Generate a security key for processing data transmission from a user device in an inactive state
By leveraging the RRC pause message and the next jump counter value in the wireless communication system, the node key is derived and the uplink message is descrambled, and the problem of how to generate and use a security key when the user equipment is in an inactive state is solved, and the security and flexibility of data transmission are achieved.
Patent Information
- Application Number
- CN202080104444.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-31
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2040-07-31
AI Technical Summary
In a wireless communication system, when the user equipment is inactive, a method is needed to generate a security key for protecting data transmission, especially if access layer resources are released.
By sending an RRC pause message from the first node, including the next jump counter value, releasing the associated access layer resource, derives the node key based on the NCC value, and receiving and descrambling uplink messages without allocating the AS resources.
It realizes that when the user equipment is inactive, data can be transmitted securely, confidentiality and integrity of the data can be ensured, and even when access layer resources are released.
Smart Images

Figure CN116114281B_ABST
Abstract
Description
Technical Field
[0001] This application relates to wireless devices, including apparatus, systems, and methods for generating, by a user equipment, a security key for use in data transmission with a node when the user equipment is in an inactive state. Background Art
[0002] The use of wireless communication systems is growing rapidly. In recent years, wireless devices such as smart phones and tablet computers have become increasingly sophisticated. In addition to supporting telephone calls, many mobile devices now also provide access to the Internet, email, text messaging, and navigation using the Global Positioning System (GPS), and are capable of operating sophisticated applications that utilize these functions. Additionally, there are many different wireless communication technologies and wireless communication standards. Some examples of wireless communication standards include GSM, UMTS (e.g., associated with the WCDMA or TD-SCDMA air interfaces), LTE, LTE-Advanced (LTE-A), HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), IEEE 802.11 (WLAN or Wi-Fi), BLUETOOTH TM etc.
[0003] The introduction of an increasing number of features and functions in wireless communication devices also requires continuous improvement of wireless communication and improvement of wireless communication devices. To increase coverage and better serve the increasing demands and scope of the intended use of wireless communication, in addition to the above communication standards, there are also wireless communication technologies under development, including fifth-generation (5G) New Radio (NR) communication. Therefore, there is a need to improve the fields that support such development and design. Summary of the Invention
[0004] Aspects of the present disclosure relate to apparatus, systems, and methods for deriving a security key that is used by a user equipment to protect transmissions to a node when the user equipment is in an inactive state.
[0005] In certain wireless systems, data between a user equipment and a central network (CN) can be encrypted independently and / or integrity protected between the UE and a specific node. These independent cipher layers and / or integrity protection help to achieve data security and privacy. In some cases, the UE can enter the Radio Resource Control (RRC) inactive state, whereby the non-access stratum (NAS) connection to the CN is maintained, but the access stratum (AS) resources are released. There is a need to allow the user equipment to transmit data while remaining in the RRC inactive state. Since the AS resources are released, there is a need to define a way to determine the encryption or integrity protection key to be used when the user equipment transmits UL data while remaining in the inactive state.
[0006] According to some aspects disclosed herein, a method for secure key derivation in a wireless system is provided, the method comprising: sending a Radio Resource Control (RRC) suspension message from a first node to a first user equipment, the RRC suspension message including a first Next Hop (NH) Chain Counter (NCC) value; releasing access stratum (AS) resources associated with the first user equipment; deriving a first node key based on the first NCC value; receiving a first uplink message from the first user equipment without allocating AS resources to the first user equipment; and descrambling the first uplink message based on the first NCC value.
[0007] In some aspects, the method may further include a case where a first uplink message is transmitted to a second node and a first node key is derived by the first node, and further includes: receiving a request from the second node for the first node key; and transmitting the first node key to the second node. In some aspects, the method may further include a case where a first uplink message is transmitted to the second node, and further includes transmitting a first NCC value to the second node, where the first node key is derived by the second node. In some aspects, the method may further include a case where, in response to a request from the second node for the first node key, a first NCC value is transmitted to the second node. In some aspects, the method may further include a case where the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and where the first node key is the same as the second node key. In some aspects, the method may further include a case where the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and where deriving the first node key includes horizontally deriving the first node key based on the second node key. In some aspects, the method may further include a case where the first NCC value is different from a second NCC value previously used to derive a second node key. In some aspects, the method may further include: transmitting first cell information from the first node, where the first node key is derived based on a first NCC value and the first cell information from the first node. In some aspects, the method may further include horizontally deriving a third node key based on the first node key. In some aspects, the method may further include: transmitting second cell information from the second node; deriving a third node key based on the first NCC value and the second cell information. In some aspects, the method may further include a case where the RRC suspension message includes a plurality of NCC values, and further includes: deriving a second node key based on a second NCC value among the plurality of NCC values; receiving a second uplink message from the first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the second node key. In some aspects, the method may further include: determining that each NCC value among the plurality of NCC values has been used to derive a node key; horizontally deriving a third node key based on the most recently used previous node key. In some aspects, the method may further include a case where it is determined that each NCC value among the plurality of NCC values has been used to derive a node key; vertically deriving a third node key based on the most recently used previous node key. In some aspects, the method may further include: transmitting a second NCC value from the second node; deriving a second node key based on the second NCC value; receiving a second uplink message from the first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the second node key.
[0008] The techniques described herein can be implemented in and / or used with multiple different types of devices, including but not limited to any one of cellular phones, wireless devices, tablet computers, wearable computing devices, portable media players, and various other computing devices.
[0009] This summary is intended to provide a brief overview of some of the subject matter described in this document. Accordingly, it should be understood that the above features are merely examples and should not be construed in any way as narrowing the scope or essence of the subject matter described herein. Other features, aspects, and advantages of the subject matter described herein will become apparent from the following detailed description, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] A better understanding of the subject matter can be obtained when the following detailed description of the various aspects is considered in conjunction with the following drawings, in which:
[0011] Figure 1 An exemplary wireless communication system in accordance with aspects of the present disclosure is shown.
[0012] Figure 2 A base station (BS) communicating with a user equipment (UE) device in accordance with aspects of the present disclosure is shown.
[0013] Figure 3 An exemplary block diagram of a UE in accordance with aspects of the present disclosure is shown.
[0014] Figure 4 An exemplary block diagram of a BS in accordance with aspects of the present disclosure is shown.
[0015] Figure 5 An exemplary block diagram of a cellular communication circuit in accordance with aspects of the present disclosure is shown.
[0016] Figure 6 An exemplary block diagram of a network element in accordance with aspects of the present disclosure is shown.
[0017] Figures 7 to 8 A communication flow diagram showing communication flows for entering and resuming from the RRC inactive state in accordance with aspects of the present disclosure.
[0018] Figure 9 A diagram showing key derivation in accordance with aspects of the present disclosure.
[0019] Figures 10 to 20 A communication flow diagram showing an exemplary technique for key generation for inactive state data transmission in accordance with aspects of the present disclosure.
[0020] Figure 21Is a flowchart showing techniques for generating keys by a user equipment for inactive state data transmission according to aspects of the present disclosure.
[0021] Figure 22 Is a flowchart showing techniques for generating additional keys by a user equipment for inactive state data transmission according to aspects of the present disclosure.
[0022] Figure 23 Is a flowchart showing techniques for generating additional keys by a user equipment for inactive state data transmission according to aspects of the present disclosure.
[0023] Figure 24 Is a flowchart showing techniques for generating keys by a node for inactive state data transmission according to aspects of the present disclosure.
[0024] Figure 25 Is a flowchart showing techniques for generating additional keys by a node for inactive state data transmission according to aspects of the present disclosure.
[0025] Figure 26 Is a flowchart showing techniques for generating additional keys by a node for inactive state data transmission according to aspects of the present disclosure.
[0026] Although the features described herein may be subject to various modifications and alternative forms, specific aspects thereof are shown by way of example in the drawings and described in detail herein. However, it should be understood that the drawings and the detailed description thereof are not intended to limit the present disclosure to the specific forms disclosed, but on the contrary, are intended to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the subject matter as defined by the appended claims. Detailed Description
[0027] The following is a glossary of terms that may be used in the present disclosure:
[0028] Memory medium—Any of various types of non-transitory memory devices or storage devices. The term "memory medium" is intended to include installation media such as CD-ROMs, floppy disks, or magnetic tape devices; computer system memory or random access memory such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory such as flash memory, magnetic media such as hard disk drives or optical storage devices; registers or other similar types of memory elements, etc. The memory medium may also include other types of non-transitory memory or combinations thereof. Additionally, the memory medium may be located in a first computer system that executes a program, or may be located in a different second computer system that is connected to the first computer system via a network such as the Internet. In the latter case, the second computer system may provide program instructions to the first computer for execution. The term "memory medium" may include two or more memory media that may reside at different locations in different computer systems connected, for example, via a network. The memory medium may store program instructions (e.g., embodied as a computer program) executable by one or more processors.
[0029] Carrier medium—The storage medium as described above and physical transmission media such as buses, networks, and / or other physical transmission media that convey signals such as electrical, electromagnetic, or digital signals.
[0030] Programmable hardware element—Includes various hardware devices that include a plurality of programmable function blocks connected via programmable interconnects. Examples include FPGAs (Field Programmable Gate Arrays), PLDs (Programmable Logic Devices), FPOAs (Field Programmable Object Arrays), and CPLDs (Complex PLDs). The programmable function blocks can vary from fine-grained (combinational logic components or look-up tables) to coarse-grained (arithmetic logic units or processor cores). Programmable hardware elements may also be referred to as "configurable logic components".
[0031] Computer system—Any of various types of computing or processing systems, including personal computer systems (PCs), mainframe computer systems, workstations, network appliances, Internet appliances, personal digital assistants (PDAs), television systems, grid computing systems, or other devices or combinations of devices. Generally speaking, the term "computer system" can be broadly defined to cover any device (or combination of devices) having at least one processor that executes instructions from a memory medium.
[0032] User equipment (UE) (or "UE device")—Any of various types of computer systems or devices that are mobile or portable and perform wireless communication. Examples of UE devices include mobile phones or smartphones (e.g., iPhone TM 、based on AndroidTM telephone), portable gaming devices (e.g., Nintendo DS TM , PlayStation Portable TM , Gameboy Advance TM , iPhone TM ), laptop computers, wearable devices (e.g., smartwatches, smart glasses), PDAs, portable Internet devices, music players, data storage devices, or other handheld devices, etc. Generally speaking, the term "UE" or "UE device" can be broadly defined to cover any electronic device, computing device, and / or telecommunications device (or combination of devices) that is easily transported by a user and capable of wireless communication.
[0033] Wireless device—Any one of various types of computer systems or devices that perform wireless communication. The wireless device can be portable (or mobile), or can be stationary or fixed in a certain location. A UE is an example of a wireless device.
[0034] Communication device—Any one of various types of computer systems or devices that perform communication, where the communication can be wired or wireless. The communication device can be portable (or mobile), or can be stationary or fixed in a certain location. A wireless device is an example of a communication device. A UE is another example of a communication device.
[0035] Base station—The term "base station" has the full scope of its ordinary meaning and includes at least a wireless communication station that is installed in a fixed location and used for communication as part of a wireless telephone system or radio system. For example, if a base station is implemented in the context of LTE, it can alternatively be referred to as an "eNodeB" or "eNB". If a base station is implemented in the context of 5G NR, it can alternatively be referred to as a "gNodeB" or "gNB". Although certain aspects are described in the context of LTE or 5G NR, references to "eNB", "gNB", "nodeB", "base station", "NB", etc. can also refer to one or more wireless nodes that serve a cell to provide a wireless connection between a user equipment and a generally wider network, and the concepts discussed are not limited to any specific wireless technology. Although certain aspects are described in the context of LTE or 5G NR, references to "eNB", "gNB", "nodeB", "base station", "NB", etc. are not intended to limit the concepts discussed herein to any specific wireless technology, and the concepts discussed can be applied to any wireless system.
[0036] Node—As used herein, the term "node" can refer to one or more devices associated with a cell that provides a wireless connection between a user equipment and a generally wider network.
[0037] Processing element (or processor) - refers to various elements or combinations of elements that can perform functions in a device such as a user equipment or a cellular network device. A processing element may include, for example: a processor and associated memory, portions or circuits of individual processor cores, entire processor cores, individual processors, processor arrays, circuits such as ASICs (Application Specific Integrated Circuits), programmable hardware elements such as field programmable gate arrays (FPGAs), and any of the various combinations above.
[0038] Channel - a medium for transmitting information from a transmitter to a receiver. It should be noted that since the characteristics of the term "channel" can vary according to different wireless protocols, the term "channel" used in the present invention can be considered to be used in a manner that conforms to the standards of the type of device to which the term usage refers. In some standards, the channel width can be variable (e.g., depending on device capabilities, frequency band conditions, etc.). For example, LTE can support scalable channel bandwidths from 1.4 MHz to 20 MHz. In contrast, a WLAN channel can be 22 MHz wide, while a Bluetooth channel can be 1 MHz wide. Other protocols and standards may include different definitions of channels. In addition, some standards may define and use multiple types of channels, such as different channels for uplink or downlink and / or different channels for different purposes such as data, control information, etc.
[0039] Frequency band - the term "frequency band" has the full range of its ordinary meaning and at least includes a segment of the spectrum (e.g., radio frequency spectrum) in which channels are used or set aside for the same purpose.
[0040] Automatically - refers to the performance of an action or operation by a computer system (e.g., software executed by a computer system) or a device (e.g., a circuit, a programmable hardware element, an ASIC, etc.) without the action or operation being directly specified or performed through user input. Thus, the term "automatically" is contrary to an operation performed or specified manually by a user, where the user provides input to directly perform the operation. An automatic process can be initiated by input provided by the user, but the subsequent actions performed "automatically" are not specified by the user, i.e., are not performed "manually", where the user specifies each action to be performed. For example, a user filling out a spreadsheet by selecting each field and providing input to specify information (e.g., by typing information, selecting checkboxes, radio selections, etc.) is manually filling out the form, even though the computer system must update the form in response to the user's actions. The form can be filled out automatically by a computer system, where the computer system (e.g., software executed on a computer system) analyzes the fields of the form and fills out the form without any user input specifying the answers to the fields. As indicated above, the user can invoke the automatic filling of the form but does not participate in the actual filling of the form (e.g., the user does not manually specify the answers to the fields but they are completed automatically). This specification provides various examples of operations that are automatically performed in response to actions taken by a user.
[0041] About - refers to a value that is close to the correct or exact value. For example, about can refer to a value within 1% to 10% of the exact (or desired) value. However, it should be noted that the actual threshold (or tolerance) can depend on the application. For example, in some aspects, "about" can mean within 0.1% of some specified or desired value, while in various other aspects, depending on the expectations or requirements of a particular application, the threshold can be, for example, 2%, 3%, 5%, etc.
[0042] Concurrent - refers to the parallel execution or implementation, where tasks, processes, or programs are executed in at least a partially overlapping manner. For example, "strong" or strict parallelism can be used to achieve concurrency, where tasks are executed (at least partially) in parallel on corresponding computing elements; or "weak parallelism" can be used to achieve concurrency, where tasks are executed in an interleaved manner (e.g., through time multiplexing of execution threads).
[0043] Configured to - Various components can be described as "configured to" perform one or more tasks. In such an environment, "configured to" is a broad statement that generally means "having" the "structure" to perform one or more tasks during operation. Thus, even when the component is not currently performing a task, the component can be configured to perform the task (e.g., a set of electrical conductors can be configured to electrically connect a module to another module even when the two modules are not connected). In some contexts, "configured to" can be a broad statement that generally means "having" the "circuitry" to perform one or more tasks during operation. Thus, even when the component is not currently powered on, the component can be configured to perform the task. Generally, the circuitry that forms the structure corresponding to "configured to" can include hardware circuitry.
[0044] For ease of description, various components can be described as performing one or more tasks. Such a description should be interpreted to include the phrase "configured to". A component described as configured to perform one or more tasks is expressly intended not to invoke the § 112(f) interpretation of that component under 35 U.S.C.
[0045] Exemplary wireless communication system
[0046] Now turning to Figure 1 , a simplified example of a wireless communication system in accordance with some aspects is shown. Note that Figure 1 the system of
[0047] As shown, the exemplary wireless communication system includes a base station 102A that communicates with one or more user devices 106A, user devices 106B through user devices 106N, etc. via a transmission medium. Each user device may be referred to herein as a "user equipment" (UE). Thus, the user device 106 is referred to as a UE or a UE device.
[0048] The base station (BS) 102A can be a transceiver base station (BTS) or a cell site ("cellular base station") and can include hardware that enables wireless communication with UEs 106A through 106N.
[0049] The communication area (or coverage area) of a base station can be referred to as a "cell". The base station 102A and the user equipment 106 can be configured to communicate via a transmission medium using any one of various radio access technologies (RATs), which are also known as wireless communication technologies or telecommunication standards, such as GSM, UMTS (associated with, for example, WCDMA or TD-SCDMA air interfaces), LTE, LTE-Advanced (LTE-A), 5G New Radio (5G NR), HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), etc.
[0050] As shown, the base station 102A can also be equipped to communicate with the network 100 (e.g., among various possibilities, the core network of a cellular service provider, a telecommunication network such as a public switched telephone network (PSTN) and / or the Internet). Thus, the base station 102A can facilitate communication between user equipments and / or between user equipments and the network 100. In particular, the cellular base station 102A can provide the UE 106 with various communication capabilities such as voice, SMS, and / or data services.
[0051] The base station 102A and other similar base stations operating according to the same or different cellular communication standards (such as base stations 102B......102N) can thus be provided as a network of cells, which can provide continuous or almost continuous overlapping services to the UE 106A-N and similar devices over a geographical area via one or more cellular communication standards.
[0052] Thus, although the base station 102A can act as the "serving cell" of the UE 106A-N as shown in Figure 1 , each UE 106 may also be able to receive signals (and potentially be within its communication range) from one or more other cells (which can be provided by the base stations 102B-N and / or any other base stations), and these one or more other cells can be referred to as "neighboring cells". Such cells may also be able to facilitate communication between user equipments and / or between user equipments and the network 100. Such cells can include "macro" cells, "micro" cells, "pico" cells, and / or any various other granularities of cells providing service area sizes. For example, the base stations 102A to 102B shown in Figure 1 can be macro cells, while the base station 102N can be a micro cell. Other configurations are also possible.
[0053] In some aspects, base station 102A may be a next-generation base station, e.g., a 5G New Radio (5G NR) base station or a "gNB". In some aspects, the gNB may be connected to a traditional Evolved Packet Core (EPC) network and / or connected to a NR Core (NRC) / 5G Core (5GC) network. Additionally, a gNB cell may include one or more Transmission and Reception Points (TRPs). Further, a UE capable of operating according to 5G NR may be connected to one or more TRPs within one or more gNBs. For example, base station 102A and one or more other base stations 102 may support joint transmission such that UE 106 may be able to receive transmissions from multiple base stations (and / or multiple TRPs provided by the same base station). For example, as Figure 1 shown, both base station 102A and base station 102C are shown as serving UE 106A.
[0054] Note that UE 106 is capable of communicating using multiple wireless communication standards. For example, in addition to at least one cellular communication protocol (e.g., GSM, UMTS (associated with, e.g., WCDMA or TD-SCDMA air interfaces), LTE, LTE-A, 5G NR, HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), etc.), UE 106 may be configured to communicate using wireless networking (e.g., Wi-Fi) and / or peer-to-peer wireless communication protocols (e.g., Bluetooth, Wi-Fi peer-to-peer, etc.). If desired, UE 106 may also or alternatively be configured to communicate using one or more Global Navigation Satellite Systems (GNSS, e.g., GPS or GLONASS), one or more mobile television broadcast standards (e.g., Advanced Television Systems Committee-Mobile / Handheld (ATSC-M / H)), and / or any other wireless communication protocol. Other combinations of wireless communication standards (including more than two wireless communication standards) are also possible.
[0055] Exemplary User Equipment (UE)
[0056] Figure 2 illustrates user equipment 106 (e.g., one of devices 106A to 106N) communicating with base station 102 according to some aspects. UE 106 may be a device with cellular communication capabilities, such as a mobile phone, a handheld device, a computer, a laptop, a tablet, a smartwatch, or other wearable device or indeed any type of wireless device.
[0057] UE 106 may include a processor (processing element) configured to execute program instructions stored in a memory. UE 106 may perform any of the method aspects described herein by executing such stored instructions. Alternatively or additionally, UE 106 may include programmable hardware elements such as an FPGA (Field Programmable Gate Array), an integrated circuit, and / or any of various other possible hardware components configured to perform (e.g., individually or in combination) any of the method aspects described herein or any part of any of the method aspects described herein.
[0058] UE 106 may include one or more antennas for communicating using one or more wireless communication protocols or technologies. In some aspects, UE 106 may be configured to communicate using, for example, NR or LTE using at least some shared radio components. As an additional possibility, the UE 106 may be configured to communicate using CDMA2000 (1xRTT / 1xEV-DO / HRPD / eHRPD) or LTE using a single shared radio component and / or using GSM or LTE using a single shared radio component. The shared radio may be coupled to a single antenna or may be coupled to multiple antennas (e.g., for MIMO) for performing wireless communication. Generally, the radio components may include any combination of a baseband processor, analog radio frequency (RF) signal processing circuitry (e.g., including filters, mixers, oscillators, amplifiers, etc.), or digital processing circuitry (e.g., for digital modulation and other digital processing). Similarly, the radio components may use the foregoing hardware to implement one or more receive chains and transmit chains. For example, UE 106 may share one or more portions of a receive chain and / or a transmit chain among multiple wireless communication technologies such as those discussed above.
[0059] In some aspects, UE 106 may include separate transmit chains and / or receive chains (e.g., including separate antennas and other radio components) for each wireless communication protocol it is configured to communicate with. As another possibility, UE 106 may include one or more radio components shared among multiple wireless communication protocols and one or more radio components uniquely used by a single wireless communication protocol. For example, UE 106 may include shared radio components for communicating using either LTE or 5G NR (or, among various possibilities, either LTE or 1xRTT, or either LTE or GSM) and separate radio components for communicating using each of Wi-Fi and Bluetooth. Other configurations are possible.
[0060] Exemplary communication device
[0061] Figure 3An exemplary simplified block diagram of a communication device 106 in accordance with some aspects is shown. Note that Figure 3 the block diagram of the communication device is only one example of a possible communication device. In accordance with various aspects, in addition to other devices, the communication device 106 can be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop, notebook or portable computing device), a tablet, and / or a combination of devices. As shown, the communication device 106 can include a set of components 300 configured to perform core functions. For example, the set of components can be implemented as a system on a chip (SOC), which can include portions for various purposes. Alternatively, the set of components 300 can be implemented as separate components or groups of components for various purposes. This set of components 300 can be (e.g., communicatively; directly or indirectly) coupled to various other circuits of the communication device 106.
[0062] For example, the communication device 106 can include various types of memory (e.g., including NAND flash 310), input / output interfaces such as a connector I / F 320 (e.g., for connecting to a computer system; a docking station; a charging station; an input device, such as a microphone, a camera, a keyboard; an output device, such as a speaker; etc.), a display 360 that can be integrated with or external to the communication device 106, and wireless communication circuitry 330 (e.g., for LTE, LTE-A, NR, UMTS, GSM, CDMA2000, Bluetooth, Wi-Fi, NFC, GPS, etc.). In some aspects, the communication device 106 can include wired communication circuitry (not shown), such as, for example, a network interface card for Ethernet.
[0063] The wireless communication circuitry 330 can be (e.g., communicatively; directly or indirectly) coupled to one or more antennas, such as one or more antennas 335 as shown. The wireless communication circuitry 330 can include cellular communication circuitry and / or mid-short range wireless communication circuitry, and can include multiple receive chains and / or multiple transmit chains for receiving and / or transmitting multiple spatial streams, such as in a multiple-input multiple-output (MIMO) configuration.
[0064] In some aspects, as further described below, the cellular communication circuitry 330 may include one or more receive chains of multiple RATs (including and / or coupled to (e.g., communicatively; directly or indirectly) dedicated processors and / or radio components (e.g., a first receive chain for LTE and a second receive chain for 5G NR). Additionally, in some aspects, the cellular communication circuitry 330 may include a single transmit chain that may switch between radio components dedicated to a particular RAT. For example, a first radio component may be dedicated to a first RAT (e.g., LTE) and may communicate with a dedicated receive chain and a transmit chain shared with a second radio component. The second radio component may be dedicated to a second RAT (e.g., 5G NR) and may communicate with a dedicated receive chain and the shared transmit chain.
[0065] The communication device 106 may also include one or more user interface elements and / or be configured to work with one or more user interface elements. The user interface elements may include various elements such as a display 360 (which may be a touchscreen display), a keyboard (which may be a discrete keyboard or may be implemented as part of a touchscreen display), a mouse, a microphone and / or a speaker, one or more cameras, one or more buttons, and / or any of various other elements capable of providing information to a user and / or receiving or interpreting user input.
[0066] The communication device 106 may also include one or more smart cards 345 having SIM (Subscriber Identity Module) functionality, such as one or more UICC cards (one or more Universal Integrated Circuit Cards) 345.
[0067] As shown, the SOC 300 may include a processor 302 and a display circuit 304. The processor may execute program instructions for the communication device 106, and the display circuit may perform graphics processing and provide a display signal to the display 360. One or more processors 302 may also be coupled to a memory management unit (MMU) 340 (which may be configured to receive addresses from one or more processors 302 and translate those addresses into locations in memory (e.g., memory 306, read-only memory (ROM) 350, NAND flash memory 310)), and / or coupled to other circuits or devices (such as the display circuit 304, the wireless communication circuitry 330, the connector I / F 320, and / or the display 360). The MMU 340 may be configured to perform memory protection and page table translation or setup. In some aspects, the MMU 340 may be included as part of the processor 302.
[0068] As described above, the communication device 106 may be configured to communicate using wireless and / or wired communication circuitry. As described herein, the communication device 106 may include hardware and software components for implementing any of the various features and techniques described herein. For example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), the processor 302 of the communication device 106 may be configured to implement some or all of the features described in the present invention. Alternatively (or in addition), the processor 302 may be configured as a programmable hardware element, such as a FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit). Alternatively (or in addition), in combination with one or more of the other components 300, 304, 306, 310, 320, 330, 340, 345, 350, 360, the processor 302 of the communication device 106 may be configured to implement some or all of the features described herein.
[0069] In addition, as described in the present invention, the processor 302 may include one or more processing elements. Thus, the processor 302 may include one or more integrated circuits (ICs) configured to perform the functions of the processor 302. In addition, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform one or more of the functions of the processor 302.
[0070] In addition, as described herein, the wireless communication circuitry 330 may include one or more processing elements. In other words, one or more processing elements may be included in the wireless communication circuitry 330. Thus, the wireless communication circuitry 330 may include one or more integrated circuits (ICs) configured to perform the functions of the wireless communication circuitry 330. In addition, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the wireless communication circuitry 330.
[0071] Exemplary Base Station
[0072] Figure 4 An exemplary block diagram of a base station 102 is shown in accordance with some aspects. Note that Figure 4 the base station shown is only one example of a possible base station. As shown, the base station 102 may include a processor 404 that may execute program instructions for the base station 102. The processor 404 may also be coupled to a memory management unit (MMU) 440 or other circuit or device, which may be configured to receive addresses from the processor 404 and translate those addresses to locations in a memory (e.g., memory 460 and read-only memory (ROM) 450).
[0073] The base station 102 may include at least one network port 470. The network port 470 may be configured to couple to a telephone network and provide access to Figure 1 andFigure 2 Multiple devices of the telephone network described in
[0074] The network port 470 (or an additional network port) may also be configured or alternatively configured to be coupled to a cellular network, such as the core network of a cellular service provider. The core network may provide mobility-related services and / or other services to multiple devices such as UE device 106. In some cases, the network port 470 may be coupled to the telephone network via the core network, and / or the core network may provide the telephone network (e.g., in other UE devices served by the cellular service provider).
[0075] In some aspects, the base station 102 may be a next-generation base station, e.g., a 5G New Radio (5G NR) base station or a "gNB". In such aspects, the base station 102 may be connected to a traditional Evolved Packet Core (EPC) network and / or connected to an NR Core (NRC) / 5G Core (5GC) network. Additionally, the base station 102 may be regarded as a 5G NR cell and may include one or more Transmission and Reception Points (TRPs). Furthermore, a UE capable of operating according to 5G NR may be connected to one or more TRPs within one or more gNBs.
[0076] The base station 102 may include at least one antenna 434 and possibly multiple antennas. The at least one antenna 434 may be configured to function as a wireless transceiver and may be further configured to communicate with the UE device 106 via the radio component 430. The antenna 434 communicates with the radio component 430 via the communication link 432. The communication link 432 may be a receive link, a transmit link, or both. The radio component 430 may be configured to communicate via various wireless communication standards, which include but are not limited to 5G NR, LTE, LTE-A, GSM, UMTS, CDMA2000, Wi-Fi, etc.
[0077] The base station 102 may be configured to perform wireless communication using multiple wireless communication standards. In some cases, the base station 102 may include multiple radios that enable the base station 102 to communicate according to multiple wireless communication technologies. For example, as a possibility, the base station 102 may include an LTE radio component for performing communication according to LTE and a 5G NR radio component for performing communication according to 5G NR. In this case, the base station 102 may be capable of operating as both an LTE base station and a 5G NR base station. As another possibility, the base station 102 may include a multi-mode radio component capable of performing communication according to any one of multiple wireless communication technologies (e.g., 5G NR and LTE, 5G NR and Wi-Fi, LTE and Wi-Fi, LTE and UMTS, LTE and CDMA2000, UMTS and GSM, etc.).
[0078] As further described hereinafter, BS 102 may include hardware and software components for implementing or supporting the specific implementations of the features described herein. The processor 404 of the base station 102 may be configured to implement or support the implementation of part or all of the methods described herein, for example, by executing program instructions stored in a memory medium (e.g., a non-transitory computer-readable memory medium). Alternatively, the processor 404 may be configured as a programmable hardware element such as an FPGA (Field Programmable Gate Array), or as an ASIC (Application Specific Integrated Circuit), or a combination thereof. Alternatively (or in addition), in combination with one or more of the other components 430, component 432, component 434, component 440, component 450, component 460, component 470, the processor 404 of the base station 102 may be configured to implement or support the implementation of part or all of the features described herein.
[0079] Furthermore, as described in the present invention, one or more processors 404 may include one or more processing elements. Thus, the processor 404 may include one or more integrated circuits (ICs) configured to perform the functions of the processor 404. In addition, each integrated circuit may include circuits (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of one or more processors 404.
[0080] Furthermore, as described in the present invention, the radio component 430 may include one or more processing elements. Thus, the radio component 430 may include one or more integrated circuits (ICs) configured to perform the functions of the radio component 430. In addition, each integrated circuit may include circuits (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the radio component 430.
[0081] Exemplary cellular communication circuitry
[0082] Figure 5 An exemplary simplified block diagram of a cellular communication circuit according to some aspects is shown. Note that Figure 5 the block diagram of the cellular communication circuit is merely an example of a possible cellular communication circuit; other circuits, such as a circuit including or coupled to a sufficient number of antennas for different RATs to perform uplink activities using independent antennas, or a circuit including or coupled to fewer antennas, e.g., a circuit that can be shared among multiple RATs, are also possible. According to some aspects, the cellular communication circuit 330 may be included in a communication device such as the communication device 106 described above. As described above, in addition to other devices, the communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop computer, notebook or portable computing device), a tablet computer, and / or a combination of devices.
[0083] The cellular communication circuitry 330 may be (e.g., communicatively; directly or indirectly) coupled to one or more antennas, such as antennas 335a-b and 336 as shown. In some aspects, the cellular communication circuitry 330 may include dedicated receive chains for multiple RATs, including and / or coupled to (e.g., communicatively; directly or indirectly) dedicated processors and / or radio components (e.g., a first receive chain for LTE and a second receive chain for 5G NR). For example, as Figure 5 shown, the cellular communication circuitry 330 may include a first modem 510 and a second modem 520. The first modem 510 may be configured for communication according to a first RAT (e.g., such as LTE or LTE-A), and the second modem 520 may be configured for communication according to a second RAT (e.g., such as 5G NR).
[0084] As shown, the first modem 510 may include one or more processors 512 and a memory 516 communicative with the processors 512. The modem 510 may communicate with a radio frequency (RF) front end 530. The RF front end 530 may include circuitry for transmitting and receiving radio signals. For example, the RF front end 530 may include a receive circuit (RX) 532 and a transmit circuit (TX) 534. In some aspects, the receive circuit 532 may communicate with a downlink (DL) front end 550, which may include circuitry for receiving radio signals via antenna 335a.
[0085] Similarly, the second modem 520 may include one or more processors 522 and a memory 526 communicative with the processors 522. The modem 520 may communicate with an RF front end 540. The RF front end 540 may include circuitry for transmitting and receiving radio signals. For example, the RF front end 540 may include a receive circuit 542 and a transmit circuit 544. In some aspects, the receive circuit 542 may communicate with a DL front end 560, which may include circuitry for receiving radio signals via antenna 335b.
[0086] In some aspects, switch 570 may couple the transmit circuit 534 to the uplink (UL) front end 572. Additionally, switch 570 may couple the transmit circuit 544 to the UL front end 572. The UL front end 572 may include circuitry for transmitting radio signals via antenna 336. Thus, when the cellular communication circuit 330 receives an instruction to transmit according to a first RAT (e.g., supported via the first modem 510), switch 570 may be switched to a first state that allows the first modem 510 to transmit signals according to the first RAT (e.g., via a transmit chain including the transmit circuit 534 and the UL front end 572). Similarly, when the cellular communication circuit 330 receives an instruction to transmit according to a second RAT (e.g., supported via the second modem 520), switch 570 may be switched to a second state that allows the second modem 520 to transmit signals according to the second RAT (e.g., via a transmit chain including the transmit circuit 544 and the UL front end 572).
[0087] As described herein, the first modem 510 and / or the second modem 520 may include hardware and software components for implementing any of the various features and techniques described herein. For example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), the processors 512, 522 may be configured to implement some or all of the features described herein. Alternatively (or in addition), the processors 512, 522 may be configured as programmable hardware elements, such as an FPGA (field-programmable gate array) or as an ASIC (application-specific integrated circuit). Alternatively (or in addition), in combination with one or more of the other components 530, 532, 534, 540, 542, 544, 550, 570, 572, 335, and 336, the processors 512, 522 may be configured to implement some or all of the features described herein.
[0088] Furthermore, as described herein, the processors 512, 522 may include one or more processing elements. Thus, the processors 512, 522 may include one or more integrated circuits (ICs) configured to perform the functions of the processors 512, 522. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the processors 512, 522.
[0089] In some aspects, the cellular communication circuitry 330 may include only one transmit / receive chain. For example, the cellular communication circuitry 330 may not include the modem 520, the RF front end 540, the DL front end 560, and / or the antenna 335b. As another example, the cellular communication circuitry 330 may not include the modem 510, the RF front end 530, the DL front end 550, and / or the antenna 335a. In some aspects, the cellular communication circuitry 330 may also not include the switch 570, and the RF front end 530 or the RF front end 540 may communicate with the UL front end 572, for example, directly.
[0090] Exemplary network element
[0091] Figure 6 An exemplary block diagram of a network element 600 is shown in accordance with some aspects. In accordance with some aspects, the network element 600 may implement one or more logical functions / entities of a cellular core network, such as a Mobility Management Entity (MME), a Serving Gateway (S-GW), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a Network Slice Quota Management (NSQM) function, etc. It should be noted that Figure 6 the network element 600 shown is only one example of a possible network element 600. As shown, the core network element 600 may include one or more processors 604 that may execute program instructions of the core network element 600. The processor 604 may also be coupled to a Memory Management Unit (MMU) 640 (which may be configured to receive addresses from the processor 604 and translate these addresses into locations in a memory, such as the memory 660 and the Read Only Memory (ROM) 650), or be coupled to other circuits or devices.
[0092] The network element 600 may include at least one network port 670. The network port 670 may be configured to couple to one or more base stations and / or other cellular network entities and / or devices. The network element 600 may communicate with base stations (e.g., eNB / gNB) and / or other network entities / devices via any of a variety of communication protocols and / or interfaces.
[0093] As further described hereinbelow, network element 600 may include hardware and software components for implementing or supporting embodiments of the features described herein. The processor 604 of the core network element 600 may be configured to implement or support embodiments of part or all of the methods described herein, for example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium). Alternatively, the processor 604 may be configured as a programmable hardware element such as an FPGA (Field Programmable Gate Array) or configured as an ASIC (Application Specific Integrated Circuit) or a combination thereof. The network element 600 may operate according to various methods disclosed herein for enabling a wireless device to perform cell measurements using configured reference signals in a cellular communication system when the wireless device is in an inactive state.
[0094] Radio Resource Control (RRC) idle state and inactive state
[0095] Multiple cellular communication technologies include using the Radio Resource Control (RRC) protocol (e.g., which may facilitate connection establishment and release, radio bearer establishment, reconfiguration, and release) and / or various other possible signaling functions that support the air interface between a wireless device and a cellular base station.
[0096] A wireless device may generally operate in one of a number of possible states with respect to RRC. For example, in LTE, a wireless device may operate in an RRC connected state (e.g., where the wireless device may perform continuous data transmission and where handovers between cells are managed by the network and the access stratum (AS) context information is reserved for the wireless device), or may operate in an RRC idle state (e.g., where the wireless device may operate in a more battery-efficient state when not performing continuous data transmission, where the wireless device may handle its cell reselection activities, and where the network may not reserve AS context information for the wireless device).
[0097] In addition to the RRC connected state and the RRC idle state, according to at least some aspects, one or more other types of RRC states for a wireless device may also be supported. For example, for NR, an RRC inactive state may be supported, in which the wireless device may be able to operate in a relatively battery-efficient state while the network still retains at least some AS context information. In some aspects, the wireless device may maintain a non-access stratum connection (NAS) to the CN and the RRC configuration as it was before the UE entered the inactive state. In some cases, dedicated AS resources may not be allocated to the UE in the inactive state. According to at least some aspects, such a state may be based on the mobility of the wireless device, e.g., such that the wireless device may move within a radio access network notification area (RNA) without notifying the next generation (NG) radio access network (RAN). While in this state, the wireless device may perform cell reselection and system information acquisition for itself. Meanwhile, the previous serving base station (e.g., gNB) may maintain the wireless device context and the NG connection to the 5G core network (CN) associated with the wireless device, e.g., to facilitate an easier transition back to the RRC connected state. When paging a wireless device in the RRC inactive state, the RAN may use RNA-specific parameters, e.g., including UE-specific DRX and UE identity index values (e.g., I-RNTI).
[0098] According to some aspects, e.g., when the wireless device moves out of its currently configured RNA to a different RNA, a wireless device operating in this RRC inactive state may perform RNA updates periodically (e.g., based on a configured periodic RNA update timer) and / or in an event-based manner.
[0099] In at least some cases, using the RRC inactive state may help reduce the network signaling overhead for a wireless device connection. For example, for wireless devices with infrequent data transmissions, using this RRC inactive state may reduce the amount of mobility-related signaling (e.g., for handovers) required compared to using the RRC connected state, e.g., because the wireless device may be able to manage its own cell reselection process when moving between cells. For such wireless devices, using the RRC inactive state may also reduce the amount of connection establishment-related signaling required compared to using the RRC idle state, e.g., because the network may retain at least some context information for the wireless device. This can directly reduce the signaling latency associated with the transition to the RRC connected state.
[0100] As another potential benefit, for example, compared to operating in the RRC idle state, this state can reduce the control plane latency of a wireless device. For example, for the RRC inactive state relative to the RRC idle state, it is possible to shorten the access stratum connection establishment period and / or the non-access stratum connection establishment period. Therefore, the time from the battery active state to the start of continuous data transmission can be reduced.
[0101] Additionally, for example, compared to operating in the RRC connected state, this state can improve the power saving ability of a wireless device. For example, compared to being in the RRC inactive state, when in the RRC connected state, services and / or neighbor cell measurements may be required more frequently, for example, at least in accordance with the connection mode discontinuous reception (C-DRX) cycle of the wireless device.
[0102] A wireless device can manage cell reselection while in the RRC inactive state. The objectives of the cell reselection process can include keeping the wireless device camped on a suitable cell, which can include a cell having sufficient signal strength, signal quality, and / or other characteristics such that the wireless device can establish / activate a connection and perform data transmission via the cell. Cell reselection can include either or both intra-frequency cell reselection or inter-frequency cell reselection. As part of the cell reselection process while in this RRC inactive state, the wireless device can perform cell measurements on the serving cell and / or neighbor cells. The way these cell measurements are performed can potentially have a significant impact on the wireless device power consumption and the amount of time required to access the continuous data transmission capability (e.g., by resuming operation in the RRC connected state). For example, if synchronized signal blocks (SSBs) are used to perform cell measurements, there may be a delay between the wake-up instance of the wireless device in the inactive state and the next SSB burst, and / or the measurements may be performed over a relatively long period of time to allow receiver beam scanning over multiple SSB bursts. Additionally, such SSB bursts can be performed at a different frequency and / or with a wider bandwidth than the designated wake-up instance of the wireless device. Alternatively, the cellular base station can provide paging instances aligned with the SBS in the time domain and / or frequency domain, for example, to facilitate reducing the power consumption of the wireless device in the RRC inactive state.
[0103] Figure 7 is a communication flow diagram showing a communication flow 700 for entering and recovering from the RRC inactive state according to aspects of the present disclosure. Aspects of this communication flow can be implemented by a wireless device, for example, in combination with one or more wireless devices and one or more parts of a core network (CN), such as in Figure 7The UE 702, gNB 704, previous serving gNB 706, and access and mobility function (AMF) 708 shown and described herein, or more generally, any one of the computer circuits, systems, devices, elements, or components shown in the above figures as needed. For example, the processor (and / or other hardware) of such a device may be configured to cause the device to perform any combination of the illustrated method elements and / or other method elements.
[0104] In communication flow 700, a wireless device such as UE 702 receives, for example, an RRC release message (step 1) from the previous serving gNB 706. The RRC release message may include suspension configuration information for the UE 702 to enter the RRC inactive state. The suspension configuration information may include information for operating in the RRC inactive state and / or resuming a connection from the RRC inactive state, such as information about the RNA and security parameters for supporting a resume message for encryption, such as UE identity and resume security information. The RNA may include a region associated with a set of gNBs within which the UE is allowed to move without notifying the network.
[0105] In some cases, the UE 702 may want to perform dedicated data transmission / reception that cannot be performed in the inactive state. To exit the inactive state, the UE 702 may initiate an RRC resume procedure by transmitting an RRC resume request to a gNB, which in this example is gNB 704, a gNB different from the previous serving gNB 706 (step 2). The RRC resume request may include, for example, UE identity and resume security information. Then, gNB 704 may retrieve the context about UE 702 from the previous serving gNB (step 3). After receiving the UE context (step 4), gNB 704 may send an RRC resume message to UE 702 in response to the RRC resume request (step 5). Then, UE 702 may transition to the RRC connected state 710 and send an RRC resume complete message to gNB 704 (step 6).
[0106] Then, gNB 704 performs a handover of the UE from the previous serving gNB 706 by sending a data forwarding address indication to the previous serving gNB (step 7) and a path switch request to the AMF 708 (step 8). The AMF 708 responds with a path switch request response (step 9), and the gNB sends a UE context release to the previous serving gNB 706 (step 10).
[0107] In some wireless communication networks, encryption and / or integrity protection can be used to help provide data integrity and security. For example, in 5G NR, user data in a data radio bearer (DRB) block can be encrypted to provide data confidentiality and integrity protection for the user data. Additionally, RRC signaling in a signaling radio bearer (SRB) block is encrypted separately from the user data to help provide signaling data confidentiality and radio network integrity. The key used for NAS-level security between the CN and the wireless device is thus cryptographically separated from, for example, the AS key used for RRC signaling. In some cases, a sequence number can be used as an input for encryption and / or integrity protection. For example, a next-hop (NH) chain counter (NCC) sequence number can be used in combination with an NH parameter value to generate a key (K gNB ) for use between the UE and the gNB. The NH parameter value can be calculated by the AMF and the UE, rather than by the gNB, and the NCC sequence number can be provided by the AMF (as discussed in more detail below).
[0108] Figure 8 is a communication flow diagram showing a communication flow 800 for entering and resuming from the RRC inactive state according to aspects of the present disclosure. In the communication flow 800, the UE 802 receives an RRC release message from the gNB1 804. In some cases, the RRC release message includes suspension configuration information and recovery security information including a first NCC sequence number. The gNB1 804 can obtain an NCC and corresponding NH parameter pair from, for example, the AMF 810 before transmitting the RRC release message to the UE 802 (not shown). After receiving the RRC release message from the gNB1 804, the UE 802 can enter the RRC inactive state. After determining that the UE needs to exit the RRC inactive state, the UE 802 can derive 812 a gNB key (K gNB *) for use between the UE 802 and the target gNB within the UE's RNA. The RRC resume message can be encrypted and / or integrity protected using the derived gNB key (K gNB *) and can include security information such as an authentication token. The gNB key (K gNB *) can be derived based on the target gNB information. For example, the target gNB information can include the physical cell ID (PCI), cell identity (Cell-ID), and cell radio network temporary identity (C-RNTI) of the target gNB2 806.
[0109] After receiving the RRC resume message, the target gNB 806 forwards the security information together with the target gNB 806 information to the source gNB (e.g., the gNB that previously communicated with the UE), here gNB1 804 (not shown). Then, the source gNB1 804 calculates the gNB key (K gNB *) based on the target gNB2 806 information and the NCC / NH parameter pair and other variables. Then, the source gNB1804 may transmit the calculated gNB key (K gNB *) back to the target gNB2 806 together with the NCC, encryption and / integrity protection algorithms, security policies, and other security information (not shown) associated with the gNB key (K gNB *).
[0110] The target gNB2 806 may also send a path switch request to the AMF to initiate the handover of the UE 802 from the source gNB1 804 to the target gNB2 806. The AMF may respond with a path switch response, confirm the handover, and provide a second NCC 2 and the corresponding second NH 2 parameter pair to the target gNB 806. The target gNB2 806 may send an RRC resume procedure message back to the UE 802 and communicate with the UE 802 in the RRC connected state using the calculated gNB key (K gNB *). After the communication, the UE 802 may return to the RRC inactive state 814 after receiving a second RRC release message from the target gNB2 806. The second RRC release message may also include suspension configuration information and recovery security information including the second NCC 2 and the corresponding second NH 2 parameter pair.
[0111] Similarly, to exit the RRC inactive state, the UE 802 may derive a second gNB key (K gNB2 *) for use between the UE802 and a second target gNB3 808, which is also within the UE's RNA. The gNB key (K gNB2 *) may be derived based on the target gNB information, which may include, for example, the PCI, cell ID, C-RNTI of the target gNB3 806. Then, the UE802 may use the second gNB key (K gNB2*) Transmit a second RRC resume message to the target gNB 3 808. The second RRC resume message may also include security information, such as an authentication token. After receiving the second RRC resume message, the target gNB3 forwards the security information together with the second target gNB3 808 information to the second source gNB, which is now gNB2 806 because the UE previously switched from gNB1 to gNB2. Then, the second source gNB2 806 calculates a second gNB key (K gNB2 *) based on the second target gNB3 808 information and the NCC / NH parameter pair and other variables. Then, the second source gNB2 806 may transmit the calculated second gNB key (K gNB2 *) back to the second target gNB3 808 together with the NCC, encryption, and / or integrity protection algorithm, security policy, and other security information (not shown) associated with the second gNB key (K gNB2 *). The second target gNB3 808 may also send a path switch request to the AMF to initiate a second handover of the UE 802 from the second source gNB2 806 to the second target gNB2 808. The AMF may respond with a path switch response, confirm the handover, and provide a third NCC 3 and the corresponding third NH 3 parameter pair to the second target gNB 808. The second target gNB 808 may send an RRC resume process message back to the UE 802 and communicate with the UE 802 in the RRC connected state using the second calculated gNB key (K gNB2 *). After the communication, the UE 802 may return to the RRC inactive state after receiving a third RRC release message from the second target gNB1 808. The third RRC release message may also include suspension configuration information and recovery security information including the third NCC 3 and the corresponding third NH 3 parameter pair.
[0112] Figure 9 is an illustration showing key derivation 900 according to aspects of the present disclosure. As part of the initial establishment of the AS key, the UE and the AMF may share an AMF key K AMF , and both the UE and the AMF may derive an initial gNB key K gNB 902 and a first NH 904 parameter from the AMF key. The initial gNB key K gNB 902 may be derived partially based on the CN's NAS uplink count. The initial gNB key K gNB 902 may be associated with NCC = 0, while the first NH 904 may be derived from the initial gNB key K gNB 902 and associated with NCC = 1.
[0113] After this initial establishment, the first pair of gNB keys and NH parameters, i.e., the initial K gNB 902 and the first NH 904, will not be used to derive gNB keys. To derive new gNB keys, two techniques can be used. When there is an unused NCC / NH pair at the gNB, vertical derivation of a new gNB key can be performed. As described above, the gNB can obtain an NH / NCC pair from the AMF, and if the gNB has an unused NH / NCC pair, the gNB can vertically derive a new gNB key K gNB using the unused NH 906 together with gNB information (such as PCI, cell ID, C-RNTI, etc.). The gNB can also provide the NCC / NH pair to the UE to derive a new gNB key K gNB . If there is no unused NCC / NH pair available at the gNB, horizontal derivation of a new gNB key can be performed. Horizontal derivation is based on the currently active gNB key (referred to as K NG-RAN ) and gNB information. The gNB can signal to the UE in an RRC release message to use either vertical or horizontal derivation of the new gNB key. If the NCC included in the RRC release message matches the currently used NCC value, horizontal derivation can be used to derive the new gNB key. If the NCC value included in the RRC release message is a new NCC value, vertical derivation can be used to derive the new gNB key.
[0114] UE Data Transmission in RRC Inactive State
[0115] In some cases, it may be desirable to allow the UE to transmit UL data while remaining in the RRC inactive state without transitioning to the RRC connected state. To transmit in the RRC inactive state, the UE will not send an RRC resume request before transmitting UL data. A target gNB that is within the UE's configured RNA but not the previous serving gNB will not be able to retrieve the NCC and the computed gNB key from the original serving gNB before UL, and it may be desirable to provide improved techniques for generating keys for transmission while in the inactive state.
[0116] Figure 10 is a communication flow diagram of Technique 1000 for key generation for inactive state data transmission according to aspects of the present disclosure. In some cases, a single NCC value can be used to generate keys for multiple gNBs to perform key generation for inactive state data transmission. In these cases, multiple new gNB values can be derived from the single NCC value included in the RRC release message. The NCC value can be a new NCC value or the currently used NCC value. There can be multiple options for deriving multiple new gNB keys from a single NCC value.
[0117] In the first option 1002, the previous gNB key from the previous serving cell can be reused for each data transmission in the RRC inactive state. In the first option 1002, the UE 802 receives the NCC value from the source gNB1 804 in the RRC release message and derives the gNB key (K gNB ) based on the received NCC value, and stores the derived gNB key (K gNB ). Then, when in the RRC inactive state, the UE 802 can transmit data encrypted and / or integrity protected using the derived gNB key (K gNB ) to the target gNB2 806, which is different from the source gNB1 804 and within the configured RNA of the UE. The UE 802 can also transmit data encrypted and / or integrity protected using the same stored derived gNB key (K gNB ) to another target gNB3 808 within the configured RNA of the UE, which is different from the source gNB1 804 and the target gNB2 806 and within the configured RNA of the UE. It is noted that in the first option 1002, the same gNB key (K gNB ) is used to encrypt and / or integrity protect data sent to multiple gNBs.
[0118] As described above, the source gNB 804 receives the NCC / NH pair from the AMF to derive the gNB key (K gNB ). The NCC / NH pair is provided only to the source gNB 804 from the AMF. For each option, on the network side, data security processing can be provided by the source gNB, or data security can be performed by each accessed gNB. In the first option 1002, if data security is handled by the source gNB1 804, when data is transmitted by the inactive UE 802 to a target gNB (such as the target gNB2 806 or the target gNB3 808), the target gNB forwards the security information of the transmitted data together with the target gNB information to the source gNB1 804. Then, the source gNB1 804 returns the derived gNB key (K gNB ) to the target gNB. If data security is handled by each accessed gNB, after the source gNB1 804 transmits the RRC release message including the RNA information to the UE 802, it can broadcast the UE context information, including the derived gNB key, to other gNBs in the configured RNA of the UE 802. Then, when the UE 802 transmits data to, for example, the target gNB3 808 in the inactive state, the target gNB3 808 will decrypt the transmitted AS data using the derived gNB key (K gNB ).
[0119] In some cases, the second option 1004 can be used to derive a new gNB key (K gNB* ) for each data transmission in the RRC inactive state. In the second option 1004, the UE 802 also receives the NCC value from the source gNB1 804. For each data transmission in the RRC inactive state, the UE uses horizontal derivation to derive a new gNB key (K gNB* ). The horizontal derivation can be based on the currently active gNB key (K NG-RAN ), based on the received NCC value, and the gNB information of the target gNB. For example, the UE 802 receives the NCC value from the source gNB1 804 in the RRC release message and derives the gNB key (K NG-RAN ) based on the received NCC value. When the UE802 wants to transmit data in the inactive state, the UE 802 selects a target gNB (such as the target gNB2 806) and obtains the gNB information (such as PCI, cell ID, C-RNTI, etc.) broadcast by the target gNB2 806. Then, the UE 802 horizontally derives a new gNB key (K NG-RAN ) based on the gNB information and the derived gNB key (K gNB2* ). For each additional transmission, the UE horizontally derives another new gNB key (K gNB2* ). If the UE 802 wants to transmit to another target gNB such as the target gNB3808 in the inactive state, the UE 802 horizontally derives the new gNB key (K gNB3* ) of the target gNB3 808 based on the gNB information of the target gNB3 808.
[0120] For the second option 1004, on the network side, data security processing can be provided again by the source gNB, or data security can be performed by each accessed gNB in a manner similar to that discussed above for the first option 1002.
[0121] In some cases, the third option 1006 can be used to vertically derive a new gNB key (K gNB ) for data transmission in the RRC inactive state. This new gNB key (K gNB ) can be used for all data transmissions in the RRC inactive state. For example, the UE 802 receives the NCC value from the source gNB1 804 in the RRC release message. In some cases, the UE 802 can vertically derive a new gNB key (K gNB)。In other cases, the UE 802 may determine an initial target gNB (such as target gNB2 806) for transmitting data to it in the RRC inactive state and obtain the gNB information broadcast by the target gNB2 806. In this example, the initial target gNB may be the first gNB to which the UE 802 transmits in the inactive state. Then, the UE 802 may vertically derive a new gNB key (K gNB ) based on this NCC value and the gNB information of the obtained target gNB2 806. )。Then, the UE 802 may use the newly derived gNB key (K gNB ) again for each subsequent data transmission. )。Continuing the previous example, the UE 802 may then use the previously derived new gNB key (K gNB ) to transmit data to another target gNB, such as target gNB3 808, in the RRC inactive state. ) to transmit data to another target gNB, such as target gNB3 808, in the RRC inactive state.
[0122] For the third option 1006, on the network side, the source gNB may provide data security processing again, or each accessed gNB may perform data security in a manner similar to that discussed above for the first option 1002. Additionally, data security may be performed by the source gNB and the initial target gNB. For example, the initial target gNB, such as target gNB2 806, may forward the security information of the data transmitted by the UE 802 along with the initial target gNB information to the source gNB1 804. Then, the source gNB1 804 returns the derived gNB key (K gNB ) to the initial target gNB. Then, the source gNB 806 or the initial target gNB2 may broadcast the derived gNB key (K gNB ) to another gNB in the UE's RNA. ) to another gNB in the UE's RNA.
[0123] In some cases, the fourth option 1008 may be used to vertically derive a new gNB key (K gNB ) for each data transmission in the RRC inactive state. For example, the serving gNB1 804 receives the NCC value and the NH parameter pair from the AMF. The UE 802 receives the NCC value from the source gNB1 804 in the RRC release message. When the UE 802 wants to transmit data in the inactive state, the UE 802 selects a target gNB (such as target gNB2 806) and obtains the gNB information broadcast by the target gNB2 806. Then, the UE 802 may vertically derive a new gNB key (K gNB2* ) based on this NCC value and the gNB information of the obtained target gNB2 806. Then, the UE 802 may use the vertically derived new gNB key (K gNB2*)Transmit data to the target gNB2 806. Then, the target gNB2 806 can forward the security information and gNB information from the received data to the source gNB1 804. Then, the source gNB1 804 can return the derived gNB key (K gNB2 ) to the target gNB2 806. In other cases, data security can be performed by each accessed gNB in a manner similar to that discussed above for the first option 1002, where the source gNB1 804 can broadcast the NCC value and NH parameter pair to other gNBs in the configured RNA of the UE 802. If the UE 802 wants to transmit data to another target gNB, such as the target gNB3 808, in the inactive state, the UE 802 obtains the gNB information of the target gNB3 808 and vertically derives a new gNB key (K gNB3* ) based on the previously obtained NCC value and the obtained gNB information of the target gNB3 808, and transmits the data to the target gNB3 808. Then, the target gNB3 808 can obtain the derived gNB key (K gNB3 ) from the source gNB1 804, or derive the gNB key (K gNB3 ) from the broadcast NCC value and NH parameter in a manner similar to that described above for the target gNB2 806.
[0124] In some cases, the fifth option 1010 can be used to vertically and horizontally derive a new gNB key (K gNB* ) for data transmission in the RRC inactive state. In the fifth option 1010, a new gNB key (K gNB* ) can be derived for each data transmission, where a new gNB key (K gNB* ) is vertically derived for the initial transmission, and a new gNB key is horizontally derived for subsequent data transmissions. For example, the serving gNB1 804 receives the NCC value and NH parameter pair from the AMF. The UE 802 receives the NCC value from the source gNB1 804 in the RRC release message. When the UE 802 wants to transmit data in the inactive state, the UE 802 selects a target gNB (such as the target gNB2 806) and obtains the gNB information broadcast by the target gNB 806. Then, the UE 802 can vertically derive a new gNB key (K gNB2* ) based on the NCC value and the obtained gNB information of the target gNB2 806. If the UE 802 wants to transmit more data in the inactive state, the UE 802 can select another target gNB, such as the target gNB3 808, obtain the gNB information from the target gNB3 808, and horizontally derive a new gNB key (KgNB3* )。
[0125] For the fifth option 1010, on the network side, data security processing can be provided again by the source gNB, or data security can be performed by each accessed gNB in a manner similar to that discussed above for the first option 1002 and the fourth option 1008.
[0126] Figure 11 is a communication flow diagram of a communication flow 1100 for entering the RRC inactive state and resuming from the RRC inactive state according to aspects of the present disclosure. The communication flow 1100 shows an example corresponding to the fourth option 1008 and in which data security is handled by each accessed gNB, as described in connection with Figure 10 discussed. In this example, the serving gNB1 1104 receives a first NCC value and an NH parameter pair from the AMF (not shown). Then, the serving gNB1 1104 transmits an RRC release message to the UE 1102, the RRC release message having the first NCC value and suspension configuration information including RNA information. Then, the serving gNB1 1104 sends UE context information including the received first NCC value and NH parameter pair to other gNBs (such as the target gNB2 1106 and the target gNB3 1109) in the RNA of the UE1102. Then, the other gNBs can vertically derive a new gNB key (K gNB* ) based on the received first NCC value, NH parameter, and their gNB information. When the UE1102 wants to transmit data in the inactive state, the UE 1102 selects a target gNB (such as the target gNB2 1106) and obtains the gNB information broadcast by the target gNB2 1106. Then, the UE 1102 can vertically derive a new gNB key (K gNB2* ) based on the NCC value and the obtained gNB information of the target gNB2 1106. Then, the UE 1102 can use the vertically derived new gNB key (K gNB2* ) to transmit data to the target gNB2 1106. The target gNB2 1106 derives 1112 a new gNB key (K gNB2* ) as described above to access the AS data received from the UE 1102. Similarly, when the UE 1102 wants to transmit data to the target gNB3 1108 in the active state, the UE 1108 can vertically derive another new gNB key (K gNB3* ) based on the NCC value and the obtained gNB information of the target gNB8 1108. The target gNB8 1108 derives 1114 a new gNB key (K gNB3*) to access the AS data received from UE 1102. In some cases, UE 1102 may want to transition to a different connection state on target gNB2 1106 than source gNB1 1104. In such cases, UE 1102 may perform the RRC resume procedure in a manner similar to that described above in conjunction with Figure 7 as described. UE 1102 may also return to the inactive state in a manner similar to that described above in conjunction with Figure 7 as described.
[0127] Figure 12 is a communication flow diagram of a communication flow 1200 for entering and resuming from the RRC inactive state according to aspects of the present disclosure. Communication flow 1200 illustrates an example corresponding to the fourth option 1008 and in which data security is handled by the source gNB, as discussed in conjunction with Figure 10 . In this example, serving gNB1 1104 receives a first NCC value and an NH parameter pair from the AMF (not shown). Then, serving gNB1 1104 transmits an RRC release message to UE 1102, the RRC release message having the first NCC value and suspension configuration information including RNA information. After data transmitted by UE 1102 in the inactive state is received by a target gNB, such as target gNB2 1106, the target gNB forwards the security information together with the target gNB information to source gNB1 1104. Then, source gNB1 1104 vertically derives 1202 a new gNB key (K gNB2* ) based on the target gNB information, the first NCC value, and the NH parameter, and transmits the derived new gNB key (K gNB* ) to target gNB2 1106. Similarly, when another target gNB3 1108 of the UE's RNA requests UE context information, source gNB1 1104 may vertically derive 1204 another new gNB key (K gNB2* ) for that another target gNB3 1108. In some cases, UE 1102 may want to transition to a different connection state on target gNB2 1106 than source gNB1 1104. In such cases, UE 1102 may perform the RRC resume procedure in a manner similar to that described above in conjunction with Figure 7 as described. UE 1102 may also return to the inactive state in a manner similar to that described above in conjunction with Figure 7 as described.
[0128] Figure 13is a communication flow diagram showing communication flow 1300 for entering and resuming from the RRC Inactive state according to aspects of the present disclosure. Communication flow 1300 shows an example corresponding to the fifth option 1010 and where data security is handled by the source gNB, as discussed in conjunction with Figure 10 . In this example, serving gNB1 1104 receives a first NCC value and an NH parameter pair from the AMF (not shown). Then, serving gNB1 1104 transmits an RRC Release message to UE 1102, the RRC Release message having the first NCC value and suspension configuration information including RNA information. After receiving the RRC Release message, the UE transitions to the RRC Inactive state. When UE 1102 wants to transmit data in the RRC Inactive state, UE 1102 selects a target gNB (such as target gNB2 1106) and obtains the gNB information broadcast by target gNB2 1106. Then, UE 1102 can vertically derive 1302 a new gNB key (K gNB2* ) based on the NCC value and the obtained gNB information of target gNB2 1106. Then, UE 1102 can use the vertically derived new gNB key (K gNB2* ) to transmit data to target gNB2 1106. After the data transmitted by UE 1102 in the Inactive state is received by target gNB2 1106, target gNB2 1106 forwards the security information together with the target gNB information to source gNB1 1104. Then, source gNB1 1104 vertically derives 1212 a new gNB key (K gNB2* ) based on the target gNB information, the first NCC value, and the NH parameter, and transmits the derived new gNB key (K gNB2* ) to target gNB2 1106. When UE 1102 transmits data to another target gNB (such as target gNB2 1108) in the RRC Inactive state, after the initial data transmission, UE 1102 obtains the gNB information broadcast by target gNB3 1108, and horizontally derives 1304 a new gNB key (K gNB3* ) based on the previous gNB key, the first NCC value, and the gNB information from target gNB3 1108. After the data transmitted by UE 1102 in the Inactive state is received by target gNB3 1103, target gNB3 1108 forwards the security information together with the target gNB information to source gNB1 1104. Then, source gNB1 1104 horizontally derives a new gNB key (K gNB3* ), and transmits the derived new gNB key (K gNB3*)Transmitted to the target gNB2 1106. In some cases, the UE 1102 may want to transition to a connection state different from the source gNB1 1104 on the target gNB2 1106. In this case, the UE 1102 can adopt a manner similar to that described above in conjunction with Figure 7 to use the gNB key (K gNB2* ) initially derived vertically to perform the RRC resume procedure. The UE 1102 can also return to the inactive state in a manner similar to that described above in conjunction with Figure 7 .
[0129] In some cases, a set of consecutive integer NCC values provided by the source gNB in the RRC release message for generating keys for multiple gNBs can be used to perform key generation for inactive state data transmission. This set of consecutive NCC values can be described by a starting NCC value and an integer n, which indicates how many consecutive NCC values are in the set. In these cases, multiple new gNB values can be derived from the set of NCC values included in the RRC release message. For example, the source gNB may receive a path switch procedure response message including a set of NCC values and an NH parameter before transmitting the RRC release to the UE. The set can include any integer n of consecutive NCC values, where n > 1. Then, the source gNB can transmit an RRC release message that has suspension configuration information including the set of NCC values. After the UE enters the RCC inactive state, the UE may want to transmit data in the RCC inactive state. Then, the UE can vertically derive a new gNB key for the first transmission based on the first NCC value from the set of NCC values. The UE can continue to vertically derive new gNB keys based on the consecutive NCC values from the set of NCC values for each data transmission in the RCC inactive state. After n data transmissions, the UE will have used all the NCC values from the set of NCC values.
[0130] On the network side, data security processing can be provided by multiple alternative processing procedures. In the first alternative network side data security processing procedure, data processing security can be performed by the source gNB. For example, in this first alternative, when the UE transmits data to the target gNB in the inactive state, the target gNB forwards the security information of the transmitted data together with the target gNB information to the source gNB. Then, the source gNB uses the gNB key (K gNB)Returned to the target gNB. In the second alternative network-side data security processing procedure, data processing security can be performed by each accessed gNB based on the NCC / NH pair broadcast by the source gNB. For example, in this second alternative, after the source gNB transmits an RRC release message including RNA information to the UE, it can broadcast UE context information including the set of NCC values and NH parameters to other gNBs in the configured RNA of UE 802. Then, when UE802 transmits data to the target gNB in the inactive state, the target gNB can derive the gNB key (K gNB ). In the third alternative network-side data security processing procedure, data processing security can be performed by each accessed gNB based on the UE context data retrieved from the source gNB. For example, in this third alternative, when the UE transmits data to the target gNB in the inactive state, the target gNB forwards the security information of the transmitted data together with the target gNB information to the source gNB. Then, the source gNB returns the UE context data including the NCC value and NH parameters to the target gNB. Then, the target gNB can derive the gNB key (K gNB ).
[0131] In addition, there can be multiple options for handling subsequent data transmissions after all NCC values from the set of NCC values have been used. Each of these multiple options can be combined with any one of the alternative network-side data security processing procedures described in detail above.
[0132] In the first option, the last gNB key (N gNBn* ) derived from the set of NCC values can be used together with the gNB information from the target gNB to horizontally derive the subsequent gNB key (N gNBn+m* ). For example, after all n NCC values in the set of NCC values have been used, the UE can derive a new gNB key (N gNBn* ) by using horizontal derivation based on the currently active (e.g., last) gNB key (N gNBn+1* ) derived from the set of NCC values and the gNB information of the target gNB. For each additional data transmission in the RRC inactive state, horizontal derivation can be used to continue generating additional new gNB keys. On the network side, data security can be performed using any one of the alternative network-side data security processing procedures described in detail above.
[0133] In the second option, the last gNB key (N gNBn* ) derived from the set of NCC values can be used again for subsequent data transmissions in the RRC inactive state. For example, after all n NCC values in the set of NCC values have been used, the UE can continue to use the currently active (e.g., last) gNB key (NgNBn* )For additional data transmission in the RRC Inactive state. On the network side, data security can be performed using any one of the alternative network-side data security handling procedures described in detail above.
[0134] In the third option, after the NCC values in the set of NCC values have been used, the RRC resume procedure can be triggered. For example, after all n NCC values in the set of NCC values have been used, the UE can send an RRC resume procedure to the target gNB. The NCC value for the RRC resume procedure can be the last NCC value in the set of NCC values, or there can be a dedicated NCC value for the RCC resume procedure provided together with the set of NCC values. Then, the target gNB can send a path switch request to the AMF. Then, the AMF can respond with a path switch response message including another set of NCC values and the NH parameter. In some cases, the path switch request procedure can also hand over the UE from the previous source gNB to the target gNB. Then, the target gNB can send the other set of NCC values to the UE in an RRC release message.
[0135] In the fourth option, after the NCC values in the set of NCC values have been used, a new additional gNB key (N Figure 10 ) can be derived in a manner similar to that described for deriving an additional gNB key from a single NCC value in the third option 1006 in combination with gNBn* . For example, after all the NCC values in the set of NCC values have been used, a new gNB key (K gNBn* ) can be derived vertically based on the currently active (e.g., the last) gNB key (N gNB ), the NCC value, and the gNB information. Then, the UE can use the derived new gNB key (K gNB ) again for each subsequent data transmission.
[0136] In the fifth option, after the NCC values in the set of NCC values have been used, a new additional gNB key (N Figure 10 ) can be derived in a manner similar to that described for deriving an additional gNB key from a single NCC value in the fourth option 1008 in combination with gNBn* . For example, after all the NCC values in the set of NCC values have been used, a new gNB key (K gNBn* ) can be derived vertically based on the currently active (e.g., the last) gNB key (N gNB2* ) and the gNB information of the obtained target gNB. For subsequent transactions, it can also be based on the currently active gNB key (e.g., K gNB2*)), NCC values, and the gNB information of the obtained target gNB to vertically derive an additional new gNB key (K gNBN* ).
[0137] In the sixth option, after using the NCC values in the set of NCC values, an additional new gNB key (N Figure 10 ) can be derived in a manner similar to that described in the sixth option 1010 for deriving an additional gNB key from a single NCC value. For example, after using all the NCC values in the set of NCC values, a new gNB key (K gNBn* ) can be vertically derived based on the currently active (e.g., the last) gNB key (N gNBn* ), NCC values, and the gNB information of the obtained target gNB. For subsequent data transmissions, an additional new gNB key (K gNB2* ) can be horizontally derived based on the currently active gNB key (e.g., gNB key (K gNB2* )). gNBN* )
[0138] Figure 14 is a communication flowchart showing an exemplary technique 1400 for key generation for data transmission in the inactive state according to aspects of the present disclosure. Technique 1400 shows an example of the above-described third option, which is used to handle subsequent data transmissions after using all the NCC values from the set of NCC values in combination with the first alternative network-side data security processing procedure. In this example, the source gNB1 1104 can receive a path switch procedure response message including a set of NCC values and an NH parameter from the AMF 1110 before transmitting an RRC release to the UE 1102. In this example, the set includes two consecutive NCC values and an NH parameter (e.g., n = 2). Then, the source gNB1 1104 can transmit an RRC release message based on the set of NCC values received from the AMF 1110, and the RRC release message has suspension configuration information including a set of NCC values. After the UE 1102 enters the RCC inactive state, the UE 1102 may want to transmit data in the RCC inactive state. Then, the UE 1102 can vertically derive 1402 a first gNB key (K gNB2 ) for the first transmission to the first target gNB2 1106 based on the first NCC value from the set of NCC values and the gNB information of the first target gNB2 1106, and then forward the security information of the first transmission together with the gNB information to the source gNB11104. Then, the source gNB1 1104 vertically derives a first gNB key (K gNB2), and transmit a response including the first gNB key (K gNB2 ) back to the first target gNB 2 1106. When the source gNB 11102 derives each gNB key, the source gNB 1 1102 can track the NCC value usage and know which NCC value is currently active. When the UE 1102 wants to transmit additional data in the RRC inactive state to, for example, the second target gNB 3 1108, the UE 1102 can vertically derive 1404 the second gNB key (K gNB3 ) for a second transmission to the second target gNB 3 1108 based on the next (e.g., last) NCC value from the set of NCC values and the gNB information of the second target gNB 3 1108. The second target gNB 3 1108 can obtain the second gNB key (K gNB2 ) in a manner similar to how the first target gNB 2 1106 obtains the first gNB key (K gNB3 ).
[0139] After the second transmission, the UE 1102 can perform an RRC resume procedure with, for example, the first target gNB 2 1106 and transition to the RRC connected mode. In this example, the UE 1102 can use a dedicated NCC value included in the set of NCC values to transmit the RRC resume message. In other cases, the last NCC value in the set of NCC values can be used to transmit the RRC resume message. In some cases, the RRC resume message can include an indication regarding the need for additional NCC values for protecting additional data transmissions in the RRC inactive mode. Then, the first target gNB 2 1106 can transmit a UE context acquisition message to the source gNB 1 1104. Then, the source gNB 1 1104 can vertically derive the first gNB key (K gNB2 ) based on the NH value received from the AMF and the gNB information received from the first target gNB 2 1106. Then, the first target gNB 2 1106 can transmit a path switch request to the AMF 1110. Then, the AMF 1110 can respond with a path switch response message including another set of NCC values and the NH parameter. In some cases, the path switch request procedure can also hand over the UE 1102 from the previous source gNB 1 1104 to the first target gNB 2 1106. Then, the first target gNB 2 1106 can transmit another set of NCC values to the UE 1102 in an RRC release message.
[0140] Figure 15is a communication flow diagram showing an exemplary technique 1500 for key generation for inactive state data transmission according to aspects of the present disclosure. Technique 1500 shows an example of the above-mentioned third option, which is used to process subsequent data transmissions after using all NCC values from the set of NCC values in combination with the second alternative network side data security processing procedure. In this example, the source gNB1 1104 may receive a path switch procedure response message including a set of NCC values and an NH parameter from the AMF 1110 before transmitting an RRC release to the UE 1102. In this example, the set includes two NCC values (e.g., n = 2). Then, the source gNB1 1104 may transmit an RRC release message based on the NCC values received from the AMF 1110, and the RRC release message has suspension configuration information including a set of NCC values. The source gNB1 1104 may broadcast UE context information including the set of NCC values and the NH parameter to other gNBs (e.g., gNB2 1106 and gNB3 1108) in the configured RNA of the UE 1102.
[0141] After the UE 1102 enters the RCC inactive state, the UE 1102 may want to transmit data in the RCC inactive state. Then, the UE 1102 may vertically derive 1502 a first gNB key (K gNB2 ) for the first transmission to the first target gNB2 1106 based on the first NCC value from the set of NCC values and the gNB information of the first target gNB2 1106. After receiving the first transmission, the first target gNB2 1106 may also vertically derive the first gNB key (K gNB2 ) based on the set of NCC values and the NH parameter broadcast by the source gNB1 1104. The first target gNB2 1106 also broadcasts a UE data transmission number indicating which NCC has been used by the UE 1102 (e.g., incrementing a counter) to other gNBs (e.g., gNB1 1104 and gNB3 1108) in the configured RNA of the UE 1102. When the UE 1102 wants to transmit additional data to, for example, the second target gNB3 1108 in the RRC inactive state, the UE 1102 may vertically derive 1504 a second gNB key (K gNB3 ) for the second transmission to the second target gNB3 1108 based on the next (e.g., last) NCC value from the set of NCC values and the gNB information of the second target gNB3 1108. The second target gNB3 1108 may similarly derive the second gNB key (K gNB3)。The second target gNB3 1108 also broadcasts to other gNBs (e.g., gNB1 1104 and gNB2 1106) in the configured RNA of the UE 1102 another UE data transmission number indicating which NCC value has been used by the UE 1102.
[0142] After the second transmission, the UE 1102 may perform the RRC resume procedure in a manner similar to that described above with respect to Figure 14 For example, the UE 1102 may use a dedicated NCC value included within the set of NCC values to transmit the RRC resume message. In other cases, the last NCC value in the set of NCC values may be used to transmit the RRC resume message. In some cases, the RRC resume message may include an indication regarding the need for additional NCC values for protecting additional data transmissions in the RRC inactive mode. Then, the first target gNB2 1106 may transmit a UE context acquisition message to the source gNB1 1104. Then, the source gNB1 1104 may vertically derive the first gNB key (K gNB2 ) based on the NH parameter received from the AMF and the gNB information received from the first target gNB2 1106. Then, the first target gNB2 1106 may transmit a path switch request to the AMF 1110. Then, the AMF 1110 may respond with a path switch response message including another set of NCC values and the NH parameter. In some cases, the path switch request procedure may also hand over the UE 1102 from the previous source gNB1 1104 to the first target gNB2 1106. Then, the first target gNB2 1106 may transmit another set of NCC values to the UE 1102 in the RRC release message.
[0143] Figure 16is a communication flow diagram showing an exemplary technique 1600 for key generation for inactive state data transmission according to aspects of the present disclosure. Technique 1600 shows an example of the above-mentioned third option, which is used to process subsequent data transmissions after using all NCC values from the set of NCC values in combination with a third alternative network-side data security processing procedure. In this example, the source gNB1 1104 may receive a path switch procedure response message including a set of NCC values and an NH parameter from the AMF 1110 before transmitting an RRC release to the UE 1102. In this example, the set includes two NCC values (e.g., n = 2). Then, the source gNB1 1104 may transmit an RRC release message based on the NCC values received from the AMF 1110, and the RRC release message has suspension configuration information including a set of two NCC values. After the UE 1102 enters the RCC inactive state, the UE 1102 may want to transmit data in the RCC inactive state. Then, the UE 1102 may vertically derive 1602 a first gNB key (K gNB2 ) for the first transmission to the first target gNB2 1106 based on the first NCC value from the set of NCC values and the gNB information of the first target gNB2 1106. After receiving the first transmission, the first target gNB2 1106 sends a UE context acquisition message to the source gNB1 1104, and the source gNB1 1104 responds by returning a UE context response message including the next NCC value and the NH parameter. Since the UE context is accessed by the source gNB1 1104 whenever another gNB receives a data transmission from the UE 1102, the source gNB1 1104 can track the NCC value usage and know which NCC value is currently active. Then, the first target gNB2 1106 may vertically derive the first gNB key (K gNB2 ) based on the next NCC value, the NH parameter, and the gNB information. When the UE 1102 wants to transmit additional data to, for example, the second target gNB3 1108 in the RRC inactive state, the UE 1102 may vertically derive 1604 a second gNB key (K gNB3 ) for the second transmission to the second target gNB3 1108 based on the last NCC value from the set of NCC values and the gNB information of the second target gNB3 1108. The second target gNB3 1108 also transmits a UE context acquisition message to the source gNB1 1104, and the source gNB1 1104 responds by returning a UE context response message including the next NCC value and the NH parameter. Then, the second target gNB3 1108 may vertically derive the first gNB key (K gNB2 ) based on the next NCC value, the NH parameter, and the gNB information. After the second transmission, the UE 1102 may adopt a similar approach as described above regardingFigure 14 Perform the RRC resume procedure in the manner described above.
[0144] Figure 17 FIG. 1700 is a communication flow diagram illustrating an exemplary technique for key generation for inactivity state data transmission in accordance with aspects of the present disclosure. Technique 1700 illustrates an example of using a list of discontinuous NCC values. Technique 1700 is a variant that uses a set of consecutive integer NCC values, and all options and alternative network-side data security handling procedures described with respect to that set of consecutive integer NCC values are also applicable to the variant using a list of discontinuous NCC values. For example, technique 1700 illustrates the operation of a discontinuous list of NCC values used in conjunction with a first alternative network-side data security handling procedure, and details regarding the handling of subsequent data transmissions after all NCC values from the list of NCC values have been used are omitted. It will be understood that all options for handling subsequent data transmissions after all NCC values from the list of NCC values, as well as other alternative network-side data security handling, may also be combined with the discontinuous list of NCC values. Instead of using a starting NCC value and an integer to describe a set of consecutive NCC values, the set of NCC values may be a discontinuous list of NCC value and NH parameter pairs. The operation of deriving the gNB key using the list of NCC values is substantially similar on both the UE side and the network side, as described above with respect to the set of consecutive NCC values. Compared to the operation using the set of consecutive NCC values, the operation using the discontinuous list of NCC values will operate using a specific NCC value rather than a continuously increasing starting NCC value. For example, in technique 1700, source gNB1 1104 may receive a path switch procedure response message from AMF 1110 that includes a list of NCC value and NH parameter pairs (e.g., ((NCC1, NH1), (NCC3, NH3),...)) prior to transmitting an RRC release to UE 1102. Source gNB1 1104 may then transmit an RRC release message to UE 1102 that has suspension configuration information that includes the list of NCC values. After UE 1102 enters the RCC inactive state, UE 1102 may want to transmit data in the RCC inactive state. Then, UE 1102 may vertically derive 1702 a first gNB key (K gNB2 ) for a first transmission to first target gNB2 1106 based on the first NCC value (NCC1) from the set of NCC values and the gNB information of first target gNB2 1106. After receiving the first transmission, first target gNB2 1106 may then forward the security information of the first transmission along with the gNB information to source gNB1 1104. Source gNB1 1104 may then vertically derive the first gNB key (K gNB2), and transmit a response including the first gNB key (K gNB2 ) back to the first target gNB 2 1106. When the UE 1102 wants to transmit additional data to, for example, the second target gNB 3 1108 in the RRC inactive state, the UE 1102 can vertically derive 1704 the second gNB key (K gNB3 ) for a second transmission to the second target gNB 3 1108 based on the next (e.g., last) NCC value (e.g., NCC3) from the list of NCC values and the gNB information of the second target gNB 3 1108. The second target gNB 3 1108 can obtain the second gNB key (K gNB2 ) in a manner similar to how the first target gNB 2 1106 obtains the first gNB key (K gNB3 ).
[0145] Figure 18 is a communication flow diagram of an exemplary technique 1800 for key generation for inactive state data transmission according to aspects of the present disclosure. Technique 1800 is a variant of other exemplary techniques that use a set of consecutive integer NCC values, whereby the UE includes an indication of which NCC value is currently active, such as by using an incrementing counter. It should be understood that all options and alternative network-side data security processing procedures described with respect to this set of consecutive integer NCC values can also be applied to technique 1800. For example, as shown, technique 1800 applies a second alternative network-side data security processing procedure and omits details regarding handling subsequent data transmissions after all NCC values from the list of NCC values have been used. It can be understood that all options for handling subsequent data transmissions after all NCC values from the list of NCC values, as well as other alternative network-side data security processing, can also be combined with a non-consecutive list of NCC values. In this example, the source gNB 1 1104 can receive a path switch procedure response message including a set of NCC values and an NH parameter from the AMF 1110 before transmitting an RRC release to the UE 1102. In this example, the set includes two NCC values (e.g., n = 2). The source gNB 1 1104 can then transmit an RRC release message based on the NCC values received from the AMF 1110, the RRC release message having suspension configuration information including a set of NCC values. The source gNB 1 1104 can broadcast UE context information including the set of NCC values and the NH parameter to other gNBs (e.g., gNB 2 1106 and gNB 3 1108) in the configured RNA of the UE 1102.
[0146] After the UE 1102 enters the RCC inactive state, the UE 1102 may want to transmit data in the RCC inactive state. Then, the UE 1102 can vertically derive 1802 the first gNB key (K gNB2 ) for the first transmission to the first target gNB2 1106 based on the first NCC value from the set of NCC values and the gNB information of the first target gNB2 1106. The first transmission includes a first indication of the current NCC access number. After receiving the first transmission, the first target gNB2 1106 can also vertically derive the first gNB key (K gNB2 ) based on the set of NCC values broadcast by the source gNB1 1104, the indication of the current NCC access number, and the NH parameter. When the UE 1102 wants to transmit additional data to, for example, the second target gNB3 1108 in the RRC inactive state, the UE 1102 can vertically derive 1804 the second gNB key (K gNB3 ) for the second transmission to the second target gNB3 1108 based on the next (e.g., last) NCC value from the set of NCC values and the gNB information of the second target gNB3 1108. The second transmission includes a second indication of the current NCC access number, and the second indication is different from the first indication (e.g., incremented). The second target gNB3 1108 can similarly derive the second gNB key (K gNB3 ).
[0147] Figure 19is a communication flow diagram showing an exemplary technique 1900 for key generation for inactivity state data transmission according to aspects of the present disclosure. Technique 1900 is an exemplary variant that uses a list of discontinuous NCC values, whereby the UE includes an indication of which NCC value is currently active, such as by using an incrementing counter. It should be understood that all options and alternative network-side data security processing procedures described with respect to this set of consecutive integer NCC values are also applicable to technique 1900. For example, as shown, technique 1900 applies a second alternative network-side data security processing procedure and omits details regarding processing subsequent data transmissions after all NCC values from the NCC value list have been used. It can be understood that all options for processing subsequent data transmissions after all NCC values from the NCC value list, as well as other alternative network-side data security processing, can also be combined with the discontinuous list of NCC values. For example, in technique 1900, the source gNB1 1104 may receive a path switch procedure response message from the AMF 1110 that includes a list of NCC value and NH parameter pairs (e.g., ((NCC1,NH1), (NCC3,NH3)…)) before transmitting an RRC release to the UE 1102. Then, the source gNB1 1104 may transmit an RRC release message to the UE 1102, the RRC release message having suspension configuration information that includes the list of NCC values. The source gNB1 1104 may broadcast UE context information that includes the list of NCC values and NH parameters to other gNBs (e.g., gNB2 1106 and gNB3 1108) in the configured RNA of the UE 1102.
[0148] After the UE 1102 enters the RCC inactive state, the UE 1102 may want to transmit data in the RCC inactive state. Then, the UE 1102 may vertically derive 1902 a first gNB key (K gNB2 ) for a first transmission to the first target gNB2 1106 based on the first NCC value (NCC1) from the set of NCC values and the gNB information of the first target gNB2 1106. A first indication of the current NCC access number is included within the first transmission. After receiving the first transmission, the first target gNB2 1106 may also vertically derive the first gNB key (K gNB2 ) based on the list of NCC values broadcast by the source gNB1 1104, the indication of the current NCC access number, and the NH parameter. When the UE 1102 wants to transmit additional data in the RRC inactive state to, for example, a second target gNB3 1108, the UE 1102 may vertically derive 1904 a second gNB key (K gNB3)for a second transmission to the second target gNB 3 1108. The second transmission includes a second indication of the current NCC access number, the second indication being different from the first indication (e.g., incremented). The second target gNB 3 1108 can similarly derive the second gNB key (K gNB3 ) based on the list of NCC values broadcast by the source gNB 1 1104 and the second indication of the current NCC access number.
[0149] In some cases, a set of NCC values and NH parameters can be used to perform key generation for inactive state data transmission, where the NCC value for the next transmission in the RRC inactive state is provided to the UE. Figure 20 is a communication flow diagram showing an exemplary technique 2000 for key generation for inactive state data transmission in accordance with aspects of the present disclosure. Technique 2000 shows an example of providing the NCC value for the next transmission in the RRC inactive state to the UE. In this example, the source gNB 1 1104 can receive a path switch procedure response message including a set of NCC values and NH parameters before transmitting an RRC release to the UE. In a first option, the set can include multiple NCC values and NH parameters. The multiple NCC values and NH parameters can be consecutive NCC values described by a starting NCC value and an integer n indicating how many consecutive NCC values are in the set, or the set can be a list of multiple non - consecutive NCC values. In a second option, the set can include a single NCC value and NH parameter pair. In the second option, when in the RRC inactive state, each subsequent gNB receiving a data transmission from the UE 1102 requests a new NCC value (NCC1) and NH parameter pair from the CN (such as the AMF 1110) for the next transmission in the RRC inactive state. In either option, the source gNB 1 1104 then can transmit an RRC release message to the UE 1102, the RRC release message having suspension configuration information including a first NCC value (NCC1) and RNA information. The UE 1102 can enter the RRC inactive state. The UE 1102 may want to transmit a first transmission to the first target gNB 2 1106 in the RRC inactive state and can vertically derive 2002 a new first gNB key (K gNB2)。After receiving the first transmission, the first target gNB 2 1106 may perform the alternative network - side data security processing procedures discussed below. Additionally, the first target gNB 2 1106 may obtain the next second NCC value (NCC2) and the NH parameter. The first target gNB 2 1106 may provide the next second NCC value (NCC2) to the UE 1102 by using, for example, a Media Access Control (MAC) control element (MAC - CE), a Radio Link Control (RLC) control packet data unit (PDU), or a Packet Data Convergence Protocol (PDCP) control PDU signaling. The UE 1102 may also want to transmit a second transmission to the second target gNB 3 1108 in the RRC inactive state and may vertically derive 2004 a new second gNB key (K gNB3 )。After receiving the first transmission, the second target gNB 3 1108 may also perform the alternative network - side data security processing procedures discussed below. Additionally, the second target gNB 3 1108 may obtain the next third NCC value (NCC3) and the NH parameter. The second target gNB 3 1108 may provide the next third NCC value (NCC3) to the UE 1102 by using, for example, MAC - CE, RLC control PDU, or PDCP control PDU signaling. The UE 1102 may perform an RRC resume procedure with, for example, the first target gNB 2 1106 and transition to the RRC connected mode. In this example, the UE 1102 may derive 2006 a new third gNB key (K based on the third NCC value (NCC3), the NH parameter, and / or the gNB information for the previous serving gNB 3 1108 gNB3* ) to transmit an RRC resume message. Then, the first target gNB 2 1106 may transmit a path switch request to the AMF 1110. Then, the AMF 1110 may respond with a path switch response message including another set of NCC values and NH parameters. In some cases, the path switch request procedure may also hand over the UE 1102. Then, the first target gNB 2 1106 may transmit another set of NCC values to the UE 1102 in an RRC release message.
[0150] On the network side, in any option, the network-side data security processing can be provided by multiple alternative handlers. In the first alternative solution, the data processing security can be performed by the source gNB. This first alternative solution can be combined with the first option. In this first alternative solution combined with the first option, after receiving the first transmission destined for the first target gNB2 1106, the first target gNB2 1106 forwards the security information of the first transmission together with the first target gNB2 1106 information to the source gNB11104. Then, the source gNB1 1104 vertically derives 2002 a new first gNB key (K gNB2 ) based on the set of NCC values and the first target gNB2 1106 information, and returns the new first gNB key (K gNB2 ) to the first target gNB2 1106. Similarly, after receiving the second transmission destined for the second target gNB3 1108, the second target gNB3 1108 also forwards the security information of the second transmission together with the second target gNB3 1108 information to the source gNB1 1104. Then, the source gNB1 1104 can vertically derive 2004 a new second gNB key (K gNB3 ) based on the set of NCC values and the second target gNB3 1108 information, and returns the new second gNB key (K gNB3 ) to the second target gNB31108.
[0151] Compared with the combination with the first option, this first alternative solution can also be combined with the second option with some modifications. In this combination, after receiving the first transmission destined for the first target gNB2 1106, the first target gNB2 1106 forwards the security information of the first transmission together with the first target gNB21106 information to the source gNB1 1104. Then, the source gNB11104 vertically derives 2002 a new first gNB key (K gNB2 ) based on the NCC value (NCC1) and the first target gNB2 1106 information, and returns the new first gNB key (K gNB2)Return to the first target gNB 21106. Then, the first target gNB 21106 connects to the CN, such as the AMF 1110, and obtains the next second NCC value (NCC2) and the NH parameter. Then, the target gNB 21106 provides the next second NCC value (NCC2) to the UE 1102 by using, for example, MAC-CE, RLC control PDU, or PDCP control PDU signaling. Then, the target gNB 21106 may broadcast an indication that the target gNB 21106 has the next second NCC value (NCC2) to other gNBs in the UE's RNA (e.g., gNB 11104 and gNB 31108). After receiving the second transmission destined for the second target gNB 31108, the second target gNB 31108 forwards the security information of the second transmission together with the second target gNB 31108 information to the first target gNB 21106 based on the broadcast indication. Then, the first target gNB 21106 may vertically derive 2004 a new second gNB key (K gNB3 ). Then, the first target gNB 21106 returns the new second gNB key (K gNB3 ) to the second target gNB 31108. Then, the second target gNB 31108 obtains the next third NCC value (NCC3) and the NH parameter from the CN. Then, the second target gNB 31108 may provide the next third NCC value (NCC3) to the UE 1102 by using, again, for example, MAC-CE, RLC control PDU, or PDCP control PDU signaling. Then, the second target gNB 31108 may also broadcast an indication that the second target gNB 31108 has the next third NCC value (NCC3) to other gNBs in the UE's RNA (e.g., gNB 11104 and gNB 21106).
[0152] In the second alternative network - side data security processing procedure, data - processing security can be performed by each accessed gNB based on the NCC / NH pair broadcast by the source gNB. This second alternative can be combined with the first option or the second option in substantially the same way. In this second alternative, the source gNB1 1104 can broadcast UE 1102 context information including the set of NCC values (or the single NCC value of option 2) and the NH parameter to other gNBs (e.g., gNB2 1106 and gNB2 1108) in the configured RNA of the UE 1102. After the UE 1102 enters the RCC inactive state, the UE 1102 may want to transmit data in the RCC inactive state. Then, the UE 1102 can vertically derive 2002 the first gNB key (K gNB2 ) based on the first NCC value (NCC1) received from the source gNB1 1104 and transmit the first transmission to the first target gNB2 1106 in the RRC inactive state. The first target gNB2 1106 can derive the first gNB key (K gNB2 ) based on the first NCC value (NCC1) and the NH parameter broadcast by the source gNB1 1104. The first target gNB2 1106 can also broadcast a UE data transmission number indicating which NCC has been used by the UE 1102 (e.g., incrementing a counter) to other gNBs (e.g., gNB1 1104 and gNB3 1108) in the configured RNA of the UE 1102. The first target gNB2 1106 can also obtain the next second NCC value (NCC2) via the set of NCC values transmitted by the source gNB1 1104 (e.g., for option 1) or by connecting to the CN (such as AMF 1110) and obtaining the next second NCC value (NCC2) and the NH parameter (e.g., for option 2). Then, the first target gNB2 1106 provides the next second NCC value (NCC2) to the UE 1102 by using, for example, MAC - CE, RLC control PDU, or PDCP control PDU signaling. The first target gNB2 1106 can (e.g., for option 2) broadcast the NCC value and the NH parameter obtained from the CN to another gNB (e.g., gNB1 1104 and gNB3 1108) in the configured RNA of the UE 1102. If the UE 1102 wants to transmit more data in the RCC inactive state, the UE 1102 can vertically derive 2004 the second gNB key (K gNB2) And transmit a second transmission to the second target gNB 3 1108 in the RRC inactive mode. After receiving the second transmission destined for the second target gNB 3 1108 from the UE 1102, the second target gNB 3 1108 may vertically derive the second gNB key (K gNB2 ) based on the second NCC value (NCC2) and the NH parameter broadcast by the source gNB 1 1104 (e.g., for option 1) or based on the second NCC value (NCC2) and the NH parameter broadcast by the first target gNB 2 1106 (e.g., for option 2). The second target gNB 3 1108 may also obtain the next third NCC value (NCC3) via the set of NCC values transmitted by the source gNB 1 1104 (e.g., for option 1) or by connecting to the CN (such as the AMF 1110) and obtaining the next third NCC value (NCC3) and the NH parameter (e.g., for option 2). Then, the second target gNB 3 1108 provides the next second NCC value (NCC2) to the UE 1102 by using, for example, MAC-CE, RLC control PDU, or PDCP control PDU signaling. The third target gNB 3 1108 may (e.g., for option 2) broadcast the NCC value and the NH parameter obtained from the CN to another gNB (e.g., gNB 1 1104 and gNB 2 1106) in the configured RNA of the UE 1102. The second target gNB 3 1108 may also broadcast to other gNBs (e.g., gNB 1 1104 and gNB 2 1106) in the configured RNA of the UE 1102 another UE data transmission number indicating which NCC value has been used by the UE 1102.
[0153] In a third alternative, data processing security may be performed by each accessing gNB based on the UE context data retrieved from the source gNB. This third alternative may be combined with the first option. In this third alternative, with the first option, after the UE 1102 performs a data transmission to the first target gNB 2 1106 in the inactive state, the first target gNB 2 1106 requests the UE context data from the source gNB 1 1104. Then, the source gNB 1 1104 returns the UE context data including at least the first NCC value (NCC1) and the NH parameter to the first target gNB 2 1106. Then, the first target gNB 2 1106 may vertically derive the 2002 first gNB key (K gNB2) Similarly, after receiving the second transmission destined for the second target gNB 3 1108, the second target gNB 3 1108 also requests UE context data from the source gNB 1 1104. Then, the source gNB 1 1104 returns the UE context data including at least the second NCC value (NCC2) and the NH parameter to the second target gNB 3 1108. Then, the second target gNB 3 1108 can vertically derive 2004 the second gNB key (K gNB3 )
[0154] Compared with the combination with the first option, this third alternative can also be combined with the second option with some modifications. In this combination, after receiving the first transmission destined for the target gNB 2 1106, the target gNB 2 1106 requests UE context data from the source gNB 11104. Then, the source gNB 11104 returns the UE context data including the first NCC value (NCC1) and the NH parameter to the first target gNB 2 1106. Then, the first target gNB 2 1106 connects to the CN, such as the AMF 1110, and obtains the second NCC value (NCC2) and the NH parameter. Then, the target gNB 21106 provides the second NCC value (NCC2) to the UE 1102 by using, for example, MAC-CE, RLC control PDU, or PDCP control PDU signaling. Then, the first target gNB 2 1106 can broadcast an indication to other gNBs (e.g., gNB 1 1104 and gNB 3 1108) in the UE's RNA that the first target gNB 2 1106 has the next second NCC value (NCC2). After receiving the second transmission destined for the second target gNB 3 1108, the second target gNB 3 1108 requests UE context data from the first target gNB 2 1106 based on the broadcast indication. Then, the first target gNB 2 1106 returns the UE context data including the second NCC value (NCC2) and the NH parameter to the second target gNB 3 1108. Then, the second target gNB 3 1108 can vertically derive 2004 the new second gNB key (K gNB3)。Then, the second target gNB 3 1108 obtains the next third NCC value (NCC3) and the NH parameter from the CN. Then, the second target gNB 3 1108 can provide the next third NCC value (NCC3) to the UE 1102 by using signaling such as MAC-CE, RLC control PDU, or PDCP control PDU again. Then, the second target gNB 3 1108 can also broadcast an indication to other gNBs in the UE's RNA (e.g., gNB 1 1104 and gNB 2 1106) that the second target gNB 3 1108 has the next third NCC value (NCC3).
[0155] Figure 21 is a flowchart showing a technique 2100 for generating a key by a user equipment for inactivity state data transmission according to aspects of the present disclosure. At block 2102, a radio resource control (RRC) suspension message including a next-hop (NH) chain counter (NCC) value can be received from a first node. At block 2104, the RRC inactive state can be entered. At block 2106, a first node key can be derived based on the first NCC value. It can be understood that, as used herein, a node key refers to a derived key that can be used to access a cell (such as a gNB cell, an eNB cell, a small cell, etc.). For example, the first node key can be based on a previously used node key, a horizontally derived node key, or a vertically derived node key. At block 2108, a first uplink message for transmission in the RRC inactive state can be generated based on the first node key. At block 2110, the first uplink message can be transmitted to the node while in the RRC inactive state. It can be understood that one or more of the various options referred to Figure 22 above can be used in a given wireless communication system at different times and / or according to different settings.
[0156] Figure 22 is a flowchart showing a technique 2200 for generating an additional key by a user equipment for inactivity state data transmission according to aspects of the present disclosure. At block 2202, a second node key can be derived based on a second NCC value among a plurality of NCC values included in the RCC suspension message. For example, the second node key can be based on a previously used node key, a horizontally derived node key, or a vertically derived node key. At block 2204, a second uplink message for transmission in the RRC inactive state can be generated based on the second node key. At block 2206, the second uplink can be transmitted to a third node while in the RRC inactive state.
[0157] Figure 23FIG. 2300 is a flowchart showing techniques 2300 for generating an additional key for inactivity state data transmission by a user equipment according to aspects of the present disclosure. At block 2302, a second NCC value may be received from a second node. At block 2304, a second node key may be derived based on the second NCC value. At block 2306, a second uplink message for transmission in the RRC inactive state may be generated based on the second node key. At block 2308, the second uplink message may be transmitted to a third node while in the RRC inactive state.
[0158] Figure 24 FIG. 2400 is a flowchart showing techniques 2400 for generating a key for inactivity state data transmission by a node according to aspects of the present disclosure. At block 2402, a radio resource control (RRC) suspension message including a first next-hop (NH) chain counter (NCC) value may be sent from a first node to a first user equipment. At block 2204, access stratum (AS) resources associated with the first user equipment may be released. At block 2206, a first node key may be derived based on the first NCC value. For example, the first node key may be derived horizontally, vertically, or based on a previously used node key. At block 2208, a first uplink message may be received from the first user equipment without allocating AS resources to the first user equipment. At block 2210, the first uplink message may be descrambled based on the first NCC value. It will be appreciated that one or more of the various options described with reference Figure 24 may be used in a given wireless communication system at different times and / or according to different settings.
[0159] Figure 25 FIG. 2500 is a flowchart showing techniques 2500 for generating an additional key for inactivity state data transmission by a node according to aspects of the present disclosure. At block 2502, a second node key may be derived based on a second NCC value among a plurality of NCC values, where the RCC suspension message includes the plurality of NCC values. For example, the second node key may be derived horizontally, vertically, or based on a previously used node key. At block 2504, a second uplink message may be received from the first user equipment without allocating AS resources to the first user equipment. At block 2506, the second uplink message may be descrambled based on the second node key.
[0160] Figure 26FIG. 2600 is a flowchart showing a technique 2600 for generating additional keys for an inactivity state data transmission by a node according to aspects of the present disclosure. At block 2602, a second NCC value may be transmitted from a second node. At block 2604, a second node key may be derived based on the second NCC value. At block 2606, a second uplink message may be received from a first user equipment without allocating AS resources to the first user equipment. At block 2608, the second uplink message may be descrambled based on the second node key.
[0161] Note that while the above examples and aspects mainly focus on methods for calculating the maximum number of non-overlapping CCEs in a carrier aggregation scenario, similar methods and formulas can also be applied to calculate the maximum number of PDCCH candidates (i.e., M) in a wireless communication scenario. Similarly, while the above examples and aspects mainly focus on methods for calculating the maximum number of non-overlapping CCEs in a carrier aggregation scenario, equally, similar methods and formulas can also be applied to calculate the limit on the number of blind decodings (BDs) that may be attempted by a UE in a carrier aggregation scenario.
[0162] Embodiments
[0163] In the following sections, additional exemplary embodiments are provided.
[0164] According to Embodiment 1, a method for secure key derivation in a wireless system is disclosed, the method comprising: receiving a radio resource control (RRC) suspension message from a first node, the RRC suspension message including a first next-hop (NH) chain counter (NCC) value; entering the RRC inactivity state; deriving a first node key based on the first NCC value for use in the RRC inactivity state; generating a first uplink message for transmission in the RRC inactivity state based on the first node key; and transmitting the first uplink message to a node while in the RRC inactivity state.
[0165] Embodiment 2 includes the subject matter of Embodiment 1, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein the first node key is the same as the second node key.
[0166] Embodiment 3 includes the subject matter of Embodiment 1, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
[0167] Embodiment 4 includes the subject matter of Embodiment 1, wherein the first NCC value is different from a second NCC value previously used to derive a second node key.
[0168] Embodiment 5 includes the subject matter according to Embodiment 4, and further includes: receiving first cell information from a second node, wherein a first node key is vertically derived based on a first NCC value and the first cell information from the second node; generating a second uplink message for transmission in the RRC inactive state based on the first node key; and transmitting the second uplink message when in the RRC inactive state.
[0169] Embodiment 6 includes the subject matter according to Embodiment 4, and further includes: receiving first cell information from a second node, wherein a first node key is vertically derived based on a first NCC value and the first cell information from the second node; horizontally deriving a third node key based on the first node key; generating a third uplink message for transmission in the RRC inactive state based on the third node key; and transmitting the third uplink message to a node when in the RRC inactive state.
[0170] Embodiment 7 includes the subject matter according to Embodiment 5, and further includes: receiving third cell information from a third node; vertically deriving a fourth node key based on the first NCC value and the third cell information; generating a third uplink message for transmission in the RRC inactive state based on the fourth node key; and transmitting the third uplink message to the third node when in the RRC inactive state.
[0171] Embodiment 8 includes the subject matter according to Embodiment 1, wherein the RRC suspension message includes a plurality of NCC values, and further includes: vertically deriving a second node key based on a second NCC value among the plurality of NCC values; generating a second uplink message for transmission in the RRC inactive state based on the second node key; and transmitting the second uplink message to a node when in the RRC inactive state.
[0172] Embodiment 9 includes the subject matter according to Embodiment 8, and further includes: determining that each NCC value among the plurality of NCC values has been used to derive a node key; horizontally deriving a third node key based on the determination that each NCC value among the plurality of NCC values has been used, based on the most recently used previous node key; generating a third uplink message for transmission in the RRC inactive state based on the third node key; and transmitting the third uplink message to a node when in the RRC inactive state.
[0173] Embodiment 10 includes the subject matter according to Embodiment 8, and further includes: determining that each NCC value among the plurality of NCC values has been used to derive a node key; generating a third uplink message for transmission in the RRC inactive state based on the most recently used previous node key; and transmitting the third uplink message to a node when in the RRC inactive state.
[0174] Embodiment 11 includes the subject matter according to Embodiment 8, and further includes: determining that each of the plurality of NCC values has been used to derive a node key; and triggering an RRC resume procedure.
[0175] Embodiment 12 includes the subject matter according to Embodiment 1, wherein a first uplink message is transmitted to a second node, and further includes: receiving a second NCC value from the second node; vertically deriving a second node key based on the second NCC value; generating a second uplink message for transmission in the RRC inactive state based on the second node key; and transmitting the second uplink message to a third node when in the RRC inactive state.
[0176] Embodiment 13 includes the subject matter according to Embodiment 1, wherein a first uplink message is transmitted to a second node, and further includes: receiving a second NCC value from the second node; determining that the second NCC value is the same as the first NCC value; horizontally deriving a second node key based on the first or second NCC value; generating a second uplink message for transmission in the RRC inactive state based on the second node key; and transmitting the second uplink message to a third node when in the RRC inactive state.
[0177] According to Embodiment 14, a wireless device is disclosed, the wireless device includes: an antenna; radio components, the radio components being operatively coupled to the antenna; and a processor, the processor being operatively coupled to the radio components; wherein the wireless device is configured to: receive a radio resource control (RRC) suspension message from a first node, the RRC suspension message including a first next-hop (NH) chain counter (NCC) value; enter the RRC inactive state; derive a first node key based on the first NCC value for use in the RRC inactive state; generate a first uplink message for transmission in the RRC inactive state based on the first node key; and transmit the first uplink message to a node when in the RRC inactive state.
[0178] Embodiment 15 includes the subject matter according to Embodiment 14, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein the first node key is the same as the second node key.
[0179] Embodiment 16 includes the subject matter according to Embodiment 14, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
[0180] Embodiment 17 includes the subject matter according to Embodiment 14, wherein the first NCC value is different from the second NCC value previously used to derive the second node key.
[0181] Embodiment 18 includes the subject matter according to Embodiment 17, wherein the wireless device is further configured to: receive first cell information from a second node, wherein a first node key is vertically derived based on the first NCC value and the first cell information from the second node; generate a second uplink message for transmission in the RRC inactive state based on the first node key; and transmit the second uplink message when in the RRC inactive state.
[0182] Embodiment 19 includes the subject matter according to Embodiment 18, wherein the wireless device is further configured to: receive first cell information from a second node, wherein a first node key is vertically derived based on the first NCC value and the first cell information from the second node; horizontally derive a third node key based on the first node key; generate a third uplink message for transmission in the RRC inactive state based on the third node key; and transmit the third uplink message to a node when in the RRC inactive state.
[0183] Embodiment 20 includes the subject matter according to Embodiment 18, wherein the wireless device is further configured to: receive third cell information from a third node; vertically derive a fourth node key based on the first NCC value and the third cell information; generate a third uplink message for transmission in the RRC inactive state based on the fourth node key; and transmit the third uplink message to the third node when in the RRC inactive state.
[0184] Embodiment 21 includes the subject matter according to Embodiment 14, wherein the RRC suspension message includes a plurality of NCC values, and the wireless device is further configured to: vertically derive a second node key based on a second NCC value among the plurality of NCC values; generate a second uplink message for transmission in the RRC inactive state based on the second node key; and transmit the second uplink message to a node when in the RRC inactive state.
[0185] Embodiment 22 includes the subject matter according to Embodiment 21, wherein the wireless device is further configured to: determine that each NCC value among the plurality of NCC values has been used to derive a node key; horizontally derive a third node key based on the determination that each NCC value among the plurality of NCC values has been used, based on the most recently used previous node key; generate a third uplink message for transmission in the RRC inactive state based on the third node key; and transmit the third uplink message to a node when in the RRC inactive state.
[0186] Embodiment 23 includes the subject matter according to Embodiment 21, wherein the wireless device is further configured to: determine that each of the plurality of NCC values has been used to derive a node key; generate a third uplink message for transmission in the RRC inactive state based on the most recently used previous node key; and transmit the third uplink message to a node when in the RRC inactive state.
[0187] Embodiment 24 includes the subject matter according to Embodiment 21, wherein the wireless device is further configured to: determine that each of the plurality of NCC values has been used to derive a node key; and trigger an RRC resume procedure.
[0188] Embodiment 25 includes the subject matter according to Embodiment 14, wherein a first uplink message is transmitted to a second node, and the wireless device is further configured to:
[0189] receive a second NCC value from the second node; vertically derive a second node key based on the second NCC value; generate a second uplink message for transmission in the RRC inactive state based on the second node key; and transmit the second uplink message to a third node when in the RRC inactive state.
[0190] Embodiment 26 includes the subject matter according to Embodiment 14, wherein a first uplink message is transmitted to a second node, and the wireless device is further configured to:
[0191] receive a second NCC value from the second node; determine that the second NCC value is the same as the first NCC value; horizontally derive a second node key based on the first or second NCC value; generate a second uplink message for transmission in the RRC inactive state based on the second node key; and transmit the second uplink message to a third node when in the RRC inactive state.
[0192] According to Embodiment 27, an integrated circuit is disclosed, the integrated circuit including circuitry configured to perform the following operations: cause a wireless device to receive a radio resource control (RRC) suspend message from a first node, the RRC suspend message including a first next-hop (NH) chain counter (NCC) value; cause the wireless device to enter the RRC inactive state; derive a first node key based on the first NCC value for use in the RRC inactive state; generate a first uplink message for transmission in the RRC inactive state based on the first node key; and cause the wireless device to transmit the first uplink message to a node when in the RRC inactive state.
[0193] Example 28 includes the subject matter according to Example 27, wherein the first NCC value is unchanged compared to the second NCC value previously used to derive the second node key, and wherein the first node key is the same as the second node key.
[0194] Example 29 includes the subject matter according to Example 27, wherein the first NCC value is unchanged compared to the second NCC value previously used to derive the second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
[0195] Example 30 includes the subject matter according to Example 27, wherein the first NCC value is different from the second NCC value previously used to derive the second node key.
[0196] Example 31 includes the subject matter according to Example 30, wherein the circuit is further configured to: cause the wireless device to receive first cell information from the second node, wherein the first node key is vertically derived based on the first NCC value and the first cell information from the second node; generate a second uplink message for transmission in the RRC inactive state based on the first node key; and cause the wireless device to transmit the second uplink message when in the RRC inactive state.
[0197] Example 32 includes the subject matter according to Example 31, wherein the circuit is further configured to: cause the wireless device to receive first cell information from the second node, wherein the first node key is vertically derived based on the first NCC value and the first cell information from the second node; horizontally derive a third node key based on the first node key; generate a third uplink message for transmission in the RRC inactive state based on the third node key; and cause the wireless device to transmit the third uplink message to the node when in the RRC inactive state.
[0198] Example 33 includes the subject matter according to Example 31, wherein the circuit is further configured to: cause the wireless device to receive third cell information from the third node; vertically derive a fourth node key based on the first NCC value and the third cell information; generate a third uplink message for transmission in the RRC inactive state based on the fourth node key; and cause the wireless device to transmit the third uplink message to the third node when in the RRC inactive state.
[0199] Example 34 includes the subject matter according to Example 27, wherein the RRC suspension message includes a plurality of NCC values, and wherein the circuit is further configured to: vertically derive a second node key based on a second NCC value among the plurality of NCC values; generate a second uplink message for transmission in the RRC inactive state based on the second node key; and cause the wireless device to transmit the second uplink message to the node when in the RRC inactive state.
[0200] Example 35 includes the subject matter according to Example 34, wherein the circuit is further configured to: determine that each NCC value among the plurality of NCC values has been used to derive a node key; horizontally derive a third node key based on the most recently used previous node key based on the determination that each NCC value among the plurality of NCC values has been used; generate a third uplink message for transmission in the RRC inactive state based on the third node key; and cause the wireless device to transmit the third uplink message to the node when in the RRC inactive state.
[0201] Example 36 includes the subject matter according to Example 34, wherein the circuit is further configured to: determine that each NCC value among the plurality of NCC values has been used to derive a node key; generate a third uplink message for transmission in the RRC inactive state based on the most recently used previous node key; and cause the wireless device to transmit the third uplink message to the node when in the RRC inactive state.
[0202] Example 37 includes the subject matter according to Example 34, wherein the circuit is further configured to: determine that each NCC value among the plurality of NCC values has been used to derive a node key; and trigger an RRC resume procedure.
[0203] Example 38 includes the subject matter according to Example 27, wherein a first uplink message is transmitted to a second node, and wherein the circuit is further configured to: cause the wireless device to receive a second NCC value from the second node; vertically derive a second node key based on the second NCC value; generate a second uplink message for transmission in the RRC inactive state based on the second node key; and cause the wireless device to transmit the second uplink message to a third node when in the RRC inactive state.
[0204] Embodiment 39 includes the subject matter according to Embodiment 27, wherein a first uplink message is transmitted to a second node, and wherein the circuitry is further configured to: cause the wireless device to receive a second NCC value from the second node; determine that the second NCC value is the same as the first NCC value; horizontally derive a second node key based on the first or second NCC value; generate a second uplink message for transmission in the RRC inactive state based on the second node key; and cause the wireless device to transmit the second uplink message to a third node when in the RRC inactive state.
[0205] According to Embodiment 40, a method for secure key derivation in a wireless system is disclosed, the method including: sending a Radio Resource Control (RRC) suspension message including a first Next Hop (NH) Chain Counter (NCC) value from a first node to a first user equipment; releasing access stratum (AS) resources associated with the first user equipment; deriving a first node key based on the first NCC value for use in the RRC inactive state; receiving a first uplink message from the first user equipment without allocating AS resources to the first user equipment; and descrambling the first uplink message based on the first NCC value.
[0206] Embodiment 41 includes the subject matter according to Embodiment 40, wherein the first uplink message is transmitted to a second node, and wherein the first node key is derived by the first node, and further includes: receiving a request for the first node key from the second node; and transmitting the first node key to the second node.
[0207] Embodiment 42 includes the subject matter according to Embodiment 40, wherein the first uplink message is transmitted to a second node, and further includes transmitting the first NCC value to the second node, wherein the first node key is derived by the second node.
[0208] Embodiment 43 includes the subject matter according to Embodiment 42, wherein in response to a request for the first node key from the second node, the first NCC value is transmitted to the second node.
[0209] Embodiment 44 includes the subject matter according to Embodiments 40 - 43, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein the first node key is the same as the second node key.
[0210] Embodiment 45 includes the subject matter according to Embodiments 40 - 43, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
[0211] Example 46 includes the subject matter according to Examples 40-43, wherein a first NCC value is different from a second NCC value previously used to derive a second node key.
[0212] Example 47 includes the subject matter according to Example 46, and further includes: transmitting first cell information from a second node, wherein a first node key is derived based on the first NCC value and the first cell information from the second node; receiving a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the first node key.
[0213] Example 48 includes the subject matter according to Example 46, and further includes: transmitting first cell information from a second node, wherein a first node key is derived based on the first NCC value and the first cell information from the second node; horizontally deriving a third node key based on the first node key; receiving a third uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the third uplink message based on the third node key.
[0214] Example 49 includes the subject matter according to Example 47, and further includes: transmitting third cell information from a third node; deriving a fourth node key based on the first NCC value and the third cell information; receiving a third uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the third uplink message based on the fourth node key.
[0215] Example 50 includes the subject matter according to Examples 40-43, wherein an RRC suspension message includes a plurality of NCC values, and further includes: deriving a second node key based on a second NCC value among the plurality of NCC values; receiving a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the second node key.
[0216] Example 51 includes the subject matter according to Example 50, and further includes: determining that each NCC value among the plurality of NCC values has been used to derive a node key; horizontally deriving a third node key based on the determination that each NCC value among the plurality of NCC values has been used, based on a most recently used previous node key; receiving a third uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the third node key.
[0217] Example 52 includes the subject matter according to Example 50, further comprising: determining that each of the plurality of NCC values has been used to derive a node key; receiving a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the most recently used previous node key.
[0218] Example 53 includes the subject matter according to Example 50, further comprising: after each of the plurality of NCC values has been used to derive a node key, receiving an RRC resume request from a first user equipment; and transmitting another RRC suspension message including another set of a plurality of NCC values to the first user equipment.
[0219] Example 54 includes the subject matter according to Examples 40-43, wherein a first uplink message is transmitted to a second node, and further comprising: transmitting a second NCC value from the second node; deriving a second node key based on the second NCC value; receiving a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the second node key.
[0220] Example 55 includes the subject matter according to Examples 40-43, wherein a first uplink message is transmitted to a second node, and further comprising: transmitting a first NCC value from the second node; horizontally deriving a second node key based on the first NCC value; receiving a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descrambling the second uplink message based on the second node key.
[0221] According to Example 56, a device is disclosed, the device comprising: a processor configured to: send a radio resource control (RRC) suspension message including a first next-hop (NH) chain counter (NCC) value from the device to a first user equipment; release access stratum (AS) resources associated with the first user equipment; derive a first node key based on the first NCC value for use in the RRC inactive state; receive a first uplink message from the first user equipment without allocating AS resources to the first user equipment; and descramble the first uplink message based on the first NCC value.
[0222] Example 57 includes the subject matter according to Example 56, wherein the first uplink message is transmitted to a second node, and wherein the first node key is derived by the device, and wherein the processor is further configured to: receive a request for the first node key from the second node; and transmit the first node key to the second node.
[0223] Example 58 includes the subject matter according to Example 56, wherein a first uplink message is transmitted to a second node, and wherein the processor is further configured to transmit a first NCC value to the second node, and wherein a first node key is derived by the second node.
[0224] Example 59 includes the subject matter according to Example 58, wherein in response to a request from the second node for the first node key, the first NCC value is transmitted to the second node.
[0225] Example 60 includes the subject matter according to Examples 56 - 59, wherein the first NCC value is unchanged compared to a second NCC value previously used to derive a second node key, and wherein the first node key is the same as the second node key.
[0226] Example 61 includes the subject matter according to Examples 56 - 59, wherein the first NCC value is unchanged compared to a second NCC value previously used to derive a second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
[0227] Example 62 includes the subject matter according to Examples 56 - 59, wherein the first NCC value is different from a second NCC value previously used to derive a second node key.
[0228] Example 63 includes the subject matter according to Example 62, wherein the processor is further configured to: transmit first cell information from the second node, wherein the first node key is derived based on the first NCC value and the first cell information from the second node; receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; and descramble the second uplink message based on the first node key.
[0229] Example 64 includes the subject matter according to Example 62, wherein the processor is further configured to: transmit first cell information from the first node, wherein the first node key is derived based on the first NCC value and the first cell information from the first node; horizontally derive a third node key based on the first node key;
[0230] receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; and descramble the third uplink message based on the third node key.
[0231] Example 65 includes the subject matter according to Example 64, wherein the processor is further configured to: transmit third cell information from a third node; derive a fourth node key based on a first NCC value and the third cell information; receive a third uplink message from a first user equipment without allocating AS resources to the first user equipment; and descramble the third uplink message based on the fourth node key.
[0232] Example 66 includes the subject matter according to Examples 56-59, wherein the RRC suspension message includes a plurality of NCC values, and the processor is further configured to: derive a second node key based on a second NCC value among the plurality of NCC values; receive a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descramble the second uplink message based on the second node key.
[0233] Example 67 includes the subject matter according to Example 66, wherein the processor is further configured to: determine that each NCC value among the plurality of NCC values has been used to derive a node key; derive a third node key horizontally based on the most recently used previous node key based on the determination that each NCC value among the plurality of NCC values has been used; receive a third uplink message from a first user equipment without allocating AS resources to the first user equipment; and descramble the second uplink message based on the third node key.
[0234] Example 68 includes the subject matter according to Example 66, wherein the processor is further configured to: determine that each NCC value among the plurality of NCC values has been used to derive a node key; receive a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descramble the second uplink message based on the most recently used previous node key.
[0235] Example 69 includes the subject matter according to Example 66, wherein the processor is further configured to: receive an RRC resume request from a first user equipment after each NCC value among the plurality of NCC values has been used to derive a node key; and transmit another RRC suspension message including another set of a plurality of NCC values to the first user equipment.
[0236] Example 70 includes the subject matter according to Examples 56-59, wherein a first uplink message is transmitted to a second node, and the processor is further configured to: transmit a second NCC value from the second node; derive a second node key based on the second NCC value; receive a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descramble the second uplink message based on the second node key.
[0237] Example 71 includes the subject matter according to Examples 56 - 59, wherein a first uplink message is transmitted to a second node, and the processor is further configured to: transmit a first NCC value from the second node; horizontally derive a second node key based on the first NCC value; receive a second uplink message from a first user equipment without allocating AS resources to the first user equipment; and descramble the second uplink message based on the second node key.
[0238] Another exemplary embodiment may include a method that includes: performing any or all parts of the foregoing embodiments by a device.
[0239] Yet another exemplary embodiment may include a non - transitory computer - accessible memory medium that includes program instructions that, when executed at a device, cause the device to implement any or all parts of any one of the foregoing embodiments.
[0240] Another exemplary embodiment may include a computer program that includes instructions for performing any or all parts of any one of the foregoing embodiments.
[0241] Yet another exemplary embodiment may include a device that includes means for performing any or all elements of any one of the foregoing embodiments.
[0242] Another exemplary embodiment may include a device that includes a processor configured to cause the device to perform any or all elements of any one of the foregoing embodiments.
[0243] It is well - known that the use of personally identifiable information should follow privacy policies and practices that are generally recognized to meet or exceed industry or government requirements for maintaining user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of inadvertent or unauthorized access or use, and the nature of authorized use should be clearly explained to users.
[0244] Aspects of the present disclosure can be implemented in any of a variety of forms. For example, some aspects can be implemented as a computer - implemented method, a computer - readable memory medium, or a computer system. Other aspects can be implemented using one or more custom - designed hardware devices such as an ASIC. Still other aspects can be implemented using one or more programmable hardware elements such as an FPGA.
[0245] In some aspects, a non-transitory computer-readable memory medium may be configured such that it stores program instructions and / or data, where if the program instructions are executed by a computer system, the computer system is caused to perform a method, such as any of the method embodiments described herein, or any combination of the method embodiments described herein, or any subset of any of the method embodiments described herein, or any combination of such subsets.
[0246] In some embodiments, a device (e.g., UE 106, BS 102, network element 600) may be configured to include a processor (or a set of processors) and a memory medium, where the memory medium stores program instructions, where the processor is configured to read and execute the program instructions from the memory medium, where the program instructions are executable to implement any of the various method embodiments described herein (or any combination of the method embodiments described herein, or any subset of any of the method embodiments described herein, or any combination of such subsets). The device may be implemented in any of a variety of forms.
[0247] While the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the above disclosure is fully understood. The present disclosure is intended that the following claims be construed to cover all such variations and modifications.
Claims
1. A method for security key derivation in a wireless system, comprising: sending a Radio Resource Control (RRC) suspension message from a first node to a first user equipment, the RRC suspension message including a plurality of Next Hop (NH) Chain Counter (NCC) values, the plurality of NCC values including a first NCC value; releasing access stratum (AS) resources associated with the first user equipment; deriving a first node key based on the first NCC value for use in the RRC inactive state; receiving a first uplink message from the first user equipment without allocating AS resources to the first user equipment; descrambling the first uplink message based on the first NCC value; deriving a second node key based on a second NCC value among the plurality of NCC values; receiving a second uplink message from the first user equipment without allocating AS resources to the first user equipment; descrambling the second uplink message based on the second node key; receiving an RRC resume request from the first user equipment after each of the plurality of NCC values has been used to derive a node key; and transmitting another RRC suspension message including another set of a plurality of NCC values to the first user equipment.
2. The method according to claim 1, wherein the first uplink message is transmitted to a second node, and wherein the first node key is derived by the first node, and the method further comprises: receiving a request from the second node for the first node key; and transmitting the first node key to the second node.
3. The method according to claim 1, wherein the first uplink message is transmitted to a second node, and the method further comprises transmitting the first NCC value to the second node, wherein the first node key is derived by the second node.
4. The method according to claim 3, wherein the first NCC value is transmitted to the second node in response to the second node's request for the first node key.
5. The method according to any one of claims 1 to 4, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein the first node key is the same as the second node key.
6. The method according to any one of claims 1 to 4, wherein the first NCC value has not changed compared to a second NCC value previously used to derive a second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
7. The method according to any one of claims 1 to 4, wherein the first NCC value is different from a second NCC value previously used to derive a second node key.
8. The method according to claim 7, further comprises: transmitting first cell information from a second node, wherein the first node key is derived based on the first NCC value and the first cell information from the second node; Receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descramble the second uplink message based on the first node key.
9. The method according to claim 7, further comprising: Transmit first cell information from a second node, wherein the first node key is derived based on the first NCC value and the first cell information from the second node; Derive a third node key horizontally based on the first node key; Receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descramble the third uplink message based on the third node key.
10. The method according to claim 8, further comprising: Transmit third cell information from a third node, Derive a fourth node key based on the first NCC value and the third cell information; Receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; AndDescramble the third uplink message based on the fourth node key.
11. The method according to claim 1, furthercomprising: Determine that each NCC value in the plurality of NCC values has been used to derive a node key; Based on the determination that each NCC value in the plurality of NCC values has been used, derive a third node key horizontally based on the most recently used previous node key; Receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; AndDescramble the second uplink message based on the third node key.
12. The method according to claim 1, furthercomprising: Determine that each NCC value in the plurality of NCC values has been used to derive a node key; Receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; AndDescramble the second uplink message based on the most recently used previous node key.
13. The method according to any one of claims 1 to 4, wherein the first uplink message is transmitted to a second node, and the method furthercomprising: Transmit a second NCC value from the second node; Derive a second node key based on the second NCC value; Receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; AndDescramble the second uplink message based on the second node key.
14. An electronic device, the electronic devicecomprising: A processor, the processor being configured to: Send a radio resource control (RRC) suspension message from the electronic device to a first user equipment, the RRC suspension message including a plurality of next-hop (NH) chain counters (NCC) values, the plurality of NCC values including a first NCC value; Release access stratum (AS) resources associated with the first user equipment; Derive a first node key based on the first NCC value for use in the RRC inactive state; Receiving a first uplink message from the first user equipment without allocating AS resources to the first user equipment; Descrambling the first uplink message based on the first NCC value; Deriving a second node key based on a second NCC value among the plurality of NCC values; Receiving a second uplink message from the first user equipment without allocating AS resources to the first user equipment; Descrambling the second uplink message based on the second node key; After each NCC value among the plurality of NCC values has been used to derive a node key, receiving an RRC resume request from the first user equipment; And Transmitting another RRC suspension message including another set of a plurality of NCC values to the first user equipment.
15. The electronic device according to claim 14, wherein the first uplink message is transmitted to a second node, and wherein the first node key is derived by the electronic device, and wherein the processor is further configured to: Receive a request for the first node key from the second node; and Transmit the first node key to the second node.
16. The electronic device according to claim 14, wherein the first uplink message is transmitted to a second node, and wherein the processor is further configured to transmit the first NCC value to the second node, and wherein the first node key is derived by the second node.
17. The electronic device according to claim 16, wherein in response to a request for the first node key from the second node, the first NCC value is transmitted to the second node.
18. The electronic device according to any one of claims 14 to 17, wherein the first NCC value is unchanged compared to a second NCC value previously used to derive a second node key, and wherein the first node key is the same as the second node key.
19. The electronic device according to any one of claims 14 to 17, wherein the first NCC value is unchanged compared to a second NCC value previously used to derive a second node key, and wherein deriving the first node key includes horizontally deriving the first node key based on the second node key.
20. The electronic device according to any one of claims 14 to 17, wherein the first NCC value is different from a second NCC value previously used to derive a second node key.
21. The electronic device according to claim 20, wherein the processor is further configured to: Transmit first cell information from a second node, wherein the first node key is derived based on the first NCC value and the first cell information from the second node; Receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descrambling the second uplink message based on the first node key.
22. The electronic device according to claim 20, wherein the processor is further configured to: Transmit first cell information from the first node, wherein the first node key is derived based on the first NCC value and the first cell information from the first node; Derive a third node key horizontally based on the first node key; Receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descramble the third uplink message based on the third node key.
23. The electronic device according to claim 22, wherein the processor is further configured to: Transmit third cell information from a third node; Derive a fourth node key based on the first NCC value and the third cell information; Receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descramble the third uplink message based on the fourth node key.
24. The electronic device according to claim 14, wherein the processor is further configured to: Determine that each NCC value in the plurality of NCC values has been used to derive a node key; Based on the determination that each NCC value in the plurality of NCC values has been used, derive a third node key horizontally based on the most recently used previous node key; Receive a third uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descramble the second uplink message based on the third node key.
25. The electronic device according to claim 14, wherein the processor is further configured to: Determine that each NCC value in the plurality of NCC values has been used to derive a node key; Receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; and Descramble the second uplink message based on the most recently used previous node key.
26. The electronic device according to any one of claims 14 to 17, wherein the first uplink message is transmitted to a second node, and the processor is further configured to: Transmit a second NCC value from the second node; Derive a second node key based on the second NCC value; Receive a second uplink message from the first user equipment without allocating AS resources to the first user equipment; And Descramble the second uplink message based on the second node key.
27. A non-transitory computer-readable medium storing instructions that, when executed, cause the method according to any one of claims 1-13 to be performed.
28. An integrated circuit comprising circuitry configured to cause a wireless device to perform the method according to any one of claims 1-13.
Citation Information
Patent Citations
Uplink small data transmission in inactive state
US20200137564A1