Security protection of user equipment (UE)-to-UE relay discovery
Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may encrypt a discovery message associated with a relay service based at least in part on a set of code-sending security parameters (CSSPs) associated with the relay service. The UE may transmit the encrypted discovery message. In some aspects, a UE may receive an encrypted discovery message. The UE may decrypt the encrypted discovery message based at least in part on a set of code-receiving security parameters (CRSPs) associated with the relay service. Numerous other aspects are provided.
1 . A user equipment (UE) for wireless communication, comprising:
one or more antennas; and
a processing system that includes one or more processors and one or more memories that store code and are coupled with the one or more processors, the processing system configured to cause the UE to:
encrypt a discovery message associated with a relay service based at least in part on a set of code-sending security parameters (CSSPs) associated with the relay service,
wherein the set of CSSPs includes a first set of security parameters and a second set of security parameters, and
wherein the processing system, to encrypt the discovery message based at least in part on the set of CSSPs, is configured to cause the UE to:
encrypt the discovery message using the first set of security parameters to provide end-to-end security of the discovery message, and
encrypt the discovery message using the second set of security parameters to provide hop-by-hop security for the discovery message; and
transmit the encrypted discovery message.
2 . The UE of claim 1 , wherein the discovery message comprises an end-to-end proximity services (ProSe) direct discovery information element (IE), and wherein the processing system, to encrypt the discovery message using the first set of security parameters, is configured to cause the UE to:
encrypt the end-to-end ProSe direct discovery IE based at least in part on a set of CSSPs associated with end-to-end ProSe direct discovery.
3 . The UE of claim 2 , wherein the set of CSSPs associated with the end-to-end ProSe direct discovery that is used to encrypt the end-to-end ProSe direct discovery IE is different than a set of CSSPs associated with the end-to-end ProSe direct discovery that is to be used by another UE to encrypt end-to-end ProSe direct discovery IEs.
4 . The UE of claim 1 , wherein the discovery message comprises discovery information.
5 . The UE of claim 4 , wherein the discovery information is included in a proximity services (ProSe) direct discovery information element (IE) in the discovery message.
6 . The UE of claim 4 , wherein the discovery message is a proximity services (ProSe) direct discovery message.
7 . The UE of claim 4 , wherein the processing system, to encrypt the discovery message using the first set of parameters, is configured to cause the UE to encrypt the discovery information based at least in part on a set of CSSPs associated with end-to-end proximity services (ProSe) direct discovery.
8 . The UE of claim 1 , wherein the discovery message comprises discovery information that includes at least one of an information element (IE) associated with service discovery or an IE associated with group member discovery.
9 . The UE of claim 1 , wherein the processing system is further configured to cause the UE to:
receive an encrypted response message that includes a response message associated with the relay service; and
decrypt the encrypted response message based at least in part on a set of code-receiving security parameters (CRSPs) associated with the relay service.
10 . The UE of claim 9 , wherein the processing system, to cause the UE to decrypt the encrypted response message, is configured to cause the UE to decrypt an encrypted end-to-end proximity services (ProSe) direct discovery information element (IE), included in the response message, based at least in part on a set of CRSPs associated with end-to-end ProSe direct discovery.
11 . The UE of claim 10 , wherein the set of CRSPs associated with the end-to-end ProSe direct discovery that is used to decrypt the encrypted end-to-end ProSe direct discovery IE is different than a set of CRSPs associated with the end-to-end ProSe direct discovery that is to be used by another UE to decrypt encrypted end-to-end ProSe direct discovery IEs.
12 . The UE of claim 9 , wherein the processing system is further configured to cause the UE to perform a route discovery procedure associated with the relay service or a route selection procedure associated with the relay service based at least in part on the response message.
13 . The UE of claim 9 , wherein the response message comprises discovery information that includes at least one of an information element (IE) associated with service discovery or an IE associated with group member discovery.
14 . A first user equipment (UE) for wireless communication, comprising:
one or more antennas; and
a processing system that includes one or more processors and one or more memories that store code and are coupled with the one or more processors, the processing system configured to cause the first UE to:
receive, from a second UE, an encrypted discovery message;
decrypt, based at least in part on a set of code-receiving security parameters (CRSPs) associated with a relay service, the encrypted discovery message to produce a discovery message;
add information associated with the relay service to the discovery message;
re-encrypt, based at least in part on a set of code-sending security parameters (CSSPs) associated with the relay service after adding the information associated with the relay service to the discovery message, the discovery message to produce a re-encrypted discovery message; and
transmit, to a third UE, the re-encrypted discovery message.
15 . The UE of claim 14 , wherein the discovery message comprises discovery information.
16 . The UE of claim 15 , wherein the discovery information is included in a proximity services (ProSe) direct discovery information element (IE) in the discovery message.
17 . The UE of claim 15 , wherein the discovery message is a proximity services (ProSe) direct discovery message.
18 . The UE of claim 14 , wherein the discovery message comprises discovery information that includes at least one of an information element (IE) associated with service discovery or an IE associated with group member discovery.
19 . The UE of claim 14 , wherein the processing system is further configured to cause the first UE to:
receive an encrypted response message;
decrypt, based at least in part on the set of CRSPs associated with the relay service, the encrypted response message to produce a response message;
add the information associated with the relay service to the response message;
re-encrypt, based at least in part on the set of CSSPs associated with the relay service after adding the information associated with the relay service to the response message, the response message to produce a re-encrypted response message; and
transmit the re-encrypted response message.
20 . The UE of claim 19 , wherein the response message comprises discovery information that includes at least one of an information element (IE) associated with service discovery or an IE associated with group member discovery.
21 . A user equipment (UE) for wireless communication, comprising:
one or more antennas; and
a processing system that includes one or more processors and one or more memories that store code and are coupled with the one or more processors, the processing system configured to cause the UE to:
receive an encrypted discovery message,
wherein the encrypted discovery message is encrypted based on a first set of security parameters associated with end-to-end security of a discovery message and a second set of security parameters associated with hop-by-hop security for the discovery message; and
decrypt the encrypted discovery message based at least in part on a set of code-receiving security parameters (CRSPs) associated with a relay service,
wherein the set of CRSPs associated with the relay service enable decryption of an encryption using the second set of security parameters.
22 . The UE of claim 21 , wherein the processing system is further configured to cause the UE to perform a route discovery procedure associated with the relay service or a route selection procedure associated with the relay service based at least in part on the discovery message.
23 . The UE of claim 21 , wherein the discovery message comprises discovery information.
24 . The UE of claim 23 , wherein the discovery information is included in a proximity services (ProSe) direct discovery information element (IE) in the discovery message.
25 . The UE of claim 23 , wherein the discovery message is a proximity services (ProSe) direct discovery message.
26 . The UE of claim 23 , wherein the processing system, to decrypt the encrypted discovery message, is configured to cause the UE to decrypt the discovery information based at least in part on a set of CRSPs associated with end-to-end proximity services (ProSe) direct discovery.
27 . The UE of claim 21 , wherein the discovery message comprises discovery information that includes at least one of an information element (IE) associated with service discovery or an IE associated with group member discovery.
28 . The UE of claim 21 , wherein the encrypted discovery message comprises an encrypted end-to-end proximity services (ProSe) direct discovery information element (IE), and wherein the processing system, to decrypt the encrypted discovery message, is configured to cause the UE to:
decrypt the encrypted ProSe direct discovery IE based at least in part on a set of CRSPs associated with end-to-end ProSe direct discovery.
29 . The UE of claim 21 , wherein the processing system is further configured to cause the UE to:
encrypt a response message associated with the relay service based at least in part on a set of code-sending security parameters (CSSPs) associated with the relay service; and
transmit the encrypted response message.
30 . A method of wireless communication performed by a first user equipment (UE), comprising:
receiving, from a second UE, an encrypted discovery message;
decrypting, based at least in part on a set of code-receiving security parameters (CRSPs) associated with a relay service, the encrypted discovery message to produce a discovery message;
adding information associated with the relay service to the discovery message;
re-encrypting, based at least in part on a set of code-sending security parameters (CSSPs) associated with the relay service after adding the information associated with the relay service to the discovery message, the discovery message to produce a re-encrypted discovery message; and
transmitting, to a third UE, the re-encrypted discovery message.