Security protection for mac ce
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-22
- Publication Date
- 2026-08-13
Smart Images

Figure CN2025129344_13082026_PF_FP_ABST
Abstract
Description
SECURITY PROTECTION FOR MAC CETECHNICAL FIELD
[0001] The present disclosure relates to wireless communications, and more specifically to devices for wireless communication and methods for supporting security protection for MAC CEs.BACKGROUND
[0002] A wireless communications system may include one or multiple network communication devices, such as base stations, which may be otherwise known as an eNodeB (eNB) , a next-generation NodeB (gNB) , or other suitable terminology. Each network communication devices, such as a base station may support wireless communications for one or multiple user communication devices, which may be otherwise known as UE, or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers) . Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G) ) .
[0003] It is suggested to provide security protection for some medium access control control elements (MAC CEs) e.g. layer 1 or layer 2 triggered mobility (LTM) cell switching command MAC CE. There is a need to study how to handle one or more MACs CE with security protection if security protection for the one or more MAC CEs fails.SUMMARY
[0004] The present disclosure relates to devices for wireless communication and methods that support security protection for MAC CEs. With the present disclosure, the MAC CEs with security protection may be handled properly.
[0005] Some implementations of a first device for wireless communication described herein may include a processor and a transceiver coupled to the processor, wherein the processor is configured to: receive a first medium access control protocol data unit (MAC PDU) via the transceiver from a second device for wireless communication, wherein the first MAC PDU comprises MAC CEs with security protection; and based on determining that security protection for at least one first MAC CE among the MAC CEs fails, perform at least one of the following: transmitting, via the transceiver to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication via the transceiver from the second device, or discarding the at least one first MA C CE.
[0006] In some implementations, the processor is further configured to: based on determining that security protection for one or more of the MAC CEs fails, determine the security protection for the MAC CEs fails.
[0007] In some implementations, the processor is further configured to: based on determining that security protection for at least a first number of MAC CE among the MAC CEs or for at least a first percentage of the MAC CEs succeeds, determine the security protection for the MAC CEs succeeds.
[0008] In some implementations, the processor is further configured to: receive a configuration for the first number or the first percentage via the transceiver from the second device.
[0009] In some implementations, the processor is further configured to: determine the security protection for at least one first MAC CE fails; determine security protection for at least one second MAC CE succeeds. In such implementations, the feedback associated with results of the security protection for the MAC CEs comprises at least one of the following: at least one result of the security protection for the at least one first MAC CE, or at least one result of the security protection for the at least one second MAC CE.
[0010] In some implementations, the feedback associated with results of the security protection for the MAC CEs comprises one of the following indicating the security protection for the MAC CEs succeeds or fails: a logical channel identity (LCID) associated with one of the MAC CEs, or an extended logical channel identity (eLCID) associated with one of the MAC CEs.
[0011] In some implementations, the processor is configured to transmit the feedback associated with results of the security protection for the MAC CEs via a MAC CE, wherein the MAC CE comprises a bitmap, a bit of the bitmap is associated with a respective one of the MAC CEs and indicates that the security protection for the respective one of the MAC CE succeeds or fails.
[0012] In some implementations, bits of the bitmap are arranged in the same order as the MAC CEs are assembled in the first MAC PDU.
[0013] In some implementations, the processor is further configured to: based on determining that the security protection for the at least one first MAC CE among the MAC CEs fails, transmit a first indication via the transceiver to the second device, wherein the first indication indicates a transmission or retransmission of content related to the at least one first MAC CE with security protection.
[0014] In some implementations, a type of the at least one first MAC CE which can be retransmitted or transmitted again with security protection is predefined or preconfigured.
[0015] In some implementations, the processor is further configured to: based on determining that the security protection for the at least one first MAC CE among the MAC CEs fails, transmit a second indication via the transceiver to the second device, wherein the second indication indicates one of the following: at least one security key for the at least one first MAC CE is to be updated, the at least one security key for the at least one first MAC CE and a security key for access stratum (AS) of the second device are to be updated, and the at least one security key for the at least one first MAC CE and a security key for a radio resource control (RRC) layer of the second device are to be updated;
[0016] In some implementations, the processor is further configured to: based on determining that the security protection for the at least one first MAC CE among the MAC CEs fails, transmit a third indication via the transceiver to the second device, wherein the third indication indicates one of the following: at least one security key for the at least one first MAC CE is to be reset, the at least one security key for the at least one first MAC CE and the security key for AS are to be reset, and the at least one security key for the at least one first MAC CE and the security key for the RRC layer are to be reset.
[0017] In some implementations, the at least one security key for the at least one first MAC CE is the same as or separate from the security key for AS of the second device.
[0018] In some implementations, the processor is further configured to: receive the transmission or retransmission of the at least one first MAC CE via the transceiver from the second device by: receiving a second MAC PDU on a dedicated resource via the transceiver from the second device, wherein at least one third MAC CE is multiplexed in the second MAC PDU, each of at least one third MAC CE comprises contents in a respective one of the at least one first MAC CE.
[0019] In some implementations, it is predefined or configured to allow the at least one third MAC CE is multiplexed in the second MAC PDU.
[0020] In some implementations, the second MAC PDU further comprises an initial MAC CE or MAC service data unit (SDU) .
[0021] In some implementations, at least one priority of the at least one third MAC CE is higher than or lower than a priority of the initial MAC CE without security protection.
[0022] In some implementations, at least one priority of the at least one third MAC CE is predefined or configured.
[0023] In some implementations, the at least one priority of the at least one third MAC CE is predefined or configured based on at least one type of the at least one third MAC CE.
[0024] In some implementations, no initial MAC CE or MAC service data unit (SDU) is allowed to be multiplexed in the second MAC PDU.
[0025] In some implementations, a single third MAC CE is multiplexed in the second MAC PDU.
[0026] In some implementations, it is predefined or configured not to allow multiple third MAC CEs are multiplexed in the second MAC PDU.
[0027] In some implementations, the processor is further configured to: before the security protection for at least one first MAC CE is recovered, receive a third MAC PDU via the transceiver from the second device; and suspend handling of the third MAC PDU; or discard the third MAC PDU.
[0028] In some implementations, the processor is further configured to: suspend handling of a third MAC PDU or discard the third MAC PDU, wherein the third MAC PDU has been buffered when determining the security protection for the at least one first MAC CE fails.
[0029] Some implementations of a second device for wireless communication described herein may include a processor and a transceiver coupled to the processor, wherein the processor is configured to: transmit a MAC PDU via the transceiver to a first device for wireless communication, wherein the MAC PDU comprises MAC CEs with security protection; and receive, via the transceiver from the first device, a feedback associated with results of the security protection for the MAC CEs; or transmit an indication via the transceiver to the first device.
[0030] In some implementations, the feedback associated with results of the security protection for the MAC CEs comprises at least one of the following: at least one result of security protection for the at least one first MAC CE, wherein the security protection for the at least one first MAC CE fails, or at least one result of security protection for at least one second MAC CE, wherein the security protection for the at least one second MAC CE succeeds.
[0031] In some implementations, the feedback associated with results of the security protection for the MAC CEs comprises one of the following indicating the security protection for the MAC CEs succeeds or fails: an LCID associated with one of the MAC CEs, or an eLCID associated with one of the MAC CEs.
[0032] In some implementations, the processor is configured to receive the feedback associated with results of the security protection for the MAC CEs via a MAC CE, wherein the MAC CE comprises a bitmap, a bit of the bitmap is associated with a respective one of the MAC CEs and indicates that the security protection for the respective one of the MAC CE succeeds or fails.
[0033] In some implementations, bits of the bitmap are arranged in the same order as the MAC CEs are assembled in the first MAC PDU.
[0034] In some implementations, the processor is further configured to: receive a first indication via the transceiver from the first device, wherein the first indication indicates a transmission or retransmission of content related to the at least one first MAC CE with security protection.
[0035] In some implementations, a type of the at least one first MAC CE which can be retransmitted or transmitted again with security protection is predefined or preconfigured.
[0036] In some implementations, the processor is further configured to: request, based on the first indication and by a hybrid automatic repeat request (HARQ) entity of the second device, the retransmission for the at least one first MAC CE with security protection via a first HARQ process, wherein the first HARQ process is the same as or different from a second HARQ process for an initial transmission of the at least one first MAC CE.
[0037] In some implementations, the processor is further configured to: receive a second indication via the transceiver from the first device, wherein the second indication indicates one of the following: at least one security key for the at least one first MAC CE is to be updated, the at least one security key for the at least one first MAC CE and a security key for access stratum (AS) of the second device are to be updated, and the at least one security key for the at least one first MAC CE and a security key for a radio resource control (RRC) layer of the second device are to be updated; or receive a third indication via the transceiver from the first device, wherein the third indication indicates one of the following: at least one security key for the at least one first MAC CE is to be reset, the at least one security key for the at least one first MAC CE and the security key for AS are to be reset, and the at least one security key for the at least one first MAC CE and the security key for the RRC layer are to be reset.
[0038] In some implementations, the at least one security key for the at least one first MAC CE is the same as or separate from the security key for AS of the second device.
[0039] In some implementations, the processor is further configured to: perform the transmission or retransmission of the at least one first MAC CE via the transceiver to the first device by: transmitting a second MAC PDU via the transceiver to the first device, wherein the second MAC PDU comprises at least one third MAC CE, each of at least one third MAC CE comprises contents in a respective one of the at least one first MAC CE.
[0040] In some implementations, the processor is configured to perform the transmission or retransmission of the at least one first MAC CE by: update an input for the security protection of the at least one first MAC CE; and perform security protection of the at least one third MAC CE based on the updated input.
[0041] In some implementations, the processor is configured to transmit the second MAC PDU on a dedicated resource via the transceiver to the first device, wherein the at least one third MAC CE is multiplexed in the second MAC PDU.
[0042] In some implementations, it is predefined or configured to allow the at least one third MAC CE is multiplexed in the second MAC PDU.
[0043] In some implementations, the second MAC PDU further comprises an initial MAC CE or MAC SDU.
[0044] In some implementations, at least one priority of the at least one third MAC CE is higher than or lower than a priority of the initial MAC CE without security protection.
[0045] In some implementations, at least one priority of the at least one third MAC CE is predefined or configured.
[0046] In some implementations, the at least one priority of the at least one third MAC CE is predefined or configured based on at least one type of the at least one third MAC CE.
[0047] In some implementations, no initial MAC CE or MAC SDU is allowed to be multiplexed in the second MAC PDU.
[0048] In some implementations, a single third MAC CE is multiplexed in the second MAC PDU.
[0049] In some implementations, it is predefined or configured not to allow multiple third MAC CEs are multiplexed in the second MAC PDU.
[0050] Some implementations of a method described herein may include: receiving a first MAC PDU from a second device for wireless communication, wherein the first MAC PDU comprises MAC CEs with security protection; and based on determining that security protection for at least one first MAC CE among the MAC CEs fails, performing at least one of the following: transmitting, to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication from the second device, or discarding the at least one first MA C CE.
[0051] Some implementations of a method described herein may include: transmitting a MAC PDU to a first device for wireless communication, wherein the MAC PDU comprises MAC CEs with security protection; and receiving, from the first device, a feedback associated with results of the security protection for the MAC CEs; or transmitting an indication to the first device.
[0052] Some implementations of a processor described herein may include at least one memory and a controller coupled with the at least one memory and configured to cause the controller to: receive a first MAC PDU via the transceiver from a second device for wireless communication, wherein the first MAC PDU comprises MAC CEs with security protection; and based on determining that security protection for at least one first MAC CE among the MAC CEs fails, perform at least one of the following: transmitting, via the transceiver to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication via the transceiver from the second device, or discarding the at least one first MA C CE.
[0053] Some implementations of a processor described herein may include at least one memory and a controller coupled with the at least one memory and configured to cause the controller to: transmit a MAC PDU via the transceiver to a first device for wireless communication, wherein the MAC PDU comprises MAC CEs with security protection; and receive, via the transceiver from the first device, a feedback associated with results of the security protection for the MAC CEs; or transmit an indication via the transceiver to the first device.
[0054] It is to be understood that the summary section is not intended to identify security key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Fig. 1 illustrates an example of a wireless communications system that supports security protection for MAC CEs in accordance with aspects of the present disclosure;
[0056] Fig. 2 illustrates another example of a wireless communications system that supports security protection for MAC CEs in accordance with aspects of the present disclosure;
[0057] Fig. 3 illustrates a signaling diagram illustrating an example process that supports security protection for a MAC CE in accordance with aspects of the present disclosure;
[0058] Figs. 4 and 5 illustrate an example of a MA CE indicating the feedback associated with results of the security protection for the MAC CEs in accordance with aspects of the present disclosure, respectively;
[0059] Fig. 6 illustrates an example of a device that supports security protection for MAC CEs in accordance with aspects of the present disclosure;
[0060] Fig. 7 illustrates an example of a processor that supports security protection for MAC CEs in accordance with aspects of the present disclosure; and
[0061] Figs. 8 and 9 illustrate a flowchart of a method that supports security protection for MAC CEs in accordance with aspects of the present disclosure, respectively.DETAILED DESCRIPTION
[0062] Principles of the present disclosure will now be described with reference to some embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. The disclosure described herein may be implemented in various manners other than the ones described below.
[0063] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0064] References in the present disclosure to “one embodiment, ” “an example embodiment, ” “an embodiment, ” “some embodiments, ” and the like indicate that the embodiment (s) described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment (s) . Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0065] It shall be understood that although the terms “first” and “second” or the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another element. For example, a first element could also be termed as a second element, and similarly, a second element could also be termed as a first element, without departing from the scope of embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0066] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0067] As described above, there is a need to study how to handle one or more MAC CEs with security protection if security protection for the one or more MAC CEs fails.
[0068] In view of the above, the present disclosure provides a solution supporting security protection for MAC CEs. In this solution, a first device for wireless communication receives a first MAC PDU from a second device for wireless communication. The first MAC PDU comprises MAC CEs with security protection. If security protection for at least one first MAC CE among the MAC CEs fails, the first device performs at least one of the following: transmitting, to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication from the second device, or discarding the at least one first MAC CE. With this solution, the MAC CEs with security protection may be handled properly.
[0069] Aspects of the present disclosure are described in the context of a wireless communications system.
[0070] Fig. 1 illustrates an example of a wireless communications system 100 that supports obtaining of resources for early signaling transmission in accordance with aspects of the present disclosure. The wireless communications system 100 may include one at least one of network entities 102 (also referred to as network equipment (NE) ) , one or more terminal devices or UEs 104, a core network 106, and a packet data network 108. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE-advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a 5G network, such as an NR network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including institute of electrical and electronics engineers (IEEE) 802.11 (Wi-Fi) , IEEE 802.16 (WiMAX) , IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA) , frequency division multiple access (FDMA) , or code division multiple access (CDMA) , etc.
[0071] The network entities 102 may be collectively referred to as network entities 102 or individually referred to as a network entity 102. Hereinafter, some implementations of the present disclosure will be described by taking a base station as an example of the network entity 102. Thus, the network entity 102 may be used interchangeably with the base station 102.
[0072] The network entities 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the network entities 102 described herein may be or include or may be referred to as a network node, a base station (BS) , a network element, a radio access network (RAN) node, a base transceiver station, an access point, a NodeB, an eNodeB (eNB) , a next-generation NodeB (gNB) , or other suitable terminology. A network entity 102 and a UE 104 may communicate via a communication link 110, which may be a wireless or wired connection. For example, a network entity 102 and a UE 104 may perform wireless communication (e.g., receive signalling, transmit signalling) over a Uu interface.
[0073] A network entity 102 may provide a geographic coverage area 112 for which the network entity 102 may support services (e.g., voice, video, packet data, messaging, broadcast, etc. ) for one or more UEs 104 within the geographic coverage area 112. For example, a network entity 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc. ) according to one or multiple radio access technologies. In some implementations, a network entity 102 may be moveable, for example, a satellite associated with a non-terrestrial network. In some implementations, different geographic coverage areas 112 associated with the same or different radio access technologies may overlap, but the different geographic coverage areas 112 may be associated with different network entities 102. Information and signals described herein may be represented using any of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0074] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a mobile device, a wireless device, a remote device, a remote unit, a handheld device, or a subscriber device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an internet-of-things (IoT) device, an internet-of-everything (IoE) device, or machine-type communication (MTC) device, among other examples. In some implementations, a UE 104 may be stationary in the wireless communications system 100. In some other implementations, a UE 104 may be mobile in the wireless communications system 100.
[0075] The one or more UEs 104 may be devices in different forms or having different capabilities. Some examples of UEs 104 are illustrated in Fig. 1. A UE 104 may be capable of communicating with various types of devices, such as the network entities 102, other UEs 104, or network equipment (e.g., the core network 106, the packet data network 108, a relay device, an integrated access and backhaul (IAB) node, or another network equipment) , as shown in Fig. 1. Additionally, or alternatively, a UE 104 may support communication with other network entities 102 or UEs 104, which may act as relays in the wireless communications system 100.
[0076] A UE 104 may also be able to support wireless communication directly with other UEs 104 over a communication link 114. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link 114 may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0077] A network entity 102 may support communications with the core network 106, or with another network entity 102, or both. For example, a network entity 102 may interface with the core network 106 through one or more backhaul links 116 (e.g., via an S1, N2, N2, NG, or another network interface) . The network entities 102 may communicate with each other over the backhaul links 116 (e.g., via an X2, Xn, or another network interface) . In some implementations, the network entities 102 may communicate with each other directly (e.g., between the network entities 102) . In some other implementations, the network entities 102 may communicate with each other or indirectly (e.g., via the core network 106) . In some implementations, one or more network entities 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC) . An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs) .
[0078] In some implementations, the network entity 102 may be implemented as a satellite. For example, the network entity 102-1 may be implemented as a satellite. Thus, network entity 102-1 is also referred to as a satellite 102-1. The network entity 102-1 may have full or part of an eNB / gNB on board. The communication link 110 between the satellite 102-1 and the UE 104, the communication link 116 between the satellite 102-1 and the network entity 102, and the communication link 116 between the satellite 102-1 and the core network 106 may be used for a non-terrestrial network (NTN) transparent mode. The communication link 110 between the satellite 102-1 and the UE 104, and the communication link 116 between the satellite 102-1 (with a base station on board) and the core network 106 may be used for an NTN regenerative mode.
[0079] In some implementations, a network entity 102 may be configured in a disaggregated architecture, which may be configured to utilize a protocol stack physically or logically distributed among two or more network entities 102, such as an integrated access backhaul (IAB) network, an open radio access network (O-RAN) (e.g., a network configuration sponsored by the O-RAN Alliance) , or a virtualized RAN (vRAN) (e.g., a cloud RAN (C-RAN) ) . For example, a network entity 102 may include one or more of a central unit (CU) , a distributed unit (DU) , a radio unit (RU) , a RAN intelligent controller (RIC) (e.g., a near-real time RIC (Near-RT RIC) , a non-real time RIC (Non-RT RIC) ) , a service management and orchestration (SMO) system, or any combination thereof.
[0080] An RU may also be referred to as a radio head, a smart radio head, a remote radio head (RRH) , a remote radio unit (RRU) , or a transmission reception point (TRP) . One or more components of the network entities 102 in a disaggregated RAN architecture may be co-located, or one or more components of the network entities 102 may be located in distributed locations (e.g., separate physical locations) . In some implementations, one or more network entities 102 of a disaggregated RAN architecture may be implemented as virtual units (e.g., a virtual CU (VCU) , a virtual DU (VDU) , a virtual RU (VRU) ) .
[0081] Split of functionality between a CU, a DU, and an RU may be flexible and may support different functionalities depending upon which functions (e.g., network layer functions, protocol layer functions, baseband functions, radio frequency functions, and any combinations thereof) are performed at a CU, a DU, or an RU. For example, a functional split of a protocol stack may be employed between a CU and a DU such that the CU may support one or more layers of the protocol stack and the DU may support one or more different layers of the protocol stack. In some implementations, the CU may host upper protocol layer (e.g., a layer 3 (L3) , a layer 2 (L2) ) functionality and signalling (e.g., radio resource control (RRC) , service data adaption protocol (SDAP) , packet data convergence protocol (PDCP) ) . The CU may be connected to one or more DUs or RUs, and the one or more DUs or RUs may host lower protocol layers, such as a layer 1 (L1) (e.g., physical (PHY) layer) or an L2 (e.g., radio link control (RLC) layer, medium access control (MAC) layer) functionality and signalling, and may each be at least partially controlled by the CU 160.
[0082] Additionally, or alternatively, a functional split of the protocol stack may be employed between a DU and an RU such that the DU may support one or more layers of the protocol stack and the RU may support one or more different layers of the protocol stack. The DU may support one or multiple different cells (e.g., via one or more RUs) . In some implementations, a functional split between a CU and a DU, or between a DU and an RU may be within a protocol layer (e.g., some functions for a protocol layer may be performed by one of a CU, a DU, or an RU, while other functions of the protocol layer are performed by a different one of the CU, the DU, or the RU) .
[0083] A CU may be functionally split further into CU control plane (CU-CP) and CU user plane (CU-UP) functions. A CU may be connected to one or more DUs via a midhaul communication link (e.g., F1, F1-c, F1-u) , and a DU may be connected to one or more RUs via a fronthaul communication link (e.g., open fronthaul (FH) interface) . In some implementations, a midhaul communication link or a fronthaul communication link may be implemented in accordance with an interface (e.g., a channel) between layers of a protocol stack supported by respective network entities 102 that are in communication via such communication links.
[0084] The core network 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The core network 106 may be an evolved packet core (EPC) , or a 5G core (5GC) , which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME) , an access and mobility management functions (AMF) ) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW) , a packet data network (PDN) gateway (P-GW) , or a user plane function (UPF) ) . In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc. ) for the one or more UEs 104 served by the one or more network entities 102 associated with the core network 106.
[0085] The core network 106 may communicate with the packet data network 108 over one or more backhaul links 116 (e.g., via an S1, N2, NG, or another network interface) . The packet data network 108 may include an application server 118. In some implementations, one or more UEs 104 may communicate with the application server 118. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the core network 106 via a network entity 102. The core network 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server 118 using the established session (e.g., the established PDU session) . The PDU session may be an example of a logical connection between the UE 104 and the core network 106 (e.g., one or more network functions of the core network 106) .
[0086] In the wireless communications system 100, the network entities 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers) ) to perform various operations (e.g., wireless communications) . In some implementations, the network entities 102 and the UEs 104 may support different resource structures. For example, the network entities 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the network entities 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the network entities 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures) . The network entities 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0087] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., μ=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., μ=1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., μ=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., μ=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., μ=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0088] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames) . Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0089] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., μ=0, μ=1, μ=2, μ=3, μ=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols) . In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing) , a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., μ=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0090] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (510 MHz –7.125 GHz) , FR2 (24.25 GHz –52.6 GHz) , FR3 (7.125 GHz –24.25 GHz) , FR4 (52.6 GHz –114.25 GHz) , FR4a or FR4-1 (52.6 GHz –71 GHz) , and FR5 (114.25 GHz –300 GHz) . In some implementations, the network entities 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the network entities 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data) . In some implementations, FR2 may be used by the network entities 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0091] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies) . For example, FR1 may be associated with a first numerology (e.g., μ=0) , which includes 15 kHz subcarrier spacing; a second numerology (e.g., μ=1) , which includes 30 kHz subcarrier spacing; and a third numerology (e.g., μ=2) , which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies) . For example, FR2 may be associated with a third numerology (e.g., μ=2) , which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., μ=3) , which includes 120 kHz subcarrier spacing.
[0092] Fig. 2 illustrates another example of a wireless communications system 200 that supports security protection for a MAC CE in accordance with aspects of the present disclosure. As shown in Fig. 2, the wireless communications system 200 may comprise a first device 210 for wireless communication and a second device 220 for wireless communication.
[0093] In some implementations, the first device 210 may be implemented as a receiver and the second device 220 may be implemented as a transmitter.
[0094] In some implementations, the first device 210 may be implemented as the network entity 102 in Fig. 1 and the second device 220 may be implemented as the UE 104 in Fig. 1. Alternatively, the first device 210 may be implemented as the UE 104 in Fig. 1 and the second device 220 may be implemented as the network entity 102 in Fig. 1.
[0095] Fig. 3 illustrates a signaling diagram illustrating an example process 300 that supports security protection for a MAC CE in accordance with aspects of the present disclosure. The process 300 may involve the first device 210 for wireless communication and the second device 220 for wireless communication in Fig. 2. For the purpose of discussion, the process 300 will be described with reference to Fig. 2.
[0096] As shown in Fig. 3, the second device 220 transmits 310 a first MAC PDU to the first device 210. The first MAC PDU comprises MAC CEs with security protection.
[0097] In the present disclosure, the term “a MAC CE with security protection” may be used interchangeably with the term “a MAC CE with security” .
[0098] The first device 210 determines 320 security protection for at least one first MAC CE among the MAC CEs fails.
[0099] In the present disclosure, the term “security protection for a MAC CE” may be used interchangeably with the term “security for a MAC CE” .
[0100] In some implementations, failure of security protection for a MAC CE may comprise at least one of the following: integrity verification failure, integrity protection failure, check failure, security check failure, integrity check failure, deciphering check failure or deciphering failure.
[0101] In the present disclosure, the term “integrity verification” may be used interchangeably with the term “integrity check” .
[0102] In some implementations, for integrity verification of a MAC CE, the first device 210 may calculate X-MAC based on a security key and an integrity algorithm. If the X-MAC (calculated message authentication code for integrity (MAC-I) ) corresponds to the received MAC-I included in the MAC CE, the integrity verification for the MAC CE succeeds. Otherwise, the integrity verification for the MAC CE fails.
[0103] In some implementations, before performing integrity verification and / or deciphering of a MAC CE, the first device 210 may perform cyclic redundancy check (CRC) for the MAC PDU comprising the MAC CE. If CRC for the MAC PDU succeeds, the first device 210 may decode the MAC PDU. If the first device 210 may decode the MAC PDU successfully, the first device 210 may perform integrity verification and / or deciphering of the MAC CE.
[0104] If the first device 210 determines the security protection for the at least one first MAC CE among the MAC CEs with security protection fails, the first device 210 performs 330 at least one of the following: transmitting, to the second device 220, a feedback associated with results of the security protection for the MAC CEs; receiving an indication from the second device 220; or discarding the at least one first MAC CE.
[0105] With the process 300, the MAC CEs with security protection may be handled properly.
[0106] In some implementations, if the multiple MAC CEs are subjected to security protection, there is a need to study how to consider security protection for the multiple MAC CEs if security protection for at least one MAC CE among the MAC CEs fails or succeeds.
[0107] Considering the potential multiplexing, also considering MAC CEs with integrity protection and / or cyphering, the reception results could be as listed in Table if there are more than one MAC CEs with security protection multiplexed in one MAC PDU.
[0108] Firstly, the PHY layer of the first device 210 indicates a downlink assignment which represents the CRC check result is correct as shown in the first row in Table 1.
[0109] Then, the MAC layer of the first device 210 attempts to decode the received MAC PDU (for example, assuming it is a new transmission) . The result may be success or failure as shown in the second row in Table 1.
[0110] If the MAC PDU is successfully decoded, the MAC layer delivers the decoded MAC PDU to the disassembly and demultiplexing entity. Potentially, it could be that the integrity verification succeeds or fails as shown in the third row and the fourth row in Table 1.
[0111] For example, multiple MAC CEs are multiplexed in one MAC PDU. The multiple MAC CEs may comprise at least a MAC CE #1 and a MAC CE #2 are multiplexed in one MAC PDU. If integrity verification for the MAC CE #1 fails and integrity verification for the MAC CE #2 succeeds, there is a need to study how to handle the MAC CEs in the MAC PDU. On the other hand, if integrity verification for the MAC CE #1 succeeds and integrity verification for the MAC CE #2 succeeds, there is a need to study how to handle the MAC CEs in the MAC PDU. Table 1
[0112] In some implementations, if security protection for one or more of the MAC CEs with security protection in the MAC PDU fails, the first device 210 may determine the security protection for the MAC CEs fails.
[0113] In some implementations, as long as security protection for one of the MAC CEs with security protection fails, the first device 210 may determine the security protection for the MAC CEs fails.
[0114] In some implementations, if security protection for at least a first number of MAC CE among the MAC CEs with security protection or for at least a first percentage of the MAC CEs with security protection succeeds / fails, the first device 210 may determine the security protection for the MAC CEs succeeds / fails. Otherwise, the first device 210 may determine the security protection for the MAC CEs fails / succeeds.
[0115] In some implementations, the first number may be equal to any appropriate value. For example, the first number may be equal to one. That is, as long as security protection for one of the MAC CEs with security protection succeeds / fails, the first device 210 may determine the security protection for the MAC CEs fails / succeeds.
[0116] In some implementations, the first percentage may be equal to any appropriate value.
[0117] In some implementations, if security protection for majority of the MAC CEs with security protection succeeds / fails, the first device 210 may determine the security protection for the MAC CEs succeeds / fails. For example, the first percentage may be equal to 80%. If security protection for at least 80%of the MAC CEs with security protection succeeds / fails, the first device 210 may determine the security protection for the MAC CEs succeeds / fails.
[0118] In some implementations, the first device 210 may receive a configuration for the first number or the first percentage from the second device 220.
[0119] Alternatively, in some implementations, the first number or the first percentage may be predefined or configured by default.
[0120] As described above, if the first device 210 determines the security protection for the at least one first MAC CE among the MAC CEs with security protection fails, the first device 210 transmits, to the second device 220, a feedback associated with results of the security protection for the MAC CEs.
[0121] In some implementations, the first device 210 may determine the security protection for at least one first MAC CE among the MAC CEs with security protection fails and determine security protection for at least one second MAC CE among the MAC CEs with security protection succeeds.
[0122] In some implementations, the feedback associated with results of the security protection for the MAC CEs may comprise at least one result of the security protection for the at least one first MAC CE and at least one result of the security protection for the at least one second MAC CE. The at least one result of the security protection for the at least one first MAC CE indicates the security protection for the at least one first MAC CE fails. The at least one result of the security protection for the at least one second MAC CE indicates the security protection for the at least one second MAC CE succeeds.
[0123] In some implementations, the first device 210 may transmit the feedback associated with results of the security protection for the MAC CEs via a MAC CE. The MAC CE comprises a bitmap. A bit of the bitmap is associated with a respective one of the MAC CEs and indicates that the security protection for the respective one of the MAC CE succeeds or fails.
[0124] For example, the MAC CE may comprise MAC CE i field indicating each of results of the security protection for the MAC CEs with security protection. The MAC CE i field set to 1 indicates that security protection for ith MAC CE with security protection succeeds. The MAC CE i field set to 0 indicates that security protection for ith MAC CE with security protection fails.
[0125] In some implementations, a length of the bitmap may be variable or fixed.
[0126] In some implementations, bits of the bitmap are arranged in the same order as the MAC CEs are assembled in the first MAC PDU.
[0127] Figs. 4 and 5 illustrate an example of a MAC CE indicating the feedback associated with results of the security protection for the MAC CEs in accordance with aspects of the present disclosure.
[0128] In the example of Fig. 4, the first MAC PDU may comprise a MAC CE 1 with security protection, a MAC CE 2 with security protection, …, a MAC CE 7 with security protection. The first device 210 may transmit a MAC CE to the second device 220. The MAC CE comprises a bitmap with eight bits. The eight bits are arranged in the same order as the MAC CE 1, the MAC CE 2, …, the MAC CE 7 are assembled in the first MAC PDU.
[0129] The MAC CE may further comprise at least one reserved (R) bit. The R bit (s) may be at any bit (s) of the MAC CE e.g. at the leftmost bit (s) , at the rightmost bit (s) .
[0130] The MAC CE in Fig. 5 is different from the MAC CE in Fig. 4 in that the MAC CE in Fig. 5 comprises a bitmap with more than eight bits e.g. sixteen bits.
[0131] In some implementations, the MAC CE comprising the feedback may be associated with an LCID or eLCID which is used to indicate the following MAC CE is for the results of the security protection for the MAC CEs with security protection.
[0132] Alternatively, in some implementations, the feedback associated with results of the security protection for the MAC CEs may comprise an LCID or eLCID associated with one of the MAC CEs. The LCID or eLCID indicates the security protection for the MAC CEs succeeds or fails:
[0133] Alternatively, in some implementations, the feedback associated with results of the security protection for the MAC CEs may comprise a dedicated LCID or eLCID associated with one of the MAC CEs. The dedicated LCID or eLCID indicates the security protection for the MAC CEs succeeds or fails:
[0134] For example, a first LCID or eLCID may be used to indicate the security protection for the MAC CEs succeeds, and a second LCID or eLCID may be used to indicate the security protection for the MAC CEs fails.
[0135] In some implementations, if the security protection for the at least one first MAC CE among the MAC CEs fails, the first device 210 may transmit a first indication to the second device 220. The first indication indicates a transmission or retransmission of content related to the at least one first MAC CE with security protection.
[0136] In some implementations, the first indication may comprise a scheduling signal indicating the transmission or retransmission of content related to the at least one first MAC CE with security protection.
[0137] In some implementations, a type of at least one MAC CE which can be retransmitted or transmitted again with security protection is predefined or preconfigured.
[0138] In some implementations, based on the first indication, a hybrid automatic repeat request (HARQ) entity of the second device 220 may request the retransmission for the at least one first MAC CE with security protection via a first HARQ process. The first HARQ process is the same as or different from a second HARQ process for an initial transmission of the at least one first MAC CE.
[0139] In some implementations, based on the first indication, the HARQ entity of the second device 220 may provide, to a HARQ buffer corresponding to the second HARQ process for the initial transmission of the at least one first MAC CE, a request for the retransmission for the at least one first MAC CE.
[0140] In some implementations, if the first indication indicates an uplink grant, the first HARQ process may store the uplink grant received from the HARQ entity of the second device 220.
[0141] In some implementations, in order to perform the transmission or retransmission of content related to the at least one first MAC CE, the second device 220 may update an input for the security protection of the at least one first MAC CE. The second device 220 may perform security protection of at least one third MAC CE based on the updated input. Each of at least one third MAC CE comprises contents in a respective one of the at least one first MAC CE. In turn, the second device 220 may transmit a second MAC PDU to the first device 210. The second MAC PDU comprises the at least one third MAC CE.
[0142] In some implementations, the input for the security protection of the at least one first MAC CE may comprise a sequence number (SN) or COUNT for the security protection of the at least one first MAC CE. In such implementations, the second device 220 may update the input for the security protection of the at least one first MAC CE by increasing the SN or COUNT by 1 for each transmission of the at least one first MAC CE.
[0143] In some implementations, at least one security key for the at least one first MAC CE may be the same as a security key for AS of the second device 220 e.g. Keys for UP traffic, Keys for RRC signalling, keys for the control plane and for the user plane or key used by the PDCP entity. The second device 220 may update the at least one security key for the at least one first MAC CE by updating the input for the security protection of the at least one first MAC CE. Accordingly, the security key for AS of the second device 220 may be updated.
[0144] Alternatively, in some implementations, at least one security key for the at least one first MAC CE may be separate from the security key for AS of the second device 220. If the second device 220 updates the at least one security key for the at least one first MAC CE, the security key for AS of the second device 220 may not be updated.
[0145] In some implementations, the first device 210 may transmit a second indication to the second device 220. The second indication may indicate one of the following: ‐at least one security key for the at least one first MAC CE is to be updated, ‐the at least one security key for the at least one first MAC CE and a security key for AS of the second device 220 are to be updated, and ‐the at least one security key for the at least one first MAC CE and a security key for a radio resource control (RRC) layer of the second device 220 are to be updated.
[0146] In some implementations, the first device 210 may transmit a third indication to the second device 220. The third indication may indicate one of the following: ‐at least one security key for the at least one first MAC CE is to be reset, ‐the at least one security key for the at least one first MAC CE and the security key for AS are to be reset, and ‐the at least one security key for the at least one first MAC CE and the security key for the RRC layer are to be reset.
[0147] In the present disclosure, the “key reset” may comprise “key refresh” or “key-rekeying” .
[0148] In some implementations, if the AMF determines that NAS key refresh is required due to e.g. uplink or downlink NAS counter in the current security context is about to wrap around or based on a local operator policy to refresh the NAS keys after a certain time, the AMF may trigger a primary authentication run or may derive a new KAMF key using horizontal KAMF derivation upon the reception of an initial NAS message, e.g. a Registration Request or a Service Request using the uplink NAS COUNT value in the initial NAS message as described in clause 6.9.3 of TS 33.501 for mobility update registration. The AMF resets the corresponding uplink and downlink NAS counters and derive new NAS keys from the new KAMF key and the algorithms in use. The AMF activates the new KAMF key by running a NAS SMC with UE 104 according to clause 6. 7. 2 of TS 33.501. When the new KAMF key is horizontally derived, the UE 104 shall use the uplink NAS COUNT value that was sent in the initial NAS message to derive the same KAMF key as the AMF, reset the corresponding uplink and downlink NAS counters and then derive new NAS keys from the KAMF and the algorithms in use.
[0149] In this case, if AS security is also established between the UE 104 and gNB / ng-eNB 102, then the AMF and the UE 104 shall derive a new initial KgNB from the new KAMF as specified in Annex A. 9 of TS 33.501. Further, the AMF and the UE 104 shall associate the derived new initial KgNB with a new NCC value equal to zero. Further, the derived new initial KgNB / KeNB is sent by the AMF to the gNB / ng-eNB 102 triggering the gNB / ng-eNB 102 to perform the AS key re-keying as described in clause 6. 9. 4. 4 of TS 33.501.
[0150] In some implementations, in order to perform the transmission or retransmission of content related to the at least one first MAC CE, the second device 220 may transmit the second MAC PDU on a dedicated resource to the first device 210. The at least one third MAC CE is multiplexed in the second MAC PDU.
[0151] In some implementations, it is predefined or configured to allow the at least one third MAC CE is multiplexed in the second MAC PDU.
[0152] In some implementations, the dedicated resource may comprise a dynamic scheduling resource or a preconfigured resource or a configured grant (CG) for the at least one first MAC CE.
[0153] In some implementations, the dedicated resource may comprise a first CG dedicated for the retransmission of the at least one first MAC CE with security protection.
[0154] For example, the first CG may be used for the retransmission of the at least one first MAC CE with security protection and initial transmission of an initial MAC CE or MAC SDU.
[0155] In some implementations, the dedicated resource may comprise a second CG allowed for the retransmission of the at least one first MAC CE with security protection.
[0156] For example, the second CG may be used for an initial transmission of an initial MAC CE or MAC SDU. If the second CG can accommodate the retransmission of the at least one first MAC CE with security protection, the second CG can be used for the retransmission of the at least one first MAC CE with security protection
[0157] In some implementations, the dedicated resource may comprise a third CG dedicated for only the retransmission of the at least one first MAC CE with security protection. In such implementations, the third CG cannot be used for initial transmission of an initial MAC CE or MAC SDU.
[0158] In some implementations, it is predefined or configured to allow the at least one third MAC CE and initial MAC CE or MAC SDU are multiplexed in the second MAC PDU.
[0159] In some implementations, at least one priority of the at least one third MAC CE is higher than or lower than a priority of the initial MAC CE without security protection.
[0160] In some implementations, at least one priority of the at least one third MAC CE is predefined or configured.
[0161] In some implementations, it is up to implementation of the second device 220 to determine the at least one priority of the at least one third MAC CE if there are multiple MAC CEs with security protection to be retransmitted;
[0162] In some implementations, the at least one priority of the at least one third MAC CE is predefined or configured based on at least one type of the at least one third MAC CE.
[0163] For example, the at least one priority of the at least one third MAC CE is predefined or configured in accordance with the following order (highest priority listed first) if the MAC CE is configured with security protection: -MAC CE for C-RNTI, or data from UL-CCCH; -MAC CE for (Enhanced) BFR, or MAC CE for Configured Grant Confirmation, or MAC CE for Multiple Entry Configured Grant Confirmation; -MAC CE for Sidelink Configured Grant Confirmation; -MAC CE for LBT failure; -MAC CE for SL LBT failure according to clause 5.31.2; -MAC CE for Timing Advance Report; -MAC CE for Delay Status Report; -MAC CE for SL-BSR prioritized according to clause 5.22.1.6; -MAC CE for SL-PRS Resource Request; -MAC CE for (Extended) BSR, with exception of BSR included for padding; -MAC CE for (Enhanced) Single Entry PHR, or MAC CE for (Enhanced) Multiple Entry PHR or MAC CE for Single Entry PHR with assumed PUSCH, or MAC CE for Multiple Entry PHR with assumed PUSCH, or MAC CE for Enhanced Single Entry PHR for multiple TRP or MAC CE for Enhanced Multiple Entry PHR for multiple TRP, or MAC CE for Enhanced Single Entry PHR for multiple TRP STx2P or MAC CE for Enhanced Multiple Entry PHR for multiple TRP STx2P; -MAC CE for Positioning Measurement Gap Activation / Deactivation Request; -MAC CE for the number of Desired Guard Symbols; -MAC CE for Case-6 Timing Request; -MAC CE for (Extended) Pre-emptive BSR; -MAC CE for SL-BSR, with exception of SL-BSR prioritized according to clause 5.22.1.6 and SL-BSR included for padding; -MAC CE for IAB-MT Recommended Beam Indication, or MAC CE for Desired IAB-MT PSD range, or MAC CE for Desired DL Tx Power Adjustment; -data from any Logical Channel, except data from UL-CCCH; -MAC CE for Recommended bit rate query; -MAC CE for BSR included for padding; -MAC CE for SL-BSR included for padding.
[0164] In some implementations, no initial MAC CE or MAC SDU and the at least one third MAC CE are allowed to be multiplexed in the second MAC PDU.
[0165] In some implementations, it is predefined or configured not to allow multiplexing the initial MAC CE or MAC SDU and the at least one third MAC CE in the second MAC PDU.
[0166] In some implementations, it is predefined or configured to allow multiplexing multiple third MAC CEs in the second MAC PDU.
[0167] In some implementations, it is predefined or configured not to allow multiplexing multiple third MAC CEs in the second MAC PDU. In such implementations, a single third MAC CE is multiplexed in the second MAC PDU.
[0168] In some implementations, before the security protection for at least one first MAC CE is recovered, the first device 210 may receive a third MAC PDU from the second device 220. The first device 210 may suspend handling of the third MAC PDU or discard the third MAC PDU.
[0169] In some implementations, a third MAC PDU has been buffered or is ongoing when the first device 210 determines the security protection for the at least one first MAC CE fails. The first device 210 may suspend handling of the third MAC PDU or discard the third MAC PDU.
[0170] As described with reference to Fig. 3, if the first device 210 determines the security protection for the at least one first MAC CE among the MAC CEs with security protection fails, the first device 210 may receive an indication from the second device 220.
[0171] In some implementations, if the first device 210 determines the security protection for the MAC CEs with security protection succeeds, the first device 210 may transmit a positive acknowledge (ACK) to the second device 220. If the first device 210 determines the security protection for the at least one first MAC CE among the MAC CEs with security protection fails, the first device 210 may transmit neither ACK nor a negative acknowledge (NACK) to the second device 220. In this case, the second device 220 may consider a NACK is received. In turn, the second device 220 may transmit the indication to the first device 210. The indication may indicate transmission or retransmission of content related to the first MAC PDU comprising the MAC CEs.
[0172] Fig. 6 illustrates an example of a device 600 that supports security protection for MAC CEs in accordance with aspects of the present disclosure. The device 600 may be an example of a network entity 102 or a UE 104 as described herein. The device 600 may support wireless communication with one or more network entities 102, UEs 104, or any combination thereof. The device 600 may include components for bi-directional communications including components for transmitting and receiving communications, such as a processor 602, a memory 604, a transceiver 606, and, optionally, an I / O controller 608. These components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses) .
[0173] The processor 602, the memory 604, the transceiver 606, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. For example, the processor 602, the memory 604, the transceiver 606, or various combinations or components thereof may support a method for performing one or more of the operations described herein.
[0174] In some implementations, the processor 602, the memory 604, the transceiver 606, or various combinations or components thereof may be implemented in hardware (e.g., in communications management circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic, discrete hardware components, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure. In some implementations, the processor 602 and the memory 604 coupled with the processor 602 may be configured to perform one or more of the functions described herein (e.g., executing, by the processor 602, instructions stored in the memory 604) .
[0175] For example, the processor 602 may support wireless communication at the device 600 in accordance with examples as disclosed herein. The processor 602 may be configured to operable to support a means for performing the following: receiving a first MAC PDU from a second device for wireless communication, wherein the first MAC PDU comprises MAC CEs with security protection; and based on determining that security protection for at least one first MAC CE among the MAC CEs fails, performing at least one of the following: transmitting, to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication from the second device, or discarding the at least one first MA C CE.
[0176] Alternatively, the processor 602 may be configured to operable to support a means for performing the following: transmitting a MAC PDU to a first device for wireless communication, wherein the MAC PDU comprises MAC CEs with security protection; and receiving, from the first device, a feedback associated with results of the security protection for the MAC CEs; or transmitting an indication to the first device.
[0177] The processor 602 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, a microcontroller, an ASIC, an FPGA, a programmable logic device, a discrete gate or transistor logic component, a discrete hardware component, or any combination thereof) . In some implementations, the processor 602 may be configured to operate a memory array using a memory controller. In some other implementations, a memory controller may be integrated into the processor 602. The processor 602 may be configured to execute computer-readable instructions stored in a memory (e.g., the memory 604) to cause the device 600 to perform various functions of the present disclosure.
[0178] The memory 604 may include random access memory (RAM) and read-only memory (ROM) . The memory 604 may store computer-readable, computer-executable code including instructions that, when executed by the processor 602 cause the device 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. In some implementations, the code may not be directly executable by the processor 602 but may cause a computer (e.g., when compiled and executed) to perform functions described herein. In some implementations, the memory 604 may include, among other things, a basic I / O system (BIOS) which may control basic hardware or software operation such as the interaction with peripheral components or devices.
[0179] The I / O controller 608 may manage input and output signals for the device 600. The I / O controller 608 may also manage peripherals not integrated into the device M02. In some implementations, the I / O controller 608 may represent a physical connection or port to an external peripheral. In some implementations, the I / O controller 608 may utilize an operating system such as or another known operating system. In some implementations, the I / O controller 608 may be implemented as part of a processor, such as the processor 606. In some implementations, a user may interact with the device 600 via the I / O controller 608 or via hardware components controlled by the I / O controller 608.
[0180] In some implementations, the device 600 may include a single antenna 610. However, in some other implementations, the device 600 may have more than one antenna 610 (i.e., multiple antennas) , including multiple antenna panels or antenna arrays, which may be capable of concurrently transmitting or receiving multiple wireless transmissions. The transceiver 606 may communicate bi-directionally, via the one or more antennas 610, wired, or wireless links as described herein. For example, the transceiver 606 may represent a wireless transceiver and may communicate bi-directionally with another wireless transceiver. The transceiver 606 may also include a modem to modulate the packets, to provide the modulated packets to one or more antennas 610 for transmission, and to demodulate packets received from the one or more antennas 610. The transceiver 606 may include one or more transmit chains, one or more receive chains, or a combination thereof.
[0181] A transmit chain may be configured to generate and transmit signals (e.g., control information, data, packets) . The transmit chain may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmit chain may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmit chain may also include one or more antennas 610 for transmitting the amplified signal into the air or wireless medium.
[0182] A receive chain may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receive chain may include one or more antennas 610 for receive the signal over the air or wireless medium. The receive chain may include at least one amplifier (e.g., a low-noise amplifier (LNA) ) configured to amplify the received signal. The receive chain may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receive chain may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.
[0183] Fig. 7 illustrates an example of a processor 700 that supports security protection for MAC CEs in accordance with aspects of the present disclosure. The processor 700 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 700 may include a controller 702 configured to perform various operations in accordance with examples as described herein. The processor 700 may optionally include at least one memory 704, such as L1 / L2 / L3 cache. Additionally, or alternatively, the processor 700 may optionally include one or more arithmetic-logic units (ALUs) 706. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses) .
[0184] The processor 700 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 700) or other memory (e.g., random access memory (RAM) , read-only memory (ROM) , dynamic RAM (DRAM) , synchronous dynamic RAM (SDRAM) , static RAM (SRAM) , ferroelectric RAM (FeRAM) , magnetic RAM (MRAM) , resistive RAM (RRAM) , flash memory, phase change memory (PCM) , and others) .
[0185] The controller 702 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. For example, the controller 702 may operate as a control unit of the processor 700, generating control signals that manage the operation of various components of the processor 700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0186] The controller 702 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 704 and determine subsequent instruction (s) to be executed to cause the processor 700 to support various operations in accordance with examples as described herein. The controller 702 may be configured to track memory address of instructions associated with the memory 704. The controller 702 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 702 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 700 to cause the processor 700 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 702 may be configured to manage flow of data within the processor 700. The controller 702 may be configured to control transfer of data between registers, arithmetic logic units (ALUs) , and other functional units of the processor 700.
[0187] The memory 704 may include one or more caches (e.g., memory local to or included in the processor 700 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementation, the memory 704 may reside within or on a processor chipset (e.g., local to the processor 700) . In some other implementations, the memory 704 may reside external to the processor chipset (e.g., remote to the processor 700) .
[0188] The memory 704 may store computer-readable, computer-executable code including instructions that, when executed by the processor 700, cause the processor 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 702 and / or the processor 700 may be configured to execute computer-readable instructions stored in the memory 704 to cause the processor 700 to perform various functions. For example, the processor 700 and / or the controller 702 may be coupled with or to the memory 704, the processor 700, the controller 702, and the memory 704 may be configured to perform various functions described herein. In some examples, the processor 700 may include multiple processors and the memory 704 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0189] The one or more ALUs 706 may be configured to support various operations in accordance with examples as described herein. In some implementation, the one or more ALUs 706 may reside within or on a processor chipset (e.g., the processor 700) . In some other implementations, the one or more ALUs 706 may reside external to the processor chipset (e.g., the processor 700) . One or more ALUs 706 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 706 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 706 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 706 may support logical operations such as AND, OR, exclusive-OR (XOR) , not-OR (NOR) , and not-AND (NAND) , enabling the one or more ALUs 706 to handle conditional operations, comparisons, and bitwise operations.
[0190] The processor 700 may support wireless communication at the device 600 in accordance with examples as disclosed herein. The processor 700 may be configured to operable to support a means for performing the following: receiving a first MAC PDU from a second device for wireless communication, wherein the first MAC PDU comprises MAC CEs with security protection; and based on determining that security protection for at least one first MAC CE among the MAC CEs fails, performing at least one of the following: transmitting, to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication from the second device, or discarding the at least one first MA C CE.
[0191] Alternatively, the processor 700 may be configured to operable to support a means for performing the following: transmitting a MAC PDU to a first device for wireless communication, wherein the MAC PDU comprises MAC CEs with security protection; and receiving, from the first device, a feedback associated with results of the security protection for the MAC CEs; or transmitting an indication to the first device.
[0192] Fig. 8 illustrates a flowchart of a method 800 that supports security protection for MAC CEs in accordance with aspects of the present disclosure. The operations of the method 800 may be implemented by a device or its components as described herein. For example, the operations of the method 800 may be performed by the first device 210 as described herein. In some implementations, the device may execute a set of instructions to control the function elements of the device to perform the described functions. Additionally, or alternatively, the device may perform aspects of the described functions using special-purpose hardware.
[0193] At 810, the method may include receiving a first MAC PDU from a second device for wireless communication, wherein the first MAC PDU comprises MAC CEs with security protection. The operations of 810 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 810 may be performed by a device as described with reference to Fig. 1.
[0194] At 820, the method may include based on determining that security protection for at least one first MAC CE among the MAC CEs fails, performing at least one of the following: transmitting, to the second device, a feedback associated with results of the security protection for the MAC CEs, receiving an indication from the second device, or discarding the at least one first MAC CE. The operations of 820 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 820 may be performed by a device as described with reference to Fig. 1.
[0195] Fig. 9 illustrates a flowchart of a method 900 that supports security protection for MAC CEs in accordance with aspects of the present disclosure. The operations of the method 900 may be implemented by a device or its components as described herein. For example, the operations of the method 900 may be performed by the second device 220 as described herein. In some implementations, the device may execute a set of instructions to control the function elements of the device to perform the described functions. Additionally, or alternatively, the device may perform aspects of the described functions using special-purpose hardware.
[0196] At 910, the method may include transmitting a MAC PDU to a first device for wireless communication, wherein the MAC PDU comprises MAC CEs with security protection. The operations of 910 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 910 may be performed by a device as described with reference to Fig. 1.
[0197] At 920, the method may include receiving, from the first device, a feedback associated with results of the security protection for the MAC CEs; or transmitting an indication to the first device. The operations of 920 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 920 may be performed by a device as described with reference to Fig. 1.
[0198] It shall be noted that implementations of the present disclosure which have been described with reference to Figs. 1 to 5 are also applicable to the device 600, the processor 700 as well as the methods 800 and 900.
[0199] It should be noted that the methods described herein describes possible implementations, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible. Further, aspects from two or more of the methods may be combined.
[0200] The various illustrative blocks and components described in connection with the disclosure herein may be implemented or performed with a general-purpose processor, a DSP, an ASIC, a CPU, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
[0201] The functions described herein may be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Other examples and implementations are within the scope of the disclosure and appended claims. For example, due to the nature of software, functions described herein may be implemented using software executed by a processor, hardware, firmware, hardwiring, or combinations of any of these. Features implementing functions may also be physically located at various positions, including being distributed such that portions of functions are implemented at different physical locations.
[0202] Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer. By way of example, non-transitory computer-readable media may include RAM, ROM, electrically erasable programmable ROM (EEPROM) , flash memory, compact disk (CD) ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that may be used to carry or store desired program code means in the form of instructions or data structures and that may be accessed by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor.
[0203] As used herein, including in the claims, an article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a, ” “at least one, ” “one or more, ” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of” or “one or more of” or “one or both of” ) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C) . Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0204] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1.A first device for wireless communication, comprising:a processor; anda transceiver coupled to the processor,wherein the processor is configured to:receive a first medium access control protocol data unit (MAC PDU) via the transceiver from a second device for wireless communication, wherein the first MAC PDU comprises MAC control elements (CEs) with security protection; andbased on determining that security protection for at least one first MAC CE among the MAC CEs fails, perform at least one of the following:transmitting, via the transceiver to the second device, a feedback associated with results of the security protection for the MAC CEs,receiving an indication via the transceiver from the second device, ordiscarding the at least one first MA C CE.2.The first device of claim 1, wherein the processor is further configured to:based on determining that security protection for one or more of the MAC CEs fails, determine the security protection for the MAC CEs fails.3.The first device of claim 1, wherein the processor is further configured to:based on determining that security protection for at least a first number of MAC CE among the MAC CEs or for at least a first percentage of the MAC CEs succeeds, determine the security protection for the MAC CEs succeeds.4.The first device of claim 3, wherein the processor is further configured to:receive a configuration for the first number or the first percentage via the transceiver from the second device.5.The first device of claim 1, wherein the processor is further configured to:determine the security protection for at least one first MAC CE fails;determine security protection for at least one second MAC CE succeeds; andwherein the feedback associated with results of the security protection for the MAC CEs comprises at least one of the following:at least one result of the security protection for the at least one first MAC CE, orat least one result of the security protection for the at least one second MAC CE.6.The first device of claim 5, wherein the feedback associated with results of the security protection for the MAC CEs comprises one of the following indicating the security protection for the MAC CEs succeeds or fails:a logical channel identity (LCID) associated with one of the MAC CEs, oran extended logical channel identity (eLCID) associated with one of the MAC CEs.7.The first device of claim 5, wherein the processor is configured to transmit the feedback associated with results of the security protection for the MAC CEs via a MAC CE, wherein the MAC CE comprises a bitmap, a bit of the bitmap is associated with a respective one of the MAC CEs and indicates that the security protection for the respective one of the MAC CE succeeds or fails.8.The first device of claim 1, wherein the processor is further configured to:based on determining that the security protection for the at least one first MAC CE among the MAC CEs fails, transmit a first indication via the transceiver to the second device, wherein the first indication indicates a transmission or retransmission of content related to the at least one first MAC CE with security protection.9.The first device of claim 1, wherein the processor is further configured to:based on determining that the security protection for the at least one first MAC CE among the MAC CEs fails, transmit a second indication via the transceiver to the second device, wherein the second indication indicates one of the following:at least one security key for the at least one first MAC CE is to be updated,the at least one security key for the at least one first MAC CE and a security key for access stratum (AS) of the second device are to be updated, andthe at least one security key for the at least one first MAC CE and a security key for a radio resource control (RRC) layer of the second device are to be updated; orbased on determining that the security protection for the at least one first MAC CE among the MAC CEs fails, transmit a third indication via the transceiver to the second device, wherein the third indication indicates one of the following:at least one security key for the at least one first MAC CE is to be reset,the at least one security key for the at least one first MAC CE and the security key for AS are to be reset, andthe at least one security key for the at least one first MAC CE and the security key for the RRC layer are to be reset.10.The first device of claim 8, wherein the processor is further configured to:receive the transmission or retransmission of the at least one first MAC CE via the transceiver from the second device by:receiving a second MAC PDU on a dedicated resource via the transceiver from the second device, wherein at least one third MAC CE is multiplexed in the second MAC PDU, each of at least one third MAC CE comprises contents in a respective one of the at least one first MAC CE.11.The first device of claim 1, wherein the processor is further configured to:before the security protection for at least one first MAC CE is recovered, receive a third MAC PDU via the transceiver from the second device; andsuspend handling of the third MAC PDU; ordiscard the third MAC PDU.12.The first device of claim 1, wherein the processor is further configured to:suspend handling of a third MAC PDU or discard the third MAC PDU, wherein the third MAC PDU has been buffered when determining the security protection for the at least one first MAC CE fails.13.A second device for wireless communication, comprising:a processor; anda transceiver coupled to the processor,wherein the processor is configured to:transmit a medium access control protocol data unit (MAC PDU) via the transceiver to a first device for wireless communication, wherein the MAC PDU comprises MAC control elements (CEs) with security protection; andreceive, via the transceiver from the first device, a feedback associated with results of the security protection for the MAC CEs; ortransmit an indication via the transceiver to the first device.14.The second device of claim 13, wherein the processor is further configured to:receive a first indication via the transceiver from the first device, wherein the first indication indicates a transmission or retransmission of content related to the at least one first MAC CE with security protection.15.The second device of claim 14, wherein a type of the at least one first MAC CE which can be retransmitted or transmitted again with security protection is predefined or preconfigured.16.The second device of claim 14, wherein the processor is further configured to:request, based on the first indication and by a hybrid automatic repeat request (HARQ) entity of the second device, the retransmission for the at least one first MAC CE with security protection via a first HARQ process, wherein the first HARQ process is the same as or different from a second HARQ process for an initial transmission of the at least one first MAC CE.17.The second device of claim 13, wherein the processor is further configured to:perform the transmission or retransmission of the at least one first MAC CE via the transceiver to the first device by:transmitting a second MAC PDU via the transceiver to the first device, wherein the second MAC PDU comprises at least one third MAC CE, each of at least one third MAC CE comprises contents in a respective one of the at least one first MAC CE.18.The second device of claim 17, wherein at least one priority of the at least one third MAC CE is higher than or lower than a priority of an initial MAC CE without security protection in the second MAC PDU.19.A processor for wireless communication, comprising:at least one memory; anda controller coupled with the at least one memory and configured to cause the controller to:receive a first medium access control protocol data unit (MAC PDU) via a transceiver from a second device for wireless communication, wherein the first MAC PDU comprises MAC control elements (CEs) with security protection; andbased on determining that security protection for at least one first MAC CE among the MAC CEs fails, perform at least one of the following:transmitting, via the transceiver to the second device, a feedback associated with results of the security protection for the MAC CEs,receiving an indication via the transceiver from the second device, ordiscarding the at least one first MA C CE.20.A processor for wireless communication, comprising:at least one memory; anda controller coupled with the at least one memory and configured to cause the controller to:transmit a medium access control protocol data unit (MAC PDU) via a transceiver to a first device for wireless communication, wherein the MAC PDU comprises MAC control elements (CEs) with security protection; andreceive, via the transceiver from the first device, a feedback associated with results of the security protection for the MAC CEs; ortransmit an indication via the transceiver to the first device.