Broadcast and / or Groupcast Security for Device-to-Device Positioning

A security scheme using group keys and algorithms encrypts and authenticates positioning assistance messages in sidelink communications, addressing the lack of security in device-to-device positioning and ensuring message integrity and confidentiality.

JP2026502927APending Publication Date: 2026-01-27QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025538482
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-27
Filing Date
2023-11-28
Publication Date
2026-01-27

AI Technical Summary

Technical Problem

There is a lack of mechanisms to provide security for positioning assistance messages in sidelink communications, which are crucial for accurate device-to-device positioning in wireless communication systems.

Method used

A security scheme is implemented using group keys and algorithms to encrypt and authenticate positioning assistance messages, ensuring only intended recipients can access the information, involving the derivation of encryption and integrity keys based on group keys and identifiers.

Benefits of technology

This approach enhances the security of positioning assistance messages, preventing unauthorized access and spoofing, thereby ensuring the integrity and confidentiality of the information exchanged between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026502927000001_ABST
    Figure 2026502927000001_ABST
Patent Text Reader

Abstract

Techniques for implementing wireless communications are disclosed. In some aspects, a wireless communication device may perform operations at a user equipment (UE) including generating a message including information associated with positioning reference signaling. The operations may include obtaining a group identifier, a group key, and a group key identifier. The operations may include deriving a traffic key based on the group key and the group identifier. The operations may include deriving an encryption key and an integrity key based on the traffic key. The operations may include generating a message header including the group identifier and the group key identifier. The operations may include calculating a message authentication code (MAC) using the integrity key, the message, and the message header. The operations may include encrypting the message and MAC using the encryption key. The operations may include transmitting the message header, the encrypted message, and the encrypted MAC.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Aspects of the present disclosure generally relate to wireless communications. In some implementations, examples are described for providing broadcast and / or groupcast security for device-to-device positioning (e.g., PC5 sidelink positioning, Dedicated Short Range Communication (DSRC) sidelink positioning, and / or other device-to-device positioning). [Background technology]

[0002] Wireless communication systems are being deployed to provide various telecommunication services, including, among others, telephony, video, data, messaging, and broadcast. Wireless communication systems have evolved through various generations, including first-generation analog wireless telephone service (1G), second-generation (2G) digital wireless telephone service (including interim 2.5G networks), third-generation (3G) high-speed data and Internet-enabled wireless service, and fourth-generation (4G) service (e.g., Long-Term Evolution (LTE), WiMax). Many different types of wireless communication systems are currently in use, including cellular systems and personal communications service (PCS) systems. Examples of known cellular systems include the Cellular Analog Advanced Mobile Phone System (AMPS) and digital cellular systems based on code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), Global System for Mobile communications (GSM), etc.

[0003] The fifth-generation (5G) mobile standard calls for higher data rates, more connections, and better coverage, among other improvements. According to the Next Generation Mobile Network Alliance, the 5G standard (also known as "New Radio" or "NR") is designed to provide data rates of tens of megabits per second to each of tens of thousands of users, with 1 gigabit per second provided to dozens of workers on an office floor. To support large-scale sensor deployments, hundreds of thousands of simultaneous connections should be supported. Therefore, the spectral efficiency of 5G mobile communications should be significantly improved compared to the current 4G / LTE standards. Furthermore, signaling efficiency should be improved and latency should be significantly reduced compared to current standards.

[0004] Aspects of LTE, 5G, and / or other communication protocols may support direct communication between devices, which may be referred to as sidelink communication. As used herein, sidelink or sidelink communication generally refers to any direct device-to-device communication protocol. For example, the term sidelink may refer to 3GPP sidelink (e.g., using the PC5 sidelink interface) ("3GPP" is a registered trademark). Sidelink may also refer to a Wi-Fi protocol for direct device-to-device communication, referred to as the Dedicated Short-Range Communications (DSRC) protocol. As demand for mobile broadband access and general communication continues to grow, further improvements in 5G, LTE, and other radio access technologies, as well as other communication technologies (e.g., Wi-Fi, etc.), remain useful. Summary of the Invention

[0005] The following presents a simplified summary of one or more aspects disclosed herein. As such, the following summary is not intended to be an extensive overview of all contemplated aspects, nor is it intended to identify key or critical elements of all contemplated aspects or to delineate the scope associated with any particular aspect. Thus, the sole purpose of the following summary is to present certain concepts of one or more aspects of the mechanisms disclosed herein in a simplified form as a prelude to the Detailed Description presented below.

[0006]

[0009] Systems, methods, apparatuses, and computer-readable media for implementing wireless communications are disclosed. According to at least one embodiment, a method for wireless communications is provided. The method may include, at a user equipment (UE), generating a message including information associated with positioning reference signaling, obtaining a group identifier indicating a group to which the UE belongs, obtaining a group key and a group key identifier associated with the group key, obtaining a UE identifier indicating the UE, deriving a traffic key based on at least one of the group key, the group identifier, or the UE identifier, deriving an encryption key and an integrity key based on the traffic key, generating a message header for the message, the message header including at least one of the group identifier or the group key identifier, calculating a message authentication code (MAC) using the integrity key, the message, and the message header, encrypting the message using the encryption key to generate an encrypted message, encrypting the MAC using the encryption key to generate an encrypted MAC, and transmitting the message header, the encrypted message, and the encrypted MAC.

[0007] In another example, a wireless communication device for wireless communication is provided, including at least one memory and at least one processor communicatively coupled to the memory (e.g., configured in circuitry). The at least one processor can be configured to: generate, at a user equipment (UE), a message including information associated with positioning reference signaling, obtain a group identifier indicating a group to which the UE belongs, obtain a group key and a group key identifier associated with the group key, obtain a UE identifier indicating the UE, derive a traffic key based on at least one of the group key, the group identifier, or the UE identifier, derive an encryption key and an integrity key based on the traffic key, generate a message header for the message, the message header including at least one of the group identifier or the group key identifier, calculate a message authentication code (MAC) using the integrity key, the message, and the message header, encrypt the message using the encryption key to generate an encrypted message, encrypt the MAC using the encryption key to generate the encrypted MAC, and transmit the message header, the encrypted message, and the encrypted MAC.

[0008] In another example, a non-transitory computer-readable medium for a wireless communications device is provided, the non-transitory computer-readable medium including at least one instruction stored thereon that, when executed by one or more processors, causes the one or more processors to generate, at a user equipment (UE), a message including information associated with positioning reference signaling; obtain a group identifier indicating a group to which the UE belongs; obtain a group key and a group key identifier associated with the group key; obtain a UE identifier indicating the UE; derive a traffic key based on at least one of the group key, the group identifier, or the UE identifier; derive an encryption key and an integrity key based on the traffic key; generate a message header for the message, the message header including at least one of the group identifier or the group key identifier; calculate a message authentication code (MAC) using the integrity key, the message, and the message header; encrypt the message using the encryption key to generate an encrypted message; encrypt the MAC using the encryption key to generate the encrypted MAC; and transmit the message header, the encrypted message, and the encrypted MAC.

[0009] In another embodiment, an apparatus for wireless communications is provided that may include, at a user equipment (UE), means for generating a message including information associated with positioning reference signaling, means for obtaining a group identifier indicating a group to which the UE belongs, means for obtaining a group key and a group key identifier associated with the group key, means for obtaining a UE identifier indicating the UE, means for deriving a traffic key based on at least one of the group key, the group identifier, or the UE identifier, means for deriving an encryption key and an integrity key based on the traffic key, means for generating a message header for the message, the message header including at least one of the group identifier or the group key identifier, means for computing a message authentication code (MAC) using the integrity key, the message, and the message header, means for encrypting the message using the encryption key to generate an encrypted message, means for encrypting the MAC using the encryption key to generate the encrypted MAC, and means for transmitting the message header, the encrypted message, and the encrypted MAC.

[0010] According to at least one other embodiment, a method for wireless communications is provided that may include: receiving, at a first user equipment (UE), from a second UE, a packet including an encrypted message associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header, the message header including a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key, obtaining the group identifier indicating that the first UE also belongs to the group to which the second UE belongs, obtaining the group key and the group key identifier, deriving a traffic key based on the group key, deriving an encryption key and an integrity key based on the traffic key, decrypting the encrypted message using the encryption key to generate a decrypted message, decrypting the encrypted MAC using the encryption key to generate a decrypted MAC, calculating a predicted MAC based on the integrity key, and verifying integrity of the decrypted message by comparing the decrypted MAC with the predicted MAC.

[0011] In another example, a wireless communication device for wireless communication is provided, including at least one memory and at least one processor communicatively coupled to the memory (e.g., configured in circuitry). The at least one processor can be configured to: receive, in a first user equipment (UE), from a second UE, a packet including an encrypted message associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header, where the message header includes a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key; obtain the group identifier indicating that the first UE also belongs to the group to which the second UE belongs; obtain the group key and the group key identifier; derive a traffic key based on the group key; derive an encryption key and an integrity key based on the traffic key; decrypt the encrypted message using the encryption key to generate a decrypted message; decrypt the encrypted MAC using the encryption key to generate a decrypted MAC; calculate a predicted MAC based on the integrity key; and verify integrity of the decrypted message by comparing the decrypted MAC to the predicted MAC.

[0012] In another example, a non-transitory computer-readable medium for a wireless communication device is provided, the non-transitory computer-readable medium including at least one instruction stored thereon that, when executed by one or more processors, causes the one or more processors to: receive, at a first user equipment (UE), from a second UE, a packet including an encrypted message associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header, the message header including a group identifier indicating a group to which the second UE belongs, and a group key identifier indicating a group key; the first UE to receive the encrypted message; the second UE to receive the encrypted message; the first UE to receive the encrypted message; the second UE to receive the encrypted message; the second UE to receive the encrypted message; the first UE to receive the encrypted message; the second UE to receive the encrypted message; the second UE to receive the encrypted message;

[0013] In another embodiment, an apparatus for wireless communication is provided, which may include: means for receiving, in a first user equipment (UE), from a second UE, a packet including an encrypted message associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header, the packet including a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key, means for obtaining a group identifier indicating that the first UE also belongs to the group to which the second UE belongs, means for obtaining the group key and the group key identifier, means for deriving a traffic key based on the group key, means for deriving an encryption key and an integrity key based on the traffic key, means for decrypting the encrypted message using the encryption key to generate a decrypted message, means for decrypting the encrypted MAC using the encryption key to generate a decrypted MAC, means for calculating a predicted MAC based on the integrity key, and means for verifying integrity of the decrypted message by comparing the decrypted MAC with the predicted MAC.

[0014] Aspects generally include methods, apparatus, systems, computer program products, non-transitory computer-readable media, user equipment, base stations, wireless communication devices, and / or processing systems substantially as described herein with reference to and as illustrated by the drawings and the specification.

[0015] The foregoing has outlined rather broadly the features and technical advantages of embodiments according to the present disclosure in order that the following Detailed Description may be better understood. Additional features and advantages will be described hereinafter. The concepts and specific examples disclosed may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of the present disclosure. Such equivalent structures do not depart from the scope of the appended claims. The nature of the concepts disclosed herein, both their organization and method of operation, together with associated advantages, will be better understood by considering the following description in conjunction with the accompanying figures. Each of the figures is provided for the purpose of illustration and description, and not as a definition of the limits of the claims.

[0016] Although aspects are described in this disclosure by way of example with respect to some examples, those skilled in the art will understand that such aspects may be implemented in many different configurations and scenarios. The techniques described herein may be implemented using a variety of platform types, devices, systems, shapes, sizes, and / or packaging configurations. For example, some aspects may be implemented via integrated chip embodiments or other non-modular component-based devices (e.g., end-user devices, vehicles, communications devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, and / or artificial intelligence devices). Aspects may be implemented in chip-level components, modular components, non-modular components, non-chip-level components, device-level components, and / or system-level components. Devices incorporating the described aspects and features may include additional components and features for implementing and practicing the claimed and described aspects. For example, the transmission and reception of wireless signals may include one or more components (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, summers, and / or analog summers) for analog and digital purposes. It is contemplated that aspects described herein may be practiced in a wide variety of devices, components, systems, distributed configurations, and / or end-user devices of various sizes, shapes, and configurations.

[0017] Other objects and advantages associated with the aspects disclosed herein will become apparent to one skilled in the art based on the accompanying drawings and detailed description.

[0018] The accompanying drawings are presented to aid in the explanation of various aspects of the present disclosure and are provided for purposes of illustration only and not limitation of those aspects. [Brief explanation of the drawings]

[0019] [Figure 1] 1 illustrates an exemplary wireless communication system according to aspects of the present disclosure. [Figure 2A] 1 illustrates an example of a wireless network structure in accordance with aspects of the present disclosure. [Figure 2B] 1 illustrates an example of a wireless network structure in accordance with aspects of the present disclosure. [Figure 3] FIG. 1 illustrates an example of various user equipments (UEs) communicating over a direct communication interface (referred to as a PC5 interface or sidelink interface) and a wide area network (Uu) interface, in accordance with aspects of the present disclosure. [Figure 4] FIG. 1 is a block diagram illustrating an example of a vehicle computing system in accordance with aspects of the present disclosure. [Figure 5] FIG. 1 is a block diagram illustrating an example of a computing system for a user device, according to aspects of the present disclosure. [Figure 6] FIG. 1 illustrates an example wireless communication system for providing security for sidelink positioning in accordance with aspects of the present disclosure. [Figure 7] FIG. 1 illustrates various layers of a communication model in accordance with aspects of the present disclosure. [Figure 8] FIG. 10 is a sequence diagram illustrating another example of a sequence for providing security for sidelink positioning in accordance with aspects of the present disclosure. [Figure 9] FIG. 10 is a flow diagram illustrating an example process for providing security for sidelink positioning in accordance with aspects of the present disclosure. [Figure 10] FIG. 10 is a flow diagram illustrating another example of a process for providing security for sidelink positioning in accordance with aspects of the present disclosure. [Figure 11] FIG. 1 is a block diagram illustrating an example of a computing system in accordance with aspects of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0020] Specific aspects and embodiments of the present disclosure are provided below for illustrative purposes. Alternative aspects may be devised without departing from the scope of the present disclosure. Furthermore, well-known elements of the present disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of the present disclosure. As will be apparent to one skilled in the art, some of the aspects and embodiments described herein can be applied independently, and some of them can also be applied in combination. In the following description, for purposes of explanation, specific details are set forth in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent that various embodiments can be practiced without these specific details. The figures and description are not intended to be limiting.

[0021] The following description provides exemplary embodiments only and is not intended to limit the scope, applicability, or configuration of the present disclosure. Rather, the following description of exemplary embodiments will provide those skilled in the art with an enabling description for implementing the exemplary embodiments. It should be understood that various changes can be made in the function and arrangement of elements without departing from the scope of the present application as set forth in the appended claims.

[0022] Wireless communication networks are being deployed to provide various telecommunication services such as voice, video, packet data, messaging, broadcasts, and so on. Wireless communication networks may support both access links and sidelinks for communication between wireless devices. An access link may refer to any communication link between a client device (e.g., a user equipment (UE), a station (STA), or other client device) and a base station (e.g., a 3GPP gNB, a 3GPP eNB, a Wi-Fi access point (AP), or other base station). For example, the access link may support uplink signaling, downlink signaling, attachment procedures, etc.

[0023] A sidelink may refer to any communication link between client devices (e.g., UEs, STAs, etc.). For example, a sidelink may support device-to-device (D2D) communications, vehicle-to-everything (V2X) and / or vehicle-to-vehicle (V2V) communications, message relay, discovery signaling, beacon signaling, or any combination of these or other signals transmitted over the air from one UE to one or more other UEs. In some embodiments, sidelink communications may be transmitted using a licensed or unlicensed frequency spectrum (e.g., 5 GHz or 6 GHz). As used herein, the term sidelink may refer to the use of 3GPP sidelink (e.g., using a PC5 sidelink interface), Wi-Fi Direct communications (e.g., according to the Dedicated Short-Range Communications (DSRC) protocol), or any other direct device-to-device communication protocol.

[0024] In some configurations, the UE may use sidelink communications to implement a sidelink positioning algorithm. In some cases, the sidelink positioning algorithm may be used to obtain higher accuracy than can be obtained by using more conventional positioning technologies, such as the Global Navigation Satellite System (GNSS). For example, some sidelink applications (e.g., V2X applications and / or other applications) have extremely high accuracy requirements. In one exemplary embodiment, sub-meter accuracy may be required to support vehicle steering adjustments (e.g., lane change adjustments, automatic braking of a target vehicle based on the position of another vehicle, etc.). In such cases, transmission of a positioning signal (e.g., a Positioning Reference Signal (PRS)) with a large bandwidth (e.g., approximately 80 MHz or greater) may be required. Therefore, the sidelink positioning signal (SL PRS) may be transmitted over an intelligent transport system (ITS) band, a licensed band, or an unlicensed band, depending on local regulations, positioning Quality of Service (QoS) requirements, etc.

[0025] Sidelink positioning may support both relative and absolute positioning. For example, relative positioning (also referred to as ranging) may include determining the distance between two UEs (e.g., between a pedestrian UE and an RSU, between two pedestrian UEs, between two vehicular UEs, between a pedestrian UE and a vehicular UE, etc.). Absolute positioning may include determining the global location of a target UE (e.g., by determining geographic coordinates).

[0026] In some cases, sidelink positioning may be performed based on measurements of one or more sidelink positioning signals (e.g., sidelink PRS, Channel State Information (CSI) reference signal (CSI-RS), Sounding Reference Signal (SRS), etc.) transmitted from one UE to another via the sidelink. For example, a sidelink PRS may be transmitted via the sidelink. Positioning may be based on measurements of the time of arrival (ToA), time difference of arrival (TDoA), angle of arrival (AoA), round-trip time (RTT), or other positioning-based determinations, such as the sidelink PRS, CSI-RS, or SRS. For simplicity, sidelink positioning signals may be referred to as "PRS" or "PRS signals," or individually as "PRS" or "PRS signals."

[0027] Sidelink positioning can be performed with or without network involvement. For example, the UE may autonomously schedule sidelink positioning resources without network involvement (Mode 2). In another embodiment, the scheduling of sidelink positioning resources can be performed by the base station (Mode 1). In some cases, one or both of the sidelink positioning signals (e.g., PRS, etc.) and the positioning assistance messages can be scheduled by the base station (e.g., gNB, eNB, AP, etc.) in Mode 1 operation.

[0028] Described herein are systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively "systems and techniques") for providing security for sidelink positioning. The systems and techniques provide security for sidelink positioning signaling between client devices (e.g., UEs). As described above, sidelink communication may be performed according to a 3GPP communication protocol (e.g., using a PC5 sidelink interface according to LTE, 5G, etc.), a Wi-Fi Direct communication protocol (e.g., the DSRC protocol), or using any other device-to-device communication protocol.

[0029] In some cases, transmission of a positioning assistance message may be used in connection with positioning. For example, a positioning assistance message may be transmitted before and / or after transmission of a PRS. A positioning assistance message transmitted before a PRS may be referred to herein as a “PrePRS message,” “PrePRS signal,” or “PrePRS.” A positioning assistance message transmitted after a PRS signal may be referred to herein as a “PostPRS message,” “PostPRS signal,” or “PostPRS.” A positioning assistance message (whether PrePRS or PostPRS) may carry sidelink positioning-related configuration information (e.g., PRS configuration, etc.), sidelink positioning-related measurements (e.g., Time of Arrival (ToA) measurements, Time Delay (TDoA) measurements, RTT measurements, etc.), participant information indicating one or more intended recipients of the PRS, session information associated with communication between UEs (e.g., including the spectrum to be used for the PRS signal), PRS measurements indicating the signal strength of the received PRS, location information associated with the location of the UE, movement information associated with the movement of the UE, any combination thereof, and / or other information. In some cases, a UE may broadcast or groupcast PrePRS messages (and / or PostPRS messages) to identify other UEs that will be involved in sidelink positioning, to initiate communication with other UEs, to provide location information to other UEs, any combination thereof, and / or to perform other operations. However, there is a lack of mechanisms to provide security for positioning assistance messages.

[0030] The systems and techniques described herein provide security for positioning assistance messages (and / or for sidelink positioning generally) by providing a scheme for various UEs to exchange information and generate keys for encrypting and authenticating transmissions. For example, a first UE may obtain a group key (associated with a group of UEs that includes the first UE) and an algorithm identifier indicating an algorithm. In this disclosure, the term "group key" may refer to an encryption key shared by and / or associated with a group of UEs. The first UE may use the algorithm to derive encryption and integrity keys based on the group key. In this disclosure, the term "integrity key" may refer to an encryption key that can be used to verify the integrity of a message. The first UE may use the integrity key to calculate a message authentication code (MAC) based on a message to be transmitted (e.g., a positioning assistance message). The first UE may use the encryption key to encrypt the message and MAC. The first UE may transmit (e.g., in a packet) the group identifier (indicative of the first UE's group), the encrypted message, and the encrypted MAC. In this disclosure, the term "group identifier" may refer to an identifier (e.g., a number or code) that may be associated with and / or used to identify a group of UEs, may be used to identify UEs in that group, and / or may be used to identify the group. In this manner, a first UE may protect a message by encrypting the message before broadcasting or groupcasting it.

[0031] Additionally or alternatively, the second UE may receive (e.g., in a packet) the transmitted group identifier, encrypted message, and encrypted MAC. The second UE may use an algorithm to derive encryption and integrity keys based on the group identifier of the first UE. For example, the second UE may derive the encryption and integrity keys using a technique related to (e.g., the same as) the technique used by the first UE to derive the encryption and integrity keys. For example, both the first UE and the second UE may be part of a group identified by the group identifier. In response to the first UE and the second UE being part of the group, both the first UE and the second UE may obtain the same algorithm identifier (e.g., from another source). Additionally or alternatively, the first UE may send an algorithm identifier indicating the algorithm along with the encrypted message (e.g., in a header). Furthermore, the second UE may obtain the group key from the same source from which the first UE obtained the group key (e.g., based on both the first UE and the second UE being part of the group). Thus, the second UE may be able to use the algorithm and group key to derive the same encryption and integrity keys derived by the first UE.

[0032] The second UE may decrypt the message and the encrypted MAC. The second UE may generate a predicted MAC based on the integrity key and the message. For example, the second UE may generate the predicted MAC using a technique related to (e.g., the same as) the technique used by the first UE to generate the MAC. The second UE can authenticate the message by comparing the decrypted MAC to the predicted MAC. In this way, the second UE can provide integrity to the message by authenticating it (e.g., before trusting its contents). Similar techniques can be used by one or more other UEs in the group identified by the group identifier.

[0033] In some aspects, the present systems and techniques can use a sidelink positioning protocol (SLPP) layer of a communication model. For example, a communication stack between two or more UEs can include, from bottom to top, a physical layer (PHY), a medium access control layer, a radio control link (RLC) layer, a packet data convergence (PDCP) layer, a vehicle-to-everything (V2X) / proximity security (ProSe) layer, and an SLPP layer. The present systems and techniques can implement security schemes in the SLPP layer, which can use or rely on any or all of the PHY layer, the medium access control layer, the RLC layer, the PCDP layer, or the V2X / ProSe layer.

[0034] Providing security for positioning assistance messages can provide various benefits, such as, among other things, allowing the contents of the positioning assistance message to be unavailable or unreadable to unintended recipients and / or preventing the positioning assistance message from being spoofed by an attacker.

[0035] Additional aspects of the disclosure are described in more detail below.

[0036] As used herein, the terms "user equipment" (UE) and "base station" are not intended to be specific or otherwise limited to any particular radio access technology (RAT) unless otherwise specified. In general, a UE can be any wireless communication device (e.g., a mobile phone, a router, a tablet computer, a laptop computer, a tracking device, a wearable device (e.g., a smart watch, glasses, an extended reality (XR) device, such as a virtual reality (VR) headset, an augmented reality (AR) headset or glasses, or a mixed reality (MR) headset), a vehicle (e.g., an automobile, a motorcycle, a bicycle, etc.), an Internet of Things (IoT, etc.) used by a user to communicate over a wireless communication network. A UE can be mobile or stationary (e.g., at a particular time) and can be configured to communicate over a radio access network. A UE may communicate with a RAN (Network Access Network). As used herein, the term "UE" may be referred to interchangeably as an "access terminal" or "AT," "user device," "user terminal" or UT, "client device," "wireless device," "wireless communication device," "subscriber device," "subscriber terminal," "subscriber station," "mobile device," "mobile terminal," "mobile station," or variations thereof. In general, a UE may communicate with a core network via a RAN, through which the UE may connect to external networks, such as the Internet, and with other UEs. A UE may also communicate with other UEs and / or other devices, as described herein.In some cases, other mechanisms for connecting to the core network, the Internet, and other UEs are also possible for a UE, such as via a wired access network, a wireless local area network (WLAN) network (e.g., based on IEEE 802.11, based on ultra-wideband (UWB), etc.).

[0037] A base station may operate according to one of several RATs when communicating with UEs, RSUs, and / or other devices, depending on the network in which the base station is deployed. In some cases, a base station may alternatively be referred to as an access point (AP), network node, NodeB (NB), evolved NodeB (eNB), next generation eNB (ng-eNB), New Radio (NR) NodeB (also referred to as gNB or gNodeB), etc. A base station may be primarily used to support wireless access by UEs, including supporting data, voice, and / or signaling connections for supported UEs. In some systems, a base station may simply provide edge node signaling functionality, while in other systems, a base station may provide additional control and / or network management functions. The communication link over which a UE may send signals to a base station is called an uplink (UL) channel (e.g., a reverse traffic channel, a reverse control channel, an access channel, etc.). A communication link through which a base station may transmit signals to a UE is called a downlink (DL) channel or a forward link channel (e.g., a paging channel, a control channel, a broadcast channel, or a forward traffic channel). As used herein, the term traffic channel (TCH) may refer to either an uplink / reverse traffic channel or a downlink / forward traffic channel.

[0038] The term "base station" may refer to a single physical transmission / reception point (TRP) or multiple physical TRPs, which may or may not be collocated. For example, when the term "base station" refers to a single physical TRP, the physical TRP may be an antenna of the base station corresponding to the base station's cell (or several cell sectors). When the term "base station" refers to multiple collocated physical TRPs, the physical TRPs may be an array of antennas of the base station (e.g., as in a multiple-input multiple-output (MIMO) system or when the base station employs beamforming). When the term "base station" refers to multiple non-collocated physical TRPs, the physical TRPs may be a distributed antenna system (DAS) (a network of spatially separated antennas connected to a common source via a transmission medium) or a remote radio head (RRH) (a remote base station connected to a serving base station). Alternatively, non-collocated physical TRPs may be the serving base station that receives measurement reports from the UE and neighboring base stations whose reference RF signals (or simply "reference signals") the UE is measuring. Because a TRP is a point at which a base station transmits and receives wireless signals, as used herein, references to transmission from or reception at a base station should be understood to refer to a particular TRP for that base station.

[0039] In some implementations that support UE positioning, a base station may not support wireless access by the UE (e.g., it may not support data, voice, and / or signaling connections for the UE), but instead may transmit reference signals to the UE to be measured by the UE and / or may receive and measure signals transmitted by the UE. Such a base station may be referred to as a positioning beacon (e.g., if it transmits signals to the UE) and / or a position measurement unit (e.g., if it receives and measures signals from the UE).

[0040] A roadside unit (RSU) is a device that may send and receive messages to and from one or more UEs, other RSUs, and / or base stations via a communication link or interface (e.g., a cellular-based sidelink or PC5 interface, an 802.11 or WiFi-based dedicated short-range communication (DSRC) interface, and / or other interfaces). Examples of messages that may be sent and received by an RSU include vehicle-to-everything (V2X) messages, which are described in more detail below. RSUs may be located on various transportation infrastructure systems, including roads, bridges, parking lots, toll booths, and / or other infrastructure systems. In some embodiments, an RSU may facilitate communication between a UE (e.g., a vehicle, a pedestrian user device, and / or another UE) and a transportation infrastructure system. In some implementations, an RSU may communicate with a server, a base station, and / or other systems that may perform centralized management functions.

[0041] The RSU may communicate with the communication system of the UE. For example, the RSU may use an Intelligent Transportation System (ITS) of the UE (e.g., a vehicle and / or another UE) to generate and sign messages for transmission to the RSU and to verify messages received from the RSU. The RSU may communicate with vehicles traveling along roads, bridges, or other infrastructure systems (e.g., via a PC5 interface, a DSRC interface, etc.) to obtain traffic-related data (e.g., vehicle time, speed, location, etc.). In some cases, in response to obtaining the traffic-related data, the RSU may determine or estimate traffic congestion information (e.g., start of a traffic congestion, end of a traffic congestion, etc.), travel time, and / or other information related to a particular location. In some embodiments, the RSU may communicate with other RSUs (e.g., via a PC5 interface, a DSRC interface, etc.) to determine traffic-related data. The RSU may transmit information (e.g., traffic congestion information, travel time information, and / or other information) to other vehicles, pedestrian UEs, and / or other UEs. For example, an RSU may broadcast or otherwise transmit information to any UEs (eg, vehicles, pedestrian UEs, etc.) that are within the coverage range of the RSU.

[0042] 1 illustrates an example of a wireless communication system 100. The wireless communication system 100 (which may also be referred to as a wireless wide area network (WWAN)) may include various base stations 102 and various UEs 104. The base stations 102 may include macrocell base stations (high-power cellular base stations) and / or small cell base stations (low-power cellular base stations). In one aspect, the macrocell base stations may include eNBs and / or ng-eNBs when the wireless communication system 100 supports a 4G / LTE network, or gNBs when the wireless communication system 100 supports a 5G / NR network, or a combination of both, and the small cell base stations may include femtocells, picocells, microcells, etc.

[0043] The base stations 102 collectively form a radio access network (RAN) and may interface with a core network 170 (e.g., evolved packet core (EPC) or 5G core (5GC)) through backhaul links 122, and through the core network 170 to one or more location servers 172 (which may be part of the core network 170 or may be external to the core network 170). In addition to other functions, the base stations 102 may perform functions related to one or more of the following: forwarding user data, encryption and decryption of radio channels, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection setup and release, load balancing, allocation for non-access stratum (NAS) messages, NAS node selection, synchronization, RAN sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracing, RAN information management (RIM), paging, positioning, and delivery of alert messages. The base stations 102 may communicate with each other directly or indirectly (e.g., through EPC / 5GC) via backhaul links 134, which may be wired and / or wireless.

[0044] The base stations 102 may wirelessly communicate with UEs 104. Each of the base stations 102 may provide communication coverage for a corresponding geographic coverage area 110. In one aspect, one or more cells may be supported by the base stations 102 within each coverage area 110. A "cell" is a logical communication entity used for communication with a base station (e.g., over some frequency resource, referred to as a carrier frequency, component carrier, carrier, band, etc.) and may be associated with an identifier (e.g., a physical cell identifier (PCI), a virtual cell identifier (VCI), a cell global identifier (CGI)) to distinguish between cells operating over the same or different carrier frequencies. In some cases, different cells may be configured according to different protocol types (e.g., machine-type communication (MTC), narrowband IoT (NB-IoT), enhanced mobile broadband (eMBB), etc.) that may provide access to different types of UEs. Because a cell is supported by a particular base station, the term "cell" can refer to either or both of a logical communication entity and the base station that supports that logical communication entity, depending on the context. Furthermore, because a TRP is typically the physical transmission point of a cell, the terms "cell" and "TRP" can be used interchangeably. In some cases, the term "cell" can also refer to the geographic coverage area (e.g., sector) of a base station, so long as carrier frequencies can be detected and used for communication within some portion of the geographic coverage area 110.

[0045] The geographic coverage areas 110 of neighboring macrocell base stations 102 may partially overlap (e.g., in handover regions), but some of the geographic coverage areas 110 may be substantially overlapped by larger geographic coverage areas 110. For example, a small cell base station 102' may have a coverage area 110' that substantially overlaps with the coverage area 110 of one or more macrocell base stations 102. A network including both small cell base stations and macrocell base stations may be known as a heterogeneous network. A heterogeneous network may also include home eNBs (HeNBs), which may serve restricted groups known as closed subscriber groups (CSGs).

[0046] The communication link 120 between the base station 102 and the UE 104 may include uplink (also referred to as reverse link) transmissions from the UE 104 to the base station 102 and / or downlink (also referred to as forward link) transmissions from the base station 102 to the UE 104. The communication link 120 may use MIMO antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link 120 may be over one or more carrier frequencies. The allocation of carriers may be asymmetric for the downlink and uplink (e.g., more or fewer carriers may be allocated for the downlink than for the uplink).

[0047] The wireless communication system 100 may further include a wireless local area network (WLAN) access point (AP) 150 that communicates with WLAN stations (STAs) 152 via communication links 154 in an unlicensed frequency spectrum (e.g., 5 GHz). When communicating in the unlicensed frequency spectrum, the WLAN STAs 152 and / or the WLAN AP 150 may perform a clear channel assessment (CCA) or listen before talk (LBT) procedure prior to communication to determine whether a channel is available. In some embodiments, the wireless communication system 100 may include devices (e.g., UEs, etc.) that communicate with one or more UEs 104, base stations 102, APs 150, etc., utilizing an ultra-wideband (UWB) spectrum. The UWB spectrum may be in the range of 3.1 to 10.5 GHz.

[0048] The small cell base station 102′ may operate in a licensed and / or unlicensed frequency spectrum (e.g., employing LTE or NR technology and using the same 5 GHz unlicensed frequency spectrum used by the WLAN AP 150). The wireless communication system 100 may further include a millimeter wave (mmW) base station 180 that may operate in millimeter wave (mmW) and / or quasi-mmW frequencies in communication with the UE 182. In some cases, mmW frequencies may be referred to as the FR2 band (e.g., including a frequency range of 24,250 MHz to 52,600 MHz). In some embodiments, the wireless communication system 100 may include one or more base stations (referred to herein as “hybrid base stations”) that operate in both mmW frequencies (and / or quasi-mmW frequencies) and sub-6 GHz frequencies (e.g., including a frequency range of 450 MHz to 6,000 MHz, referred to as the FR1 band). In some embodiments, the mmW base station 180, one or more hybrid base stations (not shown), and the UE 182 may utilize beamforming (transmit and / or receive) over the mmW communication link 184 to compensate for very high path loss and short distances. The wireless communication system 100 may further include a UE 164, which may communicate with the macrocell base station 102 over the communication link 120 and / or with the mmW base station 180 over the mmW communication link 184.

[0049] In some embodiments, the base station 102 and / or the UE 104 may be equipped with multiple receivers and / or transmitters to operate on multiple carrier frequencies. For example, the UE 104 may have two receivers, "Receiver 1" and "Receiver 2," where "Receiver 1" is a multi-band receiver that can be tuned to band (i.e., carrier frequency) "X" or band "Y," and "Receiver 2" is a one-band receiver that can only be tuned to band "Z."

[0050] The wireless communication system 100 may further include one or more UEs, such as a UE 190, that indirectly connect to one or more communication networks via one or more device-to-device (D2D) peer-to-peer (P2P) links (referred to as "sidelinks"). In the example of Figure 1, the UE 190 has a D2D P2P link 192 with one of the UEs 104 connected to one of the base stations 102 (e.g., through which the UE 190 may indirectly obtain cellular connectivity) and a D2D P2P link 194 with a WLAN STA 152 connected to a WLAN AP 150 (through which the UE 190 may indirectly obtain WLAN-based Internet connectivity). In one embodiment, the D2D P2P links 192 and 194 may be supported using any known D2D RAT, such as LTE Direct (LTE-D), Wi-Fi Direct (Wi-Fi-D), Bluetooth, UWB, etc.

[0051] According to various aspects, FIG. 2A illustrates an exemplary wireless network structure 200. For example, a 5GC 210 (also referred to as a Next Generation Core (NGC)) may be functionally viewed as a control plane function 214 (e.g., UE registration, authentication, network access, gateway selection, etc.) and a user plane function 212 (e.g., UE gateway function, data network access, IP routing, etc.) that cooperate to form a core network. A user plane interface (NG-U) 213 and a control plane interface (NG-C) 215 connect a gNB 222 to the 5GC 210, specifically to the control plane function 214 and the user plane function 212. In an additional configuration, an ng-eNB 224 may also be connected to the 5GC 210 via the NG-C 215 to the control plane function 214 and the NG-U 213 to the user plane function 212. Furthermore, the ng-eNB 224 may communicate directly with the gNB 222 via a backhaul connection 223. In some configurations, the new RAN 220 may include only one or more gNBs 222, while other configurations include one or more of both an ng-eNB 224 and a gNB 222. Either the gNB 222 or the ng-eNB 224 may communicate with the UE 204 (e.g., any of the UEs shown in FIG. 1).

[0052] In some aspects, the wireless network structure 200 may include a location server 230 that can communicate with the 5GC 210 to provide location assistance for the UE 204. The location servers 230 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules distributed across multiple physical servers, etc.), or alternatively, each may correspond to a single server. The location servers 230 may be configured to support one or more location-based services for UEs 204 that can connect to the location server 230 via the core network 5GC 210 and / or via the Internet (not shown). Furthermore, the location server 230 may be integrated within a component of the core network, or alternatively, may reside outside the core network. In some embodiments, the location server 230 may be operated by a carrier or provider of the 5GC 210, a third party, an original equipment manufacturer (OEM), or other party. In some cases, multiple location servers may be provided, such as a location server for a carrier, a location server for an OEM of a particular device, and / or other location servers, etc. In such cases, location assistance data may be received from the carrier's location server and other assistance data may be received from the OEM's location server.

[0053] According to various aspects, FIG. 2B illustrates another exemplary wireless network structure 250. For example, a 5GC 260 may be viewed functionally as a control plane function provided by an access and mobility management function (AMF) 264 and a user plane function provided by a user plane function (UPF) 262, which cooperate to form a core network (i.e., 5GC 260). A user plane interface 263 and a control plane interface 265 connect an ng-eNB 224 to the 5GC 260, specifically to the UPF 262 and the AMF 264, respectively. In some embodiments, a gNB 222 may also be connected to the 5GC 260 via the control plane interface 265 to the AMF 264 and the user plane interface 263 to the UPF 262. Furthermore, the ng-eNB 224 may communicate directly with the gNB 222 via the backhaul connection 223, regardless of whether the gNB is directly connected to the 5GC 260. In some configurations, the new RAN 220 may have only one or more gNBs 222, while other configurations include one or more of both an ng-eNB 224 and a gNB 222. Either the gNB 222 or the ng-eNB 224 may communicate with the UE 204 (e.g., any of the UEs shown in FIG. 1). The base stations of the new RAN 220 communicate with the AMF 264 via an N2 interface and with the UPF 262 via an N3 interface.

[0054] The functions of the AMF 264 may include registration management, connection management, reachability management, mobility management, lawful intercept, transmission of session management (SM) messages between the UE 204 and a session management function (SMF) 266, a transparent proxy service for routing SM messages, access authentication and authorization, transmission of short message service (SMS) messages between the UE 204 and a short message service function (SMSF) (not shown), and security anchor functionality (SEAF). The AMF 264 may also interact with an authentication server function (AUSF) (not shown) and the UE 204 and may receive intermediate keys established as a result of the UE 204 authentication process.

[0055] In the case of universal mobile telecommunications system (UMTS) subscriber identity module (USIM)-based authentication, the AMF 264 may obtain security material from the AUSF. The AMF 264's functionality may also include security context management (SCM). The SCM may receive keys from the SEAF, which may be used to derive access-network specific keys. The AMF 264's functionality may also include location-based service management for restricted services, transmission of location-based service messages between the UE 204 and a location management function (LMF) 270 (acting as the location server 230), transmission of location-based service messages between the new RAN 220 and the LMF 270, allocation of EPS bearer identities for interoperation with an evolved packet system (EPS), and mobility event notification for the UE 204. Furthermore, the AMF 264 may also support functionality for non-3GPP access networks.

[0056] In some cases, the UPF 262 may perform functions including serving as an anchor point for intra-RAT / inter-RAT mobility (where applicable), acting as an external protocol data unit (PDU) session point for interconnection to a data network (not shown), providing packet routing and forwarding, packet inspection, user plane policy rule enforcement (e.g., gating, redirection, traffic steering), lawful interception (user plane collection), traffic usage reporting, quality of service (QoS) processing for the user plane (e.g., uplink and / or downlink rate enforcement, reflected QoS marking in the downlink), uplink traffic validation (service data flow (SDF) to QoS flow mapping), transport-level packet marking in the uplink and downlink, buffering of downlink packets and triggering of downlink data notifications, and sending and forwarding one or more "end markers" to the source RAN node. In some aspects, the UPF 262 may also support forwarding location service messages over the user plane between the UE 204 and a location server, such as a secure user plane location (SUPL) location platform (SLP), not shown in FIG. 2B.

[0057] In some embodiments, the functions of the SMF 266 may include session management, allocation and management of Internet protocol (IP) addresses for UEs, selection and control of user plane functions, configuration of traffic steering in the UPF 262 to route traffic to the appropriate destination, control of policy enforcement and portions of QoS, and downlink data notification. The interface through which the SMF 266 communicates with the AMF 264 may be referred to as the N11 interface.

[0058] In some aspects, the wireless network structure 250 may include an LMF 270 that may communicate with the 5GC 260 to provide location assistance for the UE 204. The LMF 270 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules distributed across multiple physical servers, etc.), or alternatively, each may correspond to a single server. The LMF 270 may be configured to support one or more location-based services for the UE 204 that may connect to the LMF 270 via the core network 5GC 260 and / or via the Internet (not shown). The SLP may support similar functionality as the LMF 270, but the LMF 270 may communicate with the AMF 264, the new RAN 220, and the UE 204 via the control plane (e.g., using interfaces and protocols intended to carry signaling messages rather than voice or data), while the SLP may communicate with the UE 204 and external clients (not shown in FIG. 2B) via the user plane (e.g., using protocols intended to carry voice and / or data, such as transmission control protocol (TCP) and / or IP).

[0059] In some cases, the LMF 270 and / or the SLP may be integrated with a base station, such as the gNB 222 and / or the ng-eNB 224. When integrated with the gNB 222 and / or the ng-eNB 224, the LMF 270 and / or the SLP may be referred to as a "location management component" or "LMC." As used herein, references to the LMF 270 and the SLP include both when the LMF 270 and the SLP are components of a core network (e.g., the 5GC 260) and when the LMF 270 and the SLP are components of a base station.

[0060] As described above, a wireless communication system supports communication between multiple UEs. In various embodiments, the wireless communication system may be configured to support device-to-device (D2D) communication and / or vehicle-to-everything (V2X) communication. V2X may also be referred to as cellular V2X (C-V2X). V2X communication may be implemented using any radio access technology, such as LTE, 5G, WLAN, or other communication protocols. In some embodiments, a UE may transmit and receive V2X messages to and from other UEs, roadside units (RSUs), and / or other devices via a direct communication link or interface (e.g., a PC5 or sidelink interface, an 802.11p DSRC interface, and / or other communication interface) and / or via a network (e.g., an eNB, a WiFi AP, and / or other network entity). Communications may be carried out using resources allocated by the network (e.g., an eNB or other network device), resources pre-configured for V2X use, and / or resources determined by the UE (e.g., using clear channel assessment (CCA) regarding the resources of the 802.11 network).

[0061] V2X communications may include communications between vehicles (e.g., vehicle-to-vehicle (V2V)), between vehicles and infrastructure (e.g., vehicle-to-infrastructure (V2I)), between vehicles and pedestrians (e.g., vehicle-to-pedestrian (V2P)), and / or between vehicles and a network server (vehicle-to-network (V2N)). For V2V, V2P, and V2I communications, data packets may be transmitted directly between vehicles (e.g., using a PC5 interface, an 802.11 DSRC interface, etc.) without going through a network, eNB, or gNB. V2X-enabled vehicles may use, for example, short-range direct communication modes to complement onboard line-of-sight (LOS) sensors such as cameras, radio detection and ranging (RADAR), and light detection and ranging (LIDAR), among other sensors, by providing 360° non-line-of-sight (NLOS) sensing. The combination of wireless technology and onboard sensors enables V2X vehicles to visually observe, hear, and / or anticipate potential driving hazards (e.g., at intersections with poor visibility, in adverse weather conditions, and / or other scenarios). V2X vehicles may also understand warnings or notifications from other V2X-enabled vehicles (based on V2V communication), from infrastructure systems (based on V2I communication), and from user devices (based on V2P communication). Infrastructure systems may include roads, stoplights, road signs, bridges, toll booths, and / or other infrastructure systems that may communicate with vehicles using V2I messaging.

[0062] Depending on the desired implementation, sidelink communications may be conducted in accordance with the 3GPP communication protocol Sidelink (e.g., using a PC5 sidelink interface in accordance with LTE, 5G, etc.), a Wi-Fi direct communication protocol (e.g., the DSRC protocol), or using any other device-to-device communication protocol. In some embodiments, sidelink communications may be conducted using one or more Unlicensed National Information Infrastructure (U-NII) bands. For example, sidelink communications may be conducted in bands corresponding to the U-NII-4 band (5.850-5.925 GHz), the U-NII-5 band (5.925-6.425 GHz), the U-NII-6 band (6.425-6.525 GHz), the U-NII-7 band (6.525-6.875 GHz), the U-NII-8 band (6.875-7.125 GHz), or any other frequency band that may be suitable for conducting sidelink communications.

[0063] FIG. 3 illustrates examples of various communication mechanisms used by various UEs. In one example, FIG. 3 illustrates a vehicle 304, a vehicle 305, and a roadside unit (RSU) 303 that may communicate with each other using a PC5 signaling interface. Additionally, the vehicle 304 and the vehicle 305 may communicate with a base station 302 (shown as BS 302) using a network (Uu) interface. In some examples, the base station 302 may include a gNB (e.g., base station 102). FIG. 3 also illustrates a user device 307 that communicates with the base station 302 using the network (Uu) interface. In some aspects, functionality may be transferred from a vehicle (e.g., vehicle 304) to a user device (e.g., user device 307) based on one or more characteristics or factors (e.g., temperature, humidity, etc.). In one exemplary embodiment, V2X capabilities may be transferred from vehicle 304 to user device 307, which may then communicate with other vehicles (e.g., vehicle 305) via a PC5 interface, as shown in FIG. 3.

[0064] 3 shows a PC5 interface, various UEs (e.g., vehicles, user devices, etc.) and RSUs may communicate directly using any suitable type of direct interface, such as an 802.11 DSRC interface, a Bluetooth interface, and / or other interfaces. For example, a vehicle may communicate with a user device over a direct communication interface (e.g., using PC5 and / or DSRC), a vehicle may communicate with another vehicle over a direct communication interface, a user device may communicate with another user device over a direct communication interface, a UE (e.g., vehicle, user device, etc.) may communicate with an RSU over a direct communication interface, an RSU may communicate with another RSU over a direct communication interface, etc.

[0065] 4 is a block diagram illustrating an example vehicle computing system 450 of a vehicle 404. In some embodiments, the vehicle computing system 450 may be referred to as an on-board unit (OBU). The vehicle 404 is an example of a UE that may communicate with a network (e.g., an eNB, a gNB, a positioning beacon, a location measurement unit, and / or other network entities) via a Uu interface and may communicate with other UEs using V2X communications via a PC5 interface (or another direct device-to-device interface). As shown, the vehicle computing system 450 may include at least a power management system 451, a control system 452, an infotainment system 454, an intelligent transportation system (ITS) 455, one or more sensor systems 456, and a communication system 458. In some cases, vehicle computing system 450 may include or be implemented using any type of processing device or processing system, such as one or more central processing units (CPUs), digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), application processors (APs), graphics processing units (GPUs), vision processing units (VPUs), neural network signal processors (NSPs), microcontrollers, dedicated hardware, any combination thereof, and / or other processing devices or processing systems.

[0066] Control system 452 may be configured to control one or more operations of vehicle 404, power management system 451, computing system 450, infotainment system 454, ITS 455, and / or one or more other systems of vehicle 404 (e.g., braking system, steering system, safety systems other than ITS 455, cabin systems, and / or other systems). In some embodiments, control system 452 may include one or more electronic control units (ECUs). An ECU may control one or more of the electronic systems or subsystems within the vehicle. Examples of specific ECUs that may be included as part of control system 452 include, among others, an engine control module (ECM), a powertrain control module (PCM), a transmission control module (TCM), a brake control module (BCM), a central control module (CCM), and a central timing module (CTM). In some cases, the control system 452 may receive sensor signals from one or more sensor systems 456 and may communicate with other systems of the vehicle computing system 450 to operate the vehicle 404.

[0067] Vehicle computing system 450 also includes a power management system 451. In some implementations, power management system 451 may include a power management integrated circuit (PMIC), a backup battery, and / or other components. In some cases, other systems of vehicle computing system 450 may include one or more PMICs, batteries, and / or other components. Power management system 451 may perform power management functions for vehicle 404, such as managing the power supply for computing system 450 and / or other parts of the vehicle. For example, power management system 451 may provide a stable power supply, accounting for power fluctuations, such as due to starting the vehicle's engine. In another example, power management system 451 may perform thermal monitoring operations, such as by checking ambient temperature and / or transistor junction temperature. In another example, based on detecting a particular temperature level, power management system 451 may perform certain functions, such as causing a cooling system (e.g., one or more fans, an air conditioning system, etc.) to cool certain components of vehicle computing system 450 (e.g., control system 452, such as one or more ECUs), terminating certain functions of vehicle computing system 450 (e.g., restricting infotainment system 454 by stopping one or more displays, disconnecting from a wireless network, etc.), among other functions.

[0068] Vehicle computing system 450 further includes a communications system 458. Communications system 458 may include both software and hardware components for transmitting and receiving signals to and from a network (e.g., with a gNB or other network entity via a Uu interface) and / or with other UEs (e.g., with another vehicle or UE via a PC5 interface, a WiFi interface, a Bluetooth interface, and / or other wireless and / or wired interfaces). For example, communications system 458 is configured to transmit and receive information wirelessly via any suitable wireless network (e.g., a 3G network, a 4G network, a 5G network, a WiFi network, a Bluetooth network, and / or other networks). Communications system 458 includes various components or devices used to implement wireless communications functions, including an original equipment manufacturer (OEM) subscriber identity module (also referred to as a SIM or SIM card) 460, a user SIM 462, and a modem 464. Although vehicle computing system 450 is shown as having two SIMs and one modem, in some implementations, computing system 450 may have any number of SIMs (e.g., one SIM or three or more SIMs) and any number of modems (e.g., one modem, two modems, or three or more modems).

[0069] A SIM is a device (e.g., an integrated circuit) that can securely store a particular subscriber or user's international mobile subscriber identity (IMSI) number and associated keys (e.g., encryption-decryption keys). These IMSIs and keys can be used to identify and authenticate a subscriber on a particular UE. The OEM SIM 460 can be used by the communication system 458 to establish wireless connections for vehicle-based operations, such as to perform emergency-calling (eCall) functions, communicate with the vehicle manufacturer's communication system (e.g., for software updates), among other operations. The OEM SIM 460 can be used to support one or more emergency services, such as eCall, for making emergency calls in the event of a vehicle accident or other emergency. For example, eCall can include a service that automatically dials an emergency number (e.g., "9-1-1" in the United States, "1-1-2" in Europe, etc.) in the event of a vehicle accident and communicates the vehicle's location to emergency services such as the police and fire departments.

[0070] User SIM 462 may be used by communication system 458 to perform wireless network access functions to support user data connectivity (e.g., to conduct calling, messaging, infotainment-related services, among others). In some cases, the user's user device may connect to vehicle computing system 450 via an interface (e.g., PC5, Bluetooth, WiFi, universal serial bus (USB) port, and / or other wireless or wired interface). Once connected, the user device may transfer wireless network access functions from the user device to the vehicle's communication system 458, in which case the user device may cease performing wireless network access functions (e.g., during periods when communication system 458 is performing the wireless access functions). Communication system 458 may initiate contact with a base station to perform one or more wireless communication operations, such as facilitating a call, transmitting and / or receiving data (e.g., messaging, video, voice, etc.), among other operations. In such cases, other components of vehicle computing system 450 may be used to output data received by communication system 458. For example, infotainment system 454 (described below) may display video received by communication system 458 on one or more displays and / or output audio received by communication system 458 using one or more speakers.

[0071] A modem is a device that modulates one or more carrier signals to encode digital information for transmission and demodulates the signals to decode the transmitted information. Modem 464 (and / or one or more other modems of communication system 458) may be used for communication of data for OEM SIM 460 and / or user SIM 462. In some embodiments, modem 464 may include a 4G (or LTE) modem, and another modem (not shown) of communication system 458 may include a 5G (or NR) modem. In some embodiments, communication system 458 may include one or more Bluetooth® modems (e.g., for Bluetooth® low energy (BLE) or other types of Bluetooth communication), one or more Wi-Fi® modems (e.g., for DSRC communication and / or other Wi-Fi communication), wideband modems (e.g., ultra-wideband (UWB) modems), any combination thereof, and / or other types of modems.

[0072] In some cases, modem 464 (and / or one or more other modems of communication system 458) may be used to conduct V2X communications (e.g., with other vehicles in the case of V2V communications, with other devices in the case of D2D communications, with infrastructure systems in the case of V2I communications, with pedestrian UEs in the case of V2P communications, etc.). In some embodiments, communication system 458 may include a V2X modem used to conduct V2X communications (e.g., sidelink communications over the PC5 interface), which may be separate from one or more modems used for wireless network access functions (e.g., for network communications over the network / Uu interface and / or for sidelink communications other than V2X communications).

[0073] In some examples, communication system 458 may be or may include a telematics control unit (TCU). In some implementations, the TCU may include a network access device (NAD) (sometimes referred to as a network control unit or NCU). The NAD may include modem 464, any other modems not shown in FIG. 4 , OEM SIM 460, user SIM 462, and / or other components used for wireless communications. In some examples, communication system 458 may include a global navigation satellite system (GNSS). In some cases, the GNSS may be part of one or more sensor systems 456, as described below. The GNSS may provide the capability for vehicle computing system 450 to perform one or more location services, navigation services, and / or other services that may utilize GNSS functionality.

[0074] In some cases, the communications system 458 may further include one or more wireless interfaces for transmitting and receiving wireless communications (e.g., including, for each wireless interface, one or more transceivers and one or more baseband processors), one or more wired interfaces for implementing communications over one or more hardwired connections (e.g., serial interfaces such as Universal Serial Bus (USB) inputs, lightening connectors, and / or other wired interfaces), and / or other components that may enable the vehicle 404 to communicate with a network and / or other UEs.

[0075] The vehicle computing system 450 may also include an infotainment system 454 that may control content, as well as one or more output devices of the vehicle 404 that may be used to output content. The infotainment system 454 may also be referred to as an in-vehicle infotainment (IVI) system or an in-car entertainment (ICE) system. The content may include navigation content, media content (e.g., video content, music or other audio content, and / or other media content), among other content. The one or more output devices may include one or more graphical user interfaces, one or more displays, one or more speakers, one or more extended reality devices (e.g., VR, AR, and / or MR headsets), one or more haptic feedback devices (e.g., one or more devices configured to vibrate a seat, a steering wheel, and / or other parts of the vehicle 404), and / or other output devices.

[0076] In some embodiments, computing system 450 may include an intelligent transportation system (ITS) 455. In some embodiments, ITS 455 may be used to implement V2X communications. For example, the ITS stack of ITS 455 may generate V2X messages based on information from an application layer of the ITS. In some cases, the application layer may determine whether certain conditions are met to generate messages used by ITS 455 and / or to generate messages to be transmitted to other vehicles (in the case of V2V communications), pedestrian UEs (in the case of V2P communications), and / or infrastructure systems (in the case of V2I communications). In some cases, communication system 458 and / or ITS 455 may obtain car access network (CAN) information (e.g., from other components of the vehicle via a CAN bus). In some embodiments, communication system 458 (e.g., a TCU NAD) may obtain CAN information via a CAN bus and transmit the CAN information to the ITS stack. The CAN information may include vehicle-related information such as vehicle direction, vehicle speed, braking information, etc. The CAN information may be provided to the ITS 455 continuously or periodically (e.g., every millisecond (ms), every 10 ms, etc.).

[0077] The conditions used to determine whether to generate a message can be determined using the CAN information based on safety-related and / or other applications, including traffic safety, traffic efficiency, infotainment, business-related, and / or other applications. In one exemplary embodiment, the ITS 455 can perform lane change assistance or negotiation. For example, using the CAN information, the ITS 455 can determine that the driver of the vehicle 404 is attempting to change lanes from a current lane to an adjacent lane (e.g., based on a turn signal being activated, the user veering or steering into the adjacent lane, etc.). Based on determining that the vehicle 404 is attempting to change lanes, the ITS 455 can determine that a lane change condition has been met that is associated with a message to be sent to other vehicles in the adjacent lane that are nearby the vehicle. The ITS 455 can trigger the ITS stack to generate one or more messages to send to other vehicles, which can be used to negotiate a lane change with the other vehicles. Other example applications include forward collision warning, automatic emergency braking, lane departure warning, pedestrian avoidance or protection (e.g., when a pedestrian is detected near the vehicle 404 based on V2P communication with the user's UE, etc.), and traffic sign recognition, among others.

[0078] ITS 455 may generate messages (e.g., V2X messages) using any suitable protocol. Examples of protocols that may be used by ITS 455 include one or more Society of Automotive Engineering (SAE) standards, such as SAE J2735, SAE J2945, SAE J3161, and / or other standards, which are incorporated by reference herein in their entirety for all purposes.

[0079] The security layer of ITS 455 may be used to securely sign messages from the ITS stack that are sent to and verified by other UEs configured for V2X communications, such as other vehicles, pedestrian UEs, and / or infrastructure systems. The security layer may also validate messages received from such other UEs. In some implementations, this signing and verification process may be based on the vehicle's security context. In some examples, the security context may include one or more encryption-decryption algorithms, public and / or private keys used to generate signatures using the encryption-decryption algorithms, and / or other information. For example, each ITS message generated by the ITS stack may be signed by the security layer. This signature may be derived using the public key and the encryption-decryption algorithm. A vehicle, pedestrian UE, and / or infrastructure system receiving a signed message may verify the signature to ensure that the message is from an authorized vehicle. In some embodiments, the one or more encryption-decryption algorithms may include one or more symmetric encryption algorithms (e.g., advanced encryption standard (AES), data encryption standard (DES), and / or other symmetric encryption algorithms), one or more asymmetric encryption algorithms using public and private keys (e.g., Rivest-Shamir-Adleman (RSA) and / or other asymmetric encryption algorithms), and / or other encryption-decryption algorithms.

[0080] In some embodiments, ITS 455 may determine specific actions (e.g., V2X-based actions) to take based on messages received from other UEs. These actions may include safety-related actions and / or other actions, such as actions related to road safety, traffic efficiency, infotainment, business, and / or other applications. In some embodiments, these actions may include causing the vehicle (e.g., control system 452) to perform automated functions such as automatic braking, automatic steering (e.g., to maintain a heading within a particular lane), automated lane change negotiation with other vehicles, among other automated functions. In one exemplary embodiment, a message may be received from another vehicle by communication system 458 (e.g., via a PC5 interface) indicating that the other vehicle is about to make an emergency stop. In response to receiving the message, ITS 455 may generate a message or command and transmit the message or command to control system 452, which may cause control system 452 to automatically brake vehicle 404 to stop before colliding with the other vehicle. In other example embodiments, these actions may include triggering the display of a message alerting the driver to the presence of another vehicle in the lane next to the vehicle, a message alerting the driver to stop the vehicle, a message alerting the driver to the presence of a pedestrian in the crosswalk ahead, a message alerting the driver to the presence of a toll booth within a certain distance (e.g., within one mile) of the vehicle, among other things.

[0081] Computing system 450 further includes one or more sensor systems 456 (e.g., a first sensor system through an Nth sensor system, where N is a value greater than or equal to 0). When including multiple sensor systems, sensor systems 456 may include different types of sensor systems that may be located on or within different portions of vehicle 404. The sensor system 456 may include one or more camera sensor systems, light detection and ranging (LIDAR) sensor systems, radio detection and ranging (RADAR) sensor systems, electromagnetic detection and ranging (EmDAR) sensor systems, sound navigation and ranging (SONAR) sensor systems, sound detection and ranging (SODAR) sensor systems, global navigation satellite system (GNSS) receiver systems (e.g., one or more global positioning system (GPS) receiver systems), accelerometers, gyroscopes, inertial measurement units (IMUs), infrared sensor systems, laser range finder systems, ultrasonic sensor systems, infra-red sensor systems, microphones, any combination thereof, and / or other sensor systems. It should be understood that any number of sensors or sensor systems may be included as part of the computing system 450 of the vehicle 404.

[0082] While vehicle computing system 450 is shown to include certain components and / or systems, one skilled in the art will understand that vehicle computing system 450 may include more or fewer components than those shown in FIG. 4 . For example, vehicle computing system 450 may also include one or more input devices and one or more output devices (not shown). In some implementations, vehicle computing system 450 may also include at least one processor (e.g., as part of control system 452, infotainment system 454, communication system 458, and / or sensor system 456, or separate therefrom) and at least one memory having computer-executable instructions executed by the at least one processor. The at least one processor is in communication with and / or electrically connected to (referred to as "coupled" or "communicatively coupled to") the at least one memory. The at least one processor may include, for example, one or more microcontrollers, one or more central processing units (CPUs), one or more field programmable gate arrays (FPGAs), one or more graphics processing units (GPUs), one or more application processors (e.g., for launching or executing one or more software applications), and / or other processors. The at least one memory may include, for example, read-only memory (ROM), random access memory (RAM) (e.g., static RAM (SRAM)), electrically erasable programmable read-only memory (EEPROM), flash memory, one or more buffers, one or more databases, and / or other memories.One or more of the functions or operations described herein can be performed by executing computer-executable instructions stored at least in or on the memory.

[0083] 5 illustrates one embodiment of a computing system 570 of a wireless device 507. The wireless device 507 may include a client device, such as a UE (e.g., a UE 104, a WLAN STA 152, a UE 190) or other type of device (e.g., a station (STA) configured to communicate using a Wi-Fi interface) that can be used by an end user. The wireless device may also include a network device (e.g., a base station such as an eNB and / or a gNB, a Wi-Fi access point (AP) such as a router, a range extender, etc.). For example, the wireless device 507 may include a mobile phone, a router, a tablet computer, a laptop computer, a tracking device, a wearable device (e.g., a smart watch, glasses, an extended reality (XR) device, e.g., a virtual reality (VR), an augmented reality (AR), or a mixed reality (MR) device, etc.), an Internet of Things (IoT) device, a base station, an access point, and / or another device configured to communicate over a wireless communications network. Computing system 570 includes software and hardware components that may be electrically or communicatively coupled (or may communicate in other manners, as appropriate) via a bus 589. For example, computing system 570 includes one or more processors 584. One or more processors 584 may include one or more CPUs, ASICs, FPGAs, APs, GPUs, VPUs, NSPs, microcontrollers, special purpose hardware, any combination thereof, and / or other processing devices or systems. Bus 589 may be used by one or more processors 584 to communicate between cores and / or to communicate with one or more memory devices 586.

[0084] The computing system 570 may also include one or more memory devices 586, one or more digital signal processors (DSPs) 582, one or more SIMs 574, one or more modems 576, one or more wireless transceivers 578, an antenna 587, one or more input devices 572 (e.g., a camera, a mouse, a keyboard, a touch-sensitive screen, a touchpad, a keypad, a microphone, etc.), and one or more output devices 580 (e.g., a display, speakers, a printer, etc.).

[0085] In some aspects, computing system 570 may include one or more radio frequency (RF) interfaces configured to transmit and / or receive RF signals. In some embodiments, the RF interface may include components such as a modem 576, a wireless transceiver 578, and / or an antenna 587. The one or more wireless transceivers 578 may transmit and receive wireless signals (e.g., signals 588) via antenna 587 from one or more other devices, such as other wireless devices, network devices (e.g., base stations such as eNBs and / or gNBs, Wi-Fi access points (APs) such as routers, range extenders, etc.), cloud networks, etc. In some embodiments, computing system 570 may include multiple antennas or an antenna array that may facilitate simultaneous transmission and reception capabilities. Antenna 587 may be an omnidirectional antenna that may transmit and receive radio frequency (RF) signals in all directions. The wireless signals 588 may be transmitted over a wireless network. The wireless network may be any wireless network, such as a cellular network or telecommunications network (e.g., 3G, 4G, 5G, etc.), a wireless local area network (e.g., a Wi-Fi network), a Bluetooth® network, and / or other network.

[0086] In some embodiments, the wireless signals 588 may be transmitted directly to other wireless devices using sidelink communications (e.g., using a PC5 interface, using a DSRC interface, etc.). The wireless transceiver 578 may be configured to transmit RF signals for conducting sidelink communications via the antenna 587 in accordance with one or more transmit power parameters that may be associated with one or more coordination modes. The wireless transceiver 578 may also be configured to receive sidelink communication signals having different signal parameters from other wireless devices.

[0087] In some embodiments, one or more wireless transceivers 578 may include an RF front end that includes one or more components such as an amplifier, a mixer (also referred to as a signal multiplier) for signal downconversion, a frequency synthesizer (also referred to as an oscillator) that provides signals to the mixer, a baseband filter, an analog-to-digital converter (ADC), one or more power amplifiers, etc. The RF front end may generally handle the selection and conversion of the wireless signal 588 to a baseband frequency or an intermediate frequency, and may convert the RF signal to the digital domain, among other components.

[0088] In some cases, computing system 570 may include an encoding-decoding device (or CODEC) configured to encode and / or decode data transmitted and / or received using one or more wireless transceivers 578. In some cases, computing system 570 may include an encryption-decryption device or component configured to encrypt and / or decrypt data transmitted and / or received by one or more wireless transceivers 578 (e.g., according to the AES and / or DES standards).

[0089] One or more SIMs 574 may each securely store an International Mobile Subscriber Identity (IMSI) number and associated keys assigned to a user of the wireless device 507. The IMSI and keys may be used to identify and authenticate a subscriber when accessing a network provided by a network service provider or operator associated with the one or more SIMs 574. One or more modems 576 may modulate one or more signals to encode information for transmission using one or more wireless transceivers 578. The one or more modems 576 may also demodulate signals received by the one or more wireless transceivers 578 to decode the transmitted information. In some embodiments, the one or more modems 576 may include a Wi-Fi modem, a 4G (or LTE) modem, a 5G (or NR) modem, and / or other types of modems. The one or more modems 576 and the one or more wireless transceivers 578 may be used to communicate data related to the one or more SIMs 574.

[0090] Computing system 570 may also include (and / or be in communication with) one or more non-transitory machine-readable storage media or devices (e.g., one or more memory devices 586), which may include, but are not limited to, local and / or network-accessible storage, disk drives, drive arrays, optical storage devices, solid-state storage devices such as RAM and / or ROM, which may be programmable, flash-updateable, etc. Such storage devices may be configured to implement any suitable data storage mechanism, including, but not limited to, various file systems, database structures, etc.

[0091] In various embodiments, functions may be stored as one or more computer program products (e.g., instructions or code) in memory device 586 and executed by one or more processors 584 and / or one or more DSPs 582. Computing system 570 may also include software elements (e.g., located in one or more memory devices 586), including, for example, an operating system, device drivers, executable libraries, and / or other code such as one or more application programs, which may include computer programs that implement the functions provided by various embodiments and / or may be designed to implement methods and / or configure systems as described herein.

[0092] In some aspects, the wireless device 507 may include means for performing the operations described herein, which may include one or more of the components of the computing system 570. For example, the means for performing the operations described herein may include one or more of the input device 572, the SIM 574, the modem 576, the wireless transceiver 578, the output device (580), the DSP 582, the processor (584), the memory device 586, and / or the antenna 587.

[0093] In some aspects, the wireless device 507 may correspond to a user equipment (UE) and may include means for providing security for broadcasting and / or groupcasting sidelink positioning. In some embodiments, in the user equipment (UE), the means for generating a message including information associated with positioning reference signaling may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In this disclosure, the term “positioning reference signaling” may refer to the exchange of signals and / or messages to assist in position determination. In some embodiments, the means for obtaining a group identifier indicating a group to which the UE belongs may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for obtaining a group key and a group key identifier associated with the group key may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In this disclosure, the term "group key identifier" may refer to an identifier (e.g., a code or number) that may be associated with and / or used to identify a group key.In some embodiments, the means for obtaining a UE identifier indicative of the UE may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In this disclosure, the term “UE identifier” may refer to an identifier (e.g., a code or number) that may be associated with and / or used to identify a UE. In some embodiments, the means for deriving a traffic key based on the group key, the group identifier, and the UE identifier may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In this disclosure, the term “traffic key” may be used to refer to an encryption key that may be used in accordance with various aspects of the present disclosure to protect messages. In some embodiments, the means for deriving encryption keys and integrity keys based on the traffic key may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of the wireless device.In some embodiments, the means for generating a message header for the message, the message header including the group identifier and the group key identifier, may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for calculating a message authentication code (MAC) using the integrity key, the message, and the message header may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for encrypting a message using an encryption key to generate an encrypted message may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for encrypting a MAC using an encryption key to generate an encrypted MAC may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device.In some embodiments, the means for transmitting the message header, the encrypted message, and the encrypted MAC may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device.

[0094] In some embodiments, in a first user equipment (UE), means for receiving a packet from a second UE, the packet including an encrypted message associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header, wherein the message header includes a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key, may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for obtaining a group identifier indicating that the first UE also belongs to a group to which the second UE belongs may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for obtaining a group key and a group key identifier may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device.In some embodiments, the means for deriving traffic keys based on the group key may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for deriving encryption keys and integrity keys based on the traffic key may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for decrypting the encrypted message and the encrypted MAC using the encryption key to generate the decrypted message and the decrypted MAC may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device. In some embodiments, the means for calculating the predicted MAC based on the integrity key may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of a wireless device.In some embodiments, the means for verifying the integrity of the message by comparing the decoded MAC with the expected MAC may include one or more processors 584, one or more DSPs 582, one or more wireless transceivers 578, one or more modems 576, one or more memory devices 586, one or more wireless transceivers 578, one or more modems 576, one or more SIMs 574, any combination thereof, or other components of the wireless device.

[0095] As mentioned above, systems and techniques for providing security for sidelink positioning are described herein. FIG. 6 illustrates an example wireless communication system 600 for providing security for sidelink positioning. In some aspects, the system 600 may include a UE device such as a user equipment (UE) 602. The UE 602 may include a wireless communication device such as a vehicle (e.g., an automobile, a motorcycle, a bicycle, etc.), a mobile phone, a router, a tablet computer, a laptop computer, a tracking device, a wearable device (e.g., a smart watch, glasses, an extended reality (XR) device, such as a virtual reality (VR) headset, an augmented reality (AR) headset or glasses, or a mixed reality (MR) headset), an Internet of Things (IoT) device, or any other device capable of communicating over a wireless communication network.

[0096] In some embodiments, the system 600 may include one or more additional user equipment devices. For example, the system 600 may include one or more roadside units (e.g., RSUs 604, 606, etc.), one or more pedestrian UE devices (e.g., pedestrian UEs 608, 610, etc.), and one or more vehicles (e.g., vehicles 612, 614, etc.). In some configurations, the UE 602 may communicate with one or more of the RSUs 604, 606, pedestrian UEs 608, 610, vehicles 612, and / or vehicles 614 using sidelink communications (e.g., PC5, DSRC, etc.). In some configurations, the system 600 may also include a base station 616 that may be associated with the UE 602 (e.g., the UE 602 may communicate with the base station 616 using a network (Uu) interface). In some cases, the system 600 may also include a base station 618 associated with the RSU 604. In some aspects, the system 600 may include a location server 620, which may be coupled to or separate from the base station 616 and / or the base station 618.

[0097] In some aspects, one or more of the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614 may be configured to participate in sidelink positioning (e.g., by transmitting, receiving, and / or responding to positioning assistance messages and / or PRS messages). In some cases, the UE 602 may communicate with one or more devices (e.g., the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) using sidelink communications to implement one or more sidelink positioning algorithms (e.g., to determine the relative or absolute position of the UE 602).

[0098] In an example embodiment, the UE 602 may determine a distance between the UE 602 and two or more devices (e.g., the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) via sidelink communication (e.g., based on the PRS signal). The UE 602 may determine its relative position (e.g., with respect to the two or more devices, such as the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) based on the determined distance through multilateration, triangulation, or other positioning techniques. Additionally or alternatively, UE 602 may obtain location information data associated with two or more devices (e.g., RSU 604, RSU 606, pedestrian UE 608, pedestrian UE 610, vehicle 612, and / or vehicle 614) via sidelink communication and determine its absolute location by correcting the relative location based on the location information data.

[0099] In another example embodiment, the UE 602 may correspond to a vehicle that may obtain multiple measurements of PRS signals from a single device while the vehicle is moving. In some aspects, the vehicle (e.g., the UE 602) may include one or more sensors (e.g., the sensor system 456) that may be used to obtain measurements or data related to distance, speed, orientation, and / or any other type of measurement that may be obtained using the sensor system 456. In some examples, data from the sensors (e.g., the sensor system 456) may be used by the UE 602 to determine a distance traveled between measurements of PRS signals from devices (e.g., the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) to determine a relative and / or absolute position of the UE 602 using PRS signals from one or more devices (e.g., using a multilateration-based technique). Those skilled in the art will appreciate that the number of devices described herein are provided as example configurations and that the disclosed systems and techniques are not limited thereto.

[0100] In some cases, sidelink positioning may be or include ranging techniques between several devices (e.g., N devices, such as N UEs, where N is an integer value greater than or equal to 1) based on PRS round trip time (RTT) measurements. For example, each device may report its measured RTT along with its location (if known) to all other participating devices (e.g., UEs). For devices with limited or imprecise knowledge of their locations, the RTT provides the distance between the devices. If one or more of the devices (e.g., RSU 604 or RSU 606) have precise knowledge of their respective locations (e.g., stored in the respective memories of the one or more devices), the distance can provide an absolute location with respect to the other of the devices.

[0101] The system 600 (including the UE 602, the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) may implement a security scheme to provide security for the positioning assistance messages and / or PRS signals. For example, the system 600 (including one or more of the UE 602, the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) may encrypt the content of the positioning assistance messages and / or PRS messages to prevent non-intended recipients from accessing the content. Additionally or alternatively, the system 600 (including one or more of the UE 602, the RSU 604, the RSU 606, the pedestrian UE 608, the pedestrian UE 610, the vehicle 612, and / or the vehicle 614) may authenticate the content of the positioning assistance message and / or the PRS message (e.g., to prevent spoofing of the positioning assistance message and / or the PRS message).

[0102] 7 is a diagram illustrating various layers of a communication model 700. The communication model 700 includes a first UE 702 and a second UE 704. The first UE 702 and the second UE 704 are shown communicating using various layers, including a PHY layer 706, a medium access control layer 708, an RLC layer 710, a PDCP layer 712, a V2X / ProSe layer 714, and an SLPP layer 716.

[0103] For SL positioning (e.g., positioning based on sidelink communications), involved UEs (including, for example, the first UE 702 and the second UE 704) can exchange messages including their positioning capabilities, their assistance data, and their measurement results at the SLPP layer 716. The SLPP layer 716 may be implemented on top of the V2X / ProSe layer 714. Because multiple UEs may be involved in the session (e.g., in addition to the first UE 702 and the second UE 704 provided as examples), the messages may be exchanged using groupcast (a feature that may be supported by the V2X / ProSe layer 714). As mentioned above, systems and techniques for providing security for positioning assistance messages (e.g., at the SLPP layer 716) are described herein. For example, the systems and techniques may include encryption and authentication at the SLPP layer 716.

[0104] 8 is a sequence diagram illustrating an example of a sequence 800 for providing security for sidelink positioning (e.g., broadcast and / or groupcast security). The sequence 800 may be performed by a first UE 802, one or more additional UEs 804 (which may alternatively be referred to as UEs 804), and a group manager 806.

[0105] The first UE 802 may be or may include a vehicle (e.g., an automobile, a motorcycle, a bicycle, etc.), a wireless communication device (e.g., a mobile phone, a router, a tablet computer, a laptop computer, a tracking device, a wearable device, e.g., a smart watch, glasses, an extended reality (XR) device, e.g., a virtual reality (VR) headset, an augmented reality (AR) headset or glasses, or a mixed reality (MR) headset, etc.), an Internet of Things (IoT) device, or other device capable of communicating over a wireless communication network. The UE 804 may be or may include one or more vehicles, one or more wireless communication devices, one or more IoT devices, one or more roadside units, one or more pedestrian UE devices, etc.

[0106] The group manager 806 may be or may include a computing device capable of communicating, either directly or indirectly, with the first UE 802 and the UE 804. The group manager 806 may be or may include a group management network entity, a key management network entity, and / or a group and key management network entity. In this disclosure, the term “group management network entity” may refer to a computing device that may manage aspects of communications within a network. For example, the group management network entity may generate encryption keys for protecting communications within the network and / or provide those encryption keys to various devices in the network. A Sidelink Positioning Key Management Function (SLPKMF) is an example of a key management network entity. In some cases, the group manager 806 may reside in or be part of a base station (e.g., in one of the base stations 102). Additionally or alternatively, the group manager 806 may reside in, be part of, or be accessible through the core network 170. The group manager 806 may implement a key management function (KMF), or the group manager 806 may receive information from a KMF that may be collocated with the group manager 806 or remote from the group manager 806.

[0107] The first UE 802 may perform service authorization 808 with the group manager 806. During service authorization 808, the group manager 806 may authorize the first UE 802 to participate in sidelink positioning. For example, the first UE 802 may send a service request to the group manager 806. The group manager 806 may respond with an approval or authorization authorizing the first UE 802 to use the sidelink positioning service.

[0108] Following the service authorization 808, the first UE 802 may send a key request 810 to the group manager 806. The key request 810 may include a group identifier (alternatively, may be referred to herein as a “group ID”) of the first UE 802. In some cases, the first UE 802 may be pre-configured with the group identifier. In other cases, the group manager 806 may provide the group identifier to the first UE 802, for example, as part of the service authorization 808. The group identifier may identify a group to which the first UE 802 belongs. The group identifier may indicate that the first UE 802 is capable of performing sidelink positioning and / or participating in sidelink positioning with the UE 804. The key request 810 may further include information regarding the security capabilities of the first UE 802. For example, the key request 810 may include information regarding algorithms (e.g., encryption algorithms and / or integrity algorithms) that the first UE 802 is capable of performing. In this disclosure, the term "integrity algorithm" may refer to one or more algorithms (e.g., cryptographic functions) that may be used to generate information (e.g., a key) that may be used to verify the integrity of a message.

[0109] After receiving the key request 810, the group manager 806 may check the supported security capabilities of the first UE 802 in a check 812. For example, the group manager 806 may verify that the first UE 802 is capable of implementing sufficient and / or approved algorithms (including encryption and / or integrity algorithms).

[0110] If the group manager 806 approves the first UE 802 in the check 812, the group manager 806 may provide security material to the first UE 802 in a key response 814. The security material may include a sidelink positioning group key (which may be referred to herein as a “group key”), a sidelink positioning group key identifier (which may be referred to herein as a “group key identifier” or “group key ID”), and one or more algorithm identifiers (which may be referred to herein as “algorithm IDs”). The group key identifier may correspond to and / or identify a group key. Each of the algorithm identifiers may identify an algorithm (e.g., an encryption algorithm or an integrity algorithm) to be used by the first UE 802.

[0111] In some cases, such as to support sidelink positioning even when the first UE 802 is out of coverage (e.g., out of communication range with a base station), the group manager 806 may provide the first UE 802 with multiple sets of security material (including multiple group keys and corresponding group key identifiers) and corresponding validity times. Each set of security material may be valid for a specific time window as indicated by its validity time. For example, if the first UE 802 is capable of sidelink communication with the UE 804 but is out of communication range with the base station, the first UE 802 may still perform sidelink positioning by using the appropriate group key and group key identifier for the time indicated by its validity time.

[0112] In some cases, the security material may include a UE identifier. The UE identifier may identify the first UE 802. In other cases, the first UE 802 may select its own UE identifier. In some such cases, the first UE 802 may randomly select a UE identifier. In other cases, the first UE 802 may select another identifier associated with the first UE 802 (e.g., an identifier used by a lower layer as described with respect to FIG. 7) to identify the first UE 802. For example, the first UE 802 may select a medium access control address as its UE identifier.

[0113] If the group manager 806 provides UE identifiers (e.g., in security material), the group manager 806 may provide several UE identifiers and a corresponding number of usage configurations for privacy protection for UEs identified by the associated UE identifiers. The usage configurations may include validity periods for each UE identifier, several broadcast messages including each UE identifier, location information associated with each UE identifier, any combination thereof, and / or other information. For example, the group manager 806 may provide several UE identifiers, each UE identifier to be used during a different validity period or each to be used based on different location conditions. Additionally or alternatively, the group manager 806 may provide messages that may be broadcast by the first UE 802, which may include different UE identifiers.

[0114] The first UE 802 may determine a traffic key identifier (sometimes referred to herein as a "traffic key ID") based on the counter value, the group key, and the group key identifier. The traffic key identifier may indicate a traffic key. The first UE 802 may use the counter to ensure that the combination of the traffic key identifier and the group key identifier is unique. For example, the first UE 802 may set a unique value for the traffic key identifier that has not previously been used with a given group key identifier. In one example embodiment, the first UE 802 may select the value of the counter as the traffic key identifier. In some cases, the counter may be incremented each time a new traffic key identifier is derived so that a new counter value is used.

[0115] After receiving the key response 814 and determining the traffic key identifier, the first UE 802 may derive a key in a key derivation operation 818. For example, to perform the key derivation operation 818, the first UE 802 may derive a sidelink positioning traffic key (sometimes referred to herein as a “traffic key”). The first UE 802 may derive the sidelink positioning traffic key based on the group key (received in the key response 814), the group identifier of the first UE 802, the UE identifier of the first UE 802, and the traffic key identifier. In some cases, for example, if the first UE 802 is provided with multiple UE identifiers (e.g., in security material provided by the group manager 806), the first UE 802 may derive a separate traffic key each time it broadcasts a message.

[0116] After generating the traffic key, the first UE 802 may select an algorithm to be used to generate a sidelink positioning encryption key (which may be referred to herein as an “encryption key”) and a sidelink positioning integrity key (which may be referred to herein as an “integrity key”). For example, the first UE 802 may select an algorithm identified by one of the algorithm identifiers provided by the group manager 806 in the security material. If the security material included only one algorithm identifier, the first UE 802 may select the identified algorithm. The first UE 802 may then generate encryption and integrity keys based on the traffic key using the algorithm identified by the algorithm identifier.

[0117] The first UE 802 may generate a message (e.g., a positioning assistance message) including information associated with the positioning reference signaling. Additionally, the first UE 802 may generate a message header for the message. In one example embodiment, the message header may include a group identifier for the first UE 802, a UE identifier for the first UE 802, a group key identifier (associated with the group key used by the first UE 802 in generating the traffic key), a traffic key identifier, and an algorithm identifier indicating the algorithm used to generate the encryption and integrity keys. In some cases (e.g., if the first UE 802 selects a lower layer identifier as the UE identifier for the first UE 802), the header may not include the UE identifier for the first UE 802. The UE identifier may be identified by the recipient within data associated with the lower layer.

[0118] After deriving the encryption key and integrity key in the key derivation operation 818, the first UE 802 may calculate a message authentication code (MAC) based on the message, the message's header, the integrity key, and a counter value (e.g., a binary counter). After calculating the MAC, the first UE 802 may encrypt the message and MAC using the encryption key in an encryption operation 820. At least a portion of the counter value may be included in the header.

[0119] After encrypting the message and MAC in the encryption operation 820, the first UE 802 may transmit (in a sending operation 822) the header (including the group identifier of the first UE 802, the UE identifier of the first UE 802, the group key identifier, the traffic key identifier, the counter value used in generating the MAC, and the algorithm identifier), the encrypted message, and the encrypted MAC. In some cases, the UE 804 may expect the group identifier of the first UE 802, the UE identifier of the first UE 802, the group key identifier, the traffic key identifier, the counter value used in generating the MAC, and the algorithm identifier as a header, followed by the encrypted message, followed by the encrypted MAC. The sending operation 822 may include broadcasting or groupcasting the header, the encrypted message, and the encrypted MAC, for example, in a packet.

[0120] In some cases, the first UE 802 may transmit (e.g., in a header of a packet) a UE identifier of the first UE 802. In some cases, the first UE 802 may not transmit a UE identifier in the header because, for example, if the UE identifier is based on an identifier of the first UE 802 used by a lower layer (e.g., a medium access control layer) to identify the first UE 802, the UE 804 may be able to obtain the UE identifier from that lower layer.

[0121] The first UE 802 can provide security for messages, which may be positioning assistance messages, by encrypting the messages so that recipients without the key cannot decrypt the messages. In this way, the first UE 802 can provide security for broadcasts and / or groupcasts related to sidelink positioning.

[0122] A UE 804, which may be an intended recipient of the encrypted message, may receive a key to enable the UE 804 to decrypt the encrypted message so that the UE 804 can participate in sidelink positioning with the first UE 802. The UE 804 may perform operations similar to or the same as some of the operations described with respect to the first UE 802. For example, in the service 830, the UE 804 may perform operations similar to or the same as the service authorization 808. For example, in the service 830, the UE 804 may obtain authorization to participate in sidelink positioning. Furthermore, the UE 804 may send a key request similar to the key request 810 (including the UE 804's respective group identifier) ​​and receive a response similar to the key response 814 (including the UE 804's respective security material (including the respective group key, group key identifier, and one or more algorithm identifiers)).

[0123] The UE 804 may belong to the same group as the first UE 802. Thus, the UE 804 may receive the same group identifier, the same group key, the same group key identifier, and / or the same algorithm identifier that the first UE 802 received in the key response 814.

[0124] Following the service 830 and / or in response to receiving a transmission from the first UE 802, the UE 804 may derive a traffic key, an encryption key, and an integrity key. In a key derivation operation 832, the UE 804 may derive keys in a manner similar to how the first UE 802 derived keys in the key derivation operation 818. For example, the UE 804 may derive a traffic key based on a group key, a group identifier, a UE identifier of the first UE 802, and a traffic key identifier. The UE 804 may derive a traffic key based on a group key received at the service 830. Selection of a group key to use in deriving a traffic key may be based on a match between a group key identifier received in a header transmitted at the transmitting operation 822 and a group key identifier of a selected group key received at the service 830. The UE 804 may derive a traffic key based on a group identifier received in a header transmitted at the transmitting operation 822. The UE 804 may be part of the same group and may have received the group identifier at the service 830. The UE 804 may derive a traffic key based on the UE identifier received in the header sent in the sending operation 822. The UE 804 may derive a traffic key based on the traffic key identifier received in the header sent in the sending operation 822.

[0125] Because the first UE 802 and the UE 804 may use the same inputs (e.g., the same group key, group identifier, UE identifier (of the first UE 802), and traffic key identifier) ​​and the same algorithm when deriving the traffic key, the traffic key derived by the UE 804 in the key derivation operation 832 may be the same as the traffic key derived by the first UE 802 in the key derivation operation 818.

[0126] The UE 804 may further derive encryption and integrity keys in a manner similar to how the first UE 802 derived the keys in the key derivation operation 818. Specifically, the UE 804 may generate encryption and integrity keys based on the same traffic key (e.g., as derived independently at the first UE 802 in the key derivation operation 818 and at the UE 804 in the key derivation operation 832). Furthermore, the UE 804 may derive the encryption and integrity keys using the same algorithm used by the first UE 802 in generating the encryption and integrity keys. For example, the first UE 802 may receive one or more algorithm identifiers from the group manager 806 in the key response 814. The first UE 802 may select an algorithm identified by one of the received algorithm identifiers and generate the encryption and integrity keys using the selected algorithm. The first UE 802 may transmit an algorithm identifier in a header of the transmission transmitted in the transmitting operation 822 indicating the algorithm used by the first UE 802 to generate the encryption and integrity keys. The UE 804 may derive the encryption and integrity keys using the algorithm identified by the algorithm identifier received in the header of the transmission in the transmitting operation 822. Furthermore, the algorithm identifier may be included among one or more algorithm identifiers received in the security material by the UE 804 in the service 830. In some cases, the first UE 802 and the UE 804 may both receive only one algorithm identifier from the group manager 806 in the key response 814 and the service 830, respectively. In such cases, the first UE 802 may not include an algorithm identifier in the header of the transmission transmitted in the transmitting operation 822. In such cases, the first UE 802 and the UE 804 may both use the algorithm identified by the one algorithm identifier received from the group manager 806.

[0127] Because the first UE 802 and the UE 804 may use the same input (i.e., the same traffic key) and the same algorithm when deriving the encryption key and integrity key, the encryption key and integrity key derived by the UE 804 in the key derivation operation 832 may be the same as the encryption key and integrity key derived by the first UE 802 in the key derivation operation 818.

[0128] After deriving the encryption key and integrity key in the key derivation operation 832, the UE 804 may verify the integrity of the decrypted message in an authentication operation 834. For example, the UE 804 may use the encryption key to decrypt the message and MAC. Furthermore, the UE 804 may use the integrity key (received in the header in the send operation 822) and a counter to calculate a predicted MAC. The UE 804 may compare the received and decrypted MAC with the predicted MAC. If the received and decrypted MAC matches the predicted MAC, the UE 804 may authenticate the decrypted message.

[0129] By verifying the MAC, the UE 804 can verify the integrity of the decoded message before trusting it. In some cases, the message may be a positioning assistance message or another type of message. In embodiments where the message is a positioning assistance message, the UE 804 can provide broadcast and / or groupcast security for sidelink positioning.

[0130] 9 is a flowchart illustrating an example process 900 for providing broadcast and / or groupcast security for sidelink positioning. One or more operations described with respect to process 900 may be performed by a UE, such as the first UE 802 of FIG. 8.

[0131] At block 902, the process 900 may include generating, at a user equipment (UE), a message including information associated with the positioning reference signaling. The message may be a positioning assistance message. The information may include participant information indicating one or more intended recipients of the positioning reference signal (PRS), session information associated with communications between the UE and the one or more intended recipients, PRS measurements indicating signal strength of received PRSs, location information associated with a location of the UE, movement information associated with a movement of the UE, or any combination thereof, and / or other information useful for sidelink positioning.

[0132] At block 904, process 900 may include obtaining a group identifier indicating a group to which the UE belongs. In some cases, obtaining the group identifier at block 904 may include receiving the group identifier from a group management network entity, such as the group manager 806 of FIG. 8. In some cases, the group management network entity may include, implement, or be collocated with a KMF, which may provide the group identifier to the group management network entity. In other cases, the group management network entity may be remote from a KMF that may provide the group identifier to the group management network entity. In other cases, the UE may be pre-configured with a group identifier, and obtaining the group identifier at block 904 may include obtaining the group identifier from a memory in the UE's configuration space. At block 906, process 900 may include obtaining a group key and a group key identifier associated with the group key. In some cases, obtaining the group key and group key identifier in block 906 may include receiving the group key and group key identifier from a group management network entity, such as group manager 806 of FIG. 8. In some cases, the group management network entity may include, implement, or be co-located with a KMF, which may provide the group key and group key identifier to the group management network entity. In other cases, the group management network entity may be remote from the KMF, which may provide the group key and group key identifier to the group management network entity.

[0133] In some cases, receiving the group keys and group key identifiers in block 906 may include receiving several group keys and several respective group key identifiers. In such cases, process 900 may also include receiving several key expiration times from the group management network entity, each of the several key expiration times corresponding to a respective one of the several group keys and a respective one of the several group key identifiers. Each of the several key expiration times may indicate a period of time during which a respective one of the several group keys is valid.

[0134] At block 908, process 900 may include obtaining a UE identifier indicating the UE. The UE identifier may be or may include a group member identifier that identifies the UE within a group.

[0135] In some cases, obtaining the UE identifier in block 908 may include receiving the UE identifier from a group management network entity. In some cases, the group management network entity may include, implement, or be collocated with a KMF, which may provide the UE identifier to the group management network entity. In other cases, the group management network entity may be remote from a KMF that may provide the UE identifier to the group management network entity. In such cases, generating a message header (as described with respect to block 914) may include generating the message header to include the UE identifier.

[0136] In some cases, obtaining a UE identifier in block 908 may include receiving several UE identifiers. In such cases, process 900 may further include receiving a respective usage configuration associated with each of the several UE identifiers (e.g., a first usage configuration associated with a first UE identifier, a second usage configuration associated with a second UE identifier, a third usage configuration associated with a third UE identifier, etc.). Each of the usage configurations may include a validity time of the respective UE identifier, several broadcast messages including the respective UE identifier, location information associated with the respective UE identifier, any combination thereof, and / or other information. In such cases, generating a message header (as described with respect to block 914) may include generating the message header to include one of the several UE identifiers in accordance with the usage configurations.

[0137] In other cases, obtaining the UE identifier in block 908 may include generating the UE identifier by randomly selecting an identifier as the UE identifier. In such cases, generating the message header (as described with respect to block 914) may include generating the message header to include the UE identifier.

[0138] In still other cases, obtaining a UE identifier in block 908 may include selecting a Layer 2 identifier of the UE as the UE identifier.

[0139] At block 910, process 900 may include deriving a traffic key based on the group key, the group identifier, the UE identifier, any combination thereof, and / or based on other information. Process 900 may further include generating a traffic key identifier indicative of the traffic key. Generating the traffic key identifier may include generating the traffic key identifier such that a combination of the traffic key identifier and the group key identifier is unique. Deriving the traffic key at block 910 may include deriving the traffic key further based on the traffic key identifier. Generating a message header (as described with respect to block 914) may include generating the message header to include the traffic key identifier.

[0140] At block 912, process 900 may include deriving an encryption key and an integrity key based on the traffic key. Process 900 may further include receiving an encryption algorithm identifier from the group management network entity that indicates an encryption algorithm. Deriving the encryption key at block 912 may include deriving the encryption key further based on the encryption algorithm. Process 900 may further include receiving an integrity algorithm identifier from the group management network entity that indicates an integrity algorithm. Deriving the integrity key at block 912 may include deriving the integrity key further based on the integrity algorithm. In some cases, the group management network entity may include, implement, or be co-located with a KMF, which may provide the encryption algorithm identifier and / or integrity algorithm identifier to the group management network entity. In other cases, the group management network entity may be remote from a KMF that may provide the encryption algorithm identifier and / or integrity algorithm identifier to the group management network entity.

[0141] At block 914, process 900 may include generating a message header for the message (e.g., the message generated in block 902). The message header may include at least a group identifier and / or a group key identifier. In some cases (such as those described with respect to blocks 908, 910, and 916), the message header may further include a UE identifier (as described with respect to block 908), a traffic key identifier (as described with respect to block 910), a counter (as described with respect to block 916), any combination thereof, and / or other information.

[0142] At block 916, process 900 may include calculating a message authentication code (MAC) using the integrity key, the message, and the message header. Calculating the MAC at block 916 may include calculating the MAC further based on the counter value. Generating the message header at block 914 may include generating the message header to include at least a portion of the counter value. Calculating the MAC at block 916 may further be based on a traffic key identifier (as described with respect to block 910).

[0143] At block 918, process 900 may include encrypting the message using the encryption key to generate an encrypted message. Encrypting the message at block 918 may be further based on a traffic key identifier (as described with respect to block 910).

[0144] At block 920, process 900 may include encrypting the MAC using the encryption key to generate an encrypted MAC. The encrypting the MAC at block 920 may be further based on a traffic key identifier (as described with respect to block 910).

[0145] At block 922, process 900 may include transmitting the message header, the encrypted message, and the encrypted MAC. Transmitting the message header, the message, and the encrypted MAC may include broadcasting or groupcasting the message header, the message, and the encrypted MAC as or within a packet.

[0146] Process 900 can provide security for messages, which may be positioning assistance messages, by encrypting the messages so that recipients without the key cannot decrypt the messages. In this manner, process 900 can provide security for broadcasts and / or groupcasts related to sidelink positioning.

[0147] 10 is a flowchart illustrating an example process 1000 for providing security for broadcast and / or groupcast sidelink positioning. One or more operations described with respect to process 1000 may be performed by a UE, such as one or more of the UEs 804 of FIG. 8.

[0148] At block 1002, the process 1000 may include receiving, at a first UE, a packet from a second UE, the packet including an encrypted message, an encrypted MAC, and a message header. The message may include information associated with positioning reference signaling. The message may be a positioning assistance message. The information may include participant information indicating one or more intended recipients of a positioning reference signal (PRS), session information associated with communication between the UE and one or more intended recipients, PRS measurements indicating signal strength of received PRSs, location information associated with a location of the UE, movement information associated with a movement of the UE, or any combination thereof, and / or other information useful for sidelink positioning. The message header may include a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key. The message header may further include a traffic key identifier and / or a counter value. The encrypted message, encrypted MAC, and message header received at block 1002 may be the same as or substantially similar to the message header, encrypted message, and encrypted MAC sent at block 922 of process 900. At block 1004, process 1000 may include obtaining a group identifier. The group identifier may indicate that the first UE also belongs to a group to which the second UE belongs. For example, the first UE may obtain the group identifier at block 1004 from another source. The fact that the group identifier obtained by the first UE at block 1004 matches the group identifier in the message header received at block 1002 may indicate that the first UE belongs to the same group as the group to which the second UE belongs.

[0149] In some cases, obtaining the group identifier in block 1004 may include receiving the group identifier from a group management network entity, such as group manager 806 of FIG. 8. In some cases, the group management network entity may include, implement, or be collocated with a KMF, which may provide the group identifier to the group management network entity. In other cases, the group management network entity may be remote from a KMF that may provide the group identifier to the group management network entity. In other cases, the UE may be pre-configured with a group identifier, and obtaining the group identifier in block 1004 may include obtaining the group identifier from a memory in the UE's configuration space.

[0150] At block 1006, process 1000 may include obtaining a group key and a group key identifier. The group key identifier obtained at block 1006 may match the group key identifier in the message header received at block 1002. The group key identifier may indicate the group key received at block 1006.

[0151] In some cases, obtaining the group key and group key identifier in block 1006 may include receiving the group key and group key identifier from a group management network entity, such as group manager 806 of FIG. 8. In some cases, the group management network entity may include, implement, or be co-located with a KMF, which may provide the group key and group key identifier to the group management network entity. In other cases, the group management network entity may be remote from the KMF, which may provide the group key and group key identifier to the group management network entity.

[0152] At block 1008, process 1000 may include deriving a traffic key based on the group key. The message header received at block 1002 may further include a UE identifier indicating the second UE, a traffic key identifier indicating the traffic key, and a counter. Deriving the traffic key may include deriving the traffic key further based on the group identifier, the UE identifier, and the traffic key identifier. The UE identifier may be or include a group member identifier that identifies the second UE in the group.

[0153] At block 1010, process 1000 may include deriving an encryption key and an integrity key based on the traffic key. In some cases, process 1000 may further include receiving an encryption algorithm identifier from the group management network entity that indicates an encryption algorithm. Deriving the encryption key at block 1010 may include deriving the encryption key further based on the encryption algorithm. In some cases, process 1000 may further include receiving an integrity algorithm identifier from the group management network entity that indicates an integrity algorithm. Deriving the integrity key at block 1010 may include deriving the integrity key further based on the integrity algorithm. In some cases, the group management network entity may include, implement, or be co-located with a KMF, which may provide the encryption algorithm identifier and / or integrity algorithm identifier to the group management network entity. In other cases, the group management network entity may be remote from a KMF that may provide the encryption algorithm identifier and / or integrity algorithm identifier to the group management network entity.

[0154] In some cases, the message header received in block 1002 may include an encryption algorithm identifier. Deriving an encryption key in block 1010 may include deriving the encryption key further based on the encryption algorithm identified by the encryption algorithm identifier received in the message header. In some cases, the message header received in block 1002 may include an integrity algorithm identifier. Deriving an integrity key in block 1010 may include deriving the integrity key further based on the integrity algorithm identified by the integrity algorithm identifier received in the message header.

[0155] At block 1012, process 1000 may include decrypting the encrypted message using the encryption key to generate a decrypted message. The message header may further include a traffic key identifier indicating the traffic key and a counter. At block 1012, decrypting the encrypted message may further include decrypting the encrypted message using the traffic key identifier and the counter.

[0156] At block 1014, process 1000 may include decrypting the encrypted MAC using the encryption key to generate a decrypted MAC. The message header may further include a traffic key identifier indicating the traffic key and a counter. At block 1014, decrypting the encrypted MAC may further include decrypting the encrypted MAC using the traffic key identifier and the counter.

[0157] At block 1016, process 1000 may include calculating a predicted MAC based on the integrity key. Calculating the predicted MAC at block 1016 may include calculating the predicted MAC further based on a traffic key identifier indicative of the traffic key and a counter value. The traffic key identifier and the counter value may be received in the message header at block 1002.

[0158] At block 1018, the process 1000 verifies the integrity of the decoded message by comparing the decoded MAC with the expected MAC.

[0159] By verifying the MAC, process 1000 may verify the integrity of the message, which may be a positioning assistance message, before trusting the message. In this manner, process 1000 may provide broadcast and / or groupcast security for sidelink positioning.

[0160] Modifications, additions, or omissions may be made to the processes described herein (e.g., process 900, process 1000, and / or other processes described herein) without departing from the scope of the present disclosure. For example, the operations of process 900 and / or process 1000 may be performed in a different order. Furthermore, the outlined operations and actions are provided by way of example only, and some of the operations and actions may be optional, combined into fewer operations and actions, or expanded into additional operations and actions without detracting from the essence of the disclosed embodiments.

[0161] In some examples, the processes described herein (e.g., process 900, process 1000, and / or other processes described herein) may be performed by a computing device or apparatus (e.g., a UE, a base station, etc.). In one example, process 900 and / or process 1000 may be performed by a wireless communication device such as a UE (e.g., vehicle 404 of FIG. 4, a mobile device, and / or other UE or device). In another example, process 900 and / or process 1000 may be performed by a computing device having computing system 1100 shown in FIG. 11. For example, a wireless communication device (e.g., vehicle 404 of FIG. 4, a mobile device, and / or other UE or device) having the computing architecture shown in FIG. 11 may include components of a UE and may implement the operations of process 900 and / or process 1000.

[0162] In some cases, a computing device or apparatus may include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other components configured to perform process steps described herein. In some embodiments, a computing device may include a display, one or more network interfaces configured to communicate and / or receive data, any combination thereof, and / or other components. The one or more network interfaces may be configured to communicate and / or receive wired and / or wireless data, including data according to 3G, 4G, 5G, and / or other cellular standards, data according to the WiFi (802.11x) standard, data according to the Bluetooth standard, data according to the Internet Protocol (IP) standard, and / or other types of data.

[0163] Components of a computing device may be implemented in circuitry. For example, the components may include and / or be implemented using electronic circuitry or other electronic hardware, which may include one or more programmable electronic circuits (e.g., microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), and / or other suitable electronic circuitry), and / or may include and / or be implemented using computer software, firmware, or any combination thereof, to perform various operations described herein.

[0164] The processes described herein (e.g., process 900, process 1000, and / or other processes described herein) are illustrated as logical flow diagrams, whose operations represent sequences of actions that may be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the actions represent computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the described actions. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform particular functions or implement particular data types. The order in which the actions are described is not intended to be construed as a limitation, and any number of the described actions may be combined in any order and / or in parallel to implement the processes.

[0165] Furthermore, the processes described herein (e.g., process 900, process 1000, and / or other processes described herein) may be performed under the control of one or more computer systems comprised of executable instructions and may be implemented by hardware or a combination of hardware as code (e.g., executable instructions, one or more computer programs, or one or more applications) collectively executed on one or more processors. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program including instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.

[0166] Figure 11 illustrates an example of a system for implementing certain aspects of the present technology. Specifically, Figure 11 illustrates an example of a computing system 1100, which may be, for example, an internal computing system, a remote computing system, a camera, or any computing device comprising any of these components, the components of the system communicating with each other using a connection 1105. The connection 1105 may be a physical connection using a bus or a direct connection to a processor 1110, such as in a chipset architecture. The connection 1105 may also be a virtual, networked, or logical connection.

[0167] In some embodiments, computing system 1100 is a distributed system in which the functionality described in this disclosure may be distributed across one data center, multiple data centers, a peer network, etc. In some embodiments, one or more of the system components described represent many such components, each performing some or all of the functionality described with respect to that component. In some embodiments, the components may be physical or virtual devices.

[0168] The exemplary system 1100 includes at least one processing unit (CPU or processor) 1110 and connections 1105 that communicatively couple various system components to the processor 1110, including system memory 1115 such as read-only memory (ROM) 1120 and random access memory (RAM) 1125. The computing system 1100 may include a cache of high-speed memory 1112 that is directly connected to the processor 1110, connected in close proximity to the processor 1110, or integrated as part of the processor 1110.

[0169] Processor 1110 may include any general-purpose processor, hardware or software services such as services 1132, 1134, and 1136 stored in storage device 1130 that are configured to control processor 1110, and special-purpose processors where software instructions are embedded in the actual processor design. Processor 1110 may essentially be a completely self-contained computing system incorporating multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.

[0170] To enable user interaction, computing system 1100 includes input devices 1145, which may represent any number of input mechanisms, such as a microphone for speaking, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, speech, etc. Computing system 1100 may also include output devices 1135, which may be one or more of several output mechanisms. In some instances, a multimodal system may enable a user to provide multiple types of input / output to communicate with computing system 1100.

[0171] Computing system 1100 may include a communications interface 1140 that may generally manage and manage user input and system output. The communications interface may be an audio jack / plug, a microphone jack / plug, a Universal Serial Bus (USB) port / plug, an Apple™ Lightning™ port / plug, an Ethernet port / plug, an optical fiber port / plug, a proprietary wired port / plug, 3G, 4G, 5G, and / or other cellular data network wireless signal transmissions, Bluetooth™ wireless signal transmissions, Bluetooth™ Low Energy (BLE) wireless signal transmissions, IBEACON™ wireless signal transmissions, radio-frequency identification (RFID) wireless signal transmissions, near-field communications (NFC) wireless signal transmissions, dedicated short-range communications (DSRC) wireless signal transmissions, 802.11 Wi-Fi wireless signal transmissions, wireless local area network (WLAN) signal transmissions, visible light communication (VLC), Worldwide Interoperability for Microwave Access (WiMAX), infrared (IR) communications wireless signal transmissions, public switched telephone network (PSTN) wireless signal transmissions, and the like. The device may perform or facilitate the reception and / or transmission of wired or wireless communications using wired transceivers and / or wireless transceivers, including those utilizing Public Service Telecommunications Network (PSTN) signaling, Integrated Services Digital Network (ISDN) signaling, ad hoc network signaling, radio wave signaling, microwave signaling, infrared signaling, visible light signaling, ultraviolet light signaling, wireless signaling along the electromagnetic spectrum, or any combination thereof.Communications interface 1140 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers used to determine the location of computing system 1100 based on reception of one or more signals from one or more satellites associated with one or more GNSS systems, including, but not limited to, the U.S.-based Global Positioning System (GPS), the Russian-based Global Navigation Satellite System (GLONASS), the Chinese-based BeiDou Navigation Satellite System (BDS), and the European-based Galileo GNSS. There is no constraint to operating on any particular hardware configuration, and therefore, the basic features herein may be easily substituted for improved hardware or firmware configurations as they are developed.

[0172] The storage device 1130 may be a non-volatile memory device and / or a non-transitory memory device and / or a computer-readable memory device, such as a magnetic cassette, a flash memory card, a solid-state memory device, a digital versatile disk, a cartridge, a floppy disk, a flexible disk, a hard disk, a magnetic tape, a magnetic strip / stripe, any other magnetic storage medium, a flash memory, a memristor memory, any other solid-state memory, a compact disc read only memory (CD-ROM) optical disk, a rewritable compact disc (CD) optical disk, a digital video disk (DVD) optical disk, a Blu-ray disc (BDD) optical disk, a holographic optical disk, another optical media, a secure digital (SD) card, a micro secure digital (microSD) card, a Memory Stick® card, a smart card chip, an EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (ICC), circuit (IC) chip / card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROM, cache memory (e.g., level 1 (L1) cache, level 2 (L2) cache, level 3 (L3) cache, level 4 (L4) cache, level 5 (L5) cache, or other (L#) cache), resistive random-access memory (RRAM),The memory may be a hard disk or other type of computer-readable medium capable of storing data that is accessible by a computer, such as RRAM / ReRAM, phase change memory (PCM), spin transfer torque RAM (STT-RAM), another memory chip or cartridge, and / or any combination thereof;

[0173] Storage devices 1130 may include software services, servers, services, etc., which, when code defining such software is executed by processor 1110, cause the processor to perform functions in the system. In some embodiments, hardware services that perform a particular function may include software components stored in computer-readable media in association with necessary hardware components, such as processor 1110, connections 1105, output devices 1135, etc., to perform that function. The term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, storing, or conveying instructions and / or data. Computer-readable media may include non-transitory media that may store data, and this non-transitory media does not include carrier waves and / or ephemeral electronic signals propagating wirelessly or over wired connections. Examples of non-transitory media may include, but are not limited to, magnetic disks or tapes, optical storage media such as compact disks (CDs) or digital versatile disks (DVDs), flash memory, memories, or memory devices. Code and / or machine-executable instructions may be stored on a computer-readable medium, which may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, etc.

[0174] Although specific details have been provided in the foregoing description to provide a thorough understanding of the embodiments and examples provided herein, those skilled in the art will recognize that the present application is not limited thereto. Therefore, while exemplary embodiments of the present application have been described in detail herein, it should be understood that, except as limited by the prior art, the concepts of the present application may be variously embodied and employed in other ways, and the appended claims are intended to be construed to include such variations. The various features and aspects of the present application described above may be used individually or in combination. Moreover, the embodiments may be utilized in any number of environments and applications beyond those described herein without departing from the broader scope of the present application. Accordingly, the specification and drawings should be regarded as illustrative and not restrictive. For illustrative purposes, methods have been described in a particular order. It should be understood that in alternative embodiments, the methods may be performed in an order different from that described.

[0175] For clarity of explanation, in some instances, the technology may be presented as including individual functional blocks, including devices, device components, and method steps or routines embodied in software or a combination of hardware and software. Additional components other than those shown in the figures and / or described herein may be used. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail so as to avoid obscuring the embodiments.

[0176] Furthermore, those skilled in the art will understand that the various illustrative logic blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0177] Particular embodiments may be described above as a process or method that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. While a flowchart may describe operations as a sequential process, many of the operations may be performed in parallel or simultaneously. Moreover, the order of operations may be rearranged. A process terminates when its operations are completed, but may have additional steps not included in the figures. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination may correspond to a return of the function to the calling function or the main function.

[0178] The processes and methods according to the above-described embodiments may be implemented using computer-executable instructions stored on or otherwise available from a computer-readable medium. Such instructions may include, for example, instructions and data that cause a general-purpose computer, special-purpose computer, or processing device to perform a particular function or group of functions, or otherwise configure a general-purpose computer, special-purpose computer, or processing device to perform a particular function or group of functions. Portions of the computer resources used may be accessible over a network. The computer-executable instructions may be, for example, binary or intermediate format instructions such as assembly language, firmware, source code, etc. Examples of computer-readable media that can be used to store instructions, information used, and / or information created during methods according to the described embodiments include magnetic or optical disks, flash memory, USB devices with non-volatile memory, networked storage devices, etc.

[0179] In some embodiments, computer-readable storage devices, media, and memories may include cable or wireless signals, including bitstreams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and the signals themselves.

[0180] Those skilled in the art will appreciate that information and signals may be represented using any of a wide variety of technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips that may be referred to throughout the above description may in some cases be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof, depending in part on the particular application, desired design, corresponding technology, etc.

[0181] The various illustrative logical blocks, modules, and circuits described in connection with aspects disclosed herein may be implemented or performed using hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and may take on any of a variety of form factors. When implemented in software, firmware, middleware, or microcode, program code or code segments (e.g., a computer program product) to perform the necessary tasks may be stored in a computer-readable or machine-readable medium. A processor may perform the necessary tasks. Example form factors include laptops, smartphones, mobile phones, tablet devices or other small form factor personal computers, personal digital assistants, rack-mounted devices, standalone devices, etc. The functionality described herein may also be embodied in a peripheral device or add-in card. Such functionality may also be implemented across various chips on a circuit board or across various processes running within a single device, as further examples.

[0182] The instructions, media for communicating such instructions, computing resources for executing those instructions, and other structures for supporting such computing resources are exemplary means for providing the functionality described in this disclosure.

[0183] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as a general-purpose computer, a wireless communication device handset, or an integrated circuit device having multiple uses, including applications in wireless communication device handsets and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be embodied at least in part by a computer-readable data storage medium having program code including instructions that, when executed, perform one or more of the methods, algorithms, and / or operations described above. The computer-readable data storage medium may also form part of a computer program product, which may include packaging materials. The computer-readable medium may include memory or data storage media, such as random access memory (RAM) such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), FLASH memory, magnetic or optical data storage media, etc. These technologies may also, or alternatively, be implemented at least in part by a computer-readable communications medium, such as a propagated signal or wave, that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer.

[0184] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Accordingly, the term “processor,” as used herein, may refer to any of the above structures, any combination of the above structures, or any other structure or apparatus suitable for implementing the techniques described herein.

[0185] Those skilled in the art will understand that the less than ("<") and greater than (">") symbols or terminology used herein may be replaced with the less than or equal to ("≦") and greater than or equal to ("≧") symbols, respectively, without departing from the scope of this description.

[0186] Where a component is described as being "configured to" perform a particular operation, such configuration may be achieved, for example, by designing electronic circuitry or other hardware to perform the operation, by programming a programmable electronic circuit (e.g., a microprocessor or other suitable electronic circuitry) to perform the operation, or any combination thereof.

[0187] The phrases "coupled to" or "communicatively coupled to" refer to any component that is physically connected to another component, either directly or indirectly, and / or that is in communication with another component, either directly or indirectly (e.g., connected to the other component via a wired or wireless connection, and / or other suitable communication interface).

[0188] Claim language or other language referring to "at least one of" a set and / or "one or more" of a set indicates that one member of the set or multiple members of the set (in any combination) satisfies the claim. For example, a claim language referring to "at least one of A and B" or "at least one of A or B" means A, B, or A and B. As another example, a claim language referring to "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, or A and B and C, or any other ordering, overlap, or combination of A, B, and C, or any overlapping information or data (e.g., A and A, B and B, C and C, A and A and B, etc.), or A, B, and C. The phrases "at least one of" a set and / or "one or more" of a set do not limit the set to the items listed in the set. For example, claim language reciting "at least one of A and B" or "at least one of A or B" can mean A, B, or A and B, and may also include items not listed in the set of A and B. The phrases "at least one" and "one or more" are used interchangeably herein.

[0189] Claim language using phrases such as "at least one processor configured," "at least one processor configured," "one or more processors configured," "one or more processors configured," or other phrases indicates that one processor or multiple processors (in any combination) can perform the associated operations. For example, claim language using "at least one processor configured to do X, Y, and Z" may mean that a single processor can be used to perform operations X, Y, and Z, or that multiple processors are each responsible for a particular subset of operations X, Y, and Z such that they collectively perform X, Y, and Z, or that a group of processors cooperates to perform operations X, Y, and Z. As another example, claim language using "at least one processor configured to do X, Y, and Z" may mean that any single processor may perform only at least a subset of operations X, Y, and Z.

[0190] When one or more elements performing a function (e.g., a step of a method) are referred to, all of the functions may be performed by one element, or the functions may be performed collectively by two or more elements. When two or more elements collectively perform a function, each function need not be performed by each of the elements (e.g., different functions may be performed by different elements) and / or each function need not be performed entirely by only one element (e.g., different elements may perform different subfunctions of the function). Similarly, when one or more elements are configured to cause another element (e.g., an apparatus) to perform a function, one element may be configured to cause the other element to perform all of the functions, or two or more elements may be collectively configured to cause the other element to perform the functions.

[0191] When referring to an entity (e.g., any entity or device described herein) that performs a function or is configured to perform a function (e.g., a step of a method), the entity may be configured to cause one or more elements (individually or collectively) to perform the function. One or more elements of the entity may include at least one memory, at least one processor, at least one communication interface, another component configured to perform one or more (or all) of the functions, and / or any combination thereof. When referring to an entity that performs a function, the entity may be configured to cause one component to perform all of the functions, or to cause two or more components collectively to perform the functions. When an entity is configured to cause two or more components collectively to perform the functions, each function need not be performed by each of those components (e.g., different functions may be performed by different components) and / or each function need not be performed entirely by only one component (e.g., different components may perform different sub-functions of the function).

[0192] Exemplary embodiments of the present disclosure include the following.

[0193] Aspect 1: A method of encrypting one or more messages, the method comprising: generating, at a user equipment (UE), a message including information associated with positioning reference signaling; obtaining a group identifier indicating a group to which the UE belongs; obtaining a group key and a group key identifier associated with the group key; obtaining a UE identifier indicating the UE; deriving a traffic key based on at least one of the group key, the group identifier, or the UE identifier; deriving an encryption key and an integrity key based on the traffic key; generating a message header for the message, the message header including at least one of the group identifier or the group key identifier; calculating a message authentication code (MAC) using the integrity key, the message, and the message header; encrypting the message using the encryption key to generate an encrypted message; encrypting the MAC using the encryption key to generate an encrypted MAC; and transmitting the message header, the encrypted message, and the encrypted MAC.

[0194] Aspect 2: The method of aspect 1, wherein obtaining the group identifier includes receiving the group identifier from a group management network entity.

[0195] Aspect 3: The method of aspect 2, wherein the group management network entity includes a key management function (KMF).

[0196] Aspect 4: The method of aspect 1, wherein obtaining the group identifier includes configuring the UE with the group identifier.

[0197] Aspect 5: The method of any one of Aspects 1-4, wherein obtaining the group key and the group key identifier includes receiving the group key and the group key identifier from a group management network entity.

[0198] Aspect 6: The method of aspect 5, wherein the group management network entity includes a key management function (KMF).

[0199] Aspect 7: The method of any one of Aspects 1-6, wherein receiving a group key and a group key identifier includes receiving a number of group keys and a number of group key identifiers, and wherein the method further includes receiving a number of key expiration times from the group management network entity, each of the number of key expiration times corresponding to a respective one of the number of group keys and a respective one of the number of group key identifiers, and each of the number of key expiration times indicating a period during which a respective one of the number of group keys is valid.

[0200] Aspect 8: The method of any one of aspects 1 to 7, wherein obtaining a UE identifier includes receiving a UE identifier from a group management network entity, and generating a message header includes generating a message header including the UE identifier.

[0201] Aspect 9: The method of aspect 8, wherein receiving a UE identifier includes receiving a number of UE identifiers, the method further including receiving a usage configuration associated with each of the number of UE identifiers, each of the usage configurations including at least one of a validity time of the respective UE identifier, a number of broadcast messages including the respective UE identifier, or location information associated with the respective UE identifier, and generating a message header including the UE identifier includes generating a message header including one of the number of UE identifiers in accordance with the usage configurations.

[0202] Aspect 10: The method of aspect 8, wherein the group management network entity includes a key management function (KMF).

[0203] Aspect 11: The method of any one of aspects 1 to 7, wherein obtaining a UE identifier includes generating a UE identifier by randomly selecting an identifier as the UE identifier, and generating a message header includes generating a message header including the UE identifier.

[0204] Example 12: The method of any one of Examples 1 to 7, wherein obtaining a UE identifier includes selecting a Layer 2 identifier of the UE as the UE identifier.

[0205] Aspect 13: The method of any one of aspects 1 to 12, wherein the UE identifier includes a group member identifier that identifies a UE within a group.

[0206] Aspect 14: The method of any one of aspects 1 to 13, further including generating a traffic key identifier associated with the traffic key based on the counter value, wherein deriving the traffic key includes deriving the traffic key further based on the traffic key identifier, and wherein generating a message header includes generating a message header including the traffic key identifier.

[0207]

[0033] Aspect 15: The method of aspect 14, wherein generating the traffic key identifier includes generating the traffic key identifier such that a combination of the traffic key identifier and the group key identifier is unique.

[0208] Aspect 16: The method of any one of aspects 1 to 15, further including receiving, from the group management network entity, an algorithm identifier indicating an encryption algorithm, and deriving the encryption key includes deriving the encryption key further based on the encryption algorithm.

[0209] Aspect 17: The method of any one of aspects 1 to 16, further including receiving, from the group management network entity, an algorithm identifier indicating an integrity algorithm, and wherein deriving the integrity key includes deriving the integrity key further based on the integrity algorithm.

[0210] Aspect 18: The method of any one of aspects 1 to 17, wherein calculating the MAC includes calculating the MAC further based on the counter value, and generating the message header includes generating a message header further including at least a portion of the counter value.

[0211] Aspect 19: The method of any one of aspects 1 to 18, further including generating a traffic key identifier indicative of a traffic key, wherein calculating a MAC includes calculating the MAC further based on the counter value and the traffic key identifier, and wherein encrypting the message and encrypting the MAC includes encrypting the message and encrypting the MAC further based on the counter value and the traffic key identifier.

[0212] Aspect 20: The method of any one of aspects 1 to 19, wherein the information associated with the positioning reference signaling includes at least one of participant information indicating one or more intended recipients of the positioning reference signal (PRS), session information associated with communication between the UE and one or more intended recipients, PRS measurements indicating signal strength of received PRS, location information associated with a location of the UE, or movement information associated with movement of the UE.

[0213] Aspect 21: A method of processing one or more packets, the method comprising: receiving, at a first user equipment (UE), from a second UE, a packet including an encrypted message including information associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header, wherein the message header includes a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key; obtaining a group identifier indicating that the first UE also belongs to the group to which the second UE belongs; obtaining the group key and the group key identifier; deriving a traffic key based on the group key; deriving an encryption key and an integrity key based on the traffic key; decrypting the encrypted message using the encryption key to generate a decrypted message; decrypting the encrypted MAC using the encryption key to generate a decrypted MAC; calculating a predicted MAC based on the integrity key; and verifying integrity of the decrypted message by comparing the decrypted MAC with the predicted MAC.

[0214]

[0071] Aspect 22: The method of aspect 21, wherein obtaining the group identifier includes receiving the group identifier from a group management network entity.

[0215] Aspect 23: The method of aspect 22, wherein the group management network entity includes a key management function (KMF).

[0216] Example 24: The method of example 21, wherein obtaining the group identifier includes configuring the first UE with the group identifier.

[0217] Aspect 25: The method of any one of aspects 21 to 24, wherein obtaining the group key and the group key identifier includes receiving the group key and the group key identifier associated with the group key from a group management network entity.

[0218] Aspect 26: The method of aspect 25, wherein the group management network entity includes a key management function (KMF).

[0219] Aspect 27: The method of any one of aspects 21 to 26, wherein the message header further includes a UE identifier indicating the second UE, a traffic key identifier indicating the traffic key, and a counter, and deriving the traffic key includes deriving the traffic key further based on the group identifier, the UE identifier, and the traffic key identifier.

[0220]

[0071] Aspect 28: The method of aspect 27, wherein the UE identifier includes a group member identifier that identifies a second UE in the group.

[0221] Aspect 29: The method of any one of aspects 21 to 28, further including receiving an encryption algorithm identifier from the group management network entity indicating an encryption algorithm, and deriving the encryption key includes deriving the encryption key further based on the encryption algorithm.

[0222] Aspect 30: The method of aspect 29, wherein the group management network entity includes a key management function (KMF).

[0223] Aspect 31: The method of any one of aspects 21 to 30, wherein the message header further includes an encryption algorithm identifier indicating an encryption algorithm, and deriving the encryption key includes deriving the encryption key further based on the encryption algorithm.

[0224] Aspect 32: The method of any one of aspects 21 to 31, further comprising receiving, from the group management network entity, an integrity algorithm identifier indicating an integrity algorithm, and wherein deriving the integrity key comprises deriving the integrity key further based on the integrity algorithm.

[0225] Aspect 33: The method of aspect 32, wherein the group management network entity includes a key management function (KMF).

[0226] Aspect 34: The method of any one of aspects 21 to 33, wherein the message header further includes an integrity algorithm identifier indicating an integrity algorithm, and deriving the integrity key includes deriving the integrity key further based on the integrity algorithm.

[0227] Aspect 35: The method of any one of aspects 21 to 34, wherein the message header further includes a traffic key identifier indicating a traffic key and a counter, wherein decrypting the encrypted message further includes decrypting the encrypted message using the traffic key identifier and the counter, and wherein decrypting the encrypted MAC further includes decrypting the encrypted MAC using the traffic key identifier and the counter.

[0228]

[0071] Aspect 36: The method of any one of aspects 21 to 35, wherein calculating the predicted MAC includes calculating the predicted MAC further based on a traffic key identifier indicating the traffic key and the counter value.

[0229] Aspect 37: The method of any one of aspects 21 to 36, wherein the information associated with the positioning reference signaling includes at least one of participant information indicating one or more intended recipients of the positioning reference signal (PRS), session information associated with communication between the UE and one or more intended recipients, PRS measurements indicating signal strength of received PRS, location information associated with the location of the UE, or movement information associated with movement of the UE.

[0230] Embodiment 38. An apparatus including at least one memory and at least one processor coupled to the at least one memory, wherein the at least one processor is configured to perform operations according to any of embodiments 1-20.

[0231] Aspect 39. A non-transitory computer-readable storage medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform an operation according to any of Aspects 1-20.

[0232] Embodiment 40. An apparatus comprising one or more means for performing the operations according to any of embodiments 1-20.

[0233] Embodiment 41. An apparatus including at least one memory and at least one processor coupled to the at least one memory, wherein the at least one processor is configured to perform operations according to any of embodiments 21-37.

[0234] Aspect 42. A non-transitory computer-readable storage medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to perform an operation according to any of Aspects 21-37.

[0235] Embodiment 43. An apparatus comprising one or more means for performing the operations according to any of embodiments 21-37.

[0236] Aspect 44. An apparatus for encrypting one or more messages, comprising: at least one memory; and at least one processor coupled to the at least one memory, the at least one processor configured to: generate, at a user equipment (UE), a message including information associated with positioning reference signaling; obtain a group identifier indicating a group to which the UE belongs; obtain a group key and a group key identifier associated with the group key; obtain a UE identifier indicating the UE; derive a traffic key based on at least one of the group key, the group identifier, or the UE identifier; derive an encryption key and an integrity key based on the traffic key; generate a message header for the message, the message header including at least one of the group identifier or the group key identifier; calculate a message authentication code (MAC) using the integrity key, the message, and the message header; encrypt the message using the encryption key to generate an encrypted message; encrypt the MAC using the encryption key to generate the encrypted MAC; and cause a transmitter to transmit the message header, the encrypted message, and the encrypted MAC.

[0237]

[0071] Aspect 45. The apparatus of aspect 44, wherein to obtain the group identifier, the at least one processor is configured to receive the group identifier from a group management network entity.

[0238]

[0071] Aspect 46. The apparatus of aspect 44, wherein the at least one processor is configured to configure the UE with the group identifier to obtain the group identifier.

[0239]

[0071] Aspect 47. The apparatus of aspect 44, wherein the at least one processor is configured to receive the group key and the group key identifier from the group management network entity to obtain the group key and the group key identifier.

[0240] Aspect 48. The apparatus of aspect 47, wherein to receive the group keys and group key identifiers, at least one processor is configured to receive a number of group keys and a number of group key identifiers, and the at least one processor is further configured to receive a number of key validity times from the group management network entity, each of the number of key validity times corresponding to a respective one of the number of group keys and a respective one of the number of group key identifiers, and each of the number of key validity times indicating a period of time during which a corresponding one of the number of group keys is valid.

[0241] Aspect 49. The apparatus of aspect 44, wherein, to obtain the UE identifier, the at least one processor is configured to receive the UE identifier from a group management network entity, and, to generate the message header, the at least one processor is configured to generate a message header including the UE identifier.

[0242] Aspect 50. The apparatus of aspect 49, wherein, to receive the UE identifier, at least one processor is configured to receive a number of UE identifiers; the at least one processor is further configured to receive a respective usage configuration associated with each of the number of UE identifiers; the respective usage configurations each respectively including at least one of a validity time of the respective UE identifier, a number of broadcast messages including the respective UE identifier, or location information associated with the respective UE identifier; and, to generate a message header including the UE identifier, the at least one processor is configured to generate a message header including one of the number of UE identifiers in accordance with the usage configurations.

[0243] Aspect 51. The apparatus of aspect 44, wherein, to obtain a UE identifier, the at least one processor is configured to generate the UE identifier by randomly selecting an identifier as the UE identifier, and, to generate a message header, the at least one processor is configured to generate a message header including the UE identifier.

[0244]

[0071] Aspect 52. The apparatus of aspect 44, wherein to obtain the UE identifier, the at least one processor is configured to select a Layer 2 identifier of the UE as the UE identifier.

[0245] Embodiment 53. The apparatus of any of embodiments 44-52, wherein the UE identifier includes a group member identifier that identifies a UE within a group.

[0246] Aspect 54. The apparatus of any of aspects 44-52, wherein the at least one processor is further configured to generate, based on the counter value, a traffic key identifier associated with the traffic key; to derive the traffic key, the at least one processor is configured to derive the traffic key further based on the traffic key identifier; and to generate the message header, the at least one processor is configured to generate a message header including the traffic key identifier.

[0247]

[0033] Aspect 55. The apparatus of aspect 54, wherein to generate the traffic key identifier, the at least one processor is configured to generate the traffic key identifier such that a combination of the traffic key identifier and the group key identifier is unique.

[0248] Aspect 56. The apparatus of any of aspects 44-52, wherein the at least one processor is further configured to receive, from the group management network entity, an algorithm identifier indicating an encryption algorithm, and to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.

[0249] Embodiment 57. The apparatus of any of embodiments 44-52, wherein the at least one processor is further configured to receive, from the group management network entity, an algorithm identifier indicating an integrity algorithm, and to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.

[0250] Embodiment 58. The apparatus of any of embodiments 44-52, wherein, to calculate the MAC, the at least one processor is configured to calculate the MAC further based on the counter value, and, to generate the message header, the at least one processor is configured to generate a message header further including at least a portion of the counter value.

[0251] Embodiment 59. The apparatus of any of embodiments 44-52, wherein the at least one processor is further configured to generate a traffic key identifier indicative of a traffic key; to calculate a MAC, the at least one processor is configured to calculate the MAC further based on the counter value and the traffic key identifier; and to encrypt the message and to encrypt the MAC, the at least one processor is configured to encrypt the message and encrypt the MAC further based on the counter value and the traffic key identifier.

[0252]

[0033] Embodiment 60. The apparatus of any of embodiments 44-52, wherein the information associated with the positioning reference signaling includes at least one of: participant information indicating one or more intended recipients of the positioning reference signal (PRS); session information associated with communication between the UE and the one or more intended recipients; PRS measurements indicating signal strength of received PRSs; location information associated with a location of the UE; or movement information associated with a movement of the UE.

[0253] Aspect 61. An apparatus for processing one or more packets, comprising: at least one memory; and at least one processor coupled to the at least one memory, wherein the at least one processor is configured to: receive, at a first user equipment (UE), from a second UE, a packet including an encrypted message including information associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header including a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key; obtain the group identifier indicating that the first UE also belongs to the group to which the second UE belongs; obtain the group key and the group key identifier; derive a traffic key based on the group key; derive an encryption key and an integrity key based on the traffic key; decrypt the encrypted message using the encryption key to generate a decrypted message; decrypt the encrypted MAC using the encryption key to generate a decrypted MAC; calculate a predicted MAC based on the integrity key; and verify integrity of the decrypted message by comparing the decrypted MAC with the predicted MAC.

[0254] Aspect 62. The apparatus of aspect 61, wherein to obtain the group identifier, the at least one processor is configured to receive the group identifier from a group management network entity.

[0255]

[0063] Aspect 63. The apparatus of aspect 61, wherein the at least one processor is configured to configure the first UE with the group identifier to obtain the group identifier.

[0256] Aspect 64. The apparatus of aspect 61, wherein to obtain the group key and the group key identifier, the at least one processor is configured to receive, from a group management network entity, the group key and the group key identifier associated with the group key.

[0257] Aspect 65. The apparatus of any of aspects 61-64, wherein the message header further includes a UE identifier indicating the second UE, a traffic key identifier indicating the traffic key, and a counter, and wherein to derive the traffic key, the at least one processor is configured to derive the traffic key further based on the group identifier, the UE identifier, and the traffic key identifier.

[0258] Embodiment 66 The apparatus of embodiment 65, wherein the UE identifier includes a group member identifier that identifies a second UE in the group.

[0259] Aspect 67. The apparatus of any of aspects 61-66, wherein the at least one processor is further configured to receive, from the group management network entity, an encryption algorithm identifier indicating an encryption algorithm, and to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.

[0260] Aspect 68. The apparatus of any of aspects 61-67, wherein the message header further includes an encryption algorithm identifier indicating an encryption algorithm, and wherein to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.

[0261] Embodiment 69. The apparatus of any of embodiments 61-68, wherein the at least one processor is further configured to receive, from the group management network entity, an integrity algorithm identifier indicating an integrity algorithm, and to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.

[0262] Embodiment 70. The apparatus of any of embodiments 61-69, wherein the message header further includes an integrity algorithm identifier indicating an integrity algorithm, and wherein to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.

[0263] Aspect 71. The apparatus of any of aspects 61-70, wherein the message header further includes a traffic key identifier indicating a traffic key and a counter, and wherein, to decrypt the encrypted message, the at least one processor is configured to further use the traffic key identifier and the counter to decrypt the encrypted message, and, to further decrypt the encrypted MAC, the at least one processor is configured to further use the traffic key identifier and the counter to decrypt the encrypted MAC.

[0264]

[0041] Aspect 72. The apparatus of any of aspects 61-71, wherein to calculate the predicted MAC, the at least one processor is configured to calculate the predicted MAC further based on a traffic key identifier indicating the traffic key and a counter value.

[0265]

[0033] Aspect 73. The apparatus of any of aspects 61-72, wherein the information associated with the positioning reference signaling includes at least one of: participant information indicating one or more intended recipients of the positioning reference signal (PRS); session information associated with communication between the UE and the one or more intended recipients; PRS measurements indicating signal strength of received PRSs; location information associated with a location of the UE; or movement information associated with a movement of the UE.

Claims

1. 1. An apparatus for encrypting one or more messages, comprising: at least one memory; at least one processor coupled to the at least one memory, the at least one processor: generating, at a user equipment (UE), a message including information associated with positioning reference signaling; Obtain a group identifier indicating a group to which the UE belongs; Obtaining a group key and a group key identifier associated with the group key; Obtaining a UE identifier indicating the UE; deriving a traffic key based on at least one of the group key, the group identifier, or the UE identifier; deriving encryption and integrity keys based on the traffic keys; generating a message header for the message, the message header including at least one of the group identifier or the group key identifier; Compute a message authentication code (MAC) using the integrity key, the message, and the message header; encrypting the message using the encryption key to generate an encrypted message; encrypting the MAC using the encryption key to generate an encrypted MAC; An apparatus configured to cause a transmitter to transmit the message header, the encrypted message, and the encrypted MAC.

2. The apparatus of claim 1 , wherein to obtain the group identifier, the at least one processor is configured to receive the group identifier from a group management network entity.

3. The apparatus of claim 1 , wherein the at least one processor is configured to configure the UE with the group identifier to obtain the group identifier.

4. The apparatus of claim 1 , wherein to obtain the group key and the group key identifier, the at least one processor is configured to receive the group key and the group key identifier from a group management network entity.

5. to receive the group key and the group key identifier, the at least one processor is configured to receive a number of group keys and a number of group key identifiers; the at least one processor is further configured to receive, from the group management network entity, a number of key expiration times, each of the number of key expiration times corresponding to a respective one of the number of group keys and a respective one of the number of group key identifiers; each of the number of key validity times indicating a period during which a respective one of the number of group keys is valid; 5. The apparatus of claim 4.

6. To obtain the UE identifier, the at least one processor is configured to receive the UE identifier from a group management network entity; and generating the message header, the at least one processor configured to generate the message header including the UE identifier.

10. The apparatus of claim 1.

7. To receive the UE identifier, the at least one processor is configured to receive a number of UE identifiers; the at least one processor is further configured to receive a respective usage configuration associated with each of the number of UE identifiers; each respective usage configuration includes at least one of a validity time of a respective UE identifier, a number of broadcast messages including the respective UE identifier, or location information associated with the respective UE identifier; to generate the message header including the UE identifier, the at least one processor is configured to generate the message header including one of the number of UE identifiers according to the usage configuration.

7. The apparatus of claim 6.

8. To obtain the UE identifier, the at least one processor is configured to generate the UE identifier by randomly selecting an identifier as the UE identifier; and generating the message header, the at least one processor configured to generate the message header including the UE identifier.

10. The apparatus of claim 1.

9. The apparatus of claim 1 , wherein to obtain the UE identifier, the at least one processor is configured to select a Layer 2 identifier of the UE as the UE identifier.

10. The apparatus of claim 1 , wherein the UE identifier comprises a group member identifier that identifies the UE within the group.

11. the at least one processor is further configured to generate a traffic key identifier associated with the traffic key based on the counter value; to derive the traffic key, the at least one processor is configured to derive the traffic key further based on the traffic key identifier; and generating the message header, the at least one processor configured to generate the message header including the traffic key identifier.

10. The apparatus of claim 1.

12. 12. The apparatus of claim 11, wherein to generate the traffic key identifier, the at least one processor is configured to generate the traffic key identifier such that a combination of the traffic key identifier and the group key identifier is unique.

13. the at least one processor is further configured to receive, from a group management network entity, an algorithm identifier indicating an encryption algorithm; to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.

10. The apparatus of claim 1.

14. the at least one processor is further configured to receive, from a group management network entity, an algorithm identifier indicating an integrity algorithm; to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.

10. The apparatus of claim 1.

15. to calculate the MAC, the at least one processor is configured to calculate the MAC further based on a counter value; to generate the message header, the at least one processor being configured to generate the message header further including at least a portion of the counter value.

10. The apparatus of claim 1.

16. the at least one processor is further configured to generate a traffic key identifier indicative of the traffic key; to calculate the MAC, the at least one processor is configured to calculate the MAC further based on a counter value and the traffic key identifier; and to encrypt the message and the MAC, the at least one processor is configured to encrypt the message and the MAC further based on the counter value and a traffic key identifier.

10. The apparatus of claim 1.

17. 2. The apparatus of claim 1, wherein the information associated with the positioning reference signaling includes at least one of: participant information indicating one or more intended recipients of a positioning reference signal (PRS); session information associated with communication between the UE and the one or more intended recipients; PRS measurements indicating signal strength of received PRS; location information associated with a location of the UE; or movement information associated with movement of the UE.

18. 1. An apparatus for processing one or more packets, comprising: at least one memory; at least one processor coupled to the at least one memory, the at least one processor: receiving, at a first user equipment (UE), from a second UE, a packet including an encrypted message including information associated with positioning reference signaling, an encrypted message authentication code (MAC), and a message header including a group identifier indicating a group to which the second UE belongs and a group key identifier indicating a group key; obtaining a group identifier indicating that the first UE also belongs to the group to which the second UE belongs; obtaining the group key and the group key identifier; deriving a traffic key based on the group key; deriving encryption and integrity keys based on the traffic keys; decrypting the encrypted message using the encryption key to generate a decrypted message; decrypting the encrypted MAC using the encryption key to generate a decrypted MAC; Calculating a predicted MAC based on the integrity key; An apparatus configured to verify the integrity of the decoded message by comparing the decoded MAC with the expected MAC.

19. 20. The apparatus of claim 18, wherein to obtain the group identifier, the at least one processor is configured to receive the group identifier from a group management network entity.

20. 20. The apparatus of claim 18, wherein the at least one processor is configured to configure the first UE with the group identifier to obtain the group identifier.

21. 20. The apparatus of claim 18, wherein to obtain the group key and the group key identifier, the at least one processor is configured to receive the group key and the group key identifier associated with the group key from a group management network entity.

22. the message header further includes a UE identifier indicating the second UE, a traffic key identifier indicating the traffic key, and a counter; to derive the traffic key, the at least one processor is configured to derive the traffic key further based on the group identifier, the UE identifier, and the traffic key identifier.

20. The apparatus of claim 18.

23. 23. The apparatus of claim 22, wherein the UE identifier comprises a group member identifier that identifies the second UE within the group.

24. the at least one processor is further configured to receive, from a group management network entity, an encryption algorithm identifier indicating an encryption algorithm; to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.

20. The apparatus of claim 18.

25. the message header further includes an encryption algorithm identifier indicating an encryption algorithm; to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.

20. The apparatus of claim 18.

26. the at least one processor is further configured to receive, from a group management network entity, an integrity algorithm identifier indicating an integrity algorithm; to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.

20. The apparatus of claim 18.

27. the message header further includes an integrity algorithm identifier indicating an integrity algorithm; to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.

20. The apparatus of claim 18.

28. the message header further includes a traffic key identifier indicating the traffic key and a counter; to decrypt the encrypted message, the at least one processor is configured to further use the traffic key identifier and the counter to decrypt the encrypted message; to further decrypt the encrypted MAC, the at least one processor being configured to further use the traffic key identifier and the counter to decrypt the encrypted MAC.

20. The apparatus of claim 18.

29. 20. The apparatus of claim 18, wherein to calculate the predicted MAC, the at least one processor is configured to calculate the predicted MAC further based on a traffic key identifier indicative of the traffic key and a counter value.

30. 20. The apparatus of claim 18, wherein the information associated with the positioning reference signaling includes at least one of: participant information indicating one or more intended recipients of a positioning reference signal (PRS); session information associated with communication between the UE and the one or more intended recipients; PRS measurements indicating signal strength of received PRS; location information associated with a location of the UE; or movement information associated with movement of the UE.