430 and any additional data received in step 440 (e.g., desired location accuracy, or maximum response time).

[0090]

[0102] In stage 460, the UE 404 may transmit an LPP Provide Location Information message to the LMF 470 conveying the results of any measurements taken in stage 450 and before or when any maximum response time expires (e.g., the maximum response time provided by the LMF 470 in stage 440) (e.g., the maximum response time provided by the LMF 470 in stage 440). The LPP Provide Location Information message in stage 460 may also include the time (or times) at which the positioning measurements were taken and the identity of the TRP(s) from which the positioning measurements were taken. Note that the time between the request for location information in 440 and the response in 460 is the "response time" and indicates the latency of the positioning session.

[0091]

[0103] The LMF 470 calculates an estimated location of the UE 404 using an appropriate positioning technique (e.g., DL-TDOA, RTT, E-CID, etc.) based at least in part on the measurements received in the LPP location information provision message at stage 460.

[0092]

[0104] Various frame structures may be used to support downlink and uplink transmissions between network nodes (e.g., base stations and UEs). Figure 5 is a diagram 500 illustrating example frame structures according to aspects of the disclosure. The frame structure may be a downlink or uplink frame structure. Other wireless communication technologies may have different frame structures and / or different channels.

[0093]

[0105] LTE and in some instances NR utilize OFDM on the downlink and single-carrier frequency division multiplexing (SC-FDM) on the uplink. However, unlike LTE, NR also has the option of using OFDM on the uplink. OFDM and SC-FDM partition the system bandwidth into multiple (K) orthogonal subcarriers, also commonly referred to as tones, bins, etc. Each subcarrier may be modulated with data. Generally, modulation symbols are sent in the frequency domain with OFDM and in the time domain with SC-FDM. The spacing between adjacent subcarriers may be fixed, or the total number of subcarriers (K) may be dependent on the system bandwidth. For example, the subcarrier spacing may be 15 kilohertz (kHz), and the minimum resource allocation (resource block) may be 12 subcarriers (i.e., 180 kHz). Thus, the nominal FFT size may be equal to 128, 256, 512, 1024, or 2048 for a system bandwidth of 1.25, 2.5, 5, 10, or 20 megahertz (MHz), respectively. The system bandwidth may also be partitioned into subbands. For example, a subband may cover 1.08 MHz (i.e., 6 resource blocks), and there may be 1, 2, 4, 8, or 16 subbands for a system bandwidth of 1.25, 2.5, 5, 10, or 20 MHz, respectively.

[0094]

[0106] LTE supports a single numerology (subcarrier spacing (SCS), symbol length, etc.). In contrast, NR may support multiple numerologies (μ), e.g., subcarrier spacings of 15 kHz (μ=0), 30 kHz (μ=1), 60 kHz (μ=2), 120 kHz (μ=3), and 240 kHz (μ=4) or more may be available. At each subcarrier spacing, there are 14 symbols per slot. For a 15 kHz SCS (μ=0), there is one slot per subframe, i.e., 10 slots per frame, the slot duration is 1 millisecond (ms), the symbol duration is 66.7 microseconds (μs), and the maximum nominal system bandwidth (in MHz) with an FFT size of 4K is 50. For a 30 kHz SCS (μ=1), there are two slots per subframe, i.e., 20 slots per frame, the slot duration is 0.5 ms, the symbol duration is 33.3 μs, and the maximum nominal system bandwidth (in MHz) for a 4K FFT size is 100. For a 60 kHz SCS (μ=2), there are four slots per subframe, i.e., 40 slots per frame, the slot duration is 0.25 ms, the symbol duration is 16.7 μs, and the maximum nominal system bandwidth (in MHz) for a 4K FFT size is 200. For a 120 kHz SCS (μ=3), there are eight slots per subframe, i.e., 80 slots per frame, the slot duration is 0.125 ms, the symbol duration is 8.33 μs, and the maximum nominal system bandwidth (in MHz) for a 4K FFT size is 400. For a 240 kHz SCS (μ=4), there are 16 slots per subframe, i.e., 160 slots per frame, the slot duration is 0.0625 ms, the symbol duration is 4.17 μs, and the maximum nominal system bandwidth (in MHz) with an FFT size of 4K is 800.

[0095]

[0107] In the example of Figure 5, a numerology of 15 kHz is used. Thus, in the time domain, a 10 ms frame is divided into 10 equally sized subframes of 1 ms each, with each subframe containing one time slot. In Figure 5, time is represented horizontally (on the X-axis), with time increasing from left to right, and frequency is represented vertically (on the Y-axis), with frequency increasing (or decreasing) from bottom to top.

[0096]

[0108] A resource grid may be used to represent a time slot, with each time slot including one or more time-parallel resource blocks (RBs) (also called physical RBs (PRBs)) in the frequency domain. The resource grid is further divided into multiple resource elements (REs). An RE may correspond to one symbol length in the time domain and one subcarrier in the frequency domain. In the numerology of FIG. 5, for a normal cyclic prefix, an RB may include 12 consecutive subcarriers in the frequency domain and 7 consecutive symbols in the time domain to obtain a total of 84 REs. For an extended cyclic prefix, an RB may include 12 consecutive subcarriers in the frequency domain and 6 consecutive symbols in the time domain to obtain a total of 72 REs. The number of bits carried by each RE depends on the modulation scheme.

[0097]

[0109] Some of the REs may carry reference (pilot) signals (RS). The reference signals may include positioning reference signals (PRS), tracking reference signals (TRS), phase tracking reference signals (PTRS), cell-specific reference signals (CRS), channel state information reference signals (CSI-RS), demodulation reference signals (DMRS), primary synchronization signals (PSS), secondary synchronization signals (SSS), SSB, SRS, etc., depending on whether the illustrated frame structure is used for uplink or downlink communications. Figure 5 shows example locations of REs carrying reference signals (labeled "R").

[0098]

[0110] In one aspect, the reference signal carried on the RE, labeled "R" in FIG. 5, may be an SRS. The SRS transmitted by the UE may be used by the base station to obtain channel state information (CSI) for the transmitting UE. The CSI describes how the RF signal propagates from the UE to the base station and represents the combined effects of scattering, fading, and power attenuation with distance. The system uses the SRS for resource scheduling, link adaptation, massive MIMO, beam management, etc. In some aspects, the SRS may be used as an uplink positioning reference signal (UL-PRS).

[0099]

[0111] A set of resource elements used for transmission of REs is called a "PRS resource". A set of REs can span multiple PRBs in the frequency domain and N(s) consecutive symbol(s) within a slot in the time domain. In a given OFDM symbol in the time domain, PRS resources occupy consecutive PRBs in the frequency domain.

[0100]

[0112] The transmission of PRS resources within a given PRB has a particular comb size (also called "comb density"). The comb size "N" represents the subcarrier spacing (or frequency / tone spacing) within each symbol of the PRS resource configuration. Specifically, for comb size "N", a PRS is transmitted in every Nth subcarrier of a symbol of the PRB. For example, for Com 4, for each symbol of the PRS resource configuration, an RE corresponding to every fourth subcarrier (such as subcarriers 0, 4, 8) is used to transmit the PRS of the PRS resource. Currently, the following comb sizes are supported for DL-PRS: Com 2, Com 4, Com 6, and Com 12. Figure 5 shows an example PRS resource configuration for Com 4 (spanning four symbols). That is, the location of the shaded RE (labeled "R") indicates the Com 4 PRS resource configuration.

[0101]

[0113] Currently, DL-PRS resources may span 2, 4, 6, or 12 consecutive symbols in a slot with a staggered pattern across the frequency domain. DL-PRS resources may be configured in any higher layer configured downlink or flexible (FL) symbol of a slot. There may be a constant energy per resource element (EPRE) for all REs of a given DL-PRS resource. Below are the symbol-to-symbol frequency offsets for comb sizes 2, 4, 6, and 12 spanning 2, 4, 6, and 12 symbols. 2-symbol-comb2:{0,1}; 4-symbol-comb2:{0,1,0,1}; 6-symbol-comb2:{0,1,0,1,0,1}; 12-symbol-comb2:{0,1,0,1,0,1,0,1,0,1,0,1,0,1} (for the example in Figure 5); 4-symbol-comb4:{0,2,1,3}; 12-symbol-comb4:{0,2,1,3,0,2,1,3,0,2,1,3}; 6-symbol-comb6:{0,3,1,4,2,5}; 12-symbol-comb6:{0,3,1,4,2,5,0,3,1,4,2,5}; and 12-symbol-comb12:{0,6,3,9,1,7,4,10,2,8,5,11}.

[0102]

[0114] A "PRS resource set" is a set of PRS resources used for transmission of a PRS signal, where each PRS resource has a PRS resource ID. In addition, the PRS resources in a PRS resource set are associated with the same TRP. A PRS resource set is identified by a PRS resource set ID and is associated with a particular TRP (identified by a TRP ID). In addition, the PRS resources in a PRS resource set have the same periodicity across slots, a common muting pattern configuration, and the same repetition factor (e.g., "PRS-ResourceRepetitionFactor"). The periodicity is the time from the first repetition of the first PRS resource of the first PRS instance to the same first repetition of the same first PRS resource of the next PRS instance. The periodicity is μ=0, 1, 2, 3, where μ is a function of 2^μ *The repetition factor may have a length selected from {1, 2, 4, 6, 8, 16, 32} slots.

[0103]

[0115] A PRS resource ID in a PRS resource set is associated with a single beam (or beam ID) transmitted from a single TRP (where a TRP may transmit one or multiple beams). That is, each PRS resource in a PRS resource set may be transmitted on a different beam, and thus may also be referred to as a "PRS resource" or simply a "resource", also sometimes referred to as a "beam". Note that this does not have any implication as to whether the TRP and beam on which the PRS is transmitted are known to the UE.

[0104]

[0116] A "PRS instance" or "PRS occasion" is one instance of a periodically repeating time window (e.g., a group of one or more contiguous slots) during which a PRS is expected to be transmitted. A PRS occasion may also be referred to as a "PRS positioning occasion", "PRS positioning instance", "positioning occasion", "positioning instance", "positioning repetition", or simply an "occasion", "instance", or "repetition".

[0105]

[0117] A "positioning frequency layer" (also simply called "frequency layer") is a collection of one or more PRS resource sets across one or more TRPs with the same values ​​for some parameters. In particular, a collection of PRS resource sets has the same subcarrier spacing and cyclic prefix (CP) type (meaning that all numerologies supported for the physical downlink shared channel (PDSCH) are also supported for the PRS), the same point A, the same value of the downlink PRS bandwidth, the same starting PRB (and center frequency), and the same comb size. The point A parameter takes the value of the parameter "ARFCN-ValueNR" (where "ARFCN" stands for "absolute radio-frequency channel number"), which is an identifier / code that specifies a pair of physical radio channels used for transmission and reception. The downlink PRS bandwidth may have a granularity of 4 PRB, with a minimum of 24 PRB and a maximum of 272 PRB. Currently, up to four frequency layers are defined, and up to two PRS resource sets per TRP can be configured per frequency layer.

[0106]

[0118] The concept of frequency layer is somewhat like that of component carrier and bandwidth portion (BWP), but differs in that component carrier and BWP are used by one base station (or macrocell base station and small cell base station) to transmit data channels, whereas frequency layer is used by several (usually three or more) base stations to transmit PRS. A UE may indicate the number of frequency layers that it can support when the UE transmits its positioning capabilities to the network, such as during an LTE Positioning Protocol (LPP) session. For example, the UE may indicate whether it can support one positioning frequency layer or four positioning frequency layers.

[0107]

[0119] It should be noted that the terms "positioning reference signal" and "PRS" generally refer to specific reference signals used for positioning in NR and LTE systems. However, the terms "positioning reference signal" and "PRS" as used herein may also refer to any type of reference signal that can be used for positioning, such as, but not limited to, PRS defined in LTE and NR, TRS, PTRS, CRS, CSI-RS, DMRS, PSS, SSS, SSB, SRS, UL-PRS, etc. Furthermore, the terms "positioning reference signal" and "PRS" may refer to downlink, uplink, or sidelink positioning reference signals, unless otherwise suggested by the context. If necessary to further distinguish between types of PRS, downlink positioning reference signals may be referred to as "DL-PRS", uplink positioning reference signals (e.g., SRS for positioning, PTRS) may be referred to as "UL-PRS", and sidelink positioning reference signals may be referred to as "SL-PRS". Additionally, for signals that may be transmitted in the downlink, uplink, and / or sidelink (e.g., DMRS), a "DL", "UL", or "SL" may be prepended to the signal to distinguish the direction. For example, "UL-DMRS" is different from "DL-DMRS".

[0108]

[0120] NR supports several cellular network-based positioning techniques, including downlink-based positioning methods, uplink-based positioning methods, and downlink- and uplink-based positioning methods. Downlink-based positioning methods include observed time difference of arrival (OTDOA) in LTE, downlink time difference of arrival (DL-TDOA) in NR, and downlink angle-of-departure (DL-AoD) in NR. FIG. 6 illustrates examples of various positioning methods according to aspects of the present disclosure. In an OTDOA or DL-TDOA positioning procedure illustrated by scenario 610, a UE measures the differences between times of arrival (ToAs) of reference signals (e.g., positioning reference signals (PRS)) received from pairs of base stations, called reference signal time difference (RSTD) measurements or time difference of arrival (TDOA) measurements, and reports them to a positioning entity. More specifically, the UE receives identifiers (IDs) of a reference base station (e.g., a serving base station) and multiple non-reference base stations in assistance data. The UE then measures the RSTD between the reference base station and each of the non-reference base stations. Based on the known locations of the involved base stations and the RSTD measurements, a positioning entity (e.g., the UE in case of UE-based positioning, or a location server in case of UE-assisted positioning) can estimate the location of the UE.

[0109]

[0121] For DL-AoD positioning, as illustrated by scenario 620, the positioning entity uses measurement reports from the UE of received signal strength measurements of multiple downlink transmit beams to determine the angle(s) between the UE and the transmitting base station(s). The positioning entity can then estimate the location of the UE based on the determined angles and the known locations of the transmitting base stations.

[0110]

[0122] Uplink-based positioning methods include uplink time difference of arrival (UL-TDOA) and uplink angle-of-arrival (UL-AoA). UL-TDOA is similar to DL-TDOA, but is based on uplink reference signals (e.g., SRS) transmitted by the UE to multiple base stations. In particular, the UE transmits one or more uplink reference signals that are measured by the reference base station and multiple non-reference base stations. Each base station then reports the time of reception of the reference signal (called relative time of arrival (RTOA)) to a positioning entity (e.g., a location server) that knows the locations and relative timing of the participating base stations. Based on the reception-to-reception (Rx-Rx) time difference between the reported RTOA of the reference base station and the reported RTOA of each non-reference base station, the known locations of the base stations, and their known timing offsets, the positioning entity can estimate the location of the UE using TDOA.

[0111]

[0123] For UL-AoA positioning, one or more base stations measure the received signal strength of one or more uplink reference signals (e.g., SRS) received from the UE on one or more uplink receive beams. The positioning entity uses the signal strength measurements and the angles of the receive beams to determine an angle between the UE and the base stations. Based on the determined angle and the known locations of the base stations, the positioning entity can then estimate the location of the UE.

[0112]

[0124] Downlink and uplink based positioning methods include Extended Cell ID (E-CID) positioning, and Multi-RTT positioning (also called "Multi-cell RTT" and "Multi-RTT"). In an RTT procedure, a first entity (e.g., a base station or a UE) transmits a first RTT-related signal (e.g., a PRS or an SRS) to a second entity (e.g., a UE or a base station), and the second entity transmits a second RTT-related signal (e.g., an SRS or a PRS) back to the first entity. Each entity measures the time difference between the ToA of the received RTT-related signal and the transmission time of the transmitted RTT-related signal. This time difference is called the reception-to-transmission (Rx-Tx) time difference. The Rx-Tx time difference measurement may be made or adjusted to include only the time difference between the nearest slot boundaries for the received and transmitted signals. Both entities may then send their Rx-Tx time difference measurements to a location server (e.g., LMF 270), which calculates the round trip propagation time (i.e., RTT) between the two entities from the two Rx-Tx time difference measurements (e.g., as the sum of the two Rx-Tx time difference measurements). Alternatively, one entity may send its Rx-Tx time difference measurements to the other entity, which then calculates the RTT. The distance between the two entities may be determined from the RTT and a known signal speed (e.g., the speed of light). In the case of multi-RTT positioning illustrated by scenario 630, a first entity (e.g., a UE or a base station) performs an RTT positioning procedure with multiple second entities (e.g., multiple base stations or UEs) to enable the location of the first entity to be determined based on the distance to the second entity and the known location of the second entity (e.g., using multilateration). As illustrated by scenario 640, RTT and multi-RTT methods can be combined with other positioning techniques such as UL-AoA and DL-AoD to improve location accuracy.

[0113]

[0125] The E-CID positioning method is based on Radio Resource Management (RRM) measurements. In E-CID, the UE reports the serving cell ID, timing advance (TA), and identities, estimated timing, and signal strength of detected neighboring base stations. The location of the UE is then estimated based on this information and the known locations of the base stations.

[0114]

[0126] To assist the positioning operation, a location server (e.g., location server 230, LMF 270, SLP 272) may provide assistance data to the UE. For example, the assistance data may include an identifier of a base station (or a cell / TRP of a base station) from which to measure a reference signal, reference signal configuration parameters (e.g., the number of consecutive slots containing a PRS, the periodicity of consecutive slots containing a PRS, a muting sequence, a frequency hopping sequence, a reference signal identifier, a reference signal bandwidth, etc.), and / or other parameters applicable to a particular positioning method. Alternatively, the assistance data may be obtained directly from the base station itself (e.g., in periodically broadcasted overhead messages, etc.). In some cases, the UE may be able to detect neighboring network nodes itself without using the assistance data.

[0115]

[0127] In the case of OTDOA or DL-TDOA positioning procedures, the assistance data may further include an expected RSTD value and an associated uncertainty around the expected RSTD, i.e., a search window. In some cases, the value range for the expected RSTD may be + / - 500 microseconds (μs). In some cases, the value range for the expected RSTD uncertainty may be + / - 32 μs when any of the resources used for positioning measurements are in FR1. In other cases, the value range for the expected RSTD uncertainty may be + / - 8 μs when all of the resources used for positioning measurements are in FR2.

[0116]

[0128] A location estimate may be referred to by other names, such as a position estimate, location, position, position fix, fix, etc. A location estimate may be geodetic and comprise coordinates (e.g., latitude, longitude, and possibly altitude), or urban and comprise a street address, postal address, or some other linguistic description of the location. A location estimate may also be defined relative to some other known location, or defined absolutely (e.g., using latitude, longitude, and possibly altitude). A location estimate may include an expected error or uncertainty (e.g., by including an area or volume within which the location is expected to be contained with some specified or default level of confidence).

[0117]

[0129] FIG. 7 illustrates a TDOA-based positioning procedure in an example wireless communication system 700 according to an aspect of the disclosure. The TDOA-based positioning procedure may be an OTDOA positioning procedure, as in LTE, or a Downlink Time Difference of Arrival (DL-TDOA) positioning procedure, as in 5G NR. In the example of FIG. 7, a UE 704 (e.g., any of the UEs described herein) is attempting to calculate an estimate of its location (referred to as a "UE-based" positioning) or to assist another entity (e.g., a base station or core network component, another UE, a location server, a third party application, etc.) to calculate an estimate of its location (referred to as a "UE-assisted" positioning). The UE 704 may communicate with (e.g., transmit information to and receive information from) one or more of a number of base stations 702 (e.g., any combination of base stations described herein) labeled "BS1" 702-1, "BS2" 702-2, and "BS3" 702-3.

[0118]

[0130] To support location estimation, base stations 702 may be configured to broadcast PRS, TRS, CRS, channel state information reference signal (CSI-RS), demodulation reference signal (DMRS), etc., to UE 704 in their coverage areas to allow UE 704 to measure characteristics of such reference signals. In a TDOA-based positioning procedure, UE 704 measures the time difference, known as RSTD or TDOA, between specific downlink reference signals (e.g., PRS, TRS, CRS, CSI-RS, etc.) transmitted by different pairs of base stations 702 and either reports these RSTD measurements to a location server (e.g., location server 230, LMF 270, SLP 272) or calculates a location estimate itself from the RSTD measurements.

[0119]

[0131] In general, RSTD is measured between a reference cell (e.g., the cell supported by base station 702-1 in the example of FIG. 7) and one or more neighboring cells (e.g., the cells supported by base stations 702-2 and 702-3 in the example of FIG. 7). The reference cell remains the same for all RSTDs measured by the UE 704 for any single positioning use of TDOA and will typically correspond to the serving cell for the UE 704 or another nearby cell with good signal strength at the UE 704. In one aspect, the neighboring cell will typically be a cell supported by a different base station than the base station for the reference cell and may have good or poor signal strength at the UE 704. The location calculation can be based on the measured RSTD and knowledge of the locations and relative transmission timing of the involved base stations 702 (e.g., regarding whether the base stations 702 are precisely synchronized or whether each base station 702 transmits with some known time offset relative to the other base stations 702).

[0120]

[0132] To assist the TDOA-based positioning operation, a location server (e.g., location server 230, LMF 270, SLP 272) may provide assistance data to the UE 704 for the reference cell and neighboring cells relative to the reference cell. For example, the assistance data may include an identifier (e.g., PCI, VCI, CGI, etc.) for each cell of a set of cells (here, cells supported by base station 702) that the UE 704 is expected to measure. The assistance data may also provide each cell's center channel frequency, various reference signal configuration parameters (e.g., number of consecutive positioning slots, periodicity of positioning slots, muting sequence, frequency hopping sequence, reference signal identifier, reference signal bandwidth), and / or other cell-related parameters applicable to the TDOA-based positioning procedure. The assistance data may also indicate the serving cell for the UE 704 as the reference cell.

[0121]

[0133] In some cases, the assistance data may also include an "expected RSTD" parameter that provides the UE 704 with information about the expected RSTD value that the UE 704 will measure at its current location between the reference cell and each neighbor cell, along with the uncertainty of the expected RSTD parameter. The expected RSTD, along with the associated uncertainty, may define a search window for the UE 704 within which the UE 704 is expected to measure the RSTD value. In some cases, the value range for the expected RSTD uncertainty may be + / - 500 microseconds (μs). In some cases, when any of the resources used for positioning measurements are in FR1, the value range for the expected RSTD uncertainty may be + / - 32 μs. In other cases, when all of the resources used for positioning measurements are in FR2, the value range for the expected RSTD uncertainty may be + / - 8 μs.

[0122]

[0134] The TDOA assistance information may also include positioning reference signal configuration information parameters that enable the UE 704 to determine when positioning reference signal occasions occur relative to signals received from various neighboring cells compared to positioning reference signal occasions for the reference cell, and to determine reference signal sequences transmitted from various cells for measuring the ToA or RSTD.

[0123]

[0135] In one aspect, a location server (e.g., location server 230, LMF 270, SLP 272) may transmit the assistance data to the UE 704, but alternatively, the assistance data may originate directly from the base station 702 itself (e.g., in periodically broadcast overhead messages, etc.). Alternatively, the UE 704 may detect neighboring base stations on its own without the use of assistance data.

[0124]

[0136] The UE 704 may measure and (optionally) report the RSTD between reference signals received from a pair of base stations 702 (e.g., based in part on assistance data, if provided). Using the RSTD measurements, the known absolute or relative transmit timing of each base station 702, and the known location(s) of the reference and neighboring base stations 702, the network (e.g., location server 230 / LMF 270 / SLP 272, base station 702) or the UE 704 may estimate the location of the UE 704. More specifically, the RSTD for neighbor cell "k" relative to the reference cell "Ref" may be given as (ToA_k-ToA_Ref). In the example of Figure 7, the measured RSTD between the reference cell of base station 702-1 and the cells of neighboring base stations 702-2 and 702-3 may be represented as T2-T1 and T3-T1, where T1, T2, and T3 represent the ToAs of the reference signals from base stations 702-1, 702-2, and 702-3, respectively. The UE 704 may then (if it is not a positioning entity) transmit the RSTD measurements to a location server or other positioning entity. Using (i) the RSTD measurements, (ii) the known absolute or relative transmission timing of each base station 702, (iii) the known location(s) of the base stations 702, and / or (iv) directional reference signal characteristics such as direction of transmission, the location of the UE 704 may be determined (either by the UE 704 or the location server).

[0125]

[0137] In one aspect, the location estimate may specify a location of the UE 704 in a two-dimensional (2D) coordinate system. However, the aspects disclosed herein are not so limited and may be applicable to determining a location estimate using a three-dimensional (3D) coordinate system if additional dimensions are desired. Additionally, while FIG. 7 shows one UE 704 and three base stations 702, it will be understood that there may be more UEs 704 and more base stations 702.

[0126]

[0138] 7, when the UE 704 uses RSTD to obtain a location estimate, necessary additional data (e.g., the location and relative transmission timing of the base station 702) may be provided to the UE 704 by a location server. In some implementations, a location estimate for the UE 704 may be obtained (e.g., by the UE 704 itself or by a location server) from the RSTD and from other measurements made by the UE 704 (e.g., measurements of signal timing from GPS or other Global Navigation Satellite System (GNSS) satellites). In these implementations, referred to as hybrid positioning, the RSTD measurements may contribute to obtaining a location estimate for the UE 704 but may not completely determine the location estimate.

[0127]

[0139] 8 is a diagram 800 illustrating a base station (BS) 802 (which may correspond to any of the base stations described herein) communicating with a UE 804 (which may correspond to any of the UEs described herein). With reference to FIG. 8, the base station 802 may transmit beamformed signals to the UE 804 in one or more transmit beams 812a, 812b, 812c, 812d, 812e, 812f, 812g, 812h (collectively, beams 812), each having a beam identifier that may be used by the UE 804 to identify an individual beam. If the base station 802 is beamforming toward the UE 804 with a single array of antennas (e.g., a single TRP / cell), the base station 802 may perform "beam sweeping" by first transmitting beam 812a, then beam 812b, and so on until finally transmitting beam 812h. Alternatively, the base station 802 may transmit the beams 812 in several patterns, such as beam 812a, then beam 812h, then beam 812b, then beam 812g, etc. If the base station 802 is beamforming toward the UE 804 using multiple arrays of antennas (e.g., multiple TRPs / cells), each antenna array may perform beam sweeping of a subset of the beams 812. Alternatively, each of the beams 812 may correspond to a single antenna or antenna array.

[0128]

[0140] FIG. 8 further illustrates paths 812c, 812d, 812e, 812f, and 812g taken by beamformed signals transmitted on beams 812c, 812d, 812e, 812f, and 812g, respectively. Each path 812c, 812d, 812e, 812f, and 812g may correspond to a single "multipath" or may consist of multiple "multipaths" (clusters) due to the propagation characteristics of RF signals through the environment. Note that while only paths for beams 812c-812g are shown, this is for simplicity and signals transmitted on each of the beams 812 will follow some path. In the illustrated example, paths 812c, 812d, 812e, and 812f are straight lines and path 812g reflects off an obstacle 820 (e.g., a building, a vehicle, a terrain feature, etc.).

[0129]

[0141] The UE 804 may receive beamformed signals from the base station 802 in one or more receive beams 814a, 814b, 814c, 814d (collectively, beams 814). Note that for simplicity, the beams shown in FIG. 8 represent either transmit or receive beams, depending on which of the base station 802 and the UE 804 is transmitting and which is receiving. Thus, the UE 804 may also transmit beamformed signals to the base station 802 in one or more of the beams 814, and the base station 802 may receive beamformed signals from the UE 804 in one or more of the beams 812.

[0130]

[0142] In one aspect, the base station 802 and the UE 804 may perform beam training to align the transmit and receive beams of the base station 802 and the UE 804. For example, depending on environmental conditions and other factors, the base station 802 and the UE 804 may determine that the best transmit and receive beams are 812d and 814b, respectively, or are beams 812e and 814c, respectively. The direction of the best transmit beam for the base station 802 may or may not be the same as the direction of the best receive beam, and similarly, the direction of the best receive beam for the UE 804 may or may not be the same as the direction of the best transmit beam. However, it should be noted that aligning the transmit and receive beams is not necessary to perform DL-AoD or UL-AoA positioning procedures.

[0131]

[0143] To perform the DL-AoD positioning procedure, the base station 802 may transmit reference signals (e.g., PRS, CRS, TRS, CSI-RS, PSS, SSS, etc.) to the UE 804 on one or more of the beams 812, with each beam having a different transmit angle. The different transmit angles of the beams result in different received signal strengths (e.g., RSRP, RSRQ, SINR, etc.) at the UE 804. In particular, the received signal strength is smaller for transmit beams 812 that are farther from the line-of-sight (LOS) path 810 between the base station 802 and the UE 804 than for transmit beams 812 that are closer to the LOS path 810.

[0132]

[0144] 8, if the base station 802 transmits reference signals to the UE 804 on beams 812c, 812d, 812e, 812f, and 812g, the transmit beam 812e is best aligned with the LOS path 810, but the transmit beams 812c, 812d, 812f, and 812g are not. Thus, the beam 812e may have a greater received signal strength at the UE 804 than the beams 812c, 812d, 812f, and 812g. Note that the reference signals transmitted on some beams (e.g., beams 812c and / or 812f) may not reach the UE 804, or the energy reaching the UE 804 from these beams may be too low such that the energy may not be detectable or may at least be ignored.

[0133]

[0145] The UE 804 may report the received signal strength of each measured transmit beam 812c-812g, and optionally the associated measurement quality, or the identity of the transmit beam having the greatest received signal strength (beam 812e in the example of FIG. 8) to the base station 802. Alternatively or additionally, if the UE 804 is also involved in an RTT or Time Difference of Arrival (TDOA) positioning session with at least one base station 802 or multiple base stations 812, respectively, the UE 804 may report reception-to-transmission (Rx-Tx) time difference or RSTD measurements (and optionally the associated measurement quality) to the serving base station 802 or other positioning entity. In either case, a positioning entity (e.g., base station 802, location server, third party client, UE 804, etc.) can estimate the angle from base station 802 to UE 804 as the AoD of the transmit beam having the greatest received signal strength at UE 804, here transmit beam 812e.

[0134]

[0146] In one aspect of DL-AoD based positioning where there is only one base station 802 involved, the base station 802 and the UE 804 can perform an RTT procedure to determine the distance between the base station 802 and the UE 804. Thus, the positioning entity can determine both the direction to the UE 804 (using DL-AoD positioning) and the distance to the UE 804 (using RTT positioning) to estimate the location of the UE 804. Note that the AoD of the transmit beam with the highest received signal strength is not necessarily along the LOS path 810 as shown in FIG. 8. However, for DL-AoD based positioning purposes, it is assumed to be the case.

[0135]

[0147] In another aspect of DL-AoD based positioning where there are multiple participating base stations 812, each participating base station 802 can report to the serving base station 802 the determined AoD or RSRP measurements from the individual base station 802 to the UE 804. The serving base station 802 can then report the AoD or RSRP measurements from the other participating base station(s) 812 to the positioning entity (e.g., the UE 804 for UE-based positioning or the location server for UE-assisted positioning). With this information and knowing the geographical locations of the base stations 812, the positioning entity can estimate the location of the UE 804 as the intersection of the determined AoD. For a two-dimensional (2D) location solution, there should be at least two base stations 812 involved, but as will be appreciated, the more base stations 812 involved in the positioning procedure, the more accurate the estimated UE 804 location will be.

[0136]

[0148] To perform the UL-AoA positioning procedure, the UE 804 transmits uplink reference signals (e.g., UL-PRS, SRS, DMRS, etc.) to the base station 802 on one or more of the uplink transmit beams 814. The base station 802 receives the uplink reference signals on one or more of the uplink receive beams 812. The base station 802 determines the angle of the best receive beam 812 used to receive the one or more reference signals from the UE 804 as the AoA from the UE 804 to itself. In particular, each of the receive beams 812 will result in different received signal strengths (e.g., RSRP, RSRQ, SINR, etc.) of the one or more reference signals at the base station 802. Furthermore, the channel impulse response of the one or more reference signals will be smaller for receive beams 812 that are farther away from the actual LOS path between the base station 802 and the UE 804 than for receive beams 812 that are closer to the LOS path. Similarly, the received signal strength will be lower for receive beams 812 farther from the LOS path than for receive beams 812 closer to the LOS path. Thus, the base station 802 identifies the receive beam 812 that results in the highest received signal strength, and optionally the strongest channel impulse response, and estimates the angle from itself to the UE 804 as the AoA of that receive beam 812. Note that, similar to DL-AoD based positioning, the AoA of the receive beam 812 that results in the highest received signal strength (and strongest channel impulse response, if measured) does not necessarily lie along the LOS path 810. However, for purposes of UL-AoA based positioning in FR2, it may be assumed to lie along the path 610.

[0137]

[0149] It should be noted that although the UE 804 is shown as being capable of beamforming, this is not required for DL-AoD and UL-AoA positioning procedures. Rather, the UE 804 may receive and transmit with an omni-directional antenna.

[0138]

[0150] If the UE 804 is estimating its location (i.e., the UE is a positioning entity), it needs to obtain the geographic location of the base station 802. The UE 804 may obtain the position, for example, from the base station 802 itself or from a location server (e.g., location server 230, LMF 270, SLP 272). Knowing the distance to the base station 802 (based on RTT or TA), the angle between the base station 802 and the UE 804 (based on the UL-AoA of the best received beam 812), and the known geographic location of the base station 802, the UE 804 can estimate its location.

[0139]

[0151] Alternatively, if a positioning entity, such as the base station 802 or a location server, is estimating the location of the UE 804, the base station 802 reports the AoA of the receive beam 812 that results in the highest received signal strength (and optionally the strongest channel impulse response) of the reference signal received from the UE 804, or all received signal strengths and channel impulse responses for all receive beams 812 (allowing the positioning entity to determine the best receive beam 812). The base station 802 may additionally report the Rx-Tx time difference to the UE 804. The positioning entity can then estimate the location of the UE 814 based on the distance of the UE 804 to the base station 802, the AoA of the identified receive beams 812, and the known geographic location of the base station 802.

[0140]

[0152] 9 illustrates an example of a network node location service procedure 900 according to an aspect of the disclosure. In this example, the network node that is the target device for the location service procedure is the UE 204. The network node location service procedure 900 may be performed by the UE 204, an NG-RAN node 902 in the NG-RAN 220 (e.g., a gNB 222, a gNB-CU 226, an ng-eNB 224, or other nodes in the NG-RAN 220), the AMF 264, the LMF 270, and a 5GC location services (LCS) entity 980 (e.g., any third party application requesting the location of the UE 204, a public service access point (PSAP), an E-911 server, etc.).

[0141]

[0153] A location service request to obtain the location of a target (i.e., UE 204) can be initiated by the 5GC LCS entity 980, the AMF 264 serving the UE 204, or the UE 204 itself. Figure 9 illustrates these options as steps 910a, 910b, and 910c, respectively. Specifically, in step 910a, the 5GC LCS entity 980 sends a location service request to the AMF 264. Alternatively, in step 910b, the AMF 264 generates the location service request itself. Alternatively, in step 910c, the UE 204 sends a location service request to the AMF 264.

[0142]

[0154] Upon receiving (or generating) the location service request, the AMF 264 forwards the location service request to the LMF 270 in step 920. The LMF 270 then performs an NG-RAN positioning procedure with the NG-RAN node 902 in step 930a and a UE positioning procedure with the UE 204 in step 930b. The particular NG-RAN positioning procedure and UE positioning procedure may depend on the type(s) of positioning method(s) used to determine the location of the UE 204, which may depend on the capabilities of the UE 204. The positioning method may be downlink-based (e.g., LTE-OTDOA, DL-TDOA, DL-AoD, etc.), uplink-based (e.g., UL-TDOA, UL-AoA, etc.), and / or downlink- and uplink-based (e.g., LTE / NR E-CID, multi-RTT, etc.), as described above.

[0143]

[0155] NG-RAN and UE positioning procedures may utilize LPP signaling between the UE 204 and the LMF 270, and LPP type A (LPPa) or New Radio Positioning Protocol type A (NRPPa) signaling between the NG-RAN node 902 and the LMF 270. LPP is used point-to-point between a location server (e.g., the LMF 270) and a UE (e.g., the UE 204) to obtain location measurements or location estimates or to transfer assistance data. A single LPP session is used to support a single location request (e.g., for a single Mobile Terminated Location Request (MT-LR), Mobile Originated Location Request (MO-LR), or Network Induced Location Request (NI-LR)). Multiple LPP sessions may be used between the same endpoints to support multiple different location requests. Each LPP session comprises one or more LPP transactions, and each LPP transaction performs a single operation (e.g., capability exchange, assistance data transfer, location information transfer). LPP transactions are referred to as LPP procedures.

[0144]

[0156] A prerequisite for step 930 is that an LCS correlation identifier (ID) and an AMF ID have been passed to the LMF 270 by the serving AMF 264. Both the LCS correlation ID and the AMF ID may be represented as strings selected by the AMF 264. The LCS correlation ID and the AMF ID are provided to the LMF 270 by the AMF 264 during a location service request in step 920. Then, when the LMF 270 triggers step 930, the LMF 270 also includes the LCS correlation ID for this location session along with the AMF ID indicating the AMF instance serving the UE 204. The LCS correlation ID is used during a positioning session between the LMF 270 and the UE 204 to ensure that a positioning response message from the UE 204 is returned by the AMF 264 to the correct LMF 270 and carries an indication (LCS correlation ID) that can be recognized by the LMF 270.

[0145]

[0157] As described in more detail in 3GPP TS 23.273, which has been published and is incorporated herein by reference in its entirety, it should be noted that the LCS Correlation ID serves as a location session identifier that may be used to identify messages exchanged between the AMF 264 and the LMF 270 for a particular location session for the UE 204. As described above and shown in stage 920, a location session between the AMF 264 and the LMF 270 for a particular UE 204 is triggered by the AMF 264, and the LCS Correlation ID may be used to identify this location session (e.g., may be used by the AMF 264 to identify state information for this location session, etc.).

[0146]

[0158] LPP signaling may be used to request and report measurements related to the following positioning methods: LTE-OTDOA, DL-TDOA, A-GNSS, E-CID, Sensor, TBS, WLAN, Bluetooth, DL-AoD, UL-AoA, and Multi-RTT. Currently, LPP measurement reports may include the following measurements: (1) one or more ToA, TDOA, RSTD, or Rx-Tx time difference measurements, (2) one or more AoA and / or AoD measurements (currently only for base stations reporting UL-AoA and DL-AoD to the LMF 270), (3) one or more multipath measurements (ToA, RSRP, AoA / AoD per path), (4) one or more motion states (e.g., walking, driving, etc.) and trajectory (currently only for the UE 204), and (5) one or more report quality indications.

[0147]

[0159] As part of the NG-RAN node positioning procedure (step 930a) and the UE positioning procedure (step 930b), the LMF 270 may provide LPP assistance data in the form of Downlink Positioning Reference Signal (DL-PRS) configuration information for the selected positioning method(s) to the NG-RAN node 902 and the UE 204. Alternatively or additionally, the NG-RAN node 902 may provide DL-PRS and / or Uplink PRS (UL-PRS) configuration information for the selected positioning method(s) to the UE 204. It should be noted that although FIG. 9 shows a single NG-RAN node 902, there may be multiple NG-RAN nodes 902 involved in a positioning session.

[0148]

[0160] When configured in DL-PRS and / or UL-PRS configurations, the NG-RAN node 902 and the UE 204 transmit and receive / measure individual PRS at scheduled times. The NG-RAN node 902 and the UE 204 then transmit their respective measurements to the LMF 270. In some cases, the NG-RAN node 902 may transmit its measurements to the UE 204, which may forward them to the LMF 270 using LPP signaling. Alternatively, the NG-RAN node 902 may transmit its measurements directly to the LMF 270 in LPPa or NRPPa signaling. In some cases, the UE 204 may transmit its measurements to the NG-RAN node 902 during RRC, uplink control information (UCI), or MAC control element (MAC-CE) signaling, which may forward the measurements to the LMF 270 using LPPa or NRPPa signaling. Alternatively, the UE 204 may transmit its measurements directly to the LMF 270 using LPP signaling.

[0149]

[0161] When the LMF 270 obtains measurements from the UE 204 and / or the NG-RAN node 902 (depending on the type(s) of the positioning method(s)), it uses these measurements to calculate an estimate of the location of the UE 204. Then, in step 940, the LMF 270 transmits a location service response to the AMF 264 including the location estimate for the UE 204. The AMF 264 then forwards the location service response to the entity that generated the location service request in step 950. Specifically, if in step 910a, a location service request is received from the 5GC LCS entity 980, then in step 950a, the AMF 264 transmits the location service response to the 5GC LCS entity 980. However, if in step 910c, a location service request is received from the UE 204, then in step 950c, the AMF 264 sends the location service response to the UE 204. Alternatively, if the AMF 264 generated a location service request in step 910b, in step 950b, the AMF 264 stores / uses the location service response itself.

[0150]

[0162] It should be noted that while the network node location service procedure 900 is described above as a UE-assisted positioning operation, it may instead be a UE-based positioning operation. A UE-assisted positioning operation is one in which the LMF 270 calculates the location of the UE 204, whereas a UE-based positioning operation is one in which the UE 204 calculates its own location. For a UE-based positioning operation, steps 910c and 950c are performed. The LMF 270 may still coordinate transmission / measurement of DL-PRS (and possibly UL-PRS), but the measurements are forwarded to the UE 204 rather than the LMF 270. Thus, the location service response in steps 940 and 950c may be measurements from the involved NG-RAN node(s) 902 rather than a location estimate of the UE 204. Alternatively, if the involved NG-RAN node(s) 902 forward their respective measurements directly to the UE 204 (e.g., via RRC signaling), the location service response at stage 940 may simply be a confirmation that the NG-RAN node and UE positioning procedure at stage 930 is complete.

[0151]

[0163] NR positioning operations have security vulnerabilities and may be subject to several PRS attack scenarios. In one PRS attack scenario, a PRS attacker has knowledge of a previous PRS sequence used in a positioning operation. The PRS attacker receives one or more PRS symbols, determines transmission parameters, and transmits a new signal for a subsequent PRS. Instead of measuring the PRS transmitted from the correct PRS source, the base station or UE measures the PRS transmitted by the PRS attacker, thereby generating measurements that result in an erroneous positioning determination.

[0152]

[0164] In another PRS attack scenario, a PRS attacker receives a complete PRS configuration via broadcast assistance data or unicast RRC. The PRS attacker transmits a PRS based on information obtained from the complete PRS configuration. Again, instead of measuring the PRS transmitted from the correct PRS source, the base station or UE measures the PRS transmitted by the PRS attacker, thereby generating measurements that result in an erroneous positioning determination.

[0153]

[0165] According to some aspects of the present disclosure, some characteristics of the received PRS may be used to distinguish between a PRS transmitted by a genuine TRP and a PRS transmitted by a PRS attacker. In an aspect, the UE or base station (one or both of which are referred to herein as a "receiving entity") may check the time domain consistency of the PRS and / or SRS. One method of checking the time domain consistency includes monitoring the channel impulse (energy) response (CER). Generally speaking, FIG. 10 is a graph 1000 illustrating a channel impulse (energy) response of a multipath channel between a receiver device (e.g., either a UE or a base station described herein) and a transmitter device (e.g., either the other of a UE or a base station described herein) according to an aspect of the present disclosure. The channel impulse response represents the strength of an RF signal received through a multipath channel as a function of time delay. Thus, the horizontal axis is in units of time (e.g., milliseconds) and the vertical axis is in units of signal strength (e.g., decibels). It should be noted that a multipath channel is a channel between a transmitter and a receiver in which an RF signal follows multiple paths, or multipaths, due to transmission of the RF signal in multiple beams and / or due to the propagation characteristics of the RF signal (e.g., reflection, refraction, etc.).

[0154]

[0166] In the example of FIG. 10, the receiver detects / measures multiple (four) clusters of channel taps. Each channel tap represents a multipath that the RF signal took between the transmitter and the receiver, and possibly an RF signal transmitted by an attacker. That is, the channel taps represent the arrival of the RF signal on the multipath and / or from the attacker. Each cluster of channel taps indicates that the corresponding multipath took essentially the same path. There may be different clusters due to 1) the RF signal being transmitted on different transmit beams (and therefore at different angles), 2) the propagation characteristics of the RF signal (e.g., potentially taking different paths due to reflections), 3) the RF signal being transmitted by an attacker, or 4) any combination thereof.

[0155]

[0167] Every cluster of channel taps for a given RF signal represents a multipath channel (or simply a channel) between the transmitter and the receiver. Under the channel shown in FIG. 10, the receiver receives a first cluster of two RF signals on the channel taps at time T1, a second cluster of five RF signals on the channel taps at time T2, a third cluster of five RF signals on the channel taps at time T3, and a fourth cluster of four RF signals on the channel taps at time T4. In the example of FIG. 10, the first cluster of RF signals at time T1 is assumed to correspond to RF signals transmitted on a transmit beam aligned with a LOS, or shortest path, since it arrives first. The third cluster at time T3 consists of the strongest RF signals and may correspond, for example, to RF signals transmitted on a transmit beam aligned with a non-line-of-sight (NLOS) path. Note that while FIG. 10 shows clusters of two to five channel taps, it will be appreciated that the clusters may have more or less than the number of channel taps shown.

[0156]

[0168] In one aspect of PRS attacker detection, the receiving entity checks the consistency of CER across multiple PRS and / or SRS (both of which are hereinafter designated as "PRS") repetitions. To this end, the receiving entity may combine N PRS symbols of each PRS resource and estimate the ToA through CER peak detection. The receiving entity may check the time-domain consistency across different resource repetitions. Time-domain consistency detection may include peak location consistency, power delay profile (aka CER) consistency, etc. If such time-domain parameters are not consistent, a certain PRS and / or SRS (hereinafter referred to as "PRS") measured in the channel may originate from a source other than a genuine TRP and may include a PRS transmitted by a PRS attacker.

[0157]

[0169] In another aspect, the receiving entity may check the consistency of the CER across each PRS symbol in the PRS resource. To this end, the receiving entity may estimate the CER with each PRS symbol in the PRS resource. For a comb pattern of N PRS resources, the receiving entity should expect N CER peaks. The receiving entity may check the time domain consistency across different PRS symbols. Time domain consistency detection may include peak location consistency, power delay profile consistency, etc. Again, if such measurements are not consistent, some of the measured PRSs may originate from sources other than the genuine TRP and may include PRSs transmitted by a PRS attacker.

[0158]

[0170] In another aspect, the receiving entity may compare the CER over the PRS symbols and / or PRS resources with other communications reference signal (RS) symbols and / or resources. For security purposes, the PRS may be QCL'd with some unicast communication RSs (e.g., TRS, CSI-RS, DMRS). The receiving entity may compare the CER estimated from the PRS with their associated unicast communication RSs. If the receiving entity observes a time domain mismatch of the CERs, the receiving entity may classify the received PRS as a PRS attack event.

[0159]

[0171] According to some aspects of the disclosure, a receiving entity may receive RSTD assistance data for PRS processing from a base station and / or a location server. In one aspect, the receiving entity may be provided with expected RSTD measurements along with corresponding value uncertainties (e.g., search windows) for the TRPs in the assistance data to be measured by the receiving entity. As an example, the value range of expected RSTD uncertainty when any of the resources used for DL ​​positioning measurements are in FR1 may be + / - 32us according to some aspects. If all of the resources used for DL ​​positioning measurements are in FR2, the value range of expected RSTD uncertainty may be about + / - 8us according to some aspects.

[0160]

[0172] The receiving entity may also monitor the PRS for angle domain consistency to detect PRS attacker transmissions. In an aspect, the receiving entity may be capable of estimating the AoA for each PRS through digital beamforming. The receiving entity, such as a UE, may also acquire its own location through either a previous NR positioning fix and / or a non-RAT positioning method such as GNSS. Still further, the UE may be capable of acquiring the base station (e.g., gNB) location or other TRP location through assistance data to estimate the AoA. Based on such an estimate, the UE may check angle domain consistency across different PRS symbols and / or PRS resources. For example, the receiving entity may check the difference between the AoA of the PRS estimated based on the known TRP location and a measurement of the AoA determined from measurements of actual PRS transmissions to determine the angle consistency. In an aspect, the receiving entity may compare the estimated angle to one or more previous angle measurements of one or more recently received PRS. In various aspects, the estimated angle may be determined from RAT-dependent techniques, RAT-independent techniques, or any combination thereof. In one aspect, the receiving entity may check angle estimation consistency across multiple PRS symbols and resources, and if the receiving entity observes an angular domain mismatch for the PRS, the receiving entity may classify the received PRS as a PRS attack event.

[0161]

[0173] In some aspects, angle domain consistency may be combined with a time domain consistency check to address situations where a PRS attacker is located along the propagation path between receiving entities (e.g., between a gNB and a UE). Such a combination may also be advantageous when a PRS attacker obtains a rough estimate of the location of a victim receiving entity and uses that rough estimate in determining the timing of the attacker PRS's transmissions.

[0162]

[0174] According to some aspects of the disclosure, a receiving entity such as a UE may receive angle assistance data (e.g., predicted AoA, predicted AoD, predicted departure zenith (ZoD), predicted arrival zenith (ZoA), or other predicted angle measurements, any of which may be referred to as "predicted angle measurements") from a base station, a location server, or any combination thereof. In one aspect, the UE may be provided with the predicted angle measurements along with corresponding predicted angle measurement uncertainties for the TRPs indicated in the assistance data. In one aspect, a single predicted angle measurement (e.g., AoD and / or ZoD) and corresponding uncertainty ranges for the predicted angle measurements may be provided to the UE for each TRP that the UE is to measure during a positioning session. In one aspect, an indication of multiple predicted angle measurements (e.g., AoD and / or ZoD) and corresponding uncertainty ranges may be signaled to the UE by a location server, a base station, or any combination thereof.

[0163]

[0175] Additionally or alternatively, a receiving entity such as a base station may be provided with one or more AoAs and / or ZoAs for UL-PRS (e.g., SRS) transmitted by the UE to be measured by the base station during a positioning session. In an aspect, a single expected AoA and / or ZoA value and a corresponding uncertainty range for each AoA and / or ZoA value may be provided to the base station for each UE. Additionally or alternatively, the base station may receive multiple expected AoA and / or ZoA values ​​for each UE and a corresponding range of uncertainty for each of the multiple expected AoA and / or ZoA values. In an aspect, the base station may receive the expected angle measurements and corresponding ranges of uncertainty values ​​from a location server. Additionally or alternatively, the base station may estimate the expected angle measurements and corresponding ranges of its own uncertainty values ​​based on a previous UL-PRS (e.g., SRS) transmission of the UE measured by the base station during a previous positioning session.

[0164]

[0176] In one aspect, the receiving entity does not receive the expected angle measurements and corresponding uncertainties, e.g., if only time domain consistency is used for PRS attacker detection, the expected angle measurements and corresponding uncertainties do not need to be transmitted to the receiving entity.

[0165]

[0177] According to aspects of the disclosure, a positioning session using predicted angle and / or time domain measurements and corresponding uncertainty values ​​may be secured by hashing such values ​​to reduce the risk that a PRS attacker may intercept and use such values ​​in a PRS attack. To this end, an entity transmitting such estimates and / or uncertainty values ​​may perform a hash function on the values ​​before transmitting them to one or more receiving entities. The receiving entity may then perform the same hash function on actual measurements that the receiving entity makes during the positioning session. The receiving entity may compare the predicted measurements, the predicted uncertainties, and the hash values ​​of the actual measurements to determine whether the actual measurements match the predicted measurements. In one aspect, whether the actual measurements match the predicted measurements may be determined by determining whether a hash value of the predicted measurements with a hash value of the actual measurements is within a range of expected measurement uncertainty as reflected in a hash value of the predicted measurement uncertainty.

[0166]

[0178] A hash function is a mathematical function that converts a numeric input value into another compressed numeric value. The input to a hash function may be of any length, but the output is a fixed length. To be an effective cryptographic tool, it is desirable for a hash function to have several properties. For example, a hash function should have a degree of preimage resistance, in that it should be computationally difficult to reverse the hash function. In other words, if a hash function h is applied to an input value x to produce a hash value z, then finding the input value x from the hash value z should be a difficult process. This property protects against an attacker who only has the hash value z from determining the input value x.

[0167]

[0179] Another desirable feature of a hash function is that it has the secondary preimage resistance property, in that, given an input x and its hash z, it is difficult to find a different input that produces the same hash. In other words, if a hash function h for an input x produces a hash value h(x), then it should be difficult to find another input value y such that h(y)=h(x). This property of a hash function protects against an attacker who has an input value and its hash and wants to substitute a different value as the legitimate value in place of the original input value.

[0168]

[0180] A further desirable feature of a hash function is that it has the collision resistance property. This property means that it should be difficult to find two different inputs of any length that result in the same hash. This property is also called a collision-free hash function. In other words, for a hash function h, it is difficult to find any two different inputs x and y such that h(x)=h(y). Since hash functions are effectively compression functions with a fixed hash length, it is usually not possible for a hash function to avoid all collisions. This collision resistance property of a hash function only means that such collisions will occur very rarely. This property makes it very difficult for an attacker to find two input values ​​that have the same hash.

[0169]

[0181] The aforementioned desirable properties of hash functions can be used to secure expected measurements / uncertainty values ​​from use by a PRS attacker: using hash values ​​of expected measurements / uncertainty values ​​helps the receiving entity to assess the authenticity of such hash values, since a PRS attacker cannot modify such hash values ​​in such a way that the modification is undetectable, and the expected / uncertainty values ​​cannot be derived, individually or collectively, from the hash values ​​sent to the receiving entity.

[0170]

[0182] To further secure the transmission of the expected quantities, a hash value of each of these quantities and / or a single hash value for all of the quantities after putting all the quantities into a single stream may be signaled to the receiving entity in one or more secure layers (e.g., Layer 3 data such as RRC data). Thus, even if the security of the RRC transmission is breached, the expected corresponding uncertainty information associated with each PRS will not be compromised since the quantity hash value(s) remain secured by the hash function. Thus, the receiving entity can discard the PRS of an unauthorized source (e.g., a PRS attacker) if the hash values ​​for the quantities it receives for the expected measurements and / or corresponding uncertainty ranges do not make sense (e.g., the hash values ​​do not fall within the range of values ​​that the receiving entity expects to receive in the context of a positioning session).

[0171]

[0183] In order to maintain the integrity and authentication of the positioning measurements, an entity transmitting the hashed expected values / uncertainties may, for example, transmit one or more expected PRS Reference Signal Received Power (PRS-RSRP) measurements, 2) one or more PRS-RSRP uncertainty values ​​associated with one or more expected PRS-RSRP measurements, 3) one or more expected RSTD measurements, 4) one or more RSTD uncertainty values ​​associated with one or more expected RSTD measurements, 5) one or more expected AoA measurements, and 6) one or more AoA measurements. the one or more AoA uncertainty values ​​associated with the one or more AoD measurements, 7) one or more predicted AoD measurements, 8) one or more AoD uncertainty values ​​associated with the one or more AoD measurements, 9) one or more predicted ZoA measurements, 10) one or more ZoA uncertainty values ​​associated with the one or more ZoA measurements, 11) one or more predicted ZoD measurements, 12) one or more ZoD uncertainty values ​​associated with the one or more ZoD measurements, or 13) a hash value including any combination thereof.

[0172]

[0184] According to some aspects of the present disclosure, a receiving entity, such as a UE, receives one or more configurations of resources of one or more TRPs to be measured during a positioning session. The UE further receives a first set of one or more hash values ​​based on one or more hashing operations applied to one or more expected measurements and / or corresponding expected uncertainty values, such as expected measurements and expected uncertainty values ​​described herein. The hash values ​​of the expected measurements and / or corresponding expected uncertainty values ​​are generated, for example, by a location server and / or a base station (e.g., a gNB). In one aspect, the expected measurements and expected uncertainty values ​​are determined at the location server and / or base station. In one aspect, the expected measurements and / or expected uncertainty values ​​are generated for each time and / or angle measurement of a PRS resource measured by the UE and to be used for PRS attacker detection. Prior to transmission to the UE, the location server and / or base station applies one or more hash functions to the expected measurements and / or expected uncertainty values.

[0173]

[0185] In one aspect, one or more hash functions may be applied individually to each expected measurement and / or expected uncertainty value of each PRS resource to be measured by the UE and used for PRS attacker detection. In one aspect, the same hash function may be applied to each such individual expected measurement and / or expected uncertainty value. In one aspect, different hash functions may be applied to different ones of the individual expected measurements and / or uncertainty values. The hash functions and how they are applied to the expected measurements and / or uncertainty values ​​are agreed upon between the UE and the location server and / or base station.

[0174]

[0186] In one aspect, a hash function may be applied to the plurality of expected measurements and / or the expected uncertainty values. For example, one or more strings of the plurality of expected measurements and / or corresponding uncertainty values ​​may be generated at the location server and / or base station based on a string generation methodology agreed upon by the UE and the location server and / or base station. The location server and / or base station then applies one or more hash functions to the strings to generate hash values, the one or more hash functions being agreed upon by the UE and the location server and / or base station. In one aspect, the same hash function may be applied to each of the plurality of string values. In one aspect, different hash functions may be applied to different ones of the plurality of string values. Again, the hash function and the manner in which the hash function is applied to the plurality of strings is agreed upon by the UE and the location server and / or base station.

[0175]

[0187] During the positioning session, the UE measures the PRS resources indicated in the received transmission (e.g., assistance data) to generate actual measurements for the PRS resources. Based on whether the measurements of the PRS resources should be used for PRS attacker detection, the UE uses the actual measurements to generate one or more corresponding hash values ​​in a manner agreed upon between the UE and the location server and / or base station. As a result, the UE now has hash values ​​(e.g., a second set of one or more hash values) corresponding to one or more actual measurements of the PRS resources that can be used for PRS attacker detection.

[0176]

[0188] Once the UE generates the second set of hash values, the UE compares the second set of one or more hash values ​​to the first set of one or more hash values ​​to detect the PRS attack. In one aspect, the comparison is used to determine whether the one or more actual measurements are within tolerance limits of the one or more expected measurements. In one aspect, the comparison includes comparing the second set of one or more hash values ​​to the first set of one or more hash values ​​to determine whether at least one actual measurement of the one or more actual measurements is outside tolerance limits of at least one expected measurement of the one or more expected measurements.

[0177]

[0189] If detected, the UE may report to the location server and / or base station error information regarding the actual measurements whose corresponding hash values ​​are outside of the acceptable limits. The error information may indicate which actual measurements the UE determined are outside of the acceptable limits. In one aspect, the error information may include a bitmap indicating which parameters (e.g., RSRP, RSTD, AoD, ZoD, etc.) of the actual PRS resource measurements are outside of the acceptable limits. In one aspect, individual bits of the bitmap may correspond to individual parameters (e.g., bit 3 corresponds to RSRP, bit 2 corresponds to RSTD, bit 1 corresponds to AoD, and bit 0 corresponds to ZoD). Using this bit correspondence as an example, a bitmap of 1010 indicates that the measured RSRP and AoD values ​​are outside of the acceptable limits while RSTD and ZoD are within the acceptable limits. It will be appreciated that other bit mappings to various parameters may be used based on the teachings of the present disclosure, and the foregoing constitutes one such example.

[0178]

[0190] Additionally or alternatively, the error information may indicate the extent to which the actual measurement is outside of acceptable limits. In one aspect, the extent may be expressed as a difference between a hash value of the expected measurement and a hash value of the actual measurement. Additionally or alternatively, the extent may be expressed according to a calculation agreed upon by the UE and the location server and / or base station.

[0179]

[0191] According to some aspects of the disclosure, the determination of the range of tolerance limits used for the comparison of hash values ​​of the expected measurements and hash values ​​of the actual measurements may be based on expected uncertainty values ​​associated with the expected measurements. According to some aspects, expected measurements of PRS resources to be measured by the UE may be hashed with the corresponding expected uncertainty values ​​to generate hash values ​​used for the comparison. According to some aspects, a plurality of expected measurements associated with PRS resources to be measured by the UE may be hashed by the location server and / or base station as a basis for the comparison and transmitted to the UE. According to some aspects, a plurality of expected uncertainty values ​​associated with PRS resources to be measured by the UE may be hashed by the location server and / or base station and transmitted to the UE for use in the comparison. Additionally or alternatively, the range of tolerance limits may be based on another range agreed upon by the UE and the location server and / or base station. In such an example, the agreed upon range may be expressed as a fixed value for the range of tolerance limits or a hash value corresponding to the range of tolerance limits.

[0180]

[0192] According to some aspects of the disclosure, the UE and the location server and / or base station may agree on a hash bin configuration to be used for the comparison. In one aspect, the hash bin configuration may be based on hash values ​​that fall within tolerance limits for hash values ​​generated using expected measurements and / or expected uncertainty values. Additionally or alternatively, the hash bin configuration may include hash bins that correspond to hash values ​​that are outside of the tolerance limits.

[0181]

[0193] According to some aspects of the present disclosure, a single hash bin configuration may be associated with each given expected measurement to be measured by the UE. Additionally or alternatively, in cases where a hash value corresponds to a set of multiple expected measurements, a single hash bin configuration may be associated with each set.

[0182]

[0194] In some aspects of the present disclosure, each hash bin in a hash bin configuration may correspond to a range of hash values. Such a hash bin configuration may be implemented when the hash function used to generate the hash values ​​is a locality sensitive hash function. Locality sensitive hashing is an algorithmic technique that hashes similar input items into the same "bucket" (e.g., a bin corresponding to a range of hash values) with a high probability. Because similar hash values ​​end up in the same bucket, this technique can be used in data clustering and nearest neighbor searches to determine whether a hash value corresponding to one or more actual measurements is within an acceptable limit of a hash value corresponding to one or more expected measurements. In such cases, depending on the implementation, the number of hash collisions associated with a locality sensitive hash function may be greater than the number of hash collisions resulting from other types of hash functions. In some aspects, regardless of whether the hash function used is locality sensitive, the ability to detect PRS attacks may be increased by increasing the number of hash bins used in the configuration.

[0183]

[0195] Since there may be errors in the measurements without a PRS attack, the UE may compare the hash value of the current hash bin, the current hash bin+Y, the current hash bin-X, or a defined set of hash bins, where X and Y are configured RRC / MAC-CEs and correspond to the number of bins adjacent to the current hash bin, with the received hash value for each parameter. If there is a mismatch in one or more quantities (e.g., per configuration between the UE and the location server and / or base station), the UE reports the occurrence. In one aspect, the occurrence may be indicated in a flag or other information in a report dedicated to PRS attack detection. Additionally or alternatively, the occurrence may be indicated by a flag or other information in a report with other information reported by the UE, where the other information is provided in a report not dedicated to PRS attack detection.

[0184]

[0196] According to some aspects of the disclosure, the UE may attempt to assign hash values ​​corresponding to actual measurements to hash bins of the hash bin configuration. As an example, the UE may perform an assignment operation to assign one or more hash values ​​of the second set of hash values ​​to one or more hash bins of the agreed upon hash bin configuration. In an aspect, the UE may report to the location server and / or base station information regarding one or more hash values ​​of the second set of hash values ​​that are not assignable to permitted hash bins of the set of hash bins and / or one or more hash values ​​that fall within a hash bin that corresponds to a hash value indicative of a PRS attack.

[0185]

[0197] As described above, the hash values ​​may be generated using the individual expected measurements. In such a case, the first set of one or more hash values ​​may include a fixed size L hash value associated with each of the one or more expected measurements. Accordingly, the second set of one or more hash values ​​may include a fixed size L hash value associated with each of the one or more actual measurements. In some aspects, the value of L may be selected based on a desired accuracy of the PRS attack determination. In some aspects, the value of L may be selected based on an acceptable hash collision factor. The value of L may be RRC / MAC-CE configured based on specifications agreed upon between the UE and the location server and / or base station. Other factors for determining the value of L may also be used.

[0186]

[0198] Additionally or alternatively, the first set of one or more hash values ​​may include hash values ​​of size Z collectively associated with multiple predicted measurements of the one or more predicted measurements. Further, the second set of one or more hash values ​​may include hash values ​​of size Z collectively associated with multiple actual measurements of the one or more actual measurements. In some aspects, the value of Z may be configured via RRC / MAC-CE. Additionally or alternatively, the value of Z may be based on a specification agreed upon between the UE and the location server and / or base station.

[0187]

[0199] According to some aspects of the present disclosure, the value of Z may be based on a modulation and coding scheme (MCS) similar to the transport block size (TBS) calculation described in published 3GPP TS 138.214. Determining the value of Z in this manner facilitates the generation of dynamic reports. In one aspect, the value of Z may be determined as follows: Z=N info =#layers * spectral eff * #REs however, #layers is the number of control information layers, spectral eff is the spectral efficiency, #REs is the number of resource elements.

[0188] In some embodiments, the value of Z determined based on this calculation may be modified based on the desired accuracy of the PRS attack determination. In some embodiments, the value of Z may be modified based on an acceptable hash collision factor. Other factors for modifying the value of Z may also be used.

[0189]

[0200] The hash values ​​described herein may be signaled to the receiving entity in various ways. According to some aspects of the present disclosure, the hash values ​​are signaled via LPP. In the Uu link, the hash values ​​may be signaled in the RRC information in the PDSCH data channel. In sidelink communications, the hash values ​​may be signaled in the RRC information in the Physical Sidelink Shared Channel (PSSCH) data channel. In some aspects, some of the hash values ​​may be communicated via the RRC / PDSCH, while other hash values ​​are communicated via the RRC / PSSCH. Communicating the hash values ​​via the RRC information is beneficial in that the hash values ​​are further encrypted as part of the encryption of the RRC data, thereby providing an additional level of security to the predicted measurements and / or the corresponding uncertainty values.

[0190]

[0201] In accordance with some aspects of the disclosure, the hash value is signaled via RRC information, hi some aspects, the RRC information is carried in a PDSCH, a PSSCH, or a combination thereof.

[0191]

[0202] In some instances, encryption / decryption of the hashed expected values / uncertainties and / or hashed actual measurements during RRC transmissions may be slow, especially for mobile UEs. To address such time constraints, the hashed expected values / uncertainties and / or hashed actual measurements may be transmitted in PHY layer signaling to facilitate more efficient communication of such hashed values. In some aspects, a PHY layer carrier dedicated to transmitting the hashed expected values / uncertainties and / or hashed actual measurements may be employed. In some aspects, the UE and the base station (e.g., gNB) may exchange the hashed expected values / uncertainties and / or hashed actual measurements using such PHY layer signaling. In some aspects, the base station communicates with a location server via NRPPa to receive and / or forward the hashed expected values / uncertainties and / or hashed actual measurements.

[0192]

[0203] According to some aspects of the disclosure, the hash value may be signaled without further encryption. In some aspects, the hash value may be signaled via one or more MAC-CEs carried in the PDCCH, in a physical sidelink control channel (PSCCH), in sidelink control information (e.g., SCI-2 data) carried in the PSCCH, or in a combination thereof.

[0193]

[0204] In some aspects, the secure use of hashed measurements disclosed herein is applicable to the transmission and reception of positioning information between various network entities. In some aspects, the communication may be from a base station (e.g., gNB) to a UE, from a UE to another UE, from a UE to a base station (e.g., gNB), etc.

[0194]

[0205] In some aspects, if an insecure channel is used to communicate the hash value, a private key may be used to encrypt the hash value at the device transmitting the hash value. A public key may be used to decrypt the encrypted hash value at the receiver side. A public key and a private key are generated at the device transmitting the hash value, and the public key is shared with the device receiving the encrypted hash value. Thus, the private key is used to encrypt at the transmitting device, and the public key is used to decrypt at the receiving device. Because the private key is never shared, an attacker cannot determine or generate the encrypted hash value before receiving it. If a traditional approach to public / private key usage were employed, the public key would be used to encrypt the hash value. However, because the public key is known to all devices in the network (unless it is sent unicast or groupcast to a specific trusted device), an attacker can forge the hash value.

[0195]

[0206] In some aspects, a known payload of bits may be added to the hash value payload prior to encryption with the private key (e.g., a bit sequence of "1100" may be added to the hash value payload). A device receiving the hash value may use the public key to decrypt the transmission and determine whether the known payload of bits (e.g., the bit sequence "1100") is present. The known sequence of bits that is added to the hash value payload of the hash value may be configured (e.g., by the base station) or may be defined in a specification (e.g., a 3GPP specification). The length of the sequence may be fixed or variable.

[0196]

[0207] In some aspects, the public / private key operations described above may be extended to hash values ​​transmitted in a secure channel. Additional layers of encryption may be used to enhance the security of hash values ​​transmitted over a secure channel.

[0197]

[0208] The encryption / decryption of the hash value in the above-mentioned method is different from a conventional encryption / decryption process. Notably, according to aspects of the present disclosure, a public key may be used for encryption and a private key may be used for decryption. Furthermore, both the private key and the public key are generated by the sending device, whereas in a conventional public / private key scenario, the receiving side generates the public key and the private key.

[0198]

[0209] 11 illustrates an example method 1100 of wireless communication performed by a network node (e.g., a UE, a gNB, a base station, etc.) according to aspects of the disclosure. In operation 1102, the network node receives a first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs). In an aspect, operation 1102 may be performed by one or more WWAN transceivers 310, one or more processors 332, memory 340, and / or positioning component 342, any or all of which may be considered as a means for performing this operation. In one aspect, operation 1102 may be performed by one or more WWAN transceivers 350, one or more processors 384, memory 386, and / or positioning components 388, any or all of which may be considered a means for performing this operation.

[0199]

[0210] In operation 1104, the network node measures one or more PRS resources to obtain one or more actual measurements. In an aspect, operation 1104 may be performed by one or more WWAN transceivers 310, one or more processors 332, memory 340, and / or positioning component 342, any or all of which may be considered as a means for performing this operation. In an aspect, operation 1104 may be performed by one or more WWAN transceivers 350, one or more processors 384, memory 386, and / or positioning component 388, any or all of which may be considered as a means for performing this operation.

[0200]

[0211] In operation 1106, the network node determines whether the one or more actual measurements of the one or more PRS resources are within tolerance limits of the one or more expected measurements based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​being based on application of the one or more hash operations to the one or more actual measurements. In one aspect, operation 1106 may be performed by one or more WWAN transceivers 310, one or more processors 332, memory 340, and / or positioning component 342, any or all of which may be considered as a means for performing this operation. In one aspect, operation 1106 may be performed by one or more WWAN transceivers 350, one or more processors 384, memory 386, and / or positioning component 388, any or all of which may be considered as a means for performing this operation.

[0201]

[0212] As will be appreciated, a technical advantage of method 1100 is that a network node (e.g., a UE, a gNB, a base station, etc.) may use secured hash values ​​corresponding to expected measurements to authenticate actual PRS measurements the network node takes during a positioning session, while also facilitating the identification of PRS measurements that may be tampered with through a PRS attack. Using such secured hash values ​​for the measurements helps prevent a PRS attacker from using the expected measurements in a PRS attack where the PRS attacker attempts to generate fake PRS transmissions.

[0202]

[0213] 12 illustrates an example method 1200 of wireless communication performed by a network node (e.g., UE, gNB, base station, etc.) according to aspects of the disclosure. In operation 1202, the network node receives from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more expected measurements, the one or more expected measurements corresponding to expected measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by the network node during a positioning session. In an aspect, operation 1202 may be performed by one or more WWAN transceivers 310, one or more processors 332, memory 340, and / or positioning component 342, any or all of which may be considered as a means for performing this operation. In one aspect, operation 1202 may be performed by one or more WWAN transceivers 350, one or more processors 384, memory 386, and / or positioning components 388, any or all of which may be considered a means for performing this operation.

[0203]

[0214] In operation 1204, the network node uses the first set of one or more hash values ​​for PRS attack detection. According to some aspects of the present disclosure, using the first set of one or more hash values ​​for PRS attack detection includes transmitting the first set of one or more hash values ​​to the UE and receiving an indication from the UE that one or more actual measurements made by the UE are outside of a tolerance limit of at least one of the one or more expected measurements. According to some aspects of the present disclosure, using the first set of one or more hash values ​​for PRS attack detection includes receiving a second set of one or more hash values ​​corresponding to one or more actual measurements taken by the UE of one or more PRS resources and determining whether the one or more actual measurements of the one or more PRS resources are within a tolerance limit of the one or more expected measurements based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values ​​based on application of one or more hash operations to the one or more actual measurements. In one aspect, operation 1204 may be performed by one or more WWAN transceivers 310, one or more processors 332, memory 340, and / or positioning component 342, any or all of which may be considered as a means for performing this operation. In one aspect, operation 1204 may be performed by one or more WWAN transceivers 350, one or more processors 384, memory 386, and / or positioning component 388, any or all of which may be considered as a means for performing this operation.

[0204]

[0215] As will be appreciated, a technical advantage of method 1200 is that a network node detects potentially corrupted PRS measurements using secure hash values ​​corresponding to expected measurements. Using such secure hash values ​​for measurements helps prevent a PRS attacker from using expected measurements in a PRS attack in which the PRS attacker attempts to generate false PRS transmissions.

[0205]

[0216] As will be appreciated, a further technical advantage of method 1200 is that the network node may use the expected measurements to authenticate actual PRS measurements that the network node takes during a positioning session, while also facilitating the identification of PRS measurements that may be tampered with through a PRS attack.

[0206]

[0217] In the above detailed description, it can be seen that in each example, various features are grouped together. This manner of disclosure should not be understood as an intention that the exemplary clauses have more features than are expressly stated in each clause. Rather, various aspects of the disclosure may include fewer features than all features of each disclosed exemplary clause. Thus, the following clauses should be considered to be incorporated in the description, and each clause may stand alone as a separate example. Although each dependent clause may refer to a specific combination with one of the other clauses in the clause, the aspect(s) of the dependent clause are not limited to that specific combination. It will be understood that other exemplary clauses may also include combinations of the aspect(s) of the dependent clause with the subject matter of any other dependent clause or independent clause, or any combination of features with other dependent clauses and independent clauses. Various aspects disclosed herein expressly include these combinations, unless it is expressly expressed or can be easily inferred that a particular combination is not intended (e.g., inconsistent aspects, such as defining an element as both an electrical insulator and an electrical conductor). It is further contemplated that aspects of a clause may be included in any other independent clause, even if the clause is not directly dependent on the independent clause.

[0207]

[0218] The following numbered clauses describe example implementations.

[0208]

[0219] Clause 1. A method of wireless communications implemented by a network node, comprising: receiving a first set of one or more hash values, the first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs); measuring the one or more PRS resources to obtain one or more actual measurement values; and determining whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​based on the application of the one or more hash operations to the one or more actual measurement values.

[0209]

[0220] Clause 2. The method of clause 1, further comprising receiving a configuration of one or more PRS resources of one or more TRPs to be measured during a positioning session.

[0210]

[0221] Clause 3. The method of clause 1 or 2, further comprising: determining that at least one actual measurement of the one or more actual measurements is outside a tolerance limit of at least one expected measurement of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values; and reporting error information regarding the at least one actual measurement of the one or more actual measurements.

[0211]

[0222] Clause 4. The method of clause 3, wherein the error information includes a bitmap including flags indicating which parameters of the at least one actual measurement are outside of acceptable limits.

[0212]

[0223] Clause 5. The method of clause 3 or 4, wherein the error information includes an indication of the degree to which at least one actual measurement value is outside acceptable limits.

[0213]

[0224] Clause 6. The first set of one or more hash values ​​may include one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more RSTD uncertainty values ​​associated with the one or more predicted RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA ... uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more A 6. The method of any of clauses 1 to 5, based on application of the method to one or more AoA uncertainty values, one or more expected Angle of Departure (AoD) measurements, one or more AoD uncertainty values ​​associated with one or more AoD measurements, one or more expected Arrival Zenith (ZoA) measurements, one or more expected ZoA uncertainty values ​​associated with one or more ZoA measurements, one or more expected Departure Zenith (ZoD) measurements, one or more expected ZoD uncertainty values ​​associated with one or more ZoD measurements, or any combination thereof.

[0214]

[0225] Clause 7. The method of any of clauses 1 to 6, wherein the second set of one or more hash values ​​is based on application of one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more actual Relative Signal Time Difference (RSTD) measurements, one or more actual Angle of Arrival (AoA) measurements, one or more actual Arrival Zenith (ZoA) measurements, one or more actual Departure Zenith (ZoD) measurements, or any combination thereof.

[0215]

[0226] Clause 8. The method of any of clauses 1 to 7, wherein the first set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more expected measurements, and the second set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more actual measurements.

[0216]

[0227] Clause 9. The method of clause 8, further comprising: receiving a first final hash value of size L, the first final hash value being based on all of the hash values ​​of the one or more first sets; and receiving a second final hash value of size L, the second final hash value being based on all of the hash values ​​of the second set of one or more hash values.

[0217]

[0228] Clause 10. The first set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of predicted measurements of the one or more predicted measurements, and the second set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of actual measurements of the one or more actual measurements, where Z=#layers * spectraleff * 8. The method of any of clauses 1 to 7, based on a transport block size calculation determined as #REs, where #layers is the number of control information layers, spectraleff is the spectral efficiency, and #REs is the number of resource elements.

[0218]

[0229] Clause 11. A method according to any one of clauses 1 to 10, wherein the first set of one or more hash values ​​is received using a Long Term Evolution Positioning Protocol (LPP).

[0219]

[0230] Clause 12. A method according to any one of clauses 1 to 10, wherein the network node is a base station, the one or more PRS resources are uplink PRS (UL-PRS) resources, and the second set of one or more hashed values ​​is received from a user equipment (UE).

[0220]

[0231] Clause 13. A method according to any of clauses 1 to 10, wherein the network node is a user equipment (UE), the one or more PRS resources are downlink PRS (DL-PRS) resources, and the first set of one or more hash values ​​is received from a base station.

[0221]

[0232] Clause 14. A method according to any of clauses 1 to 10, wherein the network node is a first user equipment (UE), the first set of one or more hash values ​​is received from a second UE, and the one or more PRS resources are sidelink PRS (SL-PRS) resources.

[0222]

[0233] Clause 15. The method of any of clauses 1 to 10, wherein the network node is a user equipment (UE) and the first set of one or more hash values ​​is received in radio resource control (RRC) information.

[0223]

[0234] Clause 16. The method of clause 15, wherein the RRC information is carried in a Physical Downlink Shared Channel (PDSCH), a Physical Sidelink Shared Channel (PSSCH), or a combination thereof.

[0224]

[0235] Clause 17. A method according to any one of clauses 1 to 10, wherein the first set of one or more hash values ​​is received in one or more Medium Access Control-Control Elements (MAC-CEs) carried in a Physical Download Control Channel (PDCCH).

[0225]

[0236] Clause 18. The method of any one of clauses 1 to 10, wherein the first set of one or more hash values ​​is received in one or more Medium Access Control - Control Elements (MAC-CEs) carried in a Physical Sidelink Control Channel (PSCCH), in sidelink control information carried in the PSCCH, or in a combination thereof.

[0226]

[0237] Clause 19. The method of any of clauses 1 to 18, wherein comparing the second set of hash values ​​with the first set of hash values ​​includes performing an assignment operation to assign one or more hash values ​​of the second set of hash values ​​to a set of hash bins, the set of hash bins being based on the first set of hash values, and reporting information regarding one or more hash values ​​of the second set of hash values ​​that are not assignable to permitted hash bins of the set of hash bins.

[0227]

[0238] Clause 20. A method of wireless communications implemented by a network node, comprising: receiving from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session; and using the first set of one or more hash values ​​for PRS attack detection.

[0228]

[0239] Clause 21. The method of clause 20, wherein using a first set of one or more hash values ​​for PRS attack detection comprises transmitting the first set of one or more hash values ​​to the UE; and receiving an indication from the UE that one or more actual measurements made by the UE are outside acceptable limits for one or more expected measurement values.

[0229]

[0240] Clause 22. The method of clause 21, wherein the indication from the UE includes a bitmap containing flags indicating which parameters of the one or more actual measurements are outside of acceptable limits.

[0230]

[0241] Clause 23. A method according to any of clauses 21 to 22, wherein the indication from the UE includes an indication of the extent to which one or more actual measurements are outside the acceptable limits.

[0231]

[0242] Clause 24. The method of any of clauses 21 to 23, further comprising reporting to the location server error information relating to one or more actual measurements made by the UE that are outside the tolerance limits of the one or more expected measurements.

[0232]

[0243] Clause 25. The method of any of clauses 20 to 24, wherein using the first set of one or more hash values ​​for PRS attack detection comprises receiving a second set of one or more hash values ​​corresponding to one or more actual measurement values ​​taken by the UE of one or more PRS resources; and determining whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​with the first set of one or more hash values ​​based on application of one or more hash operations to the one or more actual measurement values.

[0233]

[0244] Clause 26. The method of clause 25, wherein the second set of one or more hash values ​​is based on applying one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more predicted Relative Signal Time Difference (RSTD) measurements, one or more predicted Angle of Arrival (AoA) measurements, or a combination thereof.

[0234]

[0245] Clause 27. The method of any of clauses 20 to 26, wherein the first set of one or more hash values ​​is based on application of one or more hash operations to one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more predicted PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more predicted RSTD uncertainty values ​​associated with the one or more RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with the one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with the one or more ZoD measurements, or any combination thereof.

[0235]

[0246] Clause 28. A network node comprising: a memory; at least one transceiver; and at least one processor communicatively coupled to the memory and the at least one transceiver, wherein the at least one processor is configured to: receive via the at least one transceiver a first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs); measure the one or more PRS resources to obtain one or more actual measurement values; and determine whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​based on application of the one or more hash operations to the one or more actual measurement values.

[0236]

[0247] Clause 29. The network node of clause 28, wherein the at least one processor is further configured to receive, via the at least one transceiver, a configuration of one or more PRS resources of one or more TRPs to be measured during the positioning session.

[0237]

[0248] Clause 30. The network node of any of clauses 28 to 29, wherein the at least one processor is further configured to: determine, based on a comparison of the second set of one or more hash values ​​with the first set of one or more hash values, that at least one actual measurement value of the one or more actual measurements is outside a tolerance limit of at least one expected measurement value of the one or more expected measurement values; and report, via the at least one transceiver, error information regarding the at least one actual measurement value of the one or more actual measurements.

[0238]

[0249] Clause 31. The network node of clause 30, wherein the error information comprises a bitmap including flags indicating which parameters of the at least one actual measurement are outside of acceptable limits.

[0239]

[0250] Clause 32. A network node according to clause 30 or 31, wherein the error information includes an indication of the extent to which at least one actual measurement value is outside acceptable limits.

[0240]

[0251] Clause 33. The first set of one or more hash values ​​may include one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more RSTD uncertainty values ​​associated with the one or more predicted RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA ... uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values 33. A network node as described in any of clauses 28 to 32 based on application of an AoA uncertainty value of one or more predicted Angle of Departure (AoD) measurements, one or more AoD uncertainty values ​​associated with one or more AoD measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with one or more ZoD measurements, or any combination thereof.

[0241]

[0252] Clause 34. A network node as described in any of clauses 28 to 33, wherein the second set of one or more hash values ​​is based on application of one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more actual Relative Signal Time Difference (RSTD) measurements, one or more actual Angle of Arrival (AoA) measurements, one or more actual Arrival Zenith (ZoA) measurements, one or more actual Departure Zenith (ZoD) measurements, or any combination thereof.

[0242]

[0253] Clause 35. A network node as described in any of clauses 28 to 34, wherein the first set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more expected measurement values, and the second set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more actual measurement values.

[0243]

[0254] Clause 36. The network node of Clause 35, wherein the at least one processor is further configured to receive, via the at least one transceiver, a first final hash value of size L, the first final hash value being based on all of the hash values ​​of the first set of one or more hash values, and to receive, via the at least one transceiver, a second final hash value of size L, the second final hash value being based on all of the hash values ​​of the second set of one or more hash values.

[0244]

[0255] Clause 37. The first set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of predicted measurements of the one or more predicted measurements, and the second set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of actual measurements of the one or more actual measurements, where Z=#layers * spectraleff * 35. A network node as described in any of clauses 28 to 34, based on a transport block size calculation determined as #REs, where #layers is the number of control information layers, spectraleff is the spectral efficiency and #REs is the number of resource elements.

[0245]

[0256] Clause 38. A network node according to any of clauses 28 to 37, wherein the first set of one or more hash values ​​is received using a Long Term Evolution Positioning Protocol (LPP).

[0246]

[0257] Clause 39. A network node according to any of clauses 28 to 36, wherein the network node is a base station, the one or more PRS resources are uplink PRS (UL-PRS) resources, and the second set of one or more hashed values ​​is received from a user equipment (UE).

[0247]

[0258] Clause 40. A network node according to any of clauses 28 to 36, wherein the network node is a user equipment (UE), the one or more PRS resources are downlink PRS (DL-PRS) resources, and the first set of one or more hashed values ​​is received from a base station.

[0248]

[0259] Clause 41. A network node as described in any of clauses 28 to 38, wherein the network node is a first user equipment (UE), a first set of one or more hash values ​​is received from a second UE, and the one or more PRS resources are sidelink PRS (SL-PRS) resources.

[0249]

[0260] Clause 42. A network node according to any of clauses 28 to 36, wherein the network node is a user equipment (UE) and the first set of one or more hash values ​​is received in radio resource control (RRC) information.

[0250]

[0261] Clause 43. The network node according to clause 42, wherein the RRC information is carried in a Physical Downlink Shared Channel (PDSCH), a Physical Sidelink Shared Channel (PSSCH), or a combination thereof.

[0251]

[0262] Clause 44. A network node according to any of clauses 28 to 36, wherein the first set of one or more hash values ​​is received in one or more Medium Access Control-Control Elements (MAC-CEs) carried in a Physical Download Control Channel (PDCCH).

[0252]

[0263] Clause 45. A network node according to any of clauses 28 to 46, wherein the first set of one or more hash values ​​is received in one or more Medium Access Control - Control Elements (MAC-CEs) carried in a Physical Sidelink Control Channel (PSCCH), in sidelink control information carried in the PSCCH, or in a combination thereof.

[0253]

[0264] Clause 46. A network node as described in any of clauses 28 to 45, comprising at least one processor configured to determine whether one or more actual measurements of one or more PRS resources are within tolerance limits of one or more expected measurements, perform an allocation operation to assign one or more hash values ​​of a second set of hash values ​​to a set of hash bins based on the first set of hash values, and report via the at least one transceiver information regarding one or more hash values ​​of the second set of hash values ​​that are not assignable to permitted hash bins of the set of hash bins.

[0254]

[0265] Clause 47. A network node comprising: a memory; at least one transceiver; and at least one processor communicatively coupled to the memory and the at least one transceiver, wherein the at least one processor is configured to receive from a location server via the at least one transceiver a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session, and to use the first set of one or more hash values ​​for PRS attack detection.

[0255]

[0266] Clause 48. A network node as described in Clause 47, comprising at least one processor configured to use a first set of one or more hash values ​​for PRS attack detection, the at least one processor configured to transmit, via the at least one transceiver, the first set of one or more hash values ​​to a UE, and to receive, via the at least one transceiver, an indication from the UE that one or more actual measurements made by the UE are outside acceptable limits of one or more expected measurement values.

[0256]

[0267] Clause 49. The network node according to clause 48, wherein the instruction from the UE comprises a bitmap comprising flags indicating which parameters of the one or more actual measurements are outside the acceptable limits.

[0257]

[0268] Clause 50. A network node as described in clause 48 or 49, wherein the indication from the UE includes an indication of the extent to which one or more actual measurements are outside the acceptable limits.

[0258]

[0269] Clause 51. A network node according to any of clauses 48 to 50, wherein the at least one processor is further configured to report, via the at least one transceiver, to the location server error information relating to one or more actual measurements made by the UE that are outside acceptable limits of the one or more expected measurements.

[0259]

[0270] Clause 52. A network node as described in any of clauses 47 to 51, comprising at least one processor configured to: receive, via the at least one transceiver, a second set of one or more hash values ​​corresponding to one or more actual measurement values ​​taken by the UE of one or more PRS resources; and determine whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​with the first set of one or more hash values ​​based on application of one or more hash operations to the one or more actual measurement values.

[0260]

[0271] Clause 53. The network node of clause 52, wherein the second set of one or more hash values ​​is based on applying one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more predicted Relative Signal Time Difference (RSTD) measurements, one or more predicted Angle of Arrival (AoA) measurements, or a combination thereof.

[0261]

[0272] 54. A network node as described in any of clauses 47 to 53, wherein the first set of one or more hash values ​​is based on application of one or more hash operations to one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more predicted PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more predicted RSTD uncertainty values ​​associated with the one or more RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with the one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with the one or more ZoD measurements, or any combination thereof.

[0262]

[0273] Clause 55. A network node comprising: means for receiving a first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurement values ​​of one or more Positioning Reference Signal (PRS) resources of one or more Transmission / Reception Points (TRPs); means for measuring the one or more PRS resources to obtain one or more actual measurement values; and means for determining whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​with the first set of one or more hash values ​​based on the application of the one or more hash operations to the one or more actual measurement values.

[0263]

[0274] Clause 56. A network node as claimed in clause 55, further comprising means for receiving a configuration of one or more PRS resources of one or more TRPs to be measured during a positioning session.

[0264]

[0275] Clause 57. The network node of clause 55 or 56, further comprising: means for determining that at least one actual measurement of the one or more actual measurements is outside a tolerance limit of at least one expected measurement of the one or more expected measurements based on a comparison of the second set of one or more hash values ​​with the first set of one or more hash values; and means for reporting error information regarding the at least one actual measurement of the one or more actual measurements.

[0265]

[0276] Clause 58. The network node of clause 57, wherein the error information includes a bitmap including flags indicating which parameters of the at least one actual measurement are outside of acceptable limits.

[0266]

[0277] Clause 59. A network node as described in clause 57 or 58, wherein the error information includes an indication of the extent to which at least one actual measurement value is outside acceptable limits.

[0267]

[0278] Clause 60. The first set of one or more hash values ​​may include one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more RSTD uncertainty values ​​associated with the one or more predicted RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA ... uncertainty values, one or more predicted AoA uncertainty values ​​associated with the one or more AoA uncertainty values 59. A network node as described in any of clauses 55 to 59 based on application of an AoA uncertainty value to one or more predicted Angle of Departure (AoD) measurements, one or more AoD uncertainty values ​​associated with one or more AoD measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with one or more ZoD measurements, or any combination thereof.

[0268]

[0279] Clause 61. A network node as described in any of clauses 55 to 60, wherein the second set of one or more hash values ​​is based on application of one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more actual Relative Signal Time Difference (RSTD) measurements, one or more actual Angle of Arrival (AoA) measurements, one or more actual Arrival Zenith (ZoA) measurements, one or more actual Departure Zenith (ZoD) measurements, or any combination thereof.

[0269]

[0280] Clause 62. A network node according to any of clauses 55 to 61, wherein the first set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more expected measurement values, and the second set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more actual measurement values.

[0270]

[0281] Clause 63. The network node of Clause 62, further comprising: means for receiving a first final hash value of size L, the first final hash value being based on all hash values ​​of the one or more first sets; and means for receiving a second final hash value of size L, the second final hash value being based on all hash values ​​of the second set of one or more hash values.

[0271]

[0282] Clause 64. The first set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of predicted measurements of the one or more predicted measurements, and the second set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of actual measurements of the one or more actual measurements, where Z is Z=#layers * spectraleff * 62. A network node as described in any of clauses 55 to 61, based on a transport block size calculation determined as #REs, where #layers is the number of control information layers, spectraleff is the spectral efficiency, and #REs is the number of resource elements.

[0272]

[0283] Clause 65. A network node according to any of clauses 55 to 64, wherein the first set of one or more hash values ​​is received using a Long Term Evolution Positioning Protocol (LPP).

[0273]

[0284] Clause 66. A network node according to any of clauses 55 to 65, wherein the network node is a base station, the one or more PRS resources are uplink PRS (UL-PRS) resources, and the second set of one or more hashed values ​​is received from a user equipment (UE).

[0274]

[0285] Clause 67. A network node according to any of clauses 55 to 64, wherein the network node is a user equipment (UE), the one or more PRS resources are downlink PRS (DL-PRS) resources, and the first set of one or more hash values ​​is received from a base station.

[0275]

[0286] Clause 68. A network node as described in any of Clauses 55 to 64, wherein the network node is a first user equipment (UE), the first set of one or more hash values ​​is received from a second UE, and the one or more PRS resources are sidelink PRS (SL-PRS) resources.

[0276]

[0287] Clause 69. A network node according to any of clauses 55 to 64, wherein the network node is a user equipment (UE) and the first set of one or more hash values ​​is received in radio resource control (RRC) information.

[0277]

[0288] Clause 70. The network node of clause 69, wherein the RRC information is carried in a Physical Downlink Shared Channel (PDSCH), a Physical Sidelink Shared Channel (PSSCH), or a combination thereof.

[0278]

[0289] Clause 71. A network node according to any of clauses 55 to 64, wherein the first set of one or more hash values ​​is received in one or more Medium Access Control-Control Elements (MAC-CEs) carried in a Physical Download Control Channel (PDCCH).

[0279]

[0290] Clause 72. A network node according to any of clauses 55 to 64, wherein the first set of one or more hash values ​​is received in one or more Medium Access Control - Control Elements (MAC-CEs) carried in a Physical Sidelink Control Channel (PSCCH), in sidelink control information carried in the PSCCH, or in a combination thereof.

[0280]

[0291] Clause 73. A network node according to any of clauses 55 to 72, wherein the means for determining whether one or more actual measurements of one or more PRS resources are within tolerance limits of one or more expected measurements comprises: means for performing an allocation operation to assign one or more hash values ​​of a second set of hash values ​​to a set of hash bins, the set of hash values ​​being based on the first set of hash values; and means for reporting information regarding one or more hash values ​​of the second set of hash values ​​that are not assignable to permitted hash bins of the set of hash bins.

[0281]

[0292] Clause 74. A network node comprising: means for receiving from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurement values ​​corresponding to predicted measurement values ​​of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session; and means for using the first set of one or more hash values ​​for PRS attack detection.

[0282]

[0293] Clause 75. A network node as described in clause 74, wherein the means for using the first set of one or more hash values ​​for PRS attack detection comprises: means for transmitting the first set of one or more hash values ​​to the UE; and means for receiving an indication from the UE that one or more actual measurements made by the UE are outside acceptable limits of one or more expected measurement values.

[0283]

[0294] Clause 76. The network node of clause 75, wherein the instruction from the UE includes a bitmap including flags indicating which parameters of the one or more actual measurements are outside of acceptable limits.

[0284]

[0295] Clause 77. A network node as described in clause 75 or 76, wherein the indication from the UE includes an indication of the extent to which one or more actual measurements are outside the acceptable limits.

[0285]

[0296] Clause 78. A network node according to any of clauses 75 to 77, further comprising means for reporting to the location server error information relating to one or more actual measurements made by the UE that are outside the tolerance limits of one or more expected measurements.

[0286]

[0297] Clause 79. The means for using a first set of one or more hash values ​​for PRS attack detection comprises: means for receiving a second set of one or more hash values ​​corresponding to one or more actual measurement values ​​taken by the UE of one or more PRS resources; and means for determining whether the one or more actual measurement values ​​of the one or more PRS resources are within tolerance limits of one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​with the first set of one or more hash values ​​based on application of one or more hash operations to the one or more actual measurement values, in a network node according to any of clauses 74 to 78.

[0287]

[0298] Clause 80. The network node of clause 79, wherein the second set of one or more hash values ​​is based on applying one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more predicted Relative Signal Time Difference (RSTD) measurements, one or more predicted Angle of Arrival (AoA) measurements, or a combination thereof.

[0288]

[0299] 81. The network node of any of clauses 74 to 80, wherein the first set of one or more hash values ​​is based on application of one or more hash operations to one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more predicted PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more predicted RSTD uncertainty values ​​associated with the one or more RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with the one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with the one or more ZoD measurements, or any combination thereof.

[0289]

[0300] Clause 82. A non-transitory computer-readable medium storing computer-executable instructions that, when executed by a network node, are configured to cause the network node to receive a first set of one or more hash values ​​based on one or more hash operations applied to one or more expected measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs), measure the one or more PRS resources to obtain one or more actual measurements, and determine whether the one or more actual measurements of the one or more PRS resources are within tolerance limits of the one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, the second set of one or more hash values ​​being based on application of the one or more hash operations to the one or more actual measurement values.

[0290]

[0301] Clause 83. The non-transitory computer-readable medium of clause 82, further comprising computer-executable instructions that, when executed by a network node, cause the network node to receive a configuration of one or more PRS resources of one or more TRPs to be measured during a positioning session.

[0291]

[0302] Clause 84. The non-transitory computer readable medium of clause 82 or 83, further comprising computer executable instructions that, when executed by a network node, cause the network node to determine that at least one actual measurement of the one or more actual measurements is outside of a tolerance limit of at least one expected measurement of the one or more expected measurements based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values, and to report error information regarding the at least one actual measurement of the one or more actual measurements.

[0292]

[0303] Clause 85. The non-transitory computer-readable medium of clause 84, wherein the error information includes a bitmap including flags indicating which parameters of the at least one actual measurement are outside of acceptable limits.

[0293]

[0304] Clause 86. The non-transitory computer-readable medium of clause 84 or 85, wherein the error information includes an indication of the degree to which at least one actual measurement value is outside of acceptable limits.

[0294]

[0305] Clause 87. The first set of one or more hash values ​​may include one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more RSTD uncertainty values ​​associated with the one or more predicted RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more AoA uncertainty values ​​associated with the one or more AoA measurements, and one or more predicted AoA uncertainty values ​​associated with the one or more AoA measurements. 87. The non-transitory computer-readable medium of any of clauses 82 to 86, based on application to an oA uncertainty value, one or more predicted Angle of Departure (AoD) measurements, one or more AoD uncertainty values ​​associated with one or more AoD measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with one or more ZoD measurements, or any combination thereof.

[0295]

[0306] Clause 88. A non-transitory computer-readable medium according to any of clauses 82 to 87, wherein the second set of one or more hash values ​​is based on application of one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more actual Relative Signal Time Difference (RSTD) measurements, one or more actual Angle of Arrival (AoA) measurements, one or more actual Arrival Zenith (ZoA) measurements, one or more actual Departure Zenith (ZoD) measurements, or any combination thereof.

[0296]

[0307] Clause 89. The non-transitory computer-readable medium of any of clauses 82 to 88, wherein the first set of one or more hash values ​​includes a hash value of size L associated with each of the one or more expected measurements, and the second set of one or more hash values ​​includes a hash value of size L associated with each of the one or more actual measurements.

[0297]

[0308] Clause 90. The non-transitory computer-readable medium of Clause 89, further comprising computer-executable instructions that, when executed by a network node, cause the network node to receive a first final hash value of size L, the first final hash value based on all of the hash values ​​in a first set of one or more hash values, and receive a second final hash value of size L, the second final hash value based on all of the hash values ​​in a second set of one or more hash values.

[0298]

[0309] Clause 91. The first set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of predicted measurements of the one or more predicted measurements, and the second set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of actual measurements of the one or more actual measurements, where Z is Z=#layers * spectraleff * 90. The non-transitory computer-readable medium of any of clauses 82 to 89, based on a transport block size calculation determined as #REs, where #layers is the number of control information layers, spectraleff is the spectral efficiency, and #REs is the number of resource elements.

[0299]

[0310] Clause 92. The non-transitory computer-readable medium of any of clauses 82 to 91, wherein the first set of one or more hash values ​​is received using a Long Term Evolution Positioning Protocol (LPP).

[0300]

[0311] Clause 93. A non-transitory computer-readable medium according to any of clauses 82 to 91, wherein the network node is a base station, the one or more PRS resources are uplink PRS (UL-PRS) resources, and the second set of one or more hashed values ​​is received from a user equipment (UE).

[0301]

[0312] Clause 94. A non-transitory computer-readable medium according to any of clauses 82 to 91, wherein the network node is a user equipment (UE), the one or more PRS resources are downlink PRS (DL-PRS) resources, and the first set of one or more hashed values ​​is received from a base station.

[0302]

[0313] Clause 95. A non-transitory computer-readable medium according to any of clauses 82 to 91, wherein the network node is a first user equipment (UE), a first set of one or more hash values ​​is received from a second UE, and the one or more PRS resources are sidelink PRS (SL-PRS) resources.

[0303]

[0314] Clause 96. A non-transitory computer-readable medium according to any of clauses 82 to 91, wherein the network node is a user equipment (UE) and the first set of one or more hash values ​​is received in radio resource control (RRC) information.

[0304]

[0315] Clause 97. The non-transitory computer-readable medium of clause 96, wherein the RRC information is carried in a physical downlink shared channel (PDSCH), a physical sidelink shared channel (PSSCH), or a combination thereof.

[0305]

[0316] Clause 98. A non-transitory computer-readable medium according to any of clauses 82 to 91, wherein the first set of one or more hash values ​​is received in one or more medium access control-control elements (MAC-CEs) carried in a physical download control channel (PDCCH).

[0306]

[0317] Clause 99. The non-transitory computer-readable medium of any of clauses 82 to 91, wherein the first set of one or more hash values ​​is received in one or more medium access control-control elements (MAC-CEs) carried in a physical sidelink control channel (PSCCH), in sidelink control information carried in the PSCCH, or in a combination thereof.

[0307]

[0318] Clause 100. A non-transitory computer readable medium according to any of clauses 82 to 99 comprising computer executable instructions which, when executed by a network node, cause the network node to determine whether one or more actual measurements of one or more PRS resources are within tolerance limits of one or more expected measurements, the computer executable instructions, when executed by the network node, cause the network node to perform an allocation operation to assign one or more hash values ​​of a second set of hash values ​​to a set of hash bins, the set of hash values ​​being based on the first set of hash values, and to report information regarding one or more hash values ​​of the second set of hash values ​​that are not assignable to permitted hash bins of the set of hash bins.

[0308]

[0319] Clause 101. A non-transitory computer-readable medium storing computer-executable instructions that, when executed by a network node, cause the network node to receive from a location server a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements corresponding to predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs) measured by a user equipment (UE) during a positioning session, and to use the first set of one or more hash values ​​for PRS attack detection.

[0309]

[0320] Clause 102. A non-transitory computer readable medium as described in clause 101, wherein the computer executable instructions, when executed by a network node, cause the network node to use a first set of one or more hash values ​​for PRS attack detection, when executed by the network node, cause the network node to transmit the first set of one or more hash values ​​to a UE and receive an indication from the UE that one or more actual measurements made by the UE are outside of acceptable limits for one or more expected measurements.

[0310]

[0321] Clause 103. The non-transitory computer-readable medium of clause 102, wherein the instructions from the UE include a bitmap including flags indicating which parameters of the one or more actual measurements are outside of acceptable limits.

[0311]

[0322] Clause 104. The non-transitory computer-readable medium of clause 102 or 103, wherein the indication from the UE includes an indication of the extent to which one or more actual measurements are outside of acceptable limits.

[0312]

[0323] Clause 105. A non-transitory computer-readable medium according to any of clauses 102 to 104, further comprising computer-executable instructions which, when executed by the network node, cause the network node to report to a location server error information relating to one or more actual measurements made by the UE that are outside of acceptable limits for one or more expected measurements.

[0313]

[0324] Clause 106. A non-transitory computer readable medium according to any of clauses 101 to 105, comprising computer executable instructions which, when executed by a network node, cause the network node to use a first set of one or more hash values ​​for PRS attack detection, the computer executable instructions, when executed by the network node, cause the network node to receive a second set of one or more hash values ​​corresponding to one or more actual measurements taken by the UE of one or more PRS resources, and determine whether the one or more actual measurements of the one or more PRS resources are within tolerance limits of one or more expected measurement values ​​based on a comparison of the second set of one or more hash values ​​to the first set of one or more hash values ​​based on application of one or more hash operations to the one or more actual measurement values.

[0314]

[0325] Clause 107. The non-transitory computer-readable medium of clause 106, wherein the second set of one or more hash values ​​is based on applying one or more hash operations to one or more actual Reference Signal Received Power (RSRP) measurements, one or more predicted Relative Signal Time Difference (RSTD) measurements, one or more predicted Angle of Arrival (AoA) measurements, or a combination thereof.

[0315]

[0326] Clause 108. The non-transitory computer-readable medium of any of clauses 101 to 107, wherein the first set of one or more hash values ​​is based on application of one or more hash operations to one or more predicted PRS Reference Signal Received Power (PRS-RSRP) measurements, one or more predicted PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements, one or more predicted Reference Signal Time Difference (RSTD) measurements, one or more predicted RSTD uncertainty values ​​associated with the one or more RSTD measurements, one or more predicted Angle of Arrival (AoA) measurements, one or more predicted AoA uncertainty values ​​associated with the one or more AoA measurements, one or more predicted Arrival Zenith (ZoA) measurements, one or more predicted ZoA uncertainty values ​​associated with the one or more ZoA measurements, one or more predicted Departure Zenith (ZoD) measurements, one or more predicted ZoD uncertainty values ​​associated with the one or more ZoD measurements, or any combination thereof.

[0316]

[0327] Those skilled in the art will appreciate that information and signals may be represented using any of a variety of different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0317]

[0328] Moreover, those skilled in the art will appreciate that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Those skilled in the art may realize the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0318]

[0329] The various example logic blocks, modules, and circuits described in connection with the aspects disclosed herein may be implemented or performed using a general purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0319]

[0330] The methods, sequences, and / or algorithms described in connection with the aspects disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in a random access memory (RAM), a flash memory, a read-only memory (ROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal (e.g., UE). Alternatively, the processor and the storage medium may reside as discrete components in a user terminal.

[0320]

[0331] In one or more exemplary aspects, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored on or transmitted via a computer-readable medium as one or more instructions or code. Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A storage medium may be any available medium that can be accessed by a computer. By way of example, and not limitation, such computer-readable media may comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included within the definition of media. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc, where disks typically reproduce data magnetically and discs reproduce data optically using lasers. Combinations of the above are also intended to be included within the scope of computer-readable media.

[0321]

[0332] Although the above disclosure illustrates exemplary aspects of the disclosure, it should be noted that various changes and modifications may be made herein without departing from the scope of the disclosure as defined by the appended claims. The functions, steps, and / or actions of the method claims in accordance with the aspects of the disclosure described herein need not be performed in any particular order. Further, although elements of the disclosure may be described or claimed in the singular, the plural is contemplated unless limitation to the singular is explicitly stated.

Claims

1. 1. A method of wireless communication implemented by a network node, comprising: receiving a first set of one or more hash values, the first set of one or more hash values ​​being based on one or more hash operations applied to one or more predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs); measuring the one or more PRS resources to obtain one or more actual measurements; detecting whether there is a PRS attack based on a comparison of a second set of one or more hash values ​​with the first set of one or more hash values, the second set being based on application of the one or more hash operations to the one or more actual measurements; A method comprising:

2. The method of claim 1, wherein detecting whether there is a PRS attack is based on whether the one or more actual measurements of the one or more PRS resources are within acceptable limits of the one or more expected measurements based on the comparison of the second set of one or more hash values ​​with the first set of one or more hash values.

3. receiving a configuration of the one or more PRS resources of the one or more TRPs to be measured during a positioning session; The method of claim 1 further comprising:

4. determining, based on the comparison of the second set of one or more hash values ​​to the first set of one or more hash values, that at least one actual measurement of the one or more actual measurements is outside the tolerance limits of at least one predicted measurement of the one or more predicted measurements; reporting error information regarding the at least one actual measurement of the one or more actual measurements; and preferably further comprises the error information comprises a bitmap containing flags indicating which parameters of the at least one actual measurement are outside the tolerance limits; or The method of claim 2 , wherein the error information includes an indication of the degree to which the at least one actual measurement value is outside the tolerance limits.

5. The first set of one or more hash values ​​is a subset of the one or more hash operations: one or more expected PRS reference signal received power (PRS-RSRP) measurements; one or more PRS-RSRP uncertainty values ​​associated with the one or more predicted PRS-RSRP measurements; one or more expected reference signal time difference (RSTD) measurements; one or more RSTD uncertainty values ​​associated with the predicted one or more RSTD measurements; one or more expected angle of arrival (AoA) measurements; one or more AoA uncertainty values ​​associated with the one or more AoA measurements; one or more expected angle of departure (AoD) measurements; one or more AoD uncertainty values ​​associated with the one or more AoD measurements; one or more predicted zenith arrival (ZoA) measurements; one or more ZoA forecast uncertainty values ​​associated with the one or more ZoA measurements; one or more predicted departure zenith (ZoD) measurements; one or more predicted ZoD uncertainty values ​​associated with said one or more ZoD measurements; or The method of claim 1 based on application to any combination thereof.

6. The second set of one or more hash values ​​is a subset of the one or more hash operations. one or more actual reference signal received power (RSRP) measurements; one or more actual relative signal time difference (RSTD) measurements; one or more actual angle of arrival (AoA) measurements; one or more actual zenith arrival (ZoA) measurements; one or more actual departure zenith (ZoD) measurements, or The method of claim 1 based on application to any combination thereof.

7. the first set of one or more hash values ​​includes a hash value of size L respectively associated with each of the one or more expected measurements; The second set of one or more hash values ​​comprises a hash value of size L respectively associated with each of the one or more actual measurements, preferably receiving a first final hash value of size L, the first final hash value being based on all hash values ​​of the first set of one or more hash values; receiving a second final hash value of size L, the second final hash value being based on all hash values ​​of the second set of one or more hash values; The method of claim 1 further comprising:

8. the first set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of predicted measurements of the one or more predicted measurements; the second set of one or more hash values ​​includes hash values ​​of size Z collectively associated with a plurality of actual measurements of the one or more actual measurements; Z is Z=#layers * spectral eff * #REs Based on the transport block size calculation, During the ceremony, #layers is the number of control information layers, spectral eff is the spectral efficiency, #REs is the number of resource elements, The method of claim 1.

9. the network node is a base station; the one or more PRS resources are uplink PRS (UL-PRS) resources; the second set of one or more hash values ​​is received from a user equipment (UE); or the network node is a user equipment (UE); the one or more PRS resources are downlink PRS (DL-PRS) resources; the first set of one or more hash values ​​is received from a base station; or the network node is a first user equipment (UE); the first set of one or more hash values ​​is received from a second UE; the one or more PRS resources are sidelink PRS (SL-PRS) resources; The method of claim 1.

10. the network node is a user equipment (UE); The first set of one or more hash values ​​is received in Radio Resource Control (RRC) information, preferably The RRC information is Physical Downlink Shared Channel (PDSCH); a physical sidelink shared channel (PSSCH), or The combination of these The method of claim 1 , wherein the method is delivered in a

11. the first set of one or more hash values ​​is received in one or more Medium Access Control - Control Elements (MAC-CEs) carried in a Physical Download Control Channel (PDCCH); The method of claim 1.

12. The first set of one or more hash values ​​comprises: one or more Medium Access Control - Control Elements (MAC-CEs) carried in a Physical Sidelink Control Channel (PSCCH); Sidelink control information carried on the PSCCH; or combinations of these The method of claim 1 , wherein the signal is received at

13. Determining whether the one or more actual measurements of the one or more PRS resources are within tolerance limits of the one or more expected measurements includes: performing an assignment operation that assigns one or more hash values ​​of the second set of hash values ​​to a set of hash bins, the set of hash bins being based on the first set of hash values; reporting information about one or more hash values ​​of the second set of hash values ​​that are not assignable to a permitted hash bin of the set of hash bins; The method of claim 2 , comprising:

14. a network node, Memory and at least one transceiver; at least one processor communicatively coupled to the memory and the at least one transceiver, wherein the at least one processor: receiving, via the at least one transceiver, a first set of one or more hash values ​​based on one or more hash operations applied to one or more predicted measurements of one or more positioning reference signal (PRS) resources of one or more transmission / reception points (TRPs); measuring the one or more PRS resources to obtain one or more actual measurements; detecting whether there is a PRS attack based on a comparison of a second set of one or more hash values ​​with the first set of one or more hash values, the second set of one or more hash values ​​being based on application of the one or more hash operations to the one or more actual measurements; A network node that is configured to:

15. The network node of claim 14, wherein the at least one processor is further configured to perform a method according to any one of claims 2 to 13.