Method and system for providing home network routing information for a remote user equipment (UE) following authentication failure during establishment of UE-to-network (U2N) relay communication

The method addresses the ambiguity in obtaining HNRI for U2N relay communication by providing HNRI to the relay UE's authentication node, facilitating secure connection resynchronization and effective communication between UEs.

JP2025529652APending Publication Date: 2025-09-09QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025504834
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-08-01
Filing Date
2023-08-02
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

Existing telecommunications standards do not specify how a first authentication node in a relay UE's home network obtains home network routing information (HNRI) for a second UE's authentication node during a synchronization failure in UE-to-network (U2N) relay communication, leading to ambiguity in resynchronization processes.

Method used

Methods and systems are disclosed to provide HNRI for the remote UE's authentication node to the relay UE's authentication node, either by the remote UE, relay UE, or from storage by the relay UE's authentication node, enabling interaction for an updated authentication challenge.

Benefits of technology

Facilitates effective resynchronization and secure connection establishment between UEs by providing clear mechanisms for obtaining HNRI, ensuring secure communication pathways in U2N relay scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025529652000001_ABST
    Figure 2025529652000001_ABST
Patent Text Reader

Abstract

Methods and systems are disclosed for providing home network routing information (HNRI) of a remote user equipment (UE) following an authentication failure, for example, during establishment of UE-to-network (U2N) relay communications. In some aspects, a first UE can detect an authentication failure during establishment of a secure connection with a second UE and, in response to detecting the authentication failure, notify the second UE of the authentication failure. Additionally, the HNRI of a first authenticating node in the home network of the first UE is provided to a second authenticating node in the home network of the second UE either by the first UE, by the second UE, or from being stored by the second authenticating node from a previous interaction with the first UE.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS)

[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 370,639, filed August 5, 2022, entitled "METHODS AND SYSTEMS FOR PROVIDING HOME NETWORK ROUTING INFORMATION OF REMOTE USER EQUIPMENT (UE) FOLLOWING AUTHENTICATION FAILURE DURING ESTABLISHMENT OF UE-TO-NETWORK (U2N) RELAY COMMUNICATION," which application is assigned to the assignee of the present application and is expressly incorporated by reference in its entirety into this specification.

[0002] introduction

[0002] Aspects of the present disclosure relate generally to wireless communications, and more specifically to communications between a network node in a home network of a remote user equipment (UE) and a network node in a home network of a UE-to-network (U2N) relay UE.

[0003] Wireless communication systems have evolved through various generations, including first-generation analog wireless telephone service (1G), second-generation (2G) digital wireless telephone service (including interim 2.5G and 2.75G networks), third-generation (3G) high-speed data, Internet-enabled wireless service, and fourth-generation (4G) service (e.g., Long Term Evolution (LTE) or WiMax). Currently, many different types of wireless communication systems are in use, including cellular systems and personal communications service (PCS) systems. Examples of known cellular systems include the cellular analog advanced mobile phone system (AMPS) and digital cellular systems based on code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), Global System for Mobile communications (GSM), etc.

[0004]

[0004] The fifth-generation (5G) wireless standard, called New Radio (NR), enables higher data rates, more connections, and better coverage, among other improvements. According to the Next Generation Mobile Network Alliance, the 5G standard is designed to provide higher data rates, more accurate positioning (e.g., based on reference signals for positioning (RS-P), such as downlink, uplink, or sidelink positioning reference signals (PRS)), and other technical enhancements compared to previous standards. These enhancements, as well as the use of higher frequency bands, advances in PRS processes and technology, and dense deployments for 5G, enable highly accurate 5G-based positioning. Summary of the Invention

[0005]

[0005] The following presents a simplified summary of one or more aspects disclosed herein. As such, the following summary should not be considered an extensive overview of all contemplated aspects, nor should it be considered as identifying key or critical elements of all contemplated aspects or as delimiting the scope of any particular aspect. Thus, the sole purpose of the following summary is to present certain concepts of one or more aspects of the mechanisms disclosed herein in a simplified form prior to the detailed description presented below.

[0006]

[0006] In one aspect, a method for wireless communication in a first user equipment (UE) includes, in response to an authentication failure during establishment of a secure connection with the second UE, sending a notification of the authentication failure to the second UE, and providing the second UE with home network routing information (HNRI) for an authentication node in the home network of the first UE.

[0007]

[0007] In one aspect, a method for wireless communication in a first UE includes receiving, from a second UE, a notification of authentication failure during establishment of a secure connection between the second UE and the first UE; receiving, from the second UE, an HNRI for a first authentication node in a home network of the second UE; and transmitting the HNRI for the first authentication node in the home network of the second UE to a second authentication node in the home network of the first UE.

[0008]

[0008] In one aspect, a method for wireless communication in a network entity includes receiving a request from a first UE in a first home network of the network entity for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network, the request including a transaction identifier (TXI); determining an HNRI for the second home network based on the TXI; determining an authentication node in the second home network based on the HNRI for the second home network; and forwarding the request to the authentication node in the second home network.

[0009]

[0009] In one aspect, an apparatus for wireless communication in a first UE includes one or more memories and one or more processors coupled to the one or more memories, wherein the one or more processors are configured to: cause the first UE to, in response to an authentication failure during establishment of a secure connection with the second UE, send a notification of the authentication failure to the second UE and provide the second UE with an HNRI for an authentication node in the home network of the first UE.

[0010]

[0010] In one aspect, an apparatus for wireless communication in a first UE includes one or more memories and one or more processors coupled to the one or more memories, wherein the one or more processors are configured to: cause the first UE to receive, from a second UE, a notification of authentication failure during establishment of a secure connection between the second UE and the first UE; receive, from the second UE, an HNRI for a first authentication node in a home network of the second UE; and transmit the HNRI for the first authentication node in the home network of the second UE to a second authentication node in the home network of the first UE.

[0011]

[0011] In one aspect, an apparatus for wireless communication in a network entity includes one or more memories and one or more processors coupled to the one or more memories, wherein the one or more processors are configured to: cause the network entity to receive a request from a first UE in a first home network of the network entity for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network, the request including a TXI; determine an HNRI for the second home network based on the TXI; determine an authentication node in the second home network based on the HNRI for the second home network; and forward the request to the authentication node in the second home network.

[0012]

[0012] In one aspect, a method of wireless communication performed in a first UE includes detecting an authentication failure during establishment of a secure connection with a second UE, and in response to detecting the authentication failure, sending a notification of the authentication failure to the second UE and providing the second UE with an HNRI for an authentication node in the home network of the first UE.

[0013]

[0013] In one aspect, a method of wireless communication performed in a first UE includes receiving a notification of authentication failure from a second UE during establishment of a secure connection between the second UE and the first UE, determining an HNRI for an authentication node in a home network of the second UE, and transmitting the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0014]

[0014] In one aspect, a method of wireless communication includes, at a network entity, receiving a request from a first UE in a home network of the network entity for security material for a secure connection between the first UE and a second UE that is not in the home network of the first UE, the request including a TXI; determining an HNRI for the home network of the second UE based on the TXI; determining an authentication node in the home network of the second UE based on the HNRI; and forwarding the request to the authentication node in the home network of the second UE.

[0015]

[0015] In one aspect, the first UE includes a memory and at least one processor coupled to the memory, wherein the memory and the at least one processor are configured to detect an authentication failure during establishment of a secure connection with the second UE, and in response to detecting the authentication failure, send a notification of the authentication failure to the second UE and provide the second UE with an HNRI for an authentication node in the home network of the first UE.

[0016]

[0016] In one aspect, the first UE includes a memory and at least one processor coupled to the memory, wherein the memory and the at least one processor are configured to receive from the second UE a notification of authentication failure during establishment of a secure connection between the second UE and the first UE, determine an HNRI for an authentication node in a home network of the second UE, and transmit the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0017]

[0017] In one aspect, a network entity includes a memory and at least one processor coupled to the memory, wherein the memory and the at least one processor are configured to receive a request from a first UE in a home network of the network entity for security material for a secure connection between the first UE and a second UE that is not in the home network of the first UE, the request including a TXI, determine an HNRI for the home network of the second UE based on the TXI, determine an authentication node in the home network of the second UE based on the HNRI, and forward the request to the authentication node in the home network of the second UE.

[0018]

[0018] In one aspect, the first UE includes means for detecting an authentication failure during establishment of a secure connection with the second UE, and means for, in response to detecting the authentication failure, sending a notification of the authentication failure to the second UE and providing the second UE with an HNRI for an authentication node in the home network of the first UE.

[0019]

[0019] In one aspect, the first UE includes means for receiving a notification of authentication failure from the second UE during establishment of a secure connection between the second UE and the first UE, means for determining an HNRI for an authentication node in the home network of the second UE, and means for transmitting the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0020]

[0020] In one aspect, a network entity includes means for receiving, from a first UE in the network entity's home network, a request for security material for a secure connection between the first UE and a second UE that is not in the first UE's home network, the request including a TXI; means for determining an HNRI for the second UE's home network based on the TXI; means for determining an authentication node in the second UE's home network based on the HNRI; and means for forwarding the request to the authentication node in the second UE's home network.

[0021]

[0021] In one aspect, a non-transitory computer-readable medium storing at least one computer-executable instruction, when executed by a first UE, causes the first UE to detect an authentication failure during establishment of a secure connection with a second UE, and in response to detecting the authentication failure, causes the first UE to send a notification of the authentication failure to the second UE and provide the second UE with an HNRI for an authentication node in the home network of the first UE.

[0022]

[0022] In one aspect, a non-transitory computer-readable medium storing at least one computer-executable instruction, when executed by a first UE, causes the first UE to receive a notification of authentication failure from a second UE during establishment of a secure connection between the second UE and the first UE, determine an HNRI for an authentication node in the home network of the second UE, and transmit the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0023]

[0023] In one aspect, a non-transitory computer-readable medium storing at least one computer-executable instruction, when executed by a network entity, causes the network entity to receive a request from a first UE in the network entity's home network for security material for a secure connection between the first UE and a second UE that is not in the first UE's home network, the request including a TXI, determine an HNRI for the second UE's home network based on the TXI, determine an authentication node in the second UE's home network based on the HNRI, and forward the request to the authentication node in the second UE's home network.

[0024]

[0024] Other objects and advantages associated with the embodiments disclosed herein will become apparent to those skilled in the art based on the accompanying drawings and detailed description. [Brief explanation of the drawings]

[0025]

[0025] The accompanying drawings are presented to aid in the description of various aspects of the present disclosure and are provided solely for illustration of the aspects, not limitation thereof. [Figure 1]

[0026] FIG. 1 illustrates an exemplary wireless communication system according to aspects of the present disclosure. [Figure 2A]

[0027] FIG. 1 illustrates an exemplary wireless network structure according to aspects of the present disclosure. [Figure 2B] FIG. 1 illustrates an exemplary wireless network structure according to aspects of the present disclosure. [Figure 2C] FIG. 1 illustrates an exemplary wireless network structure according to aspects of the present disclosure. [Figure 3A]

[0028] 1 is a simplified block diagram of several sample aspects of components that may be employed in a user equipment (UE) and configured to support communication as taught herein; [Figure 3B]1 is a simplified block diagram of several sample aspects of components that may be employed in a base station and configured to support communication as taught herein; [Figure 3C] 1 is a simplified block diagram of several sample aspects of components that may be employed in a network entity and configured to support communications as taught herein; [Figure 4]

[0029] FIG. 1 is a signaling and event diagram illustrating a user plane (UP) based security procedure involving Layer 3 (L3) UE-to-Network (U2N) relay. [Figure 5A]

[0030] FIG. 1 is a signaling and event diagram illustrating part of a control plane (CP) based security procedure involving an L3 U2N relay. [Figure 5B] FIG. 1 is a signaling and event diagram illustrating part of a control plane (CP) based security procedure involving an L3 U2N relay. [Figure 6]

[0031] FIG. 1 illustrates a resynchronization process using user plane-based security procedures. [Figure 7]

[0032] FIG. 1 illustrates a resynchronization process using control plane-based security procedures. [Figure 8A]

[0033] 10A-10C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE using UP-based security procedures, according to an aspect of the disclosure. [Figure 8B] 10A-10C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE using UP-based security procedures, according to an aspect of the disclosure. [Figure 8C] 10A-10C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE using UP-based security procedures, according to an aspect of the disclosure. [Figure 9A]

[0034] 10A-10C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE using CP-based security procedures, according to an aspect of the disclosure. [Figure 9B] 10A-10C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE using CP-based security procedures, according to an aspect of the disclosure. [Figure 9C] 10A-10C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE using CP-based security procedures, according to an aspect of the disclosure. [Figure 10]

[0035] 1 is a flowchart of an example process performed by a remote UE associated with a method and system for providing an HNRI of the remote UE following an authentication failure during establishment of U2N relay communication with the relay UE, according to an aspect of the present disclosure. [Figure 11]

[0036] 1 is a flowchart of an example process performed by a U2N relay UE associated with a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication with the remote UE, according to an aspect of the disclosure. [Figure 12]

[0037] 1 is a flowchart of an example process performed by a network node associated with a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, according to an aspect of the present disclosure. [Figure 13]

[0038] 1A-1C are simplified block diagrams of several sample aspects of electronic devices configured to support providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, in accordance with aspects of the present disclosure. [Figure 14]1A-1C are simplified block diagrams of several sample aspects of electronic devices configured to support providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, in accordance with aspects of the present disclosure. [Figure 15] 1A-1C are simplified block diagrams of several sample aspects of electronic devices configured to support providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, in accordance with aspects of the present disclosure. [Figure 16]

[0039] 10 is a flowchart of another example process performed by a remote UE in association with a method and system for providing an HNRI of the remote UE following an authentication failure during establishment of U2N relay communication with the relay UE, according to an aspect of the present disclosure. [Figure 17]

[0040] 10 is a flowchart of another example process performed by a U2N relay UE associated with a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication with the remote UE, according to an aspect of the present disclosure. [Figure 18]

[0041] 10 is a flowchart of another example process performed by a network node associated with a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, according to an aspect of the present disclosure. [Figure 19]

[0042] 1A-1C are simplified block diagrams of several sample aspects of electronic devices configured to support providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, in accordance with aspects of the present disclosure. [Figure 20] 1A-1C are simplified block diagrams of several sample aspects of electronic devices configured to support providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a relay UE, in accordance with aspects of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0026]

[0043] Sidelink communication is communication that occurs directly between one user equipment (UE) and another UE, rather than through a base station. In some types of sidelink communication, a communication link is established by or with the assistance of a base station, and the two UEs then communicate directly with the base station and each other. In other types of sidelink communication, a communication link may be established without the need for or assistance of a base station. In one form of sidelink communication, communication may be established using proximity services, or "ProSe" for short. Proximity services enable UEs to discover and connect with each other, including establishing secure connections between UEs.

[0027]

[0044] When a first UE also provides a connection to a network for a second UE connected to the first UE by a sidelink communication link (whether or not the sidelink communication is a ProSe connection), the first UE is called a UE-to-Network (U2N) relay (sometimes called a "U2N relay UE" or simply a "relay UE"), and the second UE is called a "remote UE" (sometimes called a "U2N remote UE"). In this scenario, security material provided by authorization and authentication nodes in the remote UE's home network and the relay UE's home network is used to authenticate the remote UE and relay UE, and to secure the connection between the remote UE and relay UE. Some of this security material may be associated with expiration or "freshness" parameters such that it is valid for a limited time, after which it expires and becomes invalid.

[0028]

[0045] As used herein, the term "security material" refers to any element or information related to security protection, including information necessary to protect the transmission or reception of a message. Examples of security material include, but are not limited to, security keys, key IDs, expiration dates, identification of algorithms used (e.g., selected PC5 encryption algorithms), and parameters used by such algorithms (e.g., code-receive security parameters or code-send security parameters). As used herein, the term "confidentiality protection" as applied to a message refers to protection of that message to prevent unauthorized access to information contained within that message. As used herein, the term "integrity protection" as applied to a message refers to protection of that message to ensure that the message has not been modified since its creation and transmission, and by extension, to detect when the message has been modified.

[0029]

[0046] When the remote UE is unable to authenticate the relay, this is referred to herein as a U2N relay UE authentication failure, or simply an "authentication failure." If this fails because the security material was invalid (e.g., incorrect or expired), such as when the authentication vector provided to the remote UE by the relay UE is not within a set of one or more expected values ​​(a specific type of authentication failure known as a "synchronization failure"), the remote UE must provide notification of the authentication failure to the entity seeking to be authenticated, in this case the U2N relay UE.

[0030]

[0047] When a synchronization failure occurs, a process called "resynchronization" may be performed to retrieve an updated authentication challenge for retrying authentication. Resynchronization involves interaction between a first authentication node that is an authentication node in the home network of the relay UE (and therefore may be referred to herein as the "authentication node for the relay UE") and a second authentication node that is an authentication node in the home network of the remote UE (and therefore may be referred to herein as the "authentication node for the remote UE").

[0031]

[0048] When this interaction is initiated by the first authenticating node, the first authenticating node needs to know how to contact the second authenticating node, i.e., the first authenticating node needs to know the home network routing information (HNRI) of the second authenticating node (e.g., the network address or other network identifier of the home network).

[0032]

[0049] How the first authenticating node comes into possession of this network address or network identifier for the home network of the second authenticating node is not specified by existing telecommunications standards, and the message that the first authenticating node receives to trigger the resynchronization process does not include any HNRI for the second authenticating node, so the source of this information and the mechanism by which it reaches the first authenticating node is undefined.

[0033]

[0050] To address this ambiguity, a method and system are disclosed herein for providing an HNRI of the authenticator node for the remote UE (hereinafter sometimes simply referred to as "HNRI") to an authenticator node for the relay UE following an authentication failure during establishment of U2N relay communication between the remote UE and the relay UE.

[0034]

[0051] According to aspects of the present disclosure, the HNRI of the authenticator node for the relay UE is provided to the authenticator node for the relay UE either by the remote UE, by the relay UE, or from being stored by the authenticator node for the relay UE from a previous interaction with the remote UE. Using this information, the authenticator node for the relay UE may interact with the authenticator node for the remote UE to provide an updated authentication challenge used, for example, for authenticating a secure connection between the remote UE and the relay UE and / or a secure connection between the remote UE and a network to which the relay UE provides remote UE access, such as the resynchronization procedure described above. Thus, the techniques disclosed herein provide an established procedure by which the authenticator node for the relay UE obtains the HNRI of the authenticator node for the remote UE.

[0035]

[0052] There are several approaches described herein regarding how the relay UE obtains the HNRI of the authentication node for the remote UE, which the relay UE provides to the authentication node for the relay UE. In some aspects, the remote UE provides the HNRI as part of a message (sometimes referred to herein as an “authentication failure message”) that the remote UE sends to the relay UE to inform the relay UE that the remote UE failed to authenticate the relay UE. In some aspects, the remote UE provides the HNRI in an additional message that the remote UE sends to the relay UE separate from the authentication failure message. In some aspects, the remote UE will have previously provided the HNRI to the relay UE as part of the direct communication request, and the relay UE will have stored the HNRI; when the relay UE later receives an authentication failure message, the relay UE may fetch the previously stored HNRI. In some aspects, the remote UE will have previously provided the HNRI to the relay UE as part of a direct communication request, and the relay UE will then generate and store a transaction identifier (TXI) in response to receiving the direct communication request from the remote UE and provide both the HNRI and the TXI to an authentication node for the relay UE. The authentication node for the relay UE stores the mapping of the TXI to the HNRI. When the relay UE later receives an authentication failure message, the relay UE provides the TXI to the authentication node for the relay UE, and the authentication node uses the TXI to look up the correct HNRI.

[0036]

[0053] Sidelink communications between a user equipment (UE) and another UE can be established without the need for or assistance from a base station using proximity services, or "ProSe" for short. Proximity services enable UEs to discover and connect to each other, including establishing secure connections between UEs. When a first UE also provides a connection to a network for a second UE, the first UE is called a UE-to-Network (U2N) relay (sometimes called a "U2N relay UE" or simply a "relay UE"), and the second UE is called a "remote UE." In this scenario, the remote UE and relay UE must be authenticated, and the connection between them must be secured, using security material provided by authorization and authentication nodes in the remote UE's home network and the relay UE's home network.

[0037]

[0054] If the authentication step fails, for example, because security materials are invalid or have expired, the remote UE must provide notification of the authentication failure. One example of such a process when a synchronization failure occurs is called "resynchronization." Resynchronization is performed to retrieve an updated authentication challenge for retrying authentication. Resynchronization involves an interaction between a first authentication node in the home network of the relay UE and a second authentication node in the home network of the remote UE. When this interaction is initiated by the first authentication node, the first authentication node needs to know how to contact the second authentication node, i.e., the first authentication node needs to know the home network routing information (HNRI) (e.g., the address or other network identifier of the home network) of the second authentication node. Exactly how the first authentication node possesses this network address or network identifier for the home network of the second authentication node is not specified by existing telecommunications standards, and the message the first authentication node receives to trigger the resynchronization process does not include the HNRI for the second authentication node.

[0038]

[0055] To address this ambiguity, methods and systems are disclosed herein for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and the relay UE. In some aspects, a first UE (e.g., a remote UE) may detect an authentication failure during establishment of a secure connection with a second UE (e.g., a relay UE) and, in response to detecting the authentication failure, notify the second UE of the authentication failure. The second UE then signals a second authentication node in the second UE's home network. The HNRI of the first authentication node in the first UE's home network is provided to the second authentication node either by the first UE, by the second UE, or from being stored by the second authentication node from a previous interaction with the first UE, so that the second authentication node can interact with the first authentication node to provide an updated authentication challenge used, for example, to authenticate the secure connection between the remote UE and the relay UE and / or the secure connection between the remote UE and the network to which the relay UE grants the remote UE access.

[0039]

[0056] Aspects of the present disclosure are provided in the following description and related drawings, directed to various examples provided for illustrative purposes. Alternative aspects may be devised without departing from the scope of the present disclosure. Additionally, well-known elements of the present disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of the present disclosure.

[0040]

[0057] The words "exemplary" and / or "example" are used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" and / or "example" is not necessarily to be construed as preferred or advantageous over other aspects. Likewise, the term "aspects of the present disclosure" does not require that all aspects of the present disclosure include the discussed feature, advantage or mode of operation.

[0041]

[0058] Those skilled in the art will understand that the information and signals described below may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the following description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof, depending in part on the particular application, desired design, corresponding technology, etc.

[0042]

[0059] Further, many aspects are described in terms of sequences of actions to be performed by, for example, elements of a computing device. It will be appreciated that various actions described herein can be performed by specific circuitry (e.g., application specific integrated circuits (ASICs)), by program instructions executed by one or more processors, or by a combination of both. In addition, the sequence(s) of actions described herein may be considered to be embodied entirely in any form of non-transitory computer-readable storage medium storing a corresponding set of computer instructions, which, when executed, cause or instruct the associated processor(s) of a device to perform the functionality described herein. Accordingly, various aspects of the present disclosure may be embodied in several different forms, all of which are contemplated to be within the scope of the claimed subject matter. Additionally, for each aspect described herein, the corresponding form of any such aspect may be described herein as, for example, “logic configured to” perform the described actions.

[0043]

[0060] The terms “user equipment” (UE) and “base station,” as used herein, are not intended to be specific to or limited to any particular radio access technology (RAT) unless otherwise specified. Generally, a UE can be any wireless communication device (e.g., a mobile phone, a router, a tablet computer, a laptop computer, a consumer location device, a wearable (e.g., a smart watch, glasses, augmented reality (AR) / virtual reality (VR) headset, etc.), a vehicle (e.g., a car, a motorcycle, a bicycle, etc.), an Internet of Things (IoT) device, etc.) used by a user to communicate over a wireless communication network. A UE may be mobile or may be stationary (e.g., at a given time) and may communicate with a radio access network (RAN). As used herein, the term “UE” may be referred to interchangeably as an “access terminal” or “AT,” a “client device,” a “wireless device,” a “subscriber device,” a “subscriber terminal,” a “subscriber station,” a “user terminal” or “UT,” a “mobile device,” a “mobile terminal,” a “mobile station,” or variations thereof. Generally, a UE can communicate with a core network via a RAN, through which the UE can be connected to external networks such as the Internet and to other UEs. Of course, other mechanisms for connecting to the core network and / or the Internet are also possible for a UE, such as via a wired access network, a wireless local area network (WLAN) network (e.g., based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 specification, etc.), etc.

[0044]

[0061] A base station may operate according to one of several RATs with which it communicates with UEs depending on the network in which it is deployed and may alternatively be referred to as an access point (AP), network node, Node B, evolved Node B (eNB), next generation eNB (ng-eNB), new radio (NR) Node B (also referred to as gNB or gNode B), etc. A base station may be used primarily to support wireless access by UEs, including supporting data, voice, and / or signaling connections for supported UEs. In some systems, a base station may provide only edge node signaling functionality, while in other systems, a base station may provide additional control and / or network management functions. The communication link over which a UE can send signals to a base station is called an uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). The communication links through which a base station may transmit signals to a UE are called downlink (DL) channels or forward link channels (e.g., paging channels, control channels, broadcast channels, forward traffic channels, etc.). As used herein, the term traffic channel (TCH) can refer to either an uplink / reverse traffic channel or a downlink / forward traffic channel.

[0045]

[0062] The term "base station" can refer to a single physical transmission / reception point (TRP) or multiple physical TRPs, which may or may not be collocated. For example, when the term "base station" refers to a single physical TRP, the physical TRP may be an antenna of the base station corresponding to the base station's cell (or several cell sectors). When the term "base station" refers to multiple collocated physical TRPs, the physical TRP may be an array of antennas of the base station (e.g., as in a multiple-input multiple-output (MIMO) system or when the base station employs beamforming). When the term "base station" refers to multiple non-collocated physical TRPs, the physical TRPs may be a distributed antenna system (DAS) (a network of spatially separated antennas connected to a common source via a transport medium) or a remote radio head (RRH) (a remote base station connected to a serving base station). Alternatively, non-co-located physical TRPs may be the serving base station that receives measurement reports from the UE and neighboring base stations whose reference radio frequency (RF) signals the UE is measuring. Because a TRP is a point from which a base station transmits and receives wireless signals, as used herein, references to transmission from or reception at a base station should be understood as referring to a particular TRP of the base station.

[0046]

[0063] In some implementations that support UE positioning, a base station may not support wireless access by the UE (e.g., may not support data, voice, and / or signaling connections for the UE), but instead may transmit reference signals to the UE to be measured by the UE and / or may receive and measure signals transmitted by the UE. Such a base station may be referred to as a positioning beacon (e.g., if it transmits signals to the UE) and / or a location measurement unit (e.g., if it receives and measures signals from the UE).

[0047]

[0064] An "RF signal" includes electromagnetic waves of a given frequency that propagate information through space between a transmitter and a receiver. As used herein, a transmitter may transmit a single "RF signal" or multiple "RF signals" to a receiver. However, due to the propagation characteristics of RF signals through multipath channels, the receiver may receive multiple "RF signals" corresponding to each transmitted RF signal. The same RF signal transmitted via different paths between a transmitter and a receiver may be referred to as a "multipath" RF signal. As used herein, an RF signal may also be referred to as a "wireless signal" or simply a "signal" when it is clear from the context that the term "signal" refers to a wireless signal or an RF signal.

[0048]

[0065] FIG. 1 illustrates an exemplary wireless communication system 100 according to aspects of the present disclosure. The wireless communication system 100 (sometimes referred to as a wireless wide area network (WWAN)) may include various base stations 102 (labeled “BS”) and various UEs 104. The base stations 102 may include macrocell base stations (high-power cellular base stations) and / or small cell base stations (low-power cellular base stations). In one aspect, the macrocell base stations may include eNBs and / or ng-eNBs, where the wireless communication system 100 corresponds to an LTE network, or gNBs, where the wireless communication system 100 corresponds to an NR network, or a combination of both, and the small cell base stations may include femtocells, picocells, microcells, etc. Some UEs 104 may act as relay UEs for other UEs 104. In some aspects, the UEs 104 may include a Proximity Services (ProSe) module 106 for managing certain aspects of ProSe communications between UEs.

[0049]

[0066] The base stations 102 may collectively form a RAN and may interface with a core network 170 (e.g., evolved packet core (EPC) or 5G core (5G core, 5GC)) through backhaul links 122 and to one or more location servers 172 (e.g., a location management function (LMF) or a secure user plane location (SUPL) location platform (SLP)) through the core network 170. The location server(s) 172 may be part of the core network 170 or may be external to the core network 170. The location server(s) 172 may be integrated with the base station 102. The UE 104 may communicate with the location server 172 directly or indirectly. For example, the UE 104 may communicate with the location server 172 through the base station 102 currently serving the UE 104. The UE 104 may also communicate with the location server 172 through another path, such as through an application server (not shown), through a wireless local area network (WLAN) access point (AP) (e.g., AP 150 described below), or through another network. For signaling purposes, communication between the UE 104 and the location server 172 may be represented as an indirect connection (e.g., through the core network 170) or a direct connection (e.g., as shown via direct connection 128), with intervening nodes (if any) omitted from the signaling diagrams for clarity. The core network 170 may include an authentication node 174, such as an access and mobility management function (AMF), an authentication server function (AUSF), or a ProSe key management function (PKMF), which may also include the ProSe module 106.

[0050]

[0067] In addition to other functions, the base stations 102 may perform functions related to one or more of the following: forwarding user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection setup and release, load balancing, non-access stratum (NAS) message delivery, NAS node selection, synchronization, RAN sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracing, RAN information management (RIM), paging, positioning, and alert message delivery. The base stations 102 may communicate with each other directly or indirectly (e.g., through EPC / 5GC) via backhaul links 134, which may be wired or wireless.

[0051]

[0068] The base stations 102 may wirelessly communicate with the UEs 104. Each of the base stations 102 may provide communication coverage for a respective geographic coverage area 110. In one aspect, one or more cells may be supported by the base stations 102 in each geographic coverage area 110. A “cell” is a logical communication entity used for communication with a base station (e.g., over some frequency resources referred to as a carrier frequency, component carrier, carrier, band, etc.) and may be associated with an identifier (e.g., a physical cell identifier (PCI), an enhanced cell identifier (ECI), a virtual cell identifier (VCI), a cell global identifier (CGI), etc.) to distinguish between cells operating over the same or different carrier frequencies. In some cases, different cells may be configured according to different protocol types (e.g., machine-type communication (MTC), narrowband IoT (NB-IoT), enhanced mobile broadband (eMBB), or others) that may provide access to different types of UEs. Because a cell is supported by a particular base station, the term "cell" can refer to either or both of the logical communication entity and its supporting base station, depending on the context. In addition, because a TRP is typically the physical transmission point of a cell, the terms "cell" and "TRP" may be used interchangeably. In some cases, the term "cell" can also refer to the geographic coverage area (e.g., sector) of a base station, so long as the carrier frequency can be detected and used for communication within a portion of the geographic coverage area 110.

[0052]

[0069] The geographic coverage areas 110 of neighboring macrocell base stations 102 may partially overlap (e.g., in handover regions), and some of the geographic coverage areas 110 may be significantly overlapped by larger geographic coverage areas 110. For example, a small cell base station 102' (labeled "SC" for "small cell") may have a geographic coverage area 110' that significantly overlaps with the geographic coverage area 110 of one or more macrocell base stations 102. A network including both small cell and macrocell base stations may be known as a heterogeneous network. A heterogeneous network may also include home eNBs (HeNBs), which may serve closed groups known as closed subscriber groups (CSGs).

[0053]

[0070] The communication link 120 between the base station 102 and the UE 104 may include uplink (also called reverse link) transmissions from the UE 104 to the base station 102, and / or downlink (DL) (also called forward link) transmissions from the base station 102 to the UE 104. The communication link 120 may use MIMO antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link 120 may be of one or multiple carrier frequencies. Carrier allocation may be asymmetric with respect to the downlink and uplink (e.g., the downlink may be allocated more or fewer carriers than the uplink).

[0054]

[0071] The wireless communication system 100 may further include a wireless local area network (WLAN) access point (WLAN) 150 communicating with wireless local area network (WLAN) stations (STAs) 152 over a communication link 154 in an unlicensed frequency spectrum (e.g., 5 GHz). When communicating in the unlicensed frequency spectrum, the WLAN STAs 152 and / or the WLAN AP 150 may perform a clear channel assessment (CCA) or listen before talk (LBT) procedure before communicating to determine whether a channel is available.

[0055]

[0072] The small cell base station 102' may operate in a licensed and / or unlicensed frequency spectrum. When operating in an unlicensed frequency spectrum, the small cell base station 102' may utilize LTE or NR technology and employ the same 5 GHz unlicensed frequency spectrum used by the WLAN AP 150. A small cell base station 102' employing LTE / 5G in an unlicensed frequency spectrum may extend coverage to and / or increase the capacity of an access network. NR in an unlicensed spectrum may be referred to as NR-U. LTE in an unlicensed spectrum may be referred to as LTE-U, licensed assisted access (LAA), or MultiFire.

[0056]

[0073] The wireless communication system 100 may further include an mmW base station 180 that may operate at millimeter wave (mmW) and / or sub-mmW frequencies to communicate with the UE 182. Extremely high frequency (EHF) is a portion of RF in the electromagnetic spectrum. EHF ranges from 30 GHz to 300 GHz and has wavelengths from 1 millimeter to 10 millimeters. Radio waves within this band may be referred to as millimeter waves. Sub-mmW may fall down to frequencies of 3 GHz with wavelengths of 100 millimeters. The super high frequency (SHF) band ranges from 3 GHz to 30 GHz and is also referred to as centimeter waves. Communications using the mmW / sub-mmW radio frequency bands have high path loss and relatively short range. The mmW base station 180 and the UE 182 may utilize beamforming (transmit and / or receive) over the mmW communication link 184 to compensate for the extremely high path loss and short range. Furthermore, it will be appreciated that in alternative configurations, one or more base stations 102 may also transmit using mmW or quasi-mmW and beamforming. Accordingly, it will be appreciated that the above illustrations are merely examples and should not be construed as limiting various aspects disclosed herein.

[0057]

[0074] Transmit beamforming is a technique for focusing an RF signal in a specific direction. Traditionally, when a network node (e.g., a base station) broadcasts an RF signal, it broadcasts the signal in all directions (omnidirectionally). With transmit beamforming, the network node determines where a given target device (e.g., UE) is located (relative to the transmitting network node) and emits a stronger downlink RF signal in that specific direction, thereby providing a faster and more powerful RF signal (in terms of data rate) to the receiving device(s). To change the directionality of the RF signal when transmitting, the network node can control the phase and relative amplitude of the RF signal at each of one or more transmitters broadcasting the RF signal. For example, the network node may use an array of antennas (also called a "phased array" or "antenna array") that creates beams of RF waves that can be "steered" to point in different directions without actually moving the antennas. Specifically, RF currents from the transmitters are supplied to the individual antennas with the appropriate phase relationship so that radio waves from the separate antennas are combined to cancel and suppress radiation in undesired directions while increasing radiation in desired directions.

[0058]

[0075] A transmit beam may be quasi-colocated, meaning that the transmit beam appears to a receiver (e.g., a UE) to have the same parameters regardless of whether the network node's own transmit antenna is physically colocated. In NR, there are four types of quasi-colocation (QCL) relationships. Specifically, a given type of QCL relationship means that some parameters for a second reference RF signal on a second beam can be derived from information about a source reference RF signal on a source beam. Thus, if the source reference RF signal is QCL Type A, the receiver can use the source reference RF signal to estimate the Doppler shift, Doppler spread, mean delay, and delay spread of the second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL Type B, the receiver can use the source reference RF signal to estimate the Doppler shift and Doppler spread of the second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL Type C, the receiver can use the source reference RF signal to estimate the Doppler shift and average delay of a second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL Type D, the receiver can use the source reference RF signal to estimate spatial reception parameters of a second reference RF signal transmitted on the same channel.

[0059]

[0076] In receive beamforming, a receiver uses receive beams to amplify RF signals detected on a given channel. For example, the receiver can increase the gain setting and / or adjust the phase setting of an antenna array in a particular direction to amplify (e.g., increase its gain level) RF signals received from that direction. Thus, when a receiver is said to beamform in a particular direction, it means that the beam gain in that direction is higher than the beam gains along other directions, or that the beam gain in that direction is the highest compared to the beam gains in that direction of all other receive beams available to the receiver. This results in a stronger received signal strength (e.g., reference signal received power (RSRP), reference signal received quality (RSRQ), signal-to-interference-plus-noise ratio (SINR), etc.) of RF signals received from that direction.

[0060]

[0077] The transmit beam and the receive beam may be spatially related. Spatial relationship means that parameters for a second beam (e.g., a transmit beam or a receive beam) for a second reference signal may be derived from information about a first beam (e.g., a receive beam or a transmit beam) for a first reference signal. For example, a UE may use a particular receive beam to receive a reference downlink reference signal (e.g., a synchronization signal block (SSB)) from a base station. The UE can then form a transmit beam for sending an uplink reference signal (e.g., a sounding reference signal (SRS)) to that base station based on the parameters of the receive beam.

[0061]

[0078] Note that a "downlink" beam can be either a transmit beam or a receive beam, depending on the entity that forms it. For example, if a base station forms a downlink beam to transmit a reference signal to a UE, the downlink beam is a transmit beam. However, if the UE forms a downlink beam, it is a receive beam to receive a downlink reference signal. Similarly, an "uplink" beam can be either a transmit beam or a receive beam, depending on the entity that forms it. For example, if a base station forms an uplink beam, it is an uplink receive beam, and if the UE forms an uplink beam, it is an uplink transmit beam.

[0062]

[0079] The electromagnetic spectrum is often subdivided into various classes, bands, channels, etc. based on frequency / wavelength. In 5G NR, two initial operating bands have been identified with frequency range designations FR1 (410 MHz to 7.125 GHz) and FR2 (24.25 GHz to 52.6 GHz). It should be understood that, although a portion of FR1 is above 6 GHz, FR1 is often referred to (interchangeably) as the “sub-6 GHz” band in various documents and papers. Similar nomenclature issues may arise with respect to FR2, which is often referred to (interchangeably) as the “millimeter wave” band in documents and papers, even though it is different from the extremely high frequency (EHF) band (30 GHz to 300 GHz) identified by the International Telecommunications Union (ITU) as the “millimeter wave” band.

[0063]

[0080] Frequencies between FR1 and FR2 are often referred to as mid-band frequencies. Recent 5G NR studies have identified operating bands for these mid-band frequencies as a frequency range designated FR3 (7.125 GHz to 24.25 GHz). Frequency bands included within FR3 may inherit FR1 and / or FR2 characteristics, thus effectively extending the characteristics of FR1 and / or FR2 to the mid-band frequencies. Higher frequency bands are currently being explored to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as frequency ranges designated FR4a or FR4-1 (52.6 GHz to 71 GHz), FR4 (52.6 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands is included within the EHF band.

[0064]

[0081] With the above aspects in mind, it should be understood that unless specifically stated otherwise, terms such as "sub-6 GHz," as used herein, may broadly refer to frequencies that may be below 6 GHz, may be within FR1, or may include mid-band frequencies. Furthermore, unless specifically stated otherwise, it should be understood that terms such as "mmWave," as used herein, may broadly refer to frequencies that may include mid-band frequencies, may be within the ranges of FR2, FR4, FR4-a, or FR4-1, and / or FR5, or may be within the EHF band.

[0065]

[0082] In a multi-carrier system such as 5G, one of the carrier frequencies is referred to as the "primary carrier" or "anchor carrier" or "primary serving cell" or "PCell," and the remaining carrier frequencies are referred to as "secondary carriers" or "secondary serving cells" or "SCells." In carrier aggregation, the anchor carrier is the carrier operating on the primary frequency (e.g., FR1) utilized by the UE 104 / 182 and is the cell on which the UE 104 / 182 either performs an initial radio resource control (RRC) connection establishment procedure or initiates an RRC connection re-establishment procedure. The primary carrier carries all common control channels and UE-specific control channels and may (but is not always) be a carrier among licensed frequencies. The secondary carrier is a carrier operating on a second frequency (e.g., FR2) that may be configured once an RRC connection is established between the UE 104 and the anchor carrier and may be used to provide additional radio resources. In some cases, the secondary carrier may be a carrier among unlicensed frequencies. Since both the primary uplink carrier and the primary downlink carrier are typically UE-specific, the secondary carrier shall contain only the necessary signaling information and signals; e.g., there shall be no UE-specific signaling information and signals in the secondary carrier. This means that different UEs 104 / 182 in a cell may have different downlink primary carriers. The same applies to the uplink primary carrier. The network may change the primary carrier of any UE 104 / 182 at any time. This may be done, for example, to balance the load on different carriers. Since a "serving cell" (whether PCell or SCell) corresponds to a carrier frequency / component carrier over which several base stations are communicating, terms such as "cell," "serving cell," "component carrier," and "carrier frequency" may be used interchangeably.

[0066]

[0083] For example, still referring to FIG. 1, one of the frequencies utilized by the macrocell base station 102 may be an anchor carrier (or "PCell"), and other frequencies utilized by the macrocell base station 102 and / or the mmW base station 180 may be secondary carriers ("SCells"). Simultaneous transmission and / or reception of multiple carriers allows the UE 104 / 182 to significantly increase its data transmission and / or data reception rates. For example, two 20 MHz carriers combined in a multi-carrier system would theoretically provide a 2x data rate increase (i.e., 40 MHz) compared to the data rate achieved by a single 20 MHz carrier.

[0067]

[0084] Wireless communications system 100 may further include UE 164, which may communicate with macrocell base station 102 via communications link 120 and / or with mmW base station 180 via mmW communications link 184. For example, macrocell base station 102 may support a PCell and one or more SCells for UE 164, and mmW base station 180 may support one or more SCells for UE 164.

[0068]

[0085] In some cases, the UE 164 and the UE 182 may be capable of sidelink communication. Sidelink-capable UEs (SL-UEs) can communicate with the base station 102 via a communication link 120 using the Uu interface (i.e., the air interface between the UE and the base station). SL-UEs (e.g., the UE 164, the UE 182) may also communicate directly with each other via a wireless sidelink 160 using the PC5 interface (i.e., the air interface between sidelink-capable UEs). Wireless sidelink (or simply "sidelink") is an adaptation of the core cellular (e.g., LTE, NR) standard that enables direct communication between two or more UEs without the communication having to go through a base station. Sidelink communications may be unicast or multicast and may be used for device-to-device (D2D) medium sharing, vehicle-to-vehicle (V2V) communications, vehicle-to-everything (V2X) communications (e.g., cellular V2X (cV2X) communications, enhanced V2X (eV2X) communications, etc.), emergency rescue applications, etc. One or more of a group of SL-UEs utilizing sidelink communications may be within the geographic coverage area 110 of the base station 102. Other SL-UEs in such a group may be outside the geographic coverage area 110 of the base station 102 or may in some cases be unable to receive transmissions from the base station 102. In some cases, a group of SL-UEs communicating via sidelink communications may utilize a one-to-many (1:M) system, where each SL-UE transmits to all other SL-UEs in the group. In some cases, the base station 102 facilitates scheduling of resources for sidelink communications. In other cases, sidelink communications are performed between SL-UEs without the involvement of the base station 102.

[0069]

[0086] In one aspect, the sidelink 160 may operate over a target wireless communications medium, which may be shared with other vehicular and / or infrastructure access points, as well as other wireless communications between other RATs. The “medium” may consist of one or more time, frequency, and / or spatial communications resources (e.g., encompassing one or more channels across one or more carriers) associated with wireless communications between one or more transmitter / receiver pairs. In one aspect, the target medium may correspond to at least a portion of an unlicensed frequency band shared among various RATs. While different licensed frequency bands have been reserved for certain communications systems (e.g., by government agencies such as the Federal Communications Commission (FCC) in the United States), these systems, particularly those employing small cell access points, have recently extended operation to unlicensed frequency bands, such as the Unlicensed National Information Infrastructure (U-NII) bands used by Wireless Local Area Network (WLAN) technologies, most notably the IEEE 802.11x WLAN technology commonly referred to as “Wi-Fi.” Exemplary systems of this type include CDMA systems, TDMA systems, FDMA systems, orthogonal FDMA (OFDMA) systems, single-carrier FDMA (SC-FDMA) systems, and various variations thereof.

[0070]

[0087] 1 illustrates only two of the UEs as SL-UEs (i.e., UEs 164 and 182), it should be noted that any of the illustrated UEs may be SL-UEs. Additionally, while only UE 182 has been described as being beamforming capable, any of the illustrated UEs, including UE 164, may be beamforming capable. If SL-UEs are beamforming capable, they may beamform toward each other (i.e., toward other SL-UEs), toward other UEs (e.g., UE 104), toward a base station (e.g., base station 102, 180, small cell 102′, access point 150), etc. Thus, in some cases, UE 164 and UE 182 may utilize beamforming over sidelink 160.

[0071]

[0088] In the example of FIG. 1, any of the illustrated UEs (shown in FIG. 1 as a single UE 104 for simplicity) may receive signals 124 from one or more non-terrestrial vehicles (NTVs) 112, which may include Earth-orbiting spacecraft (e.g., satellites) as well as unmanned aerial vehicles (UAVs). In one aspect, the NTVs 112 may be part of a satellite positioning system that the UEs 104 can use as independent sources of location information. A satellite positioning system typically includes a system of transmitters (e.g., NTVs 112) positioned to enable receivers (e.g., UEs 104) to determine their location on or above the Earth based, at least in part, on positioning signals (e.g., signals 124) received from the transmitters. Such transmitters typically transmit signals marked with a repeating pseudo-random noise (PN) code with a set number of chips. While typically located within the NTVs 112, transmitters may sometimes be located on ground-based control stations, base stations 102, and / or other UEs 104. The UE 104 may include one or more dedicated receivers specifically designed to receive signals 124 from the NTV 112 to derive geolocation information.

[0072]

[0089] In a satellite positioning system, the use of signals 124 may be augmented by various satellite-based augmentation systems (SBAS), which may be associated with or otherwise enabled for use with one or more global and / or regional navigation satellite systems. For example, the SBAS may include augmentation system(s) that provide integrity information, differential corrections, and the like, such as the Wide Area Augmentation System (WAAS), the European Geostationary Navigation Overlay Service (EGNOS), the Multi-functional Satellite Augmentation System (MSAS), the Global Positioning System (GPS)-aided Geo-Augmented Navigation, or the GPS and Geo Augmented Navigation system (GAGAN). Thus, as used herein, a satellite positioning system may include any combination of one or more global and / or regional navigation satellites associated with such one or more satellite positioning systems.

[0073]

[0090] In one aspect, the NTV 112 may additionally or alternatively be part of one or more non-terrestrial networks (NTNs). In an NTN, the NTV 112 is connected to an earth station (also called a ground station, NTN gateway, or gateway), which in turn is connected to an element in a 5G network, such as a modified base station 102 (without a terrestrial antenna) or a network node in a 5G network. This element would then provide access to other elements in the 5G network and ultimately to entities outside the 5G network, such as Internet web servers and other user devices. In this manner, the UE 104 may receive communication signals (e.g., signal 124) from the NTV 112 instead of, or in addition to, communication signals from the terrestrial base station 102.

[0074]

[0091] The wireless communication system 100 may further include one or more UEs, such as a UE 190, that indirectly connect to one or more communication networks via one or more device-to-device (D2D) peer-to-peer (P2P) links (referred to as “sidelinks”). In the example of FIG. 1, the UE 190 has a D2D P2P link 192 with one of the UEs 104 connected to one of the base stations 102 (e.g., through which the UE 190 may indirectly obtain cellular connectivity), and a D2D P2P link 194 with a WLAN STA 152 connected to a WLAN AP 150 (through which the UE 190 may indirectly obtain WLAN-based Internet connectivity). In one example, the D2D P2P links 192 and 194 may be supported using any well-known D2D RAT, such as LTE Direct (LTE-D), WiFi Direct (WiFi-D), Bluetooth®, etc.

[0075]

[0092] 2A illustrates an exemplary wireless network configuration 200. For example, a 5GC 210 (also referred to as a Next Generation Core (NGC)) may be functionally considered as control plane (C-plane) functions 214 (e.g., UE registration, authentication, network access, gateway selection, etc.) and user plane (U-plane) functions 212 (e.g., UE gateway functions, data network access, IP routing, etc.) that operate cooperatively to form a core network. A user plane interface (NG-U) 213 and a control plane interface (NG-C) 215 connect a gNB 222 to the 5GC 210, specifically to the user plane function 212 and the control plane function 214, respectively. In additional configurations, an ng-eNB 224 may also be connected to the 5GC 210 via the NG-C 215 to the control plane function 214 and the NG-U 213 to the user plane function 212. Additionally, the ng-eNB 224 may communicate directly with the gNB 222 via a backhaul connection 223. In some configurations, the Next Generation RAN (NG-RAN) 220 may have one or more gNBs 222, while other configurations include one or more of both the ng-eNB 224 and the gNB 222. Either the gNB 222 or the ng-eNB 224 (or both) may communicate with one or more UEs 204 (e.g., any of the UEs described herein).

[0076]

[0093] Another optional aspect may include a location server 230, which may be in communication with the 5GC 210 to provide location assistance to the UE(s) 204. The location servers 230 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules across multiple physical servers, etc.), or alternatively, each may correspond to a single server. The location servers 230 may be configured to support one or more location services for UEs 204 that can connect to the location server 230 via the core network, the 5GC 210, and / or the Internet (not shown). Furthermore, the location server 230 may be integrated into a component of the core network, or alternatively, may be external to the core network (e.g., a third-party server, such as an original equipment manufacturer (OEM) server or a service server).

[0077]

[0094] 2B illustrates another exemplary wireless network structure 240. A 5GC 260 (which may correspond to 5GC 210 in FIG. 2A) may be viewed functionally as a control plane function provided by an access and mobility management function (AMF) 264 and a user plane function provided by a user plane function (UPF) 262, which operate cooperatively to form a core network (i.e., 5GC 260). The functions of the AMF 264 include registration management, connection management, reachability management, mobility management, lawful intercept, transport for session management (SM) messages between one or more UEs 204 (e.g., any of the UEs described herein) and a session management function (SMF) 266, a transparent proxy service for routing SM messages, access authentication and authorization, transport for short message service (SMS) messages between the UE 204 and a short message service function (SMSF) (not shown), and security anchor functionality (SEAF). The AMF 264 also interacts with an authentication server function (AUSF) (not shown) and the UE 204 to receive intermediate keys established as a result of the UE 204 authentication process. In the case of UMTS (universal mobile telecommunications system) subscriber identity module (USIM)-based authentication, the AMF 264 retrieves security material from the AUSF. AMF264 functionality also includes security context management (SCM).The SCM receives keys from the SEAF that it uses to derive access network specific keys. The functionality of the AMF 264 also includes location service management for regulated services, transport for location service messages between the UE 204 and the Location Management Function (LMF) 270 (acting as the location server 230), transport for location service messages between the NG-RAN 220 and the LMF 270, EPS bearer identifier allocation for interworking with an evolved packet system (EPS), and UE 204 mobility event notification. In addition, the AMF 264 also supports functions for non-3GPP (Third Generation Partnership Project) access networks.

[0078]

[0095] The functions of the UPF 262 include acting as an anchor point for intra-RAT / inter-RAT mobility (when applicable), acting as an external protocol data unit (PDU) session point for interconnection to a data network (not shown), packet routing and forwarding, packet inspection, user plane policy rule enforcement (e.g., gating, redirection, traffic steering), lawful interception (user plane collection), traffic usage reporting, quality of service (QoS) processing for the user plane (e.g., uplink / downlink rate enforcement, reflective QoS marking in the downlink), uplink traffic validation (service data flow (SDF) to QoS flow mapping), transport-level packet marking in the uplink and downlink, downlink packet buffering and downlink data notification triggering, and sending and forwarding one or more "end markers" to the source RAN node. The UPF 262 may also support the transfer of location service messages over the user plane between the UE 204 and a location server such as the SLP 272.

[0079]

[0096] The functions of the SMF 266 include session management, UE Internet protocol (IP) address allocation and management, selection and control of user plane functions, configuration of traffic steering in the UPF 262 to route traffic to the appropriate destination, some control of policy enforcement and QoS, and downlink data notification. The interface through which the SMF 266 communicates with the AMF 264 is called the N11 interface.

[0080]

[0097] Another optional aspect may include an LMF 270, which may be in communication with the 5GC 260, to provide location assistance to the UE 204. The LMF 270 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules across multiple physical servers, etc.), or alternatively, each may correspond to a single server. The LMF 270 may be configured to support one or more location services for the UE 204 that may connect to the LMF 270 via the core network, the 5GC 260, and / or via the Internet (not shown). The SLP 272 may support similar functions as the LMF 270, while the LMF 270 may communicate with the AMF 264, the NG-RAN 220, and the UE 204 via the control plane (e.g., using interfaces and protocols intended to convey signaling messages rather than voice or data), and the SLP 272 may communicate with the UE 204 and external clients (e.g., third-party servers 274) via the user plane (e.g., using protocols intended to carry voice and / or data, such as transmission control protocol (TCP) and / or IP).

[0081]

[0098] Yet another optional aspect may include a third-party server 274 that may be in communication with the LMF 270, the SLP 272, the 5GC 260 (e.g., via the AMF 264 and / or the UPF 262), the NG-RAN 220, and / or the UE 204 to obtain location information (e.g., a location estimate) for the UE 204. Thus, in some cases, the third-party server 274 may be referred to as a location service (LCS) client or an external client. The third-party servers 274 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules spread across multiple physical servers, etc.), or alternatively, each may correspond to a single server.

[0082]

[0099] The user plane interface 263 and the control plane interface 265 connect the 5GC 260, and in particular the UPF 262 and the AMF 264, respectively, to one or more gNBs 222 and / or ng-eNBs 224 in the NG-RAN 220. The interface between the gNB(s) 222 and / or ng-eNB(s) 224 and the AMF 264 is referred to as the "N2" interface, and the interface between the gNB(s) 222 and / or ng-eNB(s) 224 and the UPF 262 is referred to as the "N3" interface. The gNB(s) 222 (and / or ng-eNB(s) 224) of the NG-RAN 220 may communicate directly with each other via a backhaul connection 223 referred to as the "Xn-C" interface. One or more of the gNBs 222 and / or ng-eNBs 224 may communicate with one or more UEs 204 via a wireless interface referred to as the "Uu" interface.

[0083]

[0100] The functionality of the gNB 222 may be divided between a gNB central unit (gNB-CU) 226, one or more gNB distributed units (gNB-DUs) 228, and one or more gNB radio units (gNB-RUs) 229. The gNB-CU 226 is a logical node that includes base station functions such as forwarding user data, mobility control, radio access network sharing, positioning, and session management, except for those functions allocated exclusively to the gNB-DU(s) 228. More specifically, the gNB-CU 226 typically hosts the radio resource control (RRC), service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP) protocols of the gNB 222. The gNB-DU 228 is a logical node that generally hosts the radio link control (RLC) and medium access control (MAC) layers of the gNB 222. Its operation is controlled by the gNB-CU 226. One gNB-DU 228 can support one or multiple cells, and one cell is supported by only one gNB-DU 228. The interface 232 between the gNB-CU 226 and one or more gNB-DUs 228 is referred to as the "F1" interface. The physical (PHY) layer functionality of the gNB 222 is generally hosted by one or more standalone gNB-RUs 229, which perform functions such as power amplification and signal transmission / reception. The interface between the gNB-DU 228 and the gNB-RU 229 is referred to as the "Fx" interface. Thus, the UE 204 communicates with the gNB-CU 226 via the RRC, SDAP, and PDCP layers, with the gNB-DU 228 via the RLC and MAC layers, and with the gNB-RU 229 via the PHY layer.

[0084]

[0101] The deployment of a communication system, such as a 5G NR system, can be configured in multiple ways using various components or parts. In a 5G NR system or network, network equipment, such as a network node, network entity, network mobility element, RAN node, core network node, network element, or base station, or one or more units (or one or more components) performing base station functionality, can be implemented in an aggregated or separated architecture. For example, a base station (such as a Node B (NB), evolved NB (eNB), NR base station, 5G NB, access point (AP), transmit / receive point (TRP), or cell) can be implemented as an aggregated base station (also known as a standalone base station or monolithic base station) or a disaggregated base station.

[0085]

[0102] An aggregated base station may be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. A disaggregated base station may be configured to utilize a protocol stack that is physically or logically distributed among two or more units (e.g., one or more centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs)). In some aspects, a CU may be implemented within a RAN node, and one or more DUs may be co-located with the CU or alternatively geographically or virtually distributed across one or more other RAN nodes. A DU may be implemented to communicate with one or more RUs. Each of the CU, DU, and RU may also be implemented as a virtual unit, i.e., a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).

[0086]

[0103] The operation of a base station type or network design may take into account the aggregation characteristics of base station functions. For example, a disaggregated base station may be utilized in an integrated access backhaul (IAB) network, an open radio access network (O-RAN, such as a network configuration supported by the O-RAN Alliance), or a virtualized radio access network (vRAN, also known as a cloud radio access network (C-RAN)). Disaggregation may include distributing functions across two or more units in different physical locations, as well as virtually distributing the functions of at least one unit, which may allow flexibility in network design. Various units of a disaggregated base station, or a disaggregated RAN architecture, may be configured for wired or wireless communication with at least one other unit.

[0087]

[0104] 2C illustrates an exemplary disaggregated base station architecture 250 according to an aspect of the present disclosure. The disaggregated base station architecture 250 may include one or more central units (CUs) 280 (e.g., gNB-CU 226) that can communicate directly with a core network 267 (e.g., 5GC 210, 5GC 260) via a backhaul link or indirectly with the core network 267 through one or more disaggregated base station units (e.g., a near-real time (RT) RAN Intelligent Controller (RIC) 259 via an E2 link, or a non-real time (non-RT) RIC 257 associated with a Service Management and Orchestration (SMO) framework 255, or both). The CU 280 may communicate with one or more distributed units (DUs) 285 (e.g., gNB-DU 228) via respective midhaul links, such as an F1 interface. The DU 285 may communicate with one or more radio units (RUs) 287 (e.g., gNB-RU 229) via respective fronthaul links. The RU 287 may communicate with each UE 204 via one or more radio frequency (RF) access links. In some implementations, a UE 204 may be served by multiple RUs 287 simultaneously.

[0088]

[0105] Each of the units, i.e., CU 280, DU 285, RU 287, and quasi-RT RIC 259, non-RT RIC 257, and SMO framework 255, may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) via a wired or wireless transmission medium. Each of the units, or an associated processor or controller that provides instructions to the unit's communication interface, may be configured to communicate with one or more of the other units via a transmission medium. For example, a unit may include a wired interface configured to receive or transmit signals to one or more of the other units via a wired transmission medium. Furthermore, the units may include a wireless interface, which may include a receiver, transmitter, or transceiver (such as a radio frequency (RF) transceiver) configured to receive, transmit, or transmit signals via a wireless transmission medium to one or more of the other units.

[0089]

[0106] In some aspects, the CU 280 can host one or more upper layer control functions. Such control functions may include Radio Resource Control (RRC), PDCP, Service Data Adaptation Protocol (SDAP), etc. Each control function may execute using an interface configured to communicate signals with other control functions hosted by the CU 280. The CU 280 may be configured to handle user plane functions (i.e., Central Unit - User Plane (CU-UP)), control plane functions (i.e., Central Unit - Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 280 may be logically divided into one or more CU-UP units and one or more CU-CP units. The CU-UP units, when implemented in an O-RAN configuration, may communicate bidirectionally with the CU-CP units via an interface such as an E1 interface. The CU 280 may be implemented to communicate with the DU 285, as needed, for network control and signaling.

[0090]

[0107] The DU 285 may correspond to a logical unit including one or more base station functions for controlling the operation of one or more RUs 287. In some aspects, the DU 285 may host one or more of a radio link control (RLC) layer, a medium access control (MAC) layer, and one or more upper physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation and demodulation, etc.), at least in part according to a functional division such as that defined by the 3rd Generation Partnership Project (3GPP). In some aspects, the DU 285 may further host one or more lower PHY layers. Each layer (or module) may be implemented with an interface configured to communicate signals with other layers (and modules) hosted by the DU 285 or with control functions hosted by the CU 280.

[0091]

[0108] Lower layer functions may be performed by one or more RUs 287. In some deployments, the RUs 287 controlled by the DUs 285 may correspond to logical nodes hosting RF processing functions, lower PHY layer functions (such as performing fast Fourier transforms (FFTs), inverse FFTs (iFFTs), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.), or both, based at least in part on a functional division, such as a lower layer functional division. In such an architecture, the RU(s) 287 may be implemented to handle over-the-air (OTA) communications with one or more UEs 204. In some implementations, real-time and non-real-time aspects of control plane and user plane communications with the RU(s) 287 may be controlled by the corresponding DUs 285. In some scenarios, this configuration may enable the DU(s) 285 and CU 280 to be implemented in a cloud-based RAN architecture, such as a vRAN architecture.

[0092]

[0109] The SMO framework 255 may be configured to support RAN deployment and provisioning of non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 255 may be configured to support deployment of dedicated physical resources for RAN coverage requirements, which may be managed via an operations and maintenance interface (such as an O1 interface). For virtualized network elements, the SMO framework 255 may be configured to interact with a cloud computing platform (such as an open cloud (O-cloud) 269) to perform network element lifecycle management (e.g., instantiate virtualized network elements) via a cloud computing platform interface (e.g., an O2 interface). Such virtualized network elements may include, but are not limited to, the CU 280, the DU 285, the RU 287, and the quasi-RT RIC 259. In some implementations, the SMO framework 255 may communicate with hardware aspects of a 4G RAN, such as an open eNB (O-eNB) 261, via the O1 interface. Additionally, in some implementations, the SMO framework 255 can communicate directly with one or more RUs 287 via an O1 interface. The SMO framework 255 may also include a non-RT RIC 257 configured to support the functionality of the SMO framework 255.

[0093]

[0110] The non-RT RIC 257 may be configured to include logic functions that enable non-real-time control and optimization of RAN elements and resources, artificial intelligence / machine learning (AI / ML) workflows including model training and updates, or policy-based guidance of applications / features in the quasi-RT RIC 259. The non-RT RIC 257 may be coupled to or in communication with the quasi-RT RIC 259 (e.g., via an A1 interface). The quasi-RT RIC 259 may be configured to include logic functions that enable near-real-time control and optimization of RAN elements and resources by data collection and action via interfaces (e.g., via an E2 interface) that connect one or more CUs 280, one or more DUs 285, or both, and the O-eNB to the quasi-RT RIC 259.

[0094]

[0111] In some implementations, the non-RT RIC 257 may receive parameters or external enrichment information from an external server to generate the AI / ML models deployed to the quasi-RT RIC 259. Such information may be utilized by the quasi-RT RIC 259 or may be received from a non-network data source or from a network function in the SMO framework 255 or the non-RT RIC 257. In some examples, the non-RT RIC 257 or the quasi-RT RIC 259 may be configured to adjust RAN behavior or performance. For example, the non-RT RIC 257 may employ AI / ML models to monitor long-term trends and patterns in performance and implement corrective actions through the SMO framework 255 (e.g., reconfiguration via O1) or through the creation of RAN management policies (e.g., A1 policies).

[0095]

[0112] 3A, 3B, and 3C illustrate several example components (represented by corresponding blocks) that may be incorporated within a UE 302 (which may correspond to any of the UEs described herein, including electronic device 1900), a base station 304 (which may correspond to any of the base stations described herein), and a network entity 306 (which may correspond to or embody any of the network functions described herein, including location server 230 and LMF 270 and electronic device 2000, or alternatively, may be independent of the NG-RAN 220 and / or 5GC 210 / 260 infrastructure shown in FIGS. 2A and 2B, such as a private network) to support the operations described herein. It will be understood that these components may be implemented in different types of devices in different implementations (e.g., in an ASIC, in a system-on-chip (SoC), etc.). The illustrated components may also be incorporated into other devices in a communication system. For example, other devices in the system may include similar components to those described to provide similar functionality, such as, but not limited to, one or more components of processing system 1902, transceiver circuitry 1910, and antenna 1912 of Figure 19, and one or more components of processing system 2002 and network interface circuitry 2010 of Figure 20. Also, a given device may include one or more of the components. For example, a device may include multiple transceiver components that enable the device to operate on multiple carriers and / or communicate via different technologies.

[0096]

[0113] The UE 302 and the base station 304 each include one or more wireless wide area network (WWAN) transceivers 310 and 350, respectively, providing means for communicating (e.g., means for transmitting, means for receiving, means for measuring, means for tuning, means for refraining from transmitting, etc.) over one or more wireless communications networks (not shown), such as an NR network, an LTE network, a GSM network, etc. The WWAN transceivers 310 and 350 may each be connected to one or more antennas 316 and 356, respectively, for communicating with other network nodes, such as other UEs, access points, base stations (e.g., eNBs, gNBs), etc., over at least one designated RAT (e.g., NR, LTE, GSM, etc.) over a wireless communications medium of interest (e.g., some set of time / frequency resources in a particular frequency spectrum). The WWAN transceivers 310 and 350 may be variously configured to transmit and encode signals 318 and 358, respectively (e.g., messages, instructions, information, etc.), and conversely, to receive and decode signals 318 and 358, respectively (e.g., messages, instructions, information, pilots, etc.) in accordance with a designated RAT. Specifically, the WWAN transceivers 310 and 350 include one or more transmitters 314 and 354, respectively, to transmit and encode signals 318 and 358, respectively, and include one or more receivers 312 and 352, respectively, to receive and decode signals 318 and 358, respectively.

[0097]

[0114] The UE 302 and base station 304 also each, at least in some cases, include one or more short-range wireless transceivers 320 and 360, respectively. The short-range wireless transceivers 320 and 360 may be connected to one or more antennas 326 and 366, respectively, and may provide means for communicating (e.g., means for transmitting, means for receiving, means for measuring, means for tuning, means for refraining from transmitting, etc.) with other network nodes, such as other UEs, access points, base stations, etc., via at least one designated RAT (e.g., WiFi, LTE-D, Bluetooth®, Zigbee®, Z-Wave®, PC5, dedicated short-range communications (DSRC), wireless access for vehicular environments (WAVE), near-field communication (NFC), ultra-wideband (UWB), etc.) over the wireless communication medium. The short-range wireless transceivers 320 and 360 may be variously configured to transmit and encode signals 328 and 368, respectively (e.g., messages, instructions, information, etc.), and conversely, to receive and decode signals 328 and 368, respectively (e.g., messages, instructions, information, pilots, etc.) in accordance with a designated RAT. Specifically, the short-range wireless transceivers 320 and 360 include one or more transmitters 324 and 364, respectively, to transmit and encode signals 328 and 368, respectively, and include one or more receivers 322 and 362, respectively, to receive and decode signals 328 and 368, respectively. As specific examples, the short-range wireless transceivers 320 and 360 may be WiFi transceivers, Bluetooth® transceivers, Zigbee® and / or Z-Wave® transceivers, NFC transceivers, UWB transceivers, or vehicle-to-vehicle (V2V) and / or vehicle-to-everything (V2X) transceivers.

[0098]

[0115] UE 302 and base station 304 also, in at least some cases, include satellite signal receivers 330 and 370. Satellite signal receivers 330 and 370 may be connected to one or more antennas 336 and 376, respectively, and may provide a means for receiving and / or measuring signals from NTVs, including, but not limited to, satellite positioning / communication signals 338 and 378, respectively. If satellite signal receivers 330 and 370 are satellite positioning system receivers, satellite positioning / communication signals 338 and 378 may be global positioning system (GPS) signals, global navigation satellite system (GLONASS) signals, Galileo signals, Beidou signals, Indian Regional Navigation Satellite System (NAVIC), Quasi-Zenith Satellite System (QZSS), etc. If satellite signal receivers 330 and 370 are non-terrestrial network (NTN) receivers, satellite positioning / communication signals 338 and 378 may be communication signals (e.g., carrying control and / or user data) originating from a 5G network. Satellite signal receivers 330 and 370 may comprise any suitable hardware and / or software for receiving and processing satellite positioning / communication signals 338 and 378, respectively. Satellite signal receivers 330 and 370 may request information and action from other systems as appropriate and, at least in some cases, perform calculations to determine the locations of UE 302 and base station 304, respectively, using the obtained measurements according to any suitable satellite positioning system algorithms.

[0099]

[0116] The base station 304 and the network entity 306 each include one or more network transceivers 380 and 390, respectively, that provide a means for communicating (e.g., a means for transmitting, a means for receiving, etc.) with other network entities (e.g., other base stations 304, other network entities 306). For example, a base station 304 may employ one or more network transceivers 380 to communicate with other base stations 304 or network entities 306 over one or more wired or wireless backhaul links. As another example, a network entity 306 may employ one or more network transceivers 390 to communicate with one or more base stations 304 over one or more wired or wireless backhaul links or with other network entities 306 over one or more wired or wireless core network interfaces.

[0100]

[0117] A transceiver may be configured to communicate over a wired link or a wireless link. The transceiver (whether a wired transceiver or a wireless transceiver) includes transmitter circuitry (e.g., transmitters 314, 324, 354, 364) and receiver circuitry (e.g., receivers 312, 322, 352, 362). In some implementations, the transceiver may be an integrated device (e.g., embodying the transmitter and receiver circuitry within a single device), in some implementations, may comprise separate transmitter and receiver circuitry, or in other implementations may be embodied in other ways. The transmitter and receiver circuitry of a wired transceiver (e.g., network transceivers 380 and 390 in some implementations) may be coupled to one or more wired network interface ports. The wireless transmitter circuitry (e.g., transmitters 314, 324, 354, 364) may include or be coupled to multiple antennas (e.g., antennas 316, 326, 356, 366), such as an antenna array that enables the respective device (e.g., UE 302, base station 304) to perform transmit “beamforming,” as described herein. Similarly, the wireless receiver circuitry (e.g., receivers 312, 322, 352, 362) may include or be coupled to multiple antennas (e.g., antennas 316, 326, 356, 366), such as an antenna array that enables the respective device (e.g., UE 302, base station 304) to perform receive beamforming, as described herein. In one aspect, the transmitter and receiver circuitry may share multiple identical antennas (e.g., antennas 316, 326, 356, 366), such that the respective device can only receive or transmit at a given time, but not both at the same time. The wireless transceivers (eg, WWAN transceivers 310 and 350, short-range wireless transceivers 320 and 360) may also include a network listen module (NLM) or the like for performing various measurements.

[0101]

[0118] As used herein, various wireless transceivers (e.g., transceivers 310, 320, 350, and 360, and network transceivers 380 and 390, in some implementations) and wired transceivers (e.g., network transceivers 380 and 390, in some implementations) may be generally characterized as a “transceiver,” “at least one transceiver,” or “one or more transceivers.” Thus, whether a particular transceiver is a wired transceiver or a wireless transceiver can be inferred from the type of communication being performed. For example, backhaul communications between network devices or servers generally involve signaling via wired transceivers, while wireless communications between a UE (e.g., UE 302) and a base station (e.g., base station 304) generally involve signaling via wireless transceivers.

[0102]

[0119] The UE 302, base station 304, and network entity 306 also include other components that may be used in conjunction with operations as disclosed herein. The UE 302, base station 304, and network entity 306 each include one or more processors 332, 384, and 394, e.g., to provide functionality related to wireless communications and to provide other processing functions. Accordingly, the processors 332, 384, and 394 may comprise processing means, such as determining means, calculating means, receiving means, transmitting means, and directing means. In one aspect, the processors 332, 384, and 394 may include, e.g., one or more general-purpose processors, multi-core processors, central processing units (CPUs), ASICs, digital signal processors (DSPs), field programmable gate arrays (FPGAs), other programmable logic devices or processing circuits, or various combinations thereof.

[0103]

[0120] The UE 302, the base station 304, and the network entity 306 include memory circuitry implementing memories 340, 386, and 396, respectively (e.g., each including a memory device) for maintaining information (e.g., information indicating reserved resources, thresholds, parameters, etc.). Thus, the memories 340, 386, and 396 may comprise storage means, retrieval means, maintaining means, etc. In some cases, the UE 302, the base station 304, and the network entity 306 may include ProSe modules 342, 388, and 398, respectively. The ProSe modules 342, 388, and 398 may be hardware circuits that are part of or coupled to the processors 332, 384, and 394, respectively, and that, when executed, cause the UE 302, the base station 304, and the network entity 306 to perform the functions described herein. In other aspects, the ProSe modules 342, 388, and 398 may be external to the processors 332, 384, and 394 (e.g., part of a modem processing system, integrated with another processing system, etc.). Alternatively, the ProSe modules 342, 388, and 398 may be memory modules stored in the memories 340, 386, and 396, respectively, which, when executed by the processors 332, 384, and 394 (or modem processing system, another processing system, etc.), cause the UE 302, the base station 304, and the network entity 306 to perform the functions described herein. FIG. 3A illustrates possible locations for the ProSe module 342, which may be part of, for example, one or more WWAN transceivers 310, memory 340, one or more processors 332, or any combination thereof, or may be a standalone component. FIG. 3B shows possible locations of a ProSe module 388, which may be, for example, part of one or more WWAN transceivers 350, memory 386, one or more processors 384, or any combination thereof, or may be a stand-alone component.FIG. 3C shows possible locations of a ProSe module 398, which may be, for example, part of one or more network transceivers 390, memory 396, one or more processors 394, or any combination thereof, or may be a stand-alone component.

[0104]

[0121] The UE 302 may include one or more sensors 344 coupled to the one or more processors 332 to provide a means of sensing or detecting movement and / or orientation information that is independent of movement data derived from signals received by the one or more WWAN transceivers 310, the one or more short-range wireless transceivers 320, and / or the satellite signal receiver 330. By way of example, the sensor(s) 344 may include an accelerometer (e.g., a micro-electrical mechanical systems (MEMS) device), a gyroscope, a geomagnetic sensor (e.g., a compass), an altimeter (e.g., a barometric altimeter), and / or any other type of movement detection sensor. Furthermore, the sensor(s) 344 may include multiple different types of devices, and their outputs may be combined to provide movement information. For example, the sensor(s) 344 may use a combination of a multi-axis accelerometer and an orientation sensor to provide the ability to calculate position in a two-dimensional (2D) and / or three-dimensional (3D) coordinate system.

[0105]

[0122] Additionally, the UE 302 includes a user interface 346 that provides a means for providing instructions (e.g., audio and / or visual instructions) to a user and / or receiving user input (e.g., upon user actuation of a sensing device such as a keypad, touch screen, microphone, etc.). Although not shown, the base station 304 and the network entity 306 may also include user interfaces.

[0106]

[0123] Referring more particularly to the one or more processors 384, on the downlink, IP packets from the network entity 306 may be provided to the processor 384. The one or more processors 384 may perform functions for an RRC layer, a PDCP layer, a radio link control (RLC) layer, and a medium access control (MAC) layer. The one or more processors 384 may provide RRC layer functions associated with broadcasting system information (e.g., master information block (MIB), system information blocks (SIBs)), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-RAT mobility, and measurement configuration for UE measurement reporting; PDCP layer functions associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functions associated with forwarding upper layer PDUs, error correction via automatic repeat request (ARQ), concatenation, segmentation, and reassembly of RLC service data units (SDUs), re-segmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, scheduling information reporting, error correction, priority handling, and logical channel prioritization.

[0107]

[0124] The transmitter 354 and receiver 352 may implement Layer 1 (L1) functions associated with various signal processing functions. Layer 1, including the physical (PHY) layer, may include error detection on transport channels, forward error correction (FEC) coding / decoding of transport channels, interleaving, rate matching, mapping onto physical channels, modulation / demodulation of physical channels, and MIMO antenna processing. The transmitter 354 handles mapping to signal constellations based on various modulation schemes (e.g., binary phase-shift keying (BPSK), quadrature phase-shift keying (QPSK), M-phase-shift keying (M-PSK), and M-quadrature amplitude modulation (M-QAM)). The coded and modulated symbols may then be split into parallel streams. Each stream may then be mapped to orthogonal frequency division multiplexing (OFDM) subcarriers, multiplexed with a reference signal (e.g., a pilot) in the time and / or frequency domain, and then combined together using an inverse fast Fourier transform (IFFT) to generate a physical channel carrying a time-domain OFDM symbol stream. The OFDM symbol stream is spatially precoded to generate multiple spatial streams. Channel estimates from a channel estimator may be used to determine coding and modulation schemes and for spatial processing. The channel estimates may be derived from a reference signal and / or channel condition feedback transmitted by the UE 302. Each spatial stream may then be provided to one or more different antennas 356. The transmitter 354 may modulate an RF carrier with each spatial stream for transmission.

[0108]

[0125] At the UE 302, the receiver 312 receives signals through its respective antenna(s) 316. The receiver 312 recovers information modulated onto RF carriers and provides the information to one or more processors 332. The transmitter 314 and receiver 312 implement Layer 1 functions associated with various signal processing functions. The receiver 312 may perform spatial processing on the information to recover any spatial streams destined for the UE 302. If multiple spatial streams are destined for the UE 302, they may be combined into a single OFDM symbol stream by the receiver 312. The receiver 312 then converts the OFDM symbol stream from the time domain to the frequency domain using a fast Fourier transform (FFT). The frequency-domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, as well as the reference signal, are recovered and demodulated by determining the most likely signal constellation point transmitted by the base station 304. These soft decisions may be based on channel estimates calculated by a channel estimator. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally transmitted on the physical channel by the base station 304. The data and control signals are then provided to one or more processors 332 that implement Layer-3 (L3) and Layer-2 (L2) functions.

[0109]

[0126] In the downlink, one or more processors 332 provide demultiplexing between transport and logical channels, packet reassembly, decryption, header recovery, and control signal processing to recover IP packets from the core network. The one or more processors 332 are also responsible for error detection.

[0110]

[0127] Similar to the functionality described in connection with downlink transmissions by the base station 304, the one or more processors 332 provide RRC layer functions related to system information (e.g., MIBs, SIBs) acquisition, RRC connection, and measurement reporting; PDCP layer functions associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functions associated with forwarding upper layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, multiplexing MAC SDUs onto transport blocks (TBs), demultiplexing MAC SDUs from TBs, scheduling information reporting, error correction via hybrid automatic repeat request (HARQ), priority handling, and logical channel prioritization.

[0111]

[0128] Channel estimates derived by the channel estimator from a reference signal or feedback transmitted by the base station 304 may be used by the transmitter 314 to select an appropriate coding and modulation scheme and to facilitate spatial processing. The spatial streams generated by the transmitter 314 may be provided to different antenna(s) 316. The transmitter 314 may modulate an RF carrier with the individual spatial streams for transmission.

[0112]

[0129] Uplink transmissions are processed at the base station 304 in a manner similar to that described with respect to the receiver function at the UE 302. The receiver 352 receives signals via its respective antenna(s) 356. The receiver 352 recovers information modulated onto an RF carrier and provides the information to one or more processors 384.

[0113]

[0130] In the uplink, one or more processors 384 provide demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets from the UE 302. The IP packets from the one or more processors 384 may be provided to the core network. The one or more processors 384 are also responsible for error detection.

[0114]

[0131] For convenience, the UE 302, base station 304, and / or network entity 306 are illustrated in FIGS. 3A, 3B, and 3C as including various components that may be configured in accordance with various examples described herein. However, it will be understood that the illustrated components may have different functions in different designs. In particular, various components in FIGS. 3A-3C are optional in alternative configurations, and various aspects include configurations that may vary due to design choice, cost, device use, or other considerations. For example, in FIG. 3A, a particular implementation of the UE 302 may omit the WWAN transceiver(s) 310 (e.g., a wearable device or tablet computer or PC or laptop may have Wi-Fi and / or Bluetooth capabilities without cellular capabilities), or may omit the short-range wireless transceiver(s) 320 (e.g., cellular only, etc.), or may omit the satellite signal receiver 330, or may omit the sensor(s) 344, etc. 3B, a particular implementation of base station 304 may omit WWAN transceiver(s) 350 (e.g., a Wi-Fi “hotspot” access point without cellular capability), or may omit short-range wireless transceiver(s) 360 (e.g., cellular only), or may omit satellite signal receiver 370, etc. For brevity, examples of various alternative configurations are not provided herein but should be readily apparent to one skilled in the art.

[0115]

[0132] The various components of the UE 302, the base station 304, and the network entity 306 may be communicatively coupled to one another via data buses 334, 382, ​​and 392, respectively. In one aspect, the data buses 334, 382, ​​and 392 may form or be part of communication interfaces of the UE 302, the base station 304, and the network entity 306, respectively. For example, when different logical entities are embodied within the same device (e.g., gNB and location server functionality incorporated within the same base station 304), the data buses 334, 382, ​​and 392 may provide communication therebetween.

[0116]

[0133] The components of Figures 3A, 3B, and 3C may be implemented in various ways. In some implementations, the components of Figures 3A, 3B, and 3C may be implemented in one or more circuits, such as, for example, one or more processors and / or one or more ASICs (which may include one or more processors), where each circuit may use and / or incorporate at least one memory component for storing information or executable code used by the circuit to provide its functionality. For example, some or all of the functionality represented by blocks 310-346 may be performed by the processor and memory component(s) of the UE 302 (e.g., by execution of appropriate code and / or by appropriate configuration of the processor components). Similarly, some or all of the functionality represented by blocks 350-388 may be performed by the processor and memory component(s) of the base station 304 (e.g., by execution of appropriate code and / or by appropriate configuration of the processor components). Additionally, some or all of the functionality represented by blocks 390-398 may be performed by processor and memory component(s) of the network entity 306 (e.g., by execution of appropriate code and / or by appropriate configuration of the processor components). For simplicity, various operations, actions, and / or functions are described herein as being performed "by the UE," "by the base station," "by the network entity," etc. However, it should be understood that such operations, actions, and / or functions may actually be performed by particular components or combinations of components of the UE 302, base station 304, network entity 306, etc., such as processors 332, 384, 394, transceivers 310, 320, 350, and 360, memories 340, 386, and 396, ProSe modules 342, 388, and 398, etc.

[0117]

[0134] In some designs, the network entity 306 may be implemented as a core network component. In other designs, the network entity 306 may be separate from the network operator or operation of the cellular network infrastructure (e.g., the NG RAN 220 and / or the 5GC 210 / 260). For example, the network entity 306 may be a component of a private network that may be configured to communicate with the UE 302 via the base station 304 or independently of the base station 304 (e.g., via a non-cellular communication link such as WiFi).

[0118]

[0135] Proximity services allow devices in close proximity to each other to communicate over direct wireless links such as PC5, which is a short-range direct communication interface between vehicles and vulnerable road users (VRUs) such as pedestrians and roadside equipment. 5G ProSe services and their use cases include, but are not limited to: 5G ProSe Direct Discovery: Allows a UE to discover other UEs using the same application. Use cases include public safety, social media, and service announcements. Unicast Mode 5G ProSe Direct Communication: Enables direct communication between two devices without requiring a connection to a cellular or other wireless network. Use cases include interactive gaming between two devices, augmented reality (XR) interactions between a mobile device and XR glasses, headsets, or wearables, and communication between public safety personnel when the network is down. 5G ProSe communication via 5G ProSe UE-to-Network (U2N) relay: Enables the extension of ProSe direct communication onto the network. Use cases include, for example, coverage extension to out-of-coverage devices or devices with very poor connectivity to the network, for both public safety and commercial use.

[0119]

[0136] According to one or more examples, during ProSe U2N relay operation, the relay UE processes and / or routes remote UE network traffic at Layer 2 or Layer 3. In the case of Layer 3 relay, network traffic is relayed at the PDCP layer or above, and security is implemented with a hop-by-hop security mechanism using PC5 packet PDCP security between the remote UE and the relay UE, and Uu PDCP security between the relay UE and the base station. The remote UE does not have end-to-end security with the network. Note that the same principles may apply to protocols other than PC5 and may also apply to non-ProSe sidelink communications.

[0120]

[0137] According to one or more examples, there are two different security procedures for a UE performing Layer 3 (L3) U2N relay operation: a user plane (UP)-based procedure and a control plane (CP)-based procedure. These UP- and CP-based procedures enable the establishment of a secure link between a remote UE and a relay UE. The network and / or the UE may perform only one or both of these types of procedures. These procedures are described in more detail in Figures 4, 5A, and 5B.

[0121]

[0138] 4 is a signaling and event diagram 400 illustrating UP-based security procedures involving an L3 U2N relay. Event diagram 400 illustrates interactions between a remote UE 402, a 5G Direct Discovery Name Management Function (DDNMF) serving the remote UE 402 (hereinafter referred to as "remote DDNMF 404"), a ProSe Key Management Function (PKMF) serving the remote UE 402 (hereinafter referred to as "remote PKMF 406"), a Home Subscriber Server (HSS) serving the remote UE 402 (hereinafter referred to as "remote HSS 408"), a UE acting as a U2N relay (hereinafter referred to as "relay UE 410"), a DDNMF serving the relay UE 410 (hereinafter referred to as "relay DDNMF 412"), and a PKMF serving the relay UE 410 (hereinafter referred to as "relay PKMF 414"). The remote DDNMF 404, the remote PKMF 406, and the remote HSS 408 are in the home network of the remote UE 402, and the relay DDNMF 412 and the relay PKMF 414 are in the home network of the relay UE 410.

[0122]

[0139] 4, at 416, the remote UE 402 optionally queries the remote DDNMF 404 to obtain the address of the remote PKMF 406. At 418, the remote UE 402 obtains discovery security material from the remote PKMF 406. During 418, the remote PKMF 406 may communicate with the relay PKMF 414 as needed to obtain discovery security material needed by the remote UE 402 to discover and connect to the relay UE 410, for example. In some aspects, the remote PKMF 406 is configured or pre-configured to know a potential list of possible PKMFs, including the relay PKMF 412.

[0123]

[0140] 4, at 420, the relay UE 410 optionally queries the relay DDNMF 412 to obtain the address of the relay PKMF 414. At 422, the relay UE 410 obtains discovery material from the relay PKMF 414.

[0124]

[0141] In the example shown in FIG. 4, at 424, the remote UE 402 sends a ProSe Relay User Key (PRUK) request to the remote PKMF 406. At 426, the remote UE 402 receives a PRUK response from the remote PKMF 406. The PRUK response includes a PRUK and a PRUK identifier (PRUK ID). The PRUK is used to derive a key for a secure connection between the remote UE 042 and the relay UE 410, such as a PC5 key. The PRUK is identified by its PRUK ID. In some aspects, the PRUK ID is similar to a UE ID.

[0125]

[0142] 4, at 428, the remote UE 402 performs a discovery procedure to find the relay UE 410. The remote UE 402 discovers the relay UE 410 based on a limited discovery procedure.

[0126]

[0143] In the example shown in FIG. 4, the remote UE 402 establishes a secure connection with the relay UE. To do so, at 430, the remote UE 402 sends a direct communication request to the relay UE 410 to initiate connection establishment. In some aspects, the direct communication request includes a relay service code (RSC) and a freshness parameter. The remote UE 402 will initially send the direct communication request including the PRUK ID that the remote UE 402 received at 426. However, if too much time has passed between 426 and 430, that PRUK ID may have expired or may otherwise be invalid. In that situation, the remote UE 402 may send a second direct communication request including a subscriber hiding identifier (SUCI) instead.

[0127]

[0144] In particular, both the PRUK ID and the SUCI contain home routing information such as a Home Public Land Mobile Network (HPLMN) ID, etc. Thus, after the relay PKMF 414 receives the key request at 432, the relay PKMF 414 can determine the home network of the remote UE 402 from the PRUK ID or the SUCI, and therefore the address of the remote PKMF 406.

[0128]

[0145] The relay UE 410 obtains a PC5 key from the remote PKMF 406 via the relay PKMF 414. In the example shown in FIG. 4, at 432, the relay UE 410 forwards the information in the direct communication request to the relay PKMF 414, for example, via a key request. At 434, the relay PKMF 414 forwards the key request to the remote PKMF 406 to check whether the remote UE 402 is authorized to use the service. The remote PKMF 406 checks the PRUK ID or SUCI, RSC, and other parameters received from the remote UE 402. At 436, the remote PKMF 406 queries the remote HSS 408 to fetch Generic Bootstrapping Architecture (GBA) Push Information (GPI) or Authentication Vector (AV) for the remote UE 402. At 438, the remote PKMF 406 sends a key response to the relay PKMF 414, the key response including a PC5 key (KNRP) or other type of key, and optionally a GPI if, for example, authentication to the network is required. Thus, the KNRP is used for a secure connection from the remote UE 402 to the relay UE 410, and the GPI is used to authenticate the remote UE 402 to the network to which the relay UE 410 will grant the remote UE 402 access. At 440, the relay PKMF 414 forwards the key response to the relay UE 410.

[0129]

[0146] At 442, the relay UE 410 sends a direct security mode command to the remote UE 402, where the direct security mode command includes the PC5 key and, optionally, a GPI if authentication is required. If the PRUK ID provided to the relay UE 410 in the direct communication request at 430 was valid (i.e., correct and not expired), the PC5 key provided by the relay UE 410 will also be correct and the relay UE 410 will be successful in authorization at 444, which the remote UE 402 will report by sending a direct security mode complete message to the relay UE 410 at 446. At 448, the relay UE 410 will authorize the remote UE 402, and at 450 the relay UE 410 will send a direct communication accept message to the remote UE 402.

[0130]

[0147] If the network decides to refresh the PRUK or if the remote UE 402 does not have a valid PRUK, a new PRUK can be established based on the GPI, allowing the remote UE 402 to authenticate and establish a PC5 key with the network without any interaction.

[0131]

[0148] 5A and 5B are signaling and event diagrams illustrating portions of a CP-based security procedure 500 involving an L3 U2N relay. Figures 5A and 5B illustrate interactions between a remote UE 502, an Access and Mobility Management Function (AMF) serving the remote UE 502 (hereinafter referred to as "remote AMF 504"), an Authentication Server Function (AUSF) serving the remote UE 502 (hereinafter referred to as "remote AUSF 506"), a Unified Data Management (UDM) server serving the remote UE 502 (hereinafter referred to as "remote UDM 508"), a ProSe Anchor Function (PAnF) serving the remote UE 502 (hereinafter referred to as "remote PAnF 510"), a UE acting as a U2N relay (hereinafter referred to as "relay UE 512"), and an AMF serving the relay UE 512 (hereinafter referred to as "relay AMF 514"). The remote AMF 504, the remote AUSF 506, the remote UDM 508, and the remote PAnF 510 are in the home network of the remote UE 502, and the relay AMF 514 is the home network of the relay UE 512. Figure 5A shows an example when the remote UE 502 has a valid PRUK ID, and Figure 5B shows an example when the remote UE 502 does not have a valid PRUK ID or is provided with a SUCI instead of a PRUK ID.

[0132]

[0149] In the example shown in Figure 5A, the remote UE 502 attaches to the network at 516, and the relay UE 512 attaches to the network at 518. The remote UE 502 is provisioned with security material and PC5 security policies from a Policy Control Function (PCF) or from a 5G DDNMF, such as the one shown in Figure 4. At 520, the remote UE 502 performs a discovery procedure to find the relay UE 512. The remote UE 502 discovers the relay UE 512 based on a limited discovery procedure.

[0133]

[0150] At 522, the remote UE 502 initiates establishment of a secure connection with the relay UE 512 by sending a direct communication request. In some aspects, the direct communication request includes a PRUK ID if the remote UE 502 possesses one, but if the remote UE 502 does not have one or if the PRUK ID has expired or is invalid, the direct communication request will include a SUCI. At 524, the relay UE 512 sends a relay key request to the relay AMF 514. The relay key request will include either the PRUK ID or the SUCI along with a transaction identifier (TXI). At 526, the relay AMF 514 authorizes the relay UE, for example, to determine whether the relay UE 512 can make such a request. In the example shown in FIG. 5A, the relay UE 512 has such authority.

[0134]

[0151] The relay AMF 514 may determine the home network of the remote UE 502 from the PRUK ID or SUCI, and therefore the address of the remote AUSF 506. At 528, the relay AMF 514 sends an authentication request to the remote AUSF 506, for example, to determine whether the remote UE 502 is authorized to use ProSe services. In the example shown in FIG. 5A, the remote UE 502 has such authorization.

[0135]

[0152] In FIG. 5A , at 530, the remote AUSF 506 sends a ProSe Key Registration Request to the remote PAnF 510, where the request includes the PRUK ID and RSC. At 532, the remote AUSF 506 receives a ProSe Key Registration Response from the remote PAnF 510, where the response includes the PRUK. At 534, the remote AUSF 506 generates a security key (KNRP) for the secure connection between the remote UE 502 and the relay UE 512. In the example shown in FIG. 5A , the security key is a PC5 key to be used for a secure PC5 link between the remote UE 502 and the relay UE 512, although a protocol other than PC5 may be used instead. At 536, the remote AUSF 506 sends a ProSe Authentication Response to the relay AMF 514, where the ProSe Authentication Response includes the security key KNRP. At 538, the relay AMF 514 forwards the security key KNRP to the relay UE 512, for example, in a Relay Key Response message.

[0136]

[0153] At 540, the relay UE 512 sends a direct security mode command to the remote UE 502 indicating success. At 542, the remote UE 502 generates its own copy of the security key KNRP. At 544, the remote UE 502 sends a direct security mode complete message to the relay UE 512. At 546, the relay UE 512 sends a direct communication accept message to the remote UE 502. In this manner, a secure connection between the remote UE 502 and the relay UE 512 is established.

[0137]

[0154] In the example shown in FIG. 5B , the direct communication request at 522, the relay key request at 524, and the ProSe authentication request sent at 528 do not include a PRUK ID, but instead include a SUCI. In this scenario, at 548, the remote AUSF 506 queries the remote UDM 508 to obtain an authentication vector (AV). At 550, the remote AUSF 506 sends a ProSe authentication response message to the relay AMF 514. At 552, the relay AMF 514 sends a relay authentication request to the relay UE 512, where the relay authentication request includes a transaction identifier TXI. At 554 and 556, the relay UE 512 exchanges Extensible Authentication Protocol (EAP) messages. At 558, the relay UE 512 issues a relay authentication response including the TXI. At 560, the relay AMF 514 issues another ProSe authentication request to the remote AUSF 506. At 562, the remote UE 502 generates a PRUK and PRUK ID, and at 564, the remote AUSF 506 generates its own copy of the PRUK and PRUK ID. At 566, the remote AUSF 506 sends a ProSe registration request to the remote PAnF 510, where the ProSe registration request includes the SUPI, PRUK, PRUK ID, and RSC. At 568, the remote PAnF 510 sends a ProSe key registration response to the remote AUSF 506. From there, the process continues from 534 shown in FIG. 5A and is therefore not repeated here.

[0138]

[0155] Figures 6 and 7 are signaling and event diagrams illustrating a process called resynchronization, which is performed when authentication between a remote UE and a home network fails, for example, at 444 in Figure 4 or after 554 in Figure 5A. Figure 6 illustrates a resynchronization process 600 using user plane-based security procedures, and Figure 7 illustrates a resynchronization process 700 using control plane-based security procedures.

[0139]

[0156] In the example shown in FIG. 6, the remote UE 402 receives a direct security mode command from the relay UE 410 (at 442 in FIG. 4) along with the security key KNRP and optional GPI, but at 602, authorization fails, so at 604 the remote UE 402 notifies the relay UE 410 of the failure by sending a direct security mode failure message including a random key (RAND) and an authentication token (AUTS).

[0140]

[0157] At 606, the relay UE 410 issues a key request to the relay PKMF 414, which also includes the RAND, AUTS, and network routing information for the home network of the remote UE 402, such as its HPLMN ID. At 608, the relay PKMF 414 forwards this request to the remote PKMF 406. At 610, the relay PKMF 414 queries the remote HSS 408 to obtain the AV and / or GPI for the remote UE 402. At 612, the remote HSS 408 provides a key response to the relay PKMF 414. At 614, the relay PKMF 414 forwards the key response to the relay UE 410.

[0141]

[0158] At 616, the relay UE 410 issues another direct security command to the remote UE 402, and this time the authorization is successful at 618. At 620, the remote UE 402 sends a direct security mode complete message to the relay UE 410.

[0142]

[0159] In the example shown in FIG. 7, the remote UE 502 receives the EAP message at 442, but the authorization fails at 702, so at 704 the remote UE 502 notifies the relay UE 512 of the failure.

[0143]

[0160] At 706, the relay UE 512 issues a key request to the relay AMF 514, where the key request includes network routing information for the home network of the remote UE 502, such as its HPLMN ID. At 708, the relay AMF 514 forwards this request to the remote AUSF 506. At 710, the remote AUSF 506 queries the remote UDM 508 for security information for the remote UE 502. At 712, the remote AUSF 506 provides a key response to the relay AMF 514. At 714, the relay AMF 514 forwards the key response to the relay UE 512.

[0144]

[0161] At 716, the relay UE 512 issues another EAP message to the remote UE 502, and this time authorization is successful at 718. At 720, the remote UE 502 notifies the relay UE 512 that authentication was successful.

[0145]

[0162] 6, it is noted that the relay UE 410 is expected to provide network address information for the home network of the remote UE 402, e.g., the HPLMN ID, that is part of the key request message in 606. However, the direct security mode failure message in 604 does not include the PRUK, PRUK ID, SUCI, or any other information from which the home network address of the remote UE 402 can be derived. 7, the relay UE 512 is expected to provide network address information for the home network of the remote UE 502, e.g., the HPLMN ID, that is part of the key request message in 706, but the EAP message in 704 does not include the PRUK, PRUK ID, SUCI, or any other information from which the home network address of the remote UE 502 can be derived. It is not specified how the relay UE 410 or relay UE 512 should know this information.

[0146]

[0163] Accordingly, provided herein are methods and systems for providing home network routing information (HNRI) of a remote UE following an authentication failure during establishment of U2N relay communication. The HNRI may include a home network address or any other information that identifies the home network of the remote UE.

[0147]

[0164] Figures 8A, 8B, and 8C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE according to an aspect of the disclosure. Each of Figures 8A-8C illustrates a portion of the user plane-based security procedure illustrated in Figure 4 and the resynchronization procedure illustrated in Figure 6. The elements of Figures 8A-8C are substantially identical to similarly numbered components in Figures 4 and 6, and therefore, detailed descriptions thereof will not be repeated here.

[0148]

[0165] FIG. 8A illustrates an approach 800 in which a remote UE 402 provides an HNRI to a relay UE 410, which forwards the HNRI to a relay PKMF 414. In the example illustrated in FIG. 8A, the remote UE 402 receives a direct security mode command, as in 442 of FIG. 4, and authentication fails, as in 602 of FIG. 6. In a first option, the remote UE 402 sends a direct security mode failure message to the relay UE 410, as in 604 of FIG. 6, and the HNRI is provided to the relay UE 410 in a separate message at 802. In a second option, the HNRI may be included in a modified direct security mode failure message at 804. However, the direct security mode failure message is not secured, and therefore, any device along the route will have access to the unencrypted payload. Regardless of the option employed, in this approach, the relay UE 410 does not need to store the PRUK ID. Instead, at 806, the relay UE 410 forwards the HNRI as part of the key request message to the relay PKMF 414. At 608, the relay PKMF 414 uses the HNRI to know where to send the key request.

[0149]

[0166] In some aspects, if the remote UE 402 does not have a valid PRUK ID or if the PRUK ID is in a 64-bit string (in which case the PRUK identifies only the remote UE 402 and not the home network), the HNRI may include the HPLMN ID for the remote UE 402.

[0150]

[0167] In some aspects, if the remote UE 402 has a PRUK ID that is in network access identifier (NAI) format, the HNRI may comprise the PRUK ID, or may comprise the PRUK ID but with the username portion set to a random value or otherwise obscured so that the identity of the remote UE 402 cannot be determined from the HNRI, for example, if the HNRI is intercepted in transmission.

[0151]

[0168] In some aspects, the HNRI (and optionally the entire message in which the HNRI is sent) is confidentiality and integrity protected using the discovery security material received by the remote PKMF 406 at 418 of FIG.

[0152]

[0169] 8B shows a technique 808 in which the relay UE 410 provides an HNRI to the relay PKMF 414. In the example shown in FIG. 8B, when the relay UE 410 receives the direct communication request at 430 in FIG. 4, the relay UE 410 stores the HNRI associated with the remote UE 402 at 810, which the relay UE 410 is able to do because both the PRUK and SUCI contain network identity information and user identity information. Then, if the relay authorization fails at 602, the relay UE 410 receives a notification at 604, fetches the HNRI of the remote UE 402 at 812, and sends the HNRI to the relay PKMF 414 in a key request at 814. The relay PKMF 414 uses the HNRI to know where to send the key request at 608.

[0153]

[0170] FIG. 8C illustrates a technique 816 by which the relay PKMF 414 stores the HNRI. In the example shown in FIG. 8C, when the relay UE 410 receives the direct communication request at 430 in FIG. 4, the relay UE 410 generates and stores a transaction identifier (TXI) at 818, or reuses the transaction identifier generated by the control plane process, if one is available. At 820, the relay UE 410 includes the TXI in a key request to the relay PKMF 414, and at 822, the relay PKMF 414 stores a mapping of the TXI to the HNRI of the remote UE 402. Then, if the relay authorization failed at 602, the relay UE 410 receives the notification at 604 and includes the TXI in a second key request to the relay PKMF 414 at 824. At 826, the relay PKMF 414 uses the TXI to fetch the HNRI of the remote UE 402. At 608, the relay PKMF 414 uses the HNRI to know where to send the key request.

[0154]

[0171] Figures 9A, 9B, and 9C are signaling and event diagrams illustrating different approaches for providing home network routing information for a remote UE according to aspects of the present disclosure. Each of Figures 9A-9C illustrates a portion of the user plane-based security procedure illustrated in Figures 5A and 5B and the resynchronization procedure illustrated in Figure 7. The elements of Figures 9A-9C are substantially identical to similarly numbered components in Figures 5A, 5B, and 7, and therefore, detailed descriptions thereof will not be repeated here.

[0155]

[0172] 9A shows a technique 900 in which the remote UE 502 provides an HNRI to the relay UE 512, and the relay UE 512 forwards the HNRI to the relay AMF 514. In the example shown in FIG. 9A, the remote UE 502 receives an EAP message, as at 554 of FIG. 5B, and authorization fails, as at 702 of FIG. 7. In a first option, the remote UE 502 sends an EAP failure message to the relay UE 512, as at 704 of FIG. 7, and the HNRI is provided to the relay UE 512 in a separate message at 902. In a second option, the HNRI may be included in a modified EAP failure message at 904. In this technique, the relay UE 512 does not need to store the PRUK ID. Instead, the relay UE 512 forwards the HNRI to the relay AMF 514 as part of a key request message at 706. The relay AMF 514 uses the HNRI at 708 to know where to send the key request.

[0156]

[0173] In some aspects, if the remote UE 502 does not have a valid PRUK ID or if the PRUK ID is in a 64-bit string (in which case the PRUK identifies only the remote UE 502 and not the home network), the HNRI may include the HPLMN ID for the remote UE 502.

[0157]

[0174] In some aspects, if the remote UE 502 has a PRUK ID that is in network access identifier (NAI) format, the HNRI may comprise the PRUK ID, or may comprise the PRUK ID but with the username portion set to a random value or otherwise obscured so that the identity of the remote UE 502 cannot be determined from the HNRI, for example, if the HNRI is intercepted in transmission.

[0158]

[0175] In some aspects, the HNRI (and optionally the entire message in which the HNRI is sent) is privacy and integrity protected using discovery security material received by the DDNMF or PCF of the remote UE.

[0159]

[0176] 9B shows a technique 906 in which the relay UE 512 provides an HNRI to the relay AMF 514. In the example shown in FIG. 9B, when the relay UE 512 receives a direct communication request at 522 in FIG. 5, the relay UE 512 stores an HNRI associated with the remote UE 502 at 908, which the relay UE 512 can do because both the PRUK and SUCI contain network identity information and user identity information. Then, if the relay authorization fails at 702, the relay UE 512 receives a notification at 704, fetches the HNRI of the remote UE 502 at 910, and sends the HNRI to the relay AMF 514 in a key request at 706. The relay AMF 514 uses the HNRI to know where to send the key request at 708.

[0160]

[0177] 9C shows a technique 912 in which the relay AMF 514 stores the HNRI. In the example shown in FIG. 9C, when the relay UE 512 receives a direct communication request at 522 in FIG. 5, the relay UE 512 generates and stores a transaction identifier (TXI) at 914. At 524, the relay UE 512 includes the TXI in a key request to the relay AMF 514, and at 915, the relay AMF 514 stores a mapping of the TXI to the HNRI of the remote UE 502. If the relay authorization failed at 702, the relay UE 512 receives a notification at 704 and includes the TXI in a second key request to the relay AMF 514 at 918. At 920, the relay AMF 514 uses the TXI to fetch the HNRI of the remote UE 502. The relay AMF 514 uses the HNRI at 708 to know where to send the key request.

[0161]

[0178] 10 is a flowchart of an example process 1000 performed by a remote UE related to a method and system for providing an HNRI of the remote UE following an authentication failure during establishment of U2N relay communication according to an aspect of the present disclosure. In some implementations, one or more process blocks of FIG. 10 may be performed by a first user equipment (UE) (e.g., the UE 104). In some implementations, one or more process blocks of FIG. 10 may be performed by another device or a group of devices that are separate from or include the UE. Additionally or alternatively, one or more process blocks of FIG. 10 may be implemented by one or more components of the UE 302, such as the processor(s) 332, memory 340, WWAN transceiver(s) 310, short-range wireless transceiver(s) 320, satellite signal receiver 330, sensor(s) 344, user interface 346, and ProSe module(s) 342, any or all of which may be means for performing the operations of process 1000.

[0162]

[0179] 10 , process 1000 may include, at block 1010, detecting an authentication failure during establishment of a secure connection with a second UE. In some aspects, the second UE is operating as a UE-to-network (U2N) relay. Means for performing the operations of block 1010 may include processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may detect the authentication failure using the processor(s) 332.

[0163]

[0180] 10 , process 1000 may include, at block 1020, sending a notification of the authentication failure to the second UE and providing home network routing information (HNRI) for the authenticating node in the home network of the first UE to the second UE. Means for performing the operations of block 1020 may include processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may send a notification of the authentication failure to the second UE and provide the HNRI to the second UE using the transmitter(s) 314.

[0164]

[0181] In some aspects, detecting an authentication failure during establishment of the secure connection with the second UE includes detecting an authentication failure during establishment of the secure connection with the second UE acting as a U2N relay.

[0165]

[0182] In some aspects, detecting an authentication failure during establishment of the secure connection with the second UE includes detecting an authentication failure during establishment of a PC5 connection with the second UE.

[0166]

[0183] In some aspects, detecting an authentication failure includes detecting a synchronization failure.

[0167]

[0184] In some aspects, sending a notification of authentication failure to the second UE and providing the second UE with an HNRI for the authenticating node in the home network of the first UE includes sending the notification of authentication failure and the HNRI in the same message.

[0168]

[0185] In some aspects, sending a notification of the authentication failure to the second UE and providing the second UE with an HNRI for the authenticating node in the home network of the first UE includes sending the notification of the authentication failure in a first message and sending the HNRI in a second message.

[0169]

[0186] In some aspects, detecting an authentication failure includes detecting an authentication failure during a user plane security procedure.

[0170]

[0187] In some aspects, detecting an authentication failure during the user plane security procedure includes receiving, from the second UE, a direct security mode command including an authentication challenge, processing the authentication challenge, and detecting a failure of the authentication challenge.

[0171]

[0188] In some aspects, receiving the direct security mode command includes receiving at least one of security material and a GPI for a secure connection with the second UE, and processing the authentication challenge includes processing the authentication challenge included in the GPI.

[0172]

[0189] In some aspects, sending a notification of the authentication failure to the second UE includes sending a direct security mode failure to the second UE.

[0173]

[0190] In some aspects, the direct security mode failure includes an HNRI.

[0174]

[0191] In some aspects, detecting an authentication failure includes detecting an authentication failure during a control plane security procedure.

[0175]

[0192] In some aspects, detecting an authentication failure during the control plane security procedure includes receiving a first EAP message from the second UE including first security information, processing an authentication challenge included in the first security information, and detecting a failure of the authentication challenge.

[0176]

[0193] In some aspects, sending a notification of the authentication failure to the second UE includes sending a second EAP message to the second UE.

[0177]

[0194] In some aspects, the second EAP message includes the HNRI.

[0178]

[0195] In some aspects, providing the HNRI to the second UE includes providing the PRUK ID, or an HNRI extracted from the SUCI or the PRUK ID, to the second UE.

[0179]

[0196] In some aspects, providing the HNRI to the second UE includes providing the HNRI to the second UE with a user identity portion modified to obscure the user identity information.

[0180]

[0197] In some aspects, providing the HNRI to the second UE includes providing the second UE with a confidentiality and integrity protected HNRI based on provisioned discovery security material.

[0181]

[0198] In some aspects, providing the HNRI to the second UE includes providing an HPLMN ID of a home network of the first UE to the second UE.

[0182]

[0199] In some aspects, the authentication node in the home network of the first UE includes a PKMF or an AUSF.

[0183]

[0200] Process 1000 may include additional implementations, such as any single implementation or any combination of implementations described below and / or with respect to one or more other processes described elsewhere herein. While Figure 10 shows example blocks of process 1000, in some implementations, process 1000 may include additional, fewer, different, or differently configured blocks than those shown in Figure 10. Additionally or alternatively, two or more of the blocks of process 1000 may be performed in parallel.

[0184]

[0201] 11 is a flowchart of an example process 1100 performed by a U2N relay UE related to a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication according to an aspect of the disclosure. In some implementations, one or more process blocks of FIG. 11 may be performed by a UE (e.g., the UE 104). In some implementations, one or more process blocks of FIG. 11 may be performed by another device or a group of devices that are separate from or include the UE. Additionally or alternatively, one or more process blocks of FIG. 11 may be implemented by one or more components of the UE 302, such as the processor(s) 332, memory 340, WWAN transceiver(s) 310, short-range wireless transceiver(s) 320, satellite signal receiver 330, sensor(s) 344, user interface 346, and ProSe(s) 342, any or all of which may be means for performing the operations of process 1100.

[0185]

[0202] 11 , process 1100 may include receiving, from the second UE, a notification of an authentication failure during establishment of the secure connection between the second UE and the first UE, at block 1110. Means for performing the operations of block 1110 may include processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may receive the notification of the authentication failure using the receiver(s) 312.

[0186]

[0203] 11 , the process 1100 may include, at block 1120, determining an HNRI for an authentication node in the home network of the second UE (block 1120). Means for performing the operations of block 1120 may include the processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. Means for performing the operations of block 1120 may include the processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may receive information via the receiver(s) 312, store information in and retrieve information from the memory 340, and perform other functions using the processor(s) 332.

[0187]

[0204] For example, in some aspects, the UE 302 may determine an HNRI for an authenticator node in the home network of the second UE by receiving an HNRI from the second UE prior to receiving a notification of authentication failure, storing the HNRI, and retrieving the HNRI in response to receiving a notification of authentication failure. In some aspects, the UE 302 may determine an HNRI for an authenticator node in the home network of the second UE by receiving an HNRI from the second UE as part of a notification of authentication failure. In some aspects, the UE 302 may determine an HNRI for an authenticator node in the home network of the second UE by receiving an HNRI from the second UE after receiving a notification of authentication failure.

[0188]

[0205] 11 , process 1100 may include, at block 1130, transmitting the HNRI for the authenticator node in the home network of the second UE to the authenticator node in the home network of the first UE (block 1130). Means for performing the operations of block 1130 may include processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may transmit the HNRI to the authenticator node in the home network of the first UE using transmitter(s) 314.

[0189]

[0206] In some aspects, receiving notification of an authentication failure includes receiving notification of a synchronization failure.

[0190]

[0207] In some aspects, determining the HNRI includes receiving the HNRI from the second UE before receiving the notification of authentication failure, storing the HNRI, and retrieving the HNRI in response to receiving the notification of authentication failure, receiving the HNRI from the second UE as part of the notification of authentication failure, or receiving the HNRI from the second UE after receiving the notification of authentication failure.

[0191]

[0208] In some aspects, receiving the HNRI from the second UE includes receiving a SUCI.

[0192]

[0209] In some aspects, receiving the HNRI from the second UE includes receiving a PRUK ID.

[0193]

[0210] In some embodiments, the PRUK ID comprises a 64-bit string or NAI format.

[0194]

[0211] In some aspects, receiving a notification of an authentication failure during establishment of the secure connection between the second UE and the first UE includes receiving a notification of an authentication failure during establishment of a PC5 connection.

[0195]

[0212] In some aspects, receiving notification of an authentication failure includes receiving notification of an authentication failure during a user plane security procedure or a control plane security procedure.

[0196]

[0213] In some aspects, determining an HNRI for an authentication node in a home network of the first UE includes determining an HNRI for a PKMF or an AUSF.

[0197]

[0214] In some embodiments, determining the HNRI includes determining the HNRI based on the SUCI.

[0198]

[0215] In some aspects, determining the HNRI includes determining the HNRI based on the PRUK ID.

[0199]

[0216] In some embodiments, the PRUK ID comprises a 64-bit string or NAI format.

[0200]

[0217] In some aspects, determining the HNRI includes determining a HPLMN ID of a home network of the second UE.

[0201]

[0218] Process 1100 may include additional implementations, such as any single implementation or any combination of implementations described below and / or with respect to one or more other processes described elsewhere herein. While Figure 11 shows example blocks of process 1100, in some implementations, process 1100 may include additional, fewer, different, or differently configured blocks than those shown in Figure 11. Additionally or alternatively, two or more of the blocks of process 1100 may be performed in parallel.

[0202]

[0219] FIG. 12 is a flowchart of an example process 1200 performed by a network entity related to a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication according to aspects of the present disclosure. In some implementations, one or more process blocks of FIG. 12 may be performed by a network entity (e.g., the relay PKMF 414, the relay AMF 514, the remote AUSF 506, etc.). In some implementations, one or more process blocks of FIG. 12 may be performed by another device or group of devices that are separate from or include the network entity. Additionally or alternatively, one or more process blocks of FIG. 12 may be performed by one or more components of the network entity 306, such as the processor(s) 394, the memory 396, the network transceiver(s) 390, and the ProSe module(s) 398, any or all of which may be means for performing the process 1200.

[0203]

[0220] 12, process 1200 may include, at block 1210, receiving a request for security material for a secure connection between the first UE and a second UE that is not within the first UE's home network, the request including the TXI, from a first UE. Means for performing the operations of block 1210 may include processor(s) 394, memory 396, or network transceiver(s) 390 of the network entity 306. For example, the network entity 306 may receive the request for the security key using the network transceiver(s) 390.

[0204]

[0221] 12, process 1200 may include, at block 1220, determining an HNRI for the home network of the second UE based on the TXI. Means for performing the operations of block 1220 may include processor(s) 394, memory 396, or network transceiver(s) 390 of network entity 306. For example, processor(s) 394 of network entity 306 may use the TXI to query a database for mapping the TXI to an HNRI stored in memory 396 to return an HNRI for the home network of the second UE.

[0205]

[0222] 12, process 1200 may include determining, based on the HNRI, an authenticator node in a home network of the second UE, at block 1230. Means for performing the operations of block 1230 may include processor(s) 394, memory 396, or network transceiver(s) 390 of the network entity 306. For example, the network entity 306 may use the processor(s) 394 to determine an authenticator node in a home network of the second UE.

[0206]

[0223] 12, process 1200 may include forwarding the request to an authentication node in a home network of the second UE, at block 1240. Means for performing the operations of block 1240 may include processor(s) 394, memory 396, or network transceiver(s) 390 of the network entity 306. For example, the network entity 306 may forward the request using the network transceiver(s) 390.

[0207]

[0224] In some aspects, process 1200 includes receiving, from the first UE, information mapping the TXI to the HNRI and storing the mapping between the TXI and the HNRI.

[0208]

[0225] In some aspects, receiving information mapping the TXI to the HNRI includes receiving a TXI and a SUCI.

[0209]

[0226] In some aspects, receiving information mapping the TXI to the HNRI includes receiving the TXI and a PRUK ID.

[0210]

[0227] In some embodiments, the PRUK ID comprises a 64-bit string or an NAI.

[0211]

[0228] In some aspects, the HNRI includes a HPLMN ID of a home network of the second UE.

[0212]

[0229] In some aspects, the authentication node in the home network of the second UE includes a PKMF or an AUSF.

[0213]

[0230] Process 1200 may include additional implementations, such as any single implementation or any combination of implementations described below and / or with respect to one or more other processes described elsewhere herein. While Figure 12 shows example blocks of process 1200, in some implementations, process 1200 may include additional, fewer, different, or differently configured blocks than those shown in Figure 12. Additionally or alternatively, two or more of the blocks of process 1200 may be performed in parallel.

[0214]

[0231] 13 illustrates an exemplary electronic device 1300, represented as a series of interrelated functional modules. In one aspect, the electronic device 1300 may be a remote UE.

[0215]

[0232] The electronic device 1300 may include a module 1310 for detecting an authentication failure during establishment of a secure connection with a second UE that may act as a U2N relay. In an aspect, the module 1310 may correspond to the processor(s) 332, the memory 340, and / or the ProSe module 342 of the UE 302.

[0216]

[0233] The electronic device 1300 may include a module 1320 for, in response to detecting the authentication failure, sending a notification of the authentication failure to the second UE and providing the second UE with an HNRI for the authenticating node in the home network of the first UE. In an aspect, the module 1320 may correspond to the processor(s) 332, the memory 340, and / or the ProSe module 342 of the UE 302.

[0217]

[0234] 14 illustrates an exemplary electronic device 1400, represented as a series of interrelated functional modules. In one aspect, the electronic device 1400 may be a U2N relay UE.

[0218]

[0235] The electronic device 1400 may include a module 1410 for receiving, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE. In an aspect, the module 1410 may correspond to the processor(s) 332, the memory 340, and / or the ProSe module 342 of the UE 302.

[0219]

[0236] The electronic device 1400 may include a module 1420 for determining an HNRI for an authentication node in a home network of the second UE. In an aspect, the module 1420 may correspond to the processor(s) 332, the memory 340, and / or the ProSe module 342 of the UE 302.

[0220]

[0237] The electronic device 1400 may include a module 1430 for transmitting the HNRI for the authenticator node in the home network of the second UE to the authenticator node in the home network of the first UE. In an aspect, the module 1430 may correspond to the processor(s) 332, the memory 340, and / or the ProSe module 342 of the UE 302.

[0221]

[0238] 15 illustrates an exemplary electronic device 1500, represented as a series of interrelated functional modules. In one aspect, the electronic device 1500 may be a network node, such as a PKMF, an AMF, or an AUSF.

[0222]

[0239] The electronic device 1500 may include a module 1510 for receiving, from a first UE, a request for security material for a secure connection between the first UE and a second UE that is not within the first UE's home network, the first request including the TXI. In an aspect, the module 1510 may correspond to the processor(s) 394, the memory 396, the network transceiver(s) 390, and the ProSe module(s) 398 of the network entity 306.

[0223]

[0240] The electronic device 1500 may include a module 1520 for determining an HNRI for a home network of the second UE based on the TXI. In an aspect, the module 1520 may correspond to the processor(s) 394, the memory 396, the network transceiver(s) 390, and the ProSe module(s) 398 of the network entity 306.

[0224]

[0241] The electronic device 1500 may include a module 1530 for determining an authenticator node in a home network of the second UE based on the HNRI. In an aspect, the module 1530 may correspond to the processor(s) 394, the memory 396, the network transceiver(s) 390, and the ProSe module(s) 398 of the network entity 306.

[0225]

[0242] The electronic device 1500 may include a module 1540 for forwarding the request to an authentication node in a home network of the second UE. In an aspect, the module 1540 may correspond to the processor(s) 394, the memory 396, the network transceiver(s) 390, and the ProSe module(s) 398 of the network entity 306.

[0226]

[0243] 16 is a flowchart of an example process 1600 performed by a remote UE related to a method and system for providing an HNRI of the remote UE following an authentication failure during establishment of U2N relay communication with the U2N relay UE, according to an aspect of the present disclosure. In some implementations, one or more process blocks of FIG. 16 may be performed by a UE (e.g., the UE 104). In some implementations, one or more process blocks of FIG. 16 may be performed by another device or a group of devices that are separate from or include the UE. Additionally or alternatively, one or more process blocks of FIG. 16 may be implemented by one or more components of the UE 302, such as the processor(s) 332, memory 340, WWAN transceiver(s) 310, short-range wireless transceiver(s) 320, satellite signal receiver 330, sensor(s) 344, user interface 346, and ProSe module(s) 342, any or all of which may be means for performing the operations of process 1600.

[0227]

[0244] 16 , the process 1600 may include, in response to an authentication failure during establishment of the secure connection with the second UE, sending a notification of the authentication failure to the second UE at block 1610. Means for performing the operations of block 1610 may include the processor(s) 332, the memory 340, or the WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may send the notification of the authentication failure to the second UE using the transmitter(s) 314.

[0228]

[0245] 16 , the process 1600 may include providing the HNRI for the authentication node in the home network of the first UE to the second UE at block 1620. Means for performing the operations of block 1620 may include the processor(s) 332, the memory 340, or the WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may provide the HNRI to the second UE using the transmitter(s) 314.

[0229]

[0246] In some aspects, detecting an authentication failure during establishment of the secure connection with the second UE includes at least one of detecting an authentication failure during establishment of the secure connection with the second UE acting as a U2N relay, detecting an authentication failure during establishment of a PC5 connection with the second UE, or detecting a synchronization failure.

[0230]

[0247] In some aspects, sending a notification of authentication failure to the second UE and providing the second UE with an HNRI for the authenticating node in the home network of the first UE includes sending the notification of authentication failure and the HNRI in the same message, or sending the notification of authentication failure in a first message and sending the HNRI in a second message.

[0231]

[0248] In some aspects, detecting an authentication failure includes detecting an authentication failure during a user plane security procedure.

[0232]

[0249] In some aspects, sending the notification of the authentication failure to the second UE includes sending a direct security mode failure message to the second UE, the direct security mode failure message including the HNRI.

[0233]

[0250] In some aspects, detecting an authentication failure includes detecting an authentication failure during a control plane security procedure.

[0234]

[0251] In some aspects, providing the HNRI to the second UE includes providing at least one of a PRUK ID or an HNRI extracted from the SUCI or the PRUK ID to the second UE.

[0235]

[0252] In some aspects, providing the HNRI to the second UE includes at least one of: modifying a user identity portion of the HNRI to obfuscate user identity information and providing the HNRI with the modified user identity portion to the second UE; confidentiality or integrity protecting the HNRI based on provisioned discovery security material and providing the confidentiality and / or integrity protected HNRI to the second UE; or providing an HPLMN identifier of the home network of the first UE to the second UE. In some aspects, the HNRI is confidentiality protected based on the provisioned security material. In some aspects, the HNRI is integrity protected based on the provisioned security material. In some aspects, the HNRI is both confidentiality and integrity protected based on the provisioned security material.

[0236]

[0253] In some aspects, providing the HNRI to the second UE includes providing an HPLMN identifier of a home network of the first UE to the second UE.

[0237]

[0254] In some aspects, the authentication node in the home network of the first UE includes a PKMF or an AUSF.

[0238]

[0255] Process 1600 may include additional implementations, such as any single implementation or any combination of implementations described below and / or with respect to one or more other processes described elsewhere herein. Although Figure 16 shows example blocks of process 1600, in some implementations, process 1600 may include additional, fewer, different, or differently configured blocks than those shown in Figure 16. Additionally or alternatively, two or more of the blocks of process 1600 may be performed in parallel.

[0239]

[0256] 17 is a flowchart of an example process 1700 performed by a U2N relay UE related to a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication with the remote UE, according to an aspect of the disclosure. In some implementations, one or more process blocks of FIG. 17 may be performed by a UE (e.g., the UE 104). In some implementations, one or more process blocks of FIG. 17 may be performed by another device or a group of devices that are separate from or include the UE. Additionally or alternatively, one or more process blocks of FIG. 17 may be implemented by one or more components of the UE 302, such as the processor(s) 332, memory 340, WWAN transceiver(s) 310, short-range wireless transceiver(s) 320, satellite signal receiver 330, sensor(s) 344, user interface 346, and ProSe module(s) 342, any or all of which may be means for performing the operations of process 1700.

[0240]

[0257] 17, the process 1700 may include receiving, from the second UE, a notification of an authentication failure during establishment of the secure connection between the second UE and the first UE, at block 1710. Means for performing the operations of block 1710 may include the processor(s) 332, the memory 340, or the WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may receive the notification of the authentication failure using the receiver(s) 312.

[0241]

[0258] 17, process 1700 may include receiving, from the second UE, an HNRI for the first authentication node in the home network of the second UE, at block 1720. Means for performing the operations of block 1720 may include processor(s) 332, memory 340, or WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may receive the HNRI using the receiver(s) 312.

[0242]

[0259] 17, the process 1700 may include transmitting the HNRI for the first authenticator node in the home network of the second UE to a second authenticator node in the home network of the first UE, at block 1730. Means for performing the operation of block 1730 may include the processor(s) 332, the memory 340, or the WWAN transceiver(s) 310 of the UE 302. For example, the UE 302 may transmit, using the transmitter(s) 314, the HNRI for the first authenticator node in the home network of the second UE to the second authenticator node in the home network of the first UE.

[0243]

[0260] In some aspects, receiving notification of an authentication failure includes receiving notification of a synchronization failure.

[0244]

[0261] In some aspects, receiving the HNRI from the second UE includes receiving the HNRI from the second UE before receiving the notification of authentication failure, storing the HNRI, and retrieving the HNRI in response to receiving the notification of authentication failure.

[0245]

[0262] In some aspects, the notification of authentication failure includes an HNRI, and receiving the HNRI from the second UE includes receiving the HNRI from the second UE as part of the notification of authentication failure.

[0246]

[0263] In some aspects, receiving the HNRI from the second UE includes receiving the HNRI from the second UE after receiving a notification of authentication failure.

[0247]

[0264] In some aspects, receiving the HNRI from the second UE includes receiving a SUCI.

[0248]

[0265] In some aspects, receiving the HNRI from the second UE includes receiving a PRUK ID.

[0249]

[0266] In some aspects, the PRUK ID comprises at least one of a 64-bit string or an NAI.

[0250]

[0267] In some aspects, receiving a notification of an authentication failure during establishment of the secure connection between the second UE and the first UE includes receiving a notification of an authentication failure during establishment of a PC5 connection.

[0251]

[0268] In some aspects, receiving notification of an authentication failure includes receiving notification of an authentication failure during at least one of a user plane security procedure or a control plane security procedure.

[0252]

[0269] In some aspects, determining the HNRI for the first authentication node in the home network of the second UE includes determining the HNRI for at least one of a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF) in the home network of the second UE.

[0253]

[0270] Process 1700 may include additional implementations, such as any single implementation or any combination of implementations described below and / or with respect to one or more other processes described elsewhere herein. While Figure 17 shows example blocks of process 1700, in some implementations, process 1700 may include additional, fewer, different, or differently configured blocks than those shown in Figure 17. Additionally or alternatively, two or more of the blocks of process 1700 may be performed in parallel.

[0254]

[0271] FIG. 18 is a flowchart of an example process 1800 performed by a network entity related to a method and system for providing an HNRI of a remote UE following an authentication failure during establishment of U2N relay communication between the remote UE and a U2N relay UE according to aspects of the present disclosure. In some implementations, one or more process blocks of FIG. 18 may be performed by a network entity (e.g., a PKMF or an AMF). In some implementations, one or more process blocks of FIG. 18 may be performed by another device or group of devices that are separate from or include the network entity. Additionally or alternatively, one or more process blocks of FIG. 18 may be performed by one or more components of the network entity 306, such as the processor(s) 394, memory 396, network transceiver(s) 390, and ProSe module(s) 398, any or all of which may be means for performing process 1800.

[0255]

[0272] 18 , process 1800 may include, at block 1810, receiving a request for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network from a first UE in a first home network of the network entity, the request including the TXI. Means for performing the operations of block 1810 may include processor(s) 394, memory 396, or network transceiver(s) 390 of the network entity 306. For example, the network entity 306 may receive the request for security material using the network transceiver(s) 390.

[0256]

[0273] 18 , process 1800 may include determining an HNRI for the second home network based on the TXI, at block 1820. Means for performing the operation of block 1820 may include processor(s) 394, memory 396, or network transceiver(s) 390 of network entity 306. For example, network entity 306 may determine the HNRI for the second home network using processor(s) 394.

[0257]

[0274] 18 , process 1800 may include, at block 1830, determining an authenticating node in the second home network based on the HNRI for the second home network. Means for performing the operations of block 1830 may include processor(s) 394, memory 396, or network transceiver(s) 390 of the network entity 306. For example, the network entity 306 may use the processor(s) 394 to determine an authenticating node in the second home network.

[0258]

[0275] 18 , the process 1800 may include forwarding the request to an authentication node in the second home network at block 1840. Means for performing the operations of block 1840 may include the processor(s) 394, the memory 396, or the network transceiver(s) 390 of the network entity 306. For example, the network entity 306 may forward the request to the authentication node in the second home network using the network transceiver(s) 390.

[0259]

[0276] In some aspects, process 1800 includes receiving, from the first UE, mapping information mapping the TXI to an HNRI for the second home network, and storing the mapping information.

[0260]

[0277] In some aspects, receiving the mapping information includes receiving a TXI and at least one of a SUCI or a PRUK ID.

[0261]

[0278] In some aspects, the PRUK ID comprises at least one of a 64-bit string or an NAI.

[0262]

[0279] In some aspects, the HNRI includes an HPLMN identifier of the second home network.

[0263]

[0280] In some aspects, the authentication node in the second home network includes at least one of a PKMF or an AUSF.

[0264]

[0281] In some aspects, the network entity includes at least one of a PKMF or an AMF.

[0265]

[0282] Process 1800 may include additional implementations, such as any single implementation or any combination of implementations described below and / or with respect to one or more other processes described elsewhere herein. While Figure 18 shows example blocks of process 1800, in some implementations, process 1800 may include additional, fewer, different, or differently configured blocks than those shown in Figure 18. Additionally or alternatively, two or more of the blocks of process 1800 may be performed in parallel.

[0266]

[0283] 19 illustrates an exemplary electronic device 1900 represented as a series of interrelated functional modules. In one aspect, the electronic device 1900 may be a remote UE or a U2N relay UE. In some aspects, the electronic device 1900 may include a processing system 1902 including a processor circuit 1904 and a memory circuit 1906 that stores code and is coupled to the processor circuit 1904 via one or more system buses 1908. In some aspects, the processing system 1902 is coupled to a transceiver circuit 1910 and one or more antennas 1912. In some aspects, the processing system 1902 includes a transmitting component 1914 for managing messages and signals transmitted by the electronic device 1900. In some aspects, the processing system 1902 includes a receiving component 1916 for managing messages and signals received by the electronic device 1900.

[0267]

[0284] In some aspects, the processing system 1902 is configured to cause the electronic device 1900 to, in response to an authentication failure during establishment of the secure connection with the second UE, send a notification of the authentication failure to the second UE. The processing system 1902 is further configured to cause the electronic device to provide the second UE with an HNRI for an authenticator node in the home network of the electronic device 1900.

[0268]

[0285] In other aspects, processing system 1902 is configured to cause electronic device 1900 to receive, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and electronic device 1900. Processing system 1902 is further configured to cause electronic device 1900 to receive, from the second UE, an HNRI for a first authenticator node in a home network of the second UE. Processing system 1902 is further configured to cause electronic device 1900 to transmit, to a second authenticator node in the home network of electronic device 1900, the HNRI for the first authenticator node in the home network of the second UE.

[0269]

[0286] 20 illustrates an exemplary electronic device 2000 represented as a series of interrelated functional modules. In one aspect, the electronic device 2000 may be a remote network entity such as a PKMF or AMF. In some aspects, the electronic device 2000 may include a processing system 2002 including a processor circuit 2004 and a memory circuit 2006 that stores code and is coupled to the processor circuit 2004 via one or more system buses 2008. In some aspects, the processing system 2002 is coupled to a network interface circuit 2010. In some aspects, the processing system 2002 includes a transmitting component 2012 for managing messages and signals transmitted by the electronic device 2000. In some aspects, the processing system 2002 includes a receiving component 2014 for managing messages and signals received by the electronic device 2000.

[0270]

[0287] In some aspects, the processing system 2002 is configured to cause the electronic device 2000 to receive, from a first UE in a first home network of the network entity, a request for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network, the request including a TXI. The processor system 2002 is further configured to determine an HNRI for the second home network based on the TXI. The processor system 2002 is further configured to determine an authenticator node in the second home network based on the HNRI for the second home network. The processor system 2002 is further configured to forward the request to the authenticator node in the second home network.

[0271]

[0288] As will be appreciated, a technical advantage of the techniques disclosed herein is that they specify how an HNRI for an authenticator node in the home network of a remote UE should be provided to an authenticator node in the home network of a U2N relay UE in situations where notification of authentication failure or resynchronization during establishment of U2N relay communications is required (something that current standards do not specify).

[0272]

[0289] In the above detailed description, it can be seen that different features are grouped together in the examples. This method of disclosure should not be understood as an intention that the exemplary embodiments have more features than are expressly stated in each example. Rather, various aspects of the present disclosure may include fewer than all features of the individual disclosed examples. Accordingly, the following examples should be considered incorporated into the description, and each example may stand on its own as a separate example. Although each dependent example may refer within that example to a specific combination with one of the other examples, the aspect(s) of that dependent example are not limited to that specific combination. It will be understood that other exemplary examples may also include combinations of aspect(s) of the dependent example with the subject matter of any other dependent example or independent example, or combinations of any features with other dependent and independent examples. The various aspects disclosed herein expressly include specific combinations (e.g., contradictory aspects, such as defining an element as both an electrical insulator and an electrical conductor) unless these combinations are expressly expressed or can be readily inferred to be unintended. Furthermore, it is also intended that aspects of an embodiment may be included in any other independent embodiment, even if the embodiment is not directly dependent on the independent embodiment.

[0273]

[0290] Example implementations are described in the following numbered examples.

[0274]

[0291] Example 1. A method of wireless communications performed in a first user equipment (UE), the method including: detecting an authentication failure during establishment of a secure connection with a second UE; in response to detecting the authentication failure, sending a notification of the authentication failure to the second UE; and providing home network routing information (HNRI) for an authenticating node in a home network of the first UE to the second UE.

[0275]

[0292] Example 2. The method of example 1, wherein detecting an authentication failure during establishment of the secure connection with the second UE includes detecting an authentication failure during establishment of the secure connection with the second UE acting as a UE-to-network (U2N) relay.

[0276]

[0293] Example 3. The method of example 1 or 2, wherein detecting an authentication failure during establishment of the secure connection with the second UE includes detecting an authentication failure during establishment of a PC5 connection with the second UE.

[0277]

[0294] Example 4. The method of any of Examples 1-3, wherein detecting an authentication failure includes detecting a synchronization failure.

[0278]

[0295] Example 5. The method of any of Examples 1 to 4, wherein sending a notification of authentication failure to the second UE and providing the second UE with an HNRI for an authenticating node in the home network of the first UE includes sending the notification of authentication failure and the HNRI in the same message.

[0279]

[0296] Example 6. The method of any of Examples 1-5, wherein sending a notification of authentication failure to the second UE and providing the second UE with an HNRI for an authenticating node in the home network of the first UE includes sending the notification of authentication failure in a first message and sending the HNRI in a second message.

[0280]

[0297] Example 7. The method of any of Examples 1-6, wherein detecting an authentication failure includes detecting an authentication failure during a user plane security procedure.

[0281]

[0298] Example 8. The method of example 7, wherein detecting an authentication failure during a user plane security procedure includes receiving, from the second UE, a direct security mode command including an authentication challenge, processing the authentication challenge, and detecting a failure of the authentication challenge.

[0282]

[0299] Example 9. The method of Example 8, wherein receiving the direct security mode command includes receiving at least one of security material for a secure connection with the second UE and Generic Bootstrapping Architecture (GBA) Push Information (GPI), and processing the authentication challenge includes processing the authentication challenge included in the GPI.

[0283]

[0300] Example 10. The method of any of Examples 7-9, wherein sending a notification of authentication failure to the second UE includes sending a direct security mode failure to the second UE.

[0284]

[0301] Example 11. The method of example 10, wherein the direct security mode failure includes HNRI.

[0285]

[0302] Example 12. The method of any of Examples 1-11, wherein detecting an authentication failure includes detecting an authentication failure during a control plane security procedure.

[0286]

[0303] Example 13. The method of example 12, wherein detecting an authentication failure during a control plane security procedure includes receiving a first Extensible Authentication Protocol (EAP) message from the second UE, the first EAP message including first security information, processing an authentication challenge included in the first security information, and detecting a failure of the authentication challenge.

[0287]

[0304] Example 14. The method of Example 12 or 13, wherein sending a notification of the authentication failure to the second UE includes sending a second EAP message to the second UE.

[0288]

[0305] Example 15. The method of example 14, wherein the second EAP message includes an HNRI.

[0289]

[0306] Example 16. The method of any of Examples 1 to 15, wherein providing the HNRI to the second UE includes providing the second UE with a ProSe Relay User Key (PRUK) Identifier (PRUK ID), or an HNRI extracted from the SUCI or PRUK ID.

[0290]

[0307] Example 17. The method of any of Examples 1-16, wherein providing the HNRI to the second UE includes providing the HNRI to the second UE with a user identity portion modified to obscure the user identity information.

[0291]

[0308] Example 18. The method of any of Examples 1-17, wherein providing the HNRI to the second UE includes providing the second UE with a confidentiality and integrity protected HNRI based on provisioned discovery security material.

[0292]

[0309] Example 19. The method of any of Examples 1-18, wherein providing the HNRI to the second UE includes providing a Home Public Land Mobile Network (HPLMN) identifier of the home network of the first UE to the second UE.

[0293]

[0310] Example 20. The method according to any one of Examples 1 to 19, wherein the authentication node in the home network of the first UE includes a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF).

[0294]

[0311] Example 21. A method of wireless communication performed in a first user equipment (UE), comprising: receiving, from a second UE, a notification of authentication failure during establishment of a secure connection between the second UE and the first UE; determining home network routing information (HNRI) for an authentication node in a home network of the second UE; and transmitting the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0295]

[0312] Example 22. The method of example 21, wherein receiving notification of an authentication failure includes receiving notification of a synchronization failure.

[0296]

[0313] Example 23. The method of Example 21 or 22, wherein determining the HNRI includes receiving the HNRI from the second UE before receiving the notification of authentication failure, storing the HNRI, and retrieving the HNRI in response to receiving the notification of authentication failure, receiving the HNRI from the second UE as part of the notification of authentication failure, or receiving the HNRI from the second UE after receiving the notification of authentication failure.

[0297]

[0314] Example 24. The method of example 23, wherein receiving the HNRI from the second UE includes receiving a subscriber hiding identifier (SUCI).

[0298]

[0315] Example 25. The method of example 23 or 24, wherein receiving the HNRI from the second UE includes receiving a ProSe Relay User Key (PRUK) Identifier (PRUK ID).

[0299]

[0316] Example 26. The method of example 25, wherein the PRUK ID comprises a 64-bit string or a network access identifier (NAI).

[0300]

[0317] Example 27. The method of any of Examples 21 to 26, wherein receiving a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE includes receiving a notification of an authentication failure during establishment of a PC5 connection.

[0301]

[0318] Example 28. The method of any one of Examples 21 to 27, wherein receiving notification of an authentication failure includes receiving notification of an authentication failure during a user plane security procedure or a control plane security procedure.

[0302]

[0319] Example 29. The method of any of Examples 21 to 28, wherein determining an HNRI for an authentication node in a home network of the first UE includes determining an HNRI for a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF).

[0303]

[0320] Example 30. The method of any of Examples 21-29, wherein determining the HNRI includes determining the HNRI based on a subscriber hiding identifier (SUCI).

[0304]

[0321] Example 31. The method of any of Examples 21-30, wherein determining the HNRI includes determining the HNRI based on a ProSe Relay User Key (PRUK) Identifier (PRUK ID).

[0305]

[0322] Example 32. The method of example 31, wherein the PRUK ID comprises a 64-bit string or a network access identifier (NAI).

[0306]

[0323] Example 33. The method of any of Examples 21-32, wherein determining the HNRI includes determining a Home Public Land Mobile Network (HPLMN) identifier of a home network of the second UE.

[0307]

[0324] Example 34. A method of wireless communication, comprising: receiving, at a network entity, a request from a first UE in a home network of the network entity for security material for a secure connection between the first UE and a second UE that is not in the home network of the first UE, the first request including a transaction identifier (TXI); determining an HNRI for the home network of the second UE based on the TXI; determining an authentication node in the home network of the second UE based on the HNRI; and forwarding the request to the authentication node in the home network of the second UE.

[0308]

[0325] Example 35. The method of Example 34, further including, before receiving the request for security material, receiving information from the first UE mapping the TXI to the HNRI, and storing the mapping between the TXI and the HNRI.

[0309]

[0326] Example 36. The method of Example 35, wherein receiving information mapping the TXI to the HNRI includes receiving the TXI and a subscriber hiding identifier (SUCI).

[0310]

[0327] Example 37. The method described in Example 35 or 36, wherein receiving information mapping the TXI to the HNRI includes receiving the TXI and a ProSe Relay User Key (PRUK) Identifier (PRUK ID).

[0311]

[0328] Example 38. The method of example 37, wherein the PRUK ID comprises a 64-bit string or a network access identifier (NAI).

[0312]

[0329] Example 39. The method of any of Examples 35 to 38, wherein the HNRI includes a Home Public Land Mobile Network (HPLMN) identifier of the home network of the second UE.

[0313]

[0330] Example 40. The method of any one of Examples 34 to 39, wherein the authentication node in the home network of the second UE includes a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF).

[0314]

[0331] Example 41. A first user equipment (UE), comprising: a memory; and at least one processor coupled to the memory, wherein the memory and the at least one processor are configured to: detect an authentication failure during establishment of a secure connection with a second UE; and, in response to detecting the authentication failure, send a notification of the authentication failure to the second UE; and provide the second UE with home network routing information (HNRI) for an authenticating node in a home network of the first UE.

[0315]

[0332] Example 42. The first UE of Example 41, wherein the memory and at least one processor are configured to detect an authentication failure during establishment of a secure connection with a second UE acting as a UE-to-network (U2N) relay to detect an authentication failure during establishment of a secure connection with the second UE.

[0316]

[0333] Example 43. The first UE of Example 41 or 42, wherein the memory and at least one processor are configured to detect an authentication failure during establishment of a PC5 connection with the second UE to detect an authentication failure during establishment of a secure connection with the second UE.

[0317]

[0334] Example 44. The first UE of any of Examples 41 to 43, wherein the memory and the at least one processor are configured to detect a synchronization failure in order to detect an authentication failure.

[0318]

[0335] Example 45. A first UE as described in any of Examples 41 to 44, wherein the memory and at least one processor are configured to send a notification of authentication failure to the second UE and provide the second UE with an HNRI for an authenticating node in the home network of the first UE, the first UE being configured to send the notification of authentication failure and the HNRI in the same message.

[0319]

[0336] Example 46. A first UE as described in any of Examples 41 to 45, wherein the memory and at least one processor are configured to send a notification of authentication failure in a first message and send the HNRI in a second message to send a notification of authentication failure to the second UE and provide the second UE with an HNRI for an authenticating node in the home network of the first UE.

[0320]

[0337] Example 47. The first UE described in any of Examples 41 to 46, wherein the memory and at least one processor are configured to detect an authentication failure during a user plane security procedure to detect an authentication failure.

[0321]

[0338] Example 48. A first UE as described in Example 47, wherein the memory and at least one processor are configured to receive a direct security mode command including an authentication challenge from a second UE, process the authentication challenge, and detect a failure of the authentication challenge, in order to detect an authentication failure during a user plane security procedure.

[0322]

[0339] Example 49. The first UE of Example 48, wherein receiving the direct security mode command includes receiving at least one of security material for a secure connection with the second UE and Generic Bootstrapping Architecture (GBA) Push Information (GPI), and processing the authentication challenge includes processing the authentication challenge included in the GPI.

[0323]

[0340] Example 50. A first UE described in any of Examples 47 to 49, wherein the memory and at least one processor are configured to send a direct security mode failure to the second UE to send a notification of authentication failure to the second UE.

[0324]

[0341] Example 51. The first UE of Example 50, wherein the direct security mode failure includes an HNRI.

[0325]

[0342] Example 52. The first UE of any of Examples 41 to 51, wherein the memory and at least one processor are configured to detect an authentication failure during a control plane security procedure to detect an authentication failure.

[0326]

[0343] Example 53. The first UE of Example 52, wherein the memory and at least one processor are configured to receive, from the second UE, a first Extensible Authentication Protocol (EAP) message including first security information, process an authentication challenge included in the first security information, and detect a failure of the authentication challenge, in order to detect an authentication failure during a control plane security procedure.

[0327]

[0344] Example 54. The first UE of Example 52 or 53, wherein the memory and at least one processor are configured to send a second EAP message to the second UE to send a notification of authentication failure to the second UE.

[0328]

[0345] Example 55. The first UE of Example 54, wherein the second EAP message includes an HNRI.

[0329]

[0346] Example 56. A first UE as described in any of Examples 41 to 55, wherein the memory and at least one processor are configured to provide the second UE with a ProSe Relay User Key (PRUK) Identifier (PRUK ID), or an HNRI extracted from the SUCI or PRUK ID, to provide the second UE with an HNRI.

[0330]

[0347] Example 57. A first UE as described in any of Examples 41 to 56, wherein the memory and at least one processor are configured to provide the HNRI to the second UE, the HNRI having a user identification portion modified to obscure the user identification information.

[0331]

[0348] Example 58. A first UE as described in any of Examples 41 to 57, wherein the memory and at least one processor are configured to provide the second UE with a confidentiality and integrity protected HNRI based on provisioned discovery security material to provide the second UE with the HNRI.

[0332]

[0349] Example 59. A first UE as described in any of Examples 41 to 58, wherein the memory and at least one processor are configured to provide a Home Public Land Mobile Network (HPLMN) identifier of the home network of the first UE to the second UE to provide the HNRI to the second UE.

[0333]

[0350] Example 60. The first UE of any of Examples 41 to 59, wherein the authentication node in the home network of the first UE includes a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF).

[0334]

[0351] Example 61. A first user equipment (UE), comprising: a memory; and at least one processor coupled to the memory, wherein the memory and the at least one processor are configured to: receive, from a second UE, a notification of authentication failure during establishment of a secure connection between the second UE and the first UE; determine home network routing information (HNRI) for an authentication node in a home network of the second UE; and send the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0335]

[0352] Example 62. The first UE of Example 61, wherein the memory and at least one processor are configured to receive a notification of a synchronization failure to receive a notification of an authentication failure.

[0336]

[0353] Example 63. A first UE as described in Example 61 or 62, wherein, to determine the HNRI, the memory and at least one processor are configured to receive the HNRI from the second UE before receiving a notification of authentication failure, store the HNRI, retrieve the HNRI in response to receiving a notification of authentication failure, receive the HNRI from the second UE as part of the notification of authentication failure, or receive the HNRI from the second UE after receiving a notification of authentication failure.

[0337]

[0354] Example 64. The first UE of Example 63, wherein the memory and the at least one processor are configured to receive a subscriber hiding identifier (SUCI) to receive the HNRI from the second UE.

[0338]

[0355] Example 65. The first UE of Example 63 or 64, wherein the memory and at least one processor are configured to receive a ProSe Relay User Key (PRUK) Identifier (PRUK ID) to receive the HNRI from the second UE.

[0339]

[0356] Example 66. The first UE of Example 65, wherein the PRUK ID includes a 64-bit string or a network access identifier (NAI).

[0340]

[0357] Example 67. A first UE described in any of Examples 61 to 66, wherein the memory and at least one processor are configured to receive a notification of authentication failure during establishment of a PC5 connection to receive a notification of authentication failure during establishment of a secure connection between the second UE and the first UE.

[0341]

[0358] Example 68. A first UE described in any of Examples 61 to 67, wherein the memory and at least one processor are configured to receive a notification of authentication failure during a user plane security procedure or a control plane security procedure to receive a notification of authentication failure.

[0342]

[0359] Example 69. A first UE as described in any of Examples 61 to 68, wherein the memory and at least one processor are configured to determine an HNRI for a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF) to determine an HNRI for an authentication node in a home network of the first UE.

[0343]

[0360] Example 70. The first UE of any of Examples 61 to 69, wherein the memory and at least one processor are configured to determine the HNRI based on a subscriber hiding identifier (SUCI) to determine the HNRI.

[0344]

[0361] Example 71. A first UE as described in any of Examples 61 to 70, wherein to determine the HNRI, the memory and at least one processor are configured to determine the HNRI based on a ProSe Relay User Key (PRUK) Identifier (PRUK ID).

[0345]

[0362] Example 72. The first UE of Example 71, wherein the PRUK ID includes a 64-bit string or a network access identifier (NAI).

[0346]

[0363] Example 73. A first UE described in any of Examples 61 to 72, wherein the memory and at least one processor are configured to determine a Home Public Land Mobile Network (HPLMN) identifier of a home network of the second UE to determine the HNRI.

[0347]

[0364] Example 74. A network entity comprising: a memory; and at least one processor coupled to the memory, wherein the memory and the at least one processor are configured to: receive a request from a first UE in a home network of the network entity for security material for a secure connection between the first UE and a second UE that is not in the home network of the first UE, the first request including a transaction identifier (TXI); determine an HNRI for the home network of the second UE based on the TXI; determine an authentication node in the home network of the second UE based on the HNRI; and forward the request to the authentication node in the home network of the second UE.

[0348]

[0365] Example 75. The network entity of Example 74, wherein the at least one processor is further configured to receive, from the first UE before receiving the request for security material, information mapping the TXI to the HNRI, and store the mapping between the TXI and the HNRI.

[0349]

[0366] Example 76. The network entity of Example 75, wherein the memory and at least one processor are configured to receive a TXI and a subscriber hiding identifier (SUCI) to receive information mapping the TXI to an HNRI.

[0350]

[0367] Example 77. A network entity described in Example 75 or 76, wherein the memory and at least one processor are configured to receive a TXI and a ProSe Relay User Key (PRUK) Identifier (PRUK ID) to receive information mapping a TXI to an HNRI.

[0351]

[0368] Example 78. The network entity of Example 77, wherein the PRUK ID includes a 64-bit string or a network access identifier (NAI).

[0352]

[0369] Example 79. The network entity of any of Examples 75 to 78, wherein the HNRI includes a Home Public Land Mobile Network (HPLMN) identifier of the home network of the second UE.

[0353]

[0370] Example 80. The network entity of any of Examples 74 to 79, wherein the authentication node in the home network of the second UE includes a ProSe Key Management Function (PKMF) or an Authentication Server Function (AUSF).

[0354]

[0371] Example 81. The network entity described in any of Examples 74 to 80, including a ProSe key management function (PKMF) or an access and mobility management function (AMF).

[0355]

[0372] Example 82. A first UE comprising: means for detecting an authentication failure during establishment of a secure connection with a second UE; and means for, in response to detecting the authentication failure, sending a notification of the authentication failure to the second UE and providing the second UE with home network routing information (HNRI) for an authenticating node in a home network of the first UE.

[0356]

[0373] Example 83. A first UE, comprising: means for receiving, from a second UE, a notification of authentication failure during establishment of a secure connection between the second UE and the first UE; means for determining home network routing information (HNRI) for an authentication node in a home network of the second UE; and means for transmitting the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0357]

[0374] Example 84. A network entity comprising: means for receiving, from a first UE in a home network of the network entity, a request for security material for a secure connection between the first UE and a second UE not in the home network of the first UE, the first request including a transaction identifier (TXI); means for determining an HNRI for the home network of the second UE based on the TXI; means for determining an authentication node in the home network of the second UE based on the HNRI; and means for forwarding the request to the authentication node in the home network of the second UE.

[0358]

[0375] Example 85. A non-transitory computer-readable medium storing at least one computer-executable instruction that, when executed by a first UE, causes the first UE to detect an authentication failure during establishment of a secure connection with a second UE, and, in response to detecting the authentication failure, causes the first UE to send a notification of the authentication failure to the second UE, and provides home network routing information (HNRI) for an authenticating node in a home network of the first UE to the second UE.

[0359]

[0376] Example 86. A non-transitory computer-readable medium storing at least one computer-executable instruction, the at least one computer-executable instruction, when executed by a first UE, causing the first UE to receive, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE, determine home network routing information (HNRI) for an authentication node in a home network of the second UE, and send the HNRI for the authentication node in the home network of the second UE to the authentication node in the home network of the first UE.

[0360]

[0377] Example 87. A non-transitory computer-readable medium storing at least one computer-executable instruction that, when executed by a network entity, causes the network entity to receive a request from a first UE in the network entity's home network for security material for a secure connection between the first UE and a second UE that is not in the first UE's home network, the first request including a transaction identifier (TXI); determine an HNRI for the second UE's home network based on the TXI; determine an authentication node in the second UE's home network based on the HNRI; and forward the request to the authentication node in the second UE's home network.

[0361]

[0378] Example 88. A method for wireless communication in a first UE, the method including: in response to an authentication failure during establishment of a secure connection with a second UE, sending a notification of the authentication failure to the second UE; and providing the second UE with an HNRI for an authentication node in a home network of the first UE.

[0362]

[0379] Example 89. The method of Example 88, wherein detecting an authentication failure during establishment of a secure connection with the second UE includes at least one of detecting an authentication failure during establishment of a secure connection with the second UE acting as a UE-to-Network (U2N) relay, detecting an authentication failure during establishment of a PC5 connection with the second UE, or detecting a synchronization failure.

[0363]

[0380] Example 90. The method of example 88 or 89, wherein sending a notification of authentication failure to the second UE and providing the second UE with an HNRI for the authentication node in the home network of the first UE includes sending the notification of authentication failure and the HNRI in the same message, or sending the notification of authentication failure in a first message and sending the HNRI in a second message.

[0364]

[0381] Example 91. The method of any of Examples 88 to 90, wherein detecting an authentication failure includes detecting an authentication failure during a user plane security procedure.

[0365]

[0382] Example 92. The method of example 91, wherein sending a notification of authentication failure to the second UE includes sending a direct security mode failure message to the second UE, and the direct security mode failure message includes an HNRI.

[0366]

[0383] Example 93. The method of any of Examples 88-92, wherein detecting an authentication failure includes detecting an authentication failure during a control plane security procedure.

[0367]

[0384] Example 94. The method of any of Examples 88 to 93, wherein providing the HNRI to the second UE includes providing the second UE with at least one of a PRUK ID, or an HNRI extracted from the SUCI or the PRUK ID.

[0368]

[0385] Example 95. The method of any of Examples 88 to 94, wherein providing the HNRI to the second UE includes at least one of: modifying a user identity portion of the HNRI to obscure user identity information and providing the HNRI with the modified user identity portion to the second UE; confidentiality or integrity protecting the HNRI based on provisioned discovery security material and providing the confidentiality and / or integrity protected HNRI to the second UE; or providing an HPLMN identifier of the home network of the first UE to the second UE.

[0369]

[0386] Example 96. The method of any of Examples 88-95, wherein providing the HNRI to the second UE includes providing the second UE with an HPLMN identifier of the home network of the first UE.

[0370]

[0387] Example 97. The method of any one of Examples 88 to 96, wherein the authentication node in the home network of the first UE includes a PKMF or an AUSF.

[0371]

[0388] Example 98. A method for wireless communication in a first UE, the method including: receiving, from a second UE, a notification of authentication failure during establishment of a secure connection between the second UE and the first UE; receiving, from the second UE, an HNRI for a first authentication node in a home network of the second UE; and transmitting, to a second authentication node in the home network of the first UE, the HNRI for the first authentication node in the home network of the second UE.

[0372]

[0389] Example 99. The method of Example 98, wherein receiving a notification of an authentication failure includes receiving a notification of a synchronization failure.

[0373]

[0390] Example 100. The method of example 98 or 99, wherein receiving the HNRI from the second UE includes receiving the HNRI from the second UE before receiving the notification of authentication failure, storing the HNRI, and retrieving the HNRI in response to receiving the notification of authentication failure.

[0374]

[0391] Example 101. The method of any of Examples 98-100, wherein the notification of authentication failure includes an HNRI, and receiving the HNRI from the second UE includes receiving the HNRI from the second UE as part of the notification of authentication failure.

[0375]

[0392] Example 102. The method of any of Examples 98-101, wherein receiving the HNRI from the second UE includes receiving the HNRI from the second UE after receiving a notification of authentication failure.

[0376]

[0393] Example 103. The method of any of Examples 100 to 102, wherein receiving the HNRI from the second UE includes receiving a subscriber hiding identifier (SUCI).

[0377]

[0394] Example 104. The method of any one of Examples 100 to 103, wherein receiving an HNRI from the second UE includes receiving a PRUK ID.

[0378]

[0395] Example 105. The method of Example 104, wherein the PRUK ID includes at least one of a 64-bit string or an NAI.

[0379]

[0396] Example 106. The method of any of Examples 98 to 105, wherein receiving a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE includes receiving a notification of an authentication failure during establishment of a PC5 connection.

[0380]

[0397] Example 107. The method of any of Examples 98 to 106, wherein receiving notification of an authentication failure includes receiving notification of an authentication failure during at least one of a user plane security procedure or a control plane security procedure.

[0381]

[0398] Example 108. The method of any of Examples 98-107, wherein determining an HNRI for a first authentication node in a home network of the second UE includes determining an HNRI for at least one of a PKMF or an AUSF in the home network of the second UE.

[0382]

[0399] Example 109. A method for wireless communication in a network entity, the method including: receiving a request from a first UE in a first home network of the network entity for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network, the request including a TXI; determining an HNRI for the second home network based on the TXI; determining an authentication node in the second home network based on the HNRI for the second home network; and forwarding the request to the authentication node in the second home network.

[0383]

[0400] Example 110. The method of example 109, further including, before receiving the request for security material, receiving mapping information from the first UE that maps the TXI to an HNRI for the second home network, and storing the mapping information.

[0384]

[0401] Example 111. The method of Example 110, wherein receiving the mapping information includes receiving a TXI and at least one of a SUCI or a PRUK ID.

[0385]

[0402] Example 112. The method of Example 111, wherein the PRUK ID includes at least one of a 64-bit string or an NAI.

[0386]

[0403] Example 113. The method of any of Examples 110-112, wherein the HNRI includes an HPLMN identifier of the second home network.

[0387]

[0404] Example 114. The method of any of Examples 109 to 113, wherein the authentication node in the second home network includes at least one of a PKMF or an AUSF.

[0388]

[0405] Example 115. The method of any one of Examples 109 to 114, wherein the network entity includes at least one of a PKMF or an AMF.

[0389]

[0406] Example 116. An apparatus for wireless communication in a first UE, comprising: one or more memories; and one or more processors coupled to the one or more memories, wherein the one or more processors are configured to: cause the first UE to, in response to an authentication failure during establishment of a secure connection with the second UE, send a notification of the authentication failure to the second UE and provide an HNRI for an authentication node in a home network of the first UE to the second UE.

[0390]

[0407] Example 117. The apparatus described in Example 116, wherein the one or more processors configured to cause a first UE to detect an authentication failure during establishment of a secure connection with a second UE are configured to cause the first UE to perform at least one of: detect an authentication failure during establishment of a secure connection with a second UE acting as a UE-to-network (U2N) relay, detect an authentication failure during establishment of a PC5 connection with the second UE, or detect a synchronization failure.

[0391]

[0408] Example 118. The apparatus described in Example 116 or 117, wherein the one or more processors configured to cause a first UE to send a notification of authentication failure to a second UE and to provide the second UE with an HNRI for an authentication node in the home network of the first UE are configured to cause the first UE to send the notification of authentication failure and the HNRI in the same message, or to send the notification of authentication failure in a first message and send the HNRI in a second message.

[0392]

[0409] Example 119. The apparatus described in any of Examples 116 to 118, wherein the one or more processors configured to cause the first UE to detect an authentication failure are configured to cause the first UE to detect an authentication failure during a user plane security procedure.

[0393]

[0410] Example 120. The apparatus of Example 119, wherein the one or more processors configured to cause the first UE to send a notification of authentication failure to the second UE are configured to cause the first UE to send a direct security mode failure message to the second UE, the direct security mode failure message including the HNRI.

[0394]

[0411] Example 121. The apparatus described in any of Examples 116 to 120, wherein the one or more processors configured to cause the first UE to detect an authentication failure are configured to cause the first UE to detect an authentication failure during a control plane security procedure.

[0395]

[0412] Example 122. The apparatus of any of Examples 116 to 121, wherein the one or more processors configured to cause the first UE to provide the HNRI to the second UE are configured to cause the second UE to provide at least one of a PRUK ID or an HNRI extracted from the SUCI or the PRUK ID.

[0396]

[0413] Example 123. The apparatus described in any of Examples 116 to 122, wherein the one or more processors configured to cause the first UE to provide the HNRI to the second UE include at least one of: modifying a user identity portion of the HNRI to obscure user identity information and providing the HNRI having the modified user identity portion to the second UE; confidentiality or integrity protecting the HNRI based on provisioned discovery security material and providing the confidentiality and integrity protected HNRI based on the provisioned discovery security material to the second UE; or providing an HPLMN identifier of the home network of the first UE to the second UE.

[0397]

[0414] Example 124. The apparatus of any of Examples 116 to 123, wherein the one or more processors configured to cause the first UE to provide the HNRI to the second UE are configured to cause the first UE to provide the second UE with an HPLMN identifier of the first UE's home network.

[0398]

[0415] Example 125. The apparatus of any one of Examples 116 to 124, wherein the authentication node in the home network of the first UE includes a PKMF or an AUSF.

[0399]

[0416] Example 126. The device described in any of Examples 116 to 125, further comprising one or more transceivers coupled to the one or more processors.

[0400]

[0417] Example 127. The apparatus of Example 116, wherein the one or more processors are configured, individually or collectively, to cause the first UE to, in response to an authentication failure during establishment of a secure connection with the second UE, send a notification of the authentication failure to the second UE and provide the second UE with an HNRI for an authenticating node in the home network of the first UE.

[0401]

[0418] Example 128. An apparatus for wireless communication in a first UE, comprising: one or more memories; and one or more processors coupled to the one or more memories, wherein the one or more processors are configured to: cause the first UE to receive, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE; receive, from the second UE, an HNRI for a first authentication node in a home network of the second UE; and transmit the HNRI for the first authentication node in the home network of the second UE to a second authentication node in the home network of the first UE.

[0402]

[0419] Example 129. The apparatus of Example 128, wherein the one or more processors configured to cause the first UE to receive a notification of authentication failure are configured to cause the first UE to receive a notification of synchronization failure.

[0403]

[0420] Example 130. The apparatus described in Example 128 or 129, wherein the one or more processors configured to cause the first UE to receive the HNRI from the second UE are configured to cause the first UE to receive the HNRI from the second UE before receiving a notification of authentication failure, store the HNRI, and retrieve the HNRI in response to receiving a notification of authentication failure.

[0404]

[0421] Example 131. The apparatus of any of Examples 128 to 130, wherein the notification of authentication failure includes an HNRI, and the one or more processors configured to cause the first UE to receive the HNRI from the second UE are configured to cause the first UE to receive the HNRI from the second UE as part of the notification of authentication failure.

[0405]

[0422] Example 132. The apparatus of any of Examples 128 to 131, wherein the one or more processors configured to cause the first UE to receive the HNRI from the second UE are configured to cause the first UE to receive the HNRI from the second UE after receiving a notification of authentication failure.

[0406]

[0423] Example 133. The apparatus of any of Examples 130 to 132, wherein the one or more processors configured to cause the first UE to receive the HNRI from the second UE are configured to cause the first UE to receive a subscriber hiding identifier (SUCI).

[0407]

[0424] Example 134. The apparatus of any of Examples 130 to 133, wherein the one or more processors configured to cause the first UE to receive the HNRI from the second UE are configured to cause the first UE to receive the PRUK ID.

[0408]

[0425] Example 135. The device described in Example 134, wherein the PRUK ID includes at least one of a 64-bit string or an NAI.

[0409]

[0426] Example 136. The apparatus of any of Examples 128 to 135, wherein the one or more processors configured to cause the first UE to receive a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE are configured to cause the first UE to receive a notification of an authentication failure during establishment of the PC5 connection.

[0410]

[0427] Example 137. The apparatus of any of Examples 128 to 136, wherein the one or more processors configured to cause the first UE to receive notification of an authentication failure are configured to cause the first UE to receive notification of an authentication failure during at least one of a user plane security procedure or a control plane security procedure.

[0411]

[0428] Example 138. The apparatus of any of Examples 128 to 137, wherein the one or more processors configured to cause the first UE to determine an HNRI for a first authentication node in a home network of the second UE are configured to cause the first UE to determine an HNRI for at least one of a PKMF or an AUSF in the home network of the second UE.

[0412]

[0429] Example 139. The device described in any of Examples 128 to 138, further comprising one or more transceivers coupled to the one or more processors.

[0413]

[0430] Example 140. The apparatus of Example 128, wherein the one or more processors are configured, individually or collectively, to cause the first UE to receive, from the second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE, receive, from the second UE, an HNRI for a first authentication node in the home network of the second UE, and transmit, to the second authentication node in the home network of the first UE, the HNRI for the first authentication node in the home network of the second UE.

[0414]

[0431] Example 141. An apparatus for wireless communication in a network entity, comprising: one or more memories; and one or more processors coupled to the one or more memories, wherein the one or more processors are configured to: cause the network entity to receive, from a first UE in a first home network of the network entity, a request for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network, the request including a TXI; determine an HNRI for the second home network based on the TXI; determine an authentication node in the second home network based on the HNRI for the second home network; and forward the request to the authentication node in the second home network.

[0415]

[0432] Example 142. The apparatus described in Example 141, wherein the one or more processors are further configured to, before receiving the request for security material, cause the network entity to receive, from the first UE, mapping information that maps the TXI to an HNRI for the second home network, and store the mapping information.

[0416]

[0433] Example 143. The device described in Example 142, wherein the one or more processors configured to cause the network entity to receive mapping information are configured to cause the network entity to receive a TXI and at least one of a SUCI or a PRUK ID.

[0417]

[0434] Example 144. The device described in Example 143, wherein the PRUK ID includes at least one of a 64-bit string or an NAI.

[0418]

[0435] Example 145. The device described in any of Examples 142 to 144, wherein the HNRI includes an HPLMN identifier of the second home network.

[0419]

[0436] Example 146. The apparatus of any of Examples 141 to 145, wherein the authentication node in the second home network includes at least one of a PKMF or an AUSF.

[0420]

[0437] Example 147. A device described in any of Examples 141 to 146, comprising at least one of a PKMF or an AMF.

[0421]

[0438] Example 148. The device described in any of Examples 141 to 147, further comprising one or more transceivers coupled to the one or more processors.

[0422]

[0439] Example 149. The device described in Example 141, wherein one or more processors are configured, individually or collectively, to cause a network entity to receive a request from a first UE in a first home network of the network entity for security material for a secure connection between the first UE and a second UE having a second home network different from the first home network, the request including a TXI, determine an HNRI for the second home network based on the TXI, determine an authentication node in the second home network based on the HNRI for the second home network, and forward the request to the authentication node in the second home network.

[0423]

[0440] Example 150. A UE for wireless communication, comprising a processing system including a processor circuit and a memory circuit storing code and coupled to the processor circuit, wherein the processing system is configured to cause the UE to perform one or more of the methods of Examples 1-33 and 88-108.

[0424]

[0441] Example 151. A network entity for wireless communications, comprising a processing system including a processor circuit and a memory circuit that stores code and is coupled to the processor circuit, wherein the processing system is configured to cause a UE to perform one or more of the methods of Examples 34-40 and 109-115.

[0425]

[0442] Those skilled in the art will understand that information and signals may be represented using any of a variety of different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0426]

[0443] Furthermore, those skilled in the art will understand that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0427]

[0444] The various example logic blocks, modules, and circuits described in connection with aspects disclosed herein may be implemented or performed using a general-purpose processor, a digital signal processor (DSP), an ASIC, a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0428]

[0445] In some aspects, an individual processor may perform all of the functions described as being performed by one or more processors. In some aspects, one or more processors may collectively perform a set of functions. For example, a first set of processor(s) of one or more processors may perform a first function described as being performed by one or more processors, and a second set of processor(s) of one or more processors may perform a second function described as being performed by one or more processors. The first set of processors and the second set of processors may be the same set of processors or different sets of processors. References to “one or more processors” should be understood to refer to any one or more of the processors described in connection with FIGS. 3A, 3B, and 3C or the processor circuits described in connection with FIGS. 19 and 20. References to "one or more memories" should be understood to refer to any one or more memories of a corresponding device, such as the memories described in connection with Figures 3A, 3B, and 3C, or the memory circuits described in connection with Figures 19 and 20. For example, functions described as being performed by one or more memories may be performed by the same subset of one or more memories, or different subsets of one or more memories.

[0429]

[0446] The methods, sequences, and / or algorithms described in connection with the aspects disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal (e.g., UE). Alternatively, the processor and the storage medium may reside as discrete components in the user terminal.

[0430]

[0447] In one or more exemplary aspects, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored on or transmitted via a computer-readable medium as one or more instructions or code. Computer-readable media includes both computer storage media and communication media, including any medium that facilitates transfer of a computer program from one place to another. Storage media may be any available medium that can be accessed by a computer. By way of example, and not limitation, such computer-readable media may comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included within the definition of medium. As used herein, disk and disc include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically and discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable recording media.

[0431]

[0448] While the above disclosure illustrates exemplary aspects of the present disclosure, it should be noted that various changes and modifications can be made herein without departing from the scope of the present disclosure, which is defined by the appended claims. The functions, steps, and / or actions of the method claims in accordance with the aspects of the present disclosure described herein need not be performed in any particular order. Furthermore, although elements of the present disclosure may be described or claimed in the singular, the plural is contemplated unless limitation to the singular is explicitly stated.

Claims

1. 1. An apparatus for wireless communication in a first user equipment (UE), comprising: one or more memories; one or more processors coupled to the one or more memories, wherein the one or more processors cause the first UE to: In response to detecting an authentication failure during establishment of a secure connection with a second UE, sending a notification of the authentication failure to the second UE; causing the second UE to provide Home Network Routing Information (HNRI) for an authentication node in the home network of the first UE; The apparatus is configured to:

2. The one or more processors configured to cause the first UE to detect the authentication failure during establishment of the secure connection with the second UE may further include causing the first UE to: detecting the authentication failure during establishment of the secure connection with the second UE acting as a UE-to-Network (U2N) relay; detecting the authentication failure during establishment of a PC5 connection with the second UE; or Detecting synchronization failures; The apparatus of claim 1 , configured to cause at least one of

3. The one or more processors configured to cause the first UE to send the notification of the authentication failure to the second UE and provide the HNRI for the authentication node in the home network of the first UE to the second UE are configured to cause the first UE to: sending said notification of said authentication failure and said HNRI in the same message; or sending the notification of the authentication failure in a first message and sending the HNRI in a second message; The apparatus of claim 1 configured to cause:

4. 2. The apparatus of claim 1, wherein the one or more processors configured to cause the first UE to detect the authentication failure are configured to cause the first UE to detect the authentication failure during a user plane security procedure or a control plane security procedure.

5. The one or more processors configured to cause the first UE to provide the HNRI to the second UE may further include causing the first UE to: ProSe Relay User Key (PRUK) Identifier (PRUK ID), or HNRI extracted from SUCI or PRUK ID, 10. The apparatus of claim 1, configured to cause the second UE to provide at least one of:

6. The one or more processors configured to cause the first UE to provide the HNRI to the second UE may further include causing the first UE to: modifying a user identity portion of the HNRI to obscure user identity information and providing the HNRI with the modified user identity portion to the second UE; providing at least one of confidentiality and integrity protection to the HNRI based on provisioned discovery security material and providing the confidentiality and / or integrity protected HNRI to the second UE; or providing the second UE with a Home Public Land Mobile Network (HPLMN) identifier of the home network of the first UE; The apparatus of claim 1 , configured to cause at least one of

7. the one or more processors configured to provide the second UE with an HNRI for the authentication node in the home network of the first UE; the HNRI for a ProSe Key Management Function (PKMF) in the home network of the first UE; or the HNRI for an Authentication Server Function (AUSF) in the home network of the first UE; 10. The apparatus of claim 1, configured to provide at least one of:

8. 1. An apparatus for wireless communication in a first user equipment (UE), comprising: one or more memories; one or more processors coupled to the one or more memories, wherein the one or more processors cause the first UE to: receiving, from a second UE, a notification of an authentication failure during establishment of a secure connection between the second UE and the first UE; receiving, from the second UE, home network routing information (HNRI) for a first authentication node in a home network of the second UE; causing the HNRI for the first authentication node in the home network of the second UE to be transmitted to a second authentication node in the home network of the first UE; The apparatus is configured to:

9. The apparatus of claim 8 , wherein the one or more processors configured to receive the notification of the authentication failure are configured to receive a notification of a synchronization failure.

10. the one or more processors configured to receive the HNRI from the second UE; receiving the HNRI from the second UE before receiving the notification of the authentication failure; storing said HNRI; retrieving the HNRI in response to receiving the notification of the authentication failure; 9. The apparatus of claim 8, wherein the apparatus is configured to:

11. 9. The apparatus of claim 8, wherein the notification of the authentication failure includes the HNRI, and the one or more processors configured to receive the HNRI from the second UE are configured to receive the HNRI from the second UE as part of the notification of the authentication failure.

12. 9. The apparatus of claim 8, wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive the HNRI from the second UE after receiving the notification of the authentication failure.

13. 11. The apparatus of claim 10, wherein the one or more processors configured to receive the HNRI from the second UE are configured to receive at least one of a Subscriber Hiding Identifier (SUCI) or a ProSe Relay User Key (PRUK) Identifier (PRUK ID).

14. 9. The apparatus of claim 8, wherein the one or more processors configured to receive the notification of the authentication failure during establishment of the secure connection between the second UE and the first UE are configured to receive the notification of the authentication failure during establishment of a PC5 connection.

15. 9. The apparatus of claim 8, wherein the one or more processors configured to receive the notification of the authentication failure are configured to receive the notification of the authentication failure during at least one of a user plane security procedure or a control plane security procedure.

16. 9. The apparatus of claim 8, wherein the one or more processors configured to determine the HNRI for the first authentication node in the home network of the second UE are configured to determine the HNRI for at least one of a ProSe Key Management Function (PKMF) in the home network of the second UE or an Authentication Server Function (AUSF) in the home network of the second UE.

17. 1. An apparatus for wireless communication in a network entity, comprising: one or more memories; one or more processors coupled to the one or more memories, wherein the one or more processors cause the network entity to: receiving a request for security material for a secure connection between a first user equipment (UE) in a first home network of the network entity and a second UE having a second home network different from the first home network, the request including a transaction identifier (TXI); determining a home network routing information (HNRI) for the second home network based on the TXI; determining an authenticator node in the second home network based on the HNRI for the second home network; forwarding the request to the authentication node in the second home network; The apparatus is configured to:

18. before the one or more processors receive the request for security material; receiving mapping information from the first UE that maps the TXI to the HNRI for the second home network; storing the mapping information; 20. The apparatus of claim 17, further configured to:

19. 20. The apparatus of claim 18, wherein the one or more processors configured to receive the mapping information are configured to receive the TXI and at least one of a Subscriber Hiding Identifier (SUCI) or a ProSe Relay User Key (PRUK) Identifier (PRUK ID).

20. 20. The apparatus of claim 18, wherein the one or more processors configured to determine the HNRI for the second home network are configured to determine a Home Public Land Mobile Network (HPLMN) identifier of the second home network.

21. 18. The apparatus of claim 17, wherein the one or more processors configured to forward the request to the authentication node in the second home network are configured to forward the request to a ProSe Key Management Function (PKMF) in the second home network or an Authentication Server Function (AUSF) in the second home network.

22. 18. The apparatus of claim 17, wherein the network entity comprises at least one of a ProSe Key Management Function (PKMF) or an Access and Mobility Management Function (AMF).

23. 1. A method for wireless communication in a first user equipment (UE), comprising: In response to an authentication failure during establishment of a secure connection with a second UE, sending a notification of the authentication failure to the second UE; providing the second UE with home network routing information (HNRI) for an authentication node in the home network of the first UE; A method comprising:

24. detecting the authentication failure during establishment of the secure connection with the second UE; detecting the authentication failure during establishment of the secure connection with the second UE acting as a UE-to-Network (U2N) relay; detecting the authentication failure during establishment of a PC5 connection with the second UE; or Detecting synchronization failures; 24. The method of claim 23, comprising at least one of:

25. sending the notification of the authentication failure to the second UE and providing the second UE with the HNRI for the authenticator node in the home network of the first UE; sending said notification of authentication failure and said HNRI in the same message; or sending the notification of the authentication failure in a first message and sending the HNRI in a second message; 24. The method of claim 23, comprising:

26. 24. The method of claim 23, wherein detecting the authentication failure comprises detecting the authentication failure during a user plane security procedure or a control plane security procedure.

27. providing the HNRI to the second UE; ProSe Relay User Key (PRUK) Identifier (PRUK ID), or HNRI extracted from SUCI or PRUK ID, 24. The method of claim 23, comprising providing at least one of:

28. providing the HNRI to the second UE; modifying a user identity portion of the HNRI to obscure user identity information, and providing the HNRI having the modified user identity portion to the second UE; providing at least one of confidentiality and integrity protection to the HNRI based on provisioned discovery security material and providing the confidentiality and / or integrity protected HNRI to the second UE; or providing the second UE with a Home Public Land Mobile Network (HPLMN) identifier of the home network of the first UE; 24. The method of claim 23, comprising at least one of:

29. 24. The method of claim 23, wherein providing the second UE with an HNRI for the authentication node in the home network of the first UE comprises providing the second UE with the HNRI for a ProSe Key Management Function (PKMF) in the home network of the first UE or the HNRI for an Authentication Server Function (AUSF) in the home network of the first UE.