Physical layer security

By employing physical layer security mechanisms with AI/ML assistance, the patent addresses the latency issues in wireless communication systems, enhancing security and reducing delays in data processing.

WO2025222628A1PCT designated stage Publication Date: 2025-10-30ZTE CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/103542
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-04
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in providing secure, low-latency data transmission due to the inefficiencies of higher-layer security mechanisms, which incur significant processing delays, particularly in Ultra-Reliable Low Latency Communications (URLLC) services.

Method used

Implementing mechanisms for physical layer security by indicating security information and commands between a base station and a UE, utilizing AI/ML to facilitate lower-layer security, including methods for indicating security levels and modes through various channels and resources, and encrypting/decrypting transmissions using channel information and scrambling sequences.

Benefits of technology

Enhances security and reduces processing delays by enabling efficient, low-latency data transmission through physical layer security mechanisms, improving the reliability of wireless communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024103542_30102025_PF_FP_ABST
    Figure CN2024103542_30102025_PF_FP_ABST
Patent Text Reader

Abstract

A method includes a wireless terminal device indicating, and a wireless access network node receiving an indication of, security information for a lower layer, wherein the security information comprises a security level and / or a security mode. Similarly, a method includes a wireless access network node indicating, and a wireless terminal device receiving an indication of, a security command for a lower layer, wherein the security command comprises a security level and / or a security mode.
Need to check novelty before this filing date? Find Prior Art

Description

PHYSICAL LAYER SECURITYTECHNICAL FIELD

[0001] This disclosure generally relates to handling transmissions in a wireless cellular access network, and is specifically directed to mechanisms for indicating physical layer security, for example, between a base station and a User Equipment (UE) .BACKGROUND

[0002] In the existing 4G and 5G systems, security (e.g., encryption and authentication) is guaranteed by the security mechanisms in higher layer, e.g., Packet Data Convergence Protocol (PDCP) layer. However, the security mechanisms in higher layers normally incur large delay in data processing. For the Ultra-Reliable Low Latency Communications (URLLC) services or Hyper Reliable Low Latency Communications (HRLLC) services in 6G, as an example, security mechanisms with a small delay are desired. Meanwhile, Artificial Intelligence  / Machine Learning (AI / ML) technology can be applied to facilitate the security mechanisms for lower layers.SUMMARY

[0003] This disclosure generally relates to handling transmissions in a wireless cellular access network, and is specifically directed to mechanisms for indicating physical layer security, for example, between a base station and a UE. Methods and associated systems are provided to achieve this objective, thereby improving security and reducing processing delay.

[0004] In some exemplary implementations, a method performed by a wireless terminal device (e.g., UE) , includes indicating, to a wireless access network node (WANN) (e.g., base station) , security information for a lower layer, wherein the security information comprises a security level and / or a security mode. Similarly, a method performed by the WANN includes receiving, from the wireless terminal device, an indication of security information for a lower layer, wherein the security information comprises a security level and / or a security mode.

[0005] In some exemplary implementations, which may be combined with any of the other  exemplary implementations disclosed herein, the methods include the wireless terminal device indicating, and the WANN receiving an indication of, the security level by a number, wherein a greater number implies a higher security level than a smaller number. Similarly, the methods may include the wireless terminal device indicating, and the WANN receiving an indication of, the security mode by indicating a security mode request or indicating whether the security mode is required. In various embodiments of the method, the security information is associated with a repetition number of preambles or a repetition number of Msg3, msg-A or msg-A PUSCH. In other embodiments, the security level or the security mode is associated with the repetition number of preambles, the repetition number of msgA, the repetition number of msg-A PUSCH, or the repetition number of Msg3. In certain embodiments of the method, the security information is associated with PRACH resources, wherein the PRACH resources may comprise PRACH occasions or preambles. In more specific embodiments, the security level or the security mode is associated with the PRACH resources.

[0006] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods include the wireless terminal device indicating, and the WANN receiving an indication of, the security information via Msg3 or PUSCH scheduled by Random access response (RAR) Uplink (UL) grant. In various embodiments of the methods, the security information is associated with a scheduling request or a PUCCH resource carrying the scheduling request. In other embodiments, the security level or the security mode is associated with the scheduling request or the PUCCH resource. In various embodiments, the methods include the WANN indicating, and the wireless terminal device receiving an indication of, a configuration of a reference signal or sequence for fingerprint information for the wireless terminal device, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence. The methods also may include the wireless terminal device transmitting, and the WANN receiving, the reference signal or sequence.

[0007] In some exemplary implementations, a method performed by the WANN includes indicating, to the wireless terminal device, a security command for a lower layer, wherein the  security command comprises a security level and / or a security mode. Similarly, a method performed by a wireless terminal device includes receiving, from the WANN, an indication of a security command for a lower layer, wherein the security command comprises a security level and / or a security mode.

[0008] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security command for a configured uplink transmission via Radio Resource Control (RRC) or broadcast / groupcast information, wherein each configured uplink transmission is associated with one security level. Similarly, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security command for a downlink semi-persistent transmission via Radio Resource Control (RRC) , wherein each downlink semi-persistent transmission is associated with one security level.

[0009] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security command for an uplink transmission via DCI, wherein the security command is associated with a number of time and / or frequency resources. The methods may further include the wireless terminal device transmitting, and the WANN receiving, a reference signal or a sequence in the associated time and / or frequency resources, and the uplink transmission. In various embodiments of the methods, the security level and / or the security mode is associated with a number of symbols at a beginning of the uplink transmission, wherein each security level is associated with the number of symbols. In such instances, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, L symbols for the uplink transmission, wherein L is an integer larger than 0, wherein the number of symbols associated with the security level is M, and wherein M is an integer not smaller than 0 and M is smaller than L. The methods may include the wireless terminal device transmitting, and the WANN receiving, the reference signal or the sequence in the first M symbols among the L symbols for the uplink transmission, and the uplink transmission in a remaining L-M symbols. In various  embodiments of the method, the security level and / or the security mode is associated with a number of resource elements or resource blocks within the uplink transmission.

[0010] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or the security mode is associated with a set of power control parameters for an uplink transmission. The methods may also include the wireless terminal device transmitting, and the WANN receiving, the uplink transmission.

[0011] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or security mode is associated with a set of frequency hopping parameters for an uplink transmission. The methods may also include the wireless terminal device transmitting, and the WANN receiving, the uplink transmission.

[0012] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a number of time and / or frequency resources. The methods may also include the WANN transmitting, and the wireless terminal device receiving a reference signal or a sequence in the associated time and / or frequency resources, and the downlink transmission. In various embodiments, the security level and / or the security mode is associated with a number of resource elements or resource blocks within the downlink transmission.

[0013] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, the security level and / or the security  mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a set of quasi co-location configurations for a downlink transmission. The methods may also include the WANN transmitting, and the wireless terminal device receiving the downlink transmission.

[0014] In some exemplary implementations, which may be combined with any of the other exemplary implementations disclosed herein, the methods may include the WANN indicating, and the wireless terminal device receiving an indication of, a configuration of a reference signal or a sequence, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence, and a repetition number of the reference signal or the sequence. The methods may also include the wireless terminal device transmitting, and the WANN receiving the reference signal or the sequence according to the configuration. The methods may also include the WANN determining a fingerprint of the wireless terminal device.

[0015] In some exemplary implementations, a method performed by the wireless terminal device includes encrypting or scrambling an uplink transmission to a wireless access network node via a key derived by channel information, wherein the wireless access network node decrypts or descrambles the uplink transmission via the key derived by the channel information. In various embodiments of the method, the channel information is downlink channel information or uplink information. In various embodiments of the method, the channel information is a channel matrix or information derived from the channel matrix. In various embodiments of the method, the channel information is a latest channel information received by the wireless terminal device from the wireless access network node or derived by the wireless terminal device. In various embodiments of the method, the channel information for deriving the key is channel information at a time and / or frequency resource, wherein the time and / or frequency resource is determined by a rule in view of at least one of the following of the uplink transmission: time domain information of the uplink transmission; frequency domain information of the uplink transmission; and / or spatial domain information of the uplink transmission.

[0016] In some exemplary implementations, a method performed by the wireless terminal device includes encrypting or scrambling an uplink transmission to the WANN via a  scrambling sequence from a set of scrambling sequences, wherein the WANN decrypts or descrambles the uplink transmission via the scrambling sequence, wherein the set of scrambling sequences are indicated by the WANN or predefined, and wherein the scrambling sequence for encryption or scrambling is selected from the set of scrambling sequences by a rule in view of at least one of the following: time domain information of the uplink transmission; frequency domain information of the uplink transmission; and / or spatial domain information of the uplink transmission.

[0017] In some exemplary implementations, a method performed by the wireless terminal device includes encrypting or scrambling an uplink transmission to the WANN via a key or a scrambling sequence from a set of scrambling sequences in response to at least one of the following: receiving, from the WANN, an activation of a security mode; receiving, from the WANN, an indication of a security level; or receiving, from the WANN , an indication of a security level higher than or equal to X, where X is indicated by the WANN or is predefined. In various embodiments the method includes the wireless terminal device applying the encryption, decryption, scrambling or descrambling to a subset of the data carried by the uplink transmission. In various embodiments the method includes the wireless terminal device receiving, from the WANN, an indication of a number between 0 and 1 to indicate a portion of the uplink transmission to which to apply the encryption, decryption, scrambling or descrambling via DCI, MAC-CE, or RRC.

[0018] In some exemplary implementations, a method performed by the WANN includes encrypting or scrambling a downlink transmission to the wireless terminal device via a key derived by channel information, wherein the wireless terminal device decrypts or descrambles the downlink transmission via the key. In various embodiments of the method, the channel information is a latest channel information received by the wireless terminal device from the WANN or derived by the wireless terminal device. In various embodiments of the method, the channel information for deriving the key is channel information at a time and / or frequency resource, wherein the time and / or frequency resource is determined by a rule in view of at least one of the following of the downlink transmission: time domain information of the downlink transmission; frequency domain information of the downlink transmission; and / or spatial  domain information of the downlink transmission.

[0019] In some exemplary implementations, a method performed by the WANN may include encrypting or scrambling a downlink transmission to a wireless terminal device via a scrambling sequence from a set of scrambling sequences, wherein the wireless terminal device decrypts or descrambles the downlink transmission via the scrambling sequence, wherein the set of scrambling sequences are indicated by the WANN or predefined, and wherein the scrambling sequence for encryption or scrambling is selected from the set of scrambling sequences by a rule in view of at least one of the following: time domain information of the downlink transmission; frequency domain information of the downlink transmission; and / or spatial domain information of the downlink transmission. In various embodiments, the method may include the WANN transmitting, to the wireless terminal device, an activation of a security mode; indicating, to the wireless terminal device, an indication of a security level; or indicating, to the wireless terminal device, a security level higher than or equal to X, where X is indicated by the wireless access network node or is predefined. The wireless terminal device responsively decrypts or descrambles the downlink transmission via the scrambling sequence in response to one or more of the above transmissions. In various embodiments of the method, the encryption, decryption, scrambling, or descrambling is applied to a subset of the data carried by the downlink transmission. In various embodiments, the method includes the WANN indicating, to the wireless terminal device, a number between 0 and 1 to indicate a portion of the downlink transmission to which to apply the encryption, decryption, scrambling or descrambling via DCI, MAC-CE, or RRC.

[0020] In some exemplary implementations, a method, or the methods discussed above with respect to Embodiments, 1, 2, and 3, may include the wireless terminal device reporting a security issue to a higher layer if a security check fails for M times, wherein M is an integer number larger than 0, and wherein a value of M is indicated by the WANN or is predefined.

[0021] In some other implementations, an apparatus for wireless communication such as a network device is disclosed. The network device may include one or more processors and one or more memories, wherein the one or more processors are configured to read computer code from the one or more memories to implement any one of the methods above. The  apparatus for wireless communication may be the wireless access network node (e.g., base station) or the wireless terminal device (e.g., UE) .

[0022] In yet some other implementations, a computer program product is disclosed. The computer program product may include a non-transitory computer-readable medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement any one of the methods above.

[0023] The above embodiments and other aspects and alternatives of their implementations are explained in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS

[0024] FIG. 1 shows a wireless access network with an exemplary uplink, downlink, and control channel configuration.

[0025] FIG. 2 shows various example processing components of the wireless terminal device and the wireless access network node of FIG. 1.

[0026] FIG. 3 shows an example diagram illustrating different security levels.

[0027] FIG. 4 shows illustrates an example flow diagram in accordance with various embodiments.DETAILED DESCRIPTION

[0028] The technology and examples of implementations and / or embodiments described in this disclosure can be used to facilitate over-the-air radio resource allocation, configuration, and signaling in wireless access networks as well as operational configuration of a UE and / or a base station within the wireless access networks. The term “exemplary” is used to mean “an example of” and unless otherwise stated, does not imply an ideal or preferred example, implementation, or embodiment. Section headers are used in the present disclosure to facilitate understanding of the disclosed implementations and are not intended to limit the disclosed technology in the sections only to the corresponding section. The disclosed implementations may be further embodied in a variety of different forms and, therefore, the  scope of this disclosure or claimed subject matter is intended to be construed as not being limited to any of the embodiments set forth below. The various implementations may be embodied as methods, devices, components, systems, or non-transitory computer readable media. Accordingly, embodiments of this disclosure may, for example, take the form of hardware, software, firmware or any combination thereof.

[0029] This disclosure is directed to handling transmissions in a wireless cellular access network and is specifically directed to mechanisms for managing models activated at a User Equipment (UE) side according to UE’s capability.

[0030] Wireless Network Overview

[0031] A wireless communication network may include a radio access network for providing network access to wireless terminal devices, and a core network for routing data between the access networks or between the wireless network and other types of data networks. In a wireless access network, radio resources are provided for allocation and used for transmitting data and control information. FIG. 1 shows an exemplary wireless access network 100 including a wireless access network node (WANN) or wireless base station 102 (herein referred to as wireless base station, base station, wireless access node, wireless access network node, or WANN) and a wireless terminal device or user equipment (UE) 104 (herein referred to as user equipment, UE, terminal device, or wireless terminal device) that communicates with one another via over-the-air (OTA) radio communication resources 106. The wireless access network 100 may be implemented as, as for example, a 2G, 3G, 4G / LTE, or 5G cellular radio access network. Correspondingly, the base station 102 may be implemented as a 2G base station, a 3G node B, an LTE eNB, or a 5G New Radio (NR) gNB. The user equipment 104 may be implemented as mobile or fixed communication devices installed with mobile identity modules for accessing the base station 102. The user equipment 104 may include but is not limited to mobile phones, laptop computers, tablets, personal digital assistants, wearable devices, distributed remote sensor devices, and desktop computers. Alternatively, the wireless access network 100 may be implemented as other types of radio access networks, such as Wi-Fi, Bluetooth, ZigBee, and WiMax networks.

[0032] FIG. 2 further shows example processing components of the WANN 102 and the UE 104 of FIG. 1. The UE 104, for example, may include transceiver circuitry 206 coupled to one or more antennas 208 to effectuate wireless communication with the WANN 102 (or to other UEs) . The transceiver circuitry 206 may also be coupled to a processor 210, which may also be coupled to a memory 212 or other storage devices. The memory 212 may be transitory or non-transitory and may store therein computer instructions or code which, when read and executed by the processor 210, cause the processor 210 to implement various ones of the, functions, methods, and processes of the UE 104 described herein. The memory 212 may also store therein, and the processor 210 may also be configured to execute one or more models (e.g., Artificial Intelligence  / Machine Learning (AI / ML) models) to perform one or more functionalities (e.g., AI / ML functionalities) . The memory 212 may also be utilized and allocated for buffering UL and DL transmissions in each band / carrier. The memory 212 may include multiple memory modules assigned to different functions (such as program memory, base band memory, and / or RF memory, to name a few) . Likewise, the WANN 102 may include transceiver circuitry 214 coupled to one or more antennas 216, which may include an antenna tower 218 in various forms, to effectuate wireless communications with the UE 104. The transceiver circuitry 214 may be coupled to one or more processors 220, which may further be coupled to a memory 222 or other storage devices. The memory 222 may be transitory or non-transitory and may store therein instructions or code that, when read and executed by the one or more processors 220, cause the one or more processors 220 to implement various functions, methods, and processes of the WANN 102 described herein.

[0033] Wireless Communication Resource Scheduling / Signaling

[0034] Returning to FIG. 1, the radio communication resources for the over-the-air interface 106 may include a combination of frequency, time, and / or spatial communication resources organized into various resource units or elements in frequency, time, and / or space. The radio communication resources 106 in frequency domain may include portions of licensed radio frequency bands, portions of unlicensed ration frequency bands, or portions of a mix of both licensed and unlicensed radio frequency bands. The radio communication resources 106 available for carrying the wireless communication signals between the base station 102 and  user equipment 104 may be further divided into physical downlink channels 110 for transmitting wireless signals from the base station 102 to the user equipment 104 and physical uplink channels 120 for transmitting wireless signals from the user equipment 104 to the base station 102. The physical downlink channels 110 may further include physical downlink control channels (PDCCHs) 112 and physical downlink shared channels (PDSCHs) 114. Likewise, the physical uplink channels 120 may further include physical uplink control channels (PUCCHs) 122 and physical uplink shared channels (PUSCHs) 124. For simplification, other types of downlink and uplink channels are not shown in FIG. 1 but are within the scope of the current disclosure. The control channels PDCCHs 112 and PUCCHs 122 may be used for carrying control information in the form of control messages 116 and 126, herein referred to as Downlink Control Information (DCI) messages or Uplink Control Information (UCI) messages. The shared channels (shared between data and control information) PDSCHs 114 and PUSCHs 124 may be allocated and used for communicating downlink data transmissions 118 and uplink data transmissions 128 between the base station 102 and the user equipment 104.

[0035] The allocation and configuration of the radio communication resources associated with the data channels, such as the PDSCHs and the PUSCHs may be provided by one or more resource scheduling DCIs carried in the PDCCHs. The PDCCHs may be shared by a plurality of UEs in the access network. In various approaches, a particular UE may be configured to perform blind decode procedures on a preconfigured UE-specific Search Space (USS) to detect and identify a payload of a resource scheduling DCI carried in the PDCCH that specifically targets the particular UE. The blind decoding may be performed on preconfigured monitoring occasions of the PDCCH associated with USS. Such monitoring occasions may be referred to as a set of PDCCH candidates. Each PDCCH candidate may be associated with a set of Control Channel Elements (CCEs) . The UE may specifically use its Radio Network Temporary Identifier (RNTI) to decode the PDCCH candidates. The RNTI may be used to demask a PDCCH candidate’s CRC. If no CRC error is detected, the UE determines that PDCCH candidate carries its own control information. The UE may then process the DCI and extract the resource allocation information pertaining to the PDSCH and / or PUSCH for  receiving and / or transmitting data.

[0036] Description of New Mechanisms for Indicating Physical Layer Security

[0037] Embodiment 1 -UE indicating a security level to the base station.

[0038] In a first approach, the UE 104 indicates security information for a lower layer to the base station 102. The base station 102 receives the security information for a lower layer from the UE 104. The lower layer may be, in various examples, a physical signal, physical channel, or procedures related to physical layer, e.g., power control, random access, etc.

[0039] In one alternative, the security information may comprise a security level. In one implementation, the security level may be indicated by a number (e.g., an integer number) , where a larger number implies a higher security level, and a smaller number implies a lower security. In another implementation, a larger number implies a lower security level, and a smaller number implies a higher security. Based on the UE’s 104 security level, the base station 102 can adjust its uplink and / or downlink transmission.

[0040] In another alternative, the security information may comprise a security mode (e.g., security mode request, or indicating whether security mode is required) . In one implementation, the base station 102 may determine whether to activate or apply the security mode based on the security information. Private, sensitive, or important information can be transmitted in the security mode. In one implementation, the security information indicates that the security mode is required. Compared with a normal mode, the security mode may require that some security mechanisms are enacted to ensure security of the lower layer. For example, the security mode may be carried by one bit, where, for example a value “1” of this bit indicates that the security mode is required, while value “0” indicates that the security mode is not required.

[0041] In one implementation, the security information may be associated with a repetition number of preambles or the repetition number of Msg3, msg-A, or msg-A PUSCH.

[0042] In one implementation, security level may be associated with the repetition  number of preambles, the repetition number of msgA, the repetition number of msg-APUSCH, or the repetition number of Msg3. Alternatively, the repetition number of preambles, the repetition number of msgA, the repetition number of msg-A PUSCH, or the repetition number of Msg3 may be associated with the security level. Typically, a higher security level corresponds to a larger repetition number. In this case, the base station 102 can better learn the fingerprint information of this UE 104, e.g., the radio frequency characteristics, and the base station 102 can determine whether this is the target UE or not based on the fingerprint information, e.g., via an artificial intelligence model. For example, a security level 0 may be associated with one transmission (i.e., one repetition) , while security level 1 may be associated with two repetitions. The repetition number of preambles or the repetition number of Msg3 can be indicated by the base station 102 or predefined. The repetition number of msg-A (PUSCH) can be associated with a mag-A (PUSCH) configuration.

[0043] In one implementation, the security mode is associated with the repetition number of preambles, the repetition number of msgA, the repetition number of msg-A PUSCH, or the repetition number of Msg3. Alternatively, the repetition number of preambles, the repetition number of msgA, the repetition number of msg-A PUSCH, or the repetition number of Msg3 is associated with the security mode. The repetition number of preambles or the repetition number of Msg3 can be indicated by the base station 102 or predefined. The repetition number of msg-A (PUSCH) can be associated with a mag-A (PUSCH) configuration. The repetition number of preambles or the repetition number of Msg3 can be indicated by the base station 102 or predefined. The repetition number of msg-A (PUSCH) can be associated with a mag-A (PUSCH) configuration.

[0044] In one implementation, the security information may be associated with the PRACH resources, where the PRACH resources may comprise PRACH occasions or preambles. In other words, the UE 104 may indicate the security information to the base station 102 via PRACH resources.

[0045] In one implementation, the security levels are associated with PRACH resources. One security level may be associated with one or multiple PRACH resources. Alternatively,  one or multiple security levels may be associated with one PRACH resource. The UE 104 may transmit a PRACH (i.e., the preamble) in the selected PRACH occasion. The base station 102 can determine the security level based on the preamble and / or selected PRACH occasion.

[0046] In one implementation, the security mode is associated with PRACH resources. The security mode may be associated with one or multiple PRACH resources (e.g., security mode is required) . While some other PRACH resources may imply that the security mode is not required. The UE 104 may transmit a PRACH (i.e., the preamble) in the selected PRACH occasion. The base station 102 can determine whether security mode is required by the UE 104 based on the preamble and / or selected PRACH occasion.

[0047] FIG. 3 illustrates an example diagram illustrating different security levels. In the example of FIG. 3, there are six PRACH occasions, i.e., RO#0, RO#1, RO#2, RO#3, RO#4 and RO#5. Security level 0 is associated with RO#0 and RO#1; security level 1 is associated with RO#2 and RO#3; and security level 2 is associated with RO#4 and RO#5. Security level 0 may imply a lowest security requirement, e.g., no need to activate the security mode. Security level 2 may imply the highest security requirement. For example, if the UE 104 sends the preamble in RO#2, then the base station 102 can understand that this UE 104 requires security level 1.

[0048] In one implementation, the UE 104 may indicate the security information to the base station 102 via Msg3 or PUSCH scheduled by Random Access Response (RAR) Uplink (UL) grant. Msg3 can be message transmitted on UL-SCH containing a C-RNTI MAC CE or CCCH SDU, submitted from an upper layer and associated with the UE Contention Resolution Identity, as part of a random access procedure.

[0049] In one implementation, the security information may be associated with the scheduling request or PUCCH resource carrying the scheduling request. The UE 104 may indicate the security information to the base station 102 via scheduling request. Alternatively, the UE 104 indicates the security information to the base station 102 via the PUCCH resource where the UE 104 sends the scheduling request.

[0050] Security levels may be associated with scheduling request or PUCCH resources. One security level may be associated with one or multiple PUCCH resources. Alternatively, one or multiple security levels may be associated with one PUCCH resource. The UE 104 may send the scheduling request in the PUCCH resource. The base station 102 can determine the security level based on the PUCCH resource, where the UE 104 sends the scheduling request.

[0051] In one implementation, the security mode may be associated with scheduling request or PUCCH resources. The security mode can be associated with one or multiple PUCCH resources (e.g., security mode is required) . While some other PUCCH resources may imply that the security mode is not required. The UE 104 transmits a PUCCH carrying the scheduling request in the PUCCH resource. The base station 102 can determine whether the security mode is required by the UE 104 based on the PUCCH resource where the UE 104 sends the scheduling request.

[0052] In one implementation, the UE 104 may indicate the security information via UE capability report or UE assistance information report.

[0053] In one implementation, the UE 104 may report the fingerprint information via a lower layer or for a lower layer. The base station 102 may determine whether a lower layer is transmitted by the UE 104 via fingerprint information. The fingerprint information may comprise characteristics of channel or device (e.g., radio frequency characteristics) .

[0054] In addition to the security information, the UE 104 may also indicate the security capability for a physical channel or signal to the base station 102. The security capability may indicate whether the UE 104 supports security command for a physical channel or signal, whether the UE 104 supports security level or security mode for uplink transmission or downlink transmission, etc.

[0055] In one implementation, the UE 104 may report the fingerprint information to the base station 102. The base station 102 may indicate a configuration of reference signal or sequence for the UE 104, where the configuration may comprise time or frequency domain resource of the reference signal or sequence. The UE 104 transmits the reference signal or  sequence according to the configuration to the base station 102. The base station 102 may receive the reference signal or sequence and determines the fingerprint of the UE 104. In various embodiments, this may be applied in combination with the above methods. However, in other examples, this may be applied independently.

[0056] As such, in accordance with various embodiments, a method performed by a wireless terminal device 104 (e.g., UE 104) , includes indicating, to a wireless access network node (WANN) 102 (e.g., base station 102) , security information for a lower layer, wherein the security information comprises a security level and / or a security mode. Similarly, a method performed by the WANN 102 includes receiving, from the wireless terminal device 104, an indication of security information for a lower layer, wherein the security information comprises a security level and / or a security mode.

[0057] In various embodiments, the methods include the wireless terminal device 104 indicating, and the WANN 102 receiving an indication of, the security level by a number, wherein a greater number implies a higher security level than a smaller number. Similarly, the methods may include the wireless terminal device 104 indicating, and the WANN 102 receiving an indication of, the security mode by indicating a security mode request or indicating whether the security mode is required. In various embodiments of the method, the security information is associated with a repetition number of preambles or a repetition number of Msg3, msg-A or msg-A PUSCH. In other embodiments, the security level or the security mode is associated with the repetition number of preambles, the repetition number of msgA, the repetition number of msg-A PUSCH, or the repetition number of Msg3. In certain embodiments of the method, the security information is associated with PRACH resources, wherein the PRACH resources may comprise PRACH occasions or preambles. In more specific embodiments, the security level or the security mode is associated with the PRACH resources.

[0058] In various embodiments, the methods include the wireless terminal device 104 indicating, and the WANN 102 receiving an indication of, the security information via Msg3 or PUSCH scheduled by Random access response (RAR) Uplink (UL) grant. In various embodiments of the methods, the security information is associated with a scheduling request  or a PUCCH resource carrying the scheduling request. In other embodiments, the security level or the security mode is associated with the scheduling request or the PUCCH resource. In various embodiments, the methods include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, a configuration of a reference signal or sequence for fingerprint information for the wireless terminal device, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence. The methods also may include the wireless terminal device 104 transmitting, and the WANN 102 receiving, the reference signal or sequence.

[0059] Embodiment 2 -Base station indicating security command to the UE.

[0060] In a second approach, the base station 102 indicates a security command to the UE 104 for a lower layer, and the UE 104 receives the security command for the lower layer. The security command may comprise a security level or a security mode. In response to a security level, the UE 104 may apply the security level for the uplink transmission or downlink transmission. In response to a security mode, the UE 104 may activate or deactivate the security mode based on the security command. For example, if the base station 102 indicates a security mode or normal mode, the UE 104 can activate or deactivate the security mode, respectively.

[0061] In another implementation, the base station 102 may indicate a security command to the UE 104 for a lower layer. The UE 104 may receive the security command for the lower layer. The security command may comprise a security level or a security mode. In an example, only when both conditions C1 and C2 are satisfied, the UE 104 may transmit security related information.

[0062] In response to a security level, the UE may apply the security level for the uplink transmission or downlink transmission. The UE 104 may perform transmission with security information when the UL transmission security level is lower than the indicated security level or, in another example, larger than the indicated security level. (E. g., condition C1. )

[0063] In response to a security mode, the UE 104 may activate or deactivate the security  mode based on the security command. For example, if the base station 102 indicates a security mode or normal mode, the UE 104 may activate or deactivate the security mode, respectively. When the security mode is set as activated, the UE may enter security mode. (E.g., condition C2. ) The security mode information can be carried in a synchronization block, DCI, or PDSCH.

[0064] In various examples, the security command may be carried by one of the following:

[0065] -Downlink Control Information (DCI) .

[0066] -MAC-CE.

[0067] –RRC.

[0068] -Combination of MAC-CE and DCI, e.g., MAC-CE indicates a set of applicable security levels and DCI indicates which security level from the applicable security levels is applied for the particular physical channel or signal.

[0069] -Combination of RRC and DCI, e.g., RRC indicates a set of applicable security levels and DCI indicates which security level is applied for the particular physical channel or signal, or RRC indicates whether the security mode is applicable, and DCI indicates whether security mode is activated for the particular physical channel or signal.

[0070] -Combination of RRC and MAC-CE, e.g., RRC indicates a set of applicable security levels and MAC-CE indicates which security level is applied for the particular physical channel or signal, or RRC indicates whether the security mode is applicable and MAC-CE indicates whether security mode is activated for the particular physical channel or signal.

[0071] -Combination of RRC, MAC-CE and DCI, e.g., RRC indicates a set of applicable security levels, MAC-CE indicates a subset of security levels from the set of applicable security levels, and DCI indicates which security level from the subset of security levels is applied for the particular physical channel or signal. In this case, the field size of DCI can be reduced.

[0072] In the following examples, the security command is carried by DCI or RRC. However, the security command in the following examples can also be carried by MAC-CE, a combination of MAC-CE and DCI, a combination of RRC and DCI, a combination of RRC and MAC-CE, or a combination of RRC, MAC-CE and DCI.

[0073] Configured grant uplink transmission

[0074] In one implementation, the base station 102 indicates the security command for the configured uplink transmission via RRC or broadcast / groupcast information. Each configured uplink transmission may be associated with one security level. Alternatively, each configured uplink transmission may be associated with a security mode.

[0075] In one implementation, the base station 102 indicates the security command for the configured uplink transmission via DCI. DCI may be used to indicate the security level or the security mode of the configured uplink transmission. One DCI can activate or deactivate a configured uplink transmission when the UL transmission security level is lower than the indicated security level or, in another example, larger than the indicated security level. One DCI can activate or deactivate configured uplink transmissions with the same security level simultaneously. One DCI can activate or deactivate configured uplink transmissions with the same security mode simultaneously.

[0076] Downlink semi-persistent transmission

[0077] In one implementation, the base station 102 indicates the security command for the downlink semi-persistent transmission via RRC. Each downlink semi-persistent transmission may be associated with one security level. Alternatively, each downlink semi-persistent transmission may be associated with a security mode.

[0078] In one implementation, the base station 102 indicates the security command for the downlink semi-persistent transmission via DCI. DCI may be used to indicate the security level or the security mode of the downlink semi-persistent transmission. One DCI can activate or deactivate downlink semi-persistent transmissions with the same security level simultaneously. One DCI can activate or deactivate downlink semi-persistent transmissions with the same security mode simultaneously.

[0079] In one implementation, the base station 102 indicates the security command for downlink transmission or uplink transmission to the UE 104 via lower layer. The downlink transmission may comprise PDSCH, PDCCH, or downlink reference signals. The uplink transmission may comprise PUSCH, PUCCH, or uplink reference signals.

[0080] Security command for uplink transmission

[0081] In one implementation, the base station 102 indicates the security command (e.g., security level or security mode) for the uplink transmission via DCI. The security command may be associated with a number of time / frequency resources. The UE 104 may transmit reference signal or sequence in the associated time / frequency resources and transmit the uplink transmission to the base station 102. The time / frequency resources can be used for the base station 102 to determine the fingerprint information and to determine whether the UE 104 is the target UE or a fake UE.

[0082] In one implementation, the security command (e.g., security level or security mode ) is associated with a number of symbols at the beginning of the uplink transmission. Each security level may be associated with a number of symbols. Since these symbols are located at the beginning of the uplink transmission, the base station 102 can quickly determine whether this UE 104 is the target UE.

[0083] In one alternative, the base station 102 may indicate L symbols for the uplink transmission, where L is an integer number larger than 0. The number of symbols associated with the security level is M, where M is an integer number not smaller than 0, and M is smaller than L. The UE 104 may transmit the reference signal or sequence in the first M symbols among the L symbols for the uplink transmission, and may transmit the uplink transmission in the remaining L-M symbols.

[0084] In another alternative, the UE 104 may transmit the reference signal or sequence in the M symbols before the L symbols for the uplink transmission, and transmits the uplink transmission in the L symbols.

[0085] In another alternative, the 104 UE may transmit the reference signal or sequence in the first M symbols of the L symbols for the uplink transmission and transmits the uplink  transmission in the L symbols after the reference signal or sequence.

[0086] In one implementation, the security command (e.g., security level or security mode) is associated with a number of resource elements or resource blocks before the uplink transmission. Each security level may be associated with a number of resource elements or resource blocks. Because these resource elements or resource blocks are located before the uplink transmission, the base station 102 can quickly determine whether this UE 104 is the target UE.

[0087] In one implementation, the security command (e.g., security level or security mode) is associated with a number of resource elements or resource blocks within the uplink transmission. Each security level may be associated with a number of resource elements or resource blocks. Since these resource elements or resource blocks are located within the uplink transmission, the base station 102 can quickly determine whether this UE 104 is the target UE when the UE 104 transmits the uplink transmission.

[0088] In one implementation, the base station 102 may indicate the security command (e.g., security level or security mode) for the uplink transmission via DCI. The security command may be associated with a set of power control parameters. The UE 104 may transmit the uplink transmission based on the power control parameters associated with the security command. For example, different security levels may be associated with different sets candidate P0 values. Based on the indicated security level, the UE 104 may apply the corresponding P0 value.

[0089] In one implementation, the base station 102 may indicate the security command (e.g., security level or security mode) for the uplink transmission via DCI. The security command may be associated with a set of frequency hopping parameters. The UE 104 may transmit the uplink transmission based on the frequency hopping parameters associated with the security command. The hopping parameters may comprise the number of hops, the hopping offset, group hopping, sequence hopping, comb offset, cyclic shift, hopping granularity, etc. For example, different security levels may be associated with different numbers of hops. Based on the indicated security level, the UE 104 may apply the  corresponding number of hops for the uplink transmission.

[0090] Security command for downlink transmission

[0091] In one implementation, the base station 102 may indicate the security command (e.g., security level or security mode) for the downlink transmission via DCI. The security command may be associated with a number of time / frequency resources. The base station 102 may transmit reference signal or sequence in the associated time / frequency resources and transmit the downlink transmission to the UE 104. The UE 104 receives the reference signal or sequence in the associated time / frequency resources and receives the downlink transmission to the UE 104. The time / frequency resources can be used for the UE 104 to determine the fingerprint command and to determine whether the base station 102 is the target base station or a fake base station.

[0092] In one implementation, the security command (e.g., security level or security mode) is associated with a number of symbols at the beginning of the downlink transmission. Each security level may be associated with a number of symbols. Because these symbols are located at the beginning of the downlink transmission, the UE 104 can quickly determine whether this base station is the target base station.

[0093] In one alternative, the base station 102 may indicate L symbols for the downlink transmission, where L is an integer number larger than 0. The number of symbols associated with the security level is M, where M is integer number not smaller than 0, and M is smaller than L. The UE 104 may receive the reference signal or sequence in the first M symbols among the L symbols for the downlink transmission, and may receive the downlink transmission in the remaining L-M symbols.

[0094] In another alternative, the UE 104 may receive the reference signal or sequence in the M symbols before the L symbols for the downlink transmission, and may receive the downlink transmission in the L symbols.

[0095] In another alternative, the UE 104 may receive the reference signal or sequence in the first M symbols of the L symbols for the downlink transmission, and may receive the downlink transmission in the L symbols after the reference signal or sequence.

[0096] In one implementation, the security command (e.g., security level or security mode) may be associated with a number of resource elements or resource blocks before the downlink transmission. Each security level may be associated with a number of resource elements or resource blocks. Since these resource elements or resource blocks are located before the downlink transmission, the UE 104 can quickly determine whether this base station 102 is the target base station.

[0097] In one implementation, the security command (e.g., security level or security mode) may be associated with a number of resource elements or resource blocks within the downlink transmission. Each security level may be associated with a number of resource elements or resource blocks. Since these resource elements or resource blocks are located within the downlink transmission, the UE 104 can quickly determine whether this base station 102 is the target base station when the UE 104 receives the downlink transmission.

[0098] In one implementation, the base station 102 may indicate the security command (e.g., security level or security mode) for the downlink transmission via DCI. The security command may be associated with a set of quasi co-location configurations. The quasi co-location configurations may comprise reference signal for determining quasi co-location command with respect to Doppler shift, Doppler spread, average delay, delay spread, spatial RX parameters when applicable. The UE 104 receives the downlink transmission based on quasi co-location configurations associated with the security command. For example, different security levels may be associated with different sets candidate reference signals for determining quasi co-location command.

[0099] In one implementation, the base station 102 may indicate the security command (e.g., security level or security mode) for the downlink transmission via DCI. The security command may be associated with a set of frequency hopping parameters. The UE 104 may receive the downlink transmission based on the frequency hopping parameters associated with the security command. The hopping parameters may comprise the number of hops, the hopping offset, group hopping, sequence hopping, comb offset, cyclic shift, hopping granularity, etc. For example, different security levels may be associated with different numbers of hops. Based on the indicated security level, the UE 104 may apply the  corresponding number of hops for the downlink transmission.

[0100] In various embodiments, DCI is carried by PDCCH.

[0101] In some examples, if the base station 102 indicates a security level for one uplink transmission, only the data with this security level or lower than this security level can be carried by this uplink transmission.

[0102] In one implementation, if the base station 102 indicates to activate the security mode, the UE 104 receives or transmits the downlink transmission and / or uplink transmission according to the security mode until a different security command received.

[0103] In one implementation, the base station 102 indicates configuration of reference signal or sequence for the UE 104, where the configuration may comprise a time or frequency domain resource of the reference signal or sequence. In addition, the configuration may also comprise a repetition number of the reference signal or sequence. The UE 104 may transmit the reference signal or sequence according to the configuration to the base station 102. The base station 102 receives the reference signal or sequence and determines the fingerprint of the UE 104.

[0104] In one implementation, the base station 102 indicates configuration of reference signal or sequence for the UE 104, where the configuration may comprise time or frequency domain resource of the reference signal or sequence. In addition, the configuration may also comprise a repetition number of the reference signal or sequence. The base station 102 indicates the security command to the UE 104. The UE 104 transmits the reference signal or sequence according to the configuration to the base station 102. The base station 102 receives the reference signal or sequence and determines the fingerprint of the UE 104.

[0105] As such, in accordance with various embodiments, a method performed by the WANN 102 includes indicating, to the wireless terminal device 104, a security command for a lower layer, wherein the security command comprises a security level and / or a security mode. Similarly, a method performed by a wireless terminal device 104 includes receiving, from the WANN 102, an indication of a security command for a lower layer, wherein the security command comprises a security level and / or a security mode.

[0106] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security command for a configured uplink transmission via Radio Resource Control (RRC) or broadcast / groupcast information, wherein each configured uplink transmission is associated with one security level. Similarly, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security command for a downlink semi-persistent transmission via Radio Resource Control (RRC) , wherein each downlink semi-persistent transmission is associated with one security level.

[0107] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security command for an uplink transmission via DCI, wherein the security command is associated with a number of time and / or frequency resources. The methods may further include the wireless terminal device 104 transmitting, and the WANN 102 receiving, a reference signal or a sequence in the associated time and / or frequency resources, and the uplink transmission. In various embodiments of the methods, the security level and / or the security mode is associated with a number of symbols at a beginning of the uplink transmission, wherein each security level is associated with the number of symbols. In such instances, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, L symbols for the uplink transmission, wherein L is an integer larger than 0, wherein the number of symbols associated with the security level is M, and wherein M is an integer not smaller than 0 and M is smaller than L. The methods may include the wireless terminal device 104 transmitting, and the WANN 102 receiving, the reference signal or the sequence in the first M symbols among the L symbols for the uplink transmission, and the uplink transmission in a remaining L-M symbols. In various embodiments of the method, the security level and / or the security mode is associated with a number of resource elements or resource blocks within the uplink transmission.

[0108] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or the security mode  is associated with a set of power control parameters for an uplink transmission. The methods may also include the wireless terminal device 104 transmitting, and the WANN 102 receiving, the uplink transmission.

[0109] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or security mode is associated with a set of frequency hopping parameters for an uplink transmission. The methods may also include the wireless terminal device 104 transmitting, and the WANN 102 receiving, the uplink transmission.

[0110] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a number of time and / or frequency resources. The methods may also include the WANN 102 transmitting, and the wireless terminal device 104 receiving a reference signal or a sequence in the associated time and / or frequency resources, and the downlink transmission. In various embodiments, the security level and / or the security mode is associated with a number of resource elements or resource blocks within the downlink transmission.

[0111] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a set of quasi co-location configurations for a downlink transmission. The methods may also include the WANN 102 transmitting, and the wireless terminal device 104 receiving the downlink transmission.

[0112] In various embodiments, the methods may include the WANN 102 indicating, and the wireless terminal device 104 receiving an indication of, a configuration of a reference signal or a sequence, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence, and a repetition number of the reference signal or the sequence.  The methods may also include the wireless terminal device 104 transmitting, and the WANN 102 receiving the reference signal or the sequence according to the configuration. The methods may also include the WANN 102 determining a fingerprint of the wireless terminal device.

[0113] Embodiment 3 -key encryption

[0114] Encryption for uplink transmission

[0115] In a third approach, the UE 104 may encrypt or scramble the uplink transmission via a key derived by the channel information. The base station 102 may decrypt or descramble the uplink transmission via the key derived by the channel information. The key can be a sequence or other types of key. The key may be symmetric or asymmetric between the UE 104 and the base station 102. Because the channel information changes dynamically, it is difficult for a fake UE or fake base station to acquire the key derived from the channel information.

[0116] The channel information can be downlink channel information or uplink information. As long as the base station 102 and UE 104 have the same understanding of the channel information, the uplink transmission can be successfully decrypted or descrambled. The channel information can be the channel matrix or information derived from the channel matrix, e.g., eigen vector of the channel matrix, Signal to Interference & Noise Ratio (SINR) , Signal to Noise Ratio (SNR) , Reference Signal Received Power (RSRP) , Received Signal Strength Indicator (RSSI) , Reference Signal Received Quality (RSRQ) , Precoding Matrix Indicator (PMI) , rank indicator, etc.

[0117] In one implementation, the channel information is the latest channel information the UE 104 receives from the base station 102 or that the UE 104 derives. Alternatively, the channel information may be the latest channel information the base station 102 receives from the UE 104 or that the base station 102 derives.

[0118] In one implementation, the channel information for deriving the key is the channel information at a time / frequency resource, where the time / frequency resource is determined by a rule by considering the at least one of the following of the uplink transmission:

[0119] -The time domain information of the uplink transmission, e.g., the slot index, symbol index, number of symbols, number of slots, repetition number, etc.

[0120] -The frequency domain information of the uplink transmission, e.g., the resource element index, resource block index, number of resource elements, number of resource blocks, number of hops, hopping offset.

[0121] -The spatial domain information of the uplink transmission, e.g., the number of layers, number of codebooks, number of ports, etc.

[0122] In one implementation, the UE 104 may encrypt or scramble the uplink transmission via a scrambling sequence from a set of scrambling sequences. The base station 102 may decrypt or descramble the uplink transmission via the scrambling sequence. The set of scrambling sequences can be indicated by the base station 102 or predefined. The scrambling sequence for encryption or scrambling may be selected from the set of scrambling sequences by a rule by considering at least one of the following:

[0123] -The time domain information of the uplink transmission, e.g., the slot index, symbol index, number of symbols, number of slots, repetition number, etc.

[0124] -The frequency domain information of the uplink transmission, e.g., the resource element index, resource block index, number of resource elements, number of resource blocks, number of hops, hopping offset.

[0125] -The spatial domain information of the uplink transmission, e.g., the number of layers, number of codebooks, number of ports, etc.

[0126] In one implementation, the UE 104 may encrypt or scramble the uplink transmission via a key or via a scrambling sequence from a set of scrambling sequences in response to one of the following:

[0127] –The base station 102 indicates security mode for one uplink transmission.

[0128] –The base station 102 indicates a security level for one uplink transmission.

[0129] –The base station 102 activates security mode.

[0130] –The base station 102 indicates a security level.

[0131] –The base station 102 indicates a security level higher than (or not lower than) X, where X is indicated by base station or predefined.

[0132] –The UE 104 indicates security mode for one uplink transmission.

[0133] –The UE 104 indicates a security level for one uplink transmission.

[0134] –The UE 104 activates security mode.

[0135] –The UE 104 indicates a security level.

[0136] –The UE 104 indicates a security level higher than (or not lower than) X, where X is indicated by base station or predefined.

[0137] As such, in accordance with various embodiments, a method performed by the wireless terminal device 104 includes encrypting or scrambling an uplink transmission to a wireless access network node via a key derived by channel information, wherein the wireless access network node decrypts or descrambles the uplink transmission via the key derived by the channel information. In various embodiments of the method, the channel information is downlink channel information or uplink information. In various embodiments of the method, the channel information is a channel matrix or information derived from the channel matrix. In various embodiments of the method, the channel information is a latest channel information received by the wireless terminal device from the wireless access network node or derived by the wireless terminal device. In various embodiments of the method, the channel information for deriving the key is channel information at a time and / or frequency resource, wherein the time and / or frequency resource is determined by a rule in view of at least one of the following of the uplink transmission: time domain information of the uplink transmission; frequency domain information of the uplink transmission; and / or spatial domain information of the uplink transmission.

[0138] A method performed by the wireless terminal device 104 includes encrypting or scrambling an uplink transmission to the WANN 102 via a scrambling sequence from a set of scrambling sequences, wherein the WANN 102 decrypts or descrambles the uplink  transmission via the scrambling sequence, wherein the set of scrambling sequences are indicated by the WANN 102 or predefined, and wherein the scrambling sequence for encryption or scrambling is selected from the set of scrambling sequences by a rule in view of at least one of the following: time domain information of the uplink transmission; frequency domain information of the uplink transmission; and / or spatial domain information of the uplink transmission.

[0139] A method performed by the wireless terminal device 104 includes encrypting or scrambling an uplink transmission to the WANN 102 via a key or a scrambling sequence from a set of scrambling sequences in response to at least one of the following: receiving, from the WANN 102, an activation of a security mode; receiving, from the WANN 102, an indication of a security level; or receiving, from the WANN 102 , an indication of a security level higher than or equal to X, where X is indicated by the WANN 102 or is predefined. In various embodiments the method includes the wireless terminal device 104 applying the encryption, decryption, scrambling or descrambling to a subset of the data carried by the uplink transmission. In various embodiments the method includes the wireless terminal device 104 receiving, from the WANN 102, an indication of a number between 0 and 1 to indicate a portion of the uplink transmission to which to apply the encryption, decryption, scrambling or descrambling via DCI, MAC-CE, or RRC.

[0140] Encryption for downlink transmission

[0141] In one implementation, the base station 102 may encrypt or scramble the downlink transmission via a key derived by the channel information. The UE 104 may decrypt or descramble the downlink transmission via the key derived by the channel information. The key can be a sequence or other types of key. The key may be symmetric or asymmetric between the UE 104 and the base station 102.

[0142] In one implementation, the channel information is the latest channel information the UE 104 receives from the base station 102 or is derived by the UE 104. Alternatively, the channel information is the latest channel information the base station 102 receives from the UE 104 or is derived by the base station 102.

[0143] In one implementation, the channel information for deriving the key is the channel information at a time / frequency resource, where the time / frequency resource is determined by a rule by considering at least one of the following of the downlink transmission:

[0144] -The time domain information of the downlink transmission, e.g., the slot index, symbol index, number of symbols, number of slots, repetition number, etc.

[0145] –The frequency domain information of the downlink transmission, e.g., the resource element index, resource block index, number of resource elements, number of resource blocks, number of hops, hopping offset.

[0146] –The spatial domain information of the downlink transmission, e.g., the number of layers, number of codebooks, number of ports, etc.

[0147] In one implementation, the base station 102 may encrypt or scramble the downlink transmission via a scrambling sequence from a set of scrambling sequences. The UE 104 may decrypt or descramble the downlink transmission via the scrambling sequence. The set of scrambling sequences can be indicated by the base station 102 or predefined. The scrambling sequence may be selected from the set of scrambling sequences by considering at least one of the following:

[0148] -The time domain information of the downlink transmission, e.g., the slot index, symbol index, number of symbols, number of slots, repetition number, etc.

[0149] -The frequency domain information of the downlink transmission, e.g., the resource element index, resource block index, number of resource elements, number of resource blocks, number of hops, hopping offset.

[0150] -The spatial domain information of the downlink transmission, e.g., the number of layers, number of codebooks, number of ports, etc.

[0151] In one implementation, the UE 104 may decrypt or descramble the downlink transmission via a scrambling sequence from a set of scrambling sequences in response to one of the following:

[0152] -The base station 102 indicates security mode for one downlink transmission.

[0153] -The base station 102 indicates a security level for one downlink transmission.

[0154] -The base station 102 activates security mode.

[0155] -The base station 102 indicates a security level.

[0156] -The base station 102 indicates a security level higher than (or not lower than) X, where X is indicated by base station or predefined.

[0157] -The UE 104 indicates security mode for one downlink transmission.

[0158] -The UE 104 indicates a security level for one downlink transmission.

[0159] -The UE 104 activates security mode.

[0160] -The UE 104 indicates a security level.

[0161] -The UE 104 indicates a security level higher than (or not lower than) X, where X is indicated by base station or predefined.

[0162] In one implementation, the encryption, decryption, scrambling, or descrambling applies to all the data carried by the downlink transmission or the uplink transmission. However, a larger size of data will result in a larger processing delay. In order to further reduce the processing delay, one potential enhancement is to apply the encryption, decryption, scrambling, or descrambling to a subset of the data carried by the downlink transmission or uplink transmission (e.g., rather than the entirety of the data) .

[0163] As one alternative, the subset of the data carried by the downlink transmission or the uplink transmission can be indicated by the base station 102. The base station 102 may indicate a number between 0 and 1 to indicate the portion to which needs to apply the encryption, decryption, scrambling, or descrambling via DCI, MAC-CE or RRC. For example, if the base station 102 indicates the first 50%of the data is encrypted for a downlink transmission, then the UE 104 would need to decrypt the first 50%of the downlink transmission. If the base station 102 indicates the first 50%of the data is encrypted for an uplink transmission, then the UE 104 would need to encrypt the first 50%of the uplink transmission.

[0164] All the embodiments can be separately applied or combined. FIG. 4 illustrates an example flow diagram in accordance with various embodiments, which shows an example of combining embodiments 1, 2, and 3. As shown in FIG. 4, in step 1, the UE 104 first indicates the security information to the base station 102. Based on the security information, the base station 102 learns that the UE’s 104 information may be important or sensitive. In step 2, the base station 102 indicates to the UE 104 to move into security mode. After that, the UE 104 encrypts its uplink data as in step 3.

[0165] As such, in accordance with various embodiments, a method performed by the WANN 102 includes encrypting or scrambling a downlink transmission to the wireless terminal device 104 via a key derived by channel information, wherein the wireless terminal device 104 decrypts or descrambles the downlink transmission via the key. In various embodiments of the method, the channel information is a latest channel information received by the wireless terminal device 104 from the WANN 102 or derived by the wireless terminal device 104. In various embodiments of the method, the channel information for deriving the key is channel information at a time and / or frequency resource, wherein the time and / or frequency resource is determined by a rule in view of at least one of the following of the downlink transmission: time domain information of the downlink transmission; frequency domain information of the downlink transmission; and / or spatial domain information of the downlink transmission.

[0166] A method performed by the WANN 102 may include encrypting or scrambling a downlink transmission to a wireless terminal device 104 via a scrambling sequence from a set of scrambling sequences, wherein the wireless terminal device 104 decrypts or descrambles the downlink transmission via the scrambling sequence, wherein the set of scrambling sequences are indicated by the WANN 102 or predefined, and wherein the scrambling sequence for encryption or scrambling is selected from the set of scrambling sequences by a rule in view of at least one of the following: time domain information of the downlink transmission; frequency domain information of the downlink transmission; and / or spatial domain information of the downlink transmission. In various embodiments, the method may include the WANN 102 transmitting, to the wireless terminal device 104, an activation of a security  mode; indicating, to the wireless terminal device 104, an indication of a security level; or indicating, to the wireless terminal device 104, a security level higher than or equal to X, where X is indicated by the wireless access network node or is predefined. The wireless terminal device 104 responsively decrypts or descrambles the downlink transmission via the scrambling sequence in response to one or more of the above transmissions. In various embodiments of the method, the encryption, decryption, scrambling, or descrambling is applied to a subset of the data carried by the downlink transmission. In various embodiments, the method includes the WANN 102 indicating, to the wireless terminal device 104, a number between 0 and 1 to indicate a portion of the downlink transmission to which to apply the encryption, decryption, scrambling or descrambling via DCI, MAC-CE, or RRC.

[0167] Embodiment 4 -Actions related to security information / command or key encryption

[0168] In a fourth approach, the base station 102 may determine not to serve one UE if the fingerprint information of this UE is not consistent with the target UE. The base station 102 may determine not to serve one UE if the encryption of this UE is not consistent with the target UE.

[0169] In various embodiments, which may be combined with or applicable to embodiments 1, 2, and 3 discussed above, the UE 104 may report security issue to the higher layer if the security check (e.g., fingerprint information or encryption) failed for M times, where M is integer number larger than 0. The value M can be indicated by the base station 102 or predefined.

[0170] As such, in accordance with various embodiments, a method, or the methods discussed above with respect to Embodiments, 1, 2, and 3, may include the wireless terminal device 104 reporting a security issue to a higher layer if a security check fails for M times, wherein M is an integer number larger than 0, and wherein a value of M is indicated by the WANN 102 or is predefined.

[0171] The description and accompanying drawings above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is  intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.

[0172] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment / implementation / example / approach” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation / example / approach” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.

[0173] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.

[0174] Reference throughout this specification to features, advantages, or similar language  does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.

[0175] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the present solution can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.

Claims

1.A method performed by a wireless terminal device comprising:indicating, to a wireless access network node, security information for a lower layer,wherein the security information comprises a security level and / or a security mode.2.The method according to claim 1, comprising:indicating, to the wireless access network node, the security level by a number, wherein a greater number implies a higher security level than a smaller number.3.The method according to claim 1, comprising:indicating, to the wireless access network node, the security mode by indicating a security mode request or indicating whether the security mode is required.4.The method according to claim 1,wherein the security information is associated with a repetition number of preambles or a repetition number of Msg3, msg-A or msg-A PUSCH.5.The method according to claim 4,wherein the security level or the security mode is associated with the repetition number of preambles, the repetition number of msgA, the repetition number of msg-A PUSCH, or the repetition number of Msg3.6.The method according to claim 1,wherein the security information is associated with PRACH resources, wherein the PRACH resources may comprise PRACH occasions or preambles.7.The method according to claim 6,wherein the security level or the security mode is associated with the PRACH resources.8.The method according to claim 1,wherein the security information is associated with a scheduling request or a PUCCH resource carrying the scheduling request.9.The method according to claim 8,wherein the security level or the security mode is associated with the scheduling request or the PUCCH resource.10.The method according to claim 1, comprising:receiving, from the wireless access network node, an indication of a configuration of a reference signal or sequence for fingerprint information for the wireless terminal device, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence; andtransmitting, to the wireless access network node, the reference signal or sequence.11.A method performed by a wireless access network node comprising:receiving, from a wireless terminal device, an indication of security information for a lower layer,wherein the security information comprises a security level and / or a security mode.12.A method performed by a wireless access network node comprising:indicating, to a wireless terminal device, a security command for a lower layer,wherein the security command comprises a security level and / or a security mode.13.The method according to claim 12, comprising:indicating, to the wireless terminal device, the security command for an uplink transmission via DCI, wherein the security command is associated with a number of time and / or frequency resources;receiving, from the wireless terminal device, a reference signal or a sequence in the associated time and / or frequency resources; andreceiving, from the wireless terminal device, the uplink transmission.14.The method according to claim 13,wherein the security level and / or the security mode is associated with a number of symbols at a beginning of the uplink transmission, wherein each security level is associated with the number of symbols.15.The method according to claim 14, comprising:indicating, to the wireless terminal device, L symbols for the uplink transmission, wherein L is an integer larger than 0,wherein the number of symbols associated with the security level is M, wherein M is an integer not smaller than 0 and M is smaller than L; andreceiving, from the wireless terminal device, the reference signal or the sequence in the first M symbols among the L symbols for the uplink transmission, and the uplink transmission in a remaining L-M symbols.16.The method according to claim 12, comprising:indicating, to the wireless terminal device, the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or the security mode is associated with a set of power control parameters for an uplink transmission; andreceiving, from the wireless terminal device, the uplink transmission.17.The method according to claim 12, comprising:indicating, to the wireless terminal device, the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or security mode is associated with a set of frequency hopping parameters for an uplink transmission; andreceiving, from the wireless terminal device, the uplink transmission.18.The method according to claim 12, comprising:indicating, to the wireless terminal device, the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a number of time and / or frequency resources;transmitting, to the wireless terminal device, a reference signal or a sequence in the associated time and / or frequency resources; andtransmitting, to the wireless terminal device, the downlink transmission.19.The method according to claim 12, comprising:indicating, to the wireless terminal device, the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a set of quasi co-location configurations for a downlink transmission; andtransmitting, to the wireless terminal device, the downlink transmission.20.The method according to claim 12, comprising:indicating, to the wireless terminal device, a configuration of a reference signal or a sequence, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence, and a repetition number of the reference signal or the sequence;receiving, from the wireless terminal device, the reference signal or the sequence according to the configuration; anddetermining a fingerprint of the wireless terminal device.21.A method performed by a wireless terminal device comprising:receiving, from a wireless access network node, an indication of a security command for a lower layer,wherein the security command comprises a security level and / or a security mode.22.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security command for a configured uplink transmission via Radio Resource Control (RRC) or broadcast / groupcast information, wherein each configured uplink transmission is associated with one security level.23.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security command for a downlink semi-persistent transmission via Radio Resource Control (RRC) , wherein each downlink semi-persistent transmission is associated with one security level.24.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security command for an uplink transmission via DCI, wherein the security command is associated with a number of time and / or frequency resources;transmitting, to the wireless access network node, a reference signal or a sequence in the associated time and / or frequency resources; andtransmitting, to the wireless access network node, the uplink transmission.25.The method according to claim 24,wherein the security level and / or the security mode is associated with a number of symbols at a beginning of the uplink transmission, wherein each security level is associated with the number of symbols.26.The method according to claim 25, comprising:receiving, from the wireless access network node, an indication of L symbols for the uplink transmission, wherein L is an integer larger than 0,wherein the number of symbols associated with the security level is M, wherein M is an integer not smaller than 0 and M is smaller than L; andtransmitting, to the wireless access network node, the reference signal or the sequence in the first M symbols among the L symbols for the uplink transmission, and the uplink transmission in a remaining L-M symbols.27.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or the security mode is associated with a set of power control parameters for an uplink transmission; andtransmitting, to the wireless access network node, the uplink transmission.28.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security level and / or the security mode for an uplink transmission via DCI, wherein the security level and / or security mode is associated with a set of frequency hopping parameters for an uplink transmission; andtransmitting, to the wireless access network node, the uplink transmissions.29.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a number of time and / or frequency resources;receiving, from the wireless access network node, a reference signal or a sequence in the associated time and / or frequency resources; andreceiving, from the wireless access network node, the downlink transmission.30.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of the security level and / or the security mode for a downlink transmission via DCI, wherein the security level and / or the security mode is associated with a set of quasi co-location configurations for a downlink transmission; andreceiving, from the wireless access network node, the downlink transmission.31.The method according to claim 21, comprising:receiving, from the wireless access network node, an indication of a configuration of a reference signal or a sequence, wherein the configuration comprises a time or frequency domain resource of the reference signal or the sequence, and a repetition number of the reference signal or the sequence; andtransmitting, to the wireless access network node, the reference signal or the sequence according to the configuration;wherein the wireless access network node determines a fingerprint of the wireless terminal device.32.The method according to any of claims 12 to 31,wherein the wireless terminal device reports a security issue to a higher layer if a security check fails for M times, wherein M is an integer number larger than 0, and wherein a value of M is indicated by the wireless access network node or is predefined.33.A method performed by a wireless terminal device comprising:encrypting or scrambling an uplink transmission to a wireless access network node via a key derived by channel information,wherein the wireless access network node decrypts or descrambles the uplink transmission via the key derived by the channel information.34.The method according to claim 33,wherein the channel information is downlink channel information or uplink information.35.The method according to claim 33,wherein the channel information for deriving the key is channel information at a time and / or frequency resource, wherein the time and / or frequency resource is determined by a rule in view of at least one of the following of the uplink transmission:time domain information of the uplink transmission;frequency domain information of the uplink transmission; and / orspatial domain information of the uplink transmission.36.A method performed by a wireless terminal device comprising:encrypting or scrambling an uplink transmission to a wireless access network node via a scrambling sequence from a set of scrambling sequences,wherein the wireless access network node decrypts or descrambles the uplink transmission via the scrambling sequence,wherein the set of scrambling sequences are indicated by the wireless access network node or predefined, andwherein the scrambling sequence for encryption or scrambling is selected from the set of scrambling sequences by a rule in view of at least one of the following:time domain information of the uplink transmission;frequency domain information of the uplink transmission; and / orspatial domain information of the uplink transmission.37.A method performed by a wireless terminal device comprising:encrypting or scrambling an uplink transmission to a wireless access network node via a key or a scrambling sequence from a set of scrambling sequences in response to at least one of the following:receiving, from the wireless access network node, an activation of a security mode;receiving, from the wireless access network node, an indication of a security level; orreceiving, from the wireless access network node, an indication of a security level higher than or equal to X, where X is indicated by the wireless access network node or is predefined.38.The method according to any of claims 33 to 37, comprising:applying the encryption, decryption, scrambling or descrambling to a subset of the data carried by the uplink transmission.39.The method according to 38, comprising:receiving, from the wireless access network node, an indication of a number between 0 and 1 to indicate a portion of the uplink transmission to which to apply the encryption, decryption, scrambling or descrambling via DCI, MAC-CE, or RRC.40.A method performed by a wireless access network node comprising:encrypting or scrambling a downlink transmission to a wireless terminal device via a key derived by channel information,wherein the wireless terminal device decrypts or descrambles the downlink transmission via the key.41.The method according to any of claims 33 to 40,wherein the wireless terminal device reports a security issue to a higher layer if a security check fails for M times, wherein M is an integer number larger than 0, and wherein a value of M is indicated by the wireless access network node or is predefined.42.An apparatus for wireless communication comprising a processor that is configured to carry out the method of any of claims 1 to 41.43.A non-transitory computer readable medium having code stored thereon, the code when executed by a processor, causing the processor to implement the method recited in any of claims 1 to 41.

Citation Information

Patent Citations

  • Data transmission method, related devices and system

    CN109391342A

  • Method and apparatus for performing paging in mobile communication system

    CN109792689A

  • Method and apparatus for indicating restricted resources of wireless terminal

    CN112313981A

  • Secure key generation in wireless networks

    CN114514726A

  • Data scrambling method and device, data descrambling method and device and storage medium

    CN115988484A