Security keys in layer 1 (L1) and layer 2 (L2) based mobility

By employing L1/L2-based mobility handover technology in wireless communication systems and deriving security keys using lower-layer signaling, the problem of low security key update efficiency during cell handover between UE and BS is solved, achieving fast and reliable security key management and improving system security and efficiency.

CN115720714BActive Publication Date: 2025-10-24QUALCOMM INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180045668.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-07-01
Filing Date
2021-07-02
Publication Date
2025-10-24
Estimated Expiration
2041-07-02

AI Technical Summary

Technical Problem

Existing wireless communication systems suffer from inefficiencies and inadequate security in updating and managing security keys during handover between user equipment (UE) and base stations (BS), especially when multiple target physical cells are associated.

Method used

Employing layer 1 (L1) and layer 2 (L2) mobility handover technologies, security keys are derived through lower-layer signaling (such as downlink control information and media access control-control elements) to ensure rapid updating and management of security keys during inter-cell handover.

Benefits of technology

It enables fast and reliable updates of security keys during inter-cell handover, improving the security and efficiency of communication systems, especially when multiple target cells are associated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115720714B_ABST
    Figure CN115720714B_ABST
Patent Text Reader

Abstract

Certain aspects of the subject matter described in this disclosure can be implemented in a method for wireless communication by a user equipment (UE). The method generally includes receiving lower layer signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and a BS, and communicating with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] This application claims priority to U.S. Application No. 17 / 365,386, filed July 1, 2021, which claims benefit of and priority to U.S. Provisional Application No. 63 / 047,623, filed July 2, 2020, which are assigned to the assignee hereof and hereby expressly incorporated by reference herein in their entirety for all purposes.

[0003] BACKGROUND

[0004] BACKGROUND

[0005] Aspects of the disclosure relate to wireless communications, and more particularly to techniques for secure key derivation.

[0006] TECHNICAL PROBLEM

[0007] Wireless communications systems are widely deployed to provide various telecommunication services such as telephony, video, data, messaging, broadcasts, etc. These wireless communications systems can employ multiple-access technologies capable of supporting communication with multiple users by sharing available system resources (e.g., bandwidth, transmit power, etc.). Examples of such multiple-access technologies include 3rd Generation Partnership Project (3GPP) Long Term Evolution (LTE) systems, 3GPP LTE-Advanced (LTE-A) systems, code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single-carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems, to name a few.

[0008] These multiple access technologies have been adopted in various telecommunication standards to provide a common protocol that enables different wireless devices to communicate on a municipal, national, regional, and even global level. New radio (e.g., 5G NR) is an example of an emerging telecommunication standard. NR is a set of enhancements to the LTE mobile standard promulgated by 3GPP. NR is designed to better support mobile broadband Internet access by improving spectral efficiency, lowering costs, improving services, making use of new spectrum, and better integrating with other open standards using OFDMA with a cyclic prefix (CP) on the downlink (DL) and on the uplink (UL). To these ends, NR supports beamforming, multiple-input multiple-output (MIMO) antenna technology, and carrier aggregation.

[0009] As the demand for mobile broadband access continues to increase, there exists a need for further improvements in NR and LTE technology. These improvements should be applicable to other multi-access technologies and the telecommunication standards that employ these technologies.

[0010] SUMMARY

[0011] The systems, methods, and devices of the disclosure each have several aspects, no single one of which is solely responsible for its desirable attributes. After considering this discussion, and particularly after reading the section entitled "DETAILED DESCRIPTION," it will be appreciated that aspects of the disclosure provide advantages over traditional techniques for improved security protocols.

[0012] Certain aspects of the subject matter described in this disclosure can be implemented in a method for wireless communication by a user equipment (UE). The method generally includes receiving lower layer signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and a base station (BS); and communicating with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0013] Certain aspects of the subject matter described in this disclosure can be implemented in a method for wireless communication by a BS. The method generally includes transmitting, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; and communicating with the UE according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0014] Certain aspects of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication by a UE. The apparatus generally includes a memory and one or more processors coupled to the memory, the memory and the one or more processors configured to: receive lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and a BS; and communicate with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0015] Certain aspects of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication by a BS. The apparatus generally includes a memory and one or more processors coupled to the memory, the memory and the one or more processors configured to: transmit, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; and communicate with the UE according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0016] Certain aspects of the subject matter described in this disclosure can be implemented in a device for wireless communication by a UE. The method generally includes means for receiving lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and a BS; and means for communicating with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0017] Certain aspects of the subject matter described in this disclosure can be implemented in a device for wireless communication by a BS. The method generally includes means for transmitting, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; and means for communicating with the UE according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0018] Certain aspects of the subject matter described in this disclosure can be implemented in a computer-readable medium having instructions stored thereon, the instructions causing a UE to: receive lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and a BS; and communicate with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0019] Certain aspects of the subject matter described in this disclosure can be implemented in a computer-readable medium having instructions stored thereon, the instructions causing a BS to: transmit, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; and communicate with the UE according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0020] Certain aspects of the subject matter described in this disclosure can be implemented in a method for wireless communication by a UE. The method generally includes receiving, from a BS, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; determining, in response to the lower layer signaling, a security key for communications with the BS, the security key being determined based on the PCIs; and communicating with the BS according to the security key and using the one or more first PCIs.

[0021] Certain aspects of the subject matter described in this disclosure can be implemented in a method for wireless communication by a BS. The method generally includes transmitting, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS, determining a security key for communications based on the PCIs, and communicating with the UE according to the security key and using the one or more first PCIs.

[0022] Certain aspects of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication by a UE. The apparatus generally includes a memory and one or more processors coupled to the memory, the memory and the one or more processors configured to receive, from a BS, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS, determine a security key for communications with the BS in response to the lower layer signaling, the security key determined based on the PCIs, and communicate with the BS according to the security key and using the one or more first PCIs.

[0023] Certain aspects of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication by a BS. The apparatus generally includes a memory and one or more processors coupled to the memory, the memory and the one or more processors configured to transmit, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS, determine a security key for communications based on the PCIs, and communicate with the UE according to the security key and using the one or more first PCIs.

[0024] Certain aspects of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication by a UE. The method generally includes means for receiving, from a base station, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS, means for determining a security key for communications with the BS in response to the lower layer signaling, the security key determined based on the PCIs, and means for communicating with the BS according to the security key and using the one or more first PCIs.

[0025] Certain aspects of the subject matter described in this disclosure can be implemented in an apparatus for wireless communication. The method generally includes means for transmitting, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS, means for determining a security key for communications based on the PCIs, and means for communicating with the UE according to the security key and using the one or more first PCIs.

[0026] Certain aspects of the subject matter described in this disclosure can be implemented in a computer-readable medium having instructions stored thereon, the instructions causing a UE to: receive, from a BS, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; determine, in response to the lower layer signaling, a security key for communications with the BS, the security key being determined based on a PCI; and communicate with the BS according to the security key and using the one or more first PCIs.

[0027] Certain aspects of the subject matter described in this disclosure can be implemented in a computer-readable medium having instructions stored thereon, the instructions causing a BS to: transmit, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS; determine, based on a PCI, a security key for communications; and communicate with the UE according to the security key and using the one or more first PCIs.

[0028] To the accomplishment of the foregoing and related ends, the one or more aspects comprise the features hereinafter fully described and particularly pointed out in the claims. The following description and the annexed drawings set forth in detail certain illustrative features of the one or more aspects. These features are indicative, however, of but a few of the various ways in which the principles of various aspects can be employed. BRIEF DESCRIPTION OF DRAWINGS

[0030] So that the above-recited features of the above-described aspects of the present disclosure can be understood in detail, a more particular description, briefly summarized above, can be had by reference to each of the aspects, some of which are illustrated in the appended drawings. It is to be noted, however, that the appended drawings illustrate only certain typical aspects of this disclosure and are therefore not to be considered limiting of its scope in any way.

[0031] FIG. 1 is a block diagram conceptually illustrating an example telecommunications system, in accordance with certain aspects of the present disclosure.

[0032] FIG. 2 is a block diagram illustrating an example architecture of a distributed radio access network (RAN), in accordance with certain aspects of the present disclosure.

[0033] FIG. 3 is a block diagram conceptually illustrating a design of an example base station (BS) and user equipment (UE), in accordance with certain aspects of the present disclosure.

[0034] FIG. 4 is an example frame format for New Radio (NR), in accordance with certain aspects of the present disclosure.

[0035] FIG. 5is a flowchart illustrating example operations for wireless communication by a UE, in accordance with certain aspects of the present disclosure.

[0036] FIG. 6 is a flowchart illustrating example operations for wireless communication by a UE, in accordance with certain aspects of the present disclosure.

[0037] FIG. 7 A communication protocol for inter-cell mobility is illustrated in accordance with certain aspects of the present disclosure.

[0038] FIG. 8 Communication devices that can include various components configured to perform operations for the techniques disclosed herein are illustrated in accordance with aspects of the present disclosure.

[0039] FIG. 9 Communication devices that can include various components configured to perform operations for the techniques disclosed herein are illustrated in accordance with aspects of the present disclosure.

[0040] To facilitate understanding, like reference numerals have been used, where possible, to designate identical elements common to the figures. It is contemplated that elements disclosed in one aspect can be beneficially utilized on other aspects without specific recitation.

[0041] DETAILED DESCRIPTION

[0042] Aspects of the present disclosure provide apparatus, methods, processing systems, and computer readable media for security key derivation for lower layer (e.g., Layer 1 (L1) / Layer 2 (L2)) based mobility. For example, lower layer signaling (e.g., downlink control information (DCI) or medium access control (MAC)-control element (CE)) can be used to switch a UE from a source physical cell identifier (PCI) to one or more target PCIs. In some cases, the one or more target PCIs can be multiple PCIs associated with the same serving cell. Certain aspects of the present disclosure generally relate to techniques for determination (e.g., derivation) of security keys after L1 / L2 based handover, especially in scenarios where multiple target PCIs are selected to serve the UE.

[0043] In some aspects, in cases where the source PCI and the target PCIs are associated with the same serving cell, the security key can not be changed upon handover. In certain aspects, a base station (BS) can indicate to a UE the PCI to be used for determining the security key. In some cases, the PCI to be used for security key derivation can be implied. In other words, the PCI can be determined based on a configuration rule, such as using the PCI with the lowest or highest identifier, the PCI that is first in time selected by the UE for communication.

[0044] The following description provides examples of security generation in a communication system and is not limiting of the scope, applicability, or examples set forth in the claims. Changes can be made in the function and arrangement of elements discussed without departing from the scope of the claims. Various examples can omit, substitute, or add various procedures or components as appropriate. For instance, the methods described can be performed in an order different than described, and other steps can be added, omitted, or combined. Also, features described with respect to some examples can be combined in some other examples. For example, an apparatus can be implemented or a method can be practiced using any number of the aspects set forth herein. In addition, the scope of the disclosure is intended to cover such an apparatus or method which is practiced using other structural, functional, or structural and functional combinations of aspects that are explicitly recited in this disclosure. It should be understood that any aspect of the disclosure disclosed herein can be implemented by one or more elements of a claim. The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any aspect described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects.

[0045] In general, any number of wireless networks can be deployed in a given geographic area. Each wireless network can support a particular radio access technology (RAT) and can operate on one or more frequencies. A RAT can also be referred to as a radio technology, an air interface, etc. A frequency can also be referred to as a carrier, a subcarrier, a frequency channel, a tone, a subband, etc. Each frequency can support one or more communication

[0046] The techniques described herein can be used for various wireless networks and radio technologies. While aspects can be described herein using terminology commonly associated with 3G, 4G, and / or new radio (e.g., 5GNR) wireless technologies, aspects of the present disclosure can be applied in other generation-based communication systems.

[0047] NR access can support various wireless communication services such as Enhanced Mobile Broadband (eMBB) that can target wide bandwidth (e.g., 80 megahertz (MHz) or beyond), millimeter wave (mmW) that can target high carrier frequency (e.g., 25 gigahertz (GHz) or beyond), massive machine type communications MTC (mMTC) that can target non-backward compatible MTC techniques, and / or mission critical that can target ultra-reliable low-latency communications (URLLC). These services can include latency and reliability requirements. These services can also have different transmission time intervals (TTI) to meet respective quality of service (QoS) requirements. In addition, these services can co-exist in the same subframe. NR supports beamforming and beam direction can be dynamically configured. MIMO transmissions with precoding can also be supported. MIMO configurations in the downlink (DL) can support up to 8 transmit antennas (multi-layer DL transmission with up to 8 streams) and up to 2 streams per UE. Multi-layer transmissions with up to 2 streams per UE can be supported. Aggregation of multiple cells can be supported with up to 8 serving cells.

[0048] FIG. 1 An example wireless communication network 100 in which aspects of the present disclosure can be performed is illustrated. For example, the wireless communication network 100 can be an NR system (e.g., a 5G NR network). As shown, the wireless communication network 100 can be in communication with a core network 132. The core network 132 can be in communication with one or more BSs 110 and / or UEs 120 in the wireless communication network 100 via one or more interfaces. FIG. 1

[0049] As FIG. 1 The wireless communication network 100 can include a number of BSs 110a-z (each also individually referred to herein as BS 110 or collectively as BSs 110) and other network entities. A BS 110 can be a station that FIG. 1 ​In the example shown in FIG, BSs 110a, 110b, and 110c may be macro BSs for macro cells 102a, 102b, and 102c, respectively. BS 110x may be a pico BS for pico cell 102x. BSs 110y and 110z may be femto BSs for femto cells 102y and 102z, respectively. BSs 110 may support one or more cells. A network controller 130 may be coupled to a group of BSs 110 and provide coordination and control for these BSs 110 (e.g., via a backhaul).

[0050] BS 110 communicates with UEs 120a-y (each also individually referred to herein as UE 120 or collectively referred to herein as UE 120) in wireless communication network 100. UEs 120 (e.g., 120x, 120y, etc.) may be dispersed throughout wireless communication network 100, and each UE 120 may be stationary or mobile. Wireless communication network 100 may also include relay stations (e.g., relay station 110r) (also referred to as relays, etc.) that receive transmissions of data and / or other information from an upstream station (e.g., BS 110a or UE 120r) and send transmissions of the data and / or other information to a downstream station (e.g., UE 120 or BS 110), or that relay transmissions between UEs 120 to facilitate communication between the devices.

[0051] According to certain aspects, BS 110 and UE 120 may be configured for secure key derivation. FIG. 1 As shown in FIG, BS 110a includes a security manager 112. According to aspects of the present disclosure, the security manager 112 may be configured to transmit lower layer signaling to a UE indicating one or more first PCIs to be used for communication between the UE and the BS and to communicate with the UE based on and using the one or more first PCIs, the security keys being associated with the PCIs.

[0052] like FIG. 1 , UE 120a includes a security manager 122. According to aspects of the present disclosure, the security manager 122 can be configured to receive lower layer signaling from a BS indicating one or more first PCIs to be used for communication between the UE and the BS and to communicate with the BS according to and using the one or more first PCIs using security keys associated with the PCIs.

[0053] FIG. 2 An example architecture of a distributed RAN 200 is illustrated, which may be FIG. 1 Implementation in the wireless communication network 100 illustrated in FIG. FIG. 2As shown in FIG. 1, the distributed RAN includes a core network (CN) 202 and access nodes 208 (e.g., gNBs 110a). FIG. 1 The gNBs 110a in the collective gNBs 110 can also be referred to as base stations, gNBs, NR BSs, NR base stations, network access nodes, or UEs, among other examples. For example, gNBs 110a can be implemented as a centralized unit (CU), a distributed unit (DU), a central office (CO), a cloud street lamp, a street lamp, or other implementation. In some aspects, the gNBs 110a can be implemented as a base station (BS) that communicates with the UEs 120a. In some aspects, the gNBs 110a can be implemented as a remote radio head (RRH), a remote radio equipment (RRE), a remote radio unit (RRU), a smart radio head (SRH), or other implementation.

[0054] The CN 202 can host core network functions. The CN 202 can be deployed centrally. CN 202 functionality can be offloaded (e.g., to advanced wireless services (AWS)) in an effort to handle peak capacity. The CN 202 can include an access and mobility management function (AMF) 204 and a user plane function (UPF) 206. The AMF 204 and the UPF 206 can perform one or more core network functions.

[0055] The AN 208 can communicate with the CN 202 (e.g., via a backhaul interface). The AN 208 can communicate with the AMF 204 via an N2 (e.g., NG-C) interface. The AN 208 can communicate with the UPF 206 via an N3 (e.g., NG-U) interface. The AN 208 can include a central unit control plane (CU-CP) 210, one or more central unit user planes (CU-UPs) 212, one or more DUs 214-218, and one or more antenna / remote radio units (AUs / RRUs) 220-224. The CU and the DU can also be referred to as gNB-CU and gNB-DU, respectively. One or more components of the AN 208 can be implemented in a gNB 226. The AN 208 can communicate with one or more neighboring gNBs / BSs.

[0056] The CU-CP 210 can be connected to one or more of the DUs 214-218. The CU-CP 210 and the DUs 214-218 can be connected via an Fl-C interface. As FIG. 2 illustrated in FIG. 1, the CU-CP 210 can be connected to multiple DUs, but a DU can be connected to only one CU-CP. Although FIG. 2 only one CU-UP 212 is illustrated, the AN 208 can include multiple CU-UPs. The CU-CP 210 selects an appropriate CU-UP(s) for a requested service (e.g., for the UE 120a). The CU-UP(s) 212 can be connected to the CU-CP 210. For example, the CU-UP(s) 212 and the CU-CP 210 can be connected via an El interface. The CU-UP(s) 212 can be connected to one or more of the DUs 214-218. The CU-UP 212 and the DUs 214-218 can be connected via an Fl-U interface. As FIG. 2 illustrated in FIG. 1, the CU-CP 210 can be connected to multiple CU-UPs, but a CU-UP can be connected to only one CU-CP.

[0057] A DU (such as DUs 214, 216, and / or 218) can host one or more transmission / reception points (TRPs), which can include an edge node (EN), an edge unit (EU), a radio head (RH), a smart radio head (SRH), and / or the like. A DU can be located at the edge of the network with radio frequency (RF) functionality. The DUs can be connected to multiple CU-UPs that are connected to the same CU-CP (e.g., under the control of the same CU-CP) (e.g., for RAN sharing, radio as a service (RaaS), and service specific deployments). The DUs can be configured to individually (e.g., dynamic selection) or jointly (e.g., joint transmission) serve traffic to a UE. Each DU 214-216 can be connected with one of AUs / RRUs 220-224.

[0058] The CU-CP 210 can be connected to multiple DUs that are connected to the same CU-UP 212 (e.g., under the control of the same CU-UP 212). Connectivity between the CU-UP 212 and the DUs can be established by the CU-CP 210. For example, the connectivity between the CU-UP 212 and the DUs can be established using a bearer context management function. Data forwarding between the CU-UP(s) 212 can be via an Xn-U interface.

[0059] The distributed RAN 200 can support fronthaul solutions across different deploymenttypes. For example, the RAN 200 architecture can be based on transmission network capabilities (e.g., bandwidth, latency, and / or jitter). The distributed RAN 200 can share features and / or components with LTE. For example, the ANs 208 can support dual connectivity with NR and can share a common fronthaul for LTE and NR. The distributed RAN 200 can enable cooperation between and among DUs 214-218, for example, via the CU-CP 212. An inter-DU interface can not be used.

[0060] FIG. 3 Example components of the BS 110a and UE 120a, which can be used to implement aspects of the present disclosure, are illustrated in wireless communication network 100. FIG. 1

[0061] At the BS 110a, a transmit processor 320 can receive data from a data source 312 and control information from a controller / processor 340. The control information can be for the physical broadcast channel (PBCH), physical control format indicator channel (PCFICH), physical hybrid automatic repeat request (HARQ) indicator channel (PHICH), physical downlink control channel (PDCCH), group common PDCCH (GC PDCCH), etc. The data can be for the physical downlink shared channel (PDSCH), etc. A media access control (MAC)-control element (MAC-CE) is a MAC layer communication structure that can be used for control command exchange between wireless nodes. The MAC-CE can be carried in a shared channel, such as a physical downlink shared channel (PDSCH), a physical uplink shared channel (PUSCH), or a physical sidelink shared channel (PSSCH).

[0062] The processor 320 can process (e.g., encode and symbol map) the data and control information to obtain data symbols and control symbols, respectively. The transmit processor 320 can also generate reference symbols, such as for the primary synchronization signal (PSS), secondary synchronization signal (SSS), and channel state information reference signal (CSI-RS). A transmit (TX) multiple-input multiple-output (MIMO) processor 330 can perform spatial processing (e.g., precoding) on the data symbols, the control symbols, and / or the reference symbols, if applicable, and can provide output symbol streams to the modulators (MODs) 332a-332t. Each modulator 332 can process a respective output symbol stream (e.g., for OFDM, etc.) to obtain an output sample stream. Each modulator 332 can further process (e.g., convert to analog, amplify, filter, and upconvert) the output sample stream to obtain a downlink (DL) signal. DL signals from modulators 332a-332t can be transmitted via the antennas 334a-334t, respectively.

[0063] At the UE 120a, the antennas 352a-352r can receive the DL signals from the BS 110a and can provide received signals to the demodulators (DEMODs) 354a-354r, respectively, in transceivers. Each demodulator can condition (e.g., filter, amplify, downconvert, and digitize) a respective received signal to obtain input samples. Each demodulator can further process the input samples (e.g., for OFDM, etc.) to obtain received symbols. A MIMO detector 356 can obtain received symbols from all the demodulators 354a-354r in the transceivers, perform MIMO detection on the received symbols if applicable, and provide detected symbols. A receive processor 358 can process (e.g., demodulate, deinterleave, and decode) the detected symbols, providing decoded data for the UE 120a to a data sink 360, and provide decoded control information to a controller / processor 380.

[0064] On the uplink (UL), at the UE 120a, a transmit processor 364 can receive and process data (e.g., for the PUSCH) from a data source 362 and control information (e.g., for the physical uplink control channel (PUCCH) from the controller / processor 380. The transmit processor 364 can also generate reference symbols for a reference signal (e.g., for the sounding reference signal (SRS)). The symbols from the transmit processor 364 can be precoded by a TX MIMO processor 366 if applicable, further processed by the modulators 354a-354r in transceivers, and transmitted to the BS 110a in accordance with the transmission scheme (e.g., for single-carrier frequency division multiplexing (SC-FDM), etc.). At the BS 110a, the UL signals from the UE 120a can be received by the antennas 334, processed by the modulators 332, detected by a MIMO detector 336 if applicable, and further processed by a receive processor 338 to obtain decoded data and control information sent by the UE 120a. The receive processor 338 can provide the decoded data to a data sink 339 and the decoded control information to a controller / processor 340.

[0065] The memory 342 and 382 can store data and program codes for the BS 110a and the UE 120a, respectively. A scheduler 344 can schedule UEs for data transmission on the DL and / or the UL.

[0066] The antennas 352, processors 366, 358, 364, and / or controller / processor 380 of the UE 120a, and / or the antennas 334, processors 320, 330, 338, and / or controller / processor 340 of the BS 110a can be used to perform the various techniques and methods described herein. For example, as described FIG. 2As shown in FIG. 13, according to aspects described herein, the controller / processor 340 of the BS 110a has a security manager 112. As FIG. 2 As shown in FIG. 13, according to aspects described herein, the controller / processor 380 of the UE 120a has a security manager 122. Although shown at the controller / processor, other components of the UE 120a and the BS 110a can be used to perform the operations described herein.

[0067] NR can utilize orthogonal frequency division multiplexing (OFDM) with cyclic prefix (CP) on the UL and DL. NR can support half-duplex operation using time division duplex (TDD). OFDM and SC-FDM partition the system bandwidth into multiple orthogonal subcarriers, which are also commonly referred to as tones, frequency bins, and the like. Each subcarrier can be modulated with data. Modulation symbols can be time-domain orthogonal frequency division multiplexing (OFDM) for frequency domain multiplexing (FDM) or frequency-division multiplexing (SC-FDM) in the frequency domain. The spacing of adjacent subcarriers can be fixed, and the total number of subcarriers can be dependent on the system bandwidth. The minimum resource allocation, called a resource block (RB), can be 12 consecutive subcarriers. The system bandwidth can also be partitioned into sub-bands. For example, a sub-band can cover multiple RBs. NR can support a base subcarrier spacing (SCS) of 15 kilohertz (kHz) and other SCS (e.g., 30 kHz, 60 kHz, 120 kHz, 240 kHz, etc.) can be defined with respect to the base SCS.

[0068] FIG. 4 is a diagram illustrating an example of a frame format 400 for NR. The transmission timeline for each of the DL and the UL can be partitioned into units of radio frames. Each radio frame can have a predetermined duration (e.g., 10 milliseconds (ms)) and can be partitioned into 10 subframes with indices 0 through 9, each of 1 ms. Each subframe can include a variable number of time slots (e.g., 1, 2, 4, 8, 16,... time slots), depending on the SCS. Each time slot can include a variable number of symbol periods (e.g., 7 or 14 symbol periods), depending on the SCS. Symbol periods in each slot can be assigned indices for

[0069] Security keys for communication between a BS and a UE in example techniques for security key derivation in layer 1 (L1) and layer 2 (L2) based mobility can be updated during handover. For example, a new key can be generated as a function of a physical cell identifier (ID) (PCI) of a target cell and an absolute radio frequency channel number (ARFCN-DL) in downlink (DL). For example, a UE and a gNB / next generation (ng) eNB can use a security key (K gNB ) to secure communication with each other.

[0070] At handover and at transition from a radio resource control (RRC) inactive mode (RRC INACTIVE) to a RRC connected mode (RRC CONNECTED) state, a K gNB currently active or from a next hop (NH) parameter. A K NG-RAN for use between the UE and a target gNB / ng-eNB (e.g., referred to as K gNB ) can be derived. Where the K NG-RAN * is derived from the K gNB currently active, this can be referred to as horizontal key derivation, and where the K NG-RAN * is derived from the NH parameter, the derivation can be referred to as vertical key derivation. At handover with vertical key derivation, the NH can be further bound to a target PCI and its frequency ARFCN-DL before it is used as the K gNB in the target gNB / ng-eNB. At handover with horizontal key derivation, the K gNB currently active can be further bound to a target PCI and its frequency ARFCN-DL before it is used as the K gNB in the target gNB / ng-eNB. Thus, security key generation is a function of a PCI and an associated ARFCN-DL.

[0071] Layer 1 (L1) / layer 2 (L2) based inter-cell mobility generally refers to techniques for switching a UE from a PCI to one or more other PCIs using L1 or L2 signaling. L1 signaling can include downlink control information (DCI), and L2 signaling can include medium access control (MAC)-control elements (CEs). L1 / L2 based inter-cell mobility allows for faster switching between cells as compared to conventional implementations where handover is performed using higher layer signaling, such as RRC signaling.

[0072] L1 / L2 based inter-cell mobility can include an implementation in which each serving cell has multiple PCIs for remote radio heads (RRHs) that are located at different physical locations. In this case, at each point in time, a base station (BS) (e.g., gNB) dynamically selects a subset of the PCIs of the same serving cell to serve a UE via L1 / L2 signaling (e.g., DCI or MAC-CE). In other implementations, each serving cell can have a single PCI. In this case, at each point in time, the BS dynamically selects at least one serving cell to serve the UE via L1 / L2 signaling. Certain aspects of the present disclosure generally relate to techniques for determination (e.g., derivation) of security keys (e.g., K gNB ) after an L1 / L2 based inter-cell handover.

[0073] FIG. 5 is a flow diagram illustrating example operations 500 for wireless communication by a base station (BS), in accordance with certain aspects of the present disclosure. The operations 500 can be performed, for example, by the BS 110a in the wireless communication network 100.

[0074] The operations 500 can be implemented as software components that are executed / run on one or more processors (e.g., controller / processor 340 of a BS 110). FIG. 2 Moreover, the transmission and reception of signals by the BS in operations 500 can be enabled, for example, by one or more antennas (e.g., antennas 334 of the BS 110). FIG. 2 In certain aspects, the transmission and / or reception of signals by the BS can be implemented via a bus interface of one or more processors (e.g., controller / processor 340) obtaining and / or outputting signals.

[0075] The operations 500 can begin, at block 505, by the BS transmitting, to a UE, lower layer signaling indicating that the UE is to handover to one or more first PCIs to be used for communication between the UE and the BS. At block 510, the BS communicates with the UE according to a security key and using the one or more first PCIs, the security key being associated with the PCIs. In some aspects, the BS can determine the security key for communication with the UE.

[0076] FIG. 6 is a flow diagram illustrating example operations 600 for wireless communication by a UE, in accordance with certain aspects of the present disclosure. The operations 600 can be performed, for example, by the UE 120a in the wireless communication network 100. The operations 600 can be complementary operations performed by the UE to the operations 500 performed by the BS.

[0077] The operations 600 can be implemented as software components that are executed / run on one or more processors (e.g., controller / processor 384 of a UE 120). FIG. 2software components that are executed and run on the processor(s) 380 of the UE. Further, signal transmission and reception by the UE in operations 600 can be achieved via one or more antennas 352 of the UE, for example. FIG. 2 In certain aspects, signal transmission and / or reception by the UE can be achieved via obtaining and / or outputting signals via a bus interface of one or more processors (e.g., the controller / processor 380).

[0078] Operations 600 can begin with receiving, by a UE, lower layer signaling (e.g., DCI, MAC-CE, or a random access channel (RACH) message of a RACH procedure initiated by the UE) indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and a BS, at block 605. At block 610, the UE communicates with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs. In some aspects, the UE can determine the security key for communications with the BS in response to the lower layer signaling. In some aspects, the security key can be determined further based on an absolute radio frequency channel number associated with the PCIs, as described herein.

[0079] In some aspects, the UE can receive another lower layer signaling (e.g., for switching) indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE. In some cases, where the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU), a same security key can be used for communications using the one or more first PCIs and the one or more second PCIs (e.g., unless the BS indicates a different PCI is to be used to determine a security key for communications using the one or more second PCIs). In some cases, where the one or more first PCIs include a plurality of PCIs, the PCI used to determine the security key can be a default PCI of the plurality of PCIs. For example, the PCI used to determine the security key can be one of the plurality of PCIs having a lowest or highest identifier (ID), or one of the plurality of PCIs that is used for communications first in time.

[0080] In some cases, the PCI can be indicated to the UE by the BS. For example, the UE can receive an indication of the PCI to be used to determine the security key from the BS.

[0081] In some aspects, the UE can receive one or more other lower layer signalings for switching, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE. The UE can determine another security key after receiving each of the one or more other lower layer signalings to be used for communications by the UE using the one or more second PCIs.

[0082] In some aspects, the UE can receive a configuration of a plurality of candidate PCIs and derive a security key for each of the plurality of candidate PCIs. In this case, determining the security key can comprise selecting one of the derived security keys associated with one or more first PCIs. In some aspects, the one or more first PCIs can comprise a single PCI, the one of the derived security keys being associated with the single PCI.

[0083] FIG. 7 A communication protocol 700 for L1 / L2 inter-cell mobility is illustrated in accordance with certain aspects of the present disclosure. As illustrated, the UE 120 can optionally indicate L1 metrics 702 to the BS via a cell associated with PCI 1. The BS can then use the L1 metrics 702 to select a subset of PCI(s) (e.g., PCI 2 and PCI 3) to serve the UE 120 and indicate the selected PCIs to the UE. Although the subset of PCIs serving the UE in the example communication protocol 700 includes multiple PCIs, in some cases the subset of PCIs can include only a single PCI. The indication of the subset of PCIs serving the UE 120 can comprise L1 or L2 signaling 704, such as DCI or a MAC-CE. As illustrated, at blocks 708, 710, the UE and the BS can determine a security key for communications between the UE and the BS. The security key can be associated with a PCI, and in some cases the PCI can be a PCI in the selected subset of PCIs (e.g., the security key can be associated with PCI 2 or PCI 3), while in other cases the PCI can not be a PCI in the selected subset of PCIs (e.g., the security key can not be associated with PCI 2 or PCI 3). At 712, the UE 120 and the BS can perform communications 712 via the security key.

[0084] Certain aspects provide techniques for determining a security key after an L1 / L2 based inter-cell handover, which can be applicable to both implementations of L1 / L2 signaling as described herein (e.g., each serving cell has multiple PCIs, or each serving cell has a single PCI). In some aspects, the security key can not change after an L1 / L2 based inter-cell handover at least without explicit signaling to update the security key. This option can be used at least when both the source PCI (e.g., PCI 1) and the target PCI(s) (e.g., PCI 2 and PCI 3) are managed by the same gNB CU. That is, the same security key derived when this feature is enabled will also be used in the later handover. For example, the security key can not be updated after an L1 / L2 based inter-cell handover as long as the source PCI and the target PCI(s) are associated with the same serving cell. See FIG. 7In case PCI 1, PCI 2, and PCI 3 are assumed to be associated with the same serving cell, the same security key used when the UE uses PCI 1 can also be used after the UE switches to use PCI 2 and PCI 3.

[0085] As one example, the same security key can be determined by a default PCI (e.g., the candidate PCI with the lowest value) and the corresponding ARFCN-DL among all candidate PCIs for L1 / L2 cell selection. For example, referring to FIG. 7 When PCI 2 and PCI 3 are selected to serve the UE, the default PCI for security key determination can be PCI 2 because PCI 2 has the lowest ID value.

[0086] As another example, when this feature is enabled, the same security key can be determined by the PCI and the corresponding ARFCN-DL of the first PCI selected to serve the UE. In other words, when multiple PCIs (e.g., PCI 2 and PCI 3) are selected to serve the UE, the first PCI for determining the security key can be the one with the lowest value or the highest value, or determined based on the order index among all selected PCIs. For example, the first PCI can be the PCI (e.g., PCI 2) that is first selected by the UE for communication in time after the handover.

[0087] In certain aspects, the security key can be updated based on explicit signaling from the BS. For example, the BS can indicate to the UE a specified PCI and the corresponding ARFCN-DL, which can be used to derive a new security key. The specified PCI can or can not be one of the candidate PCIs for L1 / L2 based cell selection. For example, referring to FIG. 7 The BS can indicate to the UE to use PCI 2, a candidate PCI (or PCI 4, which is not a candidate PCI) to determine the security key. In some aspects, the indication can be sent in the L1 / L2 cell selection command or in separate signaling. For example, the signaling 704 can be the L1 / L2 cell selection command, and the PCI to be used to determine the security key can be part of the L1 / L2 cell selection command.

[0088] In certain aspects, a security key can be implicitly updated after each L1 / L2 cell selection based on a certain rule. For example, a new security key can be derived by one PCI and the corresponding ARFCN-DL. In the case where only a single PCI is selected (e.g., the signaling 704 indicates only a single PCI serves the UE), the one PCI used for security key derivation is the selected PCI. In the case where multiple PCIs (e.g., PCI 2 and PCI 3) are selected, the one PCI used for security key derivation is one of the selected PCIs, such as the PCI with the lowest / highest value or sequential index, as described herein.

[0089] In some aspects, a BS can configure a UE with multiple candidate PCIs, and the UE can be configured to derive a security key for each of the multiple candidate PCIs. Whenever one PCI is selected to serve the UE via L1 / L2 signaling, the UE selects the security key prepared (e.g., derived) for that PCI. In some aspects, the L1 / L2 signaling can include a DCI or a MAC-CE transmitted from the BS, or a RACH message of a RACH procedure initiated by the UE.

[0090] In some aspects, one or more of the techniques described herein can be used simultaneously based on a specification rule(s) or BS configuration. For example, as described herein, the same security key can be used as long as the source PCI and one or more target PCIs are associated with the same serving cell, unless a new PCI is indicated by the BS to be used for key derivation. As another example, a security key can be implicitly derived using a certain configured rule, unless a different PCI is indicated by the BS to be used for key derivation.

[0091] Example wireless communication device

[0092] FIG. 8 A communication device 800 including various components (e.g., corresponding to means-plus-function components) configured to perform operations for the techniques disclosed herein, such as the operations illustrated in FIGS. 7-9, is illustrated and described. In some examples, the communication device 800 can be a BS, such as the BS 110a described, for example, with reference to FIG. 1. FIG. 5 In some examples, the communication device 800 can be a UE, such as the UE 110b described, for example, with reference to FIG. 1. FIG. 1 FIG. 3 In some examples, the communication device 800 can be a UE, such as the UE 110b described, for example, with reference to FIG. 1.

[0093] ​The communications device 800 includes a processing system 802 (e.g., corresponding to controller / processor 340) coupled to a transceiver 808 (e.g., a transmitter and / or receiver). The transceiver 808 can correspond to one or more of transmit processor 320, TX MIMO processor 330, modulator / demodulator 332, receive processor 338, and MIMO detector 336. The transceiver 808 is configured to transmit and receive signals for the communications device 800 via an antenna 810, such as the various signals as described herein. The processing system 802 can be configured to perform processing functions for the communications device 800, including processing signals received and / or to be transmitted by the communications device 800.

[0094] The processing system 802 includes a processor 804 coupled to a computer- readable medium / memory 812 via a bus 806. In certain aspects, the computer-readable medium / memory 812 is configured to store instructions (e.g., computer-executable code) that, when executed by the processor 804, cause the processor 804 to perform FIG. 5 operations as illustrated in the operations of FIG. 13 or other operations for performing the various techniques discussed herein for secure key derivation.

[0095] In certain aspects, the computer-readable medium / memory 812 (e.g., corresponding to memory 342) stores code for transmitting 814 (example means for transmitting); code for determining 816 (example means for determining); and code for communicating 818 (example means for communicating).

[0096] In certain aspects, the code 814 for communicating can include code to transmit, to a user equipment (UE), lower layer signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and the BS. In certain aspects, the code 814 for communicating can include code to transmit another lower layer signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, and where in instances where the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU), a same security key is used for communications using the one or more first PCIs and the one or more second PCIs. In certain aspects, the code 814 for communicating can include code to transmit, to the UE, an indication of a PCI associated with a security key. In certain aspects, the code 814 for communicating can include code to transmit one or more other lower layer signalings, each indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE. In certain aspects, the circuitry 824 for communicating can include circuitry to transmit, to the UE, a configuration of a plurality of candidate PCIs. In certain aspects, the code 816 for determining can include code to determine, based on the PCI, a security key for communications. In certain aspects, the code 816 for determining can include code to determine, after each of the one or more other lower layer signalings for communications by the UE using the one or more second PCIs, another security key to be used. In certain aspects, the code 818 for communicating can include code to communicate with the UE according to the security key and using the one or more first PCIs, the security key being associated with the PCI.

[0097] In certain aspects, the processor 804 has circuitry configured to implement code stored in the computer-readable medium / memory 812. The processor 804 includes circuitry 824 for communicating (example means for communicating); circuitry 826 for determining, based on the PCI, a security key for communications (example means for determining, based on the PCI, a security key for communications); and circuitry 828 for communicating with the UE according to the security key and using the one or more first PCIs (example means for communicating with the UE according to the security key and using the one or more first PCIs).

[0098] In certain aspects, the circuitry for communicating 824 can include circuitry for transmitting, to a UE, lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS. In certain aspects, the circuitry for communicating 824 can include circuitry for transmitting another lower layer signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, and wherein in a case that the one or more first PCIs and the one or more second PCIs are managed by a same CU, a same security key is used for communications using the one or more first PCIs and the one or more second PCIs. In certain aspects, the circuitry for communicating 824 can include circuitry for transmitting, to the UE, an indication of a PCI associated with a security key. In certain aspects, the circuitry for communicating 824 can include circuitry for transmitting one or more other lower layer signalings, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE. In certain aspects, the circuitry for communicating 824 can include circuitry for transmitting, to the UE, a configuration of a plurality of candidate PCIs. In certain aspects, the circuitry for determining 826 can include circuitry for determining, based on a PCI, a security key to be used for communications. In certain aspects, the circuitry for determining 826 can include circuitry for determining, after each of one or more other lower layer signalings by the UE using one or more second PCIs, another security key to be used. In certain aspects, the circuitry for communicating 828 can include circuitry for communicating with the UE according to a security key and using one or more first PCIs, the security key being associated with the PCIs.

[0099] FIG. 9 A communications device 900 is illustrated that can include various components (e.g., corresponding to means-plus-function components) operative to perform operations for the techniques disclosed herein, such as operations illustrated in FIG. 10, and / or other operations illustrated and / or described herein. FIG. 6 In some examples, communications device 900 can be a UE, such as, for example, UE 120a described with reference to FIG. 1 and FIG. 3 FIG. 9.

[0100] The communications device 900 includes a processing system 902 (e.g., corresponding to controller / processor 380) coupled to a transceiver 908 (e.g., a transmitter and / or receiver). The transceiver 908 can correspond to one or more of transmit processor 364, TX MIMO processor 366, modulator / demodulator 354, receive processor 358, and MIMO detector 356. The transceiver 908 is configured to transmit and receive signals for the communications device 900 via an antenna 910, such as the various signals as described herein. The processing system 902 can be configured to perform processing functions for the communications device 900, including processing signals received and / or to be transmitted by the communications device 800.

[0101] The processing system 902 includes a processor 904 coupled to a computer- readable medium / memory 912 via a bus 906. In certain aspects, the computer-readable medium / memory 912 is configured to store instructions (e.g., computer-executable code) that, when executed by the processor 904, cause the processor 904 to perform operations as discussed herein or otherwise with respect to the various techniques for secure key derivation discussed herein. FIG. 6

[0102] In certain aspects, the computer-readable medium / memory 912 stores code for initiating 914 (example means for initiating); code for receiving 916 (example means for receiving); code for deriving 918 (example means for deriving); code for determining 920 (example means for determining); and code for communicating 922 (example means for communicating).

[0103] ​In certain aspects, the code for initiating 914 can include code for initiating a random access channel (RACH) procedure, where the lower layer signaling comprises a RACH message of the RACH procedure. In certain aspects, the code for receiving 916 can include code for receiving lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS. In certain aspects, the code for receiving 916 can include code for receiving another lower layer signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, and where in the case that the one or more first PCIs and the one or more second PCIs are managed by a same CU, a same security key is used for communications using the one or more first PCIs and the one or more second PCIs. In certain aspects, the code for receiving 916 can include code for receiving an indication of a PCI associated with a security key from the BS. In certain aspects, the code for receiving 916 can include code for receiving one or more other lower layer signalings, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE. In certain aspects, the code for receiving 916 can include code for receiving a configuration of a plurality of candidate PCIs. In certain aspects, the code for deriving 918 can include code for deriving a security key for each of the plurality of candidate PCIs, where communicating with the BS according to the security key comprises communicating with the BS according to one of the derived security keys associated with the one or more first PCIs and selected by the UE. In certain aspects, the code for determining 920 can include code for determining a security key for communications with the BS in response to the lower layer signaling, the security key being determined based on the PCI. In certain aspects, the code for determining 920 can include code for determining another security key after receiving each of the one or more other lower layer signalings to be used for communications by the UE using the one or more second PCIs. In certain aspects, the code for communicating 922 can include code for communicating with the BS according to the security key and using the one or more first PCIs, the security key being associated with the PCI.

[0104] In certain aspects, the processor 904 has circuitry configured to implement code stored in the computer-readable medium / memory 912. The processor 904 includes circuitry for initiating 924 (example means for initiating); circuitry for receiving 926 (example means for receiving); and circuitry for deriving 928 (example means for deriving); circuitry for determining 930 (example means for determining); and circuitry for communicating 932 (example means for communicating).

[0105] In certain aspects, the circuitry for initiating 924 can include circuitry for initiating a RACH procedure, where the lower layer signaling comprises a RACH message of the RACH procedure. In certain aspects, the circuitry for receiving 926 can include circuitry for receiving lower layer signaling indicating that the UE is to switch to one or more first PCIs to be used for communications between the UE and the BS. In certain aspects, the circuitry for receiving 926 can include circuitry for receiving another lower layer signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, and where in the case that the one or more first PCIs and the one or more second PCIs are managed by a same CU, a same security key is used for communications using the one or more first PCIs and the one or more second PCIs. In certain aspects, the circuitry for receiving 926 can include circuitry for receiving, from the BS, an indication of a PCI associated with a security key. In certain aspects, the circuitry for receiving 926 can include circuitry for receiving one or more other lower layer signalings, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE. In certain aspects, the circuitry for receiving 926 can include circuitry for receiving a configuration of a plurality of candidate PCIs. In certain aspects, the circuitry for deriving 928 can include circuitry for deriving a security key for each of the plurality of candidate PCIs, where communicating with the BS according to the security key comprises communicating with the BS according to one of the derived security keys associated with the one or more first PCIs and selected by the UE. In certain aspects, the circuitry for determining 930 can include circuitry for determining, in response to the lower layer signaling, a security key for communications with the BS, the security key being determined based on the PCI. In certain aspects, the circuitry for determining 930 can include circuitry for determining, after receiving each of the one or more other lower layer signalings to be used for communications by the UE using the one or more second PCIs, another security key. In certain aspects, the circuitry for communicating 928 can include circuitry for communicating with the BS according to the security key and using the one or more first PCIs, the security key being associated with the PCI.

[0106] According to examples as disclosed herein, the security manager 122 or 112 can support wireless communications.

[0107] The security manager 122 or 112 can be an example of means for performing various aspects described herein. The security manager 122 or 112, or its subcomponents, can be implemented in hardware, such as in uplink (UL) resource management circuitry. The circuitry can include a processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the various functions described in the present disclosure.

[0108] In another implementation, the security manager 122 or 112, or its subcomponents, can be implemented in code (for example, as configuration management software or firmware) executed by a processor, or any combination thereof. If implemented in code executed by a processor, the functions of the security manager 122 or 112, or its subcomponents, can be executed by a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof.

[0109] In some examples, the security manager 122 or 112 can be configured to perform various operations (for example, receiving, determining, transmitting) using or otherwise in cooperation with the transceiver 808 or 908.

[0110] The security manager 122 or 112, or its subcomponents, can be physically located at various positions, including being distributed so that portions of functions are implemented at different physical locations by one or more physical components. In some examples, the security manager 122 or 112, or its subcomponents, can be a separate and distinct component according to various aspects of the present disclosure. In some examples, the security manager 122 or 112, or its subcomponents, can be combined with one or more other hardware components, including but not limited to an input / output (I / O) component, a transceiver, a network server, another computing device, one or more other components described in the present disclosure, or a combination thereof, according to various aspects of the present disclosure.

[0111] Example Clauses

[0112] Implementation examples are described in the following numbered clauses.

[0113] Clause 1: A method for wireless communication by a user equipment (UE), comprising: receiving lower layer signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communication between the UE and a base station (BS); and communicating with the BS according to a security key and using the one or more first PCIs, the security key being associated with the PCIs.

[0114] Clause 2: The method of clause 1, wherein the lower layer signaling comprises a medium access control (MAC)-control element (CE) or downlink control information (DCI).

[0115] Clause 3: The method of clause 1 or 2, further comprising initiating a random access channel (RACH) procedure, wherein the lower layer signaling comprises a RACH message of the RACH procedure.

[0116] Clause 4: The method of any of clauses 1-3, wherein the security key is determined based on an absolute radio frequency channel number associated with the PCI.

[0117] Clause 5: The method of any of clauses 1-4, further comprising receiving another lower layer signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, wherein in a case that the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU), a same security key is used for communications using the one or more first PCIs and the one or more second PCIs.

[0118] Clause 6: The method of clause 5, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs unless the BS indicates a different PCI associated with a security key for communicating using the one or more second PCIs.

[0119] Clause 7: The method of clause 5 or 6, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises a default PCI of the plurality of PCIs.

[0120] Clause 8: The method of any of clauses 5-7, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs having a lowest or highest identifier (ID).

[0121] Clause 9: The method of any of clauses 5-8, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs that is used for communications first in time.

[0122] Clause 10: The method of any of clauses 1-9, further comprising receiving an indication of the PCI associated with the security key from the BS.

[0123] Clause 11: The method of clause 10, wherein the PCI is one of the one or more first PCIs indicated via the lower layer signaling.

[0124] Clause 12: The method of any of clauses 10 or 11, wherein the PCI is different from the one or more first PCIs indicated via the lower layer signaling.

[0125] Clause 13: The method of any of clauses 10-12, wherein the lower layer signaling comprises a cell selection command for the UE to switch to the one or more first PCIs, the cell selection command further comprising an indication of a PCI associated with the security key.

[0126] Clause 14: The method of any of clauses 1-13, further comprising: receiving one or more other lower layer signaling, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE; and determining another security key after receiving each of the one or more other lower layer signaling to be used for communications by the UE using the one or more second PCIs.

[0127] Clause 15: The method of any of clauses 1-14, further comprising: receiving a configuration of a plurality of candidate PCIs; and deriving a security key for each of the plurality of candidate PCIs, wherein communicating with the BS comprises communicating with the BS according to one of the derived security keys associated with the one or more first PCIs.

[0128] Clause 16: The method of clause 15, wherein the one or more first PCIs comprise a single PCI, the one of the derived security keys is associated with the single PCI.

[0129] Clause 17: A method for wireless communications by a base station (BS), comprising: transmitting, to a user equipment (UE), lower layer signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and the BS; and communicating with the UE according to a security key and using the one or more first PCIs, the security key being associated with a PCI.

[0130] Clause 18: The method of clause 17, wherein the security key is determined based on an absolute radio frequency channel number associated with the PCI.

[0131] Clause 19: The method of any of clauses 17 or 18, further comprising: transmitting another lower layer signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, wherein in a case that the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU), a same security key is used for communications using the one or more first PCIs and the one or more second PCIs.

[0132] Clause 20: The method of clause 19, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs unless the BS indicates to the UE a different PCI associated with a security key for communications using the one or more second PCIs.

[0133] Clause 21: The method of clause 19 or 20, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises a default PCI of the plurality of PCIs.

[0134] Clause 22: The method of any of clauses 19-21, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI used to determine the security key comprises one of the plurality of PCIs having a lowest or highest identifier (ID).

[0135] Clause 23: The method of any of clauses 19-22, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs that is used for communications first in time.

[0136] Clause 24: The method of any of clauses 17-23, further comprising transmitting an indication of the PCI associated with the security key to the UE.

[0137] Clause 25: The method of clause 24, wherein the PCI is one of the one or more first PCIs indicated via the lower layer signaling.

[0138] Clause 26: The method of clause 24 or 25, wherein the lower layer signaling comprises a cell selection command for the UE to switch to the one or more first PCIs, the cell selection command further comprising an indication of the PCI associated with the security key.

[0139] Clause 27: The method of any of clauses 17-26, further comprising: transmitting one or more other lower layer signaling, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE; and determining another security key to be used after each of the one or more other lower layer signaling of communications by the UE using the one or more second PCIs.

[0140] Clause 28: The method of any of clauses 17-27, further comprising transmitting a configuration of a plurality of candidate PCIs to the UE.

[0141] Clause 29: An apparatus comprising: a memory; and one or more processors coupled to the memory, the one or more processors and the memory configured to perform the method of any of clauses 1-28.

[0142] Clause 30: An apparatus comprising means for performing the method of any of clauses 1-28.

[0143] Clause 31: A non-transitory computer-readable medium comprising executable instructions that, when executed by one or more processors of an apparatus, cause the apparatus to perform the method of any of clauses 1-28.

[0144] Additional Considerations

[0145] The techniques described herein can be used for various wireless communication technologies, such as NR (e.g., 5G NR), 3GPP Long Term Evolution (LTE), LTE-Advanced (LTE-A), code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal frequency division multiple access (OFDMA), single-carrier frequency division multiple access (SC-FDMA), time division synchronous code division multiple access (TD-SCDMA), and other networks. The terms “network” and “system” are often used interchangeably. A CDMA network can implement a radio technology such as Universal Terrestrial Radio Access (UTRA), cdma2000, and so on. UTRA includes Wideband CDMA (WCDMA) and other variants of CDMA. cdma2000 covers IS-2000, IS-95 and IS-856 standards. A TDMA network can implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network can implement a radio technology such as NR (e.g., 5G RA), Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, and so on. UTRA and E-UTRA are part of Universal Mobile Telecommunication System (UMTS). LTE and LTE-A are releases of UMTS that use E-UTRA. UTRA, E-UTRA, UMTS, LTE, LTE-A and GSM are described in documents from an organization named “3rd Generation Partnership Project” (3GPP). cdma2000 and UMB are described in documents from an organization named “3rd Generation Partnership Project 2” (3GPP2). NR is an emerging wireless communications technology.

[0146] In 3GPP, the term "cell" can refer to a coverage area of a Node B (NB) and / or a Node B subsystem serving this coverage area, depending on the context in which the term is used. In NR systems, the term “cell” and BS, next generation Node B (gNB or gNodeB), access point (AP), Distributed Unit (DU), carrier, or Transmission Reception Point (TRP) can be used interchangeably. A BS can provide communication coverage for a macro cell, a pico cell, a femto cell, and / or other types of cell. A macro cell can cover a relatively large geographic area (e.g., several kilometers in radius) and can allow unrestricted access by UEs with service subscriptions. A pico cell can cover a relatively small geographic area (e.g., a city neighborhood or a campus) and can allow unrestricted access by UEs with service subscriptions. A femto cell can cover a relatively small geographic area (e.g., a home) and can allow restricted access by UEs with service subscriptions, e.g., UEs in an closed subscriber group (CSG) or UEs with an association to the femto cell. A BS for a macro cell can be referred to as a macro BS. A BS for a pico cell can be referred to as a pico BS. A BS for a femto cell can be referred to as a femto BS or a home BS.

[0147] A UE can also be known as a mobile station, a terminal, an access terminal, a subscriber unit, a station, a Customer Premises Equipment (CPE), a cellular phone, a smart phone, a personal digital assistant (PDA), a wireless modem, a wireless communication device, a handheld device, a laptop computer, a cordless phone, a wireless local loop (WLL) station, a tablet computer, a camera, a gaming device, a netbook, a smartbook, an ultrabook, an electric appliance, a medical device or medical equipment, a biometric sensor / device, a wearable device such as a smart watch, smart clothing, smart glasses, a smart wristband, smart jewelry (e.g., a smart ring, a smart bracelet, etc.), an entertainment device (e.g., a music device, a video device, a satellite radio, etc.), a vehicular component or sensor, a smart meter / sensor, industrial manufacturing equipment, a global positioning system device, or any other suitable device that is configured to communicate via a wireless or wired medium. Some UEs can be considered machine-type communication (MTC) devices or evolved MTC (eMTC) devices. MTC and eMTC UEs include, for example, robots, drones, remote devices, sensors, meters, monitors, location tags, etc., that can communicate with a BS, another device (e.g., remote device), or some other entity. A wireless node can provide, for example, connectivity for or to a network (e.g., a wide area network such as the Internet or a cellular network) via a wired or wireless communication link. Some UEs can be considered Internet-of-Things (IoT) devices, which can be Narrowband IoT (NB-IoT) devices.

[0148] In some examples, access to the air interface may be scheduled. A scheduling entity (e.g., a BS) allocates resources for communication between some or all devices and equipment within its service area or cell. The scheduling entity may be responsible for scheduling, assigning, reconfiguring, and releasing resources for one or more subordinate entities. That is, for scheduled communications, the subordinate entities utilize the resources allocated by the scheduling entity. The BS is not the only entity that can act as a scheduling entity. In some examples, a UE may act as a scheduling entity and may schedule resources for one or more subordinate entities (e.g., one or more other UEs), and other UEs may utilize the resources scheduled by the UE for wireless communication. In some examples, a UE may act as a scheduling entity in a peer-to-peer (P2P) network and / or in a mesh network. In the mesh network example, UEs may communicate directly with each other in addition to communicating with the scheduling entity.

[0149] Each method disclosed herein includes one or more steps or actions for implementing the method. These method steps and / or actions may be interchangeable with one another without departing from the scope of the claims. In other words, unless a specific order of steps or actions is specified, the order and / or use of the specific steps and / or actions may be modified without departing from the scope of the claims.

[0150] As used herein, a phrase referring to "at least one of" a list of items refers to any combination of those items, including single members. As an example, "at least one of a, b, or c" is intended to encompass: a, b, c, ab, ac, bc, and abc, as well as any combination with multiples of the same elements (e.g., aa, aaa, aab, aac, abb, acc, bb, bbb, bbc, cc, and ccc, or any other ordering of a, b, and c).

[0151] As used herein, the term "determining" encompasses a wide variety of actions. For example, "determining" may include calculating, computing, processing, deriving, investigating, searching (e.g., searching in a table, database, or another data structure), ascertaining, and the like. Furthermore, "determining" may include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), and the like. Furthermore, "determining" may include resolving, selecting, choosing, establishing, and the like.

[0152] The previous description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects. Thus, the claims are not intended to be limited to the aspects shown herein, but is to be accorded the full scope consistent with the language of the claims, wherein reference to an element in the singular is not intended to mean "one and only one" unless specifically so stated, but rather "one or more." Unless specifically stated otherwise, the term "some" refers to one or more. All structural and functional equivalents to the elements of the various aspects described throughout this disclosure that enable a person skilled in the art to practice the disclosure, are expressly incorporated in potential alternative aspects as defined herein, and are intended to be encompassed by the claims. Any claims that are not otherwise expressly supported by the text of this specification are not intended to be abandoned or forfeited, but additional support is supplied for them in any manner permitted by section 112 or 121, 35 U.S.C. Any element in the claims that is not specifically recited in the specification as essential to the practice of the disclosure is not essential, no matter how that element can be characterized in the abstract. Also, any reference in the specification to something "first" something "second", and so on does not necessarily imply that the identified object should also be limited by the order in which it is named.

[0153] Various operations described above can be performed by any suitable means capable of performing the corresponding functions. The means can include various hardware and / or software component(s) and / or module(s), including, but not limited to a circuit, an application specific integrated circuit (ASIC), or processor. Generally, where there are operations illustrated in figures, those operations can have corresponding counterpart means-plus-function components with similar numbering.

[0154] The various illustrative logical blocks, modules, and circuits described in connection with the disclosure can be implemented or performed with a general purpose processor, a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA) or other programmable logic device (PLD), discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor can be a microprocessor, but in the alternative, the processor can be any commercially available processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0155] If implemented in hardware, an example hardware configuration can include a processing system in a wireless node. The processing system can be implemented with a bus architecture. The bus can include any number of interconnecting buses and bridges depending on the specific application of the processing system and the overall design constraints. The bus can link together various circuits such as a processor, machine-readable medium, and buses. A bus interface can be used to connect a network adapter to the processing system via the bus. The network adapter can be used to implement signal processing functionality of the physical (PHY) layer. In the case of a user terminal (see FIG. 1 ) a user interface (e.g., keypad, display, mouse, joystick, etc.) can also be connected to the bus. The bus can also link various other circuits such as timing sources, peripherals, voltage regulators, power management circuits, and the like, which are well known in the art, and therefore will not be further described. The processor can be implemented with one or more general-purpose and / or special-purpose processors. Examples include microprocessors, microcontrollers, DSP processors, and other circuitry that can execute software. Those skilled in the art will recognize how to best implement the functionality described with respect to the processing system depending on the particular application and the overall design constraints imposed on the overall network or system.

[0156] If implemented in software, the functions can be stored or transmitted over as one or more instructions or code on a computer-readable medium. Software shall be construed broadly to mean instructions, data, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. Computer-readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. The processor can be responsible for managing the bus and general processing, including the execution of software modules stored on the machine-readable storage media. A computer-readable storage medium can be coupled with the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium can be integral to the processor. By way of example, the machine-readable media can include a transmission line, a carrier wave modulated by data, and / or a computer readable storage medium with instructions stored thereon separate from the wireless node, all of which can be accessed via the bus. Alternatively, or in addition, the machine-readable media, or any portion thereof, can be integrated into the processor, such as the cache and / or general register files of the processor. Examples of machine-readable storage media can include RAM (random access memory), flash memory, ROM (read only memory), PROM (programmable read only memory), EPROM (erasable programmable read only memory), EEPROM (electrically erasable programmable read only memory), registers, magnetic disks, optical disks, hard drives, or any other suitable storage medium, or any combination thereof. The machine-readable media can be embodied in a computer-program product.

[0157] A software module may include a single instruction or many instructions and may be distributed across several different code segments, between different programs, and across multiple storage media. A computer-readable medium may include multiple software modules. These software modules include instructions that, when executed by a device (such as a processor), cause a processing system to perform various functions. These software modules may include a transmitting module and a receiving module. Each software module may reside in a single storage device or be distributed across multiple storage devices. As an example, when a triggering event occurs, a software module may be loaded from a hard drive into RAM. During the execution of a software module, the processor may load some instructions into a cache to increase access speed. One or more cache lines may then be loaded into a general register file for execution by the processor. When describing the functionality of a software module below, it will be understood that such functionality is implemented by the processor when the processor executes instructions from the software module.

[0158] Likewise, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies (such as infrared (IR), radio, and microwave), then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies (such as infrared, radio, and microwave) are included in the definition of medium. Disk and disc, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Disks typically reproduce data magnetically, while discs reproduce data optically using lasers. Thus, in some aspects, computer-readable media may include non-transitory computer-readable media (e.g., tangible media). Additionally, for other aspects, computer-readable media may include transient computer-readable media (e.g., signals). Combinations of the above should also be included within the scope of computer-readable media.

[0159] Thus, certain aspects may include a computer program product for performing the operations presented herein. For example, such a computer program product may include a computer-readable medium having instructions stored (and / or encoded) thereon, the instructions being executable by one or more processors to perform the operations described herein, such as for performing the operations described herein and in FIG. 5 and 6 Instructions for the operations explained in .

[0160] Further, it should be appreciated that modules and / or other appropriate means for performing the methods and techniques described herein can be downloaded and / or otherwise obtained by a user terminal and / or base station as applicable. For example, such a device can be coupled to a server to facilitate the transfer of means for performing the methods described herein. Alternatively, various methods described herein can be provided via a storage means (e.g., RAM, ROM, a physical storage medium such as a compact disc (CD) or floppy disk, etc.), such that a user terminal and / or base station can obtain the various methods upon coupling or providing the storage means to the device.

[0161] It will be understood that the claims are not limited to the precise configuration and components illustrated above. Various modifications, changes, and adaptations will be apparent to others skilled in the art with the benefit of this disclosure. The scope of the claims should be determined by the appropriate scope of the following claims.

Claims

1. A method for wireless communications by a user equipment (UE), comprising: receiving layer 1 (Ll) and / or layer 2 (L2) signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and a network entity, wherein the Ll signaling comprises downlink control information (DCI) and the L2 signaling comprises a medium access control (MAC)-control element (CE); communicating with the network entity according to a security key and using the one or more first PCIs, the security key being associated with a PCI; and receiving another Ll and / or L2 signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, wherein a same security key is used for communications using the one or more first PCIs and the one or more second PCIs in a case that the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU).

2. The method of claim 1, further comprising: initiating a random access channel (RACH) procedure, wherein the Ll and / or L2 signaling comprises a RACH message of the RACH procedure.

3. The method of claim 1, wherein the security key is determined based on an absolute radio frequency channel number associated with the PCI.

4. The method of claim 1, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs unless the network entity indicates a different PCI associated with a security key for communicating using the one or more second PCIs.

5. The method of claim 1, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises a default PCI of the plurality of PCIs.

6. The method of claim 1, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs having a lowest or highest identifier (ID).

7. The method of claim 1, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs that is used for communications first in time.

8. The method of claim 1, further comprising receiving an indication of the PCI associated with the security key from the network entity.

9. The method of claim 8, wherein the PCI is one of the one or more first PCIs indicated via the Ll and / or L2 signaling.

10. The method of claim 8, wherein the PCI is different from the one or more first PCIs indicated via the Ll and / or L2 signaling.

11. The method of claim 8, wherein the Ll and / or L2 signaling comprises a cell selection command for the switch of the UE to the one or more first PCIs, the cell selection command further comprising an indication of the PCI associated with the security key.

12. The method of claim 1, further comprising: receiving one or more other L1 and / or L2 signaling, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE; and determining another security key after receiving each of the one or more other L1 and / or L2 signaling to be used for communications by the UE using the one or more second PCIs.

13. The method of claim 1, further comprising: receiving a configuration of a plurality of candidate PCIs; and deriving a security key for each of the plurality of candidate PCIs, wherein communicating with the network entity comprises communicating with the network entity according to one of the derived security keys associated with the one or more first PCIs.

14. The method of claim 13, wherein the one or more first PCIs comprises a single PCI, the one of the derived security keys is associated with the single PCI.

15. A method for wireless communications by a network entity, comprising: transmitting, to a user equipment (UE), layer 1 (L1) and / or layer 2 (L2) signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and the network entity, wherein the L1 signaling comprises downlink control information (DCI) and the L2 signaling comprises a medium access control (MAC)-control element (CE); communicating with the UE according to a security key and using the one or more first PCIs, the security key being associated with a PCI; and transmitting another L1 and / or L2 signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs in a case that the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU).

16. The method of claim 15, wherein the security key is determined based on an absolute radio frequency channel number associated with the PCI.

17. The method of claim 15, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs unless the network entity indicates to the UE that a different PCI is to be associated with a security key for communications using the one or more second PCIs.

18. The method of claim 15, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises a default PCI of the plurality of PCIs.

19. The method of claim 15, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI used to determine the security key comprises one of the plurality of PCIs having a lowest or highest identifier (ID).

20. The method of claim 15, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs that is used for communications first in time.

21. The method of claim 15, further comprising transmitting, to the UE, an indication of a PCI associated with the security key.

22. The method of claim 21, wherein the PCI is one of the one or more first PCIs indicated via the LI and / or L2 signaling.

23. The method of claim 21, wherein the LI and / or L2 signaling comprises a cell selection command for the UE to switch to the one or more first PCIs, the cell selection command further comprising an indication of a PCI associated with the security key.

24. The method of claim 15, further comprising: transmitting one or more other LI and / or L2 signaling each indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE; and determining another security key to use after each of the one or more other LI and / or L2 signaling of communications by the UE using the one or more second PCIs.

25. The method of claim 15, further comprising transmitting, to the UE, a configuration of a plurality of candidate PCIs.

26. An apparatus for wireless communication by a user equipment (UE), comprising: a memory; and one or more processors coupled to the memory, the memory and the one or more processors configured to: receive layer 1 (LI) and / or layer 2 (L2) signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and a network entity, wherein the LI signaling comprises downlink control information (DCI) and the L2 signaling comprises a medium access control (MAC)-control element (CE); communicate with the network entity according to a security key and using the one or more first PCIs, the security key being associated with a PCI; and receive another LI and / or L2 signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, wherein in a case that the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU), a same security key is used for communications using the one or more first PCIs and the one or more second PCIs.

27. The apparatus of claim 26, the memory and the one or more processors further configured to initiate a random access channel (RACH) procedure, wherein the LI and / or L2 signaling comprises a RACH message of the RACH procedure.

28. The apparatus of claim 26, wherein the security key is determined based on an absolute radio frequency channel number associated with the PCI. ​ ​ 29. The apparatus of claim 26, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs unless the network entity indicates a different PCI associated with a security key for communications using the one or more second PCIs.

30. The apparatus of claim 26, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises a default PCI of the plurality of PCIs.

31. The apparatus of claim 26, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs having a lowest or highest identifier (ID).

32. The apparatus of claim 26, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs used for communications first in time.

33. The apparatus of claim 26, the memory and the one or more processors being further configured to receive, from the network entity, an indication of a PCI associated with the security key.

34. The apparatus of claim 33, wherein the PCI is one of the one or more first PCIs indicated via the LI and / or L2 signaling.

35. The apparatus of claim 33, wherein the PCI is different from the one or more first PCIs indicated via the LI and / or L2 signaling.

36. The apparatus of claim 33, wherein the LI and / or L2 signaling comprises a cell selection command for a switch of the UE to the one or more first PCIs, the cell selection command further comprising an indication of the PCI associated with the security key.

37. The apparatus of claim 26, the memory and the one or more processors being further configured to: receive one or more other LI and / or L2 signaling, each signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE; and determine another security key upon receiving each of the one or more other LI and / or L2 signaling to be used for communications by the UE using the one or more second PCIs.

38. The apparatus of claim 26, the memory and the one or more processors being further configured to: receive a configuration of a plurality of candidate PCIs; and derive a security key for each of the plurality of candidate PCIs, wherein communicating with the network entity comprises communicating with the network entity according to one of the derived security keys associated with the one or more first PCIs.

39. The apparatus of claim 38, wherein the one or more first PCIs comprise a single PCI, the one of the derived security keys being associated with the single PCI.

40. An apparatus for wireless communication by a network entity, comprising: a memory; and one or more processors coupled to the memory, the memory and the one or more processors configured to: transmit, to a user equipment (UE), layer 1 (L1) and / or layer 2 (L2) signaling indicating that the UE is to switch to one or more first physical cell identifiers (PCIs) to be used for communications between the UE and the network entity, wherein the L1 signaling comprises downlink control information (DCI) and the L2 signaling comprises a medium access control (MAC)-control element (CE); communicate with the UE according to a security key and using the one or more first PCIs, the security key being associated with the PCIs; and transmit another L1 and / or L2 signaling indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs in a case that the one or more first PCIs and the one or more second PCIs are managed by a same central unit (CU).

41. The apparatus of claim 40, wherein the security key is determined based on an absolute radio frequency channel number associated with the PCIs.

42. The apparatus of claim 40, wherein the same security key is used for communications using the one or more first PCIs and the one or more second PCIs unless the network entity indicates to the UE that a different PCI is to be associated with a security key for communications using the one or more second PCIs.

43. The apparatus of claim 40, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises a default PCI of the plurality of PCIs.

44. The apparatus of claim 40, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI used to determine the security key comprises one of the plurality of PCIs having a lowest or highest identifier (ID).

45. The apparatus of claim 40, wherein: the one or more first PCIs comprise a plurality of PCIs, and wherein the PCI associated with the security key comprises one of the plurality of PCIs that is used for communications first in time.

46. The apparatus of claim 40, the memory and the one or more processors being further configured to transmit, to the UE, an indication of the PCI associated with the security key.

47. The apparatus of claim 46, wherein the PCI is one of the one or more first PCIs indicated via the L1 and / or L2 signaling.

48. The apparatus of claim 46, wherein the L1 and / or L2 signaling comprises a cell selection command for the switch of the UE to the one or more first PCIs, the cell selection command further comprising an indication of the PCI associated with the security key.

49. The apparatus of claim 40, the memory and the one or more processors being further configured to: transmitting one or more other L1 and / or L2 signaling, each indicating that the UE is to switch to one or more second PCIs to be used for communications by the UE; and determining another security key to use after each of the one or more other L1 and / or L2 signaling of communications by the UE using the one or more second PCIs.

50. The apparatus of claim 40, the memory and one or more processors being further configured to transmit, to the UE, a configuration of a plurality of candidate PCIs.

Citation Information

Patent Citations

  • A radio access node and a method of operating the same

    US20180324160A1