Method and apparatus for performing secure updates without resynchronization
By performing security updates at a specified time, the security key synchronization delay problem during UE switching across borders in NTN and IAB scenarios is solved, and the security configuration update is achieved without random access, which improves the switching efficiency.
Patent Information
- Application Number
- CN202180100554.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-17
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-05-17
AI Technical Summary
In non-terrestrial network (NTN) and integrated access and backhaul (IAB) scenarios, prior art requires performing random access processes to synchronize and refresh security keys when UEs switch across borders, resulting in delays and potential security configuration divergences.
By performing security updates at a specified point in time, including PDCP reconstruction, RLC reconstruction, and MAC reconstruction, without the need for random access processes, the UE is instructed to make security configuration changes such as security keys and algorithm updates.
It realizes security configuration updates without random access processes during cross-border switching, reducing latency, avoiding differences in security configurations, and improving switching efficiency.
Smart Images

Figure CN117693972B_ABST
Abstract
Description
Technical Field
[0001] Example embodiments herein relate generally to wireless networks and, more particularly, to methods and apparatus for performing security updates in such networks. Background Art
[0002] A non-terrestrial network (NTN) is a network or network segment that uses satellites, airborne aircraft, or spaceborne aircraft for transmission. NTN network nodes may include access and mobility management functions (AMFs), where each AMF may correspond to a country. Two AMFs may use a single base station (e.g., implemented in a satellite, or implemented on the ground and transmitted via satellite) to communicate with user equipment (UE), which is a wireless device, typically a mobile device. The area served by the base station may include part or all of one or more countries.
[0003] When a UE crosses a border between two countries, it will be transferred from the AMF in the originating country to the AMF in the destination country. This involves a Radio Resource Control (RRC) reconfiguration procedure, which typically involves reconfiguration of synchronization between the UE and the network and security key refresh.
[0004] In other areas, such as Integrated Access and Backhaul (IAB), synchronization reconfiguration and security key refresh between the UE and the network are also involved. A common point between NTN and IAB scenarios is that during handover, the serving cell is both the source cell and the target cell, or the UE remains synchronized with the serving cell during handover. Summary of the Invention
[0005] This section is intended to contain examples and is not intended to be limiting.
[0006] In one exemplary embodiment, a method is disclosed that includes receiving, at a user equipment communicating with a first serving cell of a base station, a command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration. The method also includes, in response to the time occurring, performing, by the user equipment, the security update to the new security configuration for communication with a second serving cell without performing a random access procedure.
[0007] Another exemplary embodiment includes a computer program comprising code for performing the method of the preceding paragraph when the computer program is executed on a processor. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium containing computer program code for a computer, is another example of a computer program according to this paragraph, wherein the program can be directly loaded into an internal memory of a computer.
[0008] An exemplary apparatus includes one or more processors and one or more memories including computer program code. The one or more memories and the computer program code are configured to, with the one or more processors, cause the apparatus to perform operations including: receiving, at a user equipment communicating with a first serving cell of a base station, a command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; and, in response to the time occurring, performing, by the user equipment, a security update to the new security configuration for communication with a second serving cell without performing a random access procedure.
[0009] An exemplary computer program product includes a computer-readable storage medium including computer program code for a computer. The computer program code includes code for: receiving, at a user equipment communicating with a first serving cell of a base station, a command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; and code for performing, by the user equipment, the security update to the new security configuration for communication with a second serving cell, in response to the time occurring, without performing a random access procedure.
[0010] In another exemplary embodiment, an apparatus includes means for: receiving, at a user equipment communicating with a first serving cell of a base station, a command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; and performing, by the user equipment, a security update to the new security configuration for communication with a second serving cell, in response to an occurrence of the time, without performing a random access procedure.
[0011] In one exemplary embodiment, a method is disclosed, comprising determining, at a base station communicating with a user equipment using a first serving cell, that a security update for the user equipment is required. The method includes sending, by the base station, a command to the user equipment, the command including information to perform the security update and an indication of a time to perform the security update, to change to a new security configuration. The method also includes, in response to the time occurring, performing the security update to the new security configuration for communicating with the user equipment using a second serving cell.
[0012] Another exemplary embodiment includes a computer program comprising code for performing the method of the preceding paragraph when the computer program is executed on a processor. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium containing computer program code for a computer, is another example of a computer program according to this paragraph, wherein the program can be directly loaded into an internal memory of a computer.
[0013] An exemplary apparatus includes one or more processors and one or more memories including computer program code. The one or more memories and the computer program code are configured to, with the one or more processors, cause the apparatus to perform operations including: determining, at a base station communicating with a user equipment using a first serving cell, that a security update for the user equipment needs to be performed. The method includes sending, by the base station to the user equipment, a command including information to perform the security update and an indication of a time to perform the security update, to change to a new security configuration. The method also includes, in response to the occurrence of the time, performing the security update to the new security configuration for communicating with the user equipment using a second serving cell.
[0014] An exemplary computer program product includes a computer-readable storage medium containing computer program code for a computer. The computer program code includes: determining, at a base station communicating with a user equipment using a first serving cell, that a security update for the user equipment is required. The method includes sending, by the base station, a command to the user equipment, the command including information for performing the security update and an indication of a time to perform the security update, to change to a new security configuration. The method also includes, in response to the occurrence of the time, performing the security update to the new security configuration for communicating with the user equipment using a second serving cell.
[0015] In another exemplary embodiment, an apparatus includes means for determining, at a base station communicating with a user equipment using a first serving cell, that a security update for the user equipment is required. The method includes sending, by the base station, a command to the user equipment, the command including information to perform the security update and an indication of a time to perform the security update, to change to a new security configuration. The method also includes, in response to the time occurring, performing the security update to the new security configuration for communicating with the user equipment using a second serving cell. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In the attached figure:
[0017] Figure 1 is a block diagram of one possible non-limiting example system in which the exemplary embodiments may be implemented;
[0018] Figure 2 An example of NTN deployment is shown when a shared gNB is connected to different AMFs.
[0019] Figure 3 is a signaling diagram illustrating an example of inter-AMF HO;
[0020] Figure 4 This is an example of the network-side protocol termination options for MCG, SCG, and split bearer in MR-DC (EN-DC) with EPC;
[0021] Figure 5is a signaling diagram illustrating an example call flow for Inter-AMF HO according to an exemplary embodiment;
[0022] Figure 6 is a flow diagram of logic executed by a UE for performing a security update without resynchronization; and
[0023] Figure 7 is a flow diagram of logic executed by a base station for performing a security update without resynchronization. DETAILED DESCRIPTION
[0024] At the end of the following Detailed Description section, abbreviations that may appear in the description and / or drawings are defined.
[0025] As used herein, the word "exemplary" means "serving as an example, instance, or illustration." Any embodiment described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments. All embodiments described in this detailed description are exemplary embodiments intended to enable those skilled in the art to make or use the invention, and are not intended to limit the scope of the invention as defined by the claims.
[0026] The exemplary embodiments herein describe techniques for performing secure updates without resynchronization. These techniques will be further described after describing a system in which the exemplary embodiments may be used.
[0027] See also Figure 1 , which shows a block diagram of one possible non-limiting exemplary system in which exemplary embodiments may be implemented. A user equipment (UE) 110, radio access network (RAN) nodes 170 and 170-1, and AMFs 190, 190-1 are shown.
[0028] exist Figure 1In the present invention, user equipment (UE) 110 wirelessly communicates with wireless network 100. A UE is a wireless device capable of accessing a wireless network, typically a mobile device. UE 110 includes one or more processors 120, one or more memories 125, and one or more transceivers 130 interconnected via one or more buses 127. Each of the one or more transceivers 130 includes a receiver (Rx) 132 and a transmitter (Tx) 133. The one or more buses 127 can be address, data, or control buses and can include any interconnect mechanism, such as a series of wires on a motherboard or integrated circuit, optical fiber, or other optical communication device. The one or more transceivers 130 are connected to one or more antennas 128. The one or more memories 125 contain computer program code 123. UE 110 includes a control module 140, which includes one or both of 140-1 and / or 140-2 and can be implemented in various ways. Control module 140 can be implemented in hardware as control module 140-1, for example, as part of one or more processors 120. Control module 140-1 may also be implemented as an integrated circuit or through other hardware such as a programmable gate array. In another example, control module 140 may be implemented as control module 140-2, which may be implemented as computer program code 123 and executed by one or more processors 120. For example, one or more memories 125 and computer program code 123 may be configured to, together with one or more processors 120, cause user equipment 110 to perform one or more operations described herein. UE 110 communicates with RAN node 170 via radio link 111 and communicates with RAN node 170-1 via radio link 111-1.
[0029] RAN nodes 170 and 170-1 are base stations that provide access to wireless network 100 by wireless devices (e.g., UE 100). RAN nodes 170 and 170-1 are primarily referred to herein as gNBs, but this is for exemplary purposes only, as described below. The two RAN nodes communicate using link 176. Additional RAN nodes may be present, but are not shown. The two RAN nodes 170 and 170-1 are assumed to be similar, so only the internal circuitry of RAN node 170 will be described.
[0030] For example, RAN node 170 may be a base station for 5G (also known as New Radio (NR)), a base station for 4G (also known as Long Term Evolution (LTE)), or a base station for any other access technology. In 5G, RAN node 170 may be an NG-RAN node, which is defined as a gNB or ng-eNB. A gNB is a node that provides NR user plane and control plane protocol terminations to UEs and is connected to the 5GC (e.g., network element(s) 190) via an NG interface. An ng-eNB is a node that provides E-UTRA user plane and control plane protocol terminations to UEs and is connected to the 5GC via an NG interface. An NG-RAN network may include multiple gNBs. A gNB may include a Central Unit (CU) (gNB-CU) 196 and one or more Distributed Units (DUs) (gNB-DUs), with DU 195 shown. Note that a DU may include, connect to, and control a Radio Unit (RU). A gNB-CU is a logical node that hosts the RRC, SDAP, and PDCP protocols for a gNB or the RRC and PDCP protocols for an en-gNB, and controls the operation of one or more gNB-DUs. The gNB-CU terminates the F1 interface with the gNB-DU. The F1 interface is illustrated as reference numeral 198, but reference numeral 198 also indicates links between remote and centralized elements of the RAN node 170, such as the link between the gNB-CU 196 and the gNB-DU 195. The gNB-DU is a logical node that hosts the RLC, MAC, and PHY layers of a gNB or en-gNB, with its operations partially controlled by the gNB-CU. A gNB-DU supports one or more cells, and a cell is supported by a gNB-DU. The gNB-DU terminates the F1 interface 198 with the gNB-CU. Note that the DU 195 is considered to include the transceiver 160, e.g., as part of a RU, but in some examples, the transceiver 160 may be part of a separate RU, e.g., controlled by and connected to the DU 195. The RAN node 170 may also be an eNB (evolved NodeB) base station for LTE (Long Term Evolution) or any other suitable base station.
[0031] The RAN node 170 includes one or more processors 152, one or more memories 155, one or more network interfaces (N / WI / F) 161, and one or more transceivers 160 interconnected via one or more buses 157. Each of the one or more transceivers 160 includes a receiver Rx 162 and a transmitter Tx 163. The one or more transceivers 160 are connected to one or more antennas 158. The one or more memories 155 include computer program code 153. The CU 196 may include the processor(s) 152, the memory 155, and the network interface 161. Note that the DU 195 may also include its own memory, processor(s), and / or other hardware, but these are not shown.
[0032] RAN node 170 includes a control module 150, which includes one or both of 150-1 and / or 150-2 and can be implemented in various ways. Control module 150 can be implemented in hardware as control module 150-1, for example, as part of one or more processors 152. Control module 150-1 can also be implemented as an integrated circuit or other hardware such as a programmable gate array. In another example, control module 150 can be implemented as control module 150-2, which is implemented as computer program code 153 and executed by one or more processors 152. For example, one or more memories 155 and computer program code 153 are configured to work with one or more processors 152 to enable RAN node 170 to perform one or more operations described herein. Note that the functionality of control module 150 can be distributed, for example, between DU 195 and CU 196, or can be implemented solely in DU 195.
[0033] One or more network interfaces 161 communicate over a network such as links 176 and 131. Two or more RAN nodes 170 communicate using, for example, link 176. Link 176 may be wired or wireless or both, and may implement, for example, an Xn interface for 5G, an X2 interface for LTE, or other suitable interfaces for other standards.
[0034] The one or more buses 157 may be address, data, or control buses and may include any interconnection mechanism, such as a series of wires on a motherboard or integrated circuit, optical fiber or other optical communication equipment, a wireless channel, etc. For example, the one or more transceivers 160 may be implemented as a remote radio head (RRH) 195 for LTE or a distributed unit (DU) 195 for 5G, and other elements of the RAN node 170 may be physically located at a different location from the RRH / DU. The one or more buses 157 may be implemented in part as, for example, optical fiber cables or other suitable networks to connect other elements of the RAN node 170 (e.g., central unit (CU), gNB-CU) to the RRH / DU 195. Reference numeral 198 also denotes these suitable network links.
[0035] It's important to note that while the description in this article refers to "cells" performing functions, it should be clear that the base stations that make up the cells perform these functions. A cell forms part of a base station. That is, each base station can have multiple cells. For example, a carrier frequency and associated bandwidth can have three cells, each covering one-third of a 360-degree area, resulting in a single base station's coverage area being roughly an ellipse or circle. Furthermore, each cell can correspond to a single carrier, and a base station can utilize multiple carriers. Therefore, if each carrier has three 120-degree cells, and there are two carriers, then the base station has a total of six cells.
[0036] The wireless network 100 may include AMFs 190 and 190-1. AMF 190 is considered as a source AMF in country A, and AMF 190-1 is considered as a target AMF in country B, for a UE to traverse from country A to country B at a specific location.
[0037] RAN node 170 is connected to AMF 190 via link 131 and to AMF 190-1 via link 131-1. RAN node 170-1 is connected to AMF 190 via link 133 and to AMF 190-1 via link 133-1. Links 131, 121-1, 133, and 133-1 can be implemented as 5G NG interfaces, LTE S1 interfaces, or other suitable interfaces of other standards. Assuming that AMF 190 and 190-1 are similar, this document only describes the internal configuration of AMF 190.
[0038] AMF 190 includes one or more processors 175, one or more memories 171, and one or more network interfaces (N / WI / F) 180, interconnected via one or more buses 185. The one or more memories 125 contain computer program code (CPC) 173. AMF 190 includes a control module 174, which includes one or both of 174-1 and / or 174-2 and can be implemented in a variety of ways. Control module 174 can be implemented in hardware as control module 174-1, for example, as part of one or more processors 175. Control module 174-1 can also be implemented as an integrated circuit or through other hardware such as a programmable gate array. In another example, control module 174 can be implemented as control module 174-2, which is implemented as computer program code 173 and executed by one or more processors 175. For example, the one or more memories 171 and computer program code 173 can be configured to work with one or more processors 175 to enable AMF 190 to perform one or more operations described herein.
[0039] It should be noted that there may be other network nodes (not shown) that may include core network functions and provide connectivity via one or more links to a data network, such as a telephone network and / or a data communications network (such as the Internet). In addition to the AMFs 190 and 191, such core network functions for 5G may also include (multiple) user plane functions (UPFs) and / or (multiple) session management functions (SMFs). Such core network functions for LTE may include MME (mobility management entity) functions and / or SGW (serving gateway) functions. These are only exemplary functions that may be supported, and it should be noted that both 5G and LTE functions may be supported.
[0040] Wireless network 100 can implement network virtualization, which is the process of combining hardware and software network resources and network functions into a single, software-based, manageable entity, namely, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization. Network virtualization can be categorized as external virtualization, which combines many networks or portions of networks into a single virtual unit, and internal virtualization, which provides network-like functionality to software containers on a single system. It is important to note that the virtualized entities created by network virtualization are still implemented, to some extent, using hardware, such as processors 152 or 175 and memories 155 and 171, and these virtualized entities also produce technical effects.
[0041] Computer-readable memories 125, 155, and 171 may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. Computer-readable memories 125, 155, and 171 may be used to perform storage functions. Processors 120, 152, and 175 may be of any type suitable for the local technical environment and may include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture, as non-limiting examples. Processors 120, 152, and 175 may be used to perform functions such as controlling UE 110, RAN node 170 / 170-1, and AMF 190 / 190-1, or other functions described herein.
[0042] In general, various embodiments of the user device 110 may include, but are not limited to, cellular phones (such as smart phones), tablet computers, personal digital assistants (PDAs) with wireless communication capabilities, portable computers with wireless communication capabilities, vehicles with modem devices for wireless V2X (vehicle-to-everything) communication, image capture devices (such as digital cameras with wireless communication capabilities), gaming devices with wireless communication capabilities, music storage and playback devices with wireless communication capabilities, Internet devices that allow wireless Internet access and can allow browsing (including IoT devices), IoT devices with automated application sensors and / or actuators of tablet computers with wireless communication capabilities, and portable units or terminals that integrate a combination of the above functions.
[0043] Having introduced a suitable but non-limiting technical background for the practice of the exemplary embodiments, the exemplary embodiments will now be described in more detail.
[0044] Regarding non-terrestrial networks (NTN), 3GPP TS 23.502 defines it as follows:
[0045] “The N2-based inter-NG-RAN node handover procedure specified in clause 4.9.1.3 may also be used for intra-NG-RAN node handover”.
[0046] “Note: One use case for intra-NG-RAN handover performed by the N2 based inter-NG-RAN node handover procedure is when the NG-RAN node serves a satellite access system covering more than one country. In this case, the UE may move from a “cell” in one country to a “cell” in another country and the NG-RAN node may need to change the AMF to the AMF serving the new country of the UE.”
[0047] Figure 2Figure 1 shows an example of an NTN deployment where a shared gNB connects to different AMFs. A shared NTN gNB 170 creates an NTN cell 250 spanning Country A 210-A and Country B 210-B. Countries 210 are separated by a border 230. AMF-1 190 is used for Country A, and AMF-2 190-1 is used for Country B. A UE 110 crosses border 230 along path 220.
[0048] As shown, an NTN cell (e.g., a GEO cell) 250 can cover a large geographic area, potentially spanning multiple countries 210. This cell 250 is created by an NTN payload (e.g., a GEO satellite) 240. NTN can be implemented using a transparent NTN payload, where a gNB (e.g., a shared NTN gNB 170) is deployed on the ground and the NTN payload acts as an RF repeater. In another example embodiment, NTN can be implemented using a regenerative NTN payload that carries some gNB functionality (e.g., the gNB-DU functionality of the shared NTN gNB 170) or all gNB functionality (e.g., the shared NTN gNB 170). The shared NTN gNB / cell 170 connects to AMFs 190 and 190-1 from the associated countries 210-A and 210-B, respectively. The gNB 170 ensures that the correct AMF is selected to serve the UE 110, e.g., based on the country in which the UE is located. When an RRC-CONNECTED UE crosses a country border 230, the UE is still served by the same NTN gNB / cell 170. However, the serving AMF will change, for example, the UE will be served by AMF-2 190-1 in country B instead of AMF-1 190 in country A. The serving gNB 170 can initiate an N2-based "handover" to change the AMF for the UE.
[0049] It is important to note that this issue can also occur during inter-host IAB node migration. This is because the change in the IAB host gNB during IAB node migration requires a change in the security keys of the UE served by the migrating IAB node (or its child IAB), while the radio cell serving the UE (i.e., the migrating IAB node's cell or a cell from its child IAB) does not change. For example, the UE remains synchronized (and connected) with the serving cell, and the physical cell identifier (PCI) remains unchanged after migration, even though the serving cell may use a different NR cell global identifier. In other words, the UE's serving IAB node does not change during IAB migration (or parent IAB migration). Therefore, during IAB migration (or parent IAB migration), either an N2-based handover procedure or an Xn-based handover procedure can be performed using the exemplary proposed method.
[0050] Regarding RRC reconfiguration as defined in 3GPP TS 38.331 (copied below), when RRC reconfiguration is to perform security key refresh, synchronization (or resynchronization) involving a random access (RA) procedure is always performed. The following is from 3GPP TS 38.331:
[0051] RRC reconfiguration to perform synchronous reconfiguration includes but is not limited to the following cases:
[0052] - Reconfiguration with synchronization and security key refresh, involving sending RA to PCell / PSCell, MAC reset, refreshing security, and re-establishment of RLC and PDCP triggered by explicit L2 indicators;
[0053] - Reconfiguration with synchronization but without security key refresh, including RA to PCell / PSCell, MAC reset and RLC re-establishment, and PDCP data resumption triggered by explicit L2 indicator (for AMDRB).
[0054] - Synchronous reconfiguration for DAPS and security key refresh, involving the establishment of RA, target MAC of target PCell, and
[0055] - For non-DAPS bearers: refresh security keys and re-establish RLC and PDCP triggered by explicit L2 indicators;
[0056] -For DAPS bearer: Establish RLC for the target PCell, refresh security, and reconfigure PDCP to add the encryption function, integrity protection function, and ROHC function of the target PCell;
[0057] - For SRB: refresh security and establish RLC and PDCP for the target PCell;
[0058] This concludes the text from 3GPP TS 38.331.
[0059] Typical N2-based AMF inter-HO is as follows: Figure 3 As shown, Figure 3 A signaling diagram illustrating an example of inter-AMF HO is shown. When UE 110 starts to perform HO, it detaches from the old cell and synchronizes to the new cell (eg, as a target cell).
[0060] In step 0 (zero), an RRC CONNECTED mode UE is served by the source gNB 170 and source AMF 190 from country A. In step 2, the source gNB 170 determines that the UE needs to be HOed to the target gNB 170-1, for example, based on the measurement report received from the UE in step 1. In step 3, the source gNB 170 sends an NGAP HANDOVER REQUIRED message to the source AMF 190. In step 4, the source AMF 190 sends a Namf_Communication_CreateUEContext request from country B to the target AMF 190-1. In step 5, the target AMF 190-1 sends an NGAP HANDOVER REQUEST message to the target gNB 190-1. In step 6, the target gNB responds to the target AMF 190-1 with an NGAP HANDOVER REQUEST ACKNOWLEDGE message. In step 7, the target AMF 190-1 returns a Namf_Communication_CreateUEContext response. Source AMF 190 sends an NGAP HANDOVER COMMAND to source gNB 170 in step 8, and source gNB 170 sends the command to the UE in step 9. This command can be an RRCReconfiguration message (also known as a HandoverCommand). UE 110 detaches from the old cell and synchronizes to the new cell in step 10. This requires at least synchronization with the target gNB (step 11), random access by UE 110 in step 12 and target gNB 170-1 in step 12A, and an RRC Reconfiguration Complete message from UE 110 in step 13. In step 14, the UE is served by target gNB 170-1 and target AMF 190-1.
[0061] In the case of NTN (e.g. Figure 2The following issues may arise using the above call flow (for the scenario shown). When an RRC-connected UE undergoes a HO, the security configuration, including security keys (e.g., KAMF) and potential security algorithms, needs to be updated. Because the serving gNB / cell acts as both the source gNB / cell and the target gNB / cell, the radio configuration can remain unchanged. Current NR RRC reconfiguration only supports "synchronization and security key refresh," involving a random access procedure that introduces latency of, for example, tens of milliseconds. Currently, the random access procedure allows the UE and network to separate the time periods during which PDCP PDUs protected by the previous security configuration and PDUs protected by the new security configuration are exchanged over the radio interface.
[0062] Therefore, a method is needed to perform security update without a random access procedure to avoid divergence in security configuration using different PDCP PDUs before and after intra-cell handover.
[0063] Before describing this approach, it is important to note that in dual connectivity, radio bearers can have different protocol architectures, as described in 3GPP TS 37.340. Figure 4 This figure is an example of network-side protocol termination options for MCG, SCG, and split bearers in MR-DC with EPC (EN-DC). This figure is from 3GPP TS 37.340. Figure 4 .2.2-3. The figure shows the different architectures of the MN (Master Node) of the primary cell group MCG and the SN (Secondary Node) of the secondary cell group SCG.
[0064] An example of a radio bearer where the security keys change but a random access procedure is not required is when the security keys of the radio bearer change while the RLC / MAC / PHY layers of the bearer on a given cell group (MCG or SCG) do not change. For example, a radio bearer can be reconfigured between an MCG bearer on the MN side (i.e., PDCP anchored at the MN) and a split bearer on the SN side (i.e., PDCP anchored at the SN): because the PDCP termination point on the network side changes, the security keys of the radio bearer also change, while the MCG RLC / MAC / PHY layers of the bearer do not change. In this case, 3GPP TS 37.340 allows the Logical Channel ID (LCID) used by the MCG RLC / MAC to be changed at the same time as the key change (in this case), thus avoiding the random access procedure on the MCG. This is summarized in Annex A of 3GPP TS 37.340. The disadvantage of the above LCID change method is that the LCID space needs to accommodate two values for each radio bearer.
[0065] In LTE, the UE can be instructed to perform a RACH-less handover, where the UE skips the random access procedure and sends an RRC reconfiguration complete message, performing the handover based on the uplink scheduling grant confirmation from the network. In the intra-cell handover scenario covered by the exemplary embodiments herein, this does not resolve the potential divergence in the security keys used for each PDCP PDU, as both the RRC reconfiguration to the UE and the response (e.g., complete message) from the UE may be out of order with respect to the reception of the user plane PDUs due to (H)ARQ retransmissions. This is particularly true in NTN and IAB use cases, where the PDCP round trip time may be longer than in terrestrial networks.
[0066] To address at least some of the above issues, exemplary embodiments herein propose a procedure for changing a UE's security configuration, such as security keys, security algorithms, and / or performing other security updates, without requiring a random access procedure or requiring two LCIDs per radio bearer. In summary, consider the following points.
[0067] 1) Signaling to the UE a time point at which a security update procedure (e.g., updating security keys, security algorithms, and / or other parameters) is to be performed. The time point may be represented by a radio frame and / or time slot number, or by a Coordinated Universal Time (UTC) time format, or by a timer, or by any other indication by which the UE can determine the time point.
[0068] 2) Performing a security update procedure at a specified time may involve the following.
[0069] a) PDCP re-establishment procedure: See, for example, 3GPP TS 38.323 Section 5.1.2.
[0070] b) RLC re-establishment procedure: See, for example, 3GPP TS 38.322 Section 5.1.2.
[0071] i) It is used to clear the transmission / reception pipeline of PDCP PDUs protected by the previous key, which is also the purpose of the following HARQ process related operations at the MAC layer (see below).
[0072] c) The new "MAC Rebuild" procedure involves the following.
[0073] i) There is no random access process and no implicit requirement for the random access process to continue transmission at a later stage.
[0074] As an example of this implicit requirement, it is noted that the current MAC reset procedure involves considering all time alignment timers as expired, which requires a random access process to regain uplink time alignment with the network in order to continue transmissions associated with MAC-SDU transmissions.
[0075] ii) “Reset” all HARQ processes, for example by performing the following operations:
[0076] Setting the New Data Indicator (NDI) for all uplink HARQ processes to a value of 0 (zero), or to any other value that resets these indicators;
[0077] Flushing soft buffers for all DL HARQ processes; and
[0078] • For each DL HARQ process, the next received transmission for a TB is considered the earliest transmission.
[0079] Now that the overview has been provided, more details will be provided.
[0080] Figure 5 Figure 2 shows an example call flow using an exemplary proposed method. This is a signaling diagram illustrating an example call flow for an inter-AMF HO according to an exemplary embodiment. In this example, source gNB 170 is also target gNB 170-1. To clarify, the same gNB is both the source gNB and the target gNB. In one exemplary embodiment (e.g., in an NTN network), a cell from the gNB is both the source cell and the target cell. In another exemplary embodiment (e.g., in an IAB network), the UE synchronizes (connects) to the same cell identified by the PCI from the base station (e.g., IAB node) before and after the handover.
[0081] Figure 5 The diagram illustrates the operation of one or more exemplary methods, the results of execution of computer program instructions embodied on a computer-readable memory, functions performed by logic implemented in hardware, and / or interconnected components for performing functions according to the exemplary embodiments. The UE 110, gNB 170 / 170-1, and AMF 190 / 190-1 perform the respective operations under the control of their respective control modules 140, 150, or 174.
[0082] The process starts with the RRC CONNECTEDUE 110 located in country A210-A, served by the gNB 170 and the source AMF 190 (step 0, zero).
[0083] In step 1, when UE 110 moves (in step 0.5) from country A 210-A to country B 210-B, the UE sends an indication of its location (e.g., a location report) to gNB 170. Alternatively, gNB 170 may periodically request the UE to report its location to determine if the UE moves to a different country.
[0084] In step 2, based on the indication / location report from the UE, gNB 170 detects whether the UE's serving AMF should be changed. In this case, because the UE has changed countries, the serving AMF 190 should be changed. The gNB determines the target AMF 190-1 based on the UE's current location. gNB 170 also selects the relevant cell ID of the gNB so that the target AMF 190-1 selects the current gNB as the target for routing HO signaling.
[0085] In step 3, the gNB sends an NGAP HANDOVER REQUIRED message including an IE (or other indication) to identify the UE in the gNB (source). The content of the IE may include a global gNB ID to identify the gNB serving the UE before the HO, and an ID (e.g., RAN UE NGAP ID) to identify the UE in the gNB. Its content may be similar to the UE Context Reference in the Source IE in the LTE specification (3GPP TS 38.413), but the usage is different (i.e., the LTE IE is used when the source node acts as the target SN node, and there is no DC in this case). This information is forwarded from the source AMF 190 to the target AMF 190-1 via step 4 for Country B 210-B.
[0086] Regarding step 5, upon receiving the NGAP HANDOVER REQUEST message, the gNB detects that the handover is related to an existing UE 110. This can be detected using an IE (e.g., or other indication) in the NGAP HANDOVER REQUEST message. The gNB is here referred to as target gNB 170-1. The gNB generates an RRC Reconfiguration message containing information for reconfiguring new security, such as new security keys, new security algorithms, etc. The RRC Reconfiguration message also includes the time to perform the security change (e.g., keys and security algorithms, etc.). For example, the gNB can indicate the time in terms of radio frames and / or timeslot numbers. It can also be UTC time, a timer, or anything else that allows the UE to determine when to perform the security change.
[0087] In step 6, the gNB sends an NGAP HANDOVER REQUESTACKNOWLEDGE message including an RRCReconfiguration message (also called a HandoverCommand, which also includes time information) to the target AMF 190-1. The RRCReconfiguration message is further forwarded to the source AMF 190 in step 7. The source AMF sends an NGAP HANDOVER COMMAND message including the RRCReconfiguration message to the gNB in step 8. The gNB acts as the source gNB 170. The gNB sends the RRCReconfiguration message including the time information to the UE in step 9.
[0088] Alternatively, the time information for performing security (e.g., key and security algorithm, etc.) changes may be generated by the source gNB 170 rather than the target gNB 170-1. In an example embodiment, for example, Figure 2 In the NTN network shown in the figure or in the inter-host IAB node migration, use Figure 5 The N2-based handover procedure is shown. When the gNB serving as the source gNB 170 receives the NGAP HANDOVER COMMAND message in step 8, the gNB generates time information and sends an RRCReconfiguration message including the time information to the UE in step 9. In another example embodiment, an Xn-based handover procedure (not shown) is used, such as in inter-host IAB node migration. When the gNB serving as the source gNB 170 receives the XnAP HANDOVER REQUESTACKNOWLEDGE message (not shown), the gNB generates time information and sends an RRCReconfiguration message including the time information to the UE in step 9. When the source gNB and the target gNB are the same gNB, the time information can be exchanged between the source gNB and the target gNB, for example, via internal communication between the source gNB and the target gNB or any other implementation method.
[0089] In some cases, generating time information in the source gNB can be beneficial. For example, when the gNB is mounted on a satellite and the AMF is located on Earth, there may be long delays in communication between the gNB and the AMF. If the target gNB generates time information, the time information may be inaccurate due to the long delay between sending the NGAP HANDOVER REQUEST ACKNOWLEDGE message in step 6 and sending the RRCReconfiguration message to the UE in step 9. When the source gNB generates time information, the time information is more accurate because the source gNB only needs to consider the delay between the UE and the gNB.
[0090] Considering the high RTT in NTN, there may be some DL transmissions that occur after the UE sends RRCReconfigurationComplete but before the gNB 170-1 receives the message, which will cause key disagreement. Time-based configuration can avoid the disagreement between the UE and gNB.
[0091] In step 9, the gNB, acting as the source gNB 170, sends a handover command and a security update without resynchronization indication to the UE 110. In step 10, the UE performs a security update without random access. In step 10A, the gNB performs a security update for the UE. Steps 10 and 10A may be performed at least partially in parallel. Steps 9 and 10 refer to Figure 6 Supplementary description, refer to Step 9 and Step 10A Figure 7 Additional description.
[0092] Go to Figure 6 , which is a logic flow diagram used by a UE to perform a security update without resynchronization. The figure also illustrates the operations of one or more exemplary methods, the results of executing computer program instructions embodied on a computer-readable memory, functions performed by logic implemented in hardware, and / or interconnected components for performing functions according to exemplary embodiments. It is assumed that the UE performs these operations under the control of control module 140.
[0093] In step 9, the source gNB 170 sends an RRCReconfiguration message to the UE 110 and the message is received by the UE. Note that generating the handover command to the UE is performed by the target gNB (e.g., a characteristic of the target gNB), but sending the handover command to the UE is performed by the source gNB (e.g., a characteristic of the source gNB). In one example embodiment, the time information is generated by the target gNB, e.g., when the gNB receives the NGAP HANDOVER REQUEST message. In another example embodiment, the time information is generated by the source gNB, e.g., when the gNB receives the NGAP HANDOVER COMMAND message. As previously described, the RRCReconfiguration message carries information for reconfiguring security for security updates (e.g., creating new keys, implementing new security algorithms, etc.). Block 610 illustrates this. The RRCReconfiguration message also includes the time at which the security change was performed. See block 615.
[0094] UE 110 must wait until the specified time indicated by the timer to perform the security change. This is accomplished by the UE determining in block 620 whether the specified time has arrived. If not (block 620 = No), the UE continues to communicate with the serving cell using the current security configuration and waits. If the specified time has arrived (block 620 = Yes), the process proceeds to step 10.
[0095] For step 10, at the specific time received and indicated in step 9, UE 110 performs security update without random access using the following procedure.
[0096] a) PDCP Re-establishment Procedure. See 3GPP TS 38.323, Section 5.1.2. At a minimum, this procedure uses information to reconfigure security, such as creating new keys and implementing new security algorithms. This may generate new keys for the UE to use with the target gNB 170-1. It may also generate both new keys and new security algorithms. Either only creating new keys or only implementing new security algorithms may be performed.
[0097] b) RLC re-establishment process. See 3GPP TS 38.322 Section 5.1.2. For example, according to TS 38.22 Section 5.1.2, when the upper layer requests the RLC entity to re-establish, the UE shall discard all RLC SDUs, RLC SDU segments, and RLC PDUs (if any); stop and reset all timers; and reset all state variables to their initial values.
[0098] i) This is to clear the transmission / reception pipeline from PDCP PDUs protected by the previous key, which is also the purpose of the following HARQ process related operations at the MAC layer (see below).
[0099] c) The new "MAC Rebuild" procedure involves the following.
[0100] i) There is no random access process and no implicit requirement for the random access process to continue transmission at a later stage.
[0101] As an example of this implicit requirement, it is noted that the current MAC reset procedure involves considering all time alignment timers as expired, which requires a random access process to regain uplink time alignment with the network in order to continue transmission associated with MAC-SDU transmission.
[0102] ii) “Reset” all HARQ processes, for example by performing the following operations:
[0103] • Setting the New Data Indicator (NDI) of all uplink HARQ processes to a value of 0 (zero), or any other value for resetting these values, see block 665;
[0104] • Flushing the soft buffers for all DL HARQ processes, block 660; and
[0105] • For each DL HARQ process, consider the next received transmission for a TB as the earliest transmission, see block 665 .
[0106] In step 11, UE 110 sends an RRCReconfigurationComplete message to the gNB, which is now the target gNB 170-1. In step 12, the UE is served by the target gNB 170-1 and the target AMF 190-1.
[0107] It should be noted that Figure 3 Step 11 (synchronization) and step 12 (random access) in Figure 5 Not used in.
[0108] It is important to note that the security update procedures without random access are performed more or less simultaneously and in a coordinated manner, rather than sequentially. For example, as part of PDCP re-establishment, the PDCP layer may retransmit unacknowledged PDUs that are now protected by new keys. However, such retransmissions should not be performed before RLC re-establishment has flushed all RLC buffers.
[0109] See also Figure 7, which is a logic flow diagram for performing a security update without resynchronization by a base station. This figure also illustrates the operations of one or more exemplary methods, the results of executing computer program instructions embodied on a computer-readable memory, functions performed by logic implemented in hardware, and / or interconnected components for performing functions according to exemplary embodiments. These operations are assumed to be performed by a base station, such as gNB 170 / 170-1 (or other base station) controlled by control module 150. In this example, the base station is assumed to be a gNB, but this is for illustrative purposes only.
[0110] In step 9, the source gNB 170 sends an RRCReconfiguration (or Handover Command) message to the UE 110. As previously mentioned, it is important to note that the generation of the Handover Command to the UE is performed by the target gNB (e.g., a characteristic of the target gNB), but the sending of the Handover Command to the UE is performed by the source gNB (e.g., a characteristic of the source gNB). In one example embodiment, the time information is generated by the target gNB, e.g., when the gNB receives the NGAP HANDOVER REQUEST message. In another example embodiment, the time information is generated by the source gNB, e.g., when the gNB receives the NGAP HANDOVER COMMAND message. As previously mentioned, the RRCReconfiguration message carries information for reconfiguring security (e.g., creating new keys, implementing new security algorithms, etc.) for security updates. Block 610 illustrates this. The RRCReconfiguration message also includes the time at which the security change was performed. See block 615.
[0111] The gNB waits until the specified time indicated by the timer before performing the security change. This is accomplished by the gNB determining in block 680 whether the specified time has arrived. If not (block 680 = No), the gNB continues communicating with the UE using the current security configuration and waits. If the specified time has arrived (block 680 = Yes), the process proceeds to step 10A.
[0112] For step 10A, at the specific time sent and indicated in step 9, the gNB performs security update for UE 110 using the following procedure.
[0113] a) PDCP re-establishment process. This procedure uses information to reconfigure security, for example, creating new keys and implementing new security algorithms. This generates at least one new key for the network node to use for communication with the UE. It is also possible to generate both new keys and new security algorithms. Alternatively, it is possible to create only new keys or only implement new security algorithms.
[0114] b) RLC re-establishment process.
[0115] i) This is to clear the transmission / reception pipeline from PDCP PDUs protected by the previous key, which is also the purpose of the following HARQ process related operations at the MAC layer (see below).
[0116] c) The new "MAC Rebuild" procedure involves the following.
[0117] i) No random access process is expected or implicitly required to continue transmission at a later stage. In other words, no random access process should be performed either at the beginning of the MAC re-establishment process or at any time during this procedure.
[0118] ii) "Reset" all HARQ processes related to the UE.
[0119] It is also important to note that Figure 5 、 Figure 6 and Figure 7 While relevant to NTN, the technology disclosed herein is not limited to NTN. This type of reconfiguration, along with synchronization and security updates between the UE and the network, also relates to other areas, such as Integrated Access and Backhaul (IAB), and potentially other areas where a security update needs to be performed for the UE (e.g., due to migration of the IAB node) and the UE's serving cell remains unchanged after the security update.
[0120] It is also important to note that Figure 5 、 Figure 6 and Figure 7 This disclosure is related to, but not limited to, N2-based handovers. This type of reconfiguration, along with synchronization and security updates between the UE and the network, also pertains to other areas, such as Xn-based handovers, where a security update needs to be performed for the UE (e.g., due to migration of the IAB node), while the UE's serving cell remains unchanged after the security update.
[0121] also, Figure 5 、 Figure 6 and Figure 7 5G terminology and devices are used (e.g., gNB, AMF), but the exemplary embodiments are also applicable to 4G (e.g., eNB, MME), or networks with a mix of 5G and LTE, or other wireless networks where similar problems exist and / or the solutions described herein are applicable.
[0122] Without in any way limiting the scope, interpretation, or application of the claims appearing below, the technical effects and advantages of one or more example embodiments disclosed herein allow reconfiguration of security keys in the UE when the AMF is changed without using a synchronized full reconfiguration.
[0123] Other exemplary embodiments include the following.
[0124] Example 1. A method comprising:
[0125] receiving, at a user equipment in communication with a first serving cell of the base station, a command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; and
[0126] In response to the event occurring, a security update to a new security configuration is performed by the user equipment for communication with the second serving cell without performing a random access procedure.
[0127] Example 2. The method according to Example 1, wherein the first serving cell and the second serving cell are the same cell from a base station.
[0128] Example 3. The method of example 1 or 2, wherein the base station is part of a non-terrestrial network.
[0129] Example 4. The method of Example 1, wherein the first serving cell and the second serving cell use the same physical cell identifier, and the method is performed for integrated access and backhaul inter-host centralized unit migration, and processing user equipment whose serving integrated access and backhaul unit does not change during the migration.
[0130] Example 5. The method of any one of Examples 1 to 4, wherein performing the security update comprises performing a packet data convergence protocol reestablishment procedure, and performing the security update using the information to reconfigure security such that the user equipment creates new keys or implements new security algorithms, or both, as part of the new security configuration.
[0131] Example 6. The method according to Example 5, further comprising: performing a radio link control re-establishment procedure.
[0132] Example 7. The method according to any one of Examples 5 or 6, further comprising: performing a media access control re-establishment procedure.
[0133] Example 8. The method of Example 7, wherein the medium access control re-establishment procedure does not involve the random access procedure and does not implicitly require the random access procedure to continue transmission at a later stage.
[0134] Example 9. The method according to Example 7 or 8, further comprising: resetting all hybrid automatic repeat request processes of the user equipment.
[0135] Example 10. The method of Example 9, wherein resetting all hybrid automatic repeat request processes of the user equipment further comprises:
[0136] setting the new data indicator for all uplink hybrid automatic repeat request processes to a value indicating that the indicator is reset;
[0137] Flushing soft buffers for all downlink hybrid automatic repeat request processes; and
[0138] For each downlink HARQ process, the next received transmission for a transport block is considered as the earliest transmission.
[0139] Example 11. The method of any one of Examples 1 to 10, wherein the information for performing security update comprises: creating a new key or implementing a new security algorithm, or both creating a new key and implementing a new security algorithm.
[0140] Example 12. The method according to any one of Examples 1 to 11, further comprising: communicating, by the user equipment, with a serving cell of the base station using the new security configuration.
[0141] Example 13. The method of any one of Examples 1 to 12, wherein the indication of a time to perform a security update to a new security configuration comprises at least one of:
[0142] number of radio frames or time slots or radio frames and time slots, or
[0143] timer, or
[0144] A timestamp in Coordinated Universal Time (UTC) format.
[0145] Example 14. The method according to Example 13 further includes: determining, by the user equipment, that the time has occurred by at least performing one or more of the following:
[0146] Determine that the time has occurred based on a number of radio frames or time slots or radio frames and time slots, or
[0147] According to the timer, determine that the time has occurred, or
[0148] Determines that an event has occurred based on a timestamp in Coordinated Universal Time (UTC) time format.
[0149] Example 15. A method comprising:
[0150] At a base station communicating with the user equipment using the first serving cell, determining that a security update needs to be performed for the user equipment;
[0151] The base station sends a command to the user equipment, the command including information for performing security update and an indication of a time for performing the security update, so as to change to a new security configuration; and
[0152] In response to the event occurring, a security update to a new security configuration is performed for communicating with the user equipment using the second serving cell.
[0153] Example 16. The method of Example 15, wherein the first serving cell and the second serving cell are the same cell from a base station.
[0154] Example 17. The method of Example 16, wherein the time to perform a security update to change to a new security configuration is generated by:
[0155] In response to the handover request information received by the base station, serving as a second serving cell of the target base station; or
[0156] In response to a handover command message received by the base station in an N2-based handover process, or in response to a handover request confirmation received by the base station in an Xn-based handover process, the first serving cell of the source base station.
[0157] Example 18. The method of any one of Examples 15 to 17, wherein the base station is part of a non-terrestrial network.
[0158] Example 19. The method of Example 15, wherein the first serving cell and the second serving cell use the same physical cell identifier, and the method is performed for integrated access and backhaul inter-host centralized unit migration, and processing user equipment whose serving integrated access and backhaul unit does not change during the migration.
[0159] Example 20. The method of any one of Examples 15 to 19, wherein performing the security update comprises performing a packet data convergence protocol reestablishment procedure, and performing the security update using the information to reconfigure security such that the base station creates new keys or implements new security algorithms, or both, as part of the new security configuration.
[0160] Example 21. The method according to Example 20, further comprising: performing a radio link control re-establishment procedure.
[0161] Example 22. The method according to any one of Examples 20 or 21, further comprising performing a medium access control re-establishment procedure.
[0162] Example 23. The method of Example 22, wherein for the MAC re-establishment procedure, the base station does not expect a random access procedure, or implicitly requires the random access procedure to continue transmission at a later stage.
[0163] Example 24. The method according to any one of Examples 22 or 23, further comprising: resetting all hybrid automatic repeat request processes associated with the user equipment.
[0164] Example 25. The method of any one of Examples 15 to 24, wherein the information for performing security updates comprises: creating a new key or implementing a new security algorithm, or both creating a new key and implementing a new security algorithm.
[0165] Example 26. The method according to any one of Examples 15 to 25, further comprising: communicating, by the second serving cell, with the user equipment using the new security configuration.
[0166] Example 27. The method of any one of Examples 15 to 26, wherein the indication of a time to perform a security update to a new security configuration comprises at least one of:
[0167] number of radio frames or time slots or radio frames and time slots, or
[0168] timer, or
[0169] A timestamp in Coordinated Universal Time (UTC) format.
[0170] Example 28. The method according to Example 27 further includes: determining, by the base station, that the time has occurred by at least performing one or more of the following:
[0171] Determine that the time has occurred based on a radio frame or time slot or a number of radio frames and time slots, or
[0172] According to the timer, determine that the time has occurred, or
[0173] Determines that an event has occurred based on a timestamp in Coordinated Universal Time (UTC) time format.
[0174] Example 29. An apparatus comprising means for performing:
[0175] receiving, at a user equipment in communication with a first serving cell of the base station, a command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; and
[0176] In response to the event occurring, a security update to a new security configuration is performed by the user equipment for communication with the second serving cell without performing a random access procedure.
[0177] Example 30. The apparatus according to Example 29, wherein the first serving cell and the second serving cell are the same cell from a base station.
[0178] Example 31. The apparatus according to any of Examples 29 or 30, wherein the base station is part of a non-terrestrial network.
[0179] Example 32. The apparatus of Example 29, wherein the first serving cell and the second serving cell use the same physical cell identifier, and wherein receiving and executing security updates are performed for integrated access and backhaul inter-host centralized unit migration, and processing user equipment whose serving integrated access and backhaul unit does not change during the migration.
[0180] Example 33. The apparatus of any one of Examples 29 to 32, wherein performing the security update comprises: performing a packet data convergence protocol reestablishment procedure, and performing the security update using the information to reconfigure security such that the user equipment creates new keys or implements new security algorithms, or both, as part of the new security configuration.
[0181] Example 34. The apparatus according to Example 33, further comprising: performing a radio link control re-establishment procedure.
[0182] Example 35. The apparatus according to any one of Examples 33 or 34, further comprising: performing a medium access control re-establishment procedure.
[0183] Example 36. The apparatus according to Example 35, wherein the medium access control re-establishment procedure does not involve the random access procedure and does not implicitly require the random access procedure to continue transmission at a later stage.
[0184] Example 37. The apparatus according to any one of Examples 35 or 36, further comprising: resetting all hybrid automatic repeat request processes of the user equipment.
[0185] Example 38. The apparatus according to Example 37, wherein resetting all hybrid automatic repeat request processes of the user equipment further comprises:
[0186] setting the new data indicator for all uplink hybrid automatic repeat request processes to a value indicating that the indicator is reset;
[0187] Flushing soft buffers for all downlink hybrid automatic repeat request processes; and
[0188] For each downlink HARQ process, the next received transmission for a transport block is considered as the earliest transmission.
[0189] Example 39. The apparatus according to any one of Examples 29 to 38, wherein the information for performing security update comprises information for creating a new key or implementing a new security algorithm, or information for both creating a new key and implementing a new security algorithm.
[0190] Example 40. The apparatus according to any one of Examples 29 to 39, further comprising: communicating, by the user equipment, with a serving cell of the base station using the new security configuration.
[0191] Example 41. The apparatus of any one of Examples 29 to 40, wherein the indication of a time to perform a security update to a new security configuration comprises at least one of:
[0192] number of radio frames or time slots or radio frames and time slots, or
[0193] timer, or
[0194] A timestamp in Coordinated Universal Time (UTC) format.
[0195] Example 42. The apparatus according to Example 41, further comprising: determining, by the user equipment, that the time has occurred by at least performing one or more of the following:
[0196] Determine that the time has occurred based on a number of radio frames or time slots or radio frames and time slots, or
[0197] According to the timer, determine that the time has occurred, or
[0198] Determines that an event has occurred based on a timestamp in Coordinated Universal Time (UTC) time format.
[0199] Example 43. An apparatus comprising means for performing:
[0200] At a base station communicating with the user equipment using the first serving cell, determining that a security update needs to be performed for the user equipment;
[0201] The base station sends a command to the user equipment, the command including information for performing security update and an indication of a time for performing the security update, so as to change to a new security configuration; and
[0202] In response to the event occurring, a security update to a new security configuration is performed for communicating with the user equipment using the second serving cell.
[0203] Example 44. The apparatus according to Example 43, wherein the first serving cell and the second serving cell are the same cell from a base station.
[0204] Example 45. The apparatus of Example 44, wherein the time to perform a security update to change to a new security configuration is generated by:
[0205] In response to the handover request information received by the base station, serving as a second serving cell of the target base station; or
[0206] In response to a handover command message received by the base station in an N2-based handover process, or in response to a handover request confirmation received by the base station in an Xn-based handover process, the first serving cell of the source base station.
[0207] Example 46. The apparatus according to any one of Examples 43 to 45, wherein the base station is part of a non-terrestrial network.
[0208] Example 47. The apparatus of Example 43, wherein the first serving cell and the second serving cell use the same physical cell identifier, and determining, sending, and performing the security update are performed for integrated access and backhaul inter-host centralized unit migration, and handling user equipment whose serving integrated access and backhaul unit does not change during the migration.
[0209] Example 48. The apparatus of any one of Examples 43 to 47, wherein performing the security update comprises performing a Packet Data Convergence Protocol re-establishment procedure, and performing the security update using the information to reconfigure security such that the base station creates new keys or implements new security algorithms, or both, as part of the new security configuration.
[0210] Example 49. The apparatus according to Example 48, wherein the component is further configured to perform: performing a radio link control re-establishment procedure.
[0211] Example 50. The apparatus according to any of Examples 48 or 49, wherein the component is further configured to perform: performing a medium access control re-establishment procedure.
[0212] Example 51. The apparatus according to Example 50, wherein for the MAC re-establishment procedure, the base station does not expect the random access procedure, or implicitly requires the random access procedure to continue transmission at a later stage.
[0213] Example 52. The apparatus according to any of Examples 50 or 51, wherein the component is further configured to perform: resetting all hybrid automatic repeat request processes related to the user equipment.
[0214] Example 53. The apparatus according to any one of Examples 43 to 52, wherein the information for performing security update comprises information for creating a new key or implementing a new security algorithm, or information for both creating a new key and implementing a new security algorithm.
[0215] Example 54. The apparatus according to any one of Examples 43 to 53, wherein the component is further configured to perform: communicating, by the second serving cell, with the user equipment using the new security configuration.
[0216] Example 55. The apparatus of any one of Examples 43 to 54, wherein the indication of a time to perform a security update to a new security configuration comprises at least one of:
[0217] number of radio frames or time slots or radio frames and time slots, or
[0218] timer, or
[0219] A timestamp in Coordinated Universal Time (UTC) format.
[0220] Example 56. The apparatus of Example 55, wherein the component is further configured to perform: determining, by the base station, that the time has occurred by at least performing one or more of the following:
[0221] Determine that the time has occurred based on a number of radio frames or time slots or radio frames and time slots, or
[0222] According to the timer, determine that the time has occurred, or
[0223] Determines that an event has occurred based on a timestamp in Coordinated Universal Time (UTC) time format.
[0224] Example 57. The apparatus according to any of the preceding apparatus examples, wherein the apparatus comprises:
[0225] at least one processor; and
[0226] At least one memory including computer program code, the at least one memory and the computer program code being configured to, with at least one processor, cause the apparatus to perform operations.
[0227] As used in this application, the term "circuitry" may refer to one or more or all of the following:
[0228] (a) a pure hardware circuit implementation (such as an implementation using only analog and / or digital circuitry), and
[0229] (b) a combination of hardware circuitry and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuitry and software / firmware, and (ii) any portion of hardware processor(s) (including digital signal processors), software and memory(s) with software, which work together to enable a device (such as a mobile phone or server) to perform various functions, and
[0230] (c) Hardware circuit(s) and / or processor(s), such as microprocessor(s) or portion(s) of microprocessor(s), that require software (e.g., firmware) to operate, but which may not be present when not required for operation.
[0231] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. For example, if applicable to the particular claim element, the term circuitry also covers a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device.
[0232] Embodiments of the present invention may be implemented by software (executed by one or more processors), hardware (e.g., application specific integrated circuits), or a combination of software and hardware. In an exemplary embodiment, the software (e.g., application logic, instruction set) is stored on any of various conventional computer-readable media. In the context of this document, "computer-readable medium" can be any medium or component that can contain, store, communicate, propagate, or transport instructions for use by or in connection with an instruction execution system, apparatus, or device (e.g., a computer), for example Figure 1 An example of a computer is described and illustrated in . Computer-readable media may include computer-readable storage media (e.g., memory 125, 155, 171 or other devices), which can be any medium or component that can contain, store, and / or transmit instructions for use by or in connection with an instruction execution system, apparatus, or device (e.g., a computer). Computer-readable storage media does not include propagated signals.
[0233] If desired, the different functions discussed herein may be performed in different orders and / or simultaneously. In addition, if desired, one or more of the functions described above may be optional or may be combined.
[0234] Although various aspects of the invention are set out in the independent claims, further aspects of the invention comprise other combinations of features from the described embodiments and / or dependent claims with features from the independent claims, not just the combinations explicitly set out in the claims.
[0235] It should also be noted that, although the above describes exemplary embodiments of the present invention, these descriptions should not be viewed in a limiting sense. On the contrary, several changes and modifications may be made without departing from the scope of the present invention as defined in the appended claims.
[0236] The following abbreviations that may be found in the specification and / or drawings are defined as follows:
[0237] 3GPP Third Generation Partnership Project
[0238] 5G fifth generation
[0239] 5GC 5G core network
[0240] AMF Access and Mobility Management Function
[0241] CU Centralized Unit
[0242] DL Downlink
[0243] DC Dual Connection
[0244] DU Distributed Unit
[0245] eNB (or eNodeB) Evolved Node B (such as LTE base station)
[0246] EN-DC E-UTRA-NR Dual Connectivity
[0247] en-gNB or En-gNB node, provides NR user plane and control plane protocol terminals to the UE and acts as a secondary node in EN-DC
[0248] EPC Evolved Packet Core
[0249] E-UTRA Evolved Universal Terrestrial Radio Access, also known as LTE radio access technology
[0250] GEO Geostationary Orbit
[0251] HARQ Hybrid Automatic Repeat Request
[0252] HO Handover
[0253] gNB (or gNodeB) is a base station for 5G / NR, which provides NR user plane and control plane protocol terminals to UE and is connected to 5GC through the NG interface. IAB integrated access and postbacks
[0254] ID
[0255] IE Information Element
[0256] I / F interface
[0257] LCID Logical Channel ID
[0258] LTE Long Term Evolution
[0259] MAC Media Access Control
[0260] MCG Master Cell Group
[0261] MME Mobility Management Entity
[0262] MN Master Node
[0263] MR-DC multi-RAT dual connectivity
[0264] NAS Non-Access Stratum
[0265] NDI New Data Indicator
[0266] ng or NG next generation
[0267] ng-eNB or NG-eNB Next Generation eNB
[0268] NGAP Next Generation Access Protocol
[0269] NR New Radio
[0270] NTN Non-Terrestrial Network
[0271] N / W or NW network
[0272] PCell Primary Cell
[0273] PCI Physical Cell Identifier
[0274] PDCP Packet Data Convergence Protocol
[0275] PDU Protocol Data Unit
[0276] PHY Physical Layer
[0277] PSCell primary and secondary cells
[0278] RACH Random Access Channel
[0279] RAN Radio Access Network
[0280] Rel release
[0281] resync resynchronize
[0282] RLC Radio Link Control
[0283] RRH Remote Radio Head
[0284] RRC Radio Resource Control
[0285] RTT Return Time
[0286] RU Radio Unit
[0287] Rx Receiver
[0288] SCG Secondary Cell Group
[0289] SDAP Business Data Adaptation Protocol
[0290] SDU Service Data Unit
[0291] SGW Service Gateway
[0292] SMF session management functions
[0293] SN Secondary Node
[0294] synch synchronization
[0295] TB transfer block
[0296] TS Technical Specification
[0297] Tx Transmitter
[0298] UE User Equipment (e.g., a typical wireless mobile device)
[0299] UPF User Plane Function
Claims
1. A method for secure updating of communications, comprising: receiving, at a user equipment in communication with a first serving cell of a base station, a command, the command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; as well as In response to the event occurring, the security update to the new security configuration is performed by the user equipment for communication with a second serving cell without performing a random access procedure. 2 . The method according to claim 1 , wherein the first serving cell and the second serving cell are the same cell from the base station. The method of claim 1 , wherein the base station is part of a non-terrestrial network.
4. The method according to claim 1, wherein the first serving cell and the second serving cell use the same physical cell identifier, and for the user equipment whose integrated access and backhaul inter-host centralized unit does not change during the migration, the security update is performed for the integrated access and backhaul inter-host centralized unit migration and processing.
5. The method of claim 1 , wherein performing a security update comprises: A packet data convergence protocol re-establishment process is performed, and the security update is performed using the information to reconfigure security so that the user equipment creates new keys or implements new security algorithms, or both, as part of the new security configuration.
6. The method according to claim 5, further comprising: Perform a radio link control re-establishment procedure.
7. The method according to claim 5, further comprising: Perform the media access control re-establishment process.
8. The method according to claim 7, wherein the MAC re-establishment procedure does not involve a random access procedure and does not implicitly require the random access procedure to continue transmission at a later stage.
9. The method according to claim 7, further comprising: Reset all hybrid automatic repeat request processes of the user equipment.
10. The method according to claim 9, wherein resetting all hybrid automatic repeat request processes of the user equipment further comprises: setting new data indicators for all uplink hybrid automatic repeat request processes to a value indicating that the indicators are reset; Hybrid automatic repeat request process for all downlinks to flush soft buffers; as well as For each downlink HARQ process, the next received transmission for a transport block is considered as the earliest transmission.
11. The method of claim 1 , wherein performing the security update comprises: Information to create a new key or implement a new security algorithm, or both.
12. The method according to claim 1, further comprising: The user equipment communicates with the second serving cell of the base station using the new security configuration.
13. The method of claim 1 , wherein the indication of a time to perform the security update to the new security configuration comprises at least one of: number of radio frames or time slots or radio frames and time slots, or timer, or A timestamp in Coordinated Universal Time (UTC) format.
14. The method according to claim 13, further comprising: The user equipment determines that the time has occurred by at least performing one or more of the following: determining that said time has occurred based on said number of radio frames or time slots or radio frames and time slots, or According to the timer, it is determined that the time has occurred, or According to the timestamp in the Coordinated Universal Time (UTC) time format, it is determined that the time has occurred.
15. A method for secure updating of communications, comprising: At a base station communicating with a user equipment using a first serving cell, determining that a security update needs to be performed for the user equipment; Sending, by the base station, a command to the user equipment, the command including information for the user equipment to perform the security update and an indication of a time to perform the security update, so as to change to a new security configuration; as well as In response to the event occurring, a security update to a new security configuration is performed for communication between the second serving cell and the user equipment.
16. The method of claim 15, wherein the first serving cell and the second serving cell are the same cell from the base station.
17. The method of claim 16, wherein the time to perform the security update to change to the new security configuration is generated by: In response to the base station receiving the handover request information, the second serving cell serving as the target base station; or In response to the base station receiving a handover command message in an N2-based handover process, or in response to the base station receiving a handover request confirmation in an Xn-based handover process, the first serving cell is used as the source base station.
18. The method of claim 15, wherein the base station is part of a non-terrestrial network.
19. The method of claim 15, wherein the first serving cell and the second serving cell use the same physical cell identifier, and for the user equipment whose integrated access and backhaul inter-host centralized unit does not change during the migration, the security update is performed for the integrated access and backhaul inter-host centralized unit migration and processing.
20. The method of claim 15, wherein performing the security update comprises: A packet data convergence protocol re-establishment procedure is performed, and the security update is performed using the information to reconfigure security such that the base station creates new keys or implements new security algorithms, or both, as part of the new security configuration.
21. The method according to claim 20, further comprising: Perform a radio link control re-establishment procedure.
22. The method according to claim 20, further comprising: Perform the media access control re-establishment process.
23. The method according to claim 22, wherein for the MAC re-establishment procedure, the base station does not expect a random access procedure, or implicitly requires the random access procedure to continue transmission at a later stage.
24. The method of claim 22, further comprising: Reset all hybrid automatic repeat request processes related to the user equipment.
25. The method of claim 15, wherein performing the security update of the information comprises: Information to create a new key or implement a new security algorithm, or both.
26. The method according to claim 15, further comprising: The second serving cell communicates with the user equipment using the new security configuration.
27. The method of claim 15, wherein the indication of a time to perform the security update to the new security configuration comprises at least one of: number of radio frames or time slots or radio frames and time slots, or timer, or A timestamp in Coordinated Universal Time (UTC) format.
28. The method according to claim 27, further comprising: The base station determines that the time has occurred by at least performing one or more of the following: determining that said time has occurred based on said number of radio frames or time slots or radio frames and time slots, or According to the timer, it is determined that the time has occurred, or According to the timestamp in the Coordinated Universal Time (UTC) time format, it is determined that the time has occurred.
29. A user equipment comprising means for performing the following: receiving, at a user equipment in communication with a first serving cell of a base station, a command, the command including information to perform a security update to a new security configuration and an indication of a time to perform the security update to the new security configuration; and In response to the event occurring, the user equipment performs the security update to the new security configuration for communication with the second serving cell without performing a random access procedure.
30. The user equipment of claim 29, wherein the first serving cell and the second serving cell are the same cell from the base station.
31. The user equipment of claim 29, wherein the base station is part of a non-terrestrial network.
32. The user equipment according to claim 29, wherein the first serving cell and the second serving cell use the same physical cell identifier, and for the user equipment whose integrated access and backhaul inter-host centralized unit served does not change during the migration, the security update is performed for the integrated access and backhaul inter-host centralized unit migration and processing.
33. The user equipment of claim 29, wherein performing a security update comprises: A packet data convergence protocol re-establishment process is performed, and the security update is performed using the information to reconfigure security so that the user equipment creates new keys or implements new security algorithms, or both, as part of the new security configuration.
34. The user equipment according to claim 33, further comprising: Perform a radio link control re-establishment procedure.
35. The user equipment according to any one of claims 33 or 34, further comprising: Perform the media access control re-establishment process.
36. The user equipment according to claim 35, wherein the medium access control re-establishment procedure does not involve a random access procedure and does not implicitly require the random access procedure to continue transmission at a later stage.
37. The user equipment according to claim 35, further comprising: Reset all hybrid automatic repeat request processes of the user equipment.
38. The user equipment according to claim 37, wherein resetting all hybrid automatic repeat request processes of the user equipment further comprises: setting new data indicators for all uplink hybrid automatic repeat request processes to a value indicating that the indicators are reset; Hybrid automatic repeat request process for all downlinks to flush soft buffers; as well as For each downlink HARQ process, the next received transmission for a transport block is considered as the earliest transmission.
39. The user equipment of claim 29, wherein the information for performing the security update comprises: Information to create a new key or implement a new security algorithm, or both.
40. The user equipment according to claim 29, further comprising: The user equipment communicates with the second serving cell of the base station using the new security configuration.
41. The user equipment of claim 29, wherein the indication of a time to perform the security update to the new security configuration comprises at least one of: number of radio frames or time slots or radio frames and time slots, or timer, or A timestamp in Coordinated Universal Time (UTC) format.
42. The user equipment according to claim 41, further comprising: The user equipment determines that the time has occurred by at least performing one or more of the following: determining that said time has occurred based on said number of radio frames or time slots or radio frames and time slots, or According to the timer, it is determined that the time has occurred, or According to the timestamp in the Coordinated Universal Time (UTC) time format, it is determined that the time has occurred.
43. A base station for communication, comprising means for performing the following: At the base station communicating with the user equipment using the first serving cell, determining that a security update needs to be performed for the user equipment; Sending, by the base station, a command to the user equipment, the command including information for performing the security update and an indication of a time for performing the security update, so that the user equipment changes to a new security configuration; as well as In response to the event occurring, a security update to a new security configuration is performed for communication between the second serving cell and the user equipment.
44. The base station of claim 43, wherein the first serving cell and the second serving cell are the same cell from the base station.
45. The base station of claim 44, wherein the time to perform the security update to change to the new security configuration is generated by: In response to the base station receiving the handover request information, the second serving cell serving as the target base station; or In response to the base station receiving a handover command message in an N2-based handover process, or in response to the base station receiving a handover request confirmation in an Xn-based handover process, the first serving cell is used as the source base station.
46. A base station according to any one of claims 43 to 45, wherein the base station is part of a non-terrestrial network.
47. The base station according to claim 43, wherein the first serving cell and the second serving cell use the same physical cell identifier, and for the user equipment whose integrated access and backhaul inter-host centralized unit does not change during the migration, the security update is performed for the integrated access and backhaul inter-host centralized unit migration and processing.
48. The base station of claim 43, wherein performing the security update comprises: A packet data convergence protocol re-establishment procedure is performed, and the security update is performed using the information to reconfigure security such that the base station creates new keys or implements new security algorithms, or both, as part of the new security configuration.
49. The base station of claim 48, wherein the component is further configured to perform: performing a radio link control re-establishment procedure.
50. The base station of claim 48, wherein the component is further configured to perform: performing a medium access control re-establishment procedure.
51. The base station according to claim 50, wherein for the MAC re-establishment procedure, the base station does not expect a random access procedure, or implicitly requires the random access procedure to continue transmission at a later stage.
52. The base station of claim 50, wherein the component is further configured to perform: resetting all hybrid automatic repeat request processes related to the user equipment.
53. The base station of claim 43, wherein the information for performing the security update comprises: Information to create a new key or implement a new security algorithm, or both.
54. The base station of claim 43, wherein the component is further configured to perform: communicating, by the second serving cell, with the user equipment using the new security configuration.
55. The base station of claim 43, wherein the indication of a time to perform the security update to the new security configuration comprises at least one of: number of radio frames or time slots or radio frames and time slots, or timer, or A timestamp in Coordinated Universal Time (UTC) format.
56. The base station of claim 55, wherein the component is further configured to perform: determining, by the base station, that the time has occurred by at least performing one or more of the following: determining that said time has occurred based on said number of radio frames or time slots or radio frames and time slots, or According to the timer, it is determined that the time has occurred, or According to the timestamp in the Coordinated Universal Time (UTC) time format, it is determined that the time has occurred.
57. The base station of claim 43, wherein the base station comprises: at least one processor; as well as At least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus to perform the operations.
Citation Information
Patent Citations
Seamless mobility for 5g and LTE systems and devices
US20180302834A1
Enhanced handover methods and apparatuses using the same
WO2020088260A1