METHOD AND APPARATUS FOR INTER-WTRU RELAY DISCOVERY SECURITY AND PRIVACY - Patent application

The implementation of security keys and RSC-associated security material in UE-to-UE relays addresses the lack of security in ProSe by ensuring only authorized UEs can access sensitive information, enhancing communication security and privacy.

JP7821552B2Active Publication Date: 2026-02-27INTERDIGITAL PATENT HOLDINGS INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024555169
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-03-09
Filing Date
2024-03-06
Publication Date
2026-02-27
Estimated Expiration
2044-03-06

AI Technical Summary

Technical Problem

Existing proximity-based services (ProSe) lack effective security measures to protect UE discovery messages and maintain privacy during UE-to-UE relay procedures, particularly in scenarios requiring restricted discovery.

Method used

Implementing security keys and provisioning of security material associated with Relay Service Codes (RSCs) to ensure only authorized end UEs can exchange and process relay messages, protecting UE discovery messages and privacy-sensitive information.

Benefits of technology

Enhances security and privacy in UE-to-UE relay discovery by ensuring only authorized UEs can access IP address/prefix information, thereby safeguarding communication integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007821552000002
    Figure 0007821552000002
  • Figure 0007821552000003
    Figure 0007821552000003
  • Figure 0007821552000004
    Figure 0007821552000004
Patent Text Reader

Abstract

A method for UE-to-UE (U2U) relay discovery security is disclosed. The method may include provisioning an end UE with security material for a direct discovery set and a U2U discovery message, and provisioning a U2U relay with security material for the U2U discovery message. The security material for the direct discovery set may include at least one of a ProSe restriction code, associated key material, or an indicator associated with a relay service code (RSC) that indicates whether the RSC supports per-ProSe direct discovery set protection. The method may include sending a direct connection request (DCR) message by the end UE to the U2U relay. The DCR message may include the RSC and at least one of an end UE user information identification (ID) or the ProSe restriction code. The method may include sending, by the end UE, an indication for direct discovery set protection.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims the benefit of U.S. Provisional Patent Application No. 63 / 489,273, filed March 9, 2023, the contents of which are incorporated herein by reference. [Background technology]

[0002] Proximity-based services (ProSe) may be provided to UEs that are in close proximity to each other. A UE may support a ProSe direct discovery procedure that may be used to discover other UEs in close proximity. A UE may also support direct communication with another UE, e.g., transmitting data directly to another UE without traversing an infrastructure network.

[0003] Discovery procedures may also be considered open or restricted. In the case of open discovery, no explicit permission is required from the UE being discovered. In the case of restricted discovery, explicit permission may need to be given to the discovering UE to allow the discovering UE to discover the discovered UE. This permission may be associated, for example, with a ProSe restriction code. The ProSe restriction code may be provisioned or configured in a UE that is authorized to use, serve, or discover other UEs using the same ProSe restriction code. Summary of the Invention

[0004] Proximity-based services (ProSe) services may be provided to UEs in close proximity to each other. UEs may support a ProSe direct discovery procedure that can be used to discover other UEs in close proximity. UEs may also support direct communication with another UE. UE-to-UE relays may be capable of relaying traffic to and from end UEs. UE-to-UE relays broadcast discovery messages with their associated Relay Service Codes (RSCs) to facilitate the relay discovery process for end UEs. The discovery messages may include Direct Discovery Sets (DDSs). The DDSs may include information related to one or more end UEs in the vicinity of the UE-to-UE relay. This may include a User Information Identifier (User Information ID) and a ProSe Restriction Code. Each RSC may have one or more ProSe Restriction Codes associated with it. End UE IP address / prefix information is associated with a unique pair of ProSe Restriction Code and User Information ID.

[0005] Potential security requirements for UE-to-UE relaying may include protection of UE discovery messages and privacy-sensitive information during the UE-to-UE relay discovery procedure. Security keys may be used to protect messages during transmission. Both relay and end UEs may be provisioned with security material associated with the RSC to properly exchange and process security for relay messages. Only authorized end UEs may be provisioned with security material associated with a given ProSe restriction code. If the second end UE is authorized for restricted discovery using the same ProSe restriction code associated with the first end UE, the UE-to-UE relay can only share the first end UE's IP address / prefix information with the second end UE.

[0006] The end UE sends the protected DDS to the UE-to-UE relay, and the UE-to-UE relay includes the protected DDS in a discovery message. In one example, the end UE can run a timer to trigger sending an updated protected DDS to the UE-to-UE relay when the timer expires. In another example, the UE-to-UE relay can provide information about the next announcement opportunity, and the end UE can send the updated protected DDS to the UE-to-UE relay during the next announcement opportunity. [Brief explanation of the drawings]

[0007] A more detailed understanding may be had from the following description, given by way of example in conjunction with the accompanying drawings, in which like reference numerals indicate similar elements and in which: [Figure 1A] 1 is a system diagram illustrating an example communication system in which one or more disclosed embodiments may be implemented. [Figure 1B] 1B is a system diagram illustrating an exemplary wireless transmit / receive unit (WTRU) that may be used within the communication system illustrated in FIG. 1A, according to one embodiment. [Figure 1C] 1B is a system diagram illustrating an example radio access network (RAN) and an example core network (CN) that may be used within the communication system illustrated in FIG. 1A, according to one embodiment. [Figure 1D] 1B is a system diagram illustrating a further exemplary RAN and a further exemplary CN that may be used within the communication system illustrated in FIG. 1A, according to one embodiment. [Figure 2] 10 illustrates an example of end-UE connectivity using UE-to-UE relay connectivity over a PC5 interface. [Figure 3] 1 shows the UE-to-UE relay discovery procedure in Model A. [Figure 4] 10 shows an example of a relayed message where a single keyset associated with the RSC is used to protect the message. [Figure 5] 10 shows an example of a relayed message where multiple keysets associated with an RSC are used to protect the message. [Figure 6] 10 illustrates an example call flow for a U2U relay direct link establishment procedure with support for U2U relay discovery for Model A using multiple keysets and IP sharing privacy. [Figure 7] 10 illustrates an example call flow for a U2U relay direct link modification procedure to enable support for Model A U2U relay discovery using multiple keysets and IP shared privacy. [Figure 8] 1 illustrates an example call flow for a U2U relayed DNS query with IP sharing privacy. [Figure 9] 1 illustrates an example call flow for a U2U relay initiation Model A U2U relay discovery procedure using multiple keysets. [Figure 10] 1 illustrates an example call flow for an end-UE initiated Model A U2U relay discovery procedure using multiple keysets. [Figure 11] 1 illustrates an example call flow for a U2U relay initiation Model A U2U relay discovery procedure with delayed announcement of discovered end UEs. DETAILED DESCRIPTION OF THE INVENTION

[0008] 1A is a diagram illustrating an example communication system 100 in which one or more disclosed embodiments may be implemented. The communication system 100 may be a multiple-access system that provides content, such as voice, data, video, messaging, broadcasts, etc., to multiple wireless users. The communication system 100 may enable the multiple wireless users to access such content through sharing of system resources, including wireless bandwidth. For example, the communication system 100 may use one or more channel access methods, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), single-carrier FDMA (SC-FDMA), zero-tailed unique word discrete Fourier transform spread OFDM (ZT-UW-DFT-S-OFDM), unique word OFDM (UW-OFDM), resource block filtered OFDM, filter bank multicarrier (FBMC), etc.

[0009] 1A, communications system 100 may include wireless transmit / receive units (WTRUs) 102a, 102b, 102c, 102d, a radio access network (RAN) 104, a core network (CN) 106, a public switched telephone network (PSTN) 108, the Internet 110, and other networks 112, although it will be understood that the disclosed embodiments contemplate any number of WTRUs, base stations, networks, and / or network elements. Each of WTRUs 102a, 102b, 102c, 102d may be any type of device configured to operate and / or communicate in a wireless environment. By way of example, the WTRUs 102a, 102b, 102c, 102d, any of which may be referred to as a station (STA), may be configured to transmit and / or receive wireless signals and may include user equipment (UE), mobile stations, fixed or mobile subscriber units, subscription-based units, pagers, mobile phones, personal digital assistants (PDAs), smartphones, laptops, netbooks, personal computers, wireless sensors, hotspots or Mi-Fi devices, Internet of Things (IoT) devices, watches or other wearables, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain contexts), home electronic devices, devices operating in commercial and / or industrial wireless networks, etc. Any of the WTRUs 102a, 102b, 102c, and 102d may be interchangeably referred to as a UE.

[0010] The communications system 100 may also include a base station 114a and / or a base station 114b. Each of the base stations 114a, 114b may be any type of device configured to wirelessly interface with at least one of the WTRUs 102a, 102b, 102c, 102d to facilitate access to one or more communications networks, such as the CN 106, the Internet 110, and / or other networks 112. By way of example, the base stations 114a, 114b may be a base transceiver station (BTS), a Node B, an eNodeB (eNB), a Home Node B, a Home eNodeB, a next generation Node B (e.g., gNodeB (gNB)), a new radio (NR) Node B, a site controller, an access point (AP), a wireless router, etc. Although the base stations 114a, 114b are each illustrated as a single element, it will be understood that the base stations 114a, 114b may include any number of interconnected base stations and / or network elements.

[0011] The base station 114a may be part of the RAN 104, which may also include other base stations and / or network elements (not shown), such as a base station controller (BSC), a radio network controller (RNC), relay nodes, etc. The base station 114a and / or base station 114b may be configured to transmit and / or receive wireless signals on one or more carrier frequencies, which may be referred to as a cell (not shown). These frequencies may be licensed spectrum, unlicensed spectrum, or a combination of licensed and unlicensed spectrum. A cell may provide wireless service coverage for a particular geographic area, which may be relatively fixed or may change over time. A cell may be further divided into cell sectors. For example, the cell associated with the base station 114a may be divided into three sectors. Thus, in one embodiment, the base station 114a may include three transceivers, i.e., one transceiver for each sector of the cell. In one embodiment, the base station 114a may employ multiple-input multiple-output (MIMO) technology and utilize multiple transceivers for each sector of the cell. For example, beamforming may be used to transmit and / or receive signals in desired spatial directions.

[0012] The base stations 114a, 114b may communicate with one or more of the WTRUs 102a, 102b, 102c, 102d over an air interface 116, which may be any suitable wireless communication link (e.g., radio frequency (RF), microwave, centimeter wave, micrometer wave, infrared (IR), ultraviolet (UV), visible light, etc.). The air interface 116 may be established using any suitable radio access technology (RAT).

[0013] More specifically, as noted above, the communications system 100 may be a multiple-access system, but may use one or more channel access schemes, such as CDMA, TDMA, FDMA, OFDMA, SC-FDMA, etc. For example, the base station 114a and the WTRUs 102a, 102b, 102c of the RAN 104 may implement a radio technology such as Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (UTRA), which may establish the air interface 116 using Wideband CDMA (WCDMA). WCDMA may include communications protocols such as High Speed ​​Packet Access (HSPA) and / or Evolved HSPA (HSPA+). HSPA may include High Speed ​​Downlink (DL) Packet Access (HSDPA) and / or High Speed ​​Uplink (UL) Packet Access (HHSUPA).

[0014] In one embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as Evolved UMTS Terrestrial Radio Access (E-UTRA), which may establish the air interface 116 using Long Term Evolution (LTE) and / or LTE-Advanced (LTE-A) and / or LTE-Advanced Pro (LTE-A Pro).

[0015] In one embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement a radio technology such as NR radio access, which may establish the air interface 116 using NR.

[0016] In one embodiment, the base station 114a and the WTRUs 102a, 102b, 102c may implement multiple radio access technologies. For example, the base station 114a and the WTRUs 102a, 102b, 102c may jointly implement LTE radio access and NR radio access, e.g., using a dual connectivity (DC) principle. Thus, the air interface utilized by the WTRUs 102a, 102b, 102c may be characterized by multiple types of radio access technologies and / or transmissions sent to and from multiple types of base stations (e.g., eNBs and gNBs).

[0017] In other embodiments, the base station 114a and the WTRUs 102a, 102b, 102c may implement a wireless technology such as IEEE 802.11 (i.e., Wireless Fidelity (WiFi)), IEEE 802.16 (i.e., WiMAX (WiMAX)), CDMA2000, CDMA2000 1X, CDMA2000 EV-DO, Interim Standard 2000 (IIS-2000), Interim Standard 95 (IS-95), Interim Standard 856 (IS-856), Global System for Mobile Communications (GSM), Enhanced Data Rates for GSM Evolution (EDGE), GSM EDGE (GERAN), or the like.

[0018] 1A may be, for example, a wireless router, a Home NodeB, a Home eNodeB, or an access point and may utilize any suitable RAT to facilitate wireless connectivity in a local area such as a business, a home, a vehicle, a campus, an industrial facility, an air corridor (e.g., for use by drones), a road, etc. In one embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.11 to establish a wireless local area network (WLAN). In one embodiment, the base station 114b and the WTRUs 102c, 102d may implement a radio technology such as IEEE 802.15 to establish a wireless personal area network (WPAN). In yet another embodiment, the base station 114b and the WTRUs 102c, 102d may utilize a cellular-based RAT (e.g., WCDMA, CDMA2000, GSM, LTE, LTE-A, LTE-A Pro, NR, etc.) to establish a picocell or femtocell. 1A, the base station 114b may have a direct connection to the Internet 110. Therefore, the base station 114b may not need to access the Internet 110 through the CN 106.

[0019] The RAN 104 may communicate with the CN 106, which may be any type of network configured to provide voice, data, application, and / or Voice over Internet Protocol (VoIP) services to one or more of the WTRUs 102a, 102b, 102c, 102d. The data may have various quality of service (QoS) requirements, such as different throughput, latency, error tolerance, reliability, data throughput, mobility, etc. The CN 106 may provide call control, billing services, mobile location-based services, prepaid calling, Internet connectivity, video distribution, etc., and / or perform high-level security functions such as user authentication. Although not shown in FIG. 1A , it will be understood that the RAN 104 and / or CN 106 may communicate directly or indirectly with other RANs that use the same RAT as the RAN 104 or a different RAT. For example, in addition to being connected to the RAN 104, which may utilize NR radio technology, the CN 106 may also communicate with another RAN (not shown) employing GSM, UMTS, CDMA2000, WiMAX, E-UTRA, or WiFi radio technology.

[0020] The CN 106 may also serve as a gateway for the WTRUs 102a, 102b, 102c, 102d to access the PSTN 108, the Internet 110, and / or other networks 112. The PSTN 108 may include a circuit-switched telephone network providing plain old telephone service (POTS). The Internet 110 may include a global system of interconnected computer networks and devices, which use common communication protocols such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and / or Internet Protocol (IP) of the TCP / IP Internet protocol suite. The networks 112 may include wired and / or wireless communication networks owned and / or operated by other service providers. For example, the network 112 may include another CN connected to one or more RANs, which may use the same RAT as the RAN 104 or a different RAT.

[0021] Some or all of the WTRUs 102a, 102b, 102c, 102d in the communications system 100 may include multi-mode capabilities (e.g., the WTRUs 102a, 102b, 102c, 102d may include multiple transceivers for communicating with different wireless networks over different wireless links.) For example, the WTRU 102c shown in FIG. 1A may be configured to communicate with a base station 114a, which may employ a cellular-based wireless technology, and a base station 114b, which may employ an IEEE 802.2 wireless technology.

[0022] 1B is a system diagram illustrating an example WTRU 102. As shown in FIG. 1B, the WTRU 102 may include, among other things, a processor 118, a transceiver 120, a transmit / receive element 122, a speaker / microphone 124, a keypad 126, a display / touchpad 128, non-removable memory 130, removable memory 132, a power source 134, a global positioning system (GPS) chipset 136, and / or other peripherals 138. It will be understood that the WTRU 102 may include any sub-combination of the foregoing elements while remaining consistent with an embodiment.

[0023] The processor 118 may be a general-purpose processor, a special-purpose processor, a conventional processor, a digital signal processor (DSP), multiple microprocessors, one or more microprocessors associated with a DSP core, a controller, a microcontroller, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), any other type of integrated circuit (IC), a state machine, etc. The processor 118 may perform signal coding, data processing, power control, input / output processing, and / or any other functionality that enables the WTRU 102 to operate in a wireless environment. The processor 118 may be coupled to the transceiver 120, which may be coupled to the transmit / receive element 122. While FIG. 1B illustrates the processor 118 and the transceiver 120 as separate components, it will be understood that the processor 118 and the transceiver 120 may be integrated together in an electronic package or chip.

[0024] The transmit / receive element 122 may be configured to transmit or receive signals to or from a base station (e.g., base station 114a) over the air interface 116. For example, in one embodiment, the transmit / receive element 122 may be an antenna configured to transmit and / or receive RF signals. In one embodiment, the transmit / receive element 122 may be an emitter / detector configured to transmit and / or receive IR signals, UV signals, or visible light signals, for example. In yet another embodiment, the transmit / receive element 122 may be configured to transmit and / or receive both RF signals and light signals. It will be understood that the transmit / receive element 122 may be configured to transmit and / or receive any combination of wireless signals.

[0025] 1B as a single element, the WTRU 102 may include any number of transmit / receive elements 122. More specifically, the WTRU 102 may employ MIMO technology. Thus, in one embodiment, the WTRU 102 may include two or more transmit / receive elements 122 (e.g., multiple antennas) for transmitting and receiving wireless signals over the air interface 116.

[0026] The transceiver 120 may be configured to modulate signals transmitted by the transmit / receive element 122 and demodulate signals received by the transmit / receive element 122. As noted above, the WTRU 102 may have multi-mode capabilities. Thus, the transceiver 120 may include multiple transceivers to enable the WTRU 102 to communicate via multiple RATs, such as, for example, NR and IEEE 802.11.

[0027] The processor 118 of the WTRU 102 may be coupled to and may receive user-entered data from a speaker / microphone 124, a keypad 126, and / or a display / touchpad 128 (e.g., a liquid crystal display (LCD) display unit or an organic light-emitting diode (OLED) display unit). The processor 118 may also output user data to the speaker / microphone 124, the keypad 126, and / or the display / touchpad 128. Additionally, the processor 118 may access information from and store data in any type of suitable memory, such as non-removable memory 130 and / or removable memory 132. The non-removable memory 130 may include random access memory (RAM), read-only memory (ROM), a hard disk, or any other type of memory storage device. The removable memory 132 may include a subscriber identity module (SIM) card, a memory stick, a secure digital (SD) memory card, etc. In other embodiments, the processor 118 may access information from and store data in memory that is not physically located on the WTRU 102, such as on a server or home computer (not shown).

[0028] The processor 118 may receive power from the power source 134 and may be configured to distribute and / or control the power to other components in the WTRU 102. The power source 134 may be any suitable device for providing power to the WTRU 102. For example, the power source 134 may include one or more dry batteries (e.g., nickel cadmium (NiCd), nickel zinc (NiZn), nickel metal hydride (NiMH), lithium ion (Li-ion), etc.), solar cells, fuel cells, etc.

[0029] The processor 118 may also be coupled to a GPS chipset 136, which may be configured to provide location information (e.g., longitude and latitude) regarding the current location of the WTRU 102. In addition to, or instead of, information from the GPS chipset 136, the WTRU 102 may receive location information from base stations (e.g., base stations 114a, 114b) over the air interface 116 and / or determine its location based on the timing of signals received from two or more nearby base stations. It will be appreciated that the WTRU 102 may obtain location information by way of any suitable location determination method while remaining consistent with an embodiment.

[0030] The processor 118 may further be coupled to other peripherals 138, which may include one or more software and / or hardware modules that provide additional features, functionality, and / or wired or wireless connectivity. For example, the peripherals 138 may include an accelerometer, an electronic compass, a satellite transceiver, a digital camera (for photos and / or videos), a universal serial bus (USB) port, a vibration device, a television transceiver, a hands-free headset, a Bluetooth module, a frequency modulation (FM) radio unit, a digital music player, a media player, a video game player module, an internet browser, a virtual reality and / or augmented reality (VR / AR) device, an activity tracker, etc. The peripherals 138 may include one or more sensors. The sensors may be one or more of a gyroscope, an accelerometer, a Hall effect sensor, a magnetometer, an orientation sensor, a proximity sensor, a temperature sensor, a time sensor, a geolocation sensor, an altimeter, a light sensor, a touch sensor, a magnetometer, a barometer, a gesture sensor, a biometric sensor, a humidity sensor, etc.

[0031] The WTRU 102 may include a full-duplex radio where transmission and reception of some or all of the signals (e.g., associated with a particular subframe on both the UL (e.g., for transmission) and DL (e.g., for reception)) may be simultaneous and / or together. The full-duplex radio may include an interference management unit to reduce and or substantially eliminate self-interference through either hardware (e.g., a choke) or signal processing via a processor (e.g., via a separate processor (not shown) or processor 118). In one embodiment, the WTRU 102 may include a half-duplex radio where transmission and reception of some or all of the signals (e.g., associated with a particular subframe on either the UL (e.g., for transmission) or DL ​​(e.g., for reception)) may be simultaneous and / or together.

[0032] 1C is a system diagram illustrating the RAN 104 and the CN 106, according to one embodiment. As noted above, the RAN 104 may employ E-UTRA radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 may also communicate with the CN 106.

[0033] The RAN 104 may include eNodeBs 160a, 160b, and 160c, although it will be understood that the RAN 104 may include any number of eNodeBs while remaining consistent with an embodiment. The eNodeBs 160a, 160b, and 160c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, and 102c over the air interface 116. In an embodiment, the eNodeBs 160a, 160b, and 160c may implement MIMO technology. Thus, the eNodeB 160a may, for example, use multiple antennas to transmit wireless signals to and / or receive wireless signals from the WTRU 102a.

[0034] Each of the eNodeBs 160a, 160b, 160c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, etc. As shown in FIG. 1C, the eNodeBs 160a, 160b, 160c may communicate with one another via an X2 interface.

[0035] 1C may include a mobility management entity (MME) 162, a serving gateway (SGW) 164, and a packet data network (PDN) gateway (PGW) 166. Although the foregoing elements are illustrated as part of the CN 106, it will be understood that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0036] The MME 162 may be connected to each of the eNodeBs 162a, 162b, 162c in the RAN 104 via an S1 interface and may function as a control node. For example, the MME 162 may be responsible for authenticating users of the WTRUs 102a, 102b, 102c, activating / deactivating bearers, selecting a particular serving gateway during initial attach of the WTRUs 102a, 102b, 102c, etc. The MME 162 may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies such as GSM and / or WCDMA.

[0037] The SGW 164 may be connected to each of the eNodeBs 160a, 160b, 160c in the RAN 104 via an S1 interface. The SGW 164 may generally route and forward user data packets to and from the WTRUs 102a, 102b, 102c. The SGW 164 may perform other functions, such as anchoring the user plane during inter-eNodeB handover, triggering paging when DL data is available to the WTRUs 102a, 102b, 102c, and managing and storing the context of the WTRUs 102a, 102b, 102c.

[0038] The SGW 164 may be connected to a PGW 166, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks, such as the Internet 110, to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices.

[0039] The CN 106 may facilitate communications with other networks. For example, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to circuit-switched networks, such as the PSTN 108, to facilitate communications between the WTRUs 102a, 102b, 102c and traditional landline communications devices. For example, the CN 106 may include or communicate with an IP gateway (e.g., an IP Multimedia Subsystem (IMS) server) that serves as an interface between the CN 106 and the PSTN 108. In addition, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to other networks 112, which may include other wired and / or wireless networks owned and / or operated by other service providers.

[0040] Although the WTRU is depicted in FIGS. 1A-1D as a wireless terminal, it is contemplated that in certain representative embodiments, such a terminal may use a wired communication interface (e.g., temporarily or permanently) with the communication network.

[0041] In a representative embodiment, the other network 112 may be a WLAN.

[0042] A WLAN in infrastructure basic service set (BSS) mode may have an access point (AP) of the BSS and one or more stations (STAs) associated with the AP. The AP may have access to or interface with a distribution system (DS) or another type of wired / wireless network that carries traffic within and / or outside the BSS. Traffic originating from outside the BSS to a STA may arrive through the AP and be delivered to the STA. Traffic originating from a STA to a destination outside the BSS may be sent to the AP to be delivered to the respective destination. Traffic between STAs within the BSS may be transmitted, for example, through the AP, where the source STA may send traffic to the AP, and the AP may deliver the traffic to the destination STA. Traffic between STAs within the BSS may be considered and / or referred to as peer-to-peer traffic. Peer-to-peer traffic may be transmitted between (e.g., directly between) a source STA and a destination STA using direct link setup (DLS). In certain representative embodiments, the DLS may use 802.11e DLS or 802.11z tunneled DLS (TDLS). A WLAN using an Independent BSS (IBSS) mode may not have an AP, and STAs within or using the IBSS (e.g., all of the STAs) may communicate directly with each other. The IBSS mode of communication may be referred to herein as an "ad hoc" communication mode.

[0043] When using the 802.11ac infrastructure mode of operation or a similar mode of operation, an AP may transmit beacons on a fixed channel, such as a primary channel. The primary channel may be a fixed width (e.g., a 20 MHz wide bandwidth) or a dynamically configured width. The primary channel may be the operating channel of the BSS, but may be used by STAs to establish a connection with the AP. In certain representative embodiments, carrier sense multiple access with collision avoidance (CSMA / CA) may be implemented, for example, in an 802.11 system. With CSMA / CA, STAs (e.g., all STAs), including the AP, may sense the primary channel. If the primary channel is sensed / detected and / or determined to be busy by a particular STA, the particular STA may back off. One STA (e.g., only one station) may transmit in a given BSS at any given time.

[0044] High-throughput (HT) STAs may use 40 MHz-wide channels for communication, which may be formed, for example, through a combination of a primary 20 MHz channel and adjacent or non-adjacent 20 MHz channels.

[0045] A very high throughput (VHT) STA may support channels of 20 MHz, 40 MHz, 80 MHz, and / or 160 MHz width. A 40 MHz and / or 80 MHz channel may be formed by combining multiple contiguous 20 MHz channels. A 160 MHz channel may be formed by combining eight contiguous 20 MHz channels or by combining two non-contiguous 80 MHz channels, which may be referred to as an 80+80 configuration. For the 80+80 configuration, after channel encoding, the data may pass through a segment parser that may separate the data into two streams. Inverse fast Fourier transform (IFFT) processing and time-domain processing may be performed separately on each stream. The streams may be mapped to two 80 MHz channels, and the data may be transmitted by the transmitting STA. At the receiver of the receiving STA, the operations described above for the 80+80 configuration may be reversed, and the combined data may be transmitted to the medium access control (MAC).

[0046] Sub-1 GHz operating modes are supported by 802.11af and 802.11ah. Channel operating bandwidths and carriers are reduced in 802.11af and 802.11ah compared to those used in 802.11n and 802.11ac. 802.11af supports 5 MHz, 10 MHz, and 20 MHz bandwidths in the TV White Space (TVWS) spectrum, while 802.11ah supports 1 MHz, 2 MHz, 4 MHz, 8 MHz, and 16 MHz bandwidths using non-TVWS spectrum. According to representative embodiments, 802.11ah may support meter-type control / machine-type communication (MTC), such as MTC devices, in macro coverage areas. MTC devices may have limited capabilities, including, for example, support for (e.g., only support for) certain specific and / or limited bandwidths. MTC devices may include batteries with above-threshold battery life (e.g., to maintain very long battery life).

[0047] WLAN systems that can support multiple channels and channel bandwidths, such as 802.11n, 802.11ac, 802.11af, and 802.11ah, include a channel that can be designated as a primary channel. The primary channel can have a bandwidth equal to the maximum common operating bandwidth supported by all STAs in the BSS. The bandwidth of the primary channel can be configured and / or limited by the STAs among all STAs operating in the BSS that support the minimum bandwidth operating mode. In an 802.11ah embodiment, the primary channel can be 1 MHz wide for STAs (e.g., MTC-type devices) that support (e.g., only support) the 1 MHz mode, even if the AP and other STAs in the BSS support 2 MHz, 4 MHz, 8 MHz, 16 MHz, and / or other channel bandwidth operating modes. Carrier sensing and / or network allocation vector (NAV) configuration can depend on the status of the primary channel. For example, if a STA (that only supports 1 MHz mode of operation) transmitting to an AP has a busy primary channel, all of the available frequency bands may be considered busy even if most of the available frequency bands are idle.

[0048] In the United States, the available frequency band that can be used by 802.11ah is 902MHz to 928MHz. In South Korea, the available frequency band is 917.5MHz to 923.5MHz. In Japan, the available frequency band is 916.5MHz to 927.5MHz. The total bandwidth available for 802.11ah is 6MHz to 26MHz depending on the country code.

[0049] 1D is a system diagram illustrating the RAN 104 and the CN 106, according to one embodiment. As mentioned above, the RAN 104 may employ NR radio technology to communicate with the WTRUs 102a, 102b, 102c over the air interface 116. The RAN 104 may also communicate with the CN 106.

[0050] The RAN 104 may include gNBs 180a, 180b, and 180c, although it will be understood that the RAN 104 may include any number of gNBs while remaining consistent with an embodiment. The gNBs 180a, 180b, and 180c may each include one or more transceivers for communicating with the WTRUs 102a, 102b, and 102c over the air interface 116. In an embodiment, the gNBs 180a, 180b, and 180c may implement MIMO technology. For example, the gNB 180a, 180b may transmit signals to and / or receive signals from the gNBs 180a, 180b, and 180c using beamforming. Thus, the gNB 180a may transmit and / or receive wireless signals to and / or from the WTRU 102a using, for example, multiple antennas. In one embodiment, the gNBs 180a, 180b, 180c may implement carrier aggregation technology. For example, the gNB 180a may transmit multiple component carriers to the WTRU 102a (not shown). A subset of these component carriers may be on unlicensed spectrum, while the remaining component carriers may be on licensed spectrum. In one embodiment, the gNBs 180a, 180b, 180c may implement coordinated multipoint (CoMP) technology. For example, the WTRU 102a may receive coordinated transmissions from the gNBs 180a and 180b (and / or 180c).

[0051] The WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c using transmissions associated with scalable numerology. For example, the OFDM symbol spacing and / or OFDM subcarrier spacing may vary for different transmissions, different cells, and / or different portions of the wireless transmission spectrum. The WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c using subframes or transmission time intervals (TTIs) of varying or scalable lengths (e.g., including varying numbers of OFDM symbols and / or varying lengths of absolute time).

[0052] The gNBs 180a, 180b, 180c may be configured to communicate with the WTRUs 102a, 102b, 102c in a standalone configuration and / or a non-standalone configuration. In a standalone configuration, the WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c without accessing another RAN (e.g., eNodeBs 160a, 160b, 160c, etc.). In a standalone configuration, the WTRUs 102a, 102b, 102c may utilize one or more of the gNBs 180a, 180b, 180c as mobility anchor points. In a standalone configuration, the WTRUs 102a, 102b, 102c may communicate with the gNBs 180a, 180b, 180c using signals in unlicensed bands. In a non-standalone configuration, the WTRUs 102a, 102b, 102c may communicate with and connect to gNBs 180a, 180b, 180c while also communicating with and connecting to another RAN, such as eNodeBs 160a, 160b, 160c. For example, the WTRUs 102a, 102b, 102c may implement DC principles to communicate with one or more gNBs 180a, 180b, 180c and one or more eNodeBs 160a, 160b, 160c substantially simultaneously. In a non-standalone configuration, the eNodeBs 160a, 160b, 160c may act as mobility anchors for the WTRUs 102a, 102b, 102c, and the gNBs 180a, 180b, 180c may provide additional coverage and / or throughput for serving the WTRUs 102a, 102b, 102c.

[0053] Each of the gNBs 180a, 180b, 180c may be associated with a particular cell (not shown) and may be configured to handle radio resource management decisions, handover decisions, scheduling of users in the UL and / or DL, support for network slicing, DC, interworking between NR and E-UTRA, routing of user plane data to user plane functions (UPFs) 184a, 184b, routing of control plane information to access and mobility management functions (AMFs) 182a, 182b, etc. As shown in FIG. 1D , the gNBs 180a, 180b, 180c may communicate with each other via an Xn interface.

[0054] 1D may include at least one AMF 182a, 182b, at least one UPF 184a, 184b, at least one Session Management Function (SMF) 183a, 183b, and possibly a Data Network (DN) 185a, 185b. While the foregoing elements are illustrated as part of the CN 106, it will be understood that any of these elements may be owned and / or operated by an entity other than the CN operator.

[0055] The AMF 182a, 182b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 104 via an N2 interface and may function as a control node. For example, the AMF 182a, 182b may be responsible for user authentication of the WTRUs 102a, 102b, 102c, support for network slicing (e.g., handling different protocol data unit (PDU) sessions with different requirements), selection of a particular SMF 183a, 183b, management of registration areas, termination of non-access stratum (NAS) signaling, mobility management, etc. The network slicing may be used by the AMF 182a, 182b to customize the CN support of the WTRUs 102a, 102b, 102c based on the type of service utilizing the WTRUs 102a, 102b, 102c. For example, different network slices may be established for different use cases, such as services relying on Ultra-Reliable Low Latency (URLLC) access, services relying on Enhanced Mobile Broadband (eMBB) access, services for MTC access, etc. The AMFs 182a, 182b may provide a control plane function for switching between the RAN 104 and other RANs (not shown) that employ other radio technologies, such as LTE, LTE-A, LTE-A Pro, and / or non-3GPP access technologies, such as WiFi.

[0056] The SMFs 183a, 183b may be connected to the AMFs 182a, 182b in the CN 106 via an N11 interface. The SMFs 183a, 183b may also be connected to the UPFs 184a, 184b in the CN 106 via an N4 interface. The SMFs 183a, 183b may select and control the UPFs 184a, 184b and configure the routing of traffic through the UPFs 184a, 184b. The SMFs 183a, 183b may perform other functions, such as managing and assigning UE IP addresses, managing PDU sessions, controlling policy enforcement and QoS, providing DL data notification, etc. The PDU session type may be IP-based, non-IP-based, Ethernet-based, etc.

[0057] The UPFs 184a, 184b may be connected to one or more of the gNBs 180a, 180b, 180c in the RAN 104 via an N3 interface, which may provide the WTRUs 102a, 102b, 102c with access to packet-switched networks such as the Internet 110 to facilitate communications between the WTRUs 102a, 102b, 102c and IP-enabled devices. The UPFs 184, 184b may perform other functions such as routing and forwarding packets, enforcing user plane policy, supporting multi-homed PDU sessions, handling user plane QoS, buffering DL packets, providing mobility anchoring, etc.

[0058] The CN 106 may facilitate communication with other networks. For example, the CN 106 may include or communicate with an IP gateway (e.g., an IP Multimedia Subsystem (IMS) server) that acts as an interface between the CN 106 and the PSTN 108. Additionally, the CN 106 may provide the WTRUs 102a, 102b, 102c with access to other networks 112, which may include other wired and / or wireless networks owned and / or operated by other service providers. In one embodiment, the WTRUs 102a, 102b, 102c may be connected to the local DNs 185a, 185b through the UPFs 184a, 184b via an N3 interface to the UPFs 184a, 184b and an N6 interface between the UPFs 184a, 184b and the DNs 185a, 185b.

[0059] 1A-1D and the corresponding descriptions thereof, one or more or all of the functions described herein with respect to one or more of the WTRUs 102a-d, base stations 114a-b, eNode-Bs 160a-c, MME 162, SGW 164, PGW 166, gNBs 180a-c, AMFs 182a-b, UPFs 184a-b, SMFs 183a-b, DNs 185a-b, and / or other devices described herein may be performed by one or more emulation devices (not shown). The emulation devices may be one or more devices configured to emulate one or more or all of the functions described herein. For example, the emulation devices may be used to test other devices and / or simulate network and / or WTRU functions.

[0060] The emulation devices may be designed to implement one or more tests of other devices in a lab environment and / or an operator network environment. For example, one or more emulation devices may perform one or more or all functions while fully or partially implemented and / or deployed as part of a wired and / or wireless communication network to test other devices in the communication network. One or more emulation devices may perform one or more or all functions while temporarily implemented / deployed as part of a wired and / or wireless communication network. The emulation devices may be directly coupled to another device for the purpose of testing and / or performing tests using over-the-air wireless communication.

[0061] One or more emulation devices may perform one or more functions, inclusive, while not being implemented / deployed as part of a wired and / or wireless communication network. For example, the emulation devices may be utilized in test scenarios in a test lab and / or in an undeployed (e.g., test) wired and / or wireless communication network to implement testing of one or more components. One or more emulation devices may be test equipment. Direct RF coupling and / or wireless communication via RF circuitry (which may include, e.g., one or more antennas) may be used by the emulation devices to transmit and / or receive data.

[0062] The following abbreviations and acronyms may be referenced:

[0063] [Table 1]

[0064] Proximity-based services (ProSe) services may be provided to UEs that are in close proximity to each other. A UE may support a ProSe direct discovery procedure, which it may use to discover other UEs in its vicinity. A UE may also support direct communication with another UE, e.g., transmitting data directly to another UE without traversing an infrastructure network.

[0065] For ProSe direct discovery, two models can be considered depending on the role the UE performs. In Model A, UEs can be classified as announcing UEs or monitoring UEs based on their role. An announcing UE can announce / broadcast information that can be used by monitoring UEs to discover the announcing UE. In Model B, UEs can be classified as discovering UEs or discovered UEs based on their role. A discovering UE can send a request containing information about what it is interested in discovering, and a discovered UE that receives the request can respond with some information related to the discovering UE's request. A discovered UE can be called an announcing UE. A discovering UE can be called a monitoring UE.

[0066] Discovery procedures may also be considered open or restricted. In the case of open discovery, no explicit permission is required from the UE being discovered. In the case of restricted discovery, explicit permission may need to be given to the discovering UE to allow the discovering UE to discover the discovered UE. This permission may be associated, for example, with a ProSe restriction code. The ProSe restriction code may be provisioned or configured in a UE that is authorized to use, provide, or discover other UEs using the same ProSe restriction code. The ProSe restriction code may be associated, for example, with a ProSe service or with a ProSe application identification (e.g., ProSe app ID). The ProSe restriction code may be transmitted over the air by the announcing UE to signal its permission for discovery purposes, facilitating the discovery process.

[0067] A UE-to-UE (U2U) relay is a UE that can relay traffic to and from an end UE. Figure 2 shows an example of end UE connectivity using UE-to-UE relay connectivity over a PC5 interface.

[0068] Figure 3 shows the U2U relay discovery procedure using Model A. In (1), the U2U relay discovers other UEs in the vicinity. In (2), the U2U relay broadcasts a discovery announcement message. A relay service code (RSC) can be used to identify the connection service provided by the U2U relay. The RSC can be pre-configured or provisioned in the U2U relay and authorized end UEs. The RSC may have associated security policies or information necessary, for example, for authentication and authorization between the end UE and the U2U relay. The U2U relay can broadcast a discovery / announcement message, where the U2U relay advertises its relay service capabilities by including the associated RSC in the message.

[0069] An end UE may be interested in discovering another end UE that is authorized to use or provide a particular ProSe service, but the end UEs may not be in close proximity to each other. When an end UE is in close proximity to a U2U relay, the U2U relay may be able to facilitate the discovery process. The U2U relay may, for example, advertise information associated with the nearby end UE. A U2U relay discovery message may include, for example, information associated with the nearby end UE and the services the end UE is authorized to use / provide, such as the ProSe restriction code advertised by the end UE. At the same time, the U2U relay may also include its own information, such as an RSC, to support U2U relay discovery. Information to support U2U relay discovery may include, for example, a U2U relay information ID and a relay service code (RSC). The information associated with the end UE is called a Direct Discovery Set (DDS).

[0070] The DDS may contain information associated with end UEs that are near the U2U relay and with which the U2U relay can communicate. The DDS may contain a user information identification (user information ID) and a ProSe restriction code associated with the end UE. The user information ID may be assigned to an end UE for each service. It may be unique for each end UE that uses the service and may be used to distinguish end UEs that use the same service.

[0071] Potential security requirements for U2U relay may include protection of discovery messages and privacy of end UE confidential information during the UE-to-UE relay discovery procedure. Security keys may be used to protect messages during transmission. Both the UE-to-UE relay and the end UE may be provisioned with security material associated with an RSC to properly exchange and process relay messages. However, only authorized end UEs may be provisioned with security material associated with a given Prose restriction code.

[0072] The terms security material, security key, and security keyset are used interchangeably herein to refer to one or more parameters used to protect or secure a message or portion of a message. The terms protected message and protected message are used interchangeably herein to refer to a message protected / secured with particular security material. The security materials for different messages may be different, and therefore are represented herein by an association of the security material with some or all of the information they are protecting, e.g., using RSC-associated security material.

[0073] FIG. 4 shows an example of a relay message in which a single key set associated with the RSC is used to protect the message. A message integrity code (MIC) 401 may be calculated for message integrity protection using an integrity key. The portion of the message containing the UE-to-UE relay information ID 402 and the end-UE information element 403 may be encrypted using a secret key. (Here, the term UE-to-UE relay information ID refers to the UE-to-UE relay user information ID.) A UTC-based counter may be used in both the integrity and confidentiality calculations to ensure freshness protection and protect against replay attacks. The UTC-based counter used internally by the UE may be encoded, for example, as the 32 most significant bits of UTC time. The parameter sent in the message by the announcing UE may carry the four least significant bits (LSBs) of the UTC-based counter 404. This may be used by the monitoring UE when setting the value of the UTC-based counter to ensure that both UEs use the same value.

[0074] In one example, a single keyset may be used to protect relayed messages. When a single keyset is associated with an RSC, a UE authorized to use the RSC may be able to decrypt, tamper with, or replay any DDS transmitted with that RSC. For example, a first UE authorized to use a first ProSe service may be able to eavesdrop on the contents of a relayed message containing information about a second UE using a different ProSe service. Mitigation of this security issue may be possible by enforcing security isolation between ProSe services (i.e., avoiding multiple ProSe services from sharing a common RSC key). However, this may require the configuration of a dedicated RSC for a given ProSe service, which may be defined as part of the service deployment.

[0075] In another example, multiple keysets may be used to protect relay messages. For example, each ProSe service has an associated ProSe restriction code and security material. In this case, each individual Direct Discovery Set (DDS) may be protected using its own individual security material, e.g., ProSe restriction code-related security material. RSC-related security material may be used to encrypt U2U relay discovery messages.

[0076] 5 shows an example of a relay message where multiple keysets associated with an RSC are used to protect the message. In this example, each DDS (e.g., set #1 501 and set #2 502) can be protected using its specific keyset associated with its respective ProSe restriction code.

[0077] The single keyset approach may allow for simpler deployment options and less impact on existing discovery / provisioning procedures. Therefore, it may be appropriate when a dedicated RSC is used or when additional protection per ProSe service is not required (e.g., when used with public safety-related ProSe services). The multiple keyset approach may provide additional flexibility in terms of RSC / ProSe service deployment, configuration options, and means to mitigate the potential security / privacy risks mentioned above. This approach may be appropriate when an RSC is used by multiple commercial ProSe services. Coexistence of these approaches may be desirable to support different deployment scenarios and varying security requirements.

[0078] When employing a multiple keyset approach, even if a U2U relay may be relaying traffic associated with a given ProSe restriction code, if, for example, the U2U relay is not authorized to use the ProSe service associated with that ProSe restriction code, the keyset associated with that ProSe restriction code may not be provisioned at the U2U relay.

[0079] A U2U relay that supports protected DDS can support a multiple keyset approach. Support for protected DDS by a U2U relay may be configured in information associated with the RSC, i.e., on a per-RSC basis. This allows for the coexistence of an RSC that supports a single keyset and an RSC that supports multiple keysets (e.g., supports protected DDS). The U2U relay can use the configuration information associated with the RSC to determine whether protected DDS is supported for the RSC, and then use information from the end UE to determine whether the advertised end UE's particular DDS requires supported protection.

[0080] An end UE can send the protected DDS to the U2U relay in a discovery message. A U2U relay that supports protected DDS can extract the protected DDS from a message received from an end UE and include it in a discovery announcement message sent by the U2U relay. Since multiple end UEs can send discovery messages with protected DDS to the U2E relay, the relay can extract each received protected DDS and transparently append / append all extracted protected DDS to the discovery announcement message sent by the U2U relay.

[0081] End UEs already connected to a relay may not retransmit discovery messages with protected DDSs to the relay because they may not be needed after the relay is discovered, and sending the message multiple times may increase overhead and affect the UE's battery life. U2U relays can store received protected DDSs for transmission in later discovery announcement messages. However, due to UTC time-based replay protection, the protected DDSs may become invalid after a period of time and may subsequently be invalidated when received by the monitoring end UE. Relays may not have access to newly generated protected DDSs and may not be able to properly announce the presence of end UEs when needed.

[0082] In one example, when a U2U relay connected to an end UE determines to advertise a previously discovered or currently connected end UE, the U2U relay can request a protected DDS from these end UEs. The U2U relay can determine that the ProSe service used by the end UE is subject to DDS protection based on the ProSe restriction code stored in the PC5 link context. If a protected DDS received from a previously discovered or currently connected UE is stored, the U2U relay can verify its validity. If the protected DDS is invalid (e.g., based on UTC time), the U2U relay can send a request to obtain an updated protected DDS from the previously discovered or currently connected UE.

[0083] The protected DDS request message may be a newly defined PC5 signaling (PC5-S) message, or an existing PC5-S message may be extended to include DDS-related information. The U2U relay can send a PC5-S request message including a ProSe restriction code to request a protected DDS from the end UE. The U2U relay can receive a PC5-S response message including a protected DDS corresponding to the ProSe restriction code from the end UE. The U2U relay can then send a U2U relay discovery announcement message including the received protected DDS.

[0084] In one example, the end UE can transmit a protected DDS based on a configured U2U relay discovery time value. The end UE can run a timer, and when the timer expires, the end UE can transmit a message including an updated protected DDS to the U2U relay.

[0085] In one example, when the U2U relay receives information including the protected DDS from the end UE, the U2U relay can send a message including a time value for the next announcement opportunity to the end UE, and the end UE can then send the updated protected DDS to the U2U relay during the next announcement opportunity.

[0086] In one example, the U2U relay may include discovery scheduling assistance information in a discovery announcement message. The discovery scheduling assistance information may include information about announcement opportunities. This may be, for example, a time offset (from the current time) until the next announcement. This may include, for example, configuration for periodic announcement opportunities, including start time, end time, and periodicity of such opportunities.

[0087] Each RSC can have multiple ProSe services (e.g., ProSe restriction codes) associated with it. The user information ID assigned to an end UE is unique only for each ProSe service; that is, the same user information ID can be assigned to different end UEs using different services. Different services may be associated with the same RSC. As a result, one or more IP addresses can be associated with the same user information ID. The relay stores the user information ID and IP address / prefix information in a table so that it can respond to DNS queries. Therefore, when it receives a DNS query message containing the user information ID, it finds the user information ID in the table and returns a DNS response message containing the corresponding IP address / prefix information. In this case, there can be one or more entries in the table associated with the same user information ID. To be able to identify user information IDs received from and associated with different end UEs when receiving DNS query messages, the U2U relay can use the ProSe restriction code associated with the service in addition to the user information ID. In other words, each unique pair of ProSe restriction code and user information ID can have its own IP address / prefix information.

[0088] An end UE connected to a U2U relay may probe the relay (e.g., using a DNS query) for other end UEs' IP address / prefix information based on the end UE user information ID it may possess. This may provide a malicious end UE with a means to circumvent the authorization for limited discovery and the ability to track whether a particular end UE is connected to a U2U relay. To mitigate this risk, it is desirable to ensure that IP address / prefix information is shared only with authorized end UEs. In other words, it is desirable to ensure that a U2U relay shares end UE A's IP address / prefix information with end UE B only if end UE B is authorized for limited discovery with end UE A using the same ProSe restriction code from the unique pair of ProSe restriction code and user information ID associated with the target IP address / prefix information.

[0089] In one example, during a link establishment procedure, the U2U relay may receive a Direct Connection Request (DCR) message from the first-end UE, the DCR message including the RSC and a first ProSe restriction code. The U2U relay may store the ProSe restriction code in a context (PC5 link, DNS entry) associated with the first-end UE. The U2U relay may send a Direct Connection Accept (DCA) message to the first-end UE, acknowledging that "IP sharing protection" is enabled for the first-end UE. By enabling "IP sharing protection," the U2U relay ensures that it only shares the first-end UE's IP address / prefix information with the second-end UE if the second-end UE is allowed restricted discovery by the first ProSe restriction code.

[0090] During the DNS resolution procedure, the U2U relay may receive a DNS query message from the second end UE, the DNS query message including the second end UE user information ID and the second ProSe restriction code. The U2U relay may verify whether the second ProSe restriction code matches the first ProSe restriction code. The U2U relay may send a DNS response message to the second end UE, the DNS response message including the IP address / prefix information of the first end UE, only if the second ProSe restriction code is the same as the first ProSe restriction code.

[0091] FIG. 6 illustrates an example call flow for a U2U relay direct link establishment procedure with support for U2U relay discovery for Model A using multiple keysets and IP sharing privacy.

[0092] The end UE may be provisioned with RSC-related security material and DDS-related security material by the DDNMF, PCF, or PKMF (601, 602). The DDS security material may include ProSe restriction codes and associated key material. The U2U relay may be provisioned with RSC-related security material by the PCF or PKMF (603). The U2U relay and end UE may be configured with an indicator associated with the RSC that indicates whether the RSC supports protected DDS. The indicator may also indicate whether use of protected DDS is mandatory for the RSC, for example, whether the RSC can operate without protected DDS.

[0093] The end UE may send a Direct Connection Request (DCR) message including the RSC, the end UE User Information ID, and the ProSe Restriction Code to the U2U Relay (604). The end UE may provide an indication for DDS protection. The end UE may provide a validity time value for the ProSe Restriction Code (e.g., based on a corresponding validity time value configured by the PCF / DDNMF at the end UE). The ProSe Restriction Code may be used by the U2U Relay to determine whether a particular end UE is subject to IP sharing privacy protection and / or to enable end UE User Information ID disambiguation (when multiple entries exist).

[0094] Parameters in the DCR message, such as the RSC, end UE User Information ID, and ProSe Restriction Code, may be protected (e.g., for confidentiality, integrity, and against replay) using RSC-related security material. An indication for support of protected DDS may be provided instead of the ProSe Restriction Code. The indication may be provided to avoid exposing a specific ProSe Restriction Code and / or unauthorized linkage of the ProSe Restriction Code with the end UE User Information ID (e.g., if the Identifier parameter is not confidentiality protected in the DCR message). The indication may be used by the U2U Relay to determine that the end UE may have at least one protected Direct Discovery Set to be announced by the U2U Relay.

[0095] Upon receiving a DCR message containing a ProSe restriction code / instruction for DDS protection, the U2U relay can verify (605) whether the RSC supports protected DDS based on the indicators described above.

[0096] The U2U relay and end UE may establish security for the PC5 link (606). The U2U relay may store the ProSe restriction code / instruction for DDS protection along with the end UE user information ID in the PC5 link context (607). The U2U relay may send a Direct Connection Accept (DCA) message to the end UE including a time value for the next opportunity for announcement by the U2U relay of the protected DDS from the end UE (608).

[0097] FIG. 7 illustrates an example call flow for a U2U relay direct link modification procedure to enable support for Model A U2U relay discovery using multiple keysets and IP shared privacy.

[0098] An end UE may have an established link with a U2U relay (701). The end UE may send a Link Modification Request (LMR) message including a ProSe restriction code to the U2U relay (702) (e.g., to add another ProSe service reusing the existing link, or to securely provide a ProSe restriction code if the ProSe restriction code was not sent in the DCR, e.g., if an indication was provided during link establishment instead of the ProSe restriction code). The end UE may provide an indication about DDS protection and validity time values, as described above for the DCR case. The provided ProSe restriction code may be used by the U2U relay to determine whether a particular end UE is subject to IP sharing privacy protection and / or to enable end UE user information ID disambiguation (when multiple entries exist).

[0099] The LMR can be initiated by the end UE to activate DDS protection for the end UE and / or a specific ProSe service that is subject to DDS protection (e.g., an existing ProSe service on the PC5 link is not subject to DDS protection, and the end UE wishes to activate it). The LMR may also be initiated by the end UE to revoke a ProSe restriction code following a discovery update procedure, in which the DDNMF revokes a previously assigned ProSe restriction code. In this case, an instruction for the cancellation of the ProSe restriction code may be included. If a new code is assigned by the DDNMF and the end UE replaces the old code, the LMR may include the old and new ProSe restriction code values, and a new validity time parameter.

[0100] Upon receiving a DCR message containing a ProSe restriction code / instruction for DDS protection, the U2U relay can verify (703) that the RSC supports protected DDS based on the associated indicator.

[0101] The U2U relay can store the ProSe restriction code / instruction for DDS protection along with the existing end UE information in the PC5 link context (704). Alternatively, the U2U relay can remove or replace the ProSe restriction code if it should be revoked or replaced (as shown above). The U2U relay can decide to release the direct link if all of the end UE ProSe restriction codes have been removed and no other ProSe services remain in use.

[0102] The U2U relay may send a Link Modification Accept (LMA) message to the end UE containing an announcement time value for the next opportunity for announcement by the U2U relay of a protected DDS from the end UE (e.g., if DDS protection is activated for the ProSe service used on this link) (705). If the U2U relay canceled the last ProSe restriction code for the end UE, the U2U relay may include instructions to cancel any pending protected DDS timers.

[0103] The U2U relay may also invalidate stored ProSe restriction codes when the corresponding validity timer expires. The U2U relay may decide to release the direct link with the end UE if all of the end UE ProSe restriction codes have expired and no other ProSe services remain in use.

[0104] FIG. 8 illustrates an example call flow for a U2U relayed DNS query with IP sharing privacy.

[0105] End UE 1 may perform a direct link establishment procedure with the U2U relay 801. End UE 2 may have established a secure connection with the U2U relay (e.g., using the direct link establishment procedure) 802.

[0106] The U2U relay may receive a DNS query from end UE 2 including end UE 1 user information ID and ProSe restriction code used to discover end UE 1 (803).

[0107] The U2U relay can verify that there is an entry for end UE 1's user information ID and the received ProSe restriction code (804). There can be multiple entries for the same user information ID. The ProSe restriction code is used to select a specific entry (i.e., to retrieve a unique pair of ProSe restriction code and user information ID). The U2U relay can verify that the validity timer for the ProSe restriction code has not expired. If the previous check was successful, the U2U relay can send a DNS response to end UE 2 containing end UE 1's IP address / prefix information (805).

[0108] FIG. 9 illustrates an example call flow for a U2U relay initiation Model A U2U relay discovery procedure using multiple keysets.

[0109] The end UE 1 may perform a direct link establishment procedure with the U2U relay (901). The U2U relay may decide to announce the connected or discovered UE (902).

[0110] For each stored Prose restriction code for end UE 1, the U2U relay may send a PC5 signaling message (PC5-S) request message including the Prose restriction code previously received from end UE 1 to request the corresponding protected DDS (903). A new PC5-S signaling message may be defined or an existing PC5 message may be extended to include the new information needed, for example, a keep-alive message may be reused for the request for the protected DDS associated with the ProSe restriction code.

[0111] In one example, the U2U relay may send a PC5-S request message containing instructions to request all applicable protected DDS for all services (e.g., end UE 1 is using several different ProSe services with per-ProSe service protection). In another example, the U2U relay may send a list of Prose restriction codes.

[0112] End UE 1 may generate a secure PC5-S response message (e.g., a keep-alive message) that includes the RSC and DDS protected using direct discovery security material 904. End UE 1 may include one or more DDSs in the response message (e.g., if the request included a list of Prose restriction codes). End UE 1 may protect the PC5-S message using the PC5 link security context and send it to the U2U relay.

[0113] The U2U relay may process the PC5-S response message security and extract the protected DDS. The U2U relay may verify that the ProSe restriction code from the received protected DDS is valid (e.g., verify whether the validity timer has not expired based on the validity time value). The U2U relay may send a U2U relay protected discovery message to end UE 2, including the RSC, the U2U relay user information ID, and the protected DDS received from end UE 1 (905). The U2U relay may protect the U2U relay discovery message using security material associated with the RSC.

[0114] FIG. 10 illustrates an example call flow for an end-UE initiated model A U2U relay discovery model A procedure using multiple keysets.

[0115] End UE 1 may perform a direct link establishment procedure with the U2U relay (1001). End UE 1 may decide to provide one or more protected DDSs to the U2U relay (1002). This may be triggered based on the announcement time value provided by the U2U relay (e.g., in DCA or LMA) as described above.

[0116] End UE 1 may generate a U2U relay discovery announcement message including an RSC, a U2U relay user information ID, and one or more DDSs, each protected using their respective DDS-related security material (1003). End UE 1 may protect the U2U relay discovery message using the RSC-related security material and send it to the U2U relay. The destination L2 ID may be set to the U2U relay L2 ID discovered by end UE 1, or may use the conventional configured default L2 ID.

[0117] Alternatively, at 1004, end UE 1 can generate a secure PC5-S (unicast) request message (e.g., a keep-alive request message, or new PC5-S messages can be defined) that includes the RSC and one or more DDSs, each protected using their respective DDS-related security material. End UE 1 can protect the PC5-S message using the PC5 link security context and send it to the U2U relay.

[0118] The U2U relay can process the U2U relay discovery / PC5-S request message security and extract the included protected DDS (1005).

[0119] The U2U relay may verify that the RSC supports protected DDS and the validity of the ProSe restriction code from the received protected DDS (1006). The U2U relay may verify that each received code matches the stored ProSe restriction code for end UE 1 and that it has not expired (e.g., based on a validity time value as described above).

[0120] In an alternative case of the PC5 S message 1004, the U2U relay may send a secure PC5-S response message (e.g., a keep-alive response message, or a new PC5-S may be defined) containing the response status (e.g., success or failure) for the announcement to the end UE 1 (1007). The response may include the associated ProSe restriction code.

[0121] The U2U relay may send 1008 a U2U relay protected discovery message to end UE 2, including the RSC, the U2U relay user information ID, and the protected DDS received from end UE 1. The U2U relay may protect the U2U relay discovery message using security material associated with the RSC.

[0122] FIG. 11 illustrates an example call flow for a U2U relay initiation Model A U2U relay discovery procedure with delayed announcement of discovered end UEs.

[0123] End UE 1 may decide to send a discovery announcement message to the U2U relay (1101). The end UE may monitor previous discovery announcement messages sent by the U2U relay to determine the next scheduled announcement opportunity of the U2U relay. For example, the U2U relay may include discovery scheduling assistance information in the discovery announcement message to inform nearby end UE(s) about the next announcement opportunity by the U2U relay (e.g., expressed as a time offset / window relative to the current time or the discovery message transmission time). The end UE can use this information to schedule / synchronize the transmission of its own discovery message to the relay in a timely manner to enable the relay to include the protected DDS from the end UE in its next relay announcement message (e.g., close to real time before the U2U relay's next transmission).

[0124] The end UE 1 may generate a U2U relay discovery announcement message (1102) including the RSC, the U2U relay user information ID, and the DDS protected using direct discovery security material and a validity time value. The validity time value may be set to not exceed the maximum range allowed by time-based replay protection. For example, the validity time value may be set to not exceed the maximum time (e.g., 2, 4, or 16 seconds) maintained by the UTC-based counter LSB.

[0125] The U2U relay can process the U2U Relay Discovery / PC5-S Request message and extract the protected DDS and validity time value 1103. The U2U relay can verify that the RSC supports the protected DDS.

[0126] The U2U relay may schedule the next announcement for the end UE protected DDS according to its own next scheduled announcement opportunity (e.g., based on the implementation) and may take into account the received validity time value (1104). For example, if the time difference between the next scheduled announcement opportunities is greater than the validity time value (or if no validity time value is provided), the U2U relay may decide to immediately transmit the protected DDS for end UE 1 (or discard the current end UE 1 discovery message until a more appropriate / aligned relay announcement opportunity).

[0127] The U2U relay may transmit (1105) a U2U relay protected discovery message at the scheduled time, including the RSC, the U2U relay user information ID, and the protected DDS received from end UE 1. The U2U relay may protect the U2U relay discovery message using security material associated with the RSC.

[0128] In one example, the U2U relay may be configured with RSC-related security material, and the end UE may be configured with RSC-related security material and DDS-related security material. The security material associated with the DDS may be associated with a ProSe restriction code. The U2U relay and end UE may be configured with an indicator associated with the RSC that indicates whether the RSC supports protected DDS.

[0129] In one example, the U2U relay can send a request message for a protected DDS to the connected end UE. The request message can include a ProSe restriction code. The U2U relay can receive a response message from the connected end UE. The response message can include the requested protected DDS. The message can also include a message type, a ProSe restriction code associated with the DDS, a UTC-based counter, a MIC, and a protected end UE information ID. In another example, the end UE can send a U2U relay discovery message including the protected DDS. The U2U relay can send a discovery announcement including the received protected DDS.

[0130] While features and elements are described above in particular combinations, those skilled in the art will understand that each feature or element can be used alone or in any combination with the other features and elements. In addition, the methods described herein may be implemented in a computer program, software, or firmware embodied in a computer-readable medium for execution by a computer or processor. Examples of computer-readable media include electronic signals (transmitted via wired or wireless connections) and computer-readable storage media. Examples of computer-readable storage media include, but are not limited to, read-only memory (ROM), random-access memory (RAM), registers, cache memory, semiconductor memory devices, magnetic media such as internal hard disks and removable disks, and optical media such as magneto-optical media and CD-ROM disks and digital versatile disks (DVDs). A processor in association with software may be used to implement a radio frequency transceiver for use in a WTRU, UE, terminal, base station, RNC, or any host computer.

Claims

1. 1. A method performed by a wireless transmit / receive unit (WTRU) acting as a user equipment (UE)-to-user equipment (UE) relay, the method comprising: receiving a first message from a first end UE, the first message including a first Direct Discovery Set (DDS), the first DDS including at least a User Information Identification (User Information ID) of the first end UE, encrypted using a first secret key associated with a first Proximity Services (ProSe) service; receiving a second message from a second end UE, the second message including a second Direct Discovery Set (DDS), the second DDS including at least a User Information Identification (User Information ID) of the second end UE, encrypted using a second secret key associated with a second Proximity Services (ProSe) service; obtaining the encrypted first DDS from the first message; obtaining the encrypted second DDS from the second message; broadcasting a third message, the third message includes the encrypted first DDS, the encrypted second DDS, and a relay service code (RSC) associated with a relay connection service provided by the WTRU; the third message is encrypted using a third secret key associated with the RSC; and sending a fourth message to a fourth end UE, the fourth message being a PC5 signaling (PC5-S) request message, the fourth message including a request for a ciphered fourth DDS, the fourth message being sent during an announcement period configured in the WTRU; receiving a fifth message from the fourth end UE based on the PC5-S request message, the fifth message including the requested encrypted fourth DDS; and verifying, at the WTRU, based on a configured indication, that the relay connection service provided by the WTRU supports relay operation with encrypted DDS.

2. The method of claim 1 , wherein the first end UE is provisioned with the first private key and the second end UE is provisioned with the second private key.

3. The method of claim 1 , wherein the WTRU, the first end UE, and the second end UE are provisioned with the third secret key.

4. The method of claim 1 , wherein the configured indication is configured by a network using RRC signaling.

5. The method of claim 1 , wherein the configured instructions are pre-provisioned in the WTRU.

Citation Information

Patent Citations

  • Gateway channel allocation method based on Internet of Things system and related equipment

    CN113873647A

  • Method and apparatus for user equipment (UE) discovery

    JP2023543471A

  • Method for operating a cellular network - Patents.com

    JP2024507208A

  • Apparatus and method for supporting device to device communication in wireless communication system

    KR1020210028549A

  • Method for performing RRC connection procedure in wireless communication system and apparatus therefor

    US20200178343A1