IP Library Granted Patent US 12671571
Granted Patent B2
US 12671571 · App. 18/597,512 · Granted Jun 30, 2026

Systems and methods for support of security for sidelink communication and positioning

Inventor: Stephen William Edge (Escondido, CA)
Assignee: QUALCOMM Incorporated
H04L9/0618H04W92/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671571
App. No.
18/597,512
Granted
Jun 30, 2026
Kind
B2
Abstract

Techniques are described for supporting secure sidelink communication and secure sidelink positioning for user equipments (UEs). A server may configure each UE with a private cipher key, a random value and derived cipher keys. Two UEs may exchange their random values and may each use their private cipher key and a received random value to determine a derived cipher key already configured in the other UE. The two derived cipher keys now known to both UEs can enable secure communication and positioning. In a degenerate case, a Type B UE is configured with a random value and a derived cipher key which can be determined by a Type A UE configured with a private cipher key using the random value. The technique can be extended to secure communication and positioning for a group of UEs.

Claims (78)

1 . A method of enabling secure sidelink communication between a group of user equipments (UEs), performed by a server, the method comprising:

determining a set of private cipher keys PK and a set of corresponding cipher key IDs KID;

determining a random or partly random value RV for each UE of the group of UEs;

determining a set of derived cipher keys DK for each UE of the group of UEs based on the random or partly random value RV for the each UE and the set of private cipher keys PK, wherein determining the set of derived cipher keys DK for each UE of the group of UEs based on the random or partly random value RV for the each UE and the set of private cipher keys PK comprises:

determining each derived cipher key of the set of derived cipher keys DK based on ciphering the random or partly random value RV using a different private cipher key in the set of private cipher keys PK, wherein the set of derived cipher keys DK and the set of private cipher keys PK contain equal numbers of cipher keys, wherein each private cipher key in the set of private cipher keys PK is used to determine one derived cipher key in the set of derived cipher keys DK; and

securely configuring each UE of the group of UEs with the random or partly random value RV for the each UE, the set of derived cipher keys DK for the each UE, one private cipher key of the set of private cipher keys PK and one cipher key ID of the set of corresponding cipher key IDs KID, wherein the one cipher key ID corresponds to the one private cipher key.

2 . The method of claim 1 , further comprising:

periodically determining a new random or partly random value RV and a new set of derived cipher keys DK for each UE of the group of UEs; and

securely configuring each UE of the group of UEs with the new random or partly random value RV and the new set of derived cipher keys DK for the each UE.

3 . A method of enabling secure sidelink communication between a group of user equipments (UEs), performed by a server, the method comprising:

determining a set of private cipher keys PK and a set of corresponding cipher key IDs KID;

determining a random or partly random value RV for each UE of the group of UEs;

determining a set of derived cipher keys DK for each UE of the group of UEs based on the random or partly random value RV for the each UE and the set of private cipher keys PK; and

securely configuring each UE of the group of UEs with the random or partly random value RV for the each UE, the set of derived cipher keys DK for the each UE, one private cipher key of the set of private cipher keys PK and one cipher key ID of the set of corresponding cipher key IDs KID, wherein the one cipher key ID corresponds to the one private cipher key,

wherein securely configuring each UE of the group of UEs with the random or partly random value RV for the each UE, the set of derived cipher keys DK for the each UE, the one private cipher key of the set of private cipher keys PK and the one cipher key ID of the set of corresponding cipher key IDs KID, comprises configuring the each UE of the group of UEs using a secure connection between the each UE and the server, the secure connection based on a public key-private key pair of the server.

4 . A method of supporting secure sidelink communication between a group of user equipments (UEs), performed by a first UE of the group of UEs, the method comprising:

securely receiving, from a server, a first random or partly random value RV 1 , a first set of derived cipher keys DK 1 , a first private cipher key K 1 of a set of private cipher keys PK and a first cipher key ID K 1 ID, wherein the first cipher key ID K 1 ID identifies the first private cipher key K 1 ;

sending in plain text, to a second UE of the group of UEs, the first random or partly random value RV 1 and the first cipher key ID K 1 ID;

receiving in plain text, from the second UE of the group of UEs, a second random or partly random value RV 2 and a second cipher key ID K 2 ID, wherein the second cipher key ID K 2 ID identifies a second private cipher key K 2 of the set of private cipher keys PK configured in the second UE;

determining at least one common cipher key based on the first set of derived cipher keys DK 1 , the first private cipher key K 1 , the second random or partly random value RV 2 and the second cipher key ID K 2 ID; and

supporting secure sidelink communication with the second UE based on the at least one common cipher key.

5 . The method of claim 4 , wherein securely receiving, from the server, the first random or partly random value RV 1 , the first set of derived cipher keys DK 1 , the first private cipher key K 1 and the first cipher key ID K 1 ID comprises receiving the first random or partly random value RV 1 , the first set of derived cipher keys DK 1 , the first private cipher key K 1 and the first cipher key ID K 1 ID using a secure connection between the first UE and the server, the secure connection based on a public key-private key pair of the server.

6 . The method of claim 4 , wherein each derived cipher key DKm in the first set of derived cipher keys DK 1 corresponds to a separate private cipher key PKm in the set of private cipher keys PK, wherein the each derived cipher key DKm comprises a ciphering of the first random or partly random value RV 1 using the corresponding separate private cipher key PKm in the set of private cipher keys PK, wherein the first set of derived cipher keys DK 1 and the set of private cipher keys PK contain equal numbers of cipher keys, wherein each private cipher key in the set of private cipher keys PK is used to determine one derived cipher key in the set of derived cipher keys DK.

7 . The method of claim 4 , wherein determining the at least one common cipher key based on the first set of derived cipher keys DK 1 , the first private cipher key K 1 , the second random or partly random value RV 2 and the second cipher key ID K 2 ID comprises:

identifying a first derived cipher key in the first set of derived cipher keys DK 1 , wherein the first derived cipher key corresponds to a second private cipher key K 2 in the set of private cipher keys PK, wherein the second private cipher key K 2 is identified by the second cipher key ID K 2 ID;

determining a second derived cipher key based on ciphering the second random or partly random value RV 2 using the first private cipher key K 1 ; and

determining the at least one common cipher key based on the first derived cipher key and the second derived cipher key.

8 . The method of claim 7 , wherein determining the at least one common cipher key based on the first derived cipher key and the second derived cipher key comprises:

sending a first key component to the second UE, the first key component ciphered using the first derived cipher key or the second derived key;

receiving a second key component from the second UE, the second key component ciphered using the other of the first derived cipher key or the second derived key;

deciphering the second key component using the other of the first derived cipher key or the second derived key; and

determining the at least one common cipher key based on the first key component and the second key component.

9 . The method of claim 4 further comprising:

sending in plain text, to each UE of the group of UEs excluding the first UE and the second UE, the first random or partly random value RV 1 and the first cipher key ID K 1 ID;

receiving in plain text, from the each UE of the group of UEs, a unique random or partly random value RV and a cipher key ID K ID, wherein the cipher key ID KID identifies a private cipher key K of the set of private cipher keys PK configured in the each UE;

determining at least one common cipher key for the each UE based on the first set of derived cipher keys DK 1 , the first private cipher key K 1 , the random or partly random value RV and the cipher key ID KID;

sending at least one common group cipher key to the each UE, the at least one common group cipher key ciphered using the at least one common cipher key for the each UE; and

supporting secure sidelink communication for the group of UEs based on the at least one common group cipher key.

10 . The method of claim 4 , wherein supporting secure sidelink communication for the group of UEs based on at least one common group cipher key comprises exchanging messages for a sidelink positioning protocol (SLPP) with others of the group of UEs, wherein the SLPP messages are ciphered or integrity protected or both using the at least one common group cipher key.

11 . An apparatus for enabling secure sidelink communication between a group of user equipments (UEs), the apparatus comprising:

means for determining a set of private cipher keys PK and a set of corresponding cipher key IDs KID;

means for determining a random or partly random value RV for each UE of the group of UEs;

means for determining a set of derived cipher keys DK for each UE of the group of UEs based on the random or partly random value RV for the each UE and the set of private cipher keys PK, wherein means for determining the set of derived cipher keys DK for each UE of the group of UEs based on the random or partly random value RV for the each UE and the set of private cipher keys PK comprises:

means for determining each derived cipher key of the set of derived cipher keys DK based on ciphering the random or partly random value RV using a different private cipher key in the set of private cipher keys PK, wherein the set of derived cipher keys DK and the set of private cipher keys PK contain equal numbers of cipher keys, wherein each private cipher key in the set of private cipher keys PK is used to determine one derived cipher key in the set of derived cipher keys DK; and

means for securely configuring each UE of the group of UEs with the random or partly random value RV for the each UE, the set of derived cipher keys DK for the each UE, one private cipher key of the set of private cipher keys PK and one cipher key ID of the set of corresponding cipher key IDs KID, wherein the one cipher key ID corresponds to the one private cipher key.

12 . The apparatus of claim 11 , further comprising:

means for periodically determining a new random or partly random value RV and a new set of derived cipher keys DK for each UE of the group of UEs; and

means for securely configuring each UE of the group of UEs with the new random or partly random value RV and the new set of derived cipher keys DK for the each UE.

13 . An apparatus for enabling secure sidelink communication between a group of user equipments (UEs), the apparatus comprising:

means for determining a set of private cipher keys PK and a set of corresponding cipher key IDs KID;

means for determining a random or partly random value RV for each UE of the group of UEs;

means for determining a set of derived cipher keys DK for each UE of the group of UEs based on the random or partly random value RV for the each UE and the set of private cipher keys PK; and

means for securely configuring each UE of the group of UEs with the random or partly random value RV for the each UE, the set of derived cipher keys DK for the each UE, one private cipher key of the set of private cipher keys PK and one cipher key ID of the set of corresponding cipher key IDs KID, wherein the one cipher key ID corresponds to the one private cipher key,

wherein means for securely configuring each UE of the group of UEs with the random or partly random value RV for the each UE, the set of derived cipher keys DK for the each UE, the one private cipher key of the set of private cipher keys PK and the one cipher key ID of the set of corresponding cipher key IDs KID, comprises means for configuring the each UE of the group of UEs using a secure connection between the each UE and a server, the secure connection based on a public key-private key pair of the server.

14 . An apparatus for supporting secure sidelink communication between a group of user equipments (UEs), performed by a first UE of the group of UEs, the apparatus comprising:

means for securely receiving, from a server, a first random or partly random value RV 1 , a first set of derived cipher keys DK 1 , a first private cipher key K 1 of a set of private cipher keys PK and a first cipher key ID K 1 ID, wherein the first cipher key ID K 1 ID identifies the first private cipher key K 1 ;

means for sending in plain text, to a second UE of the group of UEs, the first random or partly random value RV 1 and the first cipher key ID K 1 ID;

means for receiving in plain text, from the second UE of the group of UEs, a second random or partly random value RV 2 and a second cipher key ID K 2 ID, wherein the second cipher key ID K 2 ID identifies a second private cipher key K 2 of the set of private cipher keys PK configured in the second UE;

means for determining at least one common cipher key based on the first set of derived cipher keys DK 1 , the first private cipher key K 1 , the second random or partly random value RV 2 and the second cipher key ID K 2 ID; and

means for supporting secure sidelink communication with the second UE based on the at least one common cipher key.

15 . The apparatus of claim 14 , wherein means for securely receiving, from the server, the first random or partly random value RV 1 , the first set of derived cipher keys DK 1 , the first private cipher key K 1 and the first cipher key ID K 1 ID comprises means for receiving the first random or partly random value RV 1 , the first set of derived cipher keys DK 1 , the first private cipher key K 1 and the first cipher key ID K 1 ID using a secure connection between the first UE and the server, the secure connection based on a public key-private key pair of the server.

16 . The apparatus of claim 14 , wherein each derived cipher key DKm in the first set of derived cipher keys DK 1 corresponds to a separate private cipher key PKm in the set of private cipher keys PK, wherein the each derived cipher key DKm comprises a ciphering of the first random or partly random value RV 1 using the corresponding separate private cipher key PKm in the set of private cipher keys PK, wherein the first set of derived cipher keys DK 1 and the set of private cipher keys PK contain equal numbers of cipher keys, wherein each private cipher key in the set of private cipher keys PK is used to determine one derived cipher key in the set of derived cipher keys DK.

17 . The apparatus of claim 14 , wherein means for determining the at least one common cipher key based on the first set of derived cipher keys DK 1 , the first private cipher key K 1 , the second random or partly random value RV 2 and the second cipher key ID K 2 ID comprises:

means for identifying a first derived cipher key in the first set of derived cipher keys DK 1 , wherein the first derived cipher key corresponds to a second private cipher key K 2 in the set of private cipher keys PK, wherein the second private cipher key K 2 is identified by the second cipher key ID K 2 ID;

means for determining a second derived cipher key based on ciphering the second random or partly random value RV 2 using the first private cipher key K 1 ; and

means for determining the at least one common cipher key based on the first derived cipher key and the second derived cipher key.

18 . The apparatus of claim 17 , wherein means for determining the at least one common cipher key based on the first derived cipher key and the second derived cipher key comprises:

means for sending a first key component to the second UE, the first key component ciphered using the first derived cipher key or the second derived key;

means for receiving a second key component from the second UE, the second key component ciphered using the other of the first derived cipher key or the second derived key;

means for deciphering the second key component using the other of the first derived cipher key or the second derived key; and

means for determining the at least one common cipher key based on the first key component and the second key component.

19 . The apparatus of claim 14 further comprising:

means for sending in plain text, to each UE of the group of UEs excluding the first UE and the second UE, the first random or partly random value RV 1 and the first cipher key ID K 1 ID;

means for receiving in plain text, from the each UE of the group of UEs, a unique random or partly random value RV and a cipher key ID KID, wherein the cipher key ID KID identifies a private cipher key K of the set of private cipher keys PK configured in the each UE;

means for determining at least one common cipher key for the each UE based on the first set of derived cipher keys DK 1 , the first private cipher key K 1 , the random or partly random value RV and the cipher key ID KID;

means for sending at least one common group cipher key to the each UE, the at least one common group cipher key ciphered using the at least one common cipher key for the each UE; and

means for supporting secure sidelink communication for the group of UEs based on the at least one common group cipher key.

20 . The apparatus of claim 14 , wherein means for supporting secure sidelink communication for the group of UEs based on at least one common group cipher key comprises means for exchanging messages for a sidelink positioning protocol (SLPP) with others of the group of UEs, wherein the SLPP messages are ciphered or integrity protected or both using the at least one common group cipher key.