MLchartDataset catalogue

Patent · US2026107145A1 · A1 · US

Method and device for authorizing role of user equipment

(11) Publication number
US2026107145A1
(21) Application number
19/114,581
(22) Filing date
2022-09-26
(30) Priority date
2022-09-26
(43) Publication date
2026-04-16
(51) IPC
H04W 12/08; H04W 64/00; H04W 92/18
(52) CPC
  • H04W Wireless communication networks: 12/08, 64/00, 92/18
(73) Assignee
Beijing Xiaomi Mobile Software Co Ltd
(72) Inventors
Wei Lu
(54) Title
Method and device for authorizing role of user equipment
(57) Abstract

A method for authorizing a role of a user equipment (UE) is performed by a network device, and includes: receiving a discovery request message sent by a first UE or a second UE, wherein the discovery request message includes at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE or the second UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and sending a discovery response message to the first UE or the second UE.

Full text
View on Google Patents

Claims (1)

  1. A method for authorizing a role of a user equipment (UE), performed by a network device, comprising: receiving a discovery request message sent by a first UE or a second UE, wherein the discovery request message comprises at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE or the second UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and sending a discovery response message to the first UE or the second UE. 2. (canceled) 3. The method according to claim 1, further comprising: determining a role of the first UE or the second UE according to a capability of the first UE or the second UE and contract information of the first UE or the second UE stored in the network device. 4. The method according to claim 1, wherein the discovery response message comprises security material, generated by the network device, for the first UE or the second UE, wherein security material corresponding to the first UE is the same as security material corresponding to the second UE. 5. The method according to claim 1, wherein the service comprises at least one of a ranging service or a sidelink positioning service. 6. (canceled) 7. The method according to claim 1, wherein the network device comprises: a first network element, and a third network element, wherein the first network element comprises a direct discovery name management function (DDNMF) network element of the first UE or a proximity service key management function (PKMF) network element of the first UE, and the third network element comprises a proximity service server or a unified data management (UDM) network element, wherein receiving, by the network device, the discovery request message sent by the first UE comprises: receiving, by the first network element, the discovery request message sent by the first UE; sending, by the network device, the discovery response message to the first UE comprises: sending, by the first network element, the discovery response message to the first UE; and the method further comprises: sending, by the first network element, a first authorization request message to the third network element, and sending, by the third network element, a first authorization response message to the first network element, wherein the first authorization response message comprises a role of the first UE determined by the third network element. 8. The method according to claim 1, wherein the network device comprises: a second network element and a third network element, wherein the second network element comprises a DDNMF network element of the second UE or a PKMF network element of the second UE, and the third network element comprises a proximity service server or a UDM network element, wherein receiving, by the network device, the discovery request message sent by the second UE comprises: receiving, by the second network element, the discovery request message sent by the second UE; sending, by the network device, the discovery response message to the second UE comprises: sending, by the second network element, the discovery response message to the second UE; and the method further comprises: sending, by the second network element, a first authorization request message to the third network element, and sending, by the third network element, a first authorization response message to the second network element, wherein the first authorization response message comprises a role of the second UE determined by the third network element. 9. The method according to claim 8, wherein the network device further comprises: a first network element comprising a DDNMF network element of the first UE or a PKMF network element of the first UE, the method further comprising: sending, by the second network element, a monitor request message to the first network element, wherein the monitor request message comprises the role of the second UE, and the monitor request message is used to request to determine whether the role of the second UE is matched with a role of the first UE; sending, by the first network element, a second authorization request message to the third network element, wherein the second authorization request message comprises the role of the first UE and the role of the second UE; and determining, by the third network element, whether the role of the second UE is matched with the role of the first UE, and sending, by the third network element, a second authorization response message to the first network element, wherein the second authorization response message is used to indicate whether the role of the first UE is matched with the role of the second UE in a service requested to be discovered by the two UEs; and sending, from the first network element to the second network element, security material generated corresponding to the second UE in response to the role of the first UE being matched with the role of the second UE. 10. A method for authorizing a role of a user equipment (UE), performed by a first UE or a second UE, comprising: sending a discovery request message to a network device, wherein the discovery request message comprises at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and receiving a discovery response message sent by the network device. 11. The method according to claim 10, further comprising: broadcasting, by the first UE, a first discovery message, wherein the first discovery message is protected by security material corresponding to the first UE, and the first discovery message comprises a role of the first UE. 12. The method according to claim 10, further comprising: receiving, by the first UE, a second discovery message broadcast by the second UE, wherein the second discovery message is protected by security material corresponding to the second UE, and the second discovery message comprises a role of the second UE; decoding and verifying, by the first UE, the second discovery message, and determining, by the first UE, whether the role of the second UE is matched with the role of the first UE in response to a successful verification; and sending, by the first UE, a first response message to the second UE in response to the role of the first UE being matched with the role of the second UE, wherein the first response message is protected by security material corresponding to the first UE, and the first response message comprises the role of the first UE. 13. (canceled) 14. The method according to claim 10, further comprising at least one of: receiving, by the second UE, a first discovery message broadcast by a first UE, wherein the first discovery message is protected by security material corresponding to the first UE, and the first discovery message comprises a role of the first UE, and decoding and verifying, by the second UE, the first discovery message, and determining, by the second UE, whether a role of the second UE is matched with the role of the first UE in response to a successful verification; or broadcasting, by the second UE, a second discovery message, wherein the second discovery message is protected by security material corresponding to the second UE, and the second discovery message comprises the role of the second UE, and receiving, by the second UE, a first response message sent by the first UE, wherein the first response message is protected by security material corresponding to the first UE, and the first response message comprises a role of the first UE. 15. (canceled) 16. (canceled) 17. The method according to claim 7, further comprising: sending, by the first network element, the first authorization request message to the server or the UDM network element according to the discovery request message, wherein the sending comprises: converting, by the first network element, a ranging application user identifier (RAUID) corresponding to the first UE into a first identifier recognizable by the server or the UDM network element, wherein the first identifier is used to indicate the first UE; and sending, by the first network element, the first authorization request message containing at least one of the first identifier, the service requested to be discovered by the first UE, or a capability of the first UE to the server or the UDM network element. 18. The method of claim 1, wherein the network device comprises: a direct discovery name management function (DDNMF) network element or a proximity service key management function (PKMF) network element of the second UE, the method further comprising: receiving, by the DDNMF network element or the PKMF network element of the second UE, a discovery request message sent by the second UE, wherein the discovery request message is used to request an authorized role for a service requested to be discovered by the second UE; sending, by the DDNMF network element or the PKMF network element of the second UE, a first authorization request message to a server or a unified data management (UDM) network element according to the discovery request message; receiving, by the DDNMF network element or the PKMF network element of the second UE, a first authorization response message sent by the server or the UDM network element, wherein the first authorization response message comprises a role of the second UE determined by the server or the UDM network element; determining, by the DDNMF network element or the PKMF network element of the second UE, security material corresponding to the second UE; and sending, by the DDNMF network element or the PKMF network element of the second UE, a discovery response message to the second UE. 19. The method according to claim 18, wherein sending, by the DDNMF network element or the PKMF network element of the second UE, the first authorization request message to the server or the UDM network element according to the discovery request message comprises: converting, by the DDNMF network element or the PKMF network element of the second UE, a ranging application user identifier (RAUID) corresponding to the second UE into a second identifier recognizable by the server or the UDM network element, wherein the second identifier is used to indicate the second UE; and sending, by the DDNMF network element or the PKMF network element of the second UE, the authorization request message containing at least one of the second identifier, the service requested to be discovered by the second UE, or a capability of the second UE to the server or the UDM network element. 20. The method according to claim 18, further comprising: sending, by the DDNMF network element or the PKMF network element of the second UE, a monitoring request message to a DDNMF network element or a PKMF network element of the first UE, wherein the monitoring request message contains the role of the second UE, the monitoring request message is used to request to determine whether the role of the second UE is matched with a role of the first UE; and receiving, by the DDNMF network element or the PKMF network element of the second UE, a monitoring response message sent by the DDNMF network element or the PKMF network element of the first UE, wherein the monitoring response message contains the security material corresponding to the second UE, wherein the security material corresponding to the second UE is the same as security material corresponding to the first UE. 21. The method of claim 1, wherein the network device comprises: a server or a unified data management (UDM), the method further comprising: receiving, by the server or the UDM, a first authorization request message sent by a direct discovery name management function (DDNMF) network element or a proximity service key management function (PKMF) network element of the first UE or the second UE, wherein the first authorization request message is used to request an authorized role for a service requested to be discovered by the first UE or the second UE; determining, by the server or the UDM, a role of the first UE or the second UE according to the first authorization request message; and sending, by the server or the UDM, a first authorization response message to the DDNMF network element or the PKMF network element of the first UE or the second UE, wherein the first authorization response message comprises the role of the first UE or the second UE. 22. The method according to claim 21, wherein determining, by the server or the UDM, the role of the first UE or the second UE according to the first authorization request message comprises: determining, by the server or the UDM according to contract information of the first or the second UE, a role allowed for the first UE or the second UE in the service requested to be discovered by the first UE or the second UE; and determining, by the server or the UDM, among the role allowed for the first UE or the second UE, a role supported by a capability of the first UE or the second UE as the role of the first UE or the second UE. 23. The method according to claim 21, further comprising: receiving, by the server or the UDM, a second authorization request message sent by the DDNMF network element or the PKMF network element of the first UE, wherein the second authorization request message comprises the role of the first UE, the role of the second UE, and the service requested to be discovered by the two UEs; determining, by the server or the UDM, whether the role of the first UE is matched with the role of the second UE in the service requested to be discovered by the two UEs; and sending, by the server or the UDM, a second authorization response message to the DDNMF network element or the PKMF network element of the first UE, wherein the second authorization response message is used to indicate whether the role of the first UE is matched with the role of the second UE. 24.- 29. (canceled) 30. A network device, comprising: a processor; and a memory storing a computer program executable by the processor, wherein the processor is configured to: receive a discovery request message sent by a first UE or a second UE, wherein the discovery request message comprises at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE or the second UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and send a discovery response message to the first UE or the second UE. 31.- 33. (canceled) 34. A user equipment (UE), comprising: a processor; and a memory storing a computer program executable by the processor, wherein the processor is configured to perform the method according to claim 10.

Description

The present disclosure generally relates to the field of communication technology, and more particularly, to a method/apparatus/device for authorizing a role of a UE and a storage medium.

In a communication system, when performing a ranging service and/or a sidelink (SL) positioning service, multiple user equipment (UE) are usually required to play different roles to participate in completing the service, where the UE roles may include an SL reference UE, a target UE, an assistant UE, a located UE, a sidelink positioning server UE, and an SL positioning client UE.

One UE may simultaneously support multiple roles for the ranging service and/or the sidelink positioning service. For example, if a UE has an ability of sending a location signal, it may be used as a reference UE. If the UE further has an ability of calculating a location, it may be used as a server UE. In a practice scenario, it may happen that the UE plays an inappropriate role in a service, that is, the UE is not allowed or capable to play the role in the service. For example, a UE has a ranging capability, but it is not allowed to play the role of the reference UE in ranging service 1. When it plays the role of the reference UE in ranging service 1, an accuracy of the ranging service may be affected and unsafe problem such as information leakage may be caused.

Record as JSON
{
  "publication_number": "US2026107145A1",
  "country": "US",
  "kind": "A1",
  "title": "Method and device for authorizing role of user equipment",
  "abstract": "A method for authorizing a role of a user equipment (UE) is performed by a network device, and includes: receiving a discovery request message sent by a first UE or a second UE, wherein the discovery request message includes at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE or the second UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and sending a discovery response message to the first UE or the second UE.",
  "claims": [
    "1. A method for authorizing a role of a user equipment (UE), performed by a network device, comprising: receiving a discovery request message sent by a first UE or a second UE, wherein the discovery request message comprises at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE or the second UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and sending a discovery response message to the first UE or the second UE. 2. (canceled) 3. The method according to claim 1, further comprising: determining a role of the first UE or the second UE according to a capability of the first UE or the second UE and contract information of the first UE or the second UE stored in the network device. 4. The method according to claim 1, wherein the discovery response message comprises security material, generated by the network device, for the first UE or the second UE, wherein security material corresponding to the first UE is the same as security material corresponding to the second UE. 5. The method according to claim 1, wherein the service comprises at least one of a ranging service or a sidelink positioning service. 6. (canceled) 7. The method according to claim 1, wherein the network device comprises: a first network element, and a third network element, wherein the first network element comprises a direct discovery name management function (DDNMF) network element of the first UE or a proximity service key management function (PKMF) network element of the first UE, and the third network element comprises a proximity service server or a unified data management (UDM) network element, wherein receiving, by the network device, the discovery request message sent by the first UE comprises: receiving, by the first network element, the discovery request message sent by the first UE; sending, by the network device, the discovery response message to the first UE comprises: sending, by the first network element, the discovery response message to the first UE; and the method further comprises: sending, by the first network element, a first authorization request message to the third network element, and sending, by the third network element, a first authorization response message to the first network element, wherein the first authorization response message comprises a role of the first UE determined by the third network element. 8. The method according to claim 1, wherein the network device comprises: a second network element and a third network element, wherein the second network element comprises a DDNMF network element of the second UE or a PKMF network element of the second UE, and the third network element comprises a proximity service server or a UDM network element, wherein receiving, by the network device, the discovery request message sent by the second UE comprises: receiving, by the second network element, the discovery request message sent by the second UE; sending, by the network device, the discovery response message to the second UE comprises: sending, by the second network element, the discovery response message to the second UE; and the method further comprises: sending, by the second network element, a first authorization request message to the third network element, and sending, by the third network element, a first authorization response message to the second network element, wherein the first authorization response message comprises a role of the second UE determined by the third network element. 9. The method according to claim 8, wherein the network device further comprises: a first network element comprising a DDNMF network element of the first UE or a PKMF network element of the first UE, the method further comprising: sending, by the second network element, a monitor request message to the first network element, wherein the monitor request message comprises the role of the second UE, and the monitor request message is used to request to determine whether the role of the second UE is matched with a role of the first UE; sending, by the first network element, a second authorization request message to the third network element, wherein the second authorization request message comprises the role of the first UE and the role of the second UE; and determining, by the third network element, whether the role of the second UE is matched with the role of the first UE, and sending, by the third network element, a second authorization response message to the first network element, wherein the second authorization response message is used to indicate whether the role of the first UE is matched with the role of the second UE in a service requested to be discovered by the two UEs; and sending, from the first network element to the second network element, security material generated corresponding to the second UE in response to the role of the first UE being matched with the role of the second UE. 10. A method for authorizing a role of a user equipment (UE), performed by a first UE or a second UE, comprising: sending a discovery request message to a network device, wherein the discovery request message comprises at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and receiving a discovery response message sent by the network device. 11. The method according to claim 10, further comprising: broadcasting, by the first UE, a first discovery message, wherein the first discovery message is protected by security material corresponding to the first UE, and the first discovery message comprises a role of the first UE. 12. The method according to claim 10, further comprising: receiving, by the first UE, a second discovery message broadcast by the second UE, wherein the second discovery message is protected by security material corresponding to the second UE, and the second discovery message comprises a role of the second UE; decoding and verifying, by the first UE, the second discovery message, and determining, by the first UE, whether the role of the second UE is matched with the role of the first UE in response to a successful verification; and sending, by the first UE, a first response message to the second UE in response to the role of the first UE being matched with the role of the second UE, wherein the first response message is protected by security material corresponding to the first UE, and the first response message comprises the role of the first UE. 13. (canceled) 14. The method according to claim 10, further comprising at least one of: receiving, by the second UE, a first discovery message broadcast by a first UE, wherein the first discovery message is protected by security material corresponding to the first UE, and the first discovery message comprises a role of the first UE, and decoding and verifying, by the second UE, the first discovery message, and determining, by the second UE, whether a role of the second UE is matched with the role of the first UE in response to a successful verification; or broadcasting, by the second UE, a second discovery message, wherein the second discovery message is protected by security material corresponding to the second UE, and the second discovery message comprises the role of the second UE, and receiving, by the second UE, a first response message sent by the first UE, wherein the first response message is protected by security material corresponding to the first UE, and the first response message comprises a role of the first UE. 15. (canceled) 16. (canceled) 17. The method according to claim 7, further comprising: sending, by the first network element, the first authorization request message to the server or the UDM network element according to the discovery request message, wherein the sending comprises: converting, by the first network element, a ranging application user identifier (RAUID) corresponding to the first UE into a first identifier recognizable by the server or the UDM network element, wherein the first identifier is used to indicate the first UE; and sending, by the first network element, the first authorization request message containing at least one of the first identifier, the service requested to be discovered by the first UE, or a capability of the first UE to the server or the UDM network element. 18. The method of claim 1, wherein the network device comprises: a direct discovery name management function (DDNMF) network element or a proximity service key management function (PKMF) network element of the second UE, the method further comprising: receiving, by the DDNMF network element or the PKMF network element of the second UE, a discovery request message sent by the second UE, wherein the discovery request message is used to request an authorized role for a service requested to be discovered by the second UE; sending, by the DDNMF network element or the PKMF network element of the second UE, a first authorization request message to a server or a unified data management (UDM) network element according to the discovery request message; receiving, by the DDNMF network element or the PKMF network element of the second UE, a first authorization response message sent by the server or the UDM network element, wherein the first authorization response message comprises a role of the second UE determined by the server or the UDM network element; determining, by the DDNMF network element or the PKMF network element of the second UE, security material corresponding to the second UE; and sending, by the DDNMF network element or the PKMF network element of the second UE, a discovery response message to the second UE. 19. The method according to claim 18, wherein sending, by the DDNMF network element or the PKMF network element of the second UE, the first authorization request message to the server or the UDM network element according to the discovery request message comprises: converting, by the DDNMF network element or the PKMF network element of the second UE, a ranging application user identifier (RAUID) corresponding to the second UE into a second identifier recognizable by the server or the UDM network element, wherein the second identifier is used to indicate the second UE; and sending, by the DDNMF network element or the PKMF network element of the second UE, the authorization request message containing at least one of the second identifier, the service requested to be discovered by the second UE, or a capability of the second UE to the server or the UDM network element. 20. The method according to claim 18, further comprising: sending, by the DDNMF network element or the PKMF network element of the second UE, a monitoring request message to a DDNMF network element or a PKMF network element of the first UE, wherein the monitoring request message contains the role of the second UE, the monitoring request message is used to request to determine whether the role of the second UE is matched with a role of the first UE; and receiving, by the DDNMF network element or the PKMF network element of the second UE, a monitoring response message sent by the DDNMF network element or the PKMF network element of the first UE, wherein the monitoring response message contains the security material corresponding to the second UE, wherein the security material corresponding to the second UE is the same as security material corresponding to the first UE. 21. The method of claim 1, wherein the network device comprises: a server or a unified data management (UDM), the method further comprising: receiving, by the server or the UDM, a first authorization request message sent by a direct discovery name management function (DDNMF) network element or a proximity service key management function (PKMF) network element of the first UE or the second UE, wherein the first authorization request message is used to request an authorized role for a service requested to be discovered by the first UE or the second UE; determining, by the server or the UDM, a role of the first UE or the second UE according to the first authorization request message; and sending, by the server or the UDM, a first authorization response message to the DDNMF network element or the PKMF network element of the first UE or the second UE, wherein the first authorization response message comprises the role of the first UE or the second UE. 22. The method according to claim 21, wherein determining, by the server or the UDM, the role of the first UE or the second UE according to the first authorization request message comprises: determining, by the server or the UDM according to contract information of the first or the second UE, a role allowed for the first UE or the second UE in the service requested to be discovered by the first UE or the second UE; and determining, by the server or the UDM, among the role allowed for the first UE or the second UE, a role supported by a capability of the first UE or the second UE as the role of the first UE or the second UE. 23. The method according to claim 21, further comprising: receiving, by the server or the UDM, a second authorization request message sent by the DDNMF network element or the PKMF network element of the first UE, wherein the second authorization request message comprises the role of the first UE, the role of the second UE, and the service requested to be discovered by the two UEs; determining, by the server or the UDM, whether the role of the first UE is matched with the role of the second UE in the service requested to be discovered by the two UEs; and sending, by the server or the UDM, a second authorization response message to the DDNMF network element or the PKMF network element of the first UE, wherein the second authorization response message is used to indicate whether the role of the first UE is matched with the role of the second UE. 24.- 29. (canceled) 30. A network device, comprising: a processor; and a memory storing a computer program executable by the processor, wherein the processor is configured to: receive a discovery request message sent by a first UE or a second UE, wherein the discovery request message comprises at least one of a ranging application user identifier (RAUID), a service identifier, or a capability of the first UE or the second UE, wherein the capability of the first UE or the second UE indicates a role of the first UE or the second UE or indicates a role supported by the first UE or the second UE; and send a discovery response message to the first UE or the second UE. 31.- 33. (canceled) 34. A user equipment (UE), comprising: a processor; and a memory storing a computer program executable by the processor, wherein the processor is configured to perform the method according to claim 10."
  ],
  "description_excerpt": "The present disclosure generally relates to the field of communication technology, and more particularly, to a method/apparatus/device for authorizing a role of a UE and a storage medium.\n\nIn a communication system, when performing a ranging service and/or a sidelink (SL) positioning service, multiple user equipment (UE) are usually required to play different roles to participate in completing the service, where the UE roles may include an SL reference UE, a target UE, an assistant UE, a located UE, a sidelink positioning server UE, and an SL positioning client UE.\n\nOne UE may simultaneously support multiple roles for the ranging service and/or the sidelink positioning service. For example, if a UE has an ability of sending a location signal, it may be used as a reference UE. If the UE further has an ability of calculating a location, it may be used as a server UE. In a practice scenario, it may happen that the UE plays an inappropriate role in a service, that is, the UE is not allowed or capable to play the role in the service. For example, a UE has a ranging capability, but it is not allowed to play the role of the reference UE in ranging service 1. When it plays the role of the reference UE in ranging service 1, an accuracy of the ranging service may be affected and unsafe problem such as information leakage may be caused.",
  "cpc": [
    "H04W 12/08",
    "H04W 64/00",
    "H04W 92/18"
  ],
  "ipc": [
    "H04W 12/08",
    "H04W 64/00",
    "H04W 92/18"
  ],
  "assignees": [
    "Beijing Xiaomi Mobile Software Co Ltd"
  ],
  "inventors": [
    "Wei Lu"
  ],
  "filing_date": "2022-09-26",
  "publication_date": "2026-04-16",
  "priority_date": "2022-09-26",
  "application_number": "US-202219114581-A",
  "family_id": "88943594",
  "cited_by_count": 0
}

Record 9 of 8,000 in Patents full text (MLC-0201). Request the full dataset.