Broadcast and/or groupcast security for device-to-device positioning
Disclosed are techniques for performing wireless communication. In some aspects, a wireless communication device may perform operations including generating, at a user equipment (UE), a message including information associated with positioning-reference signaling. The operations may include obtaining: a group identifier, a group key, and a group-key identifier. The operations may include deriving a traffic key based on the group key and the group identifier. The operations may include deriving an encryption key and an integrity key based on the traffic key. The operations may include generating a message header including the group identifier and the group-key identifier. The operations may include calculating a message-authentication code (MAC) using the integrity key, the message, and the message header. The operations may include encrypting the message and the MAC using the encryption key. The operations may include transmitting the message header, the encrypted message, and the encrypted MAC.
1 . An apparatus for encrypting one or more messages, the apparatus comprising:
at least one memory; and
at least one processor coupled to the at least one memory and configured to:
generate, at a first user equipment (UE), a message including information associated with positioning-reference signaling;
obtain, at the first UE, a group identifier indicative of a group to which the first UE belongs;
obtain, at the first UE, a group key and a group-key identifier associated with the group key;
obtain, at the first UE, a UE identifier indicative of the first UE;
derive, at the first UE, a traffic key based on at least one of the group key, the group identifier, or the UE identifier;
derive, at the first UE, an encryption key and an integrity key based on the traffic key;
generate, at the first UE, a message header for the message, the message header comprising at least one of the group identifier or the group-key identifier;
calculate, at the first UE, a message-authentication code (MAC) using the integrity key, the message, and the message header;
encrypt, at the first UE, the message using the encryption key to generate an encrypted message;
encrypt, at the first UE, the MAC using the encryption key to generate an encrypted MAC; and
cause a transmitter to transmit, from the first UE to a second UE, the message header, the encrypted message, and the encrypted MAC.
2 . The apparatus of claim 1 , wherein, to obtain the group identifier, the at least one processor is configured to receive the group identifier from a group management network entity.
3 . The apparatus of claim 1 , wherein, to obtain the group identifier, the first UE is pre-configured with the group identifier.
4 . The apparatus of claim 1 , wherein, to obtain the group key and the group-key identifier, the at least one processor is configured to receive, from a group management network entity, the group key and the group-key identifier.
5 . The apparatus of claim 4 , wherein:
to receive the group key and the group-key identifier, the at least one processor is configured to receive a number of group keys and a number of group-key identifiers;
the at least one processor is further configured to receive, from the group management network entity, a number of key-validity times, each of the number of key-validity times corresponding to a respective one of the number of group keys and a respective one of the number of group-key identifiers; and
each of the number of key-validity times is indicative of a time during which a respective one of the number of group keys is valid.
6 . The apparatus of claim 1 , wherein:
to obtain the UE identifier, the at least one processor is configured to receive the UE identifier from a group management network entity; and
to generate the message header, the at least one processor is configured to generate the message header including the UE identifier.
7 . The apparatus of claim 6 , wherein:
to receive the UE identifier, the at least one processor is configured to receive a number of UE identifiers;
the at least one processor is further configured to receive a respective usage configuration associated with each of the number of UE identifiers;
each respective usage configuration respectively comprises at least one of: a validity time of a respective UE identifier, a number of broadcast messages including the respective UE identifier, or location information associated with the respective UE identifier; and
to generate the message header including the UE identifier, the at least one processor is configured to generate the message header including one of the number of UE identifiers according to the usage configurations.
8 . The apparatus of claim 1 , wherein:
to obtain the UE identifier, the at least one processor is configured to generate the UE identifier by randomly selecting an identifier as the UE identifier; and
to generate the message header, the at least one processor is configured to generate the message header including the UE identifier.
9 . The apparatus of claim 1 , wherein, to obtain the UE identifier, the at least one processor is configured to select a Layer-2 identifier of the first UE as the UE identifier.
10 . The apparatus of claim 1 , wherein the UE identifier comprises a group-member identifier identifying the first UE within the group.
11 . The apparatus of claim 1 , wherein:
the at least one processor is further configured to generate, based on a counter value, a traffic-key identifier associated with the traffic key;
to derive the traffic key, the at least one processor is configured to derive the traffic key further based on the traffic-key identifier, and
to generate the message header, the at least one processor is configured to generate the message header including the traffic-key identifier.
12 . The apparatus of claim 11 , wherein, to generate the traffic-key identifier, the at least one processor is configured to generate the traffic-key identifier such that a combination of the traffic-key identifier and the group-key identifier is unique.
13 . The apparatus of claim 1 , wherein:
the at least one processor is further configured to receive, from a group management network entity, an algorithm identifier, indicative of an encryption algorithm; and
to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.
14 . The apparatus of claim 1 , wherein:
the at least one processor is further configured to receive, from a group management network entity, an algorithm identifier, indicative of an integrity algorithm; and
to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.
15 . The apparatus of claim 1 , wherein:
to calculate the MAC, the at least one processor is configured to calculate the MAC further based on a counter value; and
to generate the message header, the at least one processor is configured to generate the message header further including at least a part of the counter value.
16 . The apparatus of claim 1 , wherein:
the at least one processor is further configured to generate a traffic-key identifier indicative of the traffic key;
to calculate the MAC, the at least one processor is configured to calculate the MAC further based on a counter value and the traffic-key identifier, and
to encrypt the message and to encrypt the MAC, the at least one processor is configured to encrypt the message and encrypt the MAC further based on the counter value and traffic-key identifier.
17 . The apparatus of claim 1 , wherein the information associated with the positioning-reference signaling comprises at least one of: participant information indicating one or more intended recipients of a positioning reference signal (PRS), session information associated with communications between the first UE and the one or more intended recipients, PRS measurements indicative of a signal strength of a received PRS, location information associated with a location of the first UE, or motion information associated with motion of the first UE.
18 . An apparatus for processing one or more packets, the apparatus comprising:
at least one memory; and
at least one processor coupled to the at least one memory and configured to:
receive, at a first user equipment (UE) from a second UE, a packet including an encrypted message including information associated with positioning-reference signaling, an encrypted message-authentication code (MAC), and a message header, the message header comprising: a group identifier indicative of a group to which the second UE belongs, and a group-key identifier indicative of a group key;
obtain, at the first UE, a group identifier indicative that the first UE also belongs to the group to which the second UE belongs;
obtain, at the first UE, the group key and the group-key identifier;
derive, at the first UE, a traffic key based on the group key;
derive, at the first UE, an encryption key and an integrity key based on the traffic key;
decrypt, at the first UE, the encrypted message using the encryption key to generate a decrypted message;
decrypt, at the first UE, the encrypted MAC using the encryption key to generate a decrypted MAC;
calculate, at the first UE, an expected MAC based on the integrity key; and
verify, at the first UE, integrity of the decrypted message by comparing the decrypted MAC with the expected MAC.
19 . The apparatus of claim 18 , wherein to obtain the group identifier the at least one processor is configured to receive the group identifier from a group management network entity.
20 . The apparatus of claim 18 , wherein, to obtain the group identifier, the at least one processor is configured to configure the first UE with the group identifier.
21 . The apparatus of claim 18 , wherein, to obtain the group key and the group-key identifier, the at least one processor is configured to receive, from a group management network entity, the group key and the group-key identifier associated with the group key.
22 . The apparatus of claim 18 , wherein:
the message header further comprises a UE identifier indicative of the second UE, a traffic-key identifier indicative of the traffic key, and a counter; and
to derive the traffic key, the at least one processor is configured to derive the traffic key further based on the group identifier, the UE identifier, and the traffic-key identifier.
23 . The apparatus of claim 22 , wherein the UE identifier comprises a group-member identifier identifying the second UE within the group.
24 . The apparatus of claim 18 , wherein:
the at least one processor is further configured to receive, from a group management network entity, an encryption algorithm identifier indicative of an encryption algorithm; and
to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.
25 . The apparatus of claim 18 , wherein:
the message header further comprises an encryption algorithm identifier indicative an encryption algorithm; and
to derive the encryption key, the at least one processor is configured to derive the encryption key further based on the encryption algorithm.
26 . The apparatus of claim 18 , wherein:
the at least one processor is further configured to receive, from a group management network entity, an integrity algorithm identifier indicative of an integrity algorithm; and
to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.
27 . The apparatus of claim 18 , wherein:
the message header further comprises an integrity algorithm identifier indicative an integrity algorithm; and
to derive the integrity key, the at least one processor is configured to derive the integrity key further based on the integrity algorithm.
28 . The apparatus of claim 18 , wherein:
the message header further comprises a traffic-key identifier indicative of the traffic key and a counter;
to decrypt the encrypted message, the at least one processor is configured to decrypt the encrypted message further using the traffic-key identifier and the counter; and
to decrypt the encrypted MAC further, the at least one processor is configured to decrypt the encrypted MAC further using the traffic-key identifier and the counter.
29 . The apparatus of claim 18 , wherein, to calculate the expected MAC, the at least one processor is configured to calculate the expected MAC further based on a traffic-key identifier indicative of the traffic key and a counter value.
30 . The apparatus of claim 18 , wherein the information associated with the positioning-reference signaling comprises at least one of: participant information indicating one or more intended recipients of a positioning reference signal (PRS), session information associated with communications between the second UE and the one or more intended recipients, PRS measurements indicative of a signal strength of a received PRS, location information associate with a location of the second UE, or motion information associated with motion of the second UE.