IP Library › Granted Patent US 12,382,294
Granted Patent B2
US 12,382,294 · App. 17/491,371 · Granted Aug 5, 2025

Secure communication link establishment for a UE-to-UE relay

Inventors: Soo Bum Lee (San Diego, CA); Adrian Edward Escott (Reading, GB); Anand Palanigounder (San Diego, CA)
Assignee: QUALCOMM Incorporated
H04W12/50H04W8/005H04W12/0431H04W12/0433H04W76/14H04W92/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,382,294
App. No.
17/491,371
Granted
Aug 5, 2025
Kind
B2
Abstract

Aspects relate to user equipment (UE) to user equipment (UE-to-UE) relaying in a communication system. At least two remote UEs and a UE-to-UE relay receive provisioned security information from the wireless communication network, where the security information includes discovery parameters and relay security information. The security information provisioned by the wireless communication network is used to establish a connection between the two UEs and the UE-to-UE relay device including discovery of the UE-to-UE relay by the remote UEs. Furthermore, the provisioned security information is used to establish a secure connection between the two remote UEs via the UE-to-UE relay device.

Claims (68)

1. A method for wireless communication at a first user equipment (UE) in a wireless communication network, comprising:

receiving discovery parameters for discovery of a user equipment (UE-to-UE) relay device and a proximity-based services (ProSe) key management function (PKMF) address from a direct discovery name management function (DDNMF) implemented by the wireless communication network;

receiving, from the PKMF, relay security information for establishment of a first secure connection between the first UE and the UE-to-UE relay device, the relay security information including a relay service code (RSC);

receiving, from the PKMF, second security information for establishment of a second secure connection between the first UE and a second UE via the UE-to-UE relay device, the second security information including a ProSe Service Code (PSC);

discovering the UE-to-UE relay device using the received discovery parameters;

establishing the first secure connection with the UE-to-UE relay device using the received relay security information including the RSC, the first secure connection comprising a first PC5 link between the first UE and the UE-to-UE-relay device; and

establishing the second secure connection between the first UE and the second UE via the UE-to-UE relay device using an internet key exchange (IKE) version two (IKEv2) authentication process based on the received second security information including the PSC, the second secure connection being established via the first PC5 link between the first UE and the UE-to-UE-relay device and a second PC5 link between the second UE and the UE-to-UE-relay device.

2. The method of claim 1 , wherein the relay security information further comprises at least one of one or more service identifiers, one or more keys associated with each service identifier, or one or more certificates.

3. The method of claim 2 , wherein the one or more service identifiers comprise an identifier associated with the second UE.

4. The method of claim 3 , wherein the identifier associated with the second UE is a Fully Qualified Domain Name (FQDN).

5. The method of claim 1 , wherein the first UE uses the PSC as a key identifier (ID) to establish the second secure connection using an IKEv2pre-shared key (PSK) authentication process.

6. The method of claim 2 , wherein the first UE uses the PSC to identify the one or more certificates to verify a certificate of the second UE.

7. The method of claim 2 , further comprising:

receiving an association between the one or more certificates and the PSC from the wireless communication network; and

establishing the second secure connection between the first UE and the second UE using an IKEv2 certificate authentication process based on the one or more certificates associated with the PSC.

8. The method of claim 2 , wherein the one or more service identifiers comprises the RCS.

9. The method of claim 2 , wherein the one or more certificates are certificate authority (CA) certificates.

10. The method of claim 1 , wherein the UE-to-UE relay device comprises a third user equipment (UE).

11. The method of claim 1 , further comprising:

sending a direct communication request to the UE-to-UE relay device based on the discovery of the UE-to-UE relay device;

receiving a direct security mode command from the UE-to-UE relay device; and

establishing a direct security mode communication with the UE-to-UE relay device in response to the direct security mode command.

12. The method of claim 11 , further comprising:

performing an authentication and key agreement process between the first UE and UE-to-UE relay device prior to establishing the direct security mode communication.

13. A first user equipment (UE), comprising:

a wireless transceiver;

a memory storing executable code; and

one or more processors configured to execute the executable code to cause the first UE to:

receive discovery parameters for discovery of a user equipment (UE-to-UE) relay device and a proximity-based services (ProSe) key management function (PKMF) address from a direct discovery name management function (DDNMF) implemented by a wireless communication network;

receive, from the PKMF, relay security information for establishment of a first secure connection between the first UE and the UE-to-UE relay device, the relay security information including a relay service code (RSC);

receive, from the PKMF, second security information for establishment of a second secure connection between the first UE and a second UE via the UE-to-UE relay device, the second security information including a ProSe Service Code (PSC);

discover the UE-to-UE relay device using the received discovery parameters;

establish the first secure connection with the UE-to-UE relay device using the received relay security information including the RSC, the first secure connection comprising a first PC5 link between the first UE and the UE-to-UE-relay device; and

establish the second secure connection between the first UE and the second UE via the UE-to-UE relay device using an internet key exchange (IKE) version two (IKEv2) authentication process based on the received second security information including the PSC, the second secure connection being established via the first PC5 link between the first UE and the UE-to-UE-relay device and a second PC5 link between the second UE and the UE-to-UE-relay device.

14. A method for wireless communication in a user equipment (UE) to UE (UE-to-UE) relay in a wireless communication network, comprising:

receiving discovery parameters and a proximity-based services (ProSe) key management function (PKMF) address from a direct discovery name management function (DDNMF) implemented by the wireless communication network;

receiving, from the PKMF, relay security information for establishment of a first secure connection between a first UE and the UE-to-UE relay and a second secure connection between a second UE and the UE-to-UE relay, the relay security information including a relay service code (RSC);

receiving, from the PKMF, second security information for establishment of a third secure connection between the first UE and the second UE via the UE-to-UE relay, the second security information including a ProSe Service Code (PSC);

establishing the first secure connection between the first UE and the UE-to-UE-relay based on the received relay security information including the RSC, the first secure connection comprising a first PC5 link between the first UE and the UE-to-UE-relay;

establishing the second secure connection between the second UE and the UE-to-UE-relay device based on the received relay security information including the RSC, the second secure connection comprising a second PC5 link between the second UE and the UE-to-UE-relay; and

establishing a third secure connection between the first UE and the second UE based on the received second security information including the PSC, the third secure connection being via the first PC5 link between the first UE and the UE-to-UE-relay and the second PC5 link between the second UE and the UE-to-UE-relay-device.

15. The method of claim 14 , wherein the relay security information further comprises a service identifier and an associated key.

16. The method of claim 15 , wherein the service identifier is an identifier associated with a service between the first UE and the second UE.

17. The method of claim 16 , wherein the identifier associated with the service between the first UE and the second UE comprises a Fully Qualified Domain Name (FQDN).

18. The method of claim 15 , wherein the service identifier is comprises the RSC.

19. The method of claim 14 , wherein the UE-to-UE relay comprises a third user equipment (UE).

20. The method of claim 14 , further comprising:

receiving a direct communication request from at least one UE of the first UE and the second UE;

sending a direct security mode command to the at least one UE;

receiving a direct security mode completion message from the at least one UE; and

establishing a direct security mode communication with the at least one UE.

21. The method of claim 20 , further comprising:

performing an authentication and key agreement process between the at least one UE and the UE-to-UE relay prior to establishing the direct security mode communication.

22. A user equipment (UE) to UE (UE-to-UE) relay, comprising:

a wireless transceiver;

a memory storing executable code; and

one or more processors configured to execute the executable code to cause the UE-to-UE relay to:

receive discovery parameters and a proximity-based services (ProSe) key management function (PKMF) address from a direct discovery name management function (DDNMF) implemented by a wireless communication network;

receive, from the PKMF, relay security information for establishment of a first secure connection between a first UE and the UE-to-UE relay and a second secure connection between a second UE and the UE-to-UE relay, the relay security information including a relay service code (RSC);

receive, from the PKMF, second security information for establishment of a third secure connection between the first UE and the second UE via the UE-to-UE relay, the second security information including a ProSe Service Code (PSC);

establish the first secure connection between the first UE and the UE-to-UE-relay based on the received relay security information including the RSC, the first secure connection comprising a first PC5 link between the first UE and the UE-to-UE-relay;

establish the second secure connection between the second UE and the UE-to-UE-relay device based on the received relay security information including the RSC, the second secure connection comprising a second PC5 link between the second UE and the UE-to-UE-relay; and

establish a third secure connection between the first UE and the second UE based on the received second security information including the PSC, the third secure connection being via the first PC5 link between the first UE and the UE-to-UE-relay and the second PC5 link between the second UE and the UE-to-UE-relay.

23. The UE-to-UE relay of claim 22 , wherein the one or more processors are configured to execute the executable code to cause the UE-to-UE relay to:

receive a direct communication request from at least one UE of the first UE and the second UE;

send a direct security mode command to the at least one UE;

receive a direct security mode completion message from the at least one UE; and

establish a direct security mode communication with the at least one UE.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2021
From: LEE, SOO BUM; ESCOTT, ADRIAN EDWARD; PALANIGOUNDER, ANAND
To: QUALCOMM INCORPORATED
Reel/Frame 058076/0237 →
Continuity (2)
Provisional Application 63086560 · Oct 1, 2020
Related Publication 20220109996A1 · Apr 7, 2022
References Cited (42)
US 10021570B1 · Cai · 2018 [cited by examiner]
US 10534932B2 · Wang · 2020 [cited by examiner]
US 11924184B2 · Guo · 2024 [cited by examiner]
US 20130138822A1 · Hu · 2013 [cited by examiner]
US 20140337935A1 · Liu · 2014 [cited by examiner]
US 20160029213A1 · Rajadurai · 2016 [cited by examiner]
US 20160135016A1 · Zou · 2016 [cited by examiner]
US 20160155327A1 · Schlienz · 2016 [cited by examiner]
US 20160205532A1 · Chen · 2016 [cited by examiner]
US 20160205555A1 · Agiwal · 2016 [cited by examiner]
US 20160295496A1 · Atarius · 2016 [cited by examiner]
US 20170041366A1 · Dowlatkhah · 2017 [cited by examiner]
US 20170041768A1 · Pattan · 2017 [cited by examiner]
US 20170055149A1 · Lehtovirta · 2017 [cited by examiner]
US 20170118637A1 · Peng · 2017 [cited by examiner]
US 20170295531A1 · Singh · 2017 [cited by examiner]
US 20170359766A1 · Agiwal · 2017 [cited by examiner]
US 20180007612A1 · Jahangir · 2018 [cited by examiner]
US 20180234862A1 · Lee · 2018 [cited by examiner]
US 20190239147A1 · Chun · 2019 [cited by examiner]
US 20210368581A1 · Shan · 2021 [cited by examiner]
US 20210410215A1 · Kuo · 2021 [cited by examiner]
US 20230082590A1 · Peng · 2023 [cited by examiner]
US 20230254692A1 · Kim · 2023 [cited by examiner]
US 20230269802A1 · Fu · 2023 [cited by examiner]
EP 1881664A1 · 2008 [cited by examiner]
JP 7010227B2 · 2022 [cited by examiner]
KR 20210028549A · 2021 [cited by examiner]
WO WO2016116704A1 · 2016 [cited by examiner]
WO WO2019134868A1 · 2019 [cited by applicant]
WO WO2022032506A1 · 2022 [cited by examiner]
WO WO2022034540A1 · 2022 [cited by examiner]
Panton, Tim, David Llewellyn-Jones, Nathan Shone, and Mahmoud Hashem Eiza. “Secure proximity-based identity pairing using an untrusted signalling service.” In 2016 13th IEEE Annual Consumer Communications & Networking C… [cited by examiner]
Alam, Muhammad, Du Yang, Jonathan Rodriguez, and Raed A. Abd-Alhameed. “Secure device-to-device communication in LTE-A.” IEEE Communications Magazine 52, No. 4 (2014): 66-73. (Year: 2014). [cited by examiner]
ETSI, TS. “123 287: V16. 3.0 (Jul. 2020). 5G.” Architecture enhancements for 5G System (5GS) to support Vehicle-to-Everything (V2X) services (3GPP TS 23.287 version 16.3. 0 Release 16). (Year: 2020). [cited by examiner]
Kozioł, Dawid, Fernando Sanchez Moya, Ling Yu, Vinh Van Phan, and Steven Xu. “QoS and service continuity in 3GPP D2D for IoT and wearables.” In 2017 IEEE Conference on Standards for Communications and Networking (CSCN),… [cited by examiner]
Conceição, Filipe, Nouha Oualha, and Djamal Zeghlache. “Real-Time Dynamic Security for ProSe in 5G.” In 2019 2nd International Conference on Signal Processing and Information Security (ICSPIS), pp. 1-4. IEEE, 2019. (Yea… [cited by examiner]
Raghothaman, Balaji, Eric Deng, Ravikumar Pragada, Gregory Sternberg, Tao Deng, and Kiran Vanganuru. “Architecture and protocols for LTE-based device to device communication.” In 2013 International Conference on Computi… [cited by examiner]
“3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Procedures for the SG System (SGS), Stage 2 (Release 16) ”, 3GPP Draft, 23502-G60, 3rd Generation Partnership Project (3GPP… [cited by applicant]
“3rd Generation Partnership Project, Technical Specification Group Services and System Aspects, Study on System Enhancement for Proximity Based Services (ProSe) in the 5G System (5GS) (Release 17)”, 3GPP Draft, 23752-05… [cited by applicant]
International Search Report and Written Opinion—PCT/US2021/053249—ISA/EPO—Jan. 25, 2022. [cited by applicant]
“Universal Mobile Telecommunications System (UMTS), LTE, Proximity-Based Services (ProSe), Security aspects (3GPP TS 33.303 Version 16.0.0 Release 16)”, ETSI Technical Specification, European Telecommunications Standard… [cited by applicant]