IP Library Granted Patent US 12671578
Granted Patent B2
US 12671578 · App. 18/683,351 · Granted Jun 30, 2026

Techniques for on-demand secret key requesting and sharing

Inventors: Ahmed Elshafie (San Diego, CA); Hung Dinh Ly (San Diego, CA); Alexandros Manolakos (Athens, GR)
Assignee: QUALCOMM Incorporated
H04L9/0891H04L9/085H04W12/0431
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671578
App. No.
18/683,351
Granted
Jun 30, 2026
Kind
B2
Abstract

Methods, systems, and devices for wireless communications are described. A user equipment (UE) may transmit a request for an on-demand secret key to a network entity, such as if a secret key for a sidelink channel has expired before a refresh timer of the secret key expires. The UE may transmit a request for an update to a secret key associated with a first physical layer channel secured for sidelink communications based on the secret key being expired. The request may include an identifier of the first physical layer channel associated with the secret key. The UE may receive the update to the secret key based transmitting the request. In some cases, the UE may transmit an indication of the update to the secret key to a second UE.

Claims (74)

1 . A method for wireless communications at a first user equipment (UE), comprising:

transmitting, to a network entity, a request for an update to a secret key associated with a first physical layer channel secured for sidelink communications between the first UE and a second UE based at least in part on the secret key being expired, the request including at least a first identifier of the first physical layer channel associated with the secret key;

receiving, from the network entity, the update to the secret key based at least in part on transmitting the request; and

transmitting, to the second UE over a sidelink channel, an indication of the update to the secret key.

2 . The method of claim 1 , wherein receiving the update to the secret key comprises:

receiving an indication of a set of secret keys from the network entity based at least in part on the request; and

selecting an updated secret key from the set of secret keys, wherein the indication of the update includes the updated secret key.

3 . The method of claim 2 , wherein selecting the updated secret key comprises:

selecting the updated secret key based at least in part on a request from the second UE for the update to the secret key.

4 . The method of claim 2 , further comprising:

receiving a configuration for the sidelink channel including time and frequency resource scheduling information and a sidelink reference signal configuration, wherein the indication of the update to the secret key is transmitted based at least in part on the configuration for the sidelink channel.

5 . The method of claim 1 , wherein receiving the update to the secret key comprises:

receiving an indication of an updated secret key from the network entity based at least in part on the request, wherein the indication of the update includes the updated secret key.

6 . The method of claim 5 , wherein the indication of the updated secret key is received via Radio Resource Control signaling, downlink shared channel signaling, downlink control information, a medium access control (MAC) control element (CE), or any combination thereof.

7 . The method of claim 1 , further comprising:

receiving, from the second UE, an initial request for the update to the secret key based at least in part on the secret key being expired, wherein the request for the update to the secret key is transmitted to the network entity based at least in part on receiving the initial request from the second UE.

8 . The method of claim 7 , wherein:

the initial request includes a request for a key refresh, a higher security secret key, or a new secret key, or any combination thereof, and

the update for the secret key includes the key refresh, the higher security secret key, or the new secret key, or any combination thereof.

9 . The method of claim 7 , wherein the initial request for the update is received from the second UE via sidelink control information, PC5 Radio Resource Control (RRC) signaling, a PC5 medium access control (MAC) control element (CE), or any combination thereof.

10 . The method of claim 1 , wherein transmitting the request for the update to the secret key comprises:

transmitting the request for a new secret key, a security level for the update to the secret key, a refresh for the secret key, or any combination thereof, wherein the update to the secret key includes the new secret key, is based at least in part on the security level, or includes the refresh for the secret key, or any combination thereof.

11 . The method of claim 1 , further comprising:

detecting a beam failure on the sidelink channel, wherein the request for the update to the secret key is transmitted based at least in part on detecting the beam failure; and

extracting the update for the secret key based at least in part on a previous secret key.

12 . The method of claim 1 , further comprising:

updating the secret key based at least in part on the update to the secret key, wherein the first identifier for the first physical layer channel corresponds to the sidelink channel; and

communicating with the second UE over the sidelink channel based at least in part on updating the secret key.

13 . The method of claim 1 , wherein transmitting the indication of the update comprises:

transmitting the indication of the update to the second UE and a third UE based at least in part on a second sidelink channel between the second UE and the third UE, wherein the first identifier for the first physical layer channel corresponds to the second sidelink channel.

14 . The method of claim 1 , wherein the request includes one or more of a resource pool identifier, a subchannel identifier, a timestamp corresponding to a latest time for transmission of the update to the secret key, one or more cryptographic properties for the update to the secret key, a cryptographic quality of service for the update to the secret key, a maximum number of uses for the update to the secret key, a maximum refresh time for the update to the secret key, or any combination thereof.

15 . A method for wireless communications at a second user equipment (UE), comprising:

transmitting a request for an update to a secret key associated with a first physical layer channel secured for sidelink communications between the second UE and another UE based at least in part on the secret key being expired and further based at least in part on detecting a beam failure on the physical layer channel;

receiving an indication of the update to the secret key based at least in part on transmitting the request; and

communicating with the other UE over the physical layer channel based at least in part on the update to the secret key.

16 . The method of claim 15 , wherein transmitting the request for the update comprises:

transmitting the request to a first UE, wherein the indication of the update to the secret key is received from the first UE.

17 . The method of claim 16 , wherein:

the request includes a request for a key refresh, a higher security secret key, or a new secret key, or any combination thereof, and

the update for the secret key includes the key refresh, the higher security secret key, or the new secret key, or any combination thereof.

18 . The method of claim 16 , wherein the request for the update for the secret key is transmitted to the first UE via sidelink control information, PC5 Radio Resource Control (RRC) signaling, a PC5 medium access control (MAC) control element (CE), or any combination thereof.

19 . The method of claim 16 , further comprising:

communicating with the other UE or a third UE over the sidelink channel based at least in part on the update to the secret key.

20 . The method of claim 15 , wherein transmitting the request for the update to the secret key comprises:

transmitting the request to a network entity, wherein the indication of the update to the secret key is received from the network entity.

21 . The method of claim 20 , wherein:

the request for the update to the secret key includes a request for a key refresh, a higher security secret key, or a new secret key, or any combination thereof, and

the update for the secret key includes the key refresh, the higher security secret key, or the new secret key, or any combination thereof.

22 . The method of claim 20 , wherein the indication of the update to the secret key is received via Radio Resource Control signaling, downlink shared channel signaling, downlink control information, a medium access control (MAC) control element (CE), or any combination thereof.

23 . The method of claim 15 , further comprising:

extracting the update for the secret key based at least in part on a previous secret key.

24 . A method for wireless communications at a network entity, comprising:

receiving, from a first user equipment (UE), a request for an update to a secret key associated with a first physical layer channel secured for sidelink communications between the first UE and a second UE, the request indicating that the secret key is expired and including at least a first identifier of the first physical layer channel associated with the secret key;

determining the update to the secret key based at least in part on the request; and

transmitting, to the first UE, an indication of the update to the secret key based at least in part on receiving the request.

25 . The method of claim 24 , further comprising:

transmitting, to an external cryptographic entity, a request message including the request received from the first UE; and

receiving, from the external cryptographic entity, an indication of the update to the secret key based at least in part on the request message.

26 . The method of claim 24 , wherein transmitting the indication of the update to the secret key comprises:

transmitting an indication of a set of secret keys to the first UE based at least in part on the request.

27 . The method of claim 26 , further comprising:

transmitting a configuration for a sidelink channel including time and frequency resource scheduling information and a sidelink reference signal configuration, wherein the update to the secret key is based at least in part on the configuration for the sidelink channel.

28 . The method of claim 24 , wherein receiving the update to the secret key comprises:

transmitting an indication of an updated secret key to the first UE based at least in part on the request, wherein the indication of the update includes the updated secret key.

29 . The method of claim 24 , further comprising:

receiving an indication of a beam failure from the first UE, wherein the request for the update to the secret key is received based at least in part on the beam failure; and

triggering resources for extracting the update for the secret key based at least in part on a previous secret key and the indication of the beam failure.

30 . A first user equipment (UE) for wireless communication, comprising:

at least one processor;

at least one memory coupled with the at least one processor; and

instructions stored in the at least one memory and executable by the at least one processor to cause the UE to:

transmit, to a network entity, a request for an update to a secret key associated with a first physical layer channel secured for sidelink communications between the first UE and a second UE based at least in part on the secret key being expired, the request including at least a first identifier of the first physical layer channel associated with the secret key;

receive, from the network entity, the update to the secret key based at least in part on transmitting the request; and

transmit, to the second UE over a sidelink channel, an indication of the update to the secret key.