Reference signal security for integrated sensing and communication

WO2026174526A1PCT designated stage Publication Date: 2026-08-27APPLE INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/078490
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2026-08-27

Smart Images

  • Figure CN2025078490_27082026_PF_FP_ABST
    Figure CN2025078490_27082026_PF_FP_ABST
Patent Text Reader

Abstract

A method of obfuscating a reference signal at a transmitter is disclosed. The method comprises receiving, at the transmitter, receiver obfuscation capability information from a receiver. Obfuscation configuration information is sent to the receiver. Secret obfuscation information is exchanged with the receiver. A reference signal is obfuscated to form an obfuscated reference signal based, in part, on the receiver obfuscation capability information. The obfuscated reference signal is transmitted to the receiver that is obfuscated based on the receiver obfuscation capability information to enable the receiver to remove obfuscation from the obfuscated reference signal and sense the reference signal based on the obfuscation configuration information and the secret obfuscation information.
Need to check novelty before this filing date? Find Prior Art

Description

REFERENCE SIGNAL SECURITY FOR INTEGRATED SENSING AND COMMUNICATION

[0001] Embodiments of the invention relate to wireless communications, including apparatuses, systems, and methods for reference signal security in wireless communication systems with integrated sensing and communication.DESCRIPTION OF THE RELATED ART

[0002] Wireless communication systems are used to provide various communication services such as telephone, video, data and messaging. The wireless communication systems can support communication with multiple users by sharing available system resources such as bandwidth and transmit power.

[0003] The wireless communication system may include a number of base stations (BSs) that can support communication for a number of user equipment (UEs) . A BS may be referred to as a Node B, a gNB, an access point (AP) , a radio head, a transmit receive point (TRP) , a New Radio (NR) BS, a 5G Node B, a 6G Node B, or the like. A UE may be referred to as a wireless mobile device or cellular phone.

[0004] Telecommunication standards have been adopted to provide a common protocol to enable different UEs and BSs to communicate on a municipal, national, regional, and even global level. Wireless communication system standards and protocols can include the 3rd Generation Partnership Project (3GPP) long term evolution (LTE) (e.g., 4G) or new radio (NR) (e.g., 5G) . In 3GPP radio access networks (RANs) in LTE systems, the base station can include a RAN Node such as an Evolved Universal Terrestrial Radio Access Network (E-UTRAN) Node B (also commonly denoted as evolved Node B, enhanced Node B, eNodeB, or eNB) and / or Radio Network Controller (RNC) in an E-UTRAN, which communicate with the UE. In fifth generation (5G) wireless RANs, RAN Nodes can include a 5G Node, or NR node (also referred to as a next generation Node B or g Node B (gNB) ) . In sixth generation (6G) wireless RANS, RAN nodes can include a 6G Node.BRIEF DESCRIPTION OF THE DRAWINGS

[0005] A better understanding of the present subject matter can be obtained when the following detailed description of various embodiments is considered in conjunction with the following drawings, in which:

[0006] FIG. 1A illustrates an example wireless communication system according to some embodiments.

[0007] FIG. 1B illustrates an example of a base station and an access point in communication with a user equipment (UE) device, according to some embodiments.

[0008] FIG. 2 illustrates an example block diagram of a base station, according to some embodiments.

[0009] FIG. 3 illustrates an example block diagram of a server according to some embodiments.

[0010] FIG. 4 illustrates an example block diagram of a UE according to some embodiments.

[0011] FIG. 5 illustrates an example block diagram of cellular communication circuitry, according to some embodiments.

[0012] FIG. 6 illustrates an example of a baseband processor architecture for a UE, according to some embodiments.

[0013] FIG. 7 illustrates an example block diagram of an interface of baseband circuitry according to some embodiments.

[0014] FIG. 8 illustrates example components of a core network in accordance with some embodiments.

[0015] FIG. 9 illustrates an example of a wireless communications network configured to transmit and / or receive sensing signals, in accordance with some embodiments.

[0016] FIG. 10 illustrates a diagram of a sequence of operations for a network-initiated location request (NI-LR) or mobile terminated location request (MT-LR) or an MT-LR location service, according to some embodiments.

[0017] FIG 11 illustrates an example block diagram showing several procedures that can be used to obfuscate a reference signal that is communicated between a transmitter and a receiver, according to some embodiments.

[0018] FIG. 12 illustrates an example block diagram that shows a portion of a transmit chain for the transmitter, a portion of a receive chain for the receiver, and a portion of a receive chain for an eavesdropping receiver Eve, in which the RS signal is obfuscated and de-obfuscated using per subcarrier obfuscation, according to some embodiments.

[0019] FIG. 13 illustrates an example block diagram that shows a portion of a transmit chain for the transmitter, a portion of a receive chain for the receiver, and a portion of a receive chain for Eve, in which the RS signal is obfuscated and de-obfuscated using filter based obfuscation, according to some embodiments.

[0020] FIG. 14 illustrates a diagram of an example of per subcarrier (Nsc) obfuscation, according to some embodiments.

[0021] FIG. 15 illustrates a diagram of an example block diagram that shows a portion of a transmit chain for the transmitter, a portion of a receive chain for the receiver, and a portion of a receive chain for Eve, in which the RS signal is obfuscated and de-obfuscated using noise with per subcarrier obfuscation, according to some embodiments.

[0022] FIG. 16 illustrates an example of a block diagram showing subcarriers Nsc in the RS signal with noise inserted, according to some embodiments.

[0023] FIGs. 17A and 17B illustrate an example of a table and block diagram of a radio frame structure for third generation partnership project new radio 5th generation (3GPP NR 5G) , according to some embodiments.

[0024] FIG. 17C provides an example block diagram showing m+1 fixed intervals (x) , where m is a positive integer, according to some embodiments.

[0025] FIG. 18 illustrates an example block diagram of explicit and blind parameter signaling that can be used to communicate the obfuscation information between the transmitter and the receiver, according to some embodiments.

[0026] FIG. 19 illustrates an example block diagram of a signaling procedure for obfuscation of an RS signal, according to some embodiments.

[0027] FIG. 20 illustrates a flow chart of a method for obfuscating a reference signal at a transmitter, in accordance with some embodiments.

[0028] While the features described herein may be susceptible to various modifications and alternative forms, specific embodiments thereof are shown by way of example in the drawings and are herein described in detail. It should be understood, however, that the drawings and detailed description thereto are not intended to be limiting to the particular form disclosed, but on the contrary, the intention is to cover all modifications, equivalents and alternatives falling within the spirit and scope of the subject matter as defined by the appended claims.DETAILED DESCRIPTIONTerms

[0029] The following is a glossary of terms used in this disclosure:

[0030] Memory Medium or Memory –Any of various types of non-transitory memory devices or storage devices. The term “memory medium” is intended to include an installation medium, e.g., a CD-ROM, floppy disks, or tape device; a computer system memory or random-access memory such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; a non-volatile memory such as a Flash, magnetic media, e.g., a hard drive, or optical storage; registers, or other similar types of memory elements, etc. The memory medium may include other types of non-transitory memory as well or combinations thereof. In addition, the memory medium may be located in a first computer system in which the programs are executed or may be located in a second different computer system which connects to the first computer system over a network, such as the Internet. In the latter instance, the second computer system may provide program instructions to the first computer for execution. The term “memory medium” may include two or more memory mediums which may reside in different locations, e.g., in different computer systems that are connected over a network. The memory medium may store program instructions (e.g., embodied as computer programs) that may be executed by one or more processors.

[0031] Carrier Medium –a memory medium as described above, as well as a physical transmission medium, such as a bus, network, and / or other physical transmission medium that conveys signals such as electrical, electromagnetic, or digital signals.

[0032] Programmable Hardware Element includes various hardware devices comprising multiple programmable function blocks connected via a programmable interconnect. Examples include FPGAs (Field Programmable Gate Arrays) , PLDs (Programmable Logic Devices) , FPOAs (Field Programmable Object Arrays) , and CPLDs (Complex PLDs) . The programmable function blocks may range from fine grained (combinatorial logic or look up tables) to coarse grained (arithmetic logic units or processor cores) . A programmable hardware element may also be referred to as "reconfigurable logic” .

[0033] Computer System (or Computer) –any of various types of computing or processing systems, including a personal computer system (PC) , mainframe computer system, workstation, network appliance, Internet appliance, personal digital assistant (PDA) , television system, grid computing system, or other device or combinations of devices. In general, the term "computer system" can be broadly defined to encompass any device (or combination of devices) having at least one processor that executes instructions from a memory medium.

[0034] User Equipment (UE) (or “UE Device” ) –any of various types of computer systems devices which are mobile or portable and which performs wireless communications. Examples of UE devices include mobile telephones or smart phones (e.g., iPhoneTM, AndroidTM-based phones) , portable gaming devices (e.g., Nintendo DSTM, PlayStation PortableTM, Gameboy AdvanceTM, iPhoneTM) , laptops, wearable devices (e.g., smart watch, smart glasses) , PDAs, portable Internet devices, Internet of Things, music players, data storage devices, other handheld devices, unmanned aerial vehicles (UAVs) (e.g., drones) , UAV controllers (UACs) , and so forth. In general, the term “UE” or “UE device” can be broadly defined to encompass any electronic, computing, and / or telecommunications device (or combination of devices) which is easily transported by a user and capable of wireless communication.

[0035] Base Station –The term “Base Station” has the full breadth of its ordinary meaning, and at least includes a wireless communication station installed at a fixed location and used to communicate with UEs as part of a wireless telephone system or radio system, including but not limited Next Generation Node-Bs (gNB or gNodeB) in NR and NG-RAN nodes.

[0036] Processing Element (or Processor) –refers to various elements or combinations of elements that are capable of performing a function in a device, such as a user equipment or a cellular network device. Processing elements may include, for example: processors and associated memory, portions or circuits of individual processor cores, entire processor cores, processor arrays, circuits such as an ASIC (Application Specific Integrated Circuit) , programmable hardware elements such as a field programmable gate array (FPGA) , as well any of various combinations of the above.

[0037] Channel -a medium used to convey information from a sender (transmitter) to a receiver. It should be noted that since characteristics of the term “channel” may differ according to different wireless protocols, the term “channel” as used herein may be considered as being used in a manner that is consistent with the standard of the type of device with reference to which the term is used. In some standards, channel widths may be variable (e.g., depending on device capability, band conditions, etc. ) . For example, LTE may support scalable channel bandwidths from 1.4 MHz to 20MHz. 5G NR can support scalable channel bandwidths from 5 MHz to 100 MHz in Frequency Range 1 (FR1) and up to 400 MHz in FR2. In other radio access technologies, WLAN channels may be 22 MHz wide while Bluetooth channels may be 1 MHz wide. Other protocols and standards may include different definitions of channels. Furthermore, some standards may define and use multiple types of channels, e.g., different channels for uplink or downlink and / or different channels for different uses such as data, control information, etc.

[0038] Band -The term "band" has the full breadth of its ordinary meaning, and at least includes a section of spectrum (e.g., radio frequency spectrum) in which channels are used or set aside for the same purpose.

[0039] Automatically –refers to an action or operation performed by a computer system (e.g., software executed by the computer system) or device (e.g., circuitry, programmable hardware elements, ASICs, etc. ) , without user input directly specifying or performing the action or operation. Thus, the term "automatically" is in contrast to an operation being manually performed or specified by the user, where the user provides input to directly perform the operation. An automatic procedure may be initiated by input provided by the user, but the subsequent actions that are performed “automatically” are not specified by the user, i.e., are not performed “manually” , where the user specifies each action to perform. For example, a user filling out an electronic form by selecting each field and providing input specifying information (e.g., by typing information, selecting check boxes, radio selections, etc. ) is filling out the form manually, even though the computer system will update the form in response to the user actions. The form may be automatically filled out by the computer system where the computer system (e.g., software executing on the computer system) analyzes the fields of the form and fills in the form without any user input specifying the answers to the fields. As indicated above, the user may invoke the automatic filling of the form but is not involved in the actual filling of the form (e.g., the user is not manually specifying answers to fields but rather they are being automatically completed) . The present specification provides various examples of operations being automatically performed in response to actions the user has taken.

[0040] Approximately -refers to a value that is almost correct or exact. For example, approximately may refer to a value that is within 1 to 10 percent of the exact (or desired) value. It should be noted, however, that the actual threshold value (or tolerance) may be application dependent. For example, in some embodiments, “approximately” may mean within 0.1%of some specified or desired value, while in various other embodiments, the threshold may be, for example, 2%, 3%, 5%, and so forth, as desired or as set by the particular application.

[0041] Concurrent –refers to parallel execution or performance, where tasks, processes, or programs are performed in an at least partially overlapping manner. For example, concurrency may be implemented using “strong” or strict parallelism, where tasks are performed (at least partially) in parallel on respective computational elements, or using “weak parallelism” , where the tasks are performed in an interleaved manner, e.g., by time multiplexing of execution threads.

[0042] Various components may be described as “configured to” perform a task or tasks. In such contexts, “configured to” is a broad recitation generally meaning “having structure that” performs the task or tasks during operation. As such, the component can be configured to perform the task even when the component is not currently performing that task (e.g., a set of electrical conductors may be configured to electrically connect a module to another module, even when the two modules are not connected) . In some contexts, “configured to” may be a broad recitation of structure generally meaning “having circuitry that” performs the task or tasks during operation. As such, the component can be configured to perform the task even when the component is not currently on. In general, the circuitry that forms the structure corresponding to “configured to” may include hardware circuits.

[0043] Various components may be described as performing a task or tasks, for convenience in the description. Such descriptions should be interpreted as including the phrase “configured to. ” Reciting a component that is configured to perform one or more tasks is expressly intended not to invoke 35 U.S.C. § 112 (f) interpretation for that component.

[0044] The example embodiments may be further understood with reference to the following description and the related appended drawings, wherein like elements are provided with the same reference numerals. The example embodiments relate to apparatuses, systems and methods for signaling and procedure of an artificial intelligence / machine learning (AI / ML) dataset and / or model parameter transfer between a network (NW) entity and a user equipment (UE) server for two-sided model including establishment of a tunnel between a NW training entity and a UE-side training server to enable non-over-the air (non-OTA) signaling and inter-vendor training collaboration.

[0045] The example embodiments are described with regard to communication between a network (NW) via a Radio Access Networks (RAN) , e.g. a base station or a Next Generation Node B (gNB) , and a user equipment (UE) . However, reference to a base station (gNB) or a UE is merely provided for illustrative purposes. The example embodiments may be utilized with any electronic component that may establish a connection to a network and is configured with the hardware, software, and / or firmware to support establishing a tunnel for non-OTA signaling between a NW training entity and a UE-side training server. Therefore, the gNB or UE as described herein is used to represent any appropriate type of electronic component.

[0046] The example embodiments are also described with regard to a fifth generation (5G) New Radio (NR) or a sixth generation (6G) . However, reference to a 5G NR network or a 6G Network is merely provided for illustrative purposes. The example embodiments may be utilized with any appropriate type of network.Figures 1A and 1B: Communication Systems

[0047] FIG. 1A illustrates a simplified example wireless communication system, according to some embodiments. It is noted that the system of FIG. 1A is merely one example of a possible system, and that features of this disclosure may be implemented in any of various systems, as desired.

[0048] As shown, the example wireless communication system includes a base station 102A which communicates over a transmission medium with one or more user devices 106A, 106B, etc., through 106N. Each of the user devices may be referred to herein as a “user equipment” (UE) . Thus, the user devices 106 are referred to as UEs or UE devices.

[0049] The base station (BS) 102A may be a base transceiver station (BTS) or cell site (a “cellular base station” ) and may include hardware that enables wireless communication with the UEs 106A through 106N.

[0050] The communication area (or coverage area) of the base station may be referred to as a “cell. ” The base station 102A and the UEs 106 may be configured to communicate over the transmission medium using any of various radio access technologies (RATs) , also referred to as wireless communication technologies, or telecommunication standards, such as GSM, UMTS (associated with, for example, WCDMA or TD-SCDMA air interfaces) , LTE, LTE-Advanced (LTE-A) , 5G new radio (5G NR) , HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD) , etc. Note that if the base station 102A is implemented in the context of LTE, also referred to as the Evolved Universal Terrestrial Radio Access Network (E-UTRAN, it may alternately be referred to as an 'eNodeB' or ‘eNB’ . Note that if the base station 102A is implemented in the context of 5G NR, it may alternately be referred to as ‘gNodeB’ or ‘gNB’ .

[0051] As shown, the base station 102A may also be equipped to communicate with a network 100 (e.g., a core network 820 of a cellular service provider, a telecommunication network such as a public switched telephone network (PSTN) , and / or the Internet, among various possibilities) . Thus, the base station 102A may facilitate communication between the user devices and / or between the user devices and the network 100. In particular, the cellular base station 102A may provide UEs 106 with various telecommunication capabilities, such as voice, SMS and / or data services.

[0052] Base station 102A and other similar base stations (such as base stations 102B…102N) operating according to the same or a different cellular communication standard may thus be provided as a network of cells, which may provide continuous or nearly continuous overlapping service to UEs 106A-N and similar devices over a geographic area via one or more cellular communication standards.

[0053] Thus, while base station 102A may act as a “serving cell” for UEs 106A-N as illustrated in FIG. 1A, each UE 106 may also be capable of receiving signals from (and possibly within communication range of) one or more other cells (which might be provided by base stations 102B-N and / or any other base stations) , which may be referred to as “neighboring cells” . Such cells may also be capable of facilitating communication between user devices and / or between user devices and the network 100. Such cells may include “macro” cells, “micro” cells, “pico” cells, and / or cells which provide any of various other granularities of service area size. For example, base stations 102A-B illustrated in FIG. 1A might be macro cells, while base station 102N might be a micro cell. Other configurations are also possible.

[0054] In some embodiments, base station 102A may be a next generation base station, e.g., a 5G New Radio (5G NR) base station, or “gNB” . In some embodiments, a gNB may be connected to a legacy evolved packet core (EPC) network and / or to a NR core (NRC) network. In addition, a gNB cell may include one or more transmission and reception points (TRPs) . In addition, a UE capable of operating according to 5G NR may be connected to one or more TRPs within one or more gNBs.

[0055] Note that a UE 106 may be capable of communicating using multiple wireless communication standards. For example, the UE 106 may be configured to communicate using a wireless networking (e.g., Wi-Fi) and / or peer-to-peer wireless communication protocol (e.g., Bluetooth, Wi-Fi peer-to-peer, etc. ) in addition to at least one cellular communication protocol (e.g., GSM, UMTS (associated with, for example, WCDMA or TD-SCDMA air interfaces) , LTE, LTE-A, 5G NR, HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD) , etc. ) . The UE 106 may also or alternatively be configured to communicate using one or more global navigational satellite systems (GNSS, e.g., GPS or GLONASS) , one or more mobile television broadcasting standards (e.g., ATSC-M / H or DVB-H) , and / or any other wireless communication protocol, if desired. Other combinations of wireless communication standards (including more than two wireless communication standards) are also possible.

[0056] In some embodiments, the base station 102A may select an obfuscation configuration for UEs 106. The base station 102A may encode and transmit the obfuscation configuration information and secret obfuscation information to UEs 106 as part of a reference signal obfuscation process. Using the obfuscation configuration and secret obfuscation information, the UEs 106 can determine which subcarriers over an obfuscation time interval in a reference signal are beien obfuscated. The UEs 106 can then remove the obfuscation from the subcarriers over the obfuscation time interval to enable the UEs to receive and sense the reference signal sent from the base station.

[0057] FIG. 1B illustrates user equipment 106 (e.g., one of the devices 106A through 106N) in communication with a base station 102 and an access point 112, according to some embodiments. The UE 106 may be a device with both cellular communication capability and non-cellular communication capability (e.g., Bluetooth, Wi-Fi, and so forth) such as a mobile phone, a hand-held device, a computer or a tablet, or virtually any type of wireless device.

[0058] The UE 106 may include a processor that is configured to execute program instructions stored in memory. The UE 106 may perform any of the method embodiments described herein by executing such stored instructions. Alternatively, or in addition, the UE 106 may include a programmable hardware element such as an FPGA (field-programmable gate array) that is configured to perform any of the method embodiments described herein, or any portion of any of the method embodiments described herein.

[0059] The UE 106 may include one or more antennas for communicating using one or more wireless communication protocols or technologies. In some embodiments, the UE 106 may be configured to communicate using, for example, CDMA2000 (1xRTT  / 1xEV-DO  / HRPD  / eHRPD) , LTE / LTE-Advanced, or 5G NR using a single shared radio and / or GSM, LTE, LTE-Advanced, or 5G NR using the single shared radio. The shared radio may couple to a single antenna, or may couple to multiple antennas (e.g., for MIMO) for performing wireless communications. In general, a radio may include any combination of a baseband processor, analog RF signal processing circuitry (e.g., including filters, mixers, oscillators, amplifiers, etc. ) , or digital processing circuitry (e.g., for digital modulation as well as other digital processing) . Similarly, the radio may implement one or more receive and transmit chains using the aforementioned hardware. For example, the UE 106 may share one or more parts of a receive and / or transmit chain between multiple wireless communication technologies, such as those discussed above.

[0060] In some embodiments, the UE 106 may include separate transmit and / or receive chains (e.g., including separate antennas and other radio components) for each wireless communication protocol with which it is configured to communicate. As a further possibility, the UE 106 may include one or more radios which are shared between multiple wireless communication protocols, and one or more radios which are used exclusively by a single wireless communication protocol. For example, the UE 106 might include a shared radio for communicating using either of LTE or 5G NR (or LTE or 1xRTTor LTE or GSM) , and separate radios for communicating using each of Wi-Fi and Bluetooth. Other configurations are also possible.FIG. 2: Block Diagram of a Base Station (gNB)

[0061] FIG. 2 illustrates an example block diagram of a base station 102, according to some embodiments. It is noted that the base station of FIG. 2 is merely one example of a possible base station. As shown, the base station 102 may include processor (s) 204 which may execute program instructions for the base station 102. The processor (s) 204 may also be coupled to memory management unit (MMU) 240, which may be configured to receive addresses from the processor (s) 204 and translate those addresses to locations in memory (e.g., memory 260 and read only memory (ROM) 250) or to other circuits or devices.

[0062] The base station 102 may include at least one network port 270. The network port 270 may be configured to couple to a telephone network and provide a plurality of devices, such as UE devices 106, access to the telephone network as described above in Figures 1 and 2.

[0063] The network port 270 (or an additional network port) may also or alternatively be configured to couple to a cellular network, e.g., a core network of a cellular service provider. The core network may provide mobility related services and / or other services to a plurality of devices, such as UE devices 106. In some cases, the network port 270 may couple to a telephone network via the core network, and / or the core network may provide a telephone network (e.g., among other UE devices serviced by the cellular service provider) .

[0064] In some embodiments, base station 102 may be a next generation base station, e.g., a 5G New Radio (5G NR) base station, or “gNB” . In such embodiments, base station 102 may be connected to a legacy evolved packet core (EPC) network and / or to a NR core (NRC) network. In addition, base station 102 may be considered a 5G NR cell and may include one or more transmission and reception points (TRPs) . In addition, a UE capable of operating according to 5G NR may be connected to one or more TRPs within one or more gNBs.

[0065] The base station 102 may include at least one antenna 234, and possibly multiple antennas. The at least one antenna 234 may be configured to operate as a wireless transceiver and may be further configured to communicate with UE devices 106 via radio 230. The antenna 234 communicates with the radio 230 via communication chain 232. Communication chain 232 may be a receive chain, a transmit chain or both. The radio 230 may be configured to communicate via various wireless communication standards, including, but not limited to, 5G NR, LTE, LTE-A, GSM, UMTS, CDMA2000, Wi-Fi, etc.

[0066] The base station 102 may be configured to communicate wirelessly using multiple wireless communication standards. In some instances, the base station 102 may include multiple radios, which may enable the base station 102 to communicate according to multiple wireless communication technologies. For example, as one possibility, the base station 102 may include an LTE radio for performing communication according to LTE as well as a 5G NR radio for performing communication according to 5G NR. In such a case, the base station 102 may be capable of operating as both an LTE base station and a 5G NR base station. As another possibility, the base station 102 may include a multi-mode radio which is capable of performing communications according to any of multiple wireless communication technologies (e.g., 5G NR and Wi-Fi, LTE and Wi-Fi, LTE and UMTS, LTE and CDMA2000, UMTS and GSM, etc. ) .

[0067] As described further subsequently herein, the base station 102 may include hardware and software components for implementing or supporting implementation of features described herein. The processor 204 of the base station 102 may be configured to implement or support implementation of part or all of the methods described herein, e.g., by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium) . Alternatively, the processor 204 may be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) , or as an ASIC (Application Specific Integrated Circuit) , or a combination thereof. Alternatively (or in addition) the processor 204 of the base station 102, in conjunction with one or more of the other components 230, 232, 234, 240, 250, 260, 270 may be configured to implement or support implementation of part or all of the features described herein.

[0068] In addition, as described herein, processor (s) 204 may be comprised of one or more processing elements. In other words, one or more processing elements may be included in processor (s) 204. Thus, processor (s) 204 may include one or more integrated circuits (ICs) that are configured to perform the functions of processor (s) 204. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of processor (s) 204.

[0069] Further, as described herein, radio 230 may be comprised of one or more processing elements. In other words, one or more processing elements may be included in radio 230. Thus, radio 230 may include one or more integrated circuits (ICs) that are configured to perform the functions of radio 230. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of radio 230.

[0070] In some embodiments, the RAN, base station or gNB 102, and / or processors 204 thereof, can be capable of and configured to transmit (or encode for transmission) : obfuscation configuration information and secret obfuscation information for a reference signal to enable the UE to receive an obfuscated reference signal and remove the obfuscation to receive and sense the reference signal at the receiver.FIG. 3: Block Diagram of a Server

[0071] FIG. 3 illustrates an example block diagram of a server 104, according to some embodiments. It is noted that the server of FIG. 3 is merely one example of a possible server. As shown, the server 104 may include processor (s) 344 which may execute program instructions for the server 104. The processor (s) 344 may also be coupled to memory management unit (MMU) 374, which may be configured to receive addresses from the processor (s) 344 and translate those addresses to locations in memory (e.g., memory 364 and read only memory (ROM) 354) or to other circuits or devices.

[0072] The server 104 may be configured to provide a plurality of devices, such as base station 102, and UE devices 106 access to network functions, e.g., as further described herein.

[0073] In some embodiments, the server 104 may be part of a radio access network, such as a 5G New Radio (5G NR) radio access network. In some embodiments, the server 104 may be connected to a legacy evolved packet core (EPC) network and / or to a NR core (NRC) network.

[0074] As described herein, the server 104 may include hardware and software components for implementing or supporting implementation of features described herein. The processor 344 of the server 104 may be configured to implement or support implementation of part or all of the methods described herein, e.g., by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium) . Alternatively, the processor 344 may be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) , or as an ASIC (Application Specific Integrated Circuit) , or a combination thereof. Alternatively (or in addition) the processor 344 of the server 104, in conjunction with one or more of the other components 354, 364, and / or 374 may be configured to implement or support implementation of part or all of the features described herein.

[0075] In addition, as described herein, processor (s) 344 may be comprised of one or more processing elements. In other words, one or more processing elements may be included in processor (s) 344. Thus, processor (s) 344 may include one or more integrated circuits (ICs) that are configured to perform the functions of processor (s) 344. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of processor (s) 344.FIG. 4: Block Diagram of a User Equipment (UE)

[0076] FIG. 4 illustrates an example simplified block diagram of a communication device 106, according to some embodiments. It is noted that the block diagram of the communication device of FIG. 4 is only one example of a possible communication device. According to embodiments, communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop, notebook, or portable computing device) , a tablet, an unmanned aerial vehicle (UAV) , a UAV controller (UAC) and / or a combination of devices, among other devices. As shown, the communication device 106 may include a set of components 400 configured to perform core functions. For example, this set of components may be implemented as a system on chip (SOC) , which may include portions for various purposes. Alternatively, this set of components 400 may be implemented as separate components or groups of components for the various purposes. The set of components 400 may be coupled (e.g., communicatively; directly or indirectly) to various other circuits of the communication device 106.

[0077] For example, the communication device 106 may include various types of memory (e.g., including NAND flash 410) , an input / output interface such as connector I / F 420 (e.g., for connecting to a computer system; dock; charging station; input devices, such as a microphone, camera, keyboard; output devices, such as speakers; etc. ) , the display 460, which may be integrated with or external to the communication device 106, and cellular communication circuitry 430 such as for 5G NR, LTE, GSM, etc., and short to medium range wireless communication circuitry 429 (e.g., BluetoothTM and WLAN circuitry) . In some embodiments, communication device 106 may include wired communication circuitry (not shown) , such as a network interface card, e.g., for Ethernet.

[0078] The cellular communication circuitry 430 may couple (e.g., communicatively; directly or indirectly) to one or more antennas, such as antennas 435 and 436 as shown. The short to medium range wireless communication circuitry 429 may also couple (e.g., communicatively; directly or indirectly) to one or more antennas, such as antennas 437 and 438 as shown. Alternatively, the short to medium range wireless communication circuitry 429 may couple (e.g., communicatively; directly or indirectly) to the antennas 435 and 436 in addition to, or instead of, coupling (e.g., communicatively; directly or indirectly) to the antennas 437 and 438. The short to medium range wireless communication circuitry 429 and / or cellular communication circuitry 430 may include multiple receive chains and / or multiple transmit chains for receiving and / or transmitting multiple spatial streams, such as in a multiple-input multiple output (MIMO) configuration.

[0079] In some embodiments, as further described below, cellular communication circuitry 430 may include dedicated receive chains (including and / or coupled to, e.g., communicatively; directly or indirectly. dedicated processors and / or radios) for multiple RATs (e.g., a first receive chain for LTE and a second receive chain for 5G NR) . In addition, in some embodiments, cellular communication circuitry 430 may include a single transmit chain that may be switched between radios dedicated to specific RATs. For example, a first radio may be dedicated to a first RAT, e.g., LTE, and may be in communication with a dedicated receive chain and a transmit chain shared with an additional radio, e.g., a second radio that may be dedicated to a second RAT, e.g., 5G NR, and may be in communication with a dedicated receive chain and the shared transmit chain.

[0080] The communication device 106 may also include and / or be configured for use with one or more user interface elements. The user interface elements may include any of various elements, such as display 460 (which may be a touchscreen display) , a keyboard (which may be a discrete keyboard or may be implemented as part of a touchscreen display) , a mouse, a microphone and / or speakers, one or more cameras, one or more buttons, and / or any of various other elements capable of providing information to a user and / or receiving or interpreting user input.

[0081] The communication device 106 may further include one or more smart cards 445 that include SIM (Subscriber Identity Module) functionality, such as one or more UICC (s) (Universal Integrated Circuit Card (s) ) cards 445. Note that the term “SIM” or “SIM entity” is intended to include any of various types of SIM implementations or SIM functionality, such as the one or more UICC (s) cards 445, one or more eUICCs, one or more eSIMs, either removable or embedded, etc. In some embodiments, the UE 106 may include at least two SIMs. Each SIM may execute one or more SIM applications and / or otherwise implement SIM functionality. Thus, each SIM may be a single smart card that may be embedded, e.g., may be soldered onto a circuit board in the UE 106, or each SIM 410 may be implemented as a removable smart card. Thus, the SIM (s) may be one or more removable smart cards (such as UICC cards, which are sometimes referred to as “SIM cards” ) , and / or the SIMs 410 may be one or more embedded cards (such as embedded UICCs (eUICCs) , which are sometimes referred to as “eSIMs” or “eSIM cards” ) . In some embodiments (such as when the SIM (s) include an eUICC) , one or more of the SIM (s) may implement embedded SIM (eSIM) functionality; in such an embodiment, a single one of the SIM (s) may execute multiple SIM applications. Each of the SIMs may include components such as a processor and / or a memory; instructions for performing SIM / eSIM functionality may be stored in the memory and executed by the processor. In some embodiments, the UE 106 may include a combination of removable smart cards and fixed / non-removable smart cards (such as one or more eUICC cards that implement eSIM functionality) , as desired. For example, the UE 106 may comprise two embedded SIMs, two removable SIMs, or a combination of one embedded SIMs and one removable SIMs. Various other SIM configurations are also contemplated.

[0082] As noted above, in some embodiments, the UE 106 may include two or more SIMs. The inclusion of two or more SIMs in the UE 106 may allow the UE 106 to support two different telephone numbers and may allow the UE 106 to communicate on the corresponding two or more respective networks. For example, a first SIM may support a first RAT such as LTE, and a second SIM 410 support a second RAT such as 5G NR. Other implementations and RATs are of course possible. In some embodiments, when the UE 106 comprises two SIMs, the UE 106 may support Dual SIM Dual Active (DSDA) functionality. The DSDA functionality may allow the UE 106 to be simultaneously connected to two networks (and use two different RATs) at the same time, or to simultaneously maintain two connections supported by two different SIMs using the same or different RATs on the same or different networks. The DSDA functionality may also allow the UE 106 to simultaneously receive voice calls or data traffic on either phone number. In certain embodiments the voice call may be a packet switched communication. In other words, the voice call may be received using voice over LTE (VoLTE) technology and / or voice over NR (VoNR) technology. In some embodiments, the UE 106 may support Dual SIM Dual Standby (DSDS) functionality. The DSDS functionality may allow either of the two SIMs in the UE 106 to be on standby waiting for a voice call and / or data connection. In DSDS, when a call / data is established on one SIM, the other SIM is no longer active. In some embodiments, DSDx functionality (either DSDA or DSDS functionality) may be implemented with a single SIM (e.g., a eUICC) that executes multiple SIM applications for different carriers and / or RATs.

[0083] As shown, the SOC 400 may include processor (s) 402, which may execute program instructions for the communication device 106 and display circuitry 404, which may perform graphics processing and provide display signals to the display 460. The processor (s) 402 may also be coupled to memory management unit (MMU) 440, which may be configured to receive addresses from the processor (s) 402 and translate those addresses to locations in memory (e.g., memory 406, read only memory (ROM) 450, NAND flash memory 410) and / or to other circuits or devices, such as the display circuitry 404, short to medium range wireless communication circuitry 429, cellular communication circuitry 430, connector I / F 420, and / or display 460. The MMU 440 may be configured to perform memory protection and page table translation or set up. In some embodiments, the MMU 440 may be included as a portion of the processor (s) 402.

[0084] As described herein, the communication device 106 may include hardware and software components for implementing the above features for a communication device 106 to communicate a scheduling profile for power savings to a network. The processor 402 of the communication device 106 may be configured to implement part or all of the features described herein, e.g., by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium) . Alternatively (or in addition) , processor 402 may be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) , or as an ASIC (Application Specific Integrated Circuit) . Alternatively (or in addition) the processor 402 of the communication device 106, in conjunction with one or more of the other components 400, 404, 406, 410, 420, 429, 430, 440, 445, 450, 460 may be configured to implement part or all of the features described herein.

[0085] In addition, as described herein, processor 402 may include one or more processing elements. Thus, processor 402 may include one or more integrated circuits (ICs) that are configured to perform the functions of processor 402. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of processor (s) 402.

[0086] Further, as described herein, cellular communication circuitry 430 and short to medium range wireless communication circuitry 429 may each include one or more processing elements. In other words, one or more processing elements may be included in cellular communication circuitry 430 and, similarly, one or more processing elements may be included in short to medium range wireless communication circuitry 429. Thus, cellular communication circuitry 430 may include one or more integrated circuits (ICs) that are configured to perform the functions of cellular communication circuitry 430. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of cellular communication circuitry 430. Similarly, the short to medium range wireless communication circuitry 429 may include one or more ICs that are configured to perform the functions of short to medium range wireless communication circuitry 429. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of short to medium range wireless communication circuitry 429.

[0087] The UE 106 can receive an obfuscated reference signal and remove the obfuscation based on obfuscation configuration information and secret obfuscation information received and decoded at the UE using, at least in part, the processor 402.FIG. 5: Block Diagram of Cellular Communication Circuitry

[0088] FIG. 5 illustrates an example simplified block diagram of cellular communication circuitry, according to some embodiments. It is noted that the block diagram of the cellular communication circuitry of FIG. 5 is only one example of a possible cellular communication circuit. According to embodiments, cellular communication circuitry 530, which may be cellular communication circuitry 430, may be included in a communication device, such as communication device 106 described above. As noted above, communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop, notebook, or portable computing device) , a tablet and / or a combination of devices, among other devices.

[0089] The cellular communication circuitry 530 may couple (e.g., communicatively; directly or indirectly) to one or more antennas, such as antennas 435a-b and 436 as shown (in FIG. 4) . In some embodiments, cellular communication circuitry 530 may include dedicated receive chains (including and / or coupled to, e.g., communicatively; directly or indirectly. dedicated processors and / or radios) for multiple RATs (e.g., a first receive chain for LTE and a second receive chain for 5G NR) . For example, as shown in FIG. 5, cellular communication circuitry 530 may include a modem 510 and a modem 520. Modem 510 may be configured for communications according to a first RAT, e.g., such as LTE or LTE-A, and modem 520 may be configured for communications according to a second RAT, e.g., such as 5G NR.

[0090] As shown, modem 510 may include one or more processors 512 and a memory 516 in communication with processors 512. Modem 510 may be in communication with a radio frequency (RF) front end 535. RF front end 535 may include circuitry for transmitting and receiving radio signals. For example, RF front end 535 may include receive circuitry (RX) 532 and transmit circuitry (TX) 534. In some embodiments, receive circuitry 532 may be in communication with downlink (DL) front end 550, which may include circuitry for receiving radio signals via antenna 335a.

[0091] Similarly, modem 520 may include one or more processors 522 and a memory 526 in communication with processors 522. Modem 520 may be in communication with an RF front end 540. RF front end 540 may include circuitry for transmitting and receiving radio signals. For example, RF front end 540 may include receive circuitry 542 and transmit circuitry 544. In some embodiments, receive circuitry 542 may be in communication with DL front end 560, which may include circuitry for receiving radio signals via antenna 335b.

[0092] In some embodiments, a switch 570 may couple transmit circuitry 534 to uplink (UL) front end 572. In addition, switch 570 may couple transmit circuitry 544 to UL front end 572. UL front end 572 may include circuitry for transmitting radio signals via antenna 336. Thus, when cellular communication circuitry 530 receives instructions to transmit according to the first RAT (e.g., as supported via modem 510) , switch 570 may be switched to a first state that allows modem 510 to transmit signals according to the first RAT (e.g., via a transmit chain that includes transmit circuitry 534 and UL front end 572) . Similarly, when cellular communication circuitry 530 receives instructions to transmit according to the second RAT (e.g., as supported via modem 520) , switch 570 may be switched to a second state that allows modem 520 to transmit signals according to the second RAT (e.g., via a transmit chain that includes transmit circuitry 544 and UL front end 572) .

[0093] As described herein, the modem 510 may include hardware and software components for implementing the above features or for time division multiplexing UL data for NSA NR operations, as well as the various other techniques described herein. The processors 512 may be configured to implement part or all of the features described herein, e.g., by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium) . Alternatively (or in addition) , processor 512 may be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) , or as an ASIC (Application Specific Integrated Circuit) . Alternatively (or in addition) the processor 512, in conjunction with one or more of the other components 530, 532, 534, 535, 550, 570, 572, 335a, 335b, and 336 may be configured to implement part or all of the features described herein.

[0094] In addition, as described herein, processors 512 may include one or more processing elements. Thus, processors 512 may include one or more integrated circuits (ICs) that are configured to perform the functions of processors 512. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of processors 512.

[0095] The processors 522 may be configured to implement part or all of the features described herein, e.g., by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium) . Alternatively (or in addition) , processor 522 may be configured as a programmable hardware element, such as an FPGA (Field Programmable Gate Array) , or as an ASIC (Application Specific Integrated Circuit) . Alternatively (or in addition) the processor 522, in conjunction with one or more of the other components 540, 542, 544, 550, 570, 572, 335a, 335b, and 336 may be configured to implement part or all of the features described herein.

[0096] In addition, as described herein, processors 522 may include one or more processing elements. Thus, processors 522 may include one or more integrated circuits (ICs) that are configured to perform the functions of processors 522. In addition, each integrated circuit may include circuitry (e.g., first circuitry, second circuitry, etc. ) configured to perform the functions of processors 522.FIG. 6: Block Diagram of a Baseband Processor Architecture for a UE

[0097] FIG. 6 illustrates example components of a device 600 in accordance with some embodiments. It is noted that the device of FIG. 6 is merely one example of a possible system, and that features of this disclosure may be implemented in any of various UEs, as desired.

[0098] In some embodiments, the device 600 may include application circuitry 602, baseband circuitry 604, Radio Frequency (RF) circuitry 606, front-end module (FEM) circuitry 608, one or more antennas 610, and power management circuitry (PMC) 612 coupled together at least as shown. The components of the illustrated device 600 may be included in a UE 106 or a RAN node 102A. In some embodiments, the device 600 may include less elements (e.g., a RAN node may not utilize application circuitry 602, and instead include a processor / controller to process IP data received from an EPC) . In some embodiments, the device 600 may include additional elements such as, for example, memory / storage, display, camera, sensor, or input / output (I / O) interface. In other embodiments, the components described below may be included in more than one device (e.g., said circuitries may be separately included in more than one device for Cloud-RAN (C-RAN) implementations) .

[0099] The application circuitry 602 may include one or more application processors. For example, the application circuitry 602 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processor (s) may include any combination of general-purpose processors and dedicated processors (e.g., graphics processors, application processors, etc. ) . The processors may be coupled with or may include memory / storage and may be configured to execute instructions stored in the memory / storage to enable various applications or operating systems to run on the device 600. In some embodiments, processors of application circuitry 602 may process IP data packets received from an EPC.

[0100] The baseband circuitry 604 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The baseband circuitry 604 may include one or more baseband processors or control logic to process baseband signals received from a receive signal path of the RF circuitry 606 and to generate baseband signals for a transmit signal path of the RF circuitry 606. Baseband processing circuity 604 may interface with the application circuitry 602 for generation and processing of the baseband signals and for controlling operations of the RF circuitry 606. For example, in some embodiments, the baseband circuitry 604 may include a third generation (3G) baseband processor 604A, a fourth generation (4G) baseband processor 604B, a fifth generation (5G) baseband processor 604C, or other baseband processor (s) 604D for other existing generations, generations in development or to be developed in the future (e.g., second generation (2G) , sixth generation (6G) , etc. ) . The baseband circuitry 604 (e.g., one or more of baseband processors 604A-D) may handle various radio control functions that enable communication with one or more radio networks via the RF circuitry 606. In other embodiments, some or all of the functionality of baseband processors 604A-D may be included in modules stored in the memory 604G and executed via a Central Processing Unit (CPU) 604E. The radio control functions may include, but are not limited to, signal modulation / demodulation, encoding / decoding, radio frequency shifting, etc. In some embodiments, modulation / demodulation circuitry of the baseband circuitry 604 may include Fast-Fourier Transform (FFT) , precoding, or constellation mapping / demapping functionality. In some embodiments, encoding / decoding circuitry of the baseband circuitry 604 may include convolution, tail-biting convolution, turbo, Viterbi, or Low Density Parity Check (LDPC) encoder / decoder functionality. Embodiments of modulation / demodulation and encoder / decoder functionality are not limited to these examples and may include other suitable functionality in other embodiments.

[0101] In some embodiments, the baseband circuitry 604 may include one or more audio digital signal processor (s) (DSP) 604F. The audio DSP (s) 604F may be include elements for compression / decompression and echo cancellation and may include other suitable processing elements in other embodiments. Components of the baseband circuitry may be suitably combined in a single chip, a single chipset, or disposed on a same circuit board in some embodiments. In some embodiments, some or all of the constituent components of the baseband circuitry 604 and the application circuitry 602 may be implemented together such as, for example, on a system on a chip (SOC) .

[0102] In some embodiments, the baseband circuitry 604 may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry 604 may support communication with an evolved universal terrestrial radio access network (EUTRAN) or other wireless metropolitan area networks (WMAN) , a wireless local area network (WLAN) , a wireless personal area network (WPAN) . Embodiments in which the baseband circuitry 604 is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuitry.

[0103] RF circuitry 606 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry 606 may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. RF circuitry 606 may include a receive signal path which may include circuitry to down-convert RF signals received from the FEM circuitry 608 and provide baseband signals to the baseband circuitry 604. RF circuitry 606 may also include a transmit signal path which may include circuitry to up-convert baseband signals provided by the baseband circuitry 604 and provide RF output signals to the FEM circuitry 608 for transmission.

[0104] In some embodiments, the receive signal path of the RF circuitry 606 may include mixer circuitry 606a, amplifier circuitry 606b and filter circuitry 606c. In some embodiments, the transmit signal path of the RF circuitry 606 may include filter circuitry 606c and mixer circuitry 606a. RF circuitry 606 may also include synthesizer circuitry 606d for synthesizing a frequency for use by the mixer circuitry 606a of the receive signal path and the transmit signal path. In some embodiments, the mixer circuitry 606a of the receive signal path may be configured to down-convert RF signals received from the FEM circuitry 608 based on the synthesized frequency provided by synthesizer circuitry 606d. The amplifier circuitry 606b may be configured to amplify the down-converted signals and the filter circuitry 606c may be a low-pass filter (LPF) or band-pass filter (BPF) configured to remove unwanted signals from the down-converted signals to generate output baseband signals. Output baseband signals may be provided to the baseband circuitry 604 for further processing. In some embodiments, the output baseband signals may be zero-frequency baseband signals, although this is not a necessity. In some embodiments, mixer circuitry 606a of the receive signal path may comprise passive mixers, although the scope of the embodiments is not limited in this respect.

[0105] In some embodiments, the mixer circuitry 606a of the transmit signal path may be configured to up-convert input baseband signals based on the synthesized frequency provided by the synthesizer circuitry 606d to generate RF output signals for the FEM circuitry 608. The baseband signals may be provided by the baseband circuitry 604 and may be filtered by filter circuitry 606c.

[0106] In some embodiments, the mixer circuitry 606a of the receive signal path and the mixer circuitry 606a of the transmit signal path may include two or more mixers and may be arranged for quadrature downconversion and upconversion, respectively. In some embodiments, the mixer circuitry 606a of the receive signal path and the mixer circuitry 606a of the transmit signal path may include two or more mixers and may be arranged for image rejection (e.g., Hartley image rejection) . In some embodiments, the mixer circuitry 606a of the receive signal path and the mixer circuitry 606a may be arranged for direct downconversion and direct upconversion, respectively. In some embodiments, the mixer circuitry 606a of the receive signal path and the mixer circuitry 606a of the transmit signal path may be configured for super-heterodyne operation.

[0107] In some embodiments, the output baseband signals and the input baseband signals may be analog baseband signals, although the scope of the embodiments is not limited in this respect. In some alternate embodiments, the output baseband signals and the input baseband signals may be digital baseband signals. In these alternate embodiments, the RF circuitry 606 may include analog-to-digital converter (ADC) and digital-to-analog converter (DAC) circuitry and the baseband circuitry 604 may include a digital baseband interface to communicate with the RF circuitry 606.

[0108] In some dual-mode embodiments, a separate radio IC circuitry may be provided for processing signals for each spectrum, although the scope of the embodiments is not limited in this respect.

[0109] In some embodiments, the synthesizer circuitry 606d may be a fractional-N synthesizer or a fractional N / N+1 synthesizer, although the scope of the embodiments is not limited in this respect as other types of frequency synthesizers may be suitable. For example, synthesizer circuitry 606d may be a delta-sigma synthesizer, a frequency multiplier, or a synthesizer comprising a phase-locked loop with a frequency divider.

[0110] The synthesizer circuitry 606d may be configured to synthesize an output frequency for use by the mixer circuitry 606a of the RF circuitry 606 based on a frequency input and a divider control input. In some embodiments, the synthesizer circuitry 606d may be a fractional N / N+1 synthesizer.

[0111] In some embodiments, frequency input may be provided by a voltage controlled oscillator (VCO) , although that is not a necessity. Divider control input may be provided by either the baseband circuitry 604 or the applications processor 602 depending on the desired output frequency. In some embodiments, a divider control input (e.g., N) may be determined from a look-up table based on a channel indicated by the applications processor 602.

[0112] Synthesizer circuitry 606d of the RF circuitry 606 may include a divider, a delay-locked loop (DLL) , a multiplexer and a phase accumulator. In some embodiments, the divider may be a dual modulus divider (DMD) , and the phase accumulator may be a digital phase accumulator (DPA) . In some embodiments, the DMD may be configured to divide the input signal by either N or N+1 (e.g., based on a carry out) to provide a fractional division ratio. In some example embodiments, the DLL may include a set of cascaded, tunable, delay elements, a phase detector, a charge pump and a D-type flip-flop. In these embodiments, the delay elements may be configured to break a VCO period up into Nd equal packets of phase, where Nd is the number of delay elements in the delay line. In this way, the DLL provides negative feedback to help ensure that the total delay through the delay line is one VCO cycle.

[0113] In some embodiments, synthesizer circuitry 606d may be configured to generate a carrier frequency as the output frequency, while in other embodiments, the output frequency may be a multiple of the carrier frequency (e.g., twice the carrier frequency, four times the carrier frequency) and used in conjunction with quadrature generator and divider circuitry to generate multiple signals at the carrier frequency with multiple different phases with respect to each other. In some embodiments, the output frequency may be a LO frequency (fLO) . In some embodiments, the RF circuitry 606 may include an IQ / polar converter.

[0114] FEM circuitry 608 may include a receive signal path which may include circuitry configured to operate on RF signals received from one or more antennas 610, amplify the received signals and provide the amplified versions of the received signals to the RF circuitry 606 for further processing. FEM circuitry 608 may also include a transmit signal path which may include circuitry configured to amplify signals for transmission provided by the RF circuitry 606 for transmission by one or more of the one or more antennas 610. In various embodiments, the amplification through the transmit or receive signal paths may be done solely in the RF circuitry 606, solely in the FEM 608, or in both the RF circuitry 606 and the FEM 608.

[0115] In some embodiments, the FEM circuitry 608 may include a TX / RX switch to switch between transmit mode and receive mode operation. The FEM circuitry may include a receive signal path and a transmit signal path. The receive signal path of the FEM circuitry may include an LNA to amplify received RF signals and provide the amplified received RF signals as an output (e.g., to the RF circuitry 606) . The transmit signal path of the FEM circuitry 608 may include a power amplifier (PA) to amplify input RF signals (e.g., provided by RF circuitry 606) , and one or more filters to generate RF signals for subsequent transmission (e.g., by one or more of the one or more antennas 610) .

[0116] In some embodiments, the PMC 612 may manage power provided to the baseband circuitry 604. In particular, the PMC 612 may control power-source selection, voltage scaling, battery charging, or DC-to-DC conversion. The PMC 612 may often be included when the device 600 is capable of being powered by a battery, for example, when the device is included in a UE. The PMC 612 may increase the power conversion efficiency while providing desirable implementation size and heat dissipation characteristics.

[0117] While FIG. 6 shows the PMC 612 coupled only with the baseband circuitry 604, in other embodiments the PMC 612 may be additionally or alternatively coupled with, and perform similar power management operations for, other components such as, but not limited to, application circuitry 602, RF circuitry 606, or FEM 608.

[0118] In some embodiments, the PMC 612 may control, or otherwise be part of, various power saving mechanisms of the device 600. For example, if the device 600 is in a radio resource control_Connected (RRC_Connected) state, where it is still connected to the RAN node as it expects to receive traffic shortly, then it may enter a state known as Discontinuous Reception Mode (DRX) after a period of inactivity. During this state, the device 600 may power down for brief intervals of time and thus save power.

[0119] If there is no data traffic activity for an extended period of time, then the device 600 may transition off to an RRC_Idle state, where it disconnects from the network and does not perform operations such as channel quality feedback, handover, etc. The device 600 goes into a very low power state and it performs paging where, again, it periodically wakes up to listen to the network and then powers down at least portions of the device again. The device 600 may not receive data in this state. In order to receive data, it will transition back to an RRC_Connected state.

[0120] An additional power saving mode may allow a device to be unavailable to the network for periods longer than a paging interval (ranging from seconds to a few hours) . During this time, the device is totally unreachable to the network and may power down completely. Any data sent during this time incurs a large delay and it is assumed the delay is acceptable.

[0121] In some embodiments, the UE 106 and / or the baseband circuitry 604 of the one or more processors thereof can send (encode for transmission) : a tunnel establishment message to a network (NW) via a Radio Access Networks (RAN) comprising an address of the UE-side training server and a permission for a tunnel establishment between the NW training entity and the UE-side training server; a UE request message to the RAN with a request for non-over-the air (non-OTA) signaling, the address of the UE-side training server, a UE identification (ID) and a UE vendor and / or a UE type; a registration request message to an Access and Mobility Management Function (AMF) via Non-Access-Stratum (NAS) signaling comprising a request for non-over-the air (non-OTA) signaling, the address of the UE-side training server, a UE identification (ID) and UE vendor and / or UE type; a registration request message to an Access and Mobility Management Function (AMF) via Non-Access-Stratum (NAS) signaling comprising a request for non-over-the air (non-OTA) signaling, the address of the UE-side training server, a UE identification (ID) and UE vendor and / or UE type; an analytics request message to a Data Collection Analytics Function (DCAF) via a HyperText Transfer Protocol Secure (HTTPS) signaling comprising the address of the AF, a UE identification (ID) and a UE vendor and / or a UE type; a registration request message to an Access and Mobility Management Function (AMF) via a Non-Access-Stratum (NAS) signaling comprising a request for non-over-the air (non-OTA) signaling, the address of the UE-side training server, a UE identification (ID) and UE vendor and / or UE type; and a registration request message to an Access and Mobility Management Function (AMF) or a Session Management Function (SMF) using a mobile terminal (MT) of the UE.

[0122] In addition, the UE 106 and / or the baseband circuitry 604 of the one or more processors thereof can send (encode) , for transmission to a base station: receiver obfuscation capability information of the UE. The UE can receive (decode) obfuscation configuration information using the baseband circuitry. The UE can exchange secret obfuscation information with the base station to enable the base station to apply obfuscation to a reference signal to form an obfuscated reference signal based, in part, on the receiver obfuscation capability information. The UE can receive (decode) the obfuscated reference signal that is obfuscated based on the UE obfuscation capability information. The UE can remove the obfuscation from the obfuscated reference signal, using the processor 402, and sense the reference signal with the baseband processor based on the obfuscation configuration information and the secret obfuscation information.FIG. 7: Block Diagram of an Interface of Baseband Circuitry

[0123] FIG. 7 illustrates example interfaces of baseband circuitry in accordance with some embodiments. It is noted that the baseband circuitry of FIG. 7 is merely one example of a possible circuitry, and that features of this disclosure may be implemented in any of various systems, as desired.

[0124] As discussed above, the baseband circuitry 604 of FIG. 6 may comprise processors 604A-604E and a memory 604G utilized by said processors. Each of the processors 604A-604E may include a memory interface, 704A-704E, respectively, to send / receive data to / from the memory 604G.

[0125] The baseband circuitry 604 may further include one or more interfaces to communicatively couple to other circuitries / devices, such as a memory interface 712 (e.g., an interface to send / receive data to / from memory external to the baseband circuitry 604) , an application circuitry interface 714 (e.g., an interface to send / receive data to / from the application circuitry 602 of FIG. 6) , an RF circuitry interface 716 (e.g., an interface to send / receive data to / from RF circuitry 606 of FIG. 6) , a wireless hardware connectivity interface 718 (e.g., an interface to send / receive data to / from Near Field Communication (NFC) components,  components (e.g.,  Low Energy) ,  components, and other communication components) , and a power management interface 720 (e.g., an interface to send / receive power or control signals to / from the PMC 612.FIG. 8: Core Network

[0126] FIG. 8 illustrates an example architecture of a system 800 including a core network (CN) 820 in accordance with various embodiments. The CN 820 may be a core network for a 5G System (which may be referred to as a 5GC) . The system 800 is shown to include a UE 801, which may be the same or similar to the UEs 106A, 106B, or 106N discussed previously; a (R) AN 810, which may be the same or similar to the BSs 102A or 102N discussed previously; and a data network (DN) 803, which may be, for example, operator services, Internet access, or 3rd party services; and a CN 820. The CN 820 may include a number of network functions including an Authentication Server Function (AUSF) 822; an Access and Mobility Management Function (AMF) 821; a Session Management Function (SMF) 824; a Network Exposure Function (NEF) 823; a Policy Control Function (PCF) 826; a Network Repository Function (NRF) 825; a Unified Data Management (UDM) 827; an Application Function (AF) 828; a User Plane Function (UPF) 802; and a Network Slice Selection Function (NSSF) 829. These network functions may be implemented, in some cases, as virtualized software-based functions / services.

[0127] The UPF 802 may act as an anchor point for intra-RAT and inter-RAT mobility, an external packet data unit (PDU) session point of interconnect to DN 803, and a branching point to support mufti-homed PDU session. A PDU session is a logical connection between the UE and the DN. The UPF 802 may also perform packet routing and forwarding, perform packet inspection, enforce the user plane part of policy rules, lawfully intercept packets (user plane (UP) collection) , perform traffic usage reporting, perform quality of service (QoS) handling for a user plane (e.g., packet filtering, gating, UL / DL rate enforcement) , perform Uplink Traffic verification (e.g., Service Data Flows (SDF) to QoS flow mapping) , transport level packet marking in the uplink and downlink, and perform downlink packet buffering and downlink data notification triggering. UPF 802 may include an uplink classifier to support routing traffic flows to a data network, The DN 803 may represent various network operator services, Internet access, or third-party services. DN 803 may include, or be similar to, application server 104 discussed previously. The UPF 802 may interact with the SMF 824 via an N4 reference point between the SMF 824 and the UPF 802.

[0128] The AUSF 822 may store data for authentication of UE 801 and handle authentication-related functionality, The AUSF 822 may facilitate a common authentication framework for various access types. The AUSF 822 may communicate with the AMF 821 via an N12 reference point between the AMF 821 and the AUSF 822; and may communicate with the UDM 827 via an N13 reference point between the UDM 827 and the AUSF 822. Additionally, the AUSF 822 may exhibit an Nausf service-based interface.

[0129] The AMF 821 may be responsible for registration management (e.g., for registering UE 801, etc. ) , connection management, reachability management, mobility management, and lawful interception of AMF-related events, and access authentication and authorization. The AMF 821 may be a termination point for the an N11 reference point between the AMF 821 and the SMF 824. The AMF 821 may provide transport for SM messages between the UE 801 and the SMF 824, and act as a transparent proxy for routing SM messages. AMF 821 may also provide transport for Short Message Service (SMS) messages between UE 801 and an SMSF (not shown by FIG. 8) . AMF 821 may act as a security anchor function (SEAF) , which may include interaction with the AUSF 822 and the UE 801, receipt of an intermediate key that was established as a result of the UE 801 authentication process. Where Universal Subscriber Identity Module (USIM) based authentication is used, the AMF 821 may retrieve the security material from the AUSF 822. AMF 821 may also include a Security Context Management (SCM) function, which receives a key from the SEAF that it uses to derive access-network specific keys. Furthermore, AMF 821 may be a termination point of a RAN control plane (CP) interface, which may include or be an N2 reference point between the (R)AN 810 and the AMF 821; and the AMF 821 may be a termination point of NAS (Nl) signaling, and perform NAS ciphering and integrity protection.

[0130] AMF 821 may also support NAS signaling with a UE 801 over a non-3GPP Inter-Working Function (N3IWF) interface. The N3IWF may be used to provide access to untrusted entities. N3IWF may be a termination point for the N2 interface between the (R) AN 810 and the AMF 821 for the control plane and may be a termination point for the N3 reference point between the (R) AN 810 and the UPF 802 for the user plane. As such, the AMF 821 may handle N2 signaling from the SMF 824 and the AMF 821 for PDU sessions and encapsulate / de-encapsulate packets for IPSec and N3 tunneling, mark N3 user-plane packets in the uplink, and enforce QoS corresponding to N3 packet marking while considering QoS requirements associated with such marking received over N2. N3IWF may also relay uplink and downlink control plane non-access stratum (NAS) signaling between the UE 801 and AMF 821 via an N1 reference point between the UE 801 and the AMF 821, and relay uplink and downlink user-plane packets between the UE 801 and UPF 802. The N3IWF also provides mechanisms for internet protocol security (IPsec) tunnel establishment with the UE 801. The AMF 821 may exhibit an Namf service-based interface and may be a termination point for an N14 reference point between two AMFs 821 and an N17 reference point between the AMF 821 and a 5G Equipment Identity Register (5G-EIR) (not shown by FIG. 8) .

[0131] The UE 801 may need to register with the AMF 821 in order to receive network services. Registration Management (RM) is used to register or deregister the UE 801 with the network (e.g., AMF 821) , and establish a UE context in the network (e.g., AMF 821) . The UE 801 may operate in an RM-REGISTERED state or an RM-DEREGISTERED state. In the RM-DEREGISTERED state, the UE 801 is not registered with the network, and the UE context in AMF 821 holds no valid location or routing information for the UE 801 so the UE 801 is not reachable by the AMF 821. In the RM REGISTERED state, the UE 801 is registered with the network, and the UE context in AMF 821 may hold a valid location or routing information for the UE 801 so the UE 801 is reachable by the AMF 821. In the RM-REGISTERED state, the UE 801 may perform mobility registration update procedures, perform periodic registration update procedures triggered by expiration of the periodic update timer (e.g., to notify the network that the UE 801 is still active) , and perform a Registration Update procedure to update UE capability information or to re-negotiate protocol parameters with the network, among others.

[0132] The AMF 821 may store one or more RM contexts for the UE 801, where each RM context is associated with a specific access to the network. The RM context may be a data structure, database object, etc. that indicates or stores, inter glia, a registration state per access type and the periodic update timer. The AMF 821 may also store a 5GC mobility management (MM) context that may be the same or similar to the evolved packet services (EPS) Mobility Management (E) MM context discussed previously. In various embodiments, the AMF 821 may store a CE mode B Restriction parameter of the UE 801 in an associated MM context or registration management (RM) context. The AMF 821 may also derive the value, when needed, from the UE's usage setting parameter already stored in the UE context (and / or MM / RM context) .

[0133] Connection Management (CM) may be used to establish and release a signaling connection between the UE 801 and the AMF 821 over the N1 interface. The signaling connection is used to enable NAS signaling exchange between the UE 801 and the CN 820, and comprises both the signaling connection between the UE and the AN (e.g., RRC connection or UE-N3IWF connection for non-3GPP access) and the N2 connection for the UE 801 between the AN (e.g., AN 810) and the AMF 821. The UE 801 may operate in one of two CM states, CM-IDLE mode or CM-CONNECTED mode. When the UE 801 is operating in the CM-IDLE state / mode, the UE 801 may have no NAS signaling connection established with the AMF 821 over the N1 interface, and there may be (R) AN 810 signaling connection (e.g., N2 and / or N3 connections) for the UE 801. When the UE 801 is operating in the CM-CONNECTED state / mode, the UE 801 may have an established NAS signaling connection with the AMF 821 over the Nl interface, and there may be a (R) AN 810 signaling connection (e.g., N2 and / or N3 connections) for the UE 801. Establishment of an N2 connection between the (R) AN 810 and the AMF 821 may cause the UE 801 to transition from CM-IDLE mode to CM-CONNECTED mode, and the UE 801 may transition from the CM-CONNECTED mode to the CM-IDLE mode when N2 signaling between the (R) AN 810 and the AMF 821 is released.

[0134] The SMF 824 may be responsible for session management (SM) session establishment, modify and release, including tunnel maintain between UPF and AN node) ; UE IP address allocation and management (including optional authorization) ; selection and control of UP function; configuring traffic steering at UPF to route traffic to proper destination; termination of interfaces toward policy control functions; controlling part of policy enforcement and QoS; lawful intercept (for SM events and interface to LI system) ; termination of SM parts of NAS messages; downlink data notification; initiating AN specific SM information, sent via AMF over N2 to AN; and determining SSC mode of a session. SM may refer to management of a PDU session, and a PDU session or "session" may refer to a PDU connectivity service that provides or enables the exchange of PDUs between a UE 801 and a data network (DN) 803 identified by a Data Network Name (DNN) . PDU sessions may be established upon UE 801 request, modified upon UE 801 and CN 820 request, and released upon UE 801 and CN 820 request using NAS SM signaling exchanged over the N1 reference point between the UE 801 and the SMF 824. Upon request from an application server, the CN 820 may trigger a specific application in the UE 801. In response to receipt of the trigger message, the UE 801 may pass the trigger message (or relevant parts / information of the trigger message) to one or more identified applications in the UE 801. The identified application (s) in the UE 801 may establish a PDU session to a specific data network name (DNN) . The SMF 824 may check whether the UE 801 requests are compliant with user subscription information associated with the UE 801. In this regard, the SMF 824 may retrieve and / or request to receive update notifications on SMF 824 level subscription data from the UDM 827.

[0135] The SMF 824 may include the following roaming functionality: handling local enforcement to apply QoS SLAB virtual Public Land Mobile Network (VPLMN) ; charging data collection and charging interface (VPLMN) ; lawful intercept (in VPLMN for SM events and interface to LI system) ; and support for interaction with external DN for transport of signaling for PDU session authorization / authentication by external DN. An N16 reference point between two SMFs 824 may be included in the system 800, which may be between another SMF 824 in a visited network and the SMF 824 in the home network in roaming scenarios. Additionally, the SMF 824 may exhibit the Nsmf service-based interface.

[0136] The NEF 823 may provide means for securely exposing the services and capabilities provided by 3GPP network functions for third party, internal exposure / re-exposure, Application Functions (e.g., AF 828) , edge computing or fog computing systems, etc. In such embodiments, the NEF 823 may authenticate, authorize, and / or throttle the AFS. NEF 823 may also translate information exchanged with the AF 828 and information exchanged with internal network functions. For example, the NEF 823 may translate between an AF-Service-Identifier and an internal SCC information. NEF 823 may also receive information from other network functions (NFs) based on exposed capabilities of other network functions. This information may be stored at the NEF 823 as structured data, or at a data storage NF using standardized interfaces. The stored information can then be re-exposed by the NEF 823 to other NFs and AFs, and / or used for other purposes such as analytics. Additionally, the NEF 823 may exhibit an Nnef service-based interface.

[0137] The NRF 825 may support service discovery functions, receive NF discovery requests from NF instances, and provide the information of the discovered NF instances to the NF instances. NRF 825 also maintains information of available NF instances and their supported services. As used herein, the terms "instantiate, " "instantiation, " and the like may refer to the creation of an instance, and an "instance" may refer to a concrete occurrence of an object, which may occur, for example, during execution of program code. Additionally, the NRF 825 may exhibit the Nnrf service-based interface.

[0138] The PCF 826 may provide policy rules to control plane function (s) to enforce them, and may also support unified policy framework to govern network behavior, The PCF 826 may also implement a front end (FE) to access subscription information relevant for policy decisions in a UDR of the UDM 827. The PCF 826 may communicate with the AMF 821 via an N15 reference point between the PCF 826 and the AMF 821, which may include a PCF 826 in a visited network and the AMF 821 in case of roaming scenarios. The PCF 826 may communicate with the AF 828 via an NS reference point between the PCF 826 and the AF 828; and with the SMF 824 via an N7 reference point between the PCF 826 and the SMF 824, The system 800 and / or CN 820 may also include an N24 reference point between the PCF 826 (in the home network) and a PCF 826 in a visited network, Additionally, the PCF 826 may exhibit an Npcf service-based interface.

[0139] The UDM 827 may handle subscription-related information to support the network entities' handling of communication sessions and may store subscription data of UE 801. For example, subscription data may be communicated between the UDM 827 and the AMF 821 via an NS reference point between the UDM 827 and the AMF. The UDM 827 may include two parts, an application FE and a UDR (the FE and UDR are not shown by FIG. 8) . The UDR may store subscription data and policy data for the UDM 827 and the PCF 826, and / or structured data for exposure and application data (including PFDs for application detection, application request information for multiple UEs 801) for the NEF 823. The Nadr service-based interface may be exhibited by the UDR to allow the UDM 827, PCF 826, and NEF 823 to access a particular set of the stored data, as well as to read, update (e.g., add, modify) , delete, and subscribe to notification of relevant data changes in the UDR. The UDM may include a UDM-FE, which is in charge of processing credentials, location management, subscription management and so on. Several different front ends may serve the same user in different transactions. The UDM-FE accesses subscription information stored in the UDR and performs authentication credential processing, user identification handling, access authorization, registration / mobility management, and subscription management. The UDR may interact with the SMF 824 via an Nl0 reference point between the UDM 827 and the SMF 824. UDM 827 may also support SMS management, wherein an SMS-FE implements the similar application logic as discussed previously. Additionally, the UDM 827 may exhibit the Nudm service-based interface.

[0140] The AF 828 may provide application influence on traffic routing, provide access to the NCE, and interact with the policy framework for policy control. The NCE may be a mechanism that allows the CN 820 and AF 828 to provide information to each other via NEF 823, which may be used for edge computing implementations. In such implementations, the network operator and third-party services may be hosted close to the UE 801 access point of attachment to achieve an efficient service delivery through the reduced end-to-end latency and load on the transport network. For edge computing implementations, the 5GC may select a UPF 802 close to the UE 801 and execute traffic steering from the UPF 802 to DN 803 via the N6 interface. This may be based on the UE subscription data, UE location, and information provided by the AF 828. In this way, the AF 828 may influence UPF (re) selection and traffic routing. Based on operator deployment, when AF 828 is considered to be a trusted entity, the network operator may permit AF 828 to interact directly with relevant NFs. Additionally, the AF 828 may exhibit an Naf service-based interface.

[0141] The NSSF 829 may select a set of network slice instances serving the UE 801. The NSSF 829 may also determine allowed Network Slice Selection Assistance Information (NSSAI) and the mapping to the subscribed single NSSAI (S-NSSAI) is, if needed. The NSSF 829 may also determine the AMF set to be used to serve the UE 801, or a list of candidate AMF (s) 821 based on a suitable configuration and possibly by querying the NRF 825. The selection of a set of network slice instances for the UE 801 may be triggered by the AMF 821 with which the UE 801 is registered by interacting with the NSSF 829, which may lead to a change of AMF 821. The NSSF 829 may interact with the AMF 821 via an N22 reference point between AMF 821 and NSSF 829; and may communicate with another NSSF 829 in a visited network via an N31 reference point (not shown by FIG. 8) . Additionally, the NSSF 829 may exhibit an Nnssf service-based interface.

[0142] As discussed previously, the CN 820 may include a short message service function (SMSF) , which may be responsible for SMS subscription checking and verification, and relaying SM messages to / from the UE 801 to / from other entities, such as an SMS-GMSC / IWMSC / SMS-router. The SMS may also interact with AMF 821 and UDM 827 for a notification procedure that the UE 801 is available for SMS transfer (e.g., set a UE not reachable flag, and notifying UDM 827 when UE 801 is available for SMS) .

[0143] The CN 820 may further include a location management function (LMF) 830. The LMF 830 receives measurements and assistance information from the base station 102A and the UE 106 via the AMF 821 over the NLs interface to compute the position of the UE 106.

[0144] The CN 820 may also include other elements that are not shown by FIG. 8, such as a Data Storage system / architecture, a 5G-EIR, a Security Edge Protection Proxy (SEPP) , and the like. The Data Storage system may include a Structured Data Storage Network Function (SDSF) , air Unstructured Data Storage Function (UDSF) , and / or the like. Any network function (NF) may store and retrieve unstructured data into / from the UDSF (e.g., UE contexts) , via N18 reference point between any NF and the UDSF (not shown by FIG. 8) , Individual NFs may share a UDSF for storing their respective unstructured data or individual NFs may each have their own UDSF located at or near the individual NFs. Additionally, the UDSF may exhibit an Nudsf service-based interface (not shown by FIG. 8) . The 5G-EIR may be an NF that checks the status of permanent equipment identifier (PEI) for determining whether particular equipment / entities are blacklisted from the network; and the SEPP may be a non-transparent proxy that performs topology hiding, message filtering, and policing on inter-PLMN control plane interfaces.

[0145] Additionally, there may be many more reference points and / or service-based interfaces between the NF services in the NFs; however, these interfaces and reference points have been omitted from FIG. 8 for clarity. In one example, the CN 820 may include an Nx interface, which is an inter-CN interface between a mobility management entity (MME) and the AMF 821 in order to enable interworking between CN 820 and a CN in a 4G system. Other example interfaces / reference points may include an N5G-EIR service-based interface exhibited by a 5G-EIR, an N27 reference point between the NRF in the visited network and the NRF in the home network; and an N31 reference point between the NSSF in the visited network and the NSSF in the home network.

[0146] The CN 820 can be or can be part of the NW 100. As described herein, the NW 100 and / or the CN 820 can transmit and receive messages with the UE 106 via the base station 102. In addition, the NW 100 (e.g. a server operating in the network) and / or the CN 820 can dynamically manage obfuscation of reference signals sent from the base station to a UE or from the UE to the base station.Integrated Sensing and Communication Networks

[0147] Wireless communications networks based on specifications, such as the 3GPP specification, are continuously improved. Each year, 3GPP members meet multiple times to discuss, negotiate, make recommendations, and approve changes to make improvements to the specifications based on the latest capabilities of general-purpose processors, baseband processors, and radio communications equipment. These improvements over the decades have resulted in user equipment (UEs) and base stations (BSs) that are capable of: complex communication at high data rates, communication at long distances, and can provide ultra-reliable low latency communications.

[0148] As the development of wireless communication networks continues, the networks or elements of the network can be configured for integrated sensing and communication. Sensing involves the use of radio signals to detect and estimate characteristics of target objects in the environment. For example, the network or element of the network (e.g. the UE) can be configured to perform as a radar sensor, using radio signals transmitted by the network (e.g. UE or BS) to sense and understand the physical world in which the network operates. This allows the network to collect data on the range, velocity, position, orientation, size, shape, and materials of objects and devices in the network.

[0149] The sensing data collected and processed by the network can then be leveraged to enhance the network’s own operations, supplement existing services such as location determination, extended reality, and enable new services, such as gesture and activity recognition, and object detection and tracking.

[0150] In order to measure the channel and environment, wireless communication networks are configured to transmit sensing signals. The sensing signals can be configured as reference signals. However, sensing signals are not limited to being used as reference signals. A wide variety of different types of reference signals may be used to sense and measure the environment. For example, channel state information reference signals (CSI-RS) , sounding reference signals (SRS) , beamforming reference signals, demodulation reference signals (DMRS) , positioning reference signals, phase tracking reference signals, physical broadcast channel reference signals, or cell specific reference signals can be used to sense and measure the environment in which the wireless communication network operates.

[0151] In addition to transmitting reference signals that can be used to determine the attributes of a wireless communication channel, the wireless communication network can be configured to transmit sensing signals at a selected frequency, amplitude, and / or phase with a selected modulation to measure the attributes of a target. For example, as previously discussed, the sensing signal can be configured to measure the range, velocity, position, orientation, size, shape, or materials of a target by the network. This will be discussed more fully in the proceeding paragraphs.FIG. 9: ISAC and Security

[0152] While sensing signals transmitted by wireless communication networks are useful in determining the channel state and environment, the use of sensing signals can also be detrimental. Sensing signals, including reference signals, are typically transmitted with little to no security. This allows a potential eavesdropper to use the sensing signal sent by a transmitter to sense the environment and track unaware targets, such as the sensing signal transmitter and / or the intended receiver of the sensing signal.

[0153] FIG. 9 provides an example illustration of a wireless communications network 900 configured to transmit and / or receive sensing signals. In this example, a transmitter (Tx) 902 is configured to transmit a sensing signal 912, such as a reference signal (RS) to a receiver (Rx) 906. The Tx 902 and Rx 906 can be a UE 106, a base station (BS) 102, or any device with a transmit receive point (TRP) .

[0154] In some embodiments, the transmitter 902 is configured to transmit a sensing signal 912 such as an RS to the receiver 906. The sensing signal 912 may be communicated directly (e.g. line of site) from the transmitter 902 to the receiver 906. Alternatively, the sensing signal 912 may be transmitted towards a target 908. The receiver 906 can receive the sensing signal 914 that is reflected and / or refracted off of the target 908. Signals, such as the sensing signal 912, are transmitted with a certain beam width. The beam width may be a relatively narrow, directional beam, with a beam width such as 2 to 90 degrees. Alternatively, the beam width may be relatively broad, such as 90 to 360 degrees. The beam width that the sensing signal 912 is transmitted with, along with reflection and refraction of the sensing signal, can allow an eavesdropper (Eve) 910 to receive the sensing signal 916 sent from the transmitter 902 to the receiver 906 or a reflected sensing signal 918 that may be reflected and / or refracted one or more times.

[0155] In the example of FIG. 9, the sensing signal 916 and the reflected sensing signal 918 that is received by Eve 910 can have many of the same characteristics as the sensing signal 912 or reflected sensing signal 914 that is received by the receiver 906. The characteristics of the received sensing signal 916, 918 may allow Eve to estimate the location of the transmitter 902. In addition, when the sensing signal 916, 918 is a reference signal, Eve can use the RS to estimate channel state information (CSI) of a channel of the RS. In addition, Eve can extract vital information of the environment between the transmitter 902 and the receiver 906. This information may enable Eve to receive and decode additional information sent between the transmitter 902 and the receiver 906 and identify characteristics of the environment such as the location of the target.

[0156] To limit Eve’s 910 ability to detect the sensing signal 916, 918 from the transmitter 902, the sensing signal 912, 916 can be configured with radio frequency (RF) security to limit tracking by an unauthorized eavesdropper. Obfuscation of the sensing signal, and more specifically a reference signal, from the transmitter 902, can be used to conceal information on the environment carried by the electromagnetic reference signal from the transmitter, thereby limiting a value of a location or CSI estimate of the reference signal 916, 918 received by Eve 910. Examples of obfuscation can comprise, but are not limited to, radio frequency filtering, pilot tone manipulation, artificial noise embedding, and pilot constellation modification. This will be discussed more fully in the proceeding paragraphs.FIG. 10: UE-Positioning Related Services

[0157] One type of reference signal is a positioning reference signal (PRS) . A positioning reference signal can be used to determine a location of the receiver 906 based on the PRS, or other types of reference signals, sent by the transmitter 902. UE-positioning-related services can be initiated from the CN 820, such as the 5G core network (5GC) or a 6th generation core network, for a network initiated location request (NI-LR) or mobile terminated location request (MT-LR) , or a mobile originated location request (MO-LR) when a UE is the transmitter 902.

[0158] In accordance with some embodiments, FIG. 10 provides one example embodiment of a sequence of operations for an NI-LR or an MT-LR location service. In a first operation, the AMF 821 (FIG. 8) can send a location request to the LMF 830 for a target UE (e.g. Rx 906) . In a second operation, the LMF may obtain location related information from the UE and or from a serving RAN node, such as a next generation RAN node (NG-RAN) , or a 6th generation RAN. The LMF can initiate one or more LTE positioning protocol (LPP) procedures to transfer the UE positioning capabilities, provide assistance data to the UE and / or obtain location information from the UE. The receiver 906 can also initiate one or more LPP procedures after the first LPP message is received from the LMF. LPP positioning procedures can include transmitting a PRS between the transmitter 902 and the receiver 906. As previously discussed, the UE and BS / TRP can be configured to operate as either the Tx 902 or the Rx 906.

[0159] In a third operation, the LMF 830 can instigate one or more new radio positioning protocol A (NRPPa) procedures if the LMF needs location related information for the UE from the NG-RAN. The third operation may preceed the second operation.

[0160] In a fourth operation, the LMF 830 can return a location response to the AMF 821 with any location estimate obtained as a result of operations 2 and 3. The LMF may also return the LPP UE capabilities.

[0161] In some embodiments, a pseudo-random sequence can be modulated with QPSK to provide a PRS. The parameters of the PRS and modulation can be communicated via LPP or NRPPa procedures.

[0162] For other types of reference signals, such as DMRS or TRS, a pseudo-random sequence can be modulated with QPSK. The parameters of the DRMS or TRS can be communicated via radio resource control (RRC) signaling. If RRC signaling is not available, the parameters can be communicated using a cell identification (Cell-ID) .

[0163] To prevent Eve 910 (FIG. 9) from estimating the parameters used for the reference signal pseudo-random sequence, the RRC communication can be encrypted by the AS layer. Alternatively, the reference signals can be limited as UE-specific or as a closed UE-group. In another alternative, additional physical (PHY) layer reference signal security may be added. The additional PHY layer RS security will be discussed in the proceeding paragraphs.FIG. 11: Obfuscation Methods

[0164] In accordance with some embodiments, FIG. 11 provides an example bock diagram showing several procedures that can be used to obfuscate a reference signal that is communicated between a transmitter 902 and a receiver 906 (FIG. 9) .

[0165] In one example, signal manipulation can be performed, including amplitude and / or phase manipulation of the signal used to transmit the reference signal. Signal manipulation can be performed by using a function to manipulate the amplitude and / or phase of the signal at the transmitter in a known way. The function can then be used at the receiver to de-manipulate the signal in a way that allows the receiver to detect and receive the reference signal. In addition to a function, a look up table may be used, or a hybrid of a function and look up table. Moreover, a filter (digital or analog) may be used to alter the reference signal at the transmitter 902 in a known way that still allows the receiver 906 to receive the reference signal.

[0166] In another example, the obfuscation method can include noise insertion. Noise can be inserted by the transmitter 902 into the reference signal at known locations in time and frequency. The receiver 906 can then remove the noise at the known locations in time and frequency to receive the reference signal.

[0167] In another example, reference signal constellations can be altered in a known way at the transmitter. The receiver can then receive the reference signal with prior knowledge of the way in which the reference signal constellations were altered.

[0168] In each of these obfuscation procedures illustrated in FIG. 11, information regarding the details of the obfuscation procedure may be known at both the transmitter 902 and the receiver 906. The knowledge of the obfuscation procedure may be predetermined at both the transmitter and receiver. Alternatively, the obfuscation procedure may be dynamic, with the changes in obfuscation communicated between the transmitter and receiver.FIGs. 12-14: Obfuscation: Signal Manipulation and / or Filtering

[0169] In accordance with some embodiments, the sensing signal 912, such as a reference signal, can be transmitted on an orthogonal frequency division multiplexed (OFDM) signal or a Discrete Fourier Transform-Spread-Orthogonal Frequency Division Multiplexing (DFT-S-OFDM) signal. The (DFT-S-) OFDM RS can be manipulated on a per sub-carrier obfuscation  / de-obfuscation basis. In some embodiments, a known obfuscation signal can be transmitted on selected sub-carriers to change the overall reference signal. The obfuscation may be a random or fixed change in amplitude and phase for each subcarrier (Nsc (s) ) . The random or fixed change in amplitude and / or phase can be known by both of the transmitter 902 and receiver 906. In a first option, one or more subcarriers can have a phase manipulation of the reference signal. In a second option, one or more subcarriers can have an amplitude manipulation of the reference signal. In a third option, one or more subcarriers can have a phase and amplitude manipulation of the reference signal.

[0170] The receiver 906 can then remove the amplitude and / or phase manipulation of the one or more subcarriers in the reference signal during channel estimation. This may be performed by the baseband processor 604, such as 604C, 604D. FIG. 14 provides an example illustration of per subcarrier (Nsc) obfuscation. In a first column, a transmission 1410 of the RS signal 912, 916 is illustrated that comprises N subcarriers (Nsc) . While only a single symbol is illustrated in time, this is not intended to be limiting. It is for illustration purposes only. Multiple symbols and Nsc may be transmitted in an OFDM symbol that includes reference symbols. In one option, the obfuscation can comprise each subcarrier in the RS transmission, as shown in obfuscation 1420. The receiver can remove the amplitude and  / or phase manipulation of the reference signal across the entire frequency domain, Nsc. Alternatively, the obfuscation may be performed on a selected number of subcarriers. For example, the transmitter 902 may apply, and the receiver may remove the manipulation of the reference signal across a portion of the frequency domain, Nsc  / P, where P is a positive integer. For example, P =3 can mean that one third (1 / 3) of the band of the reference signal is de-obfuscated, as shown in obfuscation 2 1430. That may be sufficient for the receiver to detect and receive the obfuscated reference signal. In another example, the transmitter may obfuscate the RS 912, 916 de-obfuscated at the receiver based on a block obfuscation, as shown in obfuscation 3 1440, or a comb-based obfuscation of an RS OFDM signal, such as obfuscation 2 1430.

[0171] In some embodiments, the transmitter 902 and receiver 906 can estimate the signal change per subcarrier Nsc based on a predetermined formula. Alternatively, the signal change per subcarrier Nsc can be estimated by the transmitter and receiver based on a look-up table (LUT) . And in a third alternative, the transmitter and receiver can be configured for a hybrid, in which the transmitter and receiver can estimate the signal change per subcarrier Nsc based on the LUT and the pre-determined formula.

[0172] FIG. 12 provides an example block diagram 1200 that shows a portion of a transmit chain for the transmitter (Tx) 902, a portion of a receive chain for the receiver 906, and a portion of a receive chain for Eve 910, in which the RS signal 912, 916 is obfuscated and de-obfuscated using per subcarrier obfuscation.

[0173] In the example of FIG. 12, the obfuscation methods described in FIG. 10 can be inserted into an OFDM signal that is configured for the RS signal 912, 916 as previously discussed. The obfuscation per RS subcarrier can be inserted at the transmitter 902, such as a UE, BS, or TRP, to form an obfuscated RS signal prior to performing an inverse Fast Fourier Transform (IFFT) on the obfuscated RS signal, perform a parallel to serial conversion (P / S) , and insert the cyclic prefix (CP) . The Obfuscated RS signal can then be transmitted from the transmitter 902 to form the RS signals 912, 916.

[0174] As shown in FIG. 12, the receiver (Rx) 906 can then receive the RS signal 912, remove the cyclic prefix (CP) , perform a serial to parallel conversion (S / P) , perform a Fast Fourier Transform (FFT) , and perform de-obfuscation on the obfuscated RS signal before sending the signal for sensing and communication.

[0175] Similarly, as shown in FIG. 12, Eve 910 can receive the RS signal 914 that has travelled from the transmitter 902 to Eve, perform a CP removal, a serial to parallel conversion, and an FFT on the obfuscated RS signal. However, Eve is not aware that the RS signal is obfuscated, or how the RS signal is obfuscated. Accordingly, Eve is not aware of the obfuscation methods illustrated in FIG. 10 and is not able to de-obfuscate the obfuscated RS signal. Therefore, when the obfuscated RS signal is sent for sensing, Eve may not be able to detect the signal, and / or to obtain the information embedded in the RS signal that would be useful to Eve, such as the location of the transmitter or the channel state information of the channel.

[0176] In some embodiments, filter based obfuscation and de-obfuscation can be used to obfuscate and de-obfuscate the reference signal 912. For example, the transmitter 902 can use a filtered sequence that is transmitted as the reference signal 912. The filter parameters may be based on a formula or an LUT. The receiver 906 can use the filter parameters to de-obfuscate the filtered sequence that is transmitted as the reference signal 912.

[0177] FIG. 13 provides an example block diagram 1300 that shows a portion of a transmit chain for the transmitter (Tx) 902, a portion of a receive chain for the receiver 906, and a portion of a receive chain for Eve 910, in which the RS signal 912, 916 is obfuscated and de-obfuscated using filter based obfuscation.

[0178] In the example of FIG. 13, filter-based obfuscation can be used to filter an OFDM signal that is configured for the RS signal 912, 916 as previously discussed. The obfuscation filter can be inserted at the transmitter 902, such as a UE, BS, or TRP, to filter an RS signal and form an obfuscated RS signal prior to performing an inverse Fast Fourier Transform (IFFT) on the obfuscated RS signal, perform a parallel to serial conversion (P / S) , and insert the cyclic prefix (CP) . The Obfuscated RS signal can then be transmitted from the transmitter 902 to form the RS signals 912, 916.

[0179] As shown in FIG. 13, the receiver (Rx) 906 can then receive the RS signal 912, remove the cyclic prefix (CP) , perform a serial to parallel conversion (S / P) , perform a Fast Fourier Transform (FFT) , and use an obfuscation filter removal to perform equalization on the obfuscated RS signal before sending the signal for sensing and communication.

[0180] Similarly, as shown in FIG. 13, Eve 910 can receive the RS signal 914 that has travelled from the transmitter 902 to Eve, perform a CP removal, a serial to parallel conversion, and an FFT on the obfuscated RS signal. However, Eve is not aware that the RS signal is obfuscated using an obfuscation filter, or how the RS filter is designed (e.g. the filter parameters) to perform the obfuscation of the RS signal 914. Accordingly, Eve is not able to de-obfuscate or equalize the obfuscated RS signal. Therefore, when the obfuscated RS signal is sent for sensing, Eve may not be able to detect the signal, and / or to obtain the information embedded in the RS signal that would be useful to Eve, such as the location of the transmitter or the channel state information of the channel.FIGs. 15-16: Obfuscation with Noise Insertion / Removal

[0181] In accordance with some embodiments, the transmitter 902 can be configured to insert noise into the OFDM RS signal or DFT-S-OFDM signal 912, 916 before transmission to obfuscate the RS signal. Noise can be inserted on selected subcarriers in the RS signal that are known to both the transmitter and the receiver. The receiver can remove the noisy sub-carriers before estimating the channel. Eve 910 does not know which subcarriers include the noise. The noise that is inserted may be similar to the RS signal (e.g. the RS subcarriers) to prevent Eve from identifying the subcarriers with noise inserted. This will make it difficult for Eve to properly estimate the channel, thereby limiting Eve’s ability to determine a location of the transmitter or calculate the CSI based on the received RS signal that is obfuscated with the inserted noise.

[0182] In accordance with some embodiments, random noise can be inserted on fixed sub-carriers. In another alternative, random RS signals may be inserted on fixed sub-carriers. In another alternative, random RS plus noise insertion may be performed on random subcarriers. The noise insertion may be on the RS subcarriers or on non-RS subcarriers. The noise may be transmitted in a manner configured to jam the Eve 910 receiver. For example, subcarriers with noise may be transmitted towards Eve with relatively high power, and subcarriers with noise may be transmitted towards the receiver 906 with lower power in order to effectively jam Eve’s receiver.

[0183] FIG. 15 provides an example block diagram 1500 that shows a portion of a transmit chain for the transmitter (Tx) 902, a portion of a receive chain for the receiver 906, and a portion of a receive chain for Eve 910, in which the RS signal 912, 916 is obfuscated and de-obfuscated using noise with per subcarrier obfuscation.

[0184] In the example of FIG. 15, noise can be generated and / or inserted into an OFDM signal that is configured for the RS signal 912, 916 as previously discussed. The obfuscation per RS subcarrier can be inserted at the transmitter 902, such as a UE, BS, or TRP, to form an obfuscated RS signal prior to performing an inverse Fast Fourier Transform (IFFT) on the obfuscated RS signal, perform a parallel to serial conversion (P / S) , and insert the cyclic prefix (CP) . The Obfuscated RS signal can then be transmitted from the transmitter 902 to form the RS signals 912, 916.

[0185] As shown in FIG. 15, the receiver (Rx) 906 can then receive the RS signal 912, remove the cyclic prefix (CP) , perform a serial to parallel conversion (S / P) , perform a Fast Fourier Transform (FFT) , and perform de-obfuscation on the obfuscated RS signal to substantially remove the noise, which was inserted by the transmitter (Tx) 902, before sending the signal for sensing and communication. The RS subcarriers that include the inserted noise can be identified by the receiver and the noise can be removed. The RS subcarriers that include the noise may be identified based on information received from the transmitter or based on a predetermined procedure for inserting and removing the noise that is known at both the transmitter and the receiver.

[0186] Similarly, as shown in FIG. 15, Eve 910 can receive the RS signal 914 that has travelled from the transmitter 902 to Eve, perform a CP removal, a serial to parallel conversion, and an FFT on the RS signal that has been obfuscated with noise inserted on selected subcarriers. However, Eve is not aware that the RS signal is obfuscated, or which subcarriers in the RS signal have been obfuscated, in this example with inserted noise. Accordingly, Eve is not able to de-obfuscate the obfuscated RS signal by removing the inserted noise. Therefore, when the obfuscated RS signal is sent for sensing, Eve may not be able to detect the signal, and / or to obtain the information embedded in the RS signal that would be useful to Eve, such as the location of the transmitter or the channel state information of the channel.

[0187] FIG. 16 provides an example illustration of a block diagram showing subcarriers Nsc in the OFDM RS or DFT-S-OFDM RS signal 912, 916. In this example, the OFDM RS signal is illustrated at 1610, with RS1 –RS 7 included in selected subcarriers. In some embodiments, selected subcarriers that include the RS have noise inserted, as shown at 1620. In this example, the subcarriers of RS2, RS3, and RS6 are injected with noise by the transmitter 902, as shown in FIG. 15. This noise may then be substantially removed by the receiver 906, as shown in FIG. 15. However, Eve 910 will receive the RS signal 916, 918 that is still obfuscated with the noise inserted at the reference signals for RS2, RS3, and RS6. The inserted noise may make it difficult or impossible for Eve to sense the obfuscated RS signal and obtain accurate information from the obfuscated RS signal.Obfuscation based on RS Symbol Constellation

[0188] The RS signal 912, 916 can be modulated with a selected modulation and coding scheme (MCS) . For example, the RS signal may be modulated by the transmitter 902 using phase shift keying (PSK) or quadrature amplitude modulation (QAM) . Increasing the level of n-PSK or X-QAM directly increases the number of bits that can be transmitted per period of time, where n and X are positive integers representing a number of points in a circle used to represent the signal’s phase. The number of points are typically evenly distributed around the circle. A constellation diagram can be used to illustrate the number of points, which are typically 2n, with typical values off n (or X) from 1 to 11 (2 to 2048) , but can have higher values. In order for the receiver 906 to demodulate the RS signal 912, the receiver typically knows the type of modulation (e.g. the value of n or X) .

[0189] In accordance with some embodiments, the type of modulation (e.g. n-PSK or X-QAM) and the level of modulation (e.g. the value of n or X) can be varied over time at the transmitter 902 in a known pattern. The pattern can also be known at the receiver 906. The receiver can then demodulate the RS signal 912 based on the expected type of modulation to be used by the transmitter.

[0190] In one example, a fixed constellation (e.g. fixed value of n or X) can be used for all transmissions in selected obfuscation intervals. For example, in an OFDM symbol, slot, subframe, frame, or other desired interval.

[0191] In another example, different constellations can be used for (a) different subcarriers Nsc (s) in an OFDM symbol or (b) within an obfuscation interval. For example, quadrature PSK (QPSK) and 4-QAM may be used for different subcarriers. Or binary PSK (BPSK) , QPSK, and X-QAM may be used for different subcarriers. Or n-PSK may be used for different subcarriers. By changing the modulation of the RS signal 912, 916 over time or frequency, the RS signal can be obfuscated from being received by Eve 910, which is not aware of the change in modulation.FIGs. 17A-17C: Obfuscation Based on Duration

[0192] In the previous figures, the frequency domain of a radio frame structure has been illustrated and discussed, showing a number of subcarriers Nsc that may be transmitted in the RS signal 912, 916. In the time domain, an OFDM signal is typically divided based on units such as symbols, subframes, and frames.

[0193] FIGs. 17A and 17B provides an example illustration of a table and block diagram of a radio frame structure for 3GPP NR 5G, according to some embodiments. In 5G / NR multiple numerologies (waveform configuration like subcarrier spacing) are supported. FIG. 17A shows a table showing numerologies 0-4. Each numerology includes 14 symbols per slot. For each numerology, the number of slots per frame doubles, with numerology 0 having 10 slots per frame, and numerology 4 having 160 slots per frame. Similarly, the number of slots per subframe doubles with each increase in numerology, with numerology 0 having 1 slot per subframe, and numerology 4 having 16 slots per subframe. FIG. 17B provides an example diagram showing the radio frame structure for 3GPP 5G numerology 0, with 1 radio frame comprising 10 slots, with 1 subframe per slot, and 14 symbols per slot. The 5G structure is not intended to be limiting. Other temporal structures may be used in 6G and beyond.

[0194] In accordance with some embodiments, the RS signal 912, 916 can be obfuscated based on a duration. FIG. 17C provides an example block diagram showing m+1 fixed intervals (x) , where m is a positive integer. The interval may be per symbol, per sub-slot, per slot, per sub-frame, per frame, and so forth. During each interval, a specific type of obfuscation may be used, such as the types of obfuscation that have been discussed previously.

[0195] Alternatively, an obfuscation duration can be variable. The variation may be for a predetermined duration, such as 2x, 3x, 4x or so forth. Alternatively, signaling may be used, such as signaling in downlink control information or RRC signaling may be used to identify a change in duration or a change in a type of obfuscation for a duration. Both the transmitter 902 and the receiver 906 can be aware of when the intervals change, and what type of obfuscation is performed in each interval. In one example, time-based synchronization between the transmitters 902 and receivers 906 can be performed using a common pseudo-random generator that may be used to designate the obfuscation duration.

[0196] Since Eve 910 does not know the obfuscation duration, Eve will not know when different types of obfuscation start and stop or what types of obfuscation may be used. Without this knowledge, Eve will have a very difficult time receiving the RS signal 916, 918 and even more difficult sensing the RS signal without the ability to detect and remove the obfuscation.FIG. 18: Obfuscation Information Exchange

[0197] The transmitter 902 and receiver 906 can exchange information regarding the type of obfuscation, and how and when the obfuscation is applied in the time and frequency domains. The obfuscation information can be exchanged in such a way that limits the probability of Eve’s 910 ability to receive the obfuscation information.

[0198] The obfuscation information can be communicated in a UE-specific, UE-group, cell-specific, or network specific manner. In addition, the obfuscation information can be protocol based. For example, the obfuscation information can be communicated via LPP or NRPPa, or via RRC signaling.

[0199] The obfuscation information can be encrypted to provide security to reduce the probability of Eve 910 receiving the obfuscation information. In one example, the transmitter 902 can send a public key. One or more receivers 906 can set up parameters using the public key. Only the transmitter may know the private key to identify the obfuscation parameters. In another example, private keys can be known to both the transmitter and receiver.

[0200] In one example embodiment, a blind estimate may be used based on the receiver. A key parameter can be used to enable a receiver to identify that it has received the correct obfuscation parameters.

[0201] In another example embodiment, a round-trip transmission can be used. For instance, the transmitter 902 can send a signal to the receiver 906 and the receiver can send the signal back. The transmitter can perform sensing based on the returned signal.

[0202] FIG. 18 provides an example block diagram of explicit and blind parameter signaling that can be used to communicate the obfuscation information between the transmitter 902 and the receiver 906, in accordance with some embodiments. The explicit parameter signaling can include LPP or NRPPa signaling, higher level authentication signaling, RRC signaling, medium access control –control element (MAC-CE) signaling, or DCI signaling. In addition, blind parameter signaling such as the round trip signaling can be used to communicate the obfuscation parameters, as illustrated in FIG. 18. The knowledge of the obfuscation parameters, including the obfuscation type, the Nsc to which the obfuscation is applied, and the obfuscation duration enables the transmitter 902 to apply obfuscation to the RS signal 912, 916 and for the receiver 906 to remove the obfuscation and sense the received RS signal. In contrast, without the obfuscation information, Eve 910 will be limited in its ability to receive and sense the RS signal. This can provide security to both the transmitter 902 and receiver 906 since Eve will have a reduced ability to determine location and CSI information based on the RS signal with obfuscation that is sent by the transmitter.FIG. 19: Signaling for Obfuscation of RS Signal

[0203] FIG. 19 illustrates an example block diagram of a signaling procedure 1900 for obfuscation of an RS signal communicated between a transmitter 902 and a receiver 906, according to some embodiments. In a first operation 1910 of the signaling procedure, the transmitter and the receiver can communicate a capability exchange. The capability exchange can include a sensing capability of the receiver 906 and a sensing security capability.

[0204] The signaling procedure 1900 further comprises a second operation 1920 of communicating configuration information between the transmitter 902 and the receiver 906. The configuration information can include sensing configuration information for the receiver 906. Based on the receiver’s capability, the transmitter can send configuration information to inform the receiver how the RS signal 912, 916 has been manipulated to obfuscate the RS signals. For example, a base station 102 may send the configuration information to a UE 106.

[0205] The signaling procedure 1900 further comprises a third operation 1930 of communicating secret information, such as encryption information and private keys. The secret information may be exchanged using LPP / NRPPa , or a security edge protection proxy (SEPP) , which can be used to ensure end-to-end confidentiality and / or integrity between a source and destination network for all 5G interconnect roaming messages. In addition, a 6GPPA (6G positioning protocol A) can be used in 6G networks. The secret information may also be communicated using higher layer authentication signaling, RRC signaling, MAC-CE signaling, DCI signaling, and blind signaling, as previously discussed.

[0206] The signaling procedure 1900 further comprises a fourth operation 1940 of communicating sensing + RF security information, in which the system will commence with the sensing procedure where the RS signal is obfuscated to provide security, as previously discussed.FIG. 20: Flow Chart of Obfuscating a Reference Signal at a Transmitter

[0207] FIG. 20 illustrates a flow chart of a method 2000 for obfuscating a reference signal at a transmitter, in accordance with some embodiments. The method 2000 shown in FIG. 20 may be used in conjunction with any of the systems, methods, or devices illustrated in the figures, among other devices. In various embodiments, some of the method elements shown may be performed concurrently, in a different order than shown, or may be omitted. Additional method elements may also be performed as desired.

[0208] In some embodiments, the method 2000 comprises receiving, at the transmitter, receiver obfuscation capability information from a receiver, as shown in 2010. The method further comprises sending, from the transmitter, obfuscation configuration information to the receiver, as shown in 2020; and exchanging secret obfuscation information with the receiver, as shown in 2030. The method further comprises applying obfuscation to a reference signal to form an obfuscated reference signal based, in part, on the receiver obfuscation capability information, as shown in 2040; and transmitting the obfuscated reference signal to the receiver that is obfuscated based on the receiver obfuscation capability information to enable the receiver to remove the obfuscation from the obfuscated reference signal and sense the reference signal based on the obfuscation configuration information and the secret obfuscation information, as shown in 2050.

[0209] In some embodiments, the transmitter is one of a base station or a user equipment (UE) or a transmit receive point (TRP) and the receiver is one of the base station or the UE or the TRP.

[0210] In some embodiments, the method 2000 can further comprise obfuscating the reference signal at the transmitter by performing one or more of: modulating the reference signal that is a pseudo-random sequence using quadrature phase shift keying (QPSK) ; wherein the secret obfuscation information comprises parameters associated with the pseudo-random sequence that are communicated via: long term evolution (LTE) positioning protocol (LPP) or new radio positioning protocol A (NRPPA) for a positioning reference signal; or radio resource control (RRC) signaling or a cell identification value for a demodulation reference signal (DMRS) or a tracking reference signal (TRS) . The RRC signaling can encrypted using an access stratum layer; or the reference signal is user equipment (UE) -specific or configured for a closed UE-group.

[0211] In some embodiments, the method 2000 can further comprise obfuscating the reference signal at the transmitter by performing one or more of: manipulating one or more of an amplitude or a phase of the reference signal to obscure the reference signal from reception by an eavesdropper (Eve) ; or inserting noise into the reference signal at one or more frequency locations and time locations to obscure the reference signal from reception by the Eve; or changing a symbol constellation of the reference signal at one or more frequency locations and time locations to obscure the reference signal from reception by the Eve. In some embodiments, obfuscating the reference signal at the transmitter can be performed on a per sub-carrier basis by obfuscating a selected pattern of subcarriers in the reference signal; and communicating the selected pattern of subcarriers to the receiver to enable the receiver to remove the obfuscation of the selected subcarriers; wherein the selected pattern comprises one or more of: an entire number of subcarriers in the reference signal; or a 1 / p section of the entire number of subcarriers in the reference signal, where p is a positive integer; or a block of subcarriers in the reference signal; or a comb of subcarriers in the reference signal.

[0212] The method 2000 can further comprise manipulating one or more of the amplitude or the phase of the reference signal using one or more of: a selected function to manipulate one or more of the amplitude or the phase of the reference signal; or a look up table (LUT) to manipulate one or more of the amplitude or the phase of the reference signal; or a filter to manipulate one or more of the amplitude or the phase of the reference signal; or a hybrid of one or more of the function or the look up table or the filter to manipulate one or more of the amplitude or the phase of the reference signal.

[0213] In some embodiments, the method 2000 can further comprise applying an obfuscation filter to the reference signal prior to performing an Inverse Fast Fourier Transform on the reference signal to form the obfuscated reference signal; and transmitting the obfuscated reference signal to the receiver to enable the receiver to remove the obfuscation filter or perform equalization on the obfuscated reference signal after performing a Fast Fourier Transform (FFT) on the obfuscated reference signal.

[0214] In some embodiments, the method 2000 can further comprise inserting the obfuscation of the selected pattern of subcarriers on the reference signal prior to performing an Inverse Fast Fourier Transform on the reference signal to form the obfuscated reference signal; and transmitting the obfuscated reference signal to the receiver to enable the receiver to remove the obfuscation on the selected pattern of subcarriers after performing a Fast Fourier Transform (FFT) on the obfuscated reference signal.

[0215] In some embodiments, the method 2000 can further comprise inserting noise on selected subcarriers of the reference signal that are known to both the transmitter and the receiver using one or more of: inserting random noise for obfuscation on fixed subcarriers to form an obfuscated reference signal; or inserting noise for obfuscation on random or selected subcarriers that include reference signals to form the obfuscated reference signal; and transmitting the obfuscated reference signal to the receiver to enable the receiver to remove the noise inserted on the fixed subcarriers, the random subcarriers, or the selected subcarriers.

[0216] In some embodiments, the method 2000 further comprises inserting the random noise or the noise for obfuscation of the fixed subcarriers or the random subcarriers or the selected subcarriers on the reference signal prior to performing an Inverse Fast Fourier Transform on the reference signal to form the obfuscated reference signal; and transmitting the obfuscated reference signal to the receiver to enable the receiver to remove the random noise or the noise for obfuscation on the fixed subcarriers or the random subcarriers or the selected subcarriers after performing a Fast Fourier Transform (FFT) on the obfuscated reference signal.

[0217] In some embodiments, the operations of the method 2000 previously described can further comprise obfuscating the reference signal over one or more obfuscation time intervals to form the obfuscated reference signal, wherein the obfuscation time interval is one or more of per symbol, per sub-slot, per slot, per sub-frame, or per frame of the reference signal.

[0218] In some embodiments, the operations of the method 2000 previously described can further comprise modifying a modulation constellation for the reference signal over one or more subcarriers for an obfuscation time interval to form the obfuscated reference signal. In some embodiments, the modulation constellation is one or more of an n-phase shift keying (n-PSK) constellation or an x-quadrature amplitude modulation (x-QAM) constellation, where n and x are positive integers.

[0219] In some embodiments, the method 2000 can further comprise encrypting the secret obfuscation information at the transmitter; sending the secret obfuscation information to the receiver; and sending a public key to the receiver to enable the receiver to decrypt the secret obfuscation information, wherein only the transmitter knows a private key for encrypting the secret obfuscation information or both the transmitter and the receiver know the private key.

[0220] In some embodiments, the method 2000 further comprises sending a key parameter to the receiver to enable the receiver to determine when the obfuscation has been removed correctly; or sending a round trip time (RTT) signal to the receiver; and receiving the RTT signal from the receiver; and performing sensing at the transmitter based on the returned signal.

[0221] In some embodiments, exchanging the secret obfuscation information with the receiver further comprises: transmitting one or more obfuscation parameters to the receiver using one or more of the following: long term evolution (LTE) positioning protocol (LPP) or new radio positioning protocol A (NRPPA) ; higher layer authentication signaling; radio resource control (RRC) signaling; medium access control-control element (MAC-CE) signaling; or downlink control information (DCI) signaling; or transmitting blind parameter signaling comprising round trip signaling.

[0222] In one aspect, a baseband processor (e.g. baseband processor 600 or 604) , or functionally similar component (s) whose function may include supporting baseband layer operations (e.g., to facilitate wireless communication between the UE 106 and other wireless devices) in the UE 106, can be configured to cause the UE 106 to perform any of the methods described herein. In another aspect, the UE 106 can have one or more processors (e.g. processors 402 and / or 600 or 604) coupled to a memory 406 or 604G to cause the user equipment 106 to perform any of the methods described herein. In another aspect, a baseband processor (e.g. baseband processor 600 or 604 can be configured to cause a base station 102 to perform one or more of the methods described herein. In another aspect, the base station 102 can have one or more processors 204 and / or 600 or 604 coupled to memory 260 or 604G configured to cause the base station 102 to perform any of the methods described herein. In another aspect, a computer program product, comprising computer instructions which, when executed by one or more processors, can perform any of the operations described herein.

[0223] Embodiments of the present disclosure may be realized in any of various forms. For example, some embodiments may be realized as a computer-implemented method, a computer readable memory medium, or a computer system. Other embodiments may be realized using one or more custom-designed hardware devices such as ASICs. Still other embodiments may be realized using one or more programmable hardware elements such as FPGAs.

[0224] In some embodiments, a non-transitory computer-readable memory medium may be configured so that it stores program instructions and / or data, where the program instructions, if executed by a computer system, cause the computer system to perform a method, e.g., any of the method embodiments described herein, or, any combination of the method embodiments described herein, or, any subset of any of the method embodiments described herein, or, any combination of such subsets.

[0225] In some embodiments, a device (e.g., a UE 106) may be configured to include a processor (or a set of processors) and a memory medium, where the memory medium stores program instructions, where the processor is configured to read and execute the program instructions from the memory medium, where the program instructions are executable to implement any of the various method embodiments described herein (or, any combination of the method embodiments described herein, or, any subset of any of the method embodiments described herein, or, any combination of such subsets) . The device may be realized in any of various forms.

[0226] Any of the methods described herein for operating a user equipment (UE) may be the basis of a corresponding method for operating a base station, by interpreting each message / signal X received by the UE in the downlink as message / signal X transmitted by the base station, and each message / signal Y transmitted in the uplink by the UE as a message / signal Y received by the base station.

[0227] Although the embodiments above have been described in considerable detail, numerous variations and modifications will become apparent to those skilled in the art once the above disclosure is fully appreciated. It is intended that the following claims be interpreted to embrace all such variations and modifications .

Claims

1.A method of obfuscating a reference signal at a transmitter, the method comprising:receiving, at the transmitter, receiver obfuscation capability information from a receiver;sending, from the transmitter, obfuscation configuration information to the receiver;exchanging secret obfuscation information with the receiver;applying obfuscation to a reference signal to form an obfuscated reference signal based, in part, on the receiver obfuscation capability information; andtransmitting the obfuscated reference signal to the receiver that is obfuscated based on the receiver obfuscation capability information to enable the receiver to remove the obfuscation from the obfuscated reference signal and sense the reference signal based on the obfuscation configuration information and the secret obfuscation information.2.The method of claim 1, wherein:the transmitter is one of a base station or a user equipment (UE) or a transmit receive point (TRP) ; andthe receiver is one of the base station or the UE or the TRP.3.The method of claim 1, further comprising obfuscating the reference signal at the transmitter by performing one or more of:modulating the reference signal that is a pseudo-random sequence using quadrature phase shift keying (QPSK) ;wherein the secret obfuscation information comprises parameters associated with the pseudo-random sequence that are communicated via:long term evolution (LTE) positioning protocol (LPP) or new radio positioning protocol A (NRPPA) for a positioning reference signal; orradio resource control (RRC) signaling or a cell identification value for a demodulation reference signal (DMRS) or a tracking reference signal (TRS) .4.The method of claim 3, wherein:the RRC signaling is encrypted using an access stratum layer; orthe reference signal is user equipment (UE) -specific or configured for a closed UE-group.5.The method of claim 1, further comprising obfuscating the reference signal at the transmitter by performing one or more of:manipulating one or more of an amplitude or a phase of the reference signal to obscure the reference signal from reception by an eavesdropper (Eve) ; orinserting noise into the reference signal at one or more frequency locations and time locations to obscure the reference signal from reception by the Eve; orchanging a symbol constellation of the reference signal at one or more frequency locations and time locations to obscure the reference signal from reception by the Eve.6.The method of claim 5, further comprising:obfuscating the reference signal at the transmitter on a per sub-carrier basis by obfuscating a selected pattern of subcarriers in the reference signal; andcommunicating the selected pattern of subcarriers to the receiver to enable the receiver to remove the obfuscation of the selected subcarriers;wherein the selected pattern comprises one or more of:an entire number of subcarriers in the reference signal; ora 1 / p section of the entire number of subcarriers in the reference signal, where p is a positive integer; ora block of subcarriers in the reference signal; ora comb of subcarriers in the reference signal.7.The method of claim 5, further comprising manipulating one or more of the amplitude or the phase of the reference signal using one or more of:a selected function to manipulate one or more of the amplitude or the phase of the reference signal; ora look up table (LUT) to manipulate one or more of the amplitude or the phase of the reference signal; ora filter to manipulate one or more of the amplitude or the phase of the reference signal; ora hybrid of one or more of the function or the look up table or the filter to manipulate one or more of the amplitude or the phase of the reference signal.8.The method of claim 7, further comprising:applying an obfuscation filter to the reference signal prior to performing an Inverse Fast Fourier Transform on the reference signal to form the obfuscated reference signal; andtransmitting the obfuscated reference signal to the receiver to enable the receiver to remove the obfuscation filter or perform equalization on the obfuscated reference signal after performing a Fast Fourier Transform (FFT) on the obfuscated reference signal.9.The method of claim 6, further comprising:inserting the obfuscation of the selected pattern of subcarriers on the reference signal prior to performing an Inverse Fast Fourier Transform on the reference signal to form the obfuscated reference signal; andtransmitting the obfuscated reference signal to the receiver to enable the receiver to remove the obfuscation on the selected pattern of subcarriers after performing a Fast Fourier Transform (FFT) on the obfuscated reference signal.10.The method of claim 5, further comprising inserting noise on selected subcarriers of the reference signal that are known to both the transmitter and the receiver using one or more of:inserting random noise for obfuscation on fixed subcarriers to form an obfuscated reference signal; orinserting noise for obfuscation on random or selected subcarriers that include reference signals to form the obfuscated reference signal; andtransmitting the obfuscated reference signal to the receiver to enable the receiver to remove the noise inserted on the fixed subcarriers, the random subcarriers, or the selected subcarriers.11.The method of claim 10, further comprising:inserting the random noise or the noise for obfuscation of the fixed subcarriers or the random subcarriers or the selected subcarriers on the reference signal prior to performing an Inverse Fast Fourier Transform on the reference signal to form the obfuscated reference signal; andtransmitting the obfuscated reference signal to the receiver to enable the receiver to remove the random noise or the noise for obfuscation on the fixed subcarriers or the random subcarriers or the selected subcarriers after performing a Fast Fourier Transform (FFT) on the obfuscated reference signal.12.The method of any of the previous claims, further comprising:obfuscating the reference signal over one or more obfuscation time intervals to form the obfuscated reference signal;wherein the obfuscation time interval is one or more of per symbol, per sub-slot, per slot, per sub-frame, or per frame of the reference signal.13.The method any of the previous claims, further comprising:modifying a modulation constellation for the reference signal over one or more subcarriers for an obfuscation time interval to form the obfuscated reference signal.14.The method of claim 13, wherein the modulation constellation is one or more of an n-phase shift keying (n-PSK) constellation or an x-quadrature amplitude modulation (x-QAM) constellation, where n and x are positive integers.15.The method of claim 1, further comprising:encrypting the secret obfuscation information at the transmitter;sending the secret obfuscation information to the receiver; andsending a public key to the receiver to enable the receiver to decrypt the secret obfuscation information,wherein only the transmitter knows a private key for encrypting the secret obfuscation information or both the transmitter and the receiver know the private key.16.The method of claim 1, further comprising:sending a key parameter to the receiver to enable the receiver to determine when the obfuscation has been removed correctly; orsending a round trip time (RTT) signal to the receiver; andreceiving the RTT signal from the receiver; andperforming sensing at the transmitter based on a returned signal.17.The method of claim 1, wherein exchanging the secret obfuscation information with the receiver further comprises:transmitting one or more obfuscation parameters to the receiver using one or more of the following:long term evolution (LTE) positioning protocol (LPP) or new radio positioning protocol A (NRPPA) ;higher layer authentication signaling;radio resource control (RRC) signaling;medium access control-control element (MAC-CE) signaling; ordownlink control information (DCI) signaling; or transmitting blind parameter signaling comprising round trip signaling.18.A user equipment (UE) configured to perform any of the operations described herein.19.A next generation node B (gNB) configured to perform any of the operations described herein.20.A baseband processor configured to cause a user equipment (UE) to perform any of the methods of claims 1-17.21.An apparatus configured to cause a user equipment (UE) , having one or more processors coupled to a memory, to perform any of the methods of claims 1-17.22.A computer program product, comprising computer instructions which, when executed by one or more processors, perform any of the operations described herein.