Method and apparatus for maintaining transmission integrity and authenticity through channel measurement and reporting

By authenticating channel connections at the physical layer using predicted and real-time measurements of downlink reference signals, wireless communication systems can detect and prevent unauthorized interference, addressing security vulnerabilities in public forums.

KR102997674B1Active Publication Date: 2026-07-29QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
QUALCOMM INC
Filing Date
2022-05-02
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Wireless communication systems are vulnerable to security threats such as man-in-the-middle and replay attacks, particularly in public forums, where malicious entities can impersonate legitimate entities and gain unauthorized access to sensitive information.

Method used

Authentication of channel connections between user equipment (UE) and a base station is performed at the physical layer by comparing predicted measurements of downlink reference signals with real-time measurements, identifying unauthorized interfering devices based on discrepancies exceeding a threshold.

Benefits of technology

This method effectively detects and reports the presence of unauthorized interfering devices, enhancing security by authenticating connections and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 112023141993118-PCT00021_ABST
    Figure 112023141993118-PCT00021_ABST
Patent Text Reader

Abstract

The connection between the User Equipment (UE) and the base station can be authenticated at the physical layer, and the presence of an unauthorized interfering device can be identified based on a predicted measurement of the downlink reference signal and a real measurement of the current downlink reference signal. The predicted measurement is generated based on previous measurements of the downlink reference signal known to be received from the base station after, for example, upper-layer initial authentication. The predicted measurement may be for positioning measurement, channel measurement, or measurement of movement speed or direction, or a combination thereof. The difference between the predicted measurement and the real measurement indicates that the previously received reference signal and the currently received reference signal do not originate from the same entity, and thus there is a high probability that an entity interfering in the communication channel is performing a man-in-the-middle or replay attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] This application claims priority and interest in Greek patent application No. 20210100415, titled “METHODS AND APPARATUS FOR MAINTAINING TRANSMISSION INTEGRITY AND AUTHENTICITY THROUGH CHANNEL MEASUREMENTS AND REPORTING”, filed June 23, 2021, which is assigned to the assignee of this application and is expressly incorporated herein by reference.

[0002] The present disclosure generally relates to the field of wireless communication, and more specifically to authenticating a channel connection between a user equipment (UE) and a base station and identifying the presence of an unauthorized interfering device. Background Technology

[0003] Wireless communication systems are widely deployed to provide various types of communication content, such as voice, video, packet data, messaging, and broadcast. These systems may be able to support communication with multiple users by sharing available system resources (e.g., time, frequency, and power). Examples of such multiple access systems include Code Division Multiple Access (CDMA) systems, Time Division Multiple Access (TDMA) systems, Frequency Division Multiple Access (FDMA) systems, and Orthogonal Frequency Division Multiple Access (OFDMA) systems. A wireless multiple-access communication system may include multiple base stations, each of which simultaneously supports communication with multiple communication devices, each of which may be referred to as User Equipment (UE).

[0004] Wireless communication systems can sometimes be vulnerable to various security issues. In some cases, potential security risks may arise, particularly when wireless information and / or location-based services are provided in public forums (e.g., shopping malls, office buildings, etc.), as malicious entities may exploit the network to gain unauthorized access to sensitive information. These security risks may include cyber attacks of the "man-in-the-middle," "spoofing," and / or "phishing" types. These attacks can be based on malicious entities successfully impersonating legitimate entities by manipulating network protocols, forging credentials, and / or compromising network integrity to deceive users and gain illicit benefits. Additionally, UEs can relay data to other UEs via sidelink channels and coverage enhancement applications, which increases the likelihood of man-in-the-middle and replay attacks. Therefore, authentication of channel connections and identification of the presence of attack devices are desirable. means of solving the problem

[0005] The connection between the User Equipment (UE) and the base station can be authenticated, for example, at the physical layer, and the presence of an unauthorized interfering device between the UE and the base station can be identified based on a predicted measurement of the downlink reference signal and a real measurement of the current downlink reference signal. The predicted measurement is generated based, for example, on previous measurements of the downlink reference signal known to be received from the base station after upper-layer initial authentication. The predicted measurement may be for positioning measurement, channel measurement, movement speed or direction measurement, or a combination thereof. For example, a difference between the predicted measurement and the real measurement that is greater than a predetermined threshold indicates that the previous reference signal and the current reference signal used to generate the predicted measurement do not originate from the same entity, and therefore there is a high probability that an entity interfering in the communication channel is performing a man-in-the-middle or replay attack.

[0006] In one implementation, a method performed by a user device (UE) to authenticate a connection with a base station comprises: receiving one or more predicted values ​​for one or more measurements of downlink positioning reference signals based on measurements of previous downlink positioning reference signals received from the base station; receiving downlink positioning reference signals; performing one or more measurements of the received downlink positioning reference signals; and determining whether an attack device has transmitted the received downlink positioning reference signals based on one or more predicted values ​​for one or more measurements of the downlink positioning reference signals and one or more measurements of the current downlink positioning reference signals.

[0007] In one implementation, user equipment (UE) configured to authenticate a connection with a base station comprises: a radio transceiver configured to communicate with another entity of a wireless network; at least one memory; and at least one processor coupled to the radio transceiver and at least one memory, wherein the at least one processor receives, via the radio transceiver, one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; and receives downlink reference signals via the radio transceiver;

[0008] Perform one or more measurements of the received downlink reference signals; and

[0009] Based on one or more predicted values ​​for one or more measurements of downlink reference signals and one or more measurements of current downlink reference signals, the attack device is configured to determine whether it has transmitted received downlink reference signals.

[0010] In one embodiment, user equipment (UE) configured to authenticate a connection with a base station comprises: means for receiving one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; means for receiving downlink reference signals; means for performing one or more measurements of the received downlink reference signals; and

[0011] It includes means for determining whether an attack device has transmitted received downlink reference signals based on one or more predicted values ​​for one or more measurements of downlink reference signals and one or more measurements of current downlink reference signals.

[0012] In one embodiment, a non-transient storage medium comprising stored program code, wherein the program code is operable to configure at least one processor within a user device (UE) to authenticate a connection with a base station, and the program code comprises: a command to receive one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; a command to receive downlink reference signals; a command to perform one or more measurements of the received downlink reference signals; and

[0013] It includes a command that determines whether the attack device has transmitted received downlink reference signals based on one or more predicted values ​​for one or more measurements of downlink reference signals and one or more measurements of current downlink reference signals.

[0014] In one implementation, a method performed by a network entity to authenticate a connection between a user device (UE) and a base station comprises: obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; transmitting one or more predicted values ​​for one or more measurements of downlink reference signals to the UE; and receiving an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0015] In one implementation, a network entity configured to authenticate a connection between a user device (UE) and a base station comprises: an external interface configured to communicate with other entities of a wireless network; at least one memory; and at least one processor coupled to the external interface and at least one memory, wherein the at least one processor obtains one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; transmits one or more predicted values ​​for one or more measurements of downlink reference signals to the UE via the external interface; and is configured to receive, via the external interface, an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0016] In one implementation, a network entity configured to authenticate a connection between a user device (UE) and a base station comprises: means for obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; means for transmitting one or more predicted values ​​for one or more measurements of downlink reference signals to the UE; and means for receiving an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0017] In one embodiment, a non-transient storage medium comprising stored program code, wherein the program code is operable to configure at least one processor within a network entity to authenticate a connection between a user device (UE) and a base station, and the program code comprises: a command to obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; a command to transmit one or more predicted values ​​for one or more measurements of downlink reference signals to the UE; and a command to receive an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE. Brief explanation of the drawing

[0018] The claimed product is indicated and clearly claimed, particularly in the concluding section of the specification. However, regarding both the configuration and / or method of operation, along with its features and / or benefits, it may be best understood by referring to the following detailed description when read together with the accompanying drawings: Figure 1 is a diagram of an exemplary wireless communication system. Figure 2 illustrates an exemplary wireless network structure. Figure 3 illustrates another exemplary wireless network structure. FIG. 4 illustrates a block diagram of the design of a base station and a UE, which may be one of the base stations and one of the UEs of FIG. 1. FIG. 5 illustrates the structure of an exemplary subframe sequence having positioning reference signals (PRS) positioning occasions. FIG. 6 illustrates a simplified environment and an exemplary technique for determining the position of a UE using distances from multiple base stations. Figure 7 illustrates a simplified environment and exemplary techniques for determining the position of a UE using Time Difference of Arrival (TDOA) techniques. FIG. 8a illustrates a simplified environment and exemplary technique for determining the position of a UE using the angle of arrival (AoA) or the angle of departure (AoD). FIG. 8b illustrates a simplified environment and other exemplary techniques for determining the position of a UE using AoA or AoD. Figure 9a shows an environment in which a replay attack or man-in-the-middle attack can be performed by an attack device between the UE and the base station, and the identification of the attack device. Figure 9b is a graph showing the number of expected positioning measurements and current positioning measurements that can be compared to identify the presence of an attack device. FIG. 10 illustrates examples of predicted measurements received for positioning measurement and predicted measurements for security. FIG. 11 is a message flow illustrating messaging in a wireless network for authenticating a connection between a UE and a base station and identifying the presence of an intervening device between the UE and the base station. FIG. 12 illustrates a schematic block diagram illustrating specific exemplary features of a UE configured to support authentication of a connection with a base station and identification of the presence of an intervening device between the UE and the base station. FIG. 13 is a schematic block diagram illustrating specific exemplary features of a network entity configured to support authentication of a connection between a UE and a base station and identification of the presence of an intervening device between a UE and a base station. FIG. 14 illustrates a flowchart of an exemplary method performed by a UE to authenticate a connection with a base station. FIG. 15 illustrates a flowchart of an exemplary method performed by a network entity to authenticate a connection between a UE and a base station. Depending on specific exemplary implementations, similar reference numerals in various drawings represent similar elements. Additionally, multiple instances of an element may be indicated by a hyphen and a second number or character following the first number for the element. For example, multiple instances of element (102) may be indicated as 102-1, 102-2, 102-3, etc., or 102a, 102b, or 102c, etc. When referring to such an element using only the first number, any instance of that element should be understood (for example, element (102) in the previous example would refer to elements 102-1, 102-2, 102-3, or elements 102a, 102b, or 102c). It should be noted that the drawings are not necessarily drawn to scale, for example, for the sake of simplicity and / or clarity of example. For example, the dimensions of some embodiments may be exaggerated compared to others. It should also be understood that other embodiments may be utilized. Furthermore, structural and / or other modifications may be made without departing from the claimed claims. References to "claimed claims" throughout this specification refer to claims intended to be covered by one or more claims, or any part thereof, and are not intended to refer to a complete set of claims, a specific combination of sets of claims (e.g., method claims, device claims, etc.), or a specific claim. It should also be noted that directions and / or references, such as up, down, top, bottom, etc., may be used to facilitate discussion of the drawings and are not intended to limit the application of the claimed claims. Accordingly, the following detailed description is not taken to limit the claimed claims and / or equivalents. Specific details for implementing the invention

[0019] Those skilled in the art will recognize that the information and signals described below may be represented using any of the various different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the description below may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or particles, or any combination thereof, depending in part on the specific application, part on the required design, and part on the corresponding technology.

[0020] Additionally, many embodiments are described in terms of sequences of actions to be performed, for example, by elements of a computing device. It will be recognized that the various actions described herein may be performed by specific circuits (e.g., application-specific integrated circuits (ASICs)), by program instructions executed by one or more processors, or by a combination of both. Additionally, the sequence(s) of actions described herein may be considered to be fully realized within any form of non-transient computer-readable storage medium in which a corresponding set of computer instructions is stored that, at execution, causes the relevant processor of the device to perform the functionality described herein. Accordingly, various embodiments of the present disclosure may be realized in a number of different forms, all of which are considered to be within the scope of the claimed claims. Additionally, for each of the embodiments described herein, a corresponding form of any such embodiment may be described herein, for example, as "one or more processors configured to perform the described action."

[0021] As used herein, the terms “User Equipment” (UE) and “Base Station” are not intended to be specific to or otherwise limited to any particular Radio Access Technology (RAT) unless otherwise noted. Generally, a UE may be any radio communication device used by a user to communicate over a radio communication network (e.g., mobile phone, router, tablet computer, laptop computer, consumer tracking device for tracking consumer items, packages, assets, or entities such as individuals and pets, wearable (e.g., smartwatch, glasses, augmented reality (AR) / virtual reality (VR) headset, etc.), vehicle (e.g., car, motorcycle, bicycle, etc.), Internet of Things (IoT) device, etc.). A UE may be mobile or stationary (e.g., at certain times) and may communicate with a Radio Access Network (RAN). As used herein, the term “UE” may be interchangeably referred to as “access terminal” or “AT,” “client device,” “wireless device,” “subscriber device,” “subscriber terminal,” “subscriber station,” “user terminal,” or UT, “mobile terminal,” “mobile station,” “mobile device,” or variations thereof. Generally, UEs can communicate with a core network via a RAN, and through the core network, UEs can connect with external networks, such as the Internet, and with other UEs. Of course, other mechanisms for connecting UEs to the core network and / or the Internet, such as via wired access networks, wireless local area network (WLAN) networks (e.g., based on IEEE 802.11, etc.), are also possible.

[0022] A base station may operate according to one of several RATs that communicate with UEs depending on the deployed network, or alternatively, it may be referred to as an access point (AP), network node, NodeB, evolutionary NodeB (eNB), or new radio (NR) NodeB (also referred to as gNB). Additionally, in some systems, the base station may provide pure edge node signaling functions, while in other systems, it may provide additional control and / or network management functions. The communication link through which UEs can transmit signals to the base station is referred to as an uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). The communication link through which the base station can transmit signals to UEs is referred to as a downlink (DL) or forward link channel (e.g., paging channel, control channel, broadcast channel, forward traffic channel, etc.). The communication link through which UEs can transmit signals to other UEs is referred to as a sidelink (SL) channel. As used herein, the term traffic channel (TCH) may refer to either a UL / reverse or DL / forward traffic channel.

[0023] The term “base station” may refer to a single physical transmit-receive point (TRP) or multiple TRPs that may or may not be juxtaposed. For example, if the term “base station” refers to a single physical TRP, the physical TRP may be the base station’s antenna corresponding to the base station’s cell. If the term “base station” refers to multiple juxtaposed physical TRPs, the physical TRPs may be an array of the base station’s antennas (e.g., in a Multiple Input Multiple Output (MIMO) system or when the base station employs beamforming). If the term “base station” refers to multiple non-juxtaposed physical TRPs, the physical TRPs may be a Distributed Antenna System (DAS) (a network of spatially separated antennas connected to a common source via a transmission medium) or a Remote Radio Head (RRH) (a remote base station connected to a serving base station). Alternatively, non-juxtaposed physical TRPs may be a serving base station receiving measurement reports from the UE and a neighboring base station having reference RF signals that the UE is measuring.

[0024] To support UE positioning, two broad classes of location solutions have been defined: the control plane and the user plane. In the control plane (CP) location, signaling related to positioning and positioning support may be carried over existing network (and UE) interfaces and using existing protocols dedicated to the delivery of signaling. In the user plane (UP) location, signaling related to positioning and positioning support may be carried over as part of other data using such protocols as the Internet Protocol (IP), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP).

[0025] The 3rd Generation Partnership Project (3GPP) has defined control plane location solutions for UEs using radio access based on GSM (2G), UMTS (Universal Mobile Telecommunications System) (3G), LTE (4G), and NR (New Radio) for the 5th generation (5G). These solutions are defined in 3GPP technical specifications (TS) 23.271 and 23.273 (common part), 43.059 (GSM access), 25.305 (UMTS access), 36.305 (LTE access), and 38.305 (NR access). The Open Mobile Alliance (OMA) has similarly defined a UP location solution known as a Secure User Plane Location (SUPL) that can be used to locate a UE accessing any of the multiple radio interfaces that support IP packet access, such as GPRS (General Packet Radio Service) using GSM, GPRS using UMTS, or IP access using LTE or NR.

[0026] Both CP and UP location solutions may employ a location server (LS) to support positioning. The location server may be part of or accessible from the serving network or home network for the UE, or it may simply be accessible via the Internet or a local intranet. When UE positioning is required, the location server initiates a session with the UE (e.g., a location session or a SUPL session) and may coordinate location measurements by the UE and the determination of the UE's estimated location. During a position session, the position server may request the UE’s positioning capabilities (or the UE may provide them to the position server without request), and may provide auxiliary data to the UE (e.g., if requested by the UE or in the absence of a request), and may request position estimations or position measurements from the UE for, for example, Global Navigation Satellite System (GNSS), Time Delay of Arrival (TDOA), Angle of Departure (AOD), Round Trip Time (RTT) and Multi-Cell RTT (Multi-RTT), and / or Enhanced Cell ID (ECID) position methods. The auxiliary data may be used by the UE to acquire and measure signals of GNSS and / or reference signals, such as positioning reference signals (PRS), by providing, for example, expected characteristics of these signals such as frequency, expected time of arrival, signal coding, and signal Doppler.

[0027] In UE-based operation mode, auxiliary data may also be used by the UE to help determine location estimates from the resulting location measurements, either or instead (e.g., when auxiliary data provides satellite ephemeris data in the case of GNSS positioning, or when it provides other base station characteristics such as base station locations and PRS timing in the case of ground positioning using TDOA, AoD, multi-RTT, etc.).

[0028] In UE assist operation mode, the UE may return location measurements to a location server that can determine the UE's estimated location based on these measurements and possibly also based on other known or configured data (e.g., satellite ephemeris data for GNSS locations or, for example, base station locations and possibly base station characteristics including TDOA, AoD, multi-RTT, etc. in the case of ground positioning using PRS timing).

[0029] In other standalone modes of operation, the UE may perform location-related measurements without any positioning aid data from a location server, and may additionally calculate the position or change in position without any positioning aid data from a location server. Positioning methods that may be used in standalone mode include sensors as well as GPS and GNSS (e.g., when the UE obtains satellite orbit data from data broadcast by the GPS and GNSS satellites themselves).

[0030] For 3GPP CP locations, the location server may be an enhanced serving mobile location center (E-SMLC) for LTE access, a standalone SMLC (SAS) for UMTS access, a serving mobile location center (SMLC) for GSM access, or a Location Management Function (LMF) for 5G NR access. For OMA SUPL locations, the location server may be a SUPL Location Platform (SLP) capable of performing one of the following roles: (i) a Home SLP (H-SLP) when it is within or associated with the UE's home network or provides the UE with a permanent subscription for location services; (ii) a Discovery SLP (D-SLP) when it is within or associated with some other (non-home) network or is not associated with any network; (iii) an Emergency SLP (E-SLP) when it supports locations for emergency calls initiated by the UE; or (iv) Visiting SLP (V-SLP) if it is within or associated with the current local area or serving network for the UE.

[0031] A wireless access network may employ a reconfigurable intelligent surface (which may also be referred to as a reconfigurable intelligent surface (RIS)) to increase the communication range of devices while minimizing the increase in the amount of power consumed by the wireless access network. The reconfigurable surface may include an array of reflective elements that can be semi-statically configured to change the reflection angle of the reconfigurable surface by adjusting, for example, the reflection coefficient of the reflective elements.

[0032] Wireless communication systems can be vulnerable to various security issues. In some cases, potential security risks may arise, particularly when wireless information and / or location-based services are provided in public forums (e.g., shopping malls, office buildings, etc.), as malicious entities may exploit the network to gain unauthorized access to sensitive information. These security risks may include cyberattacks of the "man-in-the-middle," "spoofing," and / or "phishing" types. These attacks may be based on malicious entities successfully impersonating legitimate entities by manipulating network protocols, forging credentials, and / or compromising network integrity to deceive users and gain illicit benefits.

[0033] For example, a UE can relay data to other UEs in sidelink channels and coverage enhancement applications. Relaying data between UEs raises concerns regarding man-in-the-middle and replay attacks. For example, these attacks can be performed when the physical layer is used for authenticating transmits. For example, by using channel characteristics and prediction techniques for positioning measurements performed using downlink reference signals, such as positioning reference signals and / or channel parameters, a UE can determine whether received downlink transmits are most likely from a genuine transmitter.

[0034] In one implementation, the UE authenticates a connection with a base station, such as a gNB, at the physical layer and can identify the presence of an unauthorized interfering device between the UE and the base station based on predicted values ​​for one or more measurements of the downlink reference signal, which are based on one or more prior measurements of the downlink reference signal received from the base station. The UE may receive predicted values ​​for one or more measurements, for example, from a base station or a location server. The measurements may be positioning measurements, such as, for example, RSRP (Received Signal Power), RSTD (Reference Signal Time Difference) values ​​and / or uncertainty, AoA (Angle of Arrival) values ​​and / or uncertainty, departure angle values ​​and / or uncertainty, Round Trip Time (RTT), etc. The measurements may further include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports, and / or predicted movement speed and / or direction of movement for the UE. When a new downlink reference signal is received, the UE may determine whether it is from a genuine transmitter or an attack device by performing one or more measurements on the downlink reference signal and comparing the measurement value for the current reference signal with a predicted value based on previous measurements. If the current measurement value does not match the predicted measurement value within a threshold, e.g., acceptable error or uncertainty, the UE may determine that the current downlink reference signal did not originate from the same base station that transmitted the previous downlink reference signal used to generate the predicted measurement value, and therefore, it is highly likely that an unauthorized interfering device is present. The UE may report the presence of the detected interfering device as an active attack to the serving base station or location server.

[0035] FIG. 1 illustrates an exemplary wireless communication system (100) in which a UE (104) can authenticate a connection with a base station (102) at the physical layer and identify the presence of an unauthorized interfering device, as discussed herein. The wireless communication system (100), which may also be referred to as a wireless wide area network (WWAN), may include several base stations (102), which are sometimes referred to herein as a TRP (102) and several UEs (104). The base stations (102) may include macro cell base stations (high-power cellular base stations) and / or small cell base stations (low-power cellular base stations). In one embodiment, the macro cell base station may include eNBs corresponding to an LTE network, or gNBs corresponding to a 5G network, or a combination of both of these, and the small cell base stations may include femtocells, picocells, microcells, etc.

[0036] Base stations (102) may collectively form a RAN and interface with a core network (170) (e.g., an advanced packet core (EPC) or a next-generation core (NGC)) via backhaul links (122), and with one or more location servers (172) via the core network (170). In addition to other functions, base stations (102) may perform functions related to one or more of the following: transmission of user data, wireless channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, duplex connectivity), inter-cell interference coordination, connection setup and release, load balancing, distribution for non-access stratum (NAS) messages, NAS node selection, synchronization, RAN sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracking, RAN information management (RIM), paging, positioning, and delivery of alert messages. Base stations (102) may communicate directly or indirectly with each other (e.g., through EPC / NGC) via backhaul links (134) which may be wired or wireless.

[0037] Base stations (102) may communicate wirelessly with UEs (104). Each of the base stations (102) may provide communication coverage for each geographic coverage area (110). In one embodiment, one or more cells may be supported by the base station (102) in each coverage area (110). A “cell” is a logical communication entity used for communication with a base station (e.g., on some frequency resources referred to as carrier frequency, component carrier, carrier, band, etc.) and may be associated with an identifier (e.g., physical cell identifier (PCID), virtual cell identifier (VCID)) to distinguish cells operating on the same or different carrier frequencies. In some cases, different cells may be configured according to different protocol types (e.g., machine type communication (MTC), narrowband IoT (NB-IoT), enhanced mobile broadband (eMBB), etc.) that may provide access to different types of UEs. In some cases, the term “cell” may also refer to a geographical coverage area (e.g., sector) of a base station, as long as the carrier frequency is detected and can be used for communication within a portion of the geographical coverage areas (110).

[0038] The geographical coverage areas (110) of neighboring macro cell base stations (102) may partially overlap (e.g., in handover areas), but some of the geographical coverage areas (110) may be substantially overlapped by a larger geographical coverage area (110). For example, a small cell base station (102') may have a coverage area (110') that substantially overlaps with the coverage area (110) of one or more macro cell base stations (102). A network containing both small cell and macro cell base stations may be known as a heterogeneous network. A heterogeneous network may also include HeNBs (home eNBs) that may provide service to a limited group known as a closed subscriber group (CSG).

[0039] Communication links (120) between base stations (102) and UEs (104) may include UL (also referred to as reverse link) transmissions from UE (104) to base station (102) and / or downlink (DL) (also referred to as forward link) transmissions from base station (102) to UE (104). Communication links (120) may use MIMO antenna techniques including spatial multiplexing, beamforming, and / or transmit diversity. Communication links (120) may pass through one or more carrier frequencies. The allocation of carriers may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be allocated to DL than to UL).

[0040] The wireless communication system (100) may further include a wireless local area network (WLAN) access point (AP) (150) that communicates with WLAN stations (STAs) (152) via communication links (154) in an unlicensed frequency spectrum (e.g., 5 GHz). When communicating in an unlicensed frequency spectrum, the WLAN STAs (152) and / or WLAN AP (150) may perform a clear channel assessment (CCA) before communicating to determine whether a channel is available.

[0041] The small cell base station (102') may operate in licensed and / or unlicensed frequency spectrum. When operating in unlicensed frequency spectrum, the small cell base station (102') may employ LTE or 5G technology and use the same 5 GHz unlicensed frequency spectrum used by the WLAN AP (150). The small cell base station (102') employing LTE / 5G in unlicensed frequency spectrum may boost coverage for the access network and / or increase the capacity of the access network. LTE in unlicensed spectrum may be referred to as LTE-Unlicensed (LTE-U), Licensed Assisted Access (LAA), or MulteFire.

[0042] The wireless communication system (100) may further include a millimeter wave (mmW) base station (180) that may operate at mmW frequencies and / or near mmW frequencies to communicate with the UE (182). EHF (extremely high frequency) is a part of RF in the electromagnetic spectrum. EHF has a range of 30 GHz to 300 GHz and wavelengths between 1 millimeter and 10 millimeters. Radio waves in this band may also be referred to as millimeter waves. Near mmW may extend down to a frequency of 3 GHz with a wavelength of 100 millimeters. The SHF (super high frequency) band extends between 3 GHz and 30 GHz and is also referred to as centimeter waves. Communications using mmW / near mmW radio frequency bands have high path loss and a relatively short range. The mmW base station (180) and UE (182) may utilize beamforming (transmit and / or receive) over the mmW communication link (184) to compensate for extremely high path loss and short range. Additionally, in alternative configurations, it will be recognized that one or more base stations (102) may also transmit using mmW or near mmW and beamforming. Accordingly, it will be recognized that the foregoing examples are merely examples and should not be construed as limiting the various embodiments disclosed herein.

[0043] Transmit beamforming is a technique for focusing RF signals in a specific direction. Traditionally, when a network node (e.g., a base station) broadcasts an RF signal, it broadcasts the signal in all directions (omnidirectionally). With transmit beamforming, the network node determines where a given target device (e.g., a UE) is located (relative to the transmitting network node) and provides a faster and stronger RF signal (in terms of data rate) to the receiving device(s) by projecting a stronger downlink RF signal in that specific direction. To change the directionality of the RF signal when transmitting, the network node can control the phase and relative amplitude of the RF signal at each of one or more transmitters broadcasting the RF signal. For example, the network node may use an array of antennas (referred to as a "phased array" or "antenna array") that generates a beam of RF waves that can be "steered" to point in different directions without actually moving the antennas. Specifically, the RF current from the transmitter is fed to the individual antennas in the correct phase relationship, and the radio waves from the individual antennas are added together to increase radiation in the desired direction while canceling out radiation in unwanted directions to suppress it.

[0044] In receive beamforming, the receiver uses a receive beam to amplify RF signals detected on a given channel. For example, the receiver may adjust the phase setting of the array of antennas in a specific direction and / or increase the gain setting to amplify RF signals received from that direction (e.g., to increase their gain levels). Thus, when a receiver is referred to as beamforming in a specific direction, it means that the beam gain in that direction is higher than the beam gain along other directions, or that the beam gain in that direction is the highest compared to the beam gains in that direction of all other receive beams available to the receiver. This results in stronger received signal strengths for RF signals received from that direction (e.g., Reference Signal Received Power (RSRP), Reference Signal Received Quality (RSRQ), Signal-to-Interference Plus-Noise Ratio (SINR), etc.).

[0045] In 5G, the frequency spectrum in which wireless nodes (e.g., base stations (102 / 180), UEs (104 / 182)) operate is divided into multiple frequency ranges, namely FR1 (450 to 6000 MHz), FR2 (24250 to 52600 MHz), FR3 (above 52600 MHz), and FR4 (between FR1 and FR2). In a multi-carrier system such as 5G, one of the carrier frequencies is referred to as the "primary carrier," "anchor carrier," "primary serving cell," or "PCell," and the remaining carrier frequencies are referred to as the "secondary carrier," "secondary serving cell," or "SCell." In carrier aggregation, the anchor carrier is a carrier operating on the primary frequency (e.g., FR1) utilized by the cell where the UE (104 / 182) and the UE (104 / 182) perform the initial Radio Resource Control (RRC) connection establishment procedure or initiate the RRC connection re-establishment procedure. The primary carrier carries all common and UE-specific control channels. The secondary carrier is a carrier operating on a second frequency (e.g., FR2) that may be configured once an RRC connection is established between the UE (104) and the anchor carrier and may be used to provide additional radio resources. The secondary carrier may contain only the necessary signaling information and signals, and, for example, since both the primary uplink and downlink carriers are typically UE-specific, the UE-specific ones may not exist in the secondary carrier. This means that different UEs (104 / 182) in the cell may have different downlink primary carriers. The same applies to uplink primary carriers. The network can change the primary carrier of any UE (104 / 182) at any time. This is done, for example, to balance the load on different carriers.Since "serving cell" (whether PCell or SCell) corresponds to the carrier frequency / component carrier that some base stations are communicating with, terms such as "cell," "serving cell," "component carrier," and "carrier frequency" can be used interchangeably.

[0046] For example, referring still to FIG. 1, one of the frequencies utilized by the macro cell base stations (102) may be an anchor carrier (or "PCell"), and other frequencies utilized by the macro cell base stations (102) and / or mmW base stations (180) may be secondary carriers ("SCells"). Simultaneous transmission and / or reception of multiple carriers enables the UE (104 / 182) to significantly increase its data transmission and / or reception rates. For example, in a multi-carrier system, two 20 MHz aggregated carriers would theoretically lead to a twofold increase in data rate (i.e., 40 MHz) compared to that achieved by a single 20 MHz carrier.

[0047] The wireless communication system (100) may further include one or more UEs, such as UEs (190), that are indirectly connected to one or more communication networks through one or more device-to-device (D2D) peer-to-peer (P2P) links. In the example of FIG. 1, the UE (190) has a D2D P2P link (192) with one of the UEs (104) connected to one of the base stations (102) (e.g., through which the UE (190) may indirectly obtain cellular connectivity), and a D2D P2P link (194) with a WLAN STA (152) connected to a WLAN AP (150) (through which the UE (190) may indirectly obtain WLAN-based internet connectivity). In one example, D2D P2P links (192 and 194) may be supported by any well-known D2D RAT such as LTE Direct (LTE-D), WiFi Direct (WiFi-D), Bluetooth®, etc.

[0048] The wireless communication system (100) may further include a UE (164) that may communicate with a macro cell base station (102) over a communication link (120) and / or a mmW base station (180) over a mmW communication link (184). For example, the macro cell base station (102) may support PCell and one or more SCells for the UE (164), and the mmW base station (180) may support one or more SCells for the UE (164).

[0049] The attack device (112) may be performing a man-in-the-middle attack or a relay attack. For example, the attack device (112) may receive a signal from one or more base stations (102) and relay the signal to the UE (104) via a signal (114). The attack device (112) may obtain unauthorized access to sensitive information without knowledge of the UE (104) or the base station (102) through the blocking and relaying of the signal (120) to the UE (104). Therefore, detection of the presence of the attack device (112) by the UE (104) and / or the base station (102) is desirable so that corrective measures can be taken.

[0050] FIG. 2 illustrates an exemplary wireless network structure (200). For example, the NGC (210) (also referred to as “5GC”) may be functionally represented as control plane functions (214) (e.g., UE registration, authentication, network access, gateway selection, etc.) and user plane functions (212) (e.g., UE gateway function, access to data networks, IP routing, etc.), which operate cooperatively to form a core network. The user plane interface (NG-U) (213) and the control plane interface (NG-C) (215) connect the gNB (222) to the NGC (210) and specifically to the control plane functions (214) and user plane functions (212). In additional configurations, the eNB (224) may also be connected to the NGC (210) via the NG-C (215) for control plane functions (214) and the NG-U (213) for user plane functions (212). Additionally, the eNB (224) may communicate directly with the gNB (222) via a backhaul connection (223). In some configurations, the new RAN (220) may have only one or more gNBs (222), while other configurations include one or more of both eNBs (224) and gNBs (222). Either the gNB (222) or the eNB (224) may communicate with the UEs (204) (e.g., any of the UEs shown in FIG. 1). Another optional embodiment may include one or more location servers (230a, 230b) (sometimes collectively referred to as location server (230)) (which may correspond to location server (172)) that may communicate with control plane functions (214) and user plane functions (212) in the NGC (210) respectively to provide location assistance to UEs (204).The location server (230) may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules spread across multiple physical servers, etc.) or, alternatively, may correspond to a single server. The location server (230) may be configured to support one or more location services for UEs (204) who can access the location server (230) via the core network, NGC (210) and / or the Internet (not exemplified). Additionally, the location server (230) may be integrated as a component of the core network or, alternatively, may be located outside the core network, for example, in a new RAN (220).

[0051] FIG. 3 illustrates another exemplary wireless network structure (350). For example, the NGC (360) (also referred to as “5GC”) can be functionally considered as control plane functions provided by the Access and Mobility Management Function (AMF) (364), User Plane Function (UPF) (362), Session Management Function (SMF) (366), SLP (368), and LMF (370), which operate cooperatively to form a core network (i.e., NGC (360)). The User Plane Interface (363) and the Control Plane Interface (365) connect the ng-eNB (324) to the NGC (360), and specifically to the UPF (362) and AMF (364), respectively. In additional configurations, the gNB (322) may also be connected to the NGC (360) via a control plane interface (365) to the AMF (364) and a user plane interface (363) to the UPF (362). Additionally, the eNB (324) may communicate directly with the gNB (322) via a backhaul connection (323), with or without gNB direct connectivity to the NGC (360). In some configurations, the new RAN (320) may have only one or more gNBs (322), while other configurations include one or more of both ng-eNBs (324) and gNBs (322). Either the gNB (322) or the eNB (324) may communicate with the UEs (304) (e.g., any of the UEs shown in FIG. 1). The base stations of the new RAN (320) communicate with AMF (364) over the N2 interface and with UPF (362) over the N3 interface.

[0052] The functions of the AMF include registration management, access management, reachability management, mobility management, lawful interception, transmission for session management (SM) messages between the UE (304) and the SMF (366), transparent proxy services for routing SM messages, access authentication and access authorization, transmission for Short Message Service (SMS) messages between the UE (304) and the Short Message Service Function Unit (SMSF) (not shown), and security anchor functions (SEAF). The AMF also interacts with the authentication server function unit (AUSF) (not shown) and the UE (304), and receives an intermediate key established as a result of the UE (304) authentication process. In the case of authentication based on a Universal Mobile Telecommunications System (UMTS) Subscriber Identity Module (USIM), the AMF retrieves security data from the AUSF. The functions of the AMF also include security context management (SCM). The SCM receives keys from the SEAF that are used to derive access-network specific keys. The functionality of the AMF also includes location service management for regulatory services, transmission of location service messages between the UE (304) and the location management function (LMF) (370) (which may correspond to the location server (172)), as well as between the New RAN (220) and the LMF (370), assignment of Advanced Packet System (EPS) bearer identifiers for interoperability with the EPS, and notification of mobility events to the UE (304). Additionally, the AMF also supports functionality for non-3rd Generation Partnership Project (3GPP) access networks.

[0053] The functions of the UPF include acting as an anchor point for intra- / inter-RAT mobility (where applicable), acting as an external protocol data unit (PDU) session point for interconnections to a data network (not shown), providing packet routing and forwarding, packet inspection, user plane policy rule enforcement (e.g., gating, redirection, traffic steering), lawful interception (user plane collection), traffic usage reporting, quality of service (QoS) handling for the user plane (e.g., UL / DL rate enforcement, reflective QoS marking in DL), UL traffic verification (service data flow (SDF) to QoS flow mapping), transport-level packet marking in UL and DL, DL packet buffering and DL data notification triggering, and the transmission and forwarding of one or more "termination markers" to source RAN nodes.

[0054] The functions of the SMF (366) include session management, allocation and management of UE Internet Protocol (IP) addresses, selection and control of user plane functions, configuration of traffic steering in the UPF to route traffic to appropriate destinations, control of some of the QoS and policy enforcement, and downlink data notification. The interface through which the SMF (366) communicates with the AMF (364) is referred to as the N11 interface.

[0055] Other optional embodiments may include an LMF (370) that may communicate with the NGC (360) to provide location assistance to UEs (304). The LMF (370) may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules spread across multiple physical servers, etc.) or, alternatively, each may correspond to a single server. The LMF (370) may be configured to support one or more location services for UEs (304) who can access the LMF (370) via a core network, the NGC (360), and / or the Internet (not illustrated).

[0056] FIG. 4 illustrates a block diagram of a design (400) of a base station (102) and a UE (104) that may be one of the base stations and one of the UEs in FIG. 1. The base stations (102) may be equipped with T antennas (434a to 434t) and the UE (104) may be equipped with R antennas (452a to 452r), where generally T ≥ 1 and R ≥ 1.

[0057] At the base station (102), the transmitting processor (420) receives data from a data source (412) for one or more UEs, selects one or more modulation and coding schemes (MCS) for each UE based at least partially on channel quality indicators (CQIs) received from the UE, processes data for each UE (e.g., encoding and modulation) based at least partially on the MCS(s) selected for the UE, and may provide data symbols for all UEs. The transmitting processor (420) may also process system information (e.g., semi-static resource partitioning information (SRPI), etc.) and control information (e.g., CQI requests, grants, upper layer signaling, etc.) and provide overhead symbols and control symbols. The transmitting processor (420) may also generate reference symbols for reference signals (e.g., cell-specific reference signal (CRS)) and synchronization signals (e.g., primary synchronization signal (PSS) and secondary synchronization signal (SSS)). The transmitting (TX) multiple-input multiple-output (MIMO) processor (430) may perform spatial processing (e.g., precoding) on ​​data symbols, control symbols, overhead symbols, and / or reference symbols, if applicable, and may provide T output symbol streams to T modulators (MODs) (432a to 432t). Each modulator (432) may process individual output symbol streams (e.g., for OFDM, etc.) to obtain output sample streams. Each modulator (432) may further process the output sample streams (e.g., convert to analog, amplify, filter, and upconvert) to obtain downlink signals.T downlink signals from modulators (432a to 432t) may each be transmitted through T antennas (434a to 434t). According to various embodiments described in more detail below, the synchronization signals may be generated with position encoding to convey additional information.

[0058] In the UE (104), antennas (452a to 452r) may receive downlink signals from the base station (102) and / or other base stations, and may provide the received signals to demodulators (DEMODs) (454a to 454r), respectively. Each demodulator (454) may obtain input samples by conditioning the received signals (e.g., filtering, amplification, down-conversion, and digitization). Each demodulator (454) may obtain received symbols by further processing the input samples (e.g., for OFDM, etc.). A MIMO detector (456) may obtain received symbols from all R demodulators (454a to 454r), perform MIMO detection on the received symbols if applicable, and provide the detected symbols. The receiving processor (458) may process the detected symbols (e.g., demodulate and decode) and provide the decoded data for the UE (104) to the data sink (460), and may also provide the decoded control information and system information to the controller / processor (480). The channel processor may determine the reference signal received power (RSRP), the received signal strength indicator (RSSI), the reference signal received quality (RSRQ), the channel quality indicator (CQI), etc. In some embodiments, one or more components of the UE (104) may be included in the housing.

[0059] On the uplink, in the UE (104), the transmitting processor (464) may receive and process data from the data source (462) and control information from the controller / processor (480) (e.g., reports including RSRP, RSSI, RSRQ, CQI, etc.). The transmitting processor (464) may also generate reference symbols for one or more reference signals. Symbols from the transmitting processor (464) may be precoded by the TX MIMO processor (466), where applicable, further processed by modulators (454a to 454r) (e.g., for DFT-s-OFDM, CP-OFDM, etc.), and transmitted to the base station (102). At the base station (102), uplink signals from the UE (104) and other UEs may be received by antennas (434), processed by demodulators (432), detected by a MIMO detector (436) where applicable, and further processed by a receiving processor (438) to obtain decoded data and control information transmitted by the UE (104). The receiving processor (438) may provide the decoded data to a data sink (439) and the decoded control information to a controller / processor (440). The base station (102) may include a communication unit (444) and may communicate with a network controller (489) through the communication unit (444). The network controller (489) may include a communication unit (494), a controller / processor (490), and a memory (492).

[0060] The controller / processor (440) of the base station (102) and the controller / processor (480) of the UE (104) and / or any other component(s) of FIG. 4 may perform one or more techniques associated with authenticating the connection between the UE (104) and the base station (102) at the physical layer, as described in more detail elsewhere in this document, and may identify the presence of an unauthorized interfering device. For example, the controller / processor (440) of the base station (102) and / or the controller / processor (480) of the UE (104), and / or any other component(s) of FIG. 4 may perform or direct the operations of, for example, the processes (1400 and 1500) of FIG. 14 and FIG. 15, and / or other processes and algorithms as described herein. The memories (442 and 482) may store data and program codes for the base station (102) and the UE (104), respectively. In some embodiments, the memory (442) and / or memory (482) and / or memory (392) may include a non-transient computer-readable medium that stores one or more instructions for wireless communication. For example, the one or more instructions may perform or direct operations of, for example, the processes (1400) and (1500) of FIG. 14 and FIG. 15 and / or other processes described herein when executed by one or more processors of the base station (102) and / or the UE (104).

[0061] As indicated above, FIG. 4 is provided as an example. Other examples may differ from those described in relation to FIG. 4.

[0062] In 5G NR, supported positioning technologies include downlink-based positioning, DL-based positioning including DL-TDOA (using DL RSTD (Received Signal Time Difference) measurements) and DL-AoD (using Reference Signal Received Power (RSRP) measurements); uplink-based positioning including UL-TDOA (using UL RTOA (Relative Time of Arrival) measurements) and UL-AoA (using RSRP measurements); and combined downlink and uplink-based positioning including RTT (Multiple RTT) with one or more neighboring base stations (using RSRP measurements or Rx-Tx time difference measurements). Additionally, E-CID based on RRM (Radio Resource Management) measurements is supported in 5G NR (using RSRP measurements or RSRQ (Reference Signal Received Quality) measurements).

[0063] During positioning using signaling in LTE and 5G NR, the UE typically captures dedicated positioning signals transmitted by base stations, referred to as Positioning Reference Signals (PRS), which are used to generate desired measurements for supported positioning techniques. Positioning Reference Signals (PRS) are defined for 5G NR positioning to enable UEs to detect and measure more neighboring base stations or Transmit and Receive Points (TRPs). Other types of signals, namely signals not dedicated for positioning, may also be used by the UE for positioning. Several configurations are supported to enable various deployments (indoor, outdoor, sub-6, mmW). To support PRS beam operation, beam sweeping is additionally supported for the PRS. Table 1 below illustrates 3GPP release numbers (e.g., Rel.16 or Rel.15) that define specific reference signals for various UE measurements and associated positioning techniques.

[0064] DL / UL reference signals UE measurements To facilitate support for the following positioning techniques Rel.16 DL PRS DL RSTD DL-TDOA Rel.16 DL PRS DL PRS RSRP DL-TDOA, DL-AoD, Multi-RTT Rel.16 DL PRS / Rel.16 SRS for Positioning UE Rx-Tx time difference Multi-RTT 15 SSB / CSI-RS for Rel. RRM SS-RSRP (RSRP for RRM), SS-RSRQ (for RRM), CSI-RSRP (for RRM), CSI-RSRQ (for RRM) E-CID

[0065] During positioning, the UL positioning reference signal transmitted by the UE and received by one or more base stations is based on the Release 15 (Rel-15) SRS (sounding reference signal) enhanced / coordinated for positioning purposes. The UL-PRS may also sometimes be referred to as the "SRS for positioning." A new information element (IE) is configured for the SRS for positioning in RRC signaling. Table 2 below illustrates 3GPP Release 16 measurement and positioning techniques for which the SRS can be used for positioning.

[0066] DL / UL reference signals gNB measurement To facilitate support for the following positioning techniques Rel.16 SRS for positioning UL RTOA UL-TDOA Rel.16 SRS for positioning UL SRS-RSRP UL-TDOA, UL-AoA, Multi-RTT Rel.16 SRS, Rel.16 DL PRS for positioning gNB Rx-Tx time difference Multi-RTT Rel.16 SRS for positioning AoA and ZoA UL-AoA, Multi-RTT

[0067] Angle measurements such as AoA(ψ) and zenith angle of arrival (ZoA(θ)) define the estimated angle of the UE relative to a reference direction that can be determined at the TRP antenna for the UL channel corresponding to the UE. The reference direction can be defined, for example, according to a Global Coordinate System (GCS) or a Local Coordinate System (LCS). While LTE supports AoA using the GCS, 5G NR supports both AoA and ZoA, and both the GCS and the LCS. As used herein, the angle of arrival (AoA) may mean the azimuth of arrival, the zenith of arrival, or both the azimuth of arrival and the zenith.

[0068] FIG. 5 illustrates the structure of an exemplary subframe sequence (500) having positioning reference signal (PRS) positioning opportunities according to embodiments of the present disclosure. The subframe sequence (500) may be applicable to the broadcast of PRS signals from a base station (e.g., any of the base stations described herein) or other network nodes. The subframe sequence (500) may be used in LTE systems, and the same or similar subframe sequences may be used in other communication technologies / protocols such as 5G and NR. In FIG. 5, time is represented horizontally (e.g., on the X-axis) as time increases from left to right, while frequency is represented vertically (e.g., on the Y-axis) as frequency increases (or decreases) from bottom to top. As illustrated in FIG. 5, downlink and uplink radio frames (510) may each have a duration of 10 milliseconds (ms). For downlink frequency division duplex (FDD) mode, radio frames (510) are organized into 10 subframes (512), each with a duration of 1 ms, in the illustrated example. Each subframe (512) includes, for example, two slots (514) with a duration of 0.5 ms.

[0069] In the frequency domain, the available bandwidth may be divided into uniformly spaced orthogonal subcarriers (516) (also referred to as "tones" or "bins"). For example, the subcarriers (516) may be grouped into groups of twelve (12) subcarriers, for example, for a normal-length cyclic prefix (CP) using a 15 kHz interval. A resource of one OFDM symbol length in the time domain and one subcarrier in the frequency domain (represented as a block of subframes (512)) is referred to as a resource element (RE). Each grouping of twelve subcarriers (516) and fourteen OFDM symbols is referred to as a resource block (RB), and in the above example, the number of subcarriers in the resource block It may also be recorded as. For a given channel bandwidth, the number of available resource blocks on each channel (522), also referred to as the transmission bandwidth configuration (522), is It is indicated as. For example, for a 3 MHz channel bandwidth in the above example, the number of available resource blocks on each channel (522) is It is given by. Note that the frequency component of the resource block (e.g., 12 subcarriers) is referred to as the physical resource block (PRB).

[0070] A base station may transmit radio frames (e.g., radio frames (510)), or other physical layer signaling sequences, which support PRS signals (i.e., downlink (DL) PRS) according to frame configurations similar or identical to those shown in FIG. 5, which may be measured and used for position estimation of a UE (e.g., any of the UEs described herein). Other types of radio nodes in a wireless communication network (e.g., a distributed antenna system (DAS), a remote radio head (RRH), a UE, an AP, etc.) may also be configured to transmit PRS signals configured in a manner similar (or identical) to that shown in FIG. 5.

[0071] A set of resource elements used for transmitting PRS signals is referred to as a “PRS resource.” A set of resource elements may span multiple PRBs in the frequency domain and N (e.g., 1 or more) consecutive symbol(s) within a slot (514) in the time domain. For example, cross-hatched resource elements in slots (514) may be examples of two PRS resources. A “PRS resource set” is a set of PRS resources used for transmitting PRS signals, wherein each PRS resource has a PRS resource identifier (ID). Additionally, PRS resources in a PRS resource set are associated with the same transmit-receive point (TRP). A PRS resource ID in a PRS resource set is associated with a single beam transmitted from a single TRP (wherein a TRP may transmit more than one beam). Note that this does not affect whether the beams and TRPs to which the signals are transmitted are known to the UE.

[0072] A PRS may be transmitted in special positioning subframes grouped into positioning opportunities. A PRS occupation is an instance of a periodically repeated time window (e.g., consecutive slot(s)) in which a PRS is expected to be transmitted. Each periodically repeated time window may contain a group of one or more consecutive PRS occupations. Each PRS occupation is a number N of consecutive positioning subframes. PRS It may include. PRS positioning occupations for cells supported by the base station are number T PRS It may also occur periodically in intervals denoted in milliseconds or subframes. As an example, FIG. 5 shows N PRS Ga is identical to 4 518 and T RPS exemplifies the periodicity of positioning opportunities where is 20 or 520 or greater. In some modalities, T PRS It may also be measured in terms of the number of subframes between the start of consecutive positioning opportunities. Multiple PRS opportunities may be associated with the same PRS resource configuration, in which case each such opportunity is referred to as the “opportunity of PRS resources,” etc.

[0073] A location server, e.g., a location server (172) and a base station (102) (e.g., an eNodeB (eNB) for LTE access or an NR NodeB (gNB) for NR access) may exchange messages that enable the location server to (i) obtain location measurements for a specific UE from the base station, or (ii) obtain location information from a base station that is not associated with a specific UE, such as location coordinates of an antenna for the base station, cells supported by the base station (e.g., cell identities), cell timing for the base station, and / or parameters for signals transmitted by the base station, such as PRS signals. In the case of LTE access, an LPP A (LPPa) protocol may be used to transmit such messages between the base station, which is the eNodeB, and the location server, which is the E-SMLC. In the case of NR access, the New Radio Position Protocol A (which may also be referred to as NRPPa or )NRPPa) may be used to transmit such messages between the base station, which is the eNodeB, and the location server, which is the LMF.

[0074] PRS may be transmitted at a constant power. PRS may also be transmitted at zero power (i.e., muted). Muting, which turns off regularly scheduled PRS transmissions, may be useful when PRS signals between different cells overlap by occurring at the same or nearly the same time. In this case, PRS signals from some cells may be muted while PRS signals from other cells are being transmitted (e.g., at a constant power). Muting may also assist UEs in measuring the Signal Capture and Arrival Time (TOA) and Reference Signal Time Difference (RSTD) of unmuted PRS signals (by avoiding interference from muted PRS signals). Muting may also be seen as non-transmission of PRS for a given positioning opportunity for a specific cell. Muting patterns (also referred to as muting sequences) may be signaled to the UE using bit strings (e.g., using the LTE Positioning Protocol (LPP)). For example, in a bit string signaled to indicate a muting pattern, if the bit at position j is set to '0', the UE may infer that the PRS is being muted for the j-th positioning opportunity.

[0075] To further improve the audibility of the PRS, positioning subframes may be low-interference subframes transmitted without user data channels. Consequently, in ideally synchronized networks, the PRS may be interfered with by the PRSs of other cells having the same PRS pattern index (i.e., having the same frequency shift), but not by data transmissions. The frequency shift is a function of the PRS ID for a cell or another transmitting point (TP) As indicated as) or if no PRS ID is assigned, the function of the Physical Cell Identifier (PCI) ( It may also be defined as (indicated as), which generates the effective frequency reuse factor of the six (6).

[0076] Additionally, to improve the audibility of the PRS (e.g., when the PRS bandwidth is limited to only six resource blocks corresponding to a 1.4 MHz bandwidth), the frequency band for successive PRS positioning occupations (or successive PRS subframes) may be changed in a known and predictable manner through frequency hopping. Furthermore, a cell supported by a base station may support more than one PRS configuration, wherein each PRS configuration comprises a distinct frequency offset (vshift), a distinct carrier frequency, a distinct bandwidth, a distinct code sequence, and / or a specific number of subframes (N) per positioning occupation. PRS ) and specific periodicity (T PRS It may include a separate sequence of PRS positioning occultations. In some implementations, one or more of the PRS configurations supported in the cell may be for directional PRS and may then have additional separate characteristics, such as separate transmission directions, separate ranges of horizontal angles and / or separate ranges of vertical angles.

[0077] A PRS configuration as described above, including a PRS transmit / muting schedule, is signaled to the UE to enable the UE to perform PRS positioning measurements. The UE is not expected to blindly perform detection of the PRS configurations.

[0078] It should be noted that the terms “positioning reference signal” and “PRS” may sometimes refer to specific reference signals used for positioning in LTE / NR systems. However, as used herein, unless otherwise indicated, the terms “positioning reference signal” and “PRS” refer to any type of reference signal intended for positioning. Downlink (DL) or sidelink (SL) signals that are not related to positioning, such as for control or communication, are referred to herein as non-positioning reference signals (non-PRS). Examples of non-PRS include, but are not limited to, PHY channels such as SSB, TRS, CSI-RS, PDSCH, DM-RS, PDCCH, PSSCH, and PSCCH. As discussed herein, non-PRS signals typically transmitted for purposes not related to positioning may also be used by the UE for positioning purposes, for example, in hybrid positioning measurements. Similar to the DL PRS transmitted by the base station discussed above, the UE may transmit UL PRS for positioning as well as UL or SL non-PRS that may be used for positioning. UL PRS may be, for example, sounding reference signals (SRS) for positioning.

[0079] Using DL PRS or non-PRS received from base stations or SL signaling from other UEs, and / or SL to other UEs or UL PRS or non-PRS transmitted to base stations, the UE may perform various positioning measurements, such as reference signal time difference (RSTD) measurements for time difference of arrival (TDOA), reference signal received power (RSRP) measurements for TDOA, angle of departure (AoD), angle of arrival (AoA), and round trip time (RTT) or multi-cell RTT (multi-RTT) positioning techniques, and time difference between reception and transmission of signals for multi-RTT (Rx-Tx) positioning techniques.

[0080] Various positioning techniques rely on DL, UL, or SL PRS, and may also use DL, UL, or SL non-PRS. For example, positioning techniques using reference signals include downlink-based positioning, uplink-based positioning, and combined downlink and uplink-based positioning. For example, downlink-based positioning includes positioning methods such as DL-TDOA and DL-AoD. Uplink-based positioning includes positioning methods such as UL-TDOA and UL-AoA. Downlink and uplink-based positioning includes positioning methods such as RTT (Multi-RTT) with one or more neighboring base stations. Other positioning methods exist, including those that do not rely on PRS. For example, Enhanced Cell-ID (E-CID) is based on Radio Resource Management (RRM) measurements.

[0081] Currently, positioning auxiliary data for PRS beams includes the azimuth and elevation angles of each DL-PRS resource (beam), but does not provide any beam width information. Knowledge of PRS beam width (and some other beam pattern information, such as side lobe or back lobe information) may be used to help receive DL PRS beams and may also be used to enable adaptation of the UE Rx antenna for the purpose of UE power saving. For example, if the PRS beam is a wide-angle beam, a UE receiver with a single antenna is likely to achieve high-quality positioning measurements. Therefore, the UE may configure its receiver with a single Rx antenna (or a reduced number of Rx antennas) to save power consumption.

[0082] As discussed above, multiple positioning approaches are supported by 3GPP. In Release 16, auxiliary data from a network, for example, a location server (172) to a UE (104) is provided within the NR Positioning Protocol (NRPP) of 3GPP 38.455 or the LTE Positioning Protocol (LPP) of 3GPP 37.355. There are several gNB side angle estimation approaches for positioning. For example, a downlink (DL) AoD-based approach estimates the DL AoD using knowledge of the beam shape of different gNB transmitted PRS (positioning reference symbols) beams along with knowledge of the RSRPs received at the UE along with these PRSs. This estimation may occur on the network side, such as at a location server (172) in "UE-assisted" mode where the UE reports the measured RSRPs. Alternatively, in "UE-based" mode, estimation may occur in a UE (104) that is notified of beam shapes, for example, including AoD used with PRS in auxiliary data, and the UE (104) may determine the identity of the received DL beam, from which the DL AoD may be determined and a position estimate may be generated. Currently, only the beam's boresight direction is indicated in the auxiliary data.

[0083] As another example, an uplink (UL) AoA-based approach estimates the location of a UE (104) by a gNB or network, e.g., a location server (172), based on measurements of the UE's uplink transmissions (e.g., SRS) at base stations (102). The base station reports its estimated AoA to the location server (172), which may be reported in a global coordinate system (GCS) or a local coordinate system (LCS). The reports may differ for azimuth and elevation angles.

[0084] FIG. 6 illustrates a simplified environment (600) and exemplary techniques for determining the location of a UE (104) using distances from multiple base stations (102-1, 102-2, 102-3) (sometimes collectively referred to as base station (102)). Although FIG. 6 shows three base stations, embodiments may utilize additional gNBs. The distance between the UE (104) and each base station (102) may be determined using, for example, RSRP, RTT, or other suitable methods.

[0085] The RTT measurement may be obtained by either the first entity, e.g., UE (104) or the base station (102), transmitting at time t0 an RTT measurement signal (or message) that is received by either the other entity, e.g., the base station (102) or the UE (104), at time t1. The time it takes for the RTT measurement signal from the first entity to reach the second entity is a propagation delay due to the distance between the entities. After a certain time (processing delay), the second entity transmits at time t2 an RTT response signal (or message) that is received by the first entity at time t3. The time it takes for the RTT response signal from the second entity to reach the first entity is another propagation delay due to the distance between the entities. If factors such as TA (Timing Advance), which compensates for the discrepancy between the transmission timing and the reception timing, are ignored, RTT can be calculated as RTT=[t3-t0] - [t2-t1], which is approximately twice the value obtained by dividing the distance D between entities by the speed of signal propagation (speed of light). Thus, the distances (D1, D2, and D3) between the UE (104) and each base station (102-1, 102-2, and 102-3) can be determined, respectively.

[0086] To determine the location of the UE (104), network geometry, such as the known geographic location of each base station (102) in a reference coordinate system, may be used. For a UE-based positioning procedure, network geometry may be provided to the UE (104) in any way, such as providing information from beacon signals, providing information using a server, providing information using positioning support data, or providing information using uniform resource identifiers.

[0087] With the distances (D1, D2, and D3) between the UE (104) and each distinct gNB base station (102-1, 102-2, and 102-3) determined using multiple RTTs and the known locations of the base stations, the location of the UE (104) may be determined using various known geometric techniques, such as trilateration, for example. For example, from FIG. 6, it can be seen that the circles (651, 652, and 653) centered on each gNB (102-1, 102-2, 102-3) have the same radius as the distances (D1, D2, and D3). Ideally, the location of the UE (104) lies at the common intersection of all the circles (651, 652, and 653). Uncertainty in the base station (102) coordinates or distance measurements will have a direct impact on the accuracy of the UE location estimation.

[0088] FIG. 7 illustrates another simplified environment (700) and exemplary technique for determining the location of a UE (104) using the Time Difference of Arrival (TDOA) from a plurality of base stations (102-1, 102-2, 102-3) (sometimes collectively referred to as base station (102)). Although three base stations are shown in FIG. 7, embodiments may utilize additional gNBs.

[0089] In the example of FIG. 7, the UE (104) may determine an estimate of its position or assist other entities (e.g., base stations or core network components, other UEs, location servers, third-party applications, etc.) in determining an estimate of its position. The UE (104) may communicate wirelessly with multiple base stations (102-1, 102-2, and 102-3) (collectively, base stations (102)) that may correspond to any combination of base stations (102) of FIG. 1, using standardized protocols for the exchange of RF signals, the modulation of RF signals, and information packets. By extracting different types of information from the exchanged RF signals and utilizing the layout of the wireless communication system (700) (i.e., locations of base stations, geometry, etc.), the UE (104) may determine its position or assist in determining its position in a predefined reference coordinate system. In an embodiment, the UE (104) may specify its location using a two-dimensional coordinate system; however, the embodiments disclosed herein are not so limited and may also be applicable to determining locations using a three-dimensional coordinate system if additional dimensions are desired. Additionally, FIG. 7 illustrates one UE (104) and three base stations (102), but as will be recognized, there may be more UEs (104) and more or fewer base stations (102).

[0090] To support location estimation, base stations (102) may be configured to broadcast reference RF signals (e.g., PRS, CRS, CSI-RS, synchronization signals, etc.) to UEs (104) in their coverage area so that UEs (104) can measure the characteristics of these reference RF signals. For example, UEs (104) may use a TDOA positioning method, which is a multilateration method in which UEs measure the Time of Arrival (TOA) of specific reference RF signals (e.g., PRS, CRS, CSI-RS, etc.) transmitted by different pairs of network nodes (e.g., base stations (102), antennas of base stations (102), etc.). The TOA from several neighboring base stations can be subtracted from the TOA from the reference base station to determine the RSTD for the pair of base stations.

[0091] Generally, RSTDs are measured between a reference network node and one or more neighbor network nodes. In the example illustrated in FIG. 7, base station (102-1) may serve as a serving base station for UE (104) or act as a reference base station, while base stations (102-2 and 102-3) act as neighbor base stations. The reference network node remains the same for all RSTDs measured by UE (104) for any single positioning use of TDOA and will typically correspond to a serving cell for UE (104) or another nearby cell having good signal strength in UE (104). In an embodiment, if the measured network node is a cell supported by a base station, the neighbor network nodes will typically be cells supported by base stations different from the base station for the reference cell and may have good or poor signal strength in UE (104). RSTD may be the relative timing difference between two conventional cells, for example, a reference cell and an adjacent cell, which is determined based on the smallest time difference between two subframe boundaries from two different cells.

[0092] RSTD is the time difference between a neighboring base station (102-i) and a reference base station (102-1) measured at the UE (104). RSTD measurements are defined as the time difference between two base stations (modulo 1-subframe (1-ms)) and thus may correspond to range differences between a neighboring base station (102-i) and a reference base station (102-1). At least two neighboring base station measurements (i) are required, but three or more neighboring base station measurements are preferred, and the system of equations can be solved using least squares or weighted least squares methods. The transmit time offset (Ti-T1) from the transmitting base station must be (ideally) 0 in a synchronized network or considered in an asynchronous network so that RSTD defines the TDOA (Time to Arrival Difference). Geometrically, each TDOA defines a hyperbola (702 and 704), where the width of the hyperbola is determined by the TDOA errors (ni-n1) or uncertainty, as illustrated by the dashed line in FIG. 7. If the base station (102) coordinates and transmission time offsets (Ti-T1) are known at the location server (172) (e.g., LMF (270)) or at the UE (104), the position of the UE (104) may be determined. The uncertainty of the base station (102) coordinates or TDOA measurements will have a direct impact on the accuracy of the UE location estimation.

[0093] FIG. 8a illustrates another simplified environment (800) and exemplary technique for determining the position of a UE (104) using the DL AoA or DL ​​AoD of a beam (802). FIG. 8a illustrates the measurement of the AoA or AoD of a signal (402) including uncertainty (803). In the example of FIG. 8a, a base station (102) (e.g., any base station described herein) transmits a DL reference signal, such as a PRS, to the UE (104). The base station (102) transmits the signal through a plurality of transmit beams using a directional antenna that is received by the UE (104). The UE (104) can measure the angle of arrival (AoA) of the signal (802) using a directional antenna capable of generating a plurality of receive beams. For example, each of the receiving beams will result in different received signal strengths (e.g., RSRP, RSRQ, SINR, etc.) of one or more reference signals at the UE (104). Additionally, the channel impulse response of one or more reference signals will be smaller for receiving beams further from the actual LOS path between the base station (102) and the UE (104) than for receiving beams closer to the LOS path. Likewise, the received signal strength will be lower for receiving beams further from the LOS path than for receiving beams closer to the LOS path. In this way, the UE (104) can identify the receiving beam that results in the highest received signal strength and the strongest channel impulse response, and can estimate the angle from itself to the base station (102) as the AoA of that receiving beam (802).For example, the receiving antenna of the UE (104) has a known relationship with the coordinate system of the UE (104), and the UE (104) can measure the relationship with the coordinate system, for example, a global coordinate system (GCS) or a local coordinate system (LCS), using a sensor such as a magnetometer, accelerometer, gyroscope, camera, etc., in which the angle of arrival for the receiving antenna of the UE (104) can be converted to the GCS or LCS.

[0094] Additionally or alternatively, the AoD may be determined by a UE (104) identifying the transmission beam received with the highest received signal strength and the strongest channel impulse response. The AoD of each transmission beam from the base station (102) in relation to the GCS or LCS is known and may be provided to the UE (104) as supporting data for, for example, UE-based positioning or provided to a location server for UE-supported positioning. Thus, the AoD of the reference signal received by the UE (104) can be determined.

[0095] The UE (104) can also estimate the distance D between itself and the base station (102) by performing, for example, an RTT positioning procedure or RSRP with the base station (102), or timing advance measurements. The timing advance is typically the RTT between the base station and the UE, or twice the propagation time in one direction, and thus can be used to estimate the distance between the base station (802) and the UE (804) in the same way as the actual RTT procedure.

[0096] Based on the angle between the base station (102) and the UE (104) (based on AoA or AoD), knowledge of the distance D from the UE (104) to the base station (102), and the known geographical location of the base station (102), the location of the UE (104) can be estimated.

[0097] FIG. 8b illustrates another simplified environment (850) for performing AoA or AoD position determination with base stations (102-1 and 102-2). The AoA or AoD of each signal (851 and 852) can be determined as discussed in FIG. 8a. As illustrated, the AoA or AoD measurements (851 and 852) determined by each UE (104) intersect at the position of the UE (104). Thus, the position of the UE (104) can be determined based on the AoA or AoD measurements without the need for distance measurement.

[0098] In general, wireless communication systems are vulnerable to various security issues. In some cases, potential security risks may arise, particularly when wireless information and / or location-based services are provided in public forums (e.g., shopping malls, office buildings, etc.), as malicious entities may exploit the network to gain unauthorized access to sensitive information. These security risks may include cyberattacks of the "man-in-the-middle," "spoofing," and / or "phishing" types. These attacks can be based on malicious entities successfully impersonating legitimate entities by manipulating network protocols, forging credentials, and / or compromising network integrity to deceive users and gain illicit benefits.

[0099] For example, a UE can be used to relay data to other UEs in sidelink channels and coverage enhancement applications. However, relaying data between UEs raises concerns regarding man-in-the-middle and replay attacks. For example, these attacks can be performed when the physical layer is used to authenticate transmitters. By using channel characteristics and prediction techniques to measure downlink reference signals over time, such as positioning measurements or channel parameter measurements, a UE can use the physical layer to determine whether received downlink transmitters are most likely from a genuine transmitter.

[0100] For example, FIG. 9 illustrates an environment (900) in which a replay attack or a man-in-the-middle attack may be performed by an attack device (912). As illustrated, a base station (102) and a UE (104) may participate in wireless communication in which a DL signal (902) is transmitted by the base station (102) and received by the UE (104). The UE (104) may respond to the base station (102) with a UL signal (904).

[0101] At some point during wireless communication, the attack device (912) may receive DL signals (914) from the base station (102) and relay these signals (914) to the UE (104). For example, the attack device (912) may relay the DL signals (914) so ​​that the UE (104) does not recognize that the DL signals (914) are being relayed from the attack device (912) rather than being transmitted directly from the base station (102). The attack device (912) may also decode the intercepted signals (914). As a result, the DL signal (914) intended for the UE (104) is intercepted by the attack device (912) and relayed to the UE (104), so that neither the base station (102) nor the UE (104) realizes that the attack device (912) is intercepting the wireless communication intended for the UE (104).

[0102] In one implementation, the integrity and authentication of the connection between the UE (104) and the base station (102) may be maintained based on a comparison of the predicted value of one or more physical layer measurements and the actual value of one or more physical layer measurements, from which the presence of unauthorized interfering entities may be detected. For example, the physical layer measurements may be positioning measurements of downlink reference signals such as RSRP, Rx-Tx, TOA, RTT, AoD, AoA, etc., as well as velocity, direction of movement, or channel parameters. For example, the predicted value of one or more positioning measurements of downlink reference signals may be based on one or more previous positioning measurements of downlink reference signals received from the base station (102) to which the UE (104) is connected. By comparing the predicted positioning measurements based on previous measurements with the current positioning measurements, it is possible to determine whether transmissions originate from the same base station over time. The UE (104) may report to a base station or server when the UE (104) determines that an intervening entity may be present in the communication channel, or may provide periodic reports indicating, for example, whether an intervening entity has been detected.

[0103] FIG. 9b is a graph (950) showing a number of expected positioning measurements (960) and current positioning measurements (970) that can be compared to identify the presence of the attack device (912) in FIG. 9a as an example. The expected positioning measurements (960) are generated based on a number of previous positioning measurements performed by the UE (104) and provided by the base station (102) or location server (172). The expected positioning measurements are periodically transmitted to the UE (104) as shown in FIG. 9b by the expected positioning measurements transmitted at times (t2, t3, t4, t5). A downlink reference signal, which is measured by the UE (104) and compared with the expected positioning measurements, is transmitted by the base station within a limited time period from the transmission of the expected positioning measurements so that the expected positioning measurements and the actual positioning measurements are correlated. For example, immediately after the expected positioning measurement is transmitted at time t2, the base station (102) must transmit a downlink reference signal measured by the UE (104) and perform the positioning measurement shown in FIG. 9b that is aligned at time t2.

[0104] For the comparison to be valid, the downlink reference signal measured by the UE (104) must be transmitted close in time to the transmission of the expected positioning measurement. The larger the time period between the transmission of the expected positioning measurement and the downlink reference signal, the larger the possible error between the expected positioning measurement and the actual positioning measurement. In some implementations, an acceptable error may be provided with the expected positioning measurement. In some implementations, the acceptable error may be dynamic and may depend on the amount of time between receiving (or transmitting) the expected positioning measurement and receiving (or transmitting) the downlink reference signal measured for the actual positioning measurement, for example, the amount of time increases with an increase in the acceptable error.

[0105] The expected and actual positioning measurements (960 and 970), simply illustrated as bars in FIG. 9b, may be for RSRP values, RSTD values ​​and / or uncertainty, AoA values ​​and / or uncertainty, AoD values ​​and / or uncertainty, RTT, etc. Each expected positioning measurement (960) may be generated based on a plurality of previous positioning measurements (e.g., three or more) reported by the UE (104) after using upper-layer initial authentication to authenticate the connection between the UE (104) and the base station (102). For example, as indicated by the dots, the UE (104) may acquire positioning measurements (970) over a time period (including time t1) that may be provided to the base station (102) or the location server (172). A base station (102) or a location server (172) may use previous positioning measurements to generate an expected positioning measurement for a future time, e.g., time t2. The expected positioning measurement may be determined as the average (or other statistical combination) of the previous positioning measurements. In some implementations, a weighted average may be used, for example, in which the more recent measurement has a greater weight than the less recent measurement.

[0106] As illustrated in FIG. 9b, the expected positioning measurement (960) at times t2 and t3 is nearly identical to the actual positioning measurement (970) at those times. For example, referring to FIG. 9a, since the expected positioning measurement (960) at times t2 and t3 is nearly identical to the actual positioning measurement (970) at those times, it can be determined that the UE (104) at times t2 and t3 received a downlink reference signal directly from the base station (102), for example, from the DL signal (902). While there may be a change in the relative position between the UE (104) and the base station (102), for example, if the UE (104) is moving, the use of multiple previous positioning measurements from the UE (104) to generate the expected positioning measurements (960) at each time t1, t2, and t3 allows the change in position over time to be included in the expected positioning measurements (960).

[0107] As illustrated in FIG. 9b, the expected positioning measurement (960) at time t4 is approximately the same as the expected positioning measurement (960) at time t3, but the actual measured positioning measurement (970) is significantly increased. The difference between the expected positioning measurement (960) at time t4 and the actual positioning measurement (970) at time t4 may be greater than an allowable error determined by the UE (104) based on a predetermined threshold, for example, the amount of time between receiving the expected positioning measurement (960) and / or receiving the downlink reference signal. Accordingly, a comparison of the expected positioning measurement (960) at time t4 and the actual positioning measurement (970) at that time may indicate that the downlink reference signal transmitted at time t4 (or immediately thereafter) is not from the same entity that transmitted the downlink reference signal at previous times, e.g., times t1, t2, or t3. For example, referring again to FIG. 9a, the discrepancy between the expected positioning measurement (960) at time t4 and the actual positioning measurement (970) at that time may indicate that the actual positioning measurement (970) was measured from a reference signal from the attack device (912), e.g., a signal (914) from the attack device (912).

[0108] If the actual positioning measurement deviates from the expected value by, for example, more than an acceptable error, the UE (104) may report an indication that an attack device may be present in the communication channel between the UE (104) and the base station (102). For example, the UE (104) may report a "warning flag" indicating that an interfering entity may be present. Additionally or alternatively, the UE (104) may report the actual positioning measurement that the base station (102) or the location server (172) can use to determine or verify the presence of an attack device. For example, the UE (104) may report the actual positioning measurement even if, for example, the UE (104) is performing UE-based positioning measurements.

[0109] Accordingly, in some implementations, referring to FIG. 9a, one or more expected values ​​of DL PRS RSRP (e.g., expected RSRP) may be provided to the UE (104) to determine whether a new measurement of resource RSRP is within an acceptable error, to indicate whether the DL transmission is from an authenticated base station (102), or to indicate that the DL transmission is from an attack device (912).

[0110] In some implementations, a set of expected RSTD values ​​and / or expected RSTD uncertainties may be provided to the UE (104) in addition to the expected RSTD values ​​and uncertainties provided in the positioning support data as an RSTD search window during the positioning session. In some implementations, an extended RSTD search window is provided to the UE (104), so that when the UE (104) measures the RSTD, if the measurement is outside the extension of the RSTD search window or outside the expected RSTD values ​​and uncertainties, the UE (104) may determine that an attack device is present and, for example, even when the UE (104) is in a Ue-based positioning mode, transmit a corresponding report indicating the presence of the attack device, for example, as a "warning flag" or the measured RSTD value.

[0111] In some implementations, the expected AoD and / or expected AoD-uncertainty for the zenith angle or azimuth angle may be provided to the UE (104) (e.g., as supporting data) with an acceptable error in some implementations. If the measured AoD is outside this range, the UE (104) may determine that an attack device is present and may send a corresponding report indicating the presence of the attack device to the base station (102) or location server (172), for example, as a "warning flag."

[0112] In some implementations, the estimated TOA and / or RTT values ​​may be provided to the UE (104) with an acceptable error in some implementations. If the measured TOA or RTT value is outside this range, the UE (104) may determine that an attack device is present and may send a corresponding report indicating the presence of the attack device, for example as a "warning flag," to the base station (102) or location server (172).

[0113] Additionally, in some implementations, expected or predicted speed, direction, channel parameters, or any combination thereof may be provided to the UE (104). For example, channel parameters may be used to predict some channel coefficients that can be used to indicate whether the current channel after a time offset from the previous transmission corresponds to the channel estimated from the previous transmission. A discrepancy between the predicted channel coefficients and the measured channel coefficients may be used to indicate the presence of an attack device. Similarly, a discrepancy between the UE (104)'s predicted and actual speed or direction of movement may be used to indicate the presence of an attack device, which may be reported later.

[0114] FIG. 10 illustrates examples of predicted measurements received for positioning measurements and predicted measurements for security as examples. The predicted measurement for positioning measurements is illustrated as an expected RSTD search window (1002) that can be received from positioning support data, and the predicted measurement for security is illustrated as a security RSTD search window (1004). A UE (104) may receive a security RSTD search window (1004) in addition to the positioning RSTD search window (1002). An additional security RSTD search window (1004) may be defined for the positioning RSTD search window (1002) for each PRS pair. For example, the security RSTD search window (1004) may be larger than the positioning RSTD search window (1002) and may be extended by, for example, 1 μs on both sides. The security RSTD search window (1004) may be defined based on the center of the positioning RSTD search window (1002) or may be defined as an extension (1006) that defines the security RSTD search window (1004) when combined with the positioning RSTD search window (1002). Similar windows may also be used for TOA, AOD, and speed measurement.

[0115] Similarly, the location server (172) may provide the base station (102) (e.g., serving base station and / or neighboring base station) with the expected or predicted value of the physical layer measurement (e.g., UL-AoA, RTOA) being performed by the base station via NRPPa signaling. If the base station (102) performs a measurement outside the configured window, the base station (102) may provide the location server (172) and / or UE (104) with an indication such as a "warning" message or a report of the measurement value.

[0116] The number of predicted values ​​for a positioning measurement may be an LPP / RRC / MAC-CE / DCI configuration parameter configured as part of the reporting configuration. Furthermore, a timestamp, or simply the time at which the current measurement is used for a given prediction, may be provided to the UE (104) via LPP / RRC / MAC-CE signaling and used by the UE (104) to determine whether the predicted positioning measurement is properly correlated with the current positioning measurement and / or to adjust for an acceptable error for comparison between the predicted positioning measurement and the actual positioning measurement.

[0117] FIG. 11 is a message flow (1100) illustrating messaging in a wireless network for authenticating a connection between a UE and a base station and identifying the presence of an interfering device between the UE and the base station that may be performing active attacks, such as a man-in-the-middle or replay attack. For example, the message flow (1100) illustrates signaling between a UE (104), a base station (102), and a location server (172) as discussed herein. While messages related to the detection of an attacking device (912) are illustrated, it should be understood that additional messages including conventional messages may also be used in the message flow (1100).

[0118] In step (1102), the base station (102) may transmit a reference signal, such as a PRS signal, to the UE (104) after the upper layer initial authentication is performed. It should be understood that the reference signal is not limited to PRS and may be other types of reference signals, such as CRS, PSS, SSS, etc.

[0119] In step (1103), the UE (104) may perform one or more measurements on the received reference signals, such as RSRP, RSTD, TOA, AoA, RTT, etc. Other measurements may include speed, direction of movement, or channel parameters. It should be understood that some measurements may require additional signaling not shown in FIG. 11, such as a PRS signal transmitted from the second base station for RSTD measurements, or a UL signal transmitted from the UE (104) to the base station (102) for RTT measurements.

[0120] In step (1104), the measurement value generated in step (1103) may be transmitted to a base station (102) that can transmit the measurement value to a location server (172) in some implementations.

[0121] As exemplified by steps (1106, 1107, 1108), the process of receiving a reference signal, performing one or more positioning measurements on the reference signal, and transmitting the measurements to a base station (102) and / or a location server (172) may be performed multiple times.

[0122] In step (1110), the location server (172) may generate a predicted measurement for the UE (104) for a reference signal transmitted by the base station (102) based on a plurality of measurements received from the UE (104) in steps (1104 and 1108), for example. The predicted measurement may be generated based on a plurality of previous positioning measurements, for example, based on the average (or other statistical combination) of the previous positioning measurements. In some implementations, a weighted average may be used, for example, in which more recent measurements have a greater weight than less recent measurements. In some implementations, the predicted measurement (1110) may be generated by the base station (102) instead of the location server (172). The predicted measurement may contain uncertainty or an acceptable error.

[0123] In step 1112, the location server (172) (or base station (102)) may transmit the predicted measurement value to the UE (104). A timestamp may be provided along with the predicted measurement value. It should be understood that the predicted measurement value transmitted to the UE (104) is for security purposes as opposed to the positioning measurement, and therefore may be transmitted in addition to the predicted value transmitted from the positioning support data during the positioning session as discussed in FIG. 10.

[0124] In step (1114), the base station (102) may transmit other reference signals, such as a PRS signal, to the UE (104). The reference signal transmitted in step (1114) should be transmitted close in time to the predicted measurement value received in step (1112), for example, so that the predicted measurement value correlates with the measurement performed on the reference signal in step (1114).

[0125] In step (1115), the UE (104) may perform one or more measurements on a received reference signal, such as RSRP, RSTD, TOA, AoA, RTT, speed, direction of travel, or channel parameters, similar to step (1103).

[0126] In step 1116, the UE (104) can compare the predicted measurement value with the actual measurement value obtained in step 1115. For example, the UE (104) can compare the predicted measurement value and the actual measurement value to determine whether the actual measurement value is within a predetermined threshold for the predicted measurement value. The predetermined threshold may be, for example, an uncertainty or acceptable error that may be received with the predicted measurement value in step 1116. In some implementations, the acceptable error may be based at least partially on the time elapsed between the predicted measurement value (e.g., a timestamp included with the predicted measurement value) and the reception of the reference signal at stage (114). Assuming that the predicted measurement value and the actual measurement value match within the predetermined threshold, the reference signal transmitted in step (1114) may be considered authenticated and may be considered to have originated from the base station (102).

[0127] In step (1118), the measurement value generated in step (1115) may be transmitted to a base station (102) that can transmit the measurement value to a location server (172) in some implementations.

[0128] In step (1120), the location server (172) can generate a predicted measurement value for the UE (104) for a reference signal transmitted by the base station (102) based on a plurality of measurement values ​​received from the UE (104) in steps (1104 and 1108 and 1118), similar to step (1110).

[0129] In step 1122, the location server (172) (or base station (102)) may transmit the predicted measurement value to the UE (104). A timestamp may be provided along with the predicted measurement value.

[0130] In step (1124), a reference signal, such as a PRS signal, is transmitted to the UE (104) by the attack device (912). For example, the reference signal may be received by the attack device (912) from the base station (102) and transmitted to the UE (104).

[0131] In step (1125), the UE (104) can perform one or more measurements on a received reference signal, such as RSRP, RSTD, TOA, AoA, RTT, etc., similar to step (1103).

[0132] In step 1126, the UE (104) can compare the predicted measurement value, similar to step (1116), with the actual measurement value obtained in step 1125. Since the reference signal received in step (1124) comes from a different entity than the base station (102), the predicted measurement value received in step (1122) (based on the measurement of the reference signal from the base station (102)) will not match the actual measurement value of the reference signal received from the attack device (912) in step 1124. For example, the attack device (912) is not located at exactly the same location as the base station (102), and therefore the positioning measurement for the signal transmitted by the attack device (912) will differ from the predicted positioning measurement for the signal transmitted by the base station (102). Additionally, the difference in location between the attack device (912) and the base station (102) will be perceived as a sudden change in speed by the UE (104) (e.g., the UE (104) will appear to be moving an increased distance over time), and the direction of movement may differ, and accordingly, the speed or direction of movement will differ from the expected speed or direction of movement. Furthermore, because the attack device (912) is different, channel parameters such as the channel coefficient for the attack device (912) will differ from those predicted for the base station (102). Therefore, the comparison between the predicted measurement and the actual measurement will not match within a predetermined threshold, which indicates that the reference signal received in step (1124) is not from the base station (102) and is therefore not authenticated.

[0133] In step (1128), the UE (104) can transmit indications of the detected attack, such as a warning flag and / or measurement value, to the base station (102) and / or location server (172).

[0134] FIG. 12 illustrates a schematic block diagram illustrating specific exemplary features of a UE (1200) that may be the UE (104) of FIG. 1, configured to support, for example, authentication of a connection with a base station and identification of the presence of an intervening device between the UE and the base station as described herein. The UE (1200) may perform the message flow illustrated in FIG. 11 and the process flow (1400) illustrated in FIG. 14, and the supporting algorithms discussed herein. The UE (1200) may include, for example, one or more processors (1202), memory (1204), an external interface (e.g., a wireless network interface) such as at least one wireless transceiver exemplified as a WWAN transceiver (1210) and a WLAN transceiver (1212), a satellite positioning system (SPS) receiver (1215), and one or more sensors (1213), which may be operably coupled with one or more connections (1206) (e.g., buses, lines, fibers, links, etc.) to a non-transient computer-readable medium (1220) and memory (1204). The SPS receiver (1215) may, for example, receive and process SPS signals from a satellite vehicle (SV). One or more sensors (1213) may be an inertial measurement unit (IMU) that may include, for example, one or more accelerometers, one or more gyroscopes, a magnetometer, etc. The UE (1200) may additionally include additional items not illustrated, such as a user interface that may include, for example, a display, a keypad, or other input device with which a user may interface with the UE, such as a virtual keypad on the display. In certain exemplary implementations, all or part of the UE (1200) may take the form of a chipset, etc.

[0135] The UE (1200) may include at least one wireless transceiver, such as a transceiver (1210) for a WWAN communication system and a transceiver (1212) for a WLAN communication system, or a combined transceiver for both WWAN and WLAN. The WWAN transceiver (1210) may include a transmitter (1210t) and a receiver (1210r) coupled to one or more antennas (1211) to transmit wireless signals (e.g., on one or more uplink channels and / or one or more sidelink channels) and / or receive (e.g., on one or more downlink channels and / or one or more sidelink channels) and to convert signals from wireless signals to wired (e.g., electrical and / or optical) signals and from wired (e.g., electrical and / or optical) signals to wireless signals. A WLAN transceiver (1212) may include a transmitter (1212t) and a receiver (1212r) coupled to one or more antennas (1211) or separate antennas to transmit and / or receive wireless signals (e.g., on one or more uplink channels and / or one or more sidelink channels) and to convert signals from wireless signals to wired (e.g., electrical and / or optical) signals and from wired (e.g., electrical and / or optical) signals to wireless signals. The transmitters (1210t and 1212t) may include multiple transmitters which may be separate components or combined / integrated components, and / or the receivers (1210r and 1212r) may include multiple receivers which may be separate components or combined / integrated components.The WWAN transceiver (1210) may be configured to communicate signals (e.g., with base stations and / or one or more other devices) according to various radio access technologies (RATs) such as 12G New Radio (NR), GSM (Global System for Mobiles), UMTS (Universal Mobile Telecommunications System), AMPS (Advanced Mobile Phone System), CDMA (Code Division Multiple Access), WCDMA (Wideband CDMA), LTE (Long-Term Evolution), LTE Direct (LTE-D), 3GPP LTE-V2X (PC5). The New Radio may use mm wave frequencies and / or sub-6 GHz frequencies. The WLAN transceiver (1212) may be configured to communicate signals (e.g., with access points and / or one or more other devices) according to various wireless access technologies (RATs) such as 3GPP LTE-V2X (PC5), IEEE 1202.11 (including IEEE 1202.11p), WiFi, WiFi Direct (WiFi-D), Bluetooth®, Zigbee, etc. The transceivers (1210 and 1212) may be communicateably coupled to a transceiver interface by optical and / or electrical connections, which may be at least partially integrated with the transceivers (1210 and 1212).

[0136] In some embodiments, the UE (1200) may include an antenna (1211) that may be located internally or externally. The UE antenna (1211) may be used to transmit and / or receive signals processed by wireless transceivers (1210 and 1212). The antenna (1211) may include an antenna array that, for example, may be capable of receiving beamforming by adjusting the phase setting of the array of antennas in a specific direction to amplify RF signals received from that direction (e.g., by increasing the gain level of the RF signals) and / or by increasing the gain setting. The antenna (1211) may further include a plurality of antenna panels, each of which is capable of beamforming. The antenna (1211) may be capable of selecting one or more antennas to control adaptation, for example, receiving beams transmitted from a base station. For example, to reduce power consumption, for the reception of a wide-angle beam, for example, a reduced number of beams or a single beam may be selected, while for the transmission beam, an increased number of antennas of the antenna array may be selected. In some embodiments, the UE antenna (1211) may be coupled to radio transceivers (1210 and 1212). In some embodiments, measurements of signals received (transmitted) by the UE (1200) may be performed at the connection point of the UE antenna (1211) and the radio transceivers (1210 and 1212). For example, the measurement point of the reference for the received (transmitted) RF signal measurements may be the input (output) terminal of the receiver (1210r) (transmitter (1210t)) and the output (input) terminal of the UE antenna (1211). In a UE (1200) having multiple UE antennas (1211) or antenna arrays, the antenna connector may be shown as a virtual point representing the aggregated output (input) of multiple UE antennas.In some embodiments, the UE (1200) may measure received signals including signal strength and TOA measurements, and angle-related measurements and raw measurements for the DL PRS and / or SL PRS may be processed by one or more processors (1202).

[0137] One or more processors (1202) may be implemented using a combination of hardware, firmware, and software. For example, one or more processors (1202) may be configured to perform the functions discussed herein by implementing one or more instructions or program code (1208) on a non-transient computer-readable medium such as a medium (1220) and / or memory (1204). In some embodiments, one or more processors (1202) may represent one or more circuits configurable to perform at least part of a data signal computing procedure or process related to the operation of the UE (1200).

[0138] The medium (1220) and / or memory (1204) may store instructions or program code (1208) including executable code or software instructions that, when executed by one or more processors (1202), cause one or more processors (1202) to operate as a special-purpose computer programmed to perform the techniques disclosed herein. As exemplified in the UE (1200), the medium (1220) and / or memory (1204) may include one or more components or modules that may be implemented by one or more processors (1202) to perform the methodologies described herein. While the components or modules are exemplified as software in the medium (1220) executable by one or more processors (1202), it should be understood that the components or modules may be stored in memory (1204) or may be dedicated hardware located within or away from one or more processors (1202).

[0139] A number of software modules and data tables may reside in the medium (1220) and / or memory (1204) and may be utilized by one or more processors (1202) to manage both the communications and functionalities described herein. It should be understood that the organization of the contents of the medium (1220) and / or memory (1204) as shown in the UE (1200) is merely exemplary, and that the functionality of the modules and / or data structures may be combined, separated, and / or structured in different ways depending on the implementation of the UE (1200).

[0140] When the medium (1220) and / or memory (1204) is implemented by one or more processors (1202), it may include a prediction value module (1222) configured to receive one or more predicted values ​​for one or more measurements of a downlink reference signal based on a measurement of a previous downlink reference signal received from a base station via a wireless transceiver (1210). For example, the predicted values ​​for one or more measurements may include a security set of predicted values ​​for one or more measurements to determine whether an attack device has transmitted a supporting data set of predicted values ​​for one or more measurements to determine whether it is used to perform the received downlink reference signals and one or more measurements of the received downlink reference signals. The predicted values ​​may be predicted positioning measurements such as one or more predicted RSRP values; RSTD values, predicted RSTD uncertainties, or combinations thereof; predicted AoA values, predicted AoA uncertainties, or combinations thereof; predicted RTT values, etc. The predicted value may be at least one of one or more predicted channel coefficients, speeds, directions, or combinations thereof for a pair of Tx-Rx antennas or antenna ports. One or more processors (1202) may also be configured to receive one or more timestamps associated with predicted values ​​for one or more measurements of downlink reference signals via a wireless transceiver (1210).

[0141] When the medium (1220) and / or memory (1204) is implemented by one or more processors (1202), it may include a reference signal module (1224) that configures one or more processors (1202) to receive a downlink reference signal, such as a PRS, via a wireless transceiver (1210). The downlink reference signal may be received from an authenticated base station, such as a base station (102), or from an intervening device, such as an attack device (912).

[0142] When the medium (1220) and / or memory (1204) is implemented by one or more processors (1202), it may include a measurement module (1226) configured to measure a received downlink reference signal. For example, one or more processors (1202) may be configured to perform measurements of positioning measurements such as RSRP, RSTD, AOA, RTT, as well as channel counts, speed, direction of movement, or a combination thereof.

[0143] When the medium (1220) and / or memory (1204) is implemented by one or more processors (1202), it may include a comparison module (1228) configured to configure one or more processors (1202) to determine whether an attack device has transmitted a received downlink reference signal based on one or more predicted values ​​for one or more measurements of a downlink reference signal and one or more measurements of a downlink reference signal by comparing a measurement for a current downlink reference signal with a predicted value for a downlink reference signal, for example. One or more processors (1202) may be configured to determine whether the difference between the predicted measurement and the actual measurement is within an acceptable error that can be provided to the UE along with the predicted value, or determined by one or more processors (1202) based on a timestamp associated with the predicted value and the time of receiving the current downlink reference signal. One or more processors (1202) may be configured to compare predicted values ​​with actual values ​​for positioning measurements such as RSRP, RSTD, AOA, RTT, as well as channel count, speed, direction of movement, or a combination thereof.

[0144] The medium (1220) and / or memory (1204) may include a reporting module (1230) configured to transmit a report to a base station indicating the presence of an attack device in the connection between the UE and the base station when the medium (1220) and / or memory (1204) is implemented by one or more processors (1202) and, through a transceiver (1210), a received downlink reference signal is determined to have been transmitted by an attack device. For example, the UE may transmit the report to either a base station or a location server.

[0145] The methodologies described herein may be implemented by various means depending on the application. For example, these methodologies may be implemented in hardware, firmware, software, or any combination thereof. For hardware implementation, one or more processors (1202) may be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described herein, or a combination thereof.

[0146] In firmware and / or software implementations, methodologies may be implemented as modules (e.g., procedures, functions, etc.) that perform the functions described herein. Any machine-readable medium containing instructions as types may be used to implement the methodologies described herein. For example, software code may be stored in a non-transient computer-readable medium (1220) or memory (1204) connected to and executed by one or more processors (1202). Memory may be implemented within one or more processors or outside of one or more processors. As used herein, the term “memory” refers to any type of long-term, short-term, volatile, non-volatile, or other memory, and is not limited to any specific type of memory, the number of memories, or the type of medium in which the memory is stored.

[0147] Where implemented in firmware and / or software, functions may be stored as one or more instructions or program code (1208) on a non-transient computer-readable medium, such as a medium (1220) and / or memory (1204). Examples include computer-readable media encoded in a data structure and computer-readable media encoded in a computer program (1208). For example, a non-transient computer-readable medium containing stored program code (1208) may include program code (1208) to support authentication of a connection with a base station and identification of the presence of an intervening device between the UE and the base station, as described herein in a manner consistent with the disclosed embodiments. The non-transient computer-readable medium (1220) includes physical computer storage media. The storage medium may be any available medium accessible by a computer. As an example, not a limitation, such non-transient computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store the desired program code (1208) in the form of instructions or data structures that can be accessed by a computer; as used herein, disk and disc include compact discs (CD), laser discs, optical discs, digital multifunction discs (DVD), floppy discs and Blu-ray discs, wherein disks usually reproduce data magnetically, while discs reproduce data optically with a laser. Also, the above combinations should be included within the scope of computer-readable media.

[0148] In addition to storage on a computer-readable medium (1220), instructions and / or data may be provided as signals on transmission media included in a communication device. For example, the communication device may include a wireless transceiver (1210) having signals indicating instructions and data. Instructions and data are configured to enable one or more processors to implement the functions outlined in the claims. That is, the communication device includes a transmission medium having signals indicating information for performing the disclosed functions.

[0149] Memory (1204) may represent any data storage mechanism. Memory (1204) may include, for example, main memory and / or secondary memory. Primary memory may include, for example, random access memory, read-only memory, etc. Although shown in this example as being separate from one or more processors (1202), all or part of the primary memory may be provided within one or more processors (1202) or otherwise located / connected with them. Secondary memory may include, for example, memory of the same or similar type as the primary memory and / or one or more data storage devices or systems, such as, for example, a disk drive, an optical disk drive, a tape drive, a solid-state memory drive, etc.

[0150] In certain embodiments, secondary memory may operatively accommodate a non-transient computer-readable medium (1220) or otherwise be configurable to be coupled thereto. As such, in certain exemplary embodiments, the methods and / or apparatuses set forth herein may take the form of all or part of a computer-readable medium (1220) which may include stored computer-implementable code (1208) that may be operatively enabled to perform all or part of the exemplary operations as described herein when executed by one or more processors (1202). The computer-readable medium (1220) may be part of memory (1204).

[0151] FIG. 13 illustrates a schematic block diagram illustrating certain exemplary features of a network entity (1300) illustrated in FIG. 1, e.g., a base station (102) or a location server (172), e.g., configured to support authentication of a connection between a UE and a base station and identification of the presence of an intervening device between a UE and a base station, as discussed herein. The network entity (1300) may perform the signaling flow illustrated in FIG. 11 and the process flow (1500) illustrated in FIG. 15 and the algorithms discussed herein. The network entity (1300) may include, for example, one or more processors (1302), memory (1304), and external interfaces (1310) (for example, a wired or wireless network interface to a base station and / or entity of the core network if the network entity (1300) is a location server, or a wired or wireless network interface to a location server and / or other entity of the core network if the network entity (1300) is a base station), which may be operably coupled to a non-transient computer-readable medium (1320) and memory (1304) using one or more connections (1306) (e.g., a bus, line, fiber, link, etc.). In certain exemplary implementations, all or part of the network entity (1300) may take the form of a chipset, etc.

[0152] One or more processors (1302) may be implemented using a combination of hardware, firmware, and software. For example, one or more processors (1302) may be configured to perform the functions discussed herein by implementing one or more instructions or program code (1308) on a non-transient computer-readable medium such as a medium (1320) and / or memory (1304). In some embodiments, one or more processors (1302) may represent one or more circuits configurable to perform at least part of a data signal computing procedure or process related to the operation of a network entity (1300).

[0153] The medium (1320) and / or memory (1304) may store instructions or program code (1308) including executable code or software instructions that, when executed by one or more processors (1302), cause one or more processors (1302) to operate as a special-purpose computer programmed to perform the techniques disclosed herein. As exemplified in the network entity (1300), the medium (1320) and / or memory (1304) may include one or more components or modules that may be implemented by one or more processors (1302) to perform the methods described herein. Although the components or modules are exemplified as software in the medium (1320) executable by one or more processors (1302), the components or modules may be stored in memory (1304) or may be dedicated hardware located in or away from one or more processors (1302).

[0154] A number of software modules and data tables may reside in the medium (1320) and / or memory (1304) and may be utilized by one or more processors (1302) to manage both the communications and functionalities described herein. It should be noted that the organization of the contents of the medium (1320) and / or memory (1304) as illustrated in the network entity (1300) is merely exemplary, and therefore the functionality of the modules and / or data structures may be combined, separated, and / or structured in different ways depending on the implementation of the network entity (1300).

[0155] When the medium (1320) and / or memory (1304) is implemented by one or more processors (1302), it may include a prediction value module (1322) configured to obtain one or more predicted values ​​for one or more measurements of a downlink reference signal to be performed by the UE based on previous measurements of a downlink reference signal received by the UE from a base station. For example, one or more predicted values ​​may include a security set of predicted values ​​for one or more measurements to determine whether an attack device has transmitted a supporting data set of predicted values ​​for one or more measurements to determine whether the received downlink reference signals and one or more measurements of the received downlink reference signals are used to perform. One or more processors (1302) may be configured to generate one or more predicted values ​​based on a plurality of measurements received from the UE, for example, based on an average, a weighted average, or other statistical combination of measurements. In another implementation, one or more processors (1302) may be configured to receive predicted values ​​from other entities, such as a location server, when the network entity (1300) is a base station. One or more processors (1302) may be configured to transmit one or more predicted values ​​for one or more measurements of downlink reference signals to the UE via an external interface. One or more processors (1302) may be configured to update one or more predicted values ​​based on additional measurements received from the UE. The predicted values ​​may be predicted positioning measurements, such as one or more predicted RSRP values; RSTD values, predicted RSTD uncertainty, or a combination thereof; predicted AoA values, predicted AoA uncertainty, or a combination thereof; predicted RTT values, etc.The predicted value may be at least one of one or more predicted channel coefficients, velocity, direction, or combinations thereof for a pair of Tx-Rx antennas or antenna ports.

[0156] When the medium (1320) and / or memory (1304) is implemented by one or more processors (1302), it may include a reporting module (1324) configured to receive, via an external interface (1310), an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements performed by the UE regarding current downlink reference signals received by the UE and one or more predicted values ​​regarding said one or more measurements of downlink reference signals to the UE. For example, the indication may be a report providing one or more measurements performed by the UE regarding current downlink reference signals received by the UE, which may be used by one or more processors (1302) to determine or verify that an attack device is present. In another example, the indication may be a warning flag indicating the presence of an attack device.

[0157] The medium (1320) and / or memory (1304) may include a measurement module (1326) configured to receive one or more measurements of a downlink reference signal transmitted by a base station, which can be used to update a predicted value of a measurement through an external interface (1310), for example, when it is determined that no attack device exists, when implemented by one or more processors (1302).

[0158] The methodologies described herein may be implemented by various means depending on the application. For example, these methodologies may be implemented in hardware, firmware, software, or any combination thereof. For hardware implementation, one or more processors (1302) may be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described herein, or a combination thereof.

[0159] In firmware and / or software implementations, methodologies may be implemented as modules (e.g., procedures, functions, etc.) that perform the functions described herein. Any machine-readable medium containing instructions as types may be used to implement the methodologies described herein. For example, software code may be stored in a non-transient computer-readable medium (1320) or memory (1304) connected to and executed by one or more processors (1302). Memory may be implemented within one or more processors or outside one or more processors. As used herein, the term “memory” refers to any type of long-term, short-term, volatile, non-volatile, or other memory, and is not limited to any specific type of memory, the number of memories, or the type of medium in which the memory is stored.

[0160] Where implemented in firmware and / or software, functions may be stored as one or more instructions or program code (1308) on a non-transient computer-readable medium, such as a medium (1320) and / or memory (1304). Examples include computer-readable media encoded in a data structure and computer-readable media encoded in a computer program (1308). For example, a non-transient computer-readable medium containing stored program code (1308) may include program code (1308) to support authentication of a connection between a UE and a base station and identification of the presence of an intervening device between a UE and a base station in a manner consistent with the disclosed embodiments. The non-transient computer-readable medium (1320) includes physical computer storage media. The storage medium may be any available medium accessible by a computer. As an example, not a limitation, such non-transient computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store the desired program code (1308) in the form of instructions or data structures that can be accessed by a computer; as used herein, disk and disc include compact discs (CD), laser discs, optical discs, digital multifunction discs (DVD), floppy discs and Blu-ray discs, wherein disks usually reproduce data magnetically, while discs reproduce data optically with a laser. Also, the above combinations should be included within the scope of computer-readable media.

[0161] In addition to storage on a computer-readable medium (1320), instructions and / or data may be provided as signals on transmission media included in a communication device. For example, the communication device may include an external interface (1310) having signals indicating instructions and data. Instructions and data are configured to enable one or more processors to implement the functions outlined in the claims. That is, the communication device includes a transmission medium having signals indicating information for performing the disclosed functions.

[0162] Memory (1304) may represent any data storage mechanism. Memory (1304) may include, for example, main memory and / or secondary memory. Primary memory may include, for example, random access memory, read-only memory, etc. Although shown in this example as being separate from one or more processors (1302), all or part of the primary memory may be provided within one or more processors (1302) or otherwise located / connected with them. Secondary memory may include, for example, memory of the same or similar type as the primary memory and / or one or more data storage devices or systems, such as, for example, a disk drive, an optical disk drive, a tape drive, a solid-state memory drive, etc.

[0163] In certain embodiments, secondary memory may operatively accommodate a non-transient computer-readable medium (1320) or otherwise be configurable to be coupled thereto. As such, in certain exemplary embodiments, the methods and / or apparatuses set forth herein may take the form of all or part of a computer-readable medium (1320) which may include stored computer-implementable code (1308) that may be operatively enabled to perform all or part of the exemplary operations as described herein when executed by one or more processors (1302). The computer-readable medium (1320) may be part of memory (1304).

[0164] FIG. 14 illustrates a flowchart of an exemplary method (1400) performed by a UE to authenticate a connection with a base station. The UE may be, for example, a UE (104) or a UE (1200), and the base station may be, for example, a base station (102) or a network entity (1300).

[0165] In block (1402), the UE receives one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from a base station, as discussed in steps (1112 and 1122) of FIG. 11. The downlink reference signal may be, for example, a positioning reference signal (PRS). In some implementations, as discussed in steps (1112 and 1122) of FIG. 11, the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements to determine whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals. Means for receiving one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from a base station may include, for example, a predicted value module (1222) shown in FIG. 12, one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or media (1220) within the UE (1200) and a wireless transceiver (1210).

[0166] In block 1404, for example, as discussed in stages 1114 and 1124 of FIG. 11, the UE receives a downlink reference signal. The means for receiving the downlink reference signal may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or media (1220) within the UE (1200), such as the reference signal module (1224) shown in FIG. 12, for example, and a wireless transceiver (1210).

[0167] In block 1406, for example, as discussed in stages 1115 and 1125 of FIG. 11, the UE performs one or more measurements of the received downlink reference signal. The means for performing one or more measurements of the received downlink reference signal may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or media (1220) within the UE (1200), such as the measurement module (1226) shown in FIG. 12, for example.

[0168] In block 1408, the UE determines whether the attack device has transmitted the received downlink reference signals based on one or more predicted values ​​for one or more measurements of downlink reference signals and one or more measurements of current downlink reference signals, as discussed in stages 1116 and 1126 of FIG. 11. The means for determining whether the attack device has transmitted the received downlink reference signals based on one or more predicted values ​​for one or more measurements of downlink reference signals and one or more measurements of current downlink reference signals may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or media (1220) within the UE (1200), such as the comparison module (1228) shown in FIG. 12, for example.

[0169] In some implementations, as discussed in step 1128 of FIG. 11, the UE may transmit a report to a network entity indicating the presence of an attack device in the connection between the UE and the base station in response to a determination that a received downlink reference signal is transmitted by an attack device. For example, the UE may transmit the report to a network entity that may be either a base station or a location server. Means for transmitting a report to a network entity indicating the presence of an attack device in the connection between the UE and the base station in response to a determination that a received downlink reference signal is transmitted by an attack device may include, for example, a reporting module (1230) illustrated in FIG. 12, one or more processors (1202) having dedicated hardware that implement executable code or software instructions in memory (1204) and / or media (1220) within the UE (1200) and a wireless transceiver (1210).

[0170] In some implementations, one or more predicted values ​​for one or more measurements of downlink reference signals may be predicted positioning measurements. For example, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected reference signal received power (RSRP) values ​​for the downlink reference signals. In other examples, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainty, or a combination thereof. In another example, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected Angle of Arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof. In another example, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected Round-Trip Time (RTT) values ​​for the base station.

[0171] In some implementations, the UE may further receive one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of a previous downlink reference signal received from a base station, as discussed in steps (1110 and 1112) of FIG. 11, and may determine current channel coefficients from the received downlink reference signal, for example, as discussed in steps 1115 and 1125 of FIG. 11. The UE may further determine whether the attack device transmitted the received downlink reference signal based on the predicted channel coefficients and the current channel coefficients, as discussed in steps 1116 and 1126 of FIG. 11. Means for receiving one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of a previous downlink reference signal received from a base station may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or medium (1220) within the UE (1200), for example, as a predicted value module (1222) shown in FIG. 12, and a radio transceiver (1210). Means for determining current channel coefficients from a received downlink reference signal may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or medium (1220) within the UE (1200), for example, as a measurement module (1226) shown in FIG. 12.

[0172] In some implementations, the UE may further receive at least one of a speed, direction, or a combination thereof based on measurements of a previous downlink reference signal received from a base station, for example, as discussed in steps (1110 and 1112) of FIG. 11, and may determine at least one of a current speed, current direction, or a combination thereof from the received downlink reference signal, for example, as discussed in steps 1115 and 1125 of FIG. 11. The UE may determine whether the attack device transmitted the received downlink reference signals based further on at least one predicted speed, direction, or a combination thereof and at least one of the current speed, current direction, or a combination thereof, for example, as discussed in steps (1116 and 1126) of FIG. 11. Means for receiving at least one of speed, direction, or a combination thereof based on measurements of a previous downlink reference signal received from a base station may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or medium (1220) within the UE (1200), such as the prediction value module (1222) shown in FIG. 12, for example, and a wireless transceiver (1210). Means for determining at least one of the current speed, current direction, or a combination thereof from the received downlink reference signal may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or medium (1220) within the UE (1200), such as the measurement module (1226) shown in FIG. 12, for example.

[0173] In some implementations, for example as discussed in steps (1110 and 1112), the UE may additionally receive one or more timestamps associated with predicted values ​​for one or more measurements of downlink reference signals. Means for receiving one or more timestamps associated with predicted values ​​for one or more measurements of downlink reference signals may include one or more processors (1202) having dedicated hardware or implementing executable code or software instructions in memory (1204) and / or media (1220) within the UE (1200), such as the predicted value module (1222) illustrated in FIG. 12, for example, and a wireless transceiver (1210).

[0174] FIG. 15 illustrates a flowchart of an exemplary method (1500) performed by a network entity to authenticate a connection between a UE and a base station. For example, the network entity may be a base station (102), a location server (172), or a network entity (1300), and the UE may be a UE (104) or a UE (1200).

[0175] In block (1502), the network entity obtains one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from a base station, for example, as discussed in steps (1104, 1108, and 1118) of FIG. 11. The downlink reference signal may be, for example, a positioning reference signal (PRS). In some implementations, as discussed in steps (1112 and 1122) of FIG. 11, the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements to determine whether the attack device has transmitted a support data set of the predicted values ​​for the one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals. Means for obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station may include, for example, one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within the network entity (1300), such as the predicted value module (1322) shown in FIG. 13, and an external interface (1310).

[0176] In block 1504, for example, as discussed in steps 1112 and 1122 of FIG. 11, the network entity transmits one or more predicted values ​​for one or more measurements of downlink reference signals to the UE. The means for transmitting one or more predicted values ​​for one or more measurements of downlink reference signals to the UE may include one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within the network entity (1200), such as the predicted value module (1322) illustrated in FIG. 13, for example, and an external interface (1310).

[0177] In block 1506, the network entity receives an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements performed by the UE on current downlink reference signals received by the UE, and one or more predicted values ​​for the one or more measurements of downlink reference signals to the UE, for example, as discussed in steps 1118 and 1128 of FIG. 11. Means for receiving an indication of whether an attack device is present in a connection between the UE and the base station based on one or more measurements performed by the UE on current downlink reference signals received by the UE and one or more predicted values ​​for said one or more measurements of downlink reference signals to the UE may include, for example, a reporting module (1324) illustrated in FIG. 13, one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within the network entity (1200) and an external interface (1310).

[0178] In one implementation, a network entity may receive one or more measurements of a downlink reference signal transmitted by a base station, as discussed in steps (1108 and 1118) of FIG. 11, for example, and obtain one or more predicted values ​​for one or more measurements of the downlink reference signals to be performed by the UE by generating one or more predicted values ​​for the one or more measurements of the downlink reference signals based on the one or more measurements received by the UE, as discussed in steps (1110 and 1120) of FIG. 11. Means for receiving one or more measurements of a downlink reference signal transmitted by a base station performed by a UE may include, for example, a measurement module (1326) shown in FIG. 13, one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within a network entity (1300), and an external interface (1310). Means for generating one or more predicted values ​​for the one or more measurements of the downlink reference signals based on the one or more measurements received by the UE may include, for example, a predicted value module (1322) shown in FIG. 13, one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within a network entity (1200).

[0179] In one implementation, the network entity may obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE by receiving one or more predicted values ​​from a location server, for example, as discussed in steps (1110 and 1120) of FIG. 11. The means for receiving one or more predicted values ​​from the location server may include one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within the network entity (1200), for example, as the predicted value module (1322) illustrated in FIG. 13, and an external interface (1310).

[0180] In one implementation, the indication of whether an attack device is present may include a report indicating that an attack device has been detected by the UE, as discussed in step 1128 of FIG. 11. In one implementation, the indication of whether an attack device is present may include a report providing the one or more measurements performed by the UE on the current downlink reference signals received by the UE, as discussed in step 1118 or 1128 of FIG. 11. The network entity may update the one or more predicted values ​​for the one or more measurements of the downlink reference signals to be performed by the UE based on the one or more measurements performed by the UE on the current downlink reference signals, as discussed in steps 1120 and 1122 of FIG. 11. Means for updating the one or more predicted values ​​for the one or more measurements of downlink reference signals to be performed by the UE based on the one or more measurements performed by the UE for the current downlink reference signals may include, for example, one or more processors (1302) having dedicated hardware or implementing executable code or software instructions in memory (1304) and / or media (1320) within the network entity (1300), such as the predicted value module (1322) shown in FIG. 13, and an external interface (1310).

[0181] In some implementations, one or more predicted values ​​for one or more measurements of downlink reference signals may be predicted positioning measurements. For example, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected reference signal received power (RSRP) values ​​for the downlink reference signals. In other examples, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainty, or a combination thereof. In another example, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected Angle of Arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof. In another example, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected Round-Trip Time (RTT) values ​​for the base station.

[0182] In some implementations, as discussed in steps 1100 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports. In some implementations, as discussed in steps 1110 and 1112 of FIG. 11, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof.

[0183] It will be apparent to those skilled in the art that substantial changes may be made according to specific requirements. For example, custom hardware may also be used and / or specific elements may be implemented in hardware, software (including portable software such as applets, etc.), or both. Additionally, connections to other computing devices, such as network input / output devices, may be employed.

[0184] Referring to the attached drawings, components that may include memory may include non-transient machine-readable media. As used herein, the terms “machine-readable media” and “computer-readable media” refer to any storage medium that participates in providing data that causes a machine to operate in a particular way. In the embodiments provided above, various machine-readable media may be involved in providing instructions / code to a processing unit and / or other device(s) for execution. Additionally or alternatively, machine-readable media may be used to store and / or carry such instructions / code. In many implementations, computer-readable media are physical and / or tangible storage media. Such media may take a number of forms, including but not limited to non-volatile media and volatile media. Common forms of computer-readable media include, for example, magnetic and / or optical media, any other physical media having patterns of holes, RAM, programmable ROM (PROM), erasable PROM (EPROM), FLASH-EPROM, any other memory chip or cartridge, or any other media in which a computer can read instructions and / or code.

[0185] The methods, systems, and devices discussed herein are examples. Various embodiments may omit, substitute, or add various procedures or components as appropriate. For example, features described in connection with specific embodiments may be combined in various other embodiments. Different aspects and elements of the embodiments may be combined in a similar manner. Various components of the drawings provided herein may be implemented in hardware and / or software. Furthermore, technology evolves, and therefore many of the elements are examples that do not limit the scope of this disclosure to these specific examples.

[0186] It has been proven that, primarily for general use, it is sometimes convenient to refer to such signals as bits, information, values, elements, symbols, characters, variables, terms, numbers, numerical values, etc. However, it should be understood that all these or similar terms are to be associated with appropriate physical quantities and are merely convenient labels. Unless explicitly stated otherwise, as is evident from the discussion above, throughout this specification, discussions utilizing terms such as "processing," "operating," "calculating," "determining," "verifying," "identifying," "associating," "measuring," "performing," etc., are recognized as referring to the actions and processes of specific devices, such as special-purpose computers or similar special-purpose electronic computing devices. Accordingly, in the context of this specification, a special purpose computer or a similar special purpose electronic computing device can manipulate or convert signals, which are typically expressed as physical, electronic, electrical, or magnetic quantities within the memories, registers, or other information storage devices, transmitting devices, or display devices of the special purpose computer or a similar special purpose electronic computing device.

[0187] Terms such as “and” and “or” as used herein may include various meanings that are also expected to depend at least in part on the context in which such terms are used. Typically, when used to associate a list such as A, B, or C, “or” is intended to mean A, B, and C as used herein in an inclusive sense, as well as A, B, or C as used herein in an exclusive sense. Additionally, the term “one or more” as used herein may be used to describe any feature, structure, or characteristic in the singular, or to describe some combination of features, structures, or characteristics. However, this is merely an exemplary example. It should be noted that the claims are not limited to such examples. Also, when used to associate a list such as A, B, or C, the term “at least one of” may be interpreted to mean any combination of A, B, and / or C, such as A, AB, AA, AAB, AABBCCC, etc.

[0188] When describing several embodiments, various modifications, alternative configurations, and equivalents may be used without departing from the spirit of the present disclosure. For example, the elements may be merely components of a larger system, wherein other rules may take precedence or otherwise modify the application of the various embodiments. Additionally, a number of steps may be undertaken before, during, or after the elements are considered. Accordingly, the above description does not limit the scope of the present disclosure.

[0189] With these descriptions in mind, embodiments may include different combinations of features. Examples of implementation are described in the following numbered clauses.

[0190] Clause 1. A method performed by a user device (UE) to authenticate a connection with a base station, the method comprising: receiving one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; receiving downlink reference signals; performing one or more measurements of the received downlink reference signals; and determining whether an attack device has transmitted the received downlink reference signals based on the one or more predicted values ​​for the one or more measurements of the downlink reference signals and the one or more measurements of the current downlink reference signals.

[0191] Clause 2. In Clause 1, the downlink reference signals are downlink positioning reference signals.

[0192] Clause 3. In Clause 1 or 2, further comprising the step of transmitting to a network entity a report indicating the presence of said attack device in the connection between said UE and said base station in response to a determination that received downlink reference signals are transmitted by said attack device.

[0193] Clause 4. In Clause 3, the network entity is a base station or a location server.

[0194] In any one of Clause 5, Clauses 1 through 4, the one or more predicted values ​​for one or more measurements include a security set of predicted values ​​for one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0195] Clause 6. In any one of Clauses 1 through 5, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0196] Clause 7. In any one of Clauses 1 through 6, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0197] Clause 8. In any one of Clauses 1 through 7, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0198] Clause 9. In any one of Clauses 1 through 8, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0199] Clause 10. Any one of Clauses 1 through 9, further comprising: receiving one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of previous downlink reference signals received from the base station; and determining current channel coefficients from the received downlink reference signals, wherein the step of determining whether the attack device has transmitted the received downlink reference signals is further based on the predicted channel coefficients and the current channel coefficients.

[0200] Clause 11. Any one of Clauses 1 to 10, further comprising: receiving at least one of a speed, direction, or a combination thereof based on measurements of previous downlink reference signals received from the base station; and determining at least one of a current speed, current direction, or a combination thereof from the received downlink reference signals, wherein the step of determining whether the attack device has transmitted the received downlink reference signals is further based on at least one predicted speed, direction, or a combination thereof and at least one of the current speed, current direction, or a combination thereof.

[0201] Clause 12. Any one of Clauses 1 through 11 further comprises the step of receiving one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0202] Clause 13. User equipment (UE) configured to authenticate a connection with a base station comprises: a radio transceiver configured to communicate with other entities within a network; at least one memory; and at least one processor coupled to the radio transceiver and at least one memory, wherein the at least one processor is configured to receive, through the radio transceiver, one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; receive downlink reference signals through the radio transceiver; perform one or more measurements of the received downlink reference signals; and determine whether an attack device has transmitted the received downlink reference signals based on the one or more predicted values ​​for the one or more measurements of the downlink reference signals and the one or more measurements of the current downlink reference signals.

[0203] Clause 14. In Clause 13, downlink reference signals are downlink positioning reference signals.

[0204] Clause 15. In Clause 13 or 14, at least one processor is configured to transmit to a network entity, via a wireless transceiver, a report indicating the presence of said attack device in the connection between said UE and said base station in response to a determination that received downlink reference signals are transmitted by said attack device.

[0205] Clause 16. In Clause 15, the network entity is a base station or a location server.

[0206] In any one of Clause 17, Clauses 13 through 16, the one or more predicted values ​​for one or more measurements include a security set of predicted values ​​for one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0207] Clause 18. In any one of Clauses 13 through 17, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0208] Clause 19. In any one of Clauses 13 through 18, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0209] Clause 20. In any one of Clauses 13 through 19, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0210] Clause 21. In any one of Clauses 13 through 20, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0211] Clause 22. In any one of Clauses 13 to 21, at least one processor is also configured to receive one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of previous downlink reference signals received from the base station; and to determine current channel coefficients from the received downlink reference signals, wherein at least one processor is configured to determine whether an attack device has transmitted the received downlink reference signals based further on the predicted channel coefficients and the current channel coefficients.

[0212] Clause 23. In any one of Clauses 13 to 22, at least one processor is also configured to receive, via a wireless transceiver, at least one of a speed, a direction, or a combination thereof, based on measurements of previous downlink reference signals received from the base station; and to determine from the received downlink reference signals at least one of a current speed, a current direction, or a combination thereof, wherein at least one processor is configured to determine whether the attack device transmitted the received downlink reference signals based further on at least one predicted speed, a direction, or a combination thereof and at least one of the current speed, a current direction, or a combination thereof.

[0213] Clause 24. In any one of Clauses 13 through 23, at least one processor is also configured to receive one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0214] Clause 25. User equipment (UE) configured to authenticate a connection with a base station comprises: means for receiving one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; means for receiving downlink reference signals; means for performing one or more measurements of the received downlink reference signals; and means for determining whether an attack device has transmitted the received downlink reference signals based on the one or more predicted values ​​for one or more measurements of the downlink reference signals and the one or more measurements of the current downlink reference signals.

[0215] Clause 26. In Clause 25, downlink reference signals are downlink positioning reference signals.

[0216] Clause 27. In Clause 25 or 26, means further comprising transmitting to a network entity a report indicating the presence of said attack device in said connection between said UE and said base station in response to a determination that received downlink reference signals are transmitted by said attack device.

[0217] Clause 28. In Clause 27, the network entity is a base station or a location server.

[0218] In any one of Clause 29, Clauses 25 through 28, the one or more predicted values ​​for one or more measurements include a security set of predicted values ​​for one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0219] Clause 30. In any one of Clauses 25 through 29, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0220] Clause 31. In any one of Clauses 25 to 30, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0221] Clause 32. In any one of Clauses 25 through 31, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0222] Clause 33. In any one of Clauses 25 through 32, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0223] Clause 34. In any one of Clauses 25 to 33, means for receiving one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of previous downlink reference signals received from the base station; and means for determining current channel coefficients from the received downlink reference signals, wherein the means for determining whether the attacking device has transmitted the received downlink reference signals further uses the predicted channel coefficients and the current channel coefficients.

[0224] Clause 35. In any one of Clauses 25 to 34, means for receiving at least one of speed, direction, or a combination thereof based on measurements of previous downlink reference signals received from the base station; and means for determining at least one of current speed, current direction, or a combination thereof from the received downlink reference signals, wherein the means for determining whether the attack device has transmitted the received downlink reference signals further uses at least one predicted speed, direction, or a combination thereof and at least one of current speed, current direction, or a combination thereof.

[0225] Clause 36. Any one of Clauses 25 to 35 further comprises means for receiving one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0226] Clause 37. A non-transient storage medium comprising stored program code, wherein the program code is operable to configure at least one processor within a user equipment (UE) to authenticate a connection with a base station, and the program code comprises: a command to receive one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from a base station; a command to receive downlink reference signals; a command to perform one or more measurements of the received downlink reference signals; and a command to determine whether an attack device has transmitted the received downlink reference signals based on the one or more predicted values ​​for one or more measurements of the downlink reference signals and the one or more measurements of the current downlink reference signals.

[0227] Clause 38. In Clause 37, downlink reference signals are downlink positioning reference signals.

[0228] Clause 39. In Clause 37 or 38, the program code further includes a command to transmit to a network entity a report indicating the presence of said attack device in said connection between said UE and said base station in response to a determination that received downlink reference signals are transmitted by said attack device.

[0229] Clause 40. In Clause 39, the network entity is a base station or a location server.

[0230] In any one of Clause 41, Clauses 37 through 40, the one or more predicted values ​​for one or more measurements include a security set of predicted values ​​for one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0231] Clause 42. In any one of Clauses 37 through 41, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0232] Clause 43. In any one of Clauses 37 through 42, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0233] Clause 44. In any one of Clauses 37 through 43, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0234] Clause 45. In any one of Clauses 37 through 44, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0235] Clause 46. In any one of Clauses 37 through 45, the program code further comprises: a command to receive one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of previous downlink reference signals received from the base station; and a command to determine current channel coefficients from the received downlink reference signals, wherein the command to determine whether the attacking device has transmitted the received downlink reference signals further uses the predicted channel coefficients and the current channel coefficients.

[0236] Clause 47. In any one of Clauses 37 to 46, the program code further comprises: a command to receive at least one of speed, direction, or a combination thereof based on measurements of previous downlink reference signals received from the base station; and a command to determine at least one of current speed, current direction, or a combination thereof from the received downlink reference signals, and the command to determine whether the attack device has transmitted the received downlink reference signals further uses at least one predicted speed, direction, or a combination thereof and at least one of current speed, current direction, or a combination thereof.

[0237] Clause 48. In any one of Clauses 37 through 47, the program code further includes a command to receive one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0238] Clause 49. A method performed by a network entity to authenticate a connection between a user device (UE) and a base station, the method comprising: obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; transmitting one or more predicted values ​​for one or more measurements of downlink reference signals to the UE; and receiving an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0239] Clause 50. In Clause 49, the downlink reference signals are downlink positioning reference signals.

[0240] Clause 51. In either Clause 49 or Clause 50, the step of obtaining one or more predicted values ​​for one or more measurements of a downlink reference signal to be performed by the UE comprises: receiving one or more measurements of a downlink reference signal performed by the UE transmitted by a base station; and generating one or more predicted values ​​for one or more measurements of a downlink reference signal based on the received one or more measurements performed by the UE.

[0241] Clause 52. In Clause 49 or 50, the step of obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE includes the step of receiving the one or more predicted values ​​from a location server.

[0242] Clause 53. In any one of Clauses 49 through 52, the indication of whether the attack device is present includes a report indicating that the attack device has been detected by the UE.

[0243] Clause 54. In any one of Clauses 49 through 52, an indication of whether the attack device is present includes a report providing one or more measurements performed by the UE with respect to the current downlink reference signals received by the UE.

[0244] Clause 55. In Clause 54, the step of updating the one or more predicted values ​​for the one or more measurements of downlink reference signals to be performed by the UE, based on the one or more measurements performed by the UE for the current downlink reference signals.

[0245] Clause 56. In any one of Clauses 49 through 55, the network entity is one of a base station or a location server.

[0246] Clause 57. In any one of Clauses 49 through 56, the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0247] Clause 58. In any one of Clauses 49 through 57, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0248] Clause 59. In any one of Clauses 49 through 58, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0249] Clause 60. In any one of Clauses 49 through 59, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0250] Clause 61. In any one of Clauses 49 through 60, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0251] Clause 62. In any one of Clauses 49 through 61, the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports.

[0252] Clause 63. In any one of Clauses 49 through 62, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof.

[0253] Clause 64. In any one of Clauses 49 through 63, the step of transmitting to the UE one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0254] Clause 65. A network entity configured to authenticate a connection between a user device (UE) and a base station comprises: an external interface configured to communicate with other entities of a wireless network; at least one memory; and at least one processor coupled to the external interface and at least one memory, wherein the at least one processor obtains one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; transmits one or more predicted values ​​for one or more measurements of downlink reference signals to the UE via the external interface; and is configured to receive, via the external interface, an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0255] Clause 66. In Clause 65, the downlink reference signals are downlink positioning reference signals.

[0256] Clause 67. In either Clause 65 or Clause 66, at least one processor is configured to receive, through an external interface, one or more measurements of a downlink reference signal performed by a UE transmitted by a base station; and to obtain one or more predicted values ​​for one or more measurements of a downlink reference signal to be performed by a UE by generating one or more predicted values ​​for one or more measurements of a downlink reference signal based on one or more received measurements performed by the UE.

[0257] Clause 68. In Clause 65 or 66, the at least one processor is configured to obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE by being configured to receive one or more predicted values ​​from a location server.

[0258] Clause 69. In any one of Clauses 65 through 68, the indication of whether the attack device is present includes a report indicating that the attack device has been detected by the UE.

[0259] Clause 70. In any one of Clauses 65 through 68, an indication of whether the attack device is present includes a report providing one or more measurements performed by the UE with respect to the current downlink reference signals received by the UE.

[0260] Clause 71. In Clause 70, the at least one processor is also configured to update the one or more predicted values ​​for the one or more measurements of downlink reference signals to be performed by the UE, based on the one or more measurements performed by the UE for the current downlink reference signals.

[0261] Clause 72. In any one of Clauses 65 through 71, the network entity is one of a base station or a location server.

[0262] Clause 73. In any one of Clauses 65 through 72, the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0263] Clause 74. In any one of Clauses 65 through 73, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0264] Clause 75. In any one of Clauses 65 through 74, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0265] Clause 76. In any one of Clauses 65 through 75, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0266] Clause 77. In any one of Clauses 65 through 76, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0267] Clause 78. In any one of Clauses 65 through 77, the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports.

[0268] Clause 79. In any one of Clauses 65 through 78, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof.

[0269] Clause 80. In any one of Clauses 65 through 79, the at least one processor is also configured to transmit to the UE one or more timestamps associated with the predicted values ​​for the one or more measurements of the downlink reference signals.

[0270] Clause 81. A network entity configured to authenticate a connection between a user device (UE) and a base station comprises: means for obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals performed by the UE from the base station to the UE; means for transmitting one or more predicted values ​​for one or more measurements of downlink reference signals to the UE; and means for receiving an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals performed by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0271] Clause 82. In Clause 81, the downlink reference signals are downlink positioning reference signals.

[0272] Clause 83. In either Clause 81 or Clause 82, means for obtaining one or more predicted values ​​for one or more measurements of a downlink reference signal to be performed by a UE comprises: means for receiving one or more measurements of a downlink reference signal performed by a UE transmitted by a base station; and means for generating one or more predicted values ​​for one or more measurements of a downlink reference signal based on the received one or more measurements performed by the UE.

[0273] Clause 84. In Clause 81 or 82, means for obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE includes means for receiving said one or more predicted values ​​from a location server.

[0274] Clause 85. In any one of Clauses 81 through 84, the indication of whether the attack device is present includes a report indicating that the attack device has been detected by the UE.

[0275] Clause 86. In any one of Clauses 81 through 84, an indication of whether the attack device is present includes a report providing one or more measurements performed by the UE with respect to the current downlink reference signals received by the UE.

[0276] Clause 87. In Clause 86, the means further comprises updating the one or more predicted values ​​for the one or more measurements of downlink reference signals to be performed by the UE based on the one or more measurements performed by the UE for the current downlink reference signals.

[0277] Clause 88. In any one of Clauses 81 through 87, the network entity is one of a base station or a location server.

[0278] Clause 89. In any one of Clauses 81 through 88, the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0279] Clause 90. In any one of Clauses 81 through 89, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0280] Clause 91. In any one of Clauses 81 through 90, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0281] Clause 92. In any one of Clauses 81 through 91, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0282] Clause 93. In any one of Clauses 81 through 92, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0283] Clause 94. In any one of Clauses 81 through 93, the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports.

[0284] Clause 95. In any one of Clauses 81 through 94, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof.

[0285] Clause 96. In any one of Clauses 81 through 95, means further comprising transmitting to the UE one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0286] Clause 97. A non-transient storage medium comprising stored program code, wherein the program code is operable to configure at least one processor within a network entity to authenticate a connection between a user device (UE) and a base station, and the program code comprises: a command to obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; a command to transmit one or more predicted values ​​for one or more measurements of downlink reference signals to the UE; and a command to receive an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and one or more predicted values ​​for one or more measurements of downlink reference signals to the UE.

[0287] Clause 98. In Clause 97, the downlink reference signals are downlink positioning reference signals.

[0288] Clause 99. In either Clause 97 or Clause 98, a command to obtain one or more predicted values ​​for one or more measurements of a downlink reference signal to be performed by a UE comprises: a command to receive one or more measurements of a downlink reference signal performed by a UE transmitted by a base station; and a command to generate one or more predicted values ​​for one or more measurements of a downlink reference signal based on one or more of the received measurements performed by the UE.

[0289] Clause 100. In Clause 97 or 98, a command to obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE includes a command to receive one or more predicted values ​​from a location server.

[0290] Clause 101. In any one of Clauses 97 through 100, the indication of whether the attack device is present includes a report indicating that the attack device has been detected by the UE.

[0291] Clause 102. In any one of Clauses 97 through 100, an indication of whether the attack device is present includes a report providing one or more measurements performed by the UE with respect to the current downlink reference signals received by the UE.

[0292] Clause 103. In Clause 102, the program code further includes instructions to update the one or more predicted values ​​for the one or more measurements of downlink reference signals to be performed by the UE, based on the one or more measurements performed by the UE for the current downlink reference signals.

[0293] Clause 104. In any one of Clauses 97 through 103, the network entity is one of a base station or a location server.

[0294] Clause 105. In any one of Clauses 97 through 104, the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements to perform the received downlink reference signals and the one or more measurements of the received downlink reference signals.

[0295] Clause 106. In any one of Clauses 97 through 105, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals.

[0296] Clause 107. In any one of Clauses 97 through 106, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof.

[0297] Clause 108. In any one of Clauses 97 through 107, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof.

[0298] Clause 109. In any one of Clauses 97 through 108, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station.

[0299] Clause 110. In any one of Clauses 97 through 109, the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports.

[0300] Clause 111. In any one of Clauses 97 through 110, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof.

[0301] Clause 112. In any one of Clauses 97 through 111, the program code further includes a command to transmit to the UE one or more timestamps associated with the predicted values ​​for one or more measurements of the downlink reference signals.

[0302] Accordingly, the present claim is not limited to the specific examples disclosed, but is intended to include all embodiments within the scope of the appended claims and their equivalents.

Claims

Claim 1 A method performed by a user device (UE) to authenticate a connection with a base station, comprising: receiving one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; receiving downlink reference signals; performing one or more measurements of the received downlink reference signals; and determining whether an attack device has transmitted the received downlink reference signals based on the one or more predicted values ​​for the one or more measurements of the downlink reference signals and the one or more measurements of the current downlink reference signals. Claim 2 A method performed by a UE to authenticate a connection with a base station, wherein the downlink reference signals are downlink positioning reference signals, in the first aspect. Claim 3 A method performed by a UE to authenticate a connection with a base station, further comprising the step of transmitting to a network entity a report indicating the presence of the attack device in the connection between the UE and the base station in response to a determination that the received downlink reference signals are transmitted by the attack device. Claim 4 In claim 3, the method performed by the UE to authenticate a connection with a base station, wherein the network entity is the base station or location server. Claim 5 A method performed by a UE to authenticate a connection with a base station, wherein the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements for performing the received downlink reference signals and the one or more measurements of the received downlink reference signals. Claim 6 A method performed by a UE to authenticate a connection with a base station, wherein, in claim 1, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals. Claim 7 A method performed by a UE to authenticate a connection with a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof. Claim 8 A method performed by a UE to authenticate a connection with a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof. Claim 9 A method performed by a UE to authenticate a connection with a base station, wherein, in claim 1, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station. Claim 10 A method performed by a UE to authenticate a connection with a base station, wherein, in claim 1, the method further comprises the step of receiving one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of previous downlink reference signals received from the base station; and the step of determining current channel coefficients from the received downlink reference signals, wherein the step of determining whether the attacking device transmitted the received downlink reference signals is further based on the predicted channel coefficients and the current channel coefficients. Claim 11 A method performed by a UE to authenticate a connection with a base station, wherein the method further comprises: receiving at least one of a speed, a direction, or a combination thereof based on measurements of previous downlink reference signals received from the base station; and determining at least one of a current speed, a current direction, or a combination thereof from the received downlink reference signals, wherein the step of determining whether the attack device transmitted the received downlink reference signals is further based on at least one predicted speed, a direction, or a combination thereof and at least one of the current speed, a current direction, or a combination thereof. Claim 12 A method performed by a UE to authenticate a connection with a base station, further comprising the step of receiving one or more timestamps associated with the predicted values ​​for one or more measurements of downlink reference signals in claim 1. Claim 13 A user equipment (UE) configured to authenticate a connection with a base station, comprising: a wireless transceiver configured to communicate with other entities within a wireless network; at least one memory; and at least one processor coupled to the wireless transceiver and the at least one memory, wherein the at least one processor is configured to receive, through the wireless transceiver, one or more predicted values ​​for one or more measurements of downlink reference signals based on measurements of previous downlink reference signals received from the base station; receive downlink reference signals through the wireless transceiver; perform one or more measurements of the received downlink reference signals; and determine whether an attack device has transmitted the received downlink reference signals based on the one or more predicted values ​​for one or more measurements of the downlink reference signals and one or more measurements of the current downlink reference signals. Claim 14 In claim 13, a UE configured to authenticate a connection with a base station, wherein the downlink reference signals are downlink positioning reference signals. Claim 15 A UE configured to authenticate a connection with a base station, wherein the at least one processor is configured to transmit a report indicating the presence of the attack device in the connection between the UE and the base station to a network entity via the wireless transceiver in response to a determination that the received downlink reference signals are transmitted by the attack device. Claim 16 In claim 15, the network entity is a UE configured to authenticate a connection with a base station, which is a base station or a location server. Claim 17 A UE configured to authenticate a connection with a base station, wherein the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements for performing the received downlink reference signals and the one or more measurements of the received downlink reference signals. Claim 18 In claim 13, a UE configured to authenticate a connection with a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals. Claim 19 A UE configured to authenticate a connection with a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals comprise at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals received from one or more other base stations, one or more expected RSTD uncertainty, or a combination thereof. Claim 20 In claim 13, the one or more predicted values ​​for one or more measurements of downlink reference signals comprise one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof, a UE configured to authenticate a connection with a base station. Claim 21 In claim 13, a UE configured to authenticate a connection with a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station. Claim 22 A UE configured to authenticate a connection with a base station, wherein the at least one processor also receives, via the wireless transceiver, one or more predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports based on measurements of previous downlink reference signals received from the base station; is configured to determine current channel coefficients from the received downlink reference signals; and the at least one processor is configured to determine whether the attack device transmitted the received downlink reference signals based further on the predicted channel coefficients and the current channel coefficients. Claim 23 A UE configured to authenticate a connection with a base station, wherein the at least one processor also receives, through the wireless transceiver, at least one of a speed, direction, or a combination thereof based on measurements of previous downlink reference signals received from the base station; and is configured to determine at least one of a current speed, current direction, or a combination thereof from the received downlink reference signals, and the at least one processor is further configured to determine whether the attack device transmitted the received downlink reference signals based on at least one predicted speed, direction, or a combination thereof and at least one of the current speed, current direction, or a combination thereof. Claim 24 In claim 13, the at least one processor is also configured to receive one or more timestamps associated with the predicted values ​​for the one or more measurements of the downlink reference signals, and is configured to authenticate a connection with a base station. Claim 25 A method performed by a network entity to authenticate a connection between a user device (UE) and a base station, comprising: obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; transmitting the one or more predicted values ​​for the one or more measurements of downlink reference signals to the UE; and receiving an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and the one or more predicted values ​​for the one or more measurements of downlink reference signals to the UE. Claim 26 In claim 25, a method performed by a network entity to authenticate a connection between a UE and a base station, wherein the downlink reference signals are downlink positioning reference signals. Claim 27 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the step of obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE comprises: receiving one or more measurements of downlink reference signals transmitted by the base station and performed by the UE; and generating one or more predicted values ​​for the one or more measurements of downlink reference signals based on a plurality of received measurements performed by the UE. Claim 28 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the step of obtaining one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE comprises the step of receiving said one or more predicted values ​​from a location server. Claim 29 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the indication of whether the attack device exists includes a report indicating that the attack device has been detected by the UE. Claim 30 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the indication of whether the attack device is present comprises a report providing one or more measurements performed by the UE with respect to the current downlink reference signals received by the UE. Claim 31 A method performed by a network entity to authenticate a connection between a UE and a base station, further comprising the step of updating one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on one or more measurements performed by the UE for the current downlink reference signals. Claim 32 In claim 25, a method performed by a network entity to authenticate a connection between a UE and a base station, wherein the network entity is one of a base station or a location server. Claim 33 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device has transmitted a support data set of predicted values ​​for the one or more measurements for performing the received downlink reference signals and the one or more measurements of the received downlink reference signals. Claim 34 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein, in claim 25, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals. Claim 35 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals comprise at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainty, or a combination thereof. Claim 36 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof. Claim 37 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein, in claim 25, the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station. Claim 38 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports. Claim 39 A method performed by a network entity to authenticate a connection between a UE and a base station, wherein, in claim 25, the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof. Claim 40 A method performed by a network entity to authenticate a connection between a UE and a base station, further comprising the step of transmitting to the UE one or more timestamps associated with the predicted values ​​for one or more measurements of downlink reference signals. Claim 41 A network entity configured to authenticate a connection between a user equipment (UE) and a base station, comprising: an external interface configured to communicate with other entities within a wireless network; at least one memory; and at least one processor coupled to the external interface and the at least one memory, wherein the at least one processor obtains one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE based on previous measurements of downlink reference signals received by the UE from the base station; transmits the one or more predicted values ​​for the one or more measurements of downlink reference signals to the UE via the external interface; and is configured to receive, via the external interface, an indication of whether an attack device is present in the connection between the UE and the base station based on one or more measurements of current downlink reference signals received by the UE and the one or more predicted values ​​for the one or more measurements of downlink reference signals to the UE. Claim 42 In claim 41, a network entity configured to authenticate a connection between a UE and a base station, wherein the downlink reference signals are downlink positioning reference signals. Claim 43 A network entity configured to authenticate a connection between a UE and a base station, wherein the at least one processor receives, through the external interface, one or more measurements of downlink reference signals transmitted by the base station performed by the UE; and is configured to obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE by generating one or more predicted values ​​for the one or more measurements of downlink reference signals based on the one or more measurements received by the UE. Claim 44 A network entity configured to authenticate a connection between a UE and a base station, wherein the at least one processor is configured to obtain one or more predicted values ​​for one or more measurements of downlink reference signals to be performed by the UE by being configured to receive one or more predicted values ​​from a location server. Claim 45 A network entity configured to authenticate a connection between a UE and a base station, wherein the indication of whether the attack device exists includes a report indicating that the attack device has been detected by the UE. Claim 46 A network entity configured to authenticate a connection between a UE and a base station, wherein the indication of whether the attack device is present comprises a report providing one or more measurements performed by the UE with respect to the current downlink reference signals received by the UE. Claim 47 A network entity configured to authenticate a connection between a UE and a base station, wherein the at least one processor is also configured to update the one or more predicted values ​​for the one or more measurements of downlink reference signals to be performed by the UE based on the one or more measurements performed by the UE for the current downlink reference signals. Claim 48 In claim 41, the network entity is a network entity configured to authenticate a connection between a UE and a base station, which is either a base station or a location server. Claim 49 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for the one or more measurements include a security set of predicted values ​​for the one or more measurements for determining whether the attack device transmitted a support data set of predicted values ​​for the one or more measurements for performing the received downlink reference signals and the one or more measurements of the received downlink reference signals. Claim 50 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted reference signal received power (RSRP) values ​​for the downlink reference signals. Claim 51 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals comprise at least one of one or more expected reference signal time difference (RSTD) values ​​for downlink reference signals from one or more other base stations, one or more expected RSTD uncertainties, or a combination thereof. Claim 52 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more expected angle of arrival (AoA) values ​​for the downlink reference signals, one or more expected AoA uncertainties, or a combination thereof. Claim 53 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include one or more predicted round-trip time (RTT) values ​​for the base station. Claim 54 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include predicted channel coefficients for pairs of Tx-Rx antennas or antenna ports. Claim 55 A network entity configured to authenticate a connection between a UE and a base station, wherein the one or more predicted values ​​for one or more measurements of downlink reference signals include at least one of the speed of the UE, the direction of movement of the UE, or a combination thereof. Claim 56 A network entity configured to authenticate a connection between a UE and a base station, wherein the at least one processor is also configured to transmit to the UE one or more timestamps associated with the predicted values ​​for the one or more measurements of downlink reference signals.