Method and apparatus for synchronizing keys in selective scg
By sending an SN addition request message and a counter value to the auxiliary node in the wireless communication system, and having the user equipment calculate the key, the key synchronization problem when the terminal changes conditionally with the auxiliary node is solved, thus achieving effective management of security and synchronization.
Patent Information
- Application Number
- CN202480048815.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-02-21
- Filing Date
- 2024-08-05
- Publication Date
- 2026-02-24
AI Technical Summary
When the terminal makes repeated conditional secondary node (SN) changes, it is difficult to synchronize the key used between the terminal and the SN, especially when multiple SN counter values are received from the MN. Effective management and synchronization of the key becomes a challenge.
The primary node (MN) sends an SN add request message to the target secondary node (SN), including the SN counter value and the KSN key. The user equipment (UE) receives and calculates the KSN key and synchronizes it through an RRC reconfiguration message. The secondary node (SN) confirms and updates the counter value to ensure key synchronization.
It enables effective management and synchronization of keys between terminals and auxiliary nodes in wireless communication systems, ensuring security and synchronization when conditional auxiliary nodes change.
Smart Images

Figure CN121569461A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a wireless communication system. More specifically, this disclosure relates to a method and apparatus for managing keys in a wireless communication system when a terminal is in a dual-connection state. Background Technology
[0002] Fifth-generation (5G) mobile communication technology defines a wide frequency band capable of enabling high transmission rates and new services. It can be implemented not only in the "sub-6GHz" band, such as 3.5GHz, but also in the "above 6GHz" band, including 28GHz and 39GHz, known as millimeter waves. Furthermore, 6G mobile communication technology (referred to as "super 5G systems") is being considered in terahertz bands (e.g., the 95GHz to 3THz band) to achieve transmission rates up to 50 times faster than 5G and ultra-low latency one-tenth that of 5G.
[0003] In the early stages of 5G mobile communication technology development, to support services and meet performance requirements for enhanced mobile broadband (eMBB), ultra-reliable and low-latency communication (URLLC), and massive machine-type communication (mMTC), the following technologies have been standardized: beamforming and massive MIMO for reducing radio wave path loss and increasing radio wave transmission distance in millimeter waves; support parameters for dynamic operation (e.g., operating multiple subcarrier spacings) for efficient utilization of millimeter wave resources and time slot formats; initial access technologies to support multi-beam transmission and wideband; definition and operation of BWP (bandwidth portion); new channel coding methods such as LDPC (low-density parity-check) codes for large data transmissions and polar codes for highly reliable transmission of control information; L2 preprocessing; and network slicing for providing dedicated networks for specific services.
[0004] Currently, regarding the services supported by 5G mobile communication technology, the industry is continuously discussing improvements and performance enhancements to the initial 5G mobile communication technology, and physical layer standardization has been completed for technologies such as: V2X (vehicle-to-everything) for assisting driving decisions and improving user convenience based on information sent by the vehicle about its location and status; NR-U (New Radio Unlicensed) designed to comply with various regulatory requirements for system operation in unlicensed frequency bands; NR UE power saving; non-terrestrial networks (NTNs) for direct satellite communication between UEs to ensure coverage in areas where they cannot communicate with terrestrial networks; and positioning.
[0005] Furthermore, standardization of air interface architectures / protocols for technologies such as: Industrial Internet of Things (IIoT) for supporting new services through interoperability and integration with other industries; IAB (Integrated Access and Backhaul) for providing nodes for network service area extension by supporting wireless backhaul and access links in an integrated manner; mobility enhancements including conditional handover and DAPS (Dual Active Stack) handover; and two-step random access (two-step RACH for NR) for simplifying the random access process. Meanwhile, standardization of system architectures / services for technologies such as: 5G baseline architectures (e.g., service-based architectures or service-based interfaces) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies; and mobile edge computing (MEC) for receiving services based on UE location.
[0006] With the commercialization of 5G mobile communication systems, an exponential increase in connected devices will be added to communication networks, thus necessitating enhanced functionality and performance of 5G mobile communication systems and the integrated operation of connected devices. To this end, new research is underway on the following technologies: Extended Reality (XR) for efficient support of AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality), etc.; 5G performance improvements and complexity reductions through the utilization of Artificial Intelligence (AI) and Machine Learning (ML); AI service support; Metaverse service support; and drone communication.
[0007] Furthermore, this development of 5G mobile communication systems will not only lay the foundation for the development of technologies such as: new waveforms for providing coverage in the terahertz band of 6G mobile communication technology; multi-antenna transmission technologies such as full-dimensional MIMO (FD-MIMO), array antennas, and massive MIMO; metamaterial-based lenses and antennas for improving terahertz band signal coverage; high-dimensional spatial multiplexing technologies using OAM (orbital angular momentum); and RIS (reconfigurable smart surfaces), but will also lay the foundation for the development of technologies such as: full-duplex technologies for improving the frequency efficiency of 6G mobile communication technology and improving system networks; AI-based communication technologies for system optimization by leveraging satellites and AI (artificial intelligence) from the design stage and internalizing end-to-end AI support functions; and next-generation distributed computing technologies for providing services at complexity levels exceeding the operational limits of UEs by utilizing ultra-high-performance communication and computing resources. Summary of the Invention
[0008] [Technical Issues]
[0009] The purpose of this disclosure is to provide a method and apparatus for synchronizing a security key between a terminal and a secondary node (SN) during repeated conditional secondary node (SN) changes. More specifically, this disclosure addresses the problem of synchronizing the key used between a terminal and a secondary node (SN) when a terminal receives multiple SN counter values for each SN from a MN during repeated conditional SN changes (selective SCG).
[0010] The technical objectives achieved in the embodiments of this disclosure are not limited to those described above, and other technical objectives not mentioned will be clearly understood by those skilled in the art from the following description.
[0011] [Solution to the problem]
[0012] According to one aspect of this disclosure, a method is provided performed by a master node (MN) in a communication system. The method includes: sending an SN add request message to at least one target slave node (SN), the SN add request message including at least one SN counter value corresponding to each target SN and K. SN A key, wherein each target SN includes a first target SN and a second target SN; a first Radio Resource Control (RRC) reconfiguration message is sent to the User Equipment (UE), the first RRC reconfiguration message including at least one SN counter value corresponding to each target SN and K. SN The key; and sending an SN reconfiguration complete message to the first target SN, the SN reconfiguration complete message including the SN counter value received from the UE.
[0013] According to one aspect of this disclosure, a method is provided performed by a secondary node (SN) in a communication system. The method includes: receiving an SN addition request message from a primary node (MN), the SN addition request message including at least one SN counter value corresponding to each target SN and K. SN The key, wherein each target SN includes a first target SN and a second target SN; sending an SN add request confirmation message to the MN, the SN add request confirmation message including at least one algorithm information or user plane UP integrity and encryption information; and receiving from the MN an SN reconfiguration complete message including the SN counter value received from the user equipment (UE).
[0014] According to one aspect of this disclosure, a method performed by a user equipment (UE) in a communication system is provided. The method includes: receiving a first radio resource control (RRC) reconfiguration message from a master node (MN), the first RRC reconfiguration message including at least one secondary node (SN) counter value corresponding to each target SN and K. SN Key; calculate K based on the SN counter value from at least one SN counter value. SNKey; send to MN including the key used to derive K SN The key's SN counter value is displayed as an RRC reconfiguration complete message.
[0015] According to one aspect of this disclosure, a master node (MN) is provided in a communication system. The MN includes a transceiver and a controller, the controller being configured to: send an SN add request message to at least one target secondary node (SN), the SN add request message including at least one SN counter value corresponding to each target SN and K. SN A key, wherein each target SN includes a first target SN and a second target SN, is used to send a first radio resource control (RRC) reconfiguration message to the user equipment (UE). The first RRC reconfiguration message includes at least one SN counter value corresponding to each target SN and K. SN The key is sent to the first target SN, and an SN reconfiguration completion message is sent, which includes the SN counter value received from the UE.
[0016] According to one aspect of this disclosure, a secondary node (SN) in a communication system is provided. The SN includes a transceiver and a controller, the controller being configured to: receive an SN addition request message from a primary node (MN), the SN addition request message including at least one SN counter value corresponding to each target SN and K. SN The key, wherein each target SN includes a first target SN and a second target SN; sending an SN add request confirmation message to the MN, the SN add request confirmation message including at least one algorithm information or user plane (UP) integrity and encryption information; and receiving an SN reconfiguration complete message from the MN, the SN reconfiguration complete message including an SN counter value received from the user equipment (UE).
[0017] According to one aspect of this disclosure, a user equipment (UE) is provided in a communication system. The UE includes: a transceiver; and a controller configured to: receive a first radio resource control (RRC) reconfiguration message from a master node (MN), the first RRC reconfiguration message including at least one secondary node (SN) counter value corresponding to each target SN and K. SN The key, K, is calculated based on the SN counter value from at least one SN counter value. SN The key, and sending it to MN including the key used to derive K SN The key's SN counter value is displayed as an RRC reconfiguration complete message.
[0018] [Beneficial effects of the invention]
[0019] According to embodiments of this disclosure, an apparatus and method capable of effectively providing services in a wireless communication system can be provided.
[0020] The effects that can be obtained from this disclosure are not limited to those mentioned in the various embodiments, and other effects not mentioned will be clearly understood by those skilled in the art to which this disclosure pertains from the following description. Attached Figure Description
[0021] To gain a more complete understanding of this disclosure and its advantages, reference is now made to the following description in conjunction with the accompanying drawings, wherein like reference numerals denote like parts: Figure 1a A communication network according to an embodiment of this disclosure is shown; Figure 1b A wireless environment including a core network in a wireless communication system is illustrated according to an embodiment of this disclosure; Figure 2a The functional structure of a UE according to an embodiment of this disclosure is shown; Figure 2b The functional structure of a base station according to an embodiment of this disclosure is shown; Figure 2c The functional structure of the core network entities according to embodiments of this disclosure is shown; Figure 3a The process for synchronizing security keys according to embodiments of the present disclosure is illustrated; Figure 3b The process for synchronizing security keys according to embodiments of the present disclosure is illustrated; Figure 4a A process for synchronizing a security key according to another embodiment of this disclosure is shown; and Figure 4b A process for synchronizing security keys according to another embodiment of this disclosure is shown. Detailed Implementation
[0022] Before proceeding with the following detailed description, it may be advantageous to define certain words and phrases used throughout this patent document: the terms “comprising” and “including” and their derivatives mean non-restrictive inclusion; the term “or” is inclusive, meaning and / or. The phrases “associated with” and “associated with” and their derivatives mean including, being included in, interconnected with, containing, contained within, connected to or connected to, coupled to or coupled to, able to communicate with, cooperate with, intertwine, juxtapose, proximate, bound to or bound to, having, possessing the properties of, or similar meanings; the term “controller” means any device, system, or part thereof that controls at least one operation, such device may be implemented in hardware, firmware, or software, or at least a combination of both. It should be noted that the functionality associated with any particular controller may be centralized or distributed, whether local or remote.
[0023] Furthermore, the various functions described below can be implemented or supported by one or more computer programs, each computer program being formed by computer-readable program code and embodied in a computer-readable medium. The terms "application" and "program" refer to one or more computer programs, software components, instruction sets, procedures, functions, objects, classes, instances, associated data, or portions thereof suitable for implementation in appropriate computer-readable program code. The phrase "computer-readable program code" includes any type of computer code, including source code, object code, and executable code. The phrase "computer-readable medium" includes any type of medium accessible by a computer, such as read-only memory (ROM), random access memory (RAM), hard disk drive, optical disc (CD), digital video disc (DVD), or any other type of storage. "Non-transitory" computer-readable media excludes wired, wireless, optical, or other communication links that transmit transient electrical or other signals. Non-transitory computer-readable media includes media that can permanently store data, as well as media that can store data and subsequently rewrite it (such as rewritable optical discs or erasable storage devices).
[0024] Definitions of certain words and phrases are provided throughout this patent document, and those skilled in the art will understand that, in many cases (if not most), such definitions apply to the prior and future use of the words and phrases defined as such.
[0025] Figures 1 through 4B discussed below, and the various embodiments used to illustrate the principles of this disclosure in this patent document, are merely exemplary and should not be construed in any way as limiting the scope of this disclosure. Those skilled in the art will understand that the principles of this disclosure can be implemented in any suitably arranged system or apparatus.
[0026] The terminology used in this disclosure is for describing particular embodiments and is not intended to limit the scope of other embodiments. Singular expressions may include plural expressions unless the context explicitly specifies otherwise. The terminology used herein (including technical or scientific terms) may have the same meaning as commonly understood by one of ordinary skill in the art described in this disclosure. Among the terminology used in this disclosure, terms defined in a general dictionary may be interpreted as having the same or similar meaning as they have in the context of the relevant art, and should not be construed as having an idealized or overly formal meaning unless explicitly defined in this disclosure. In some cases, even terms defined in this disclosure should not be construed as excluding particular embodiments of this disclosure.
[0027] In the various embodiments of this disclosure described below, hardware-based methods are described as examples. However, since the various embodiments of this disclosure include techniques using both hardware and software, software-based methods are not excluded.
[0028] To facilitate the transition from existing 4G LTE systems to 5G systems, 3GPP, responsible for cellular mobile communication standards, has named the new core network architecture 5G Core (5GC) and is currently in the standardization process. Compared to the Evolved Packet Core (EPC), which serves as the core of existing 4G networks, 5GC supports the following differentiated features.
[0029] First, network slicing functionality is introduced in 5GC. According to 5G requirements, 5GC should support various types of terminals and services, such as enhanced mobile broadband (eMBB), ultra-reliable low latency communication (URLLC), and massive machine-type communication (mMTC).
[0030] These various types of services have different requirements for the core network. For example, eMBB service requires high data rates, while URLLC service requires high stability and low latency. One of the technologies offered to meet these diverse service requirements is network slicing.
[0031] Network slicing is a method of creating multiple logical networks by virtualizing a single physical network, and each Network Slice Instance (NSI) can have different characteristics. Therefore, various service requirements can be met by using Network Functions (NFs) with characteristics suitable for each NSI. By assigning NSIs with characteristics appropriate to the services required by each terminal, various 5G services can be effectively supported.
[0032] Secondly, 5GC can facilitate support for network virtualization paradigms by separating mobility management and session management functions. In 4G LTE, services were provided through signaling exchange with a single core device (called the Mobility Management Entity (MME)) responsible for registration, authentication, mobility management, and session management of all terminals. However, in 5G, with the explosive increase in the number of terminals and the segmentation of mobility and service / session characteristics to be supported based on terminal type, it is inevitable that the scalability of adding an entity for each required function would be reduced if all functions were supported by a single device such as the MME. Therefore, to improve scalability in terms of functional / implementation complexity and signaling load on the core device responsible for the control plane, various functions are being developed based on an architecture that separates mobility management and session management functions.
[0033] Various embodiments will be described in detail below with reference to the accompanying drawings. In the description of this disclosure, descriptions of well-known functions and structures incorporated herein may be omitted to avoid obscuring the subject matter. Furthermore, the terms described below are defined in consideration of their function in this disclosure, and these terms may vary depending on user intent, operator, or convention. Therefore, their meaning should be determined based on the entirety of this specification.
[0034] Similarly, in the accompanying drawings, some elements are exaggerated, omitted, or only briefly outlined. Furthermore, the dimensions of each element do not necessarily reflect its actual size. In all the drawings, the same or similar reference numerals are used to denote the same or similar parts.
[0035] The advantages and features of this disclosure, as well as the methods for implementing them, will become apparent from the following detailed description of embodiments taken in conjunction with the accompanying drawings. However, this disclosure is not limited to the embodiments disclosed below, but can be implemented in various different ways. These embodiments are provided only to complete this disclosure and to fully inform those skilled in the art of its scope, and this disclosure is limited only by the scope of the claims. The same reference numerals are used throughout the specification to denote the same parts.
[0036] Furthermore, it should be understood that the blocks of a flowchart and combinations thereof can be executed by computer program instructions. These computer program instructions can be loaded onto the processor of a general-purpose computer, a special-purpose computer, or a programmable data processing device, and the instructions executed by the processor of the computer or programmable data processing device create means for performing the functions described in the blocks of the flowchart. To implement the functions in a certain way, the computer program instructions can also be stored in a computer-usable or readable storage medium applicable to a special-purpose computer or programmable data processing device, and for the computer program instructions stored in the computer-usable or readable storage medium, it is possible to produce an article of art containing means for performing the functions described in the blocks of the flowchart. Since computer program instructions can be loaded onto a computer or programmable data processing device, when the computer program instructions are executed as a process having a series of operations on the computer or programmable data processing device, they can provide steps for performing the functions described in the blocks of the flowchart.
[0037] Each block of the flowchart may correspond to a module, segment, or piece of code, or a portion thereof, containing one or more executable instructions for performing one or more logical functions. It should also be noted that in some alternative cases, the functions described by the blocks may be executed in a different order than that listed. For example, two blocks listed sequentially may be executed substantially simultaneously, or in reverse order depending on their respective functions.
[0038] Here, the terms "unit," "module," etc., used in the various embodiments of this disclosure can refer to software or hardware components capable of performing functions or operations, such as FPGAs or ASICs. However, "unit," etc., is not limited to hardware or software. Units, etc., can be configured to reside in addressable storage media or drive one or more processors. For example, units, etc., can refer to components such as software components, object-oriented software components, class components or task components, processes, functions, attributes, procedures, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, or variables. The functionality provided by components and units can be a combination of smaller components and units, and it can be combined with other components and units to form larger components and units. Components and units can be implemented to drive one or more processors in a device or secure multimedia card.
[0039] In the following description, the base station, which is the primary entity that performs resource allocation for the UE, may be at least one of the following: eNode B (eNB), Node B, base station (BS), radio access network (RAN), access network (AN), RAN node, NR NB, gNB, radio access unit, base station controller, or network node.
[0040] Terminals may include user equipment (UE), mobile station (MS), cellular phone, smartphone, computer, or multimedia system capable of performing communication functions. In various embodiments of this disclosure, the case where the terminal is a UE is described as an example. Furthermore, in various embodiments of this disclosure, systems based on LTE, LTE-A, or NR are described as examples; however, various embodiments of this disclosure can also be applied to other communication systems with similar technical backgrounds or channel configurations. Moreover, as those skilled in the art will understand, various embodiments of this disclosure can be applied to other communication systems with modifications without significantly departing from the scope of this disclosure.
[0041] The terms used in the following description to identify access nodes, indicate network entities, indicate messages, indicate interfaces between network entities, and indicate various identifying information are used for illustrative purposes. Therefore, this disclosure is not limited to the terms described later, and other terms referring to objects with equivalent technical meanings may be used.
[0042] Furthermore, various embodiments are described in this disclosure using terminology found in some communication standards (e.g., the 3rd Generation Partnership Project (3GPP)), but these are merely illustrative examples. The various embodiments of this disclosure can be readily modified and applied to other communication systems. Next, some terminology used in the core network of this disclosure is predefined: AMF access and mobility management functions; CN core network; CNF containerized network functionality; DNN data network name; PCF policy control functions; HSS belongs to the user server; SMF session management functionality; UDM user data management; UPF User Plane Functionality; CNF containerized network functionality; and VNF (Virtual Network Function)
[0043] According to various embodiments of this disclosure, a method performed by a UE may include: receiving from a MN an indication of whether the MN supports selective SCG; sending to the MN an indication of whether the UE supports selective SCG; storing and managing an SN counter received from the MN; notifying the MN of the SN counter value used by the UE to use a key; generating a key using the SN counter value, incrementing the SN counter value by 1, and storing the result as a new SN counter.
[0044] According to various embodiments of this disclosure, a method performed by a base station in a wireless communication system may include: sending an indication from a MN to a UE indicating whether the MN supports selective SCG; receiving an indication from the UE indicating whether the UE supports selective SCG; and the MN determining whether to generate a K before sending an SN add request message to the SN. SN MN determines whether to send an SN counter when sending an RRC connection reconfiguration message to the UE; MN determines the number of SN counters to send when sending an RRC connection reconfiguration message to the UE; receives data from the UE for K... SN The generated SN counter; after using the SN counter value to generate the key, the SN counter value is incremented by 1, and the result is stored as a new SN counter.
[0045] Figure 1A illustrates a communication network according to an embodiment of the present disclosure.
[0046] More specifically, Figure 1A illustrates a communication network including core network entities in a wireless communication system according to various embodiments of the present disclosure. The 5G mobile communication network may consist of a 5G user equipment (UE) 110, a 5G radio access network (RAN) 120, and a 5G core network.
[0047] The 5G core network can be composed of network functions, such as Access and Mobility Management Function (AMF) 150 which provides mobility management functions to UEs, Session Management Function (SMF) 160 which provides session management functions, User Plane Function (UPF) 170 which provides data transmission roles, Policy Control Function (PCF) 180 which provides policy control functions, Unified Data Management (UDM) (153) which provides data management functions for user data and policy control data, or Unified Data Repository (UDR) which stores various network functions.
[0048] Referring to Figure 1A, User Equipment (UE) 110 can communicate via a wireless channel (i.e., access network) formed with a base station (e.g., eNB, gNB). In some embodiments, UE 110 can be a device used by a user and can be a device configured to provide a user interface (UI). As an example, UE 110 can be a device installed in a vehicle for driving. In some other embodiments, UE 110 can be a device performing machine-type communication (MTC) operations without involving a user, or it can be an autonomous vehicle. UE can be referred to as an electronic device, terminal, vehicle terminal, user equipment, mobile station, user station, remote terminal, wireless terminal, user equipment, or other terms with equivalent technical meanings. As a terminal, in addition to UE, a Customer Premises Equipment (CPE) or a Dorr-type terminal can also be used. A customer premises equipment, such as UE, can connect to an NG-RAN node while providing network access to other communication devices (e.g., laptop computers).
[0049] Referring to Figure 1A, the Access and Mobility Management Function (AMF) 150 provides access and mobility management functions for UE 110, and a UE 110 can be connected to an AMF 150 by default.
[0050] More specifically, the AMF 150 can perform at least one function in signaling between core network nodes for mobility between 3GPP access networks, connectivity between radio access networks 120 (e.g., 5G RAN) (N2 interface), NAS signaling with UE 110, identification of SMF 160, and delivery of session management (SM) messages between UE 110 and SMF 160. Some or all of the functions of the AMF 150 can be supported in a single instance of the AMF 150.
[0051] Referring to Figure 1A, the Session Management Function (SMF) 160 provides session management functions, and if the UE 110 has multiple sessions, each session can be managed by a different SMF 160.
[0052] More specifically, the SMF 160 can perform at least one of the following functions: session management (e.g., establishing, modifying, and releasing sessions, including maintaining tunnels between the UPF 170 and access network nodes), selection and control of user plane (UP) functions, flow control configuration for routing traffic to appropriate destinations in the UPF 170, termination at the SM portion of NAS messages, downlink data notification (DDN), and initiation of AN-specific SM information (e.g., transmitted to the access network via the N2 interface through the AMF 150). Some or all of the functions of the SMF 160 can be supported in a single instance of the SMF 160.
[0053] In 3GPP systems, the conceptual link connecting NFs in a 5G system can be referred to as a reference point. A reference point can also be referred to as an interface. The following illustrates reference points (hereinafter used interchangeably with interfaces) included in a 5G system architecture according to various embodiments of this disclosure: -N1: Reference point between UE 110 and AMF 150; -N2: (R) Reference point between AN 120 and AMF 150; -N3: (R) Reference point between AN 120 and UPF 170; -N4: Reference point between SMF 160 and UPF 170; -N5: Reference point between PCF 180 and AF 130; -N6: Reference point between UPF 170 and DN 140; -N7: Reference point between SMF 160 and PCF 180; -N8: Reference point between UDM 153 and AMF 150; -N9: Reference point between the two core UPF 170; -N10: Reference point between UDM 153 and SMF 160; -N11: Reference point between AMF 150 and SMF 160; -N12: Reference point between AMF 150 and Authentication Server Function (AUSF) 151; -N13: Reference point between UDM 153 and AUSF 151; -N14: Reference point between the two AMF150s; and -N15: Reference point between PCF 180 and AMF 150 for non-roaming scenarios; reference point between PCF 180 and AMF 150 within the accessed network for roaming scenarios. Figure 1B illustrates a wireless environment including a core network in a wireless communication system according to an embodiment of the present disclosure.
[0054] Referring to Figure 1B, the wireless communication system may include a radio access network (RAN) 120 and a core network (CN).
[0055] The radio access network 120, which is a network directly connected to a user equipment (e.g., UE 110), is the infrastructure that provides radio access to UE 110.
[0056] The wireless access network 120 may include a group of multiple base stations, including base station 125, and the multiple base stations may communicate through interfaces formed therebetween. At least some of the interfaces between the multiple base stations may be wired or wireless.
[0057] Base station 125 may have a structure divided into central unit (CU) and distributed unit (DU). In this case, one CU can control multiple DUs.
[0058] Base station 125 may be referred to as a base station, access point (AP), gNB (next-generation node B), 5G node (fifth-generation node), radio point, transmit / receive point (TRP), or other terms with equivalent technical meanings. UE 110 may connect to radio access network 120 to communicate with base station 125 via a radio channel. UE 110 may be referred to as a terminal, user equipment, mobile station, user station, remote terminal, radio terminal, user equipment, or other terms with equivalent technical meanings.
[0059] The core network can be a network that manages the entire system and controls the radio access network 120, processing data and control signals transmitted and received by the UE 110 through the radio access network 120. The core network can perform various functions, such as controlling the user plane and control plane, processing mobility, managing user information, charging, and interacting with other types of systems (e.g., Long Term Evolution (LTE) systems). To perform these functions, the core network can include multiple functionally separated entities with different network functions (NFs). For example, the core network 200 can include Access and Mobility Management Function (AMF) 150, Session Management Function (SMF) 160, User Plane Function (UPF) 170, Policy and Charging Function (PCF) 180, Network Repository Function (NRF) 159, Unified Data Management (UDM) 153, Network Exposure Function (NEF) 155, and Unified Data Repository (UDR) 157.
[0060] User equipment (UE) 110 can connect to radio access network 120 to access AMF 150, which performs mobility management functions of the core network.
[0061] Access and Mobility Management Function (AMF) 150 is a function or device responsible for accessing the radio access network 120 and managing the mobility of the UE 110.
[0062] Session Management Function (SMF) 160 is the NF that manages sessions. AMF 150 can connect to SMF 160, and AMF 150 can route session-related messages from UE 110 to SMF 160. SMF 160 can connect to UPF 170 to allocate user plane resources to be provided to UE 110, and can establish tunnels to transmit data between base station 125 and UPF 170.
[0063] The Policy and Charging Function (PCF) 180 can control information related to the policy and charging of the session used by UE 110.
[0064] The Network Repository Function (NRF) 159 can store information about NFs installed in a mobile network operator's network and perform the function of notifying the user of the stored information. The NRF 159 can connect to all NFs. When an NF begins operating on the operator's network, the NF registers itself with the NRF 159 to notify the NRF 159 that the NF is operating on the network.
[0065] Unified Data Management (UDM) 153 is an NF that performs a role similar to that of a Home Subscriber Server (HSS) in a 4G network and can store subscription information of UE 110 in the network or context used by UE 110.
[0066] Network Exposure Function (NEF) 155 can play a role in connecting to third-party servers and NFs of 5G mobile communication systems. Furthermore, NEF can provide data to UDR 157, update its data, or obtain data from it.
[0067] The Unified Data Repository (UDR) 157 can store UE 120 subscription information, storage policy information, data exposed to external sources, or information necessary for third-party applications. Furthermore, UDR 157 can also provide the stored data to other NFs.
[0068] Figure 2A illustrates the functional structure of a UE according to an embodiment of this disclosure.
[0069] The configuration shown in Figure 2A can be understood as the configuration of UE 110. In the following description, terms such as "...unit" and "...module" refer to a unit that processes at least one function or operation, which can be implemented by hardware, software, or a combination of both.
[0070] Referring to Figure 2A, the UE may include a communication circuit 205, a memory 210, and a controller 215.
[0071] The communication circuit 205 can perform functions for transmitting and receiving signals via a wireless channel. For example, the communication circuit 205 can perform conversion functions between baseband signals and bitstreams according to the physical layer specifications of the system. For example, during data transmission, the communication circuit 205 can generate complex symbols by encoding and modulating the transmitted bitstream. Furthermore, during data reception, the communication circuit 205 can recover the received bitstream by demodulating and decoding the baseband signal. In addition, the communication circuit 205 can upconvert the baseband signal to a radio frequency (RF) band signal and transmit the signal through an antenna, and can downconvert the RF band signal received through the antenna back to a baseband signal. For example, the communication circuit 205 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), etc.
[0072] Furthermore, the communication circuit 205 may include multiple transmit and receive paths. Additionally, the communication circuit 205 may include at least one antenna array composed of multiple antenna elements. In terms of hardware, the communication circuit 205 may consist of digital and analog circuits (e.g., radio frequency integrated circuits (RFICs)). Here, the digital and analog circuits can be implemented in a single package. Furthermore, the communication circuit 205 may include multiple radio frequency (RF) chains. Furthermore, the communication circuit 205 can perform beamforming.
[0073] As described above, the communication circuit 205 can transmit and receive signals. Therefore, all or part of the communication circuit 205 can be referred to as a transmitter, receiver, or transceiver. Furthermore, in the following description, transmission and reception performed via a wireless channel are used to include the meaning of the aforementioned processes performed by the communication circuit 205.
[0074] Memory 210 can store data such as basic programs, application programs, and configuration information for UE operation. Memory 210 may consist of volatile memory, non-volatile memory, or a combination thereof. Furthermore, memory 210 can provide the stored data upon request from controller 215.
[0075] Controller 215 can control all operations of the UE. For example, controller 215 can send and receive signals via communication circuit 205. Furthermore, controller 215 can write data to and read data from memory 210. Additionally, controller 215 can perform the functions of the protocol stack required by the communication standard. For this purpose, controller 215 may include at least one processor or microprocessor, or may be part of a processor. Additionally, communication circuit 205 and a portion of controller 215 may be referred to as a communication processor (CP). According to various embodiments, controller 215 can use a wireless communication network to control synchronization. For example, controller 215 can control the UE to perform operations according to various embodiments described later.
[0076] According to various embodiments of this disclosure, a UE may consist of a mobile device (ME) and a Universal Mobile Telecommunications Service (UMTS) Subscriber Identity Module (USIM). The ME may include a mobile terminal (MT) and a terminal device (TE). The MT may be part of the radio access protocol operation, and the TE may be part of the control function operation. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and TE may be integrated; and in the case of a laptop computer, the MT and TE may be separated. Various embodiments of this disclosure may be described in various ways depending on the separately configured operation, by representing the ME and USIM as different entities, by representing the ME and USIM as a terminal (e.g., the UE), or by representing the ME as a terminal.
[0077] Figure 2B illustrates the functional structure of a base station according to an embodiment of the present disclosure.
[0078] The configuration shown in Figure 2B can be understood as the configuration of base station 120. In the following description, terms such as "...unit" and "...module" refer to a unit that processes at least one function or operation, which can be implemented by hardware, software, or a combination of both.
[0079] Referring to Figure 2B, the base station may include a wireless communication circuit 235, a backhaul communication circuit 220, a memory 225, and a controller 230.
[0080] The wireless communication circuit 235 can perform functions for transmitting and receiving signals via a wireless channel. For example, the wireless communication circuit 235 can perform conversion functions between baseband signals and bit streams according to the physical layer specifications of the system. For example, during data transmission, the wireless communication circuit 235 can generate complex symbols by encoding and modulating the transmitted bit stream. Furthermore, during data reception, the wireless communication circuit 235 can recover the received bit stream by demodulating and decoding the baseband signal.
[0081] Furthermore, the wireless communication circuit 235 can upconvert a baseband signal to a radio frequency (RF) band signal and transmit the signal through an antenna, and can downconvert an RF band signal received through the antenna back to a baseband signal. For this purpose, the wireless communication circuit 235 may include a transmit filter, a receive filter, an amplifier, a mixer, an oscillator, a digital-to-analog converter (DAC), an analog-to-digital converter (ADC), etc. Furthermore, the wireless communication circuit 235 may include multiple transmit and receive paths. Additionally, the wireless communication circuit 235 may include at least one antenna array composed of multiple antenna elements.
[0082] In terms of hardware, the wireless communication circuit 235 can consist of digital and analog units, wherein the analog unit can be composed of multiple sub-units depending on the operating power, operating frequency, etc. The digital unit can be implemented using at least one processor (e.g., a digital signal processor (DSP)).
[0083] As described above, the wireless communication circuit 235 can transmit and receive signals. Therefore, all or part of the wireless communication circuit 235 can be referred to as a transmitter, receiver, or transceiver. Furthermore, in the following description, transmission and reception performed via a wireless channel are used to include the meaning of the aforementioned processes performed by the wireless communication circuit 235.
[0084] The backhaul communication circuit 220 can provide an interface for communicating with other nodes in the network. That is, the backhaul communication circuit 220 can convert a bit stream to be sent from a base station to another node, such as another access node, another base station, an upstream node, or the core network, into a physical signal, and can convert a physical signal received from another node into a bit stream.
[0085] The memory 225 can store data such as basic programs, application programs, and configuration information for base station operation. The memory 225 can consist of volatile memory, non-volatile memory, or a combination thereof. Furthermore, the memory 225 can provide the stored data upon request from the controller 230.
[0086] Controller 230 can control all operations of the base station. For example, controller 230 can send and receive signals via wireless communication circuit 235 or backhaul communication circuit 220. Furthermore, controller 230 can write data to and read data from memory 225. Additionally, controller 230 can perform the functions of the protocol stack required by the communication standard. According to another embodiment, the protocol stack can be included in wireless communication circuit 235. For this purpose, controller 230 may include at least one processor. According to various embodiments, controller 230 can use a wireless communication network to control synchronization. For example, controller 230 can control the base station to perform operations according to various embodiments described later.
[0087] Figure 2C illustrates the functional structure of the core network entity according to an embodiment of this disclosure.
[0088] The configuration of a core network entity in a wireless communication system according to various embodiments of the present disclosure is illustrated. The configuration shown in FIG2C can be understood as a configuration of an entity having at least one function in a network entity including the AMF 150 shown in FIG1. In the following description, terms such as “…unit” and “…module” refer to a unit that processes at least one function or operation, which can be implemented by hardware, software or a combination of both.
[0089] Referring to Figure 2C, the core network entities include communication circuit 240, memory 245, and controller 250.
[0090] Communication circuit 240 can provide an interface for communicating with other entities in the network. That is, communication circuit 240 can convert a bit stream to be sent from a core network entity to another entity into a physical signal, and can convert a physical signal received from another entity into a bit stream. In other words, communication circuit 240 can both send and receive signals. Therefore, communication circuit 240 can be referred to as a modem, transmitter, receiver, or transceiver. In this case, communication circuit 240 enables core network entities to communicate with other entities or systems via backhaul connections (e.g., wired or wireless backhaul) or over the network.
[0091] Memory 245 can store data such as basic programs, application programs, and configuration information for the operation of core network entities. Memory 245 may consist of volatile memory, non-volatile memory, or a combination thereof. Furthermore, memory 245 can provide the stored data upon request from controller 250.
[0092] Controller 250 can control all operations of the core network entity. For example, controller 250 can send and receive signals via communication circuit 240. Additionally, controller 250 can write data to and read data from memory 245. For this purpose, controller 250 may include at least one processor. According to various embodiments, controller 250 can use a wireless communication network to control synchronization. For example, controller 250 can control the core network entity to perform operations according to various embodiments described later.
[0093] The terms used in the following description to identify access nodes, indicate network entities, indicate messages, indicate interfaces between network entities, and indicate various identifying information are used for illustrative purposes. Therefore, this disclosure is not limited to the terms described later, and other terms referring to objects with equivalent technical meanings may be used.
[0094] For ease of description below, this disclosure may use terms and names defined in 5G System (5GS) and New Radio (NR) standards, which are the most recent standards defined by the 3GPP organization in current existing communication standards. However, this disclosure is not limited to the foregoing terms and names and can be applied equivalently to wireless communication networks conforming to other standards. In particular, this disclosure can be applied to 3GPP fifth-generation mobile communication standards (e.g., 5GS and NR).
[0095] A UE can have dual connectivity. In dual connectivity, the base station providing macro cell coverage can become the primary node (MN) and handle both the control plane and user plane, while other base stations with small cell coverage can be called secondary nodes (SN) and play a supporting role in handling some user plane or control plane functions. That is, the MN can handle control signaling, and the SN can be used to improve data transmission speed.
[0096] The MN can provide the UE with conditional PSCell change (CPC) configuration information; the UE can evaluate the corresponding conditions, and if the conditions are met, the UE can make a change request to the SN that meets the conditions. Furthermore, the UE can store CPC configuration information for several SNs provided by the MN, and can make an SN change request as long as the conditions are met after evaluation. In this case, whenever the UE changes an SN, the UE can change the key it uses, and even if it changes to the same SN, the UE can choose not to use the previously used key. For this purpose, the MN provides the UE with multiple SN counter values for each SN.
[0097] In the following, this disclosure will provide a method for performing security key synchronization when repeated SN changes occur in a dual-connection scenario of a UE.
[0098] Figures 3A and 3B illustrate a process for performing security key synchronization according to an embodiment of the present disclosure.
[0099] More specifically, Figure 3 illustrates, according to an embodiment of this disclosure, that when repeated conditional SN changes are performed in a dual-connectivity scenario, synchronization will be used in the K-series between the UE and the secondary node (SN). SN The process.
[0100] Referring to Figures 3A and 3B, in step 310, the user equipment (UE) 301 and the master node (MN) 303 may share with each other their respective capabilities or capability information for repeated conditional SN changes (selective SCG). The capability or capability information for repeated conditional SN changes may include an indication of whether selective SCG is supported.
[0101] The sharing of capabilities or capability information for repeated conditional SN changes can be performed through registration messages or Access Layer (AS) SMC messages. SMC messages may include AS Security Mode Command messages sent from the base station to the UE, and AS Security Mode Completion messages sent from the UE to the base station in response.
[0102] The AS security mode command message is a message sent from the base station to the UE, and can be the first integrity protection message in the AS message.
[0103] The AS security mode completion message is a message sent from the UE to the base station and can be the first encryption and integrity protection message in the AS message.
[0104] If UE 301 or MN 303 does not send capability or capability information for repeated conditional SN changes, this in itself may mean that the UE or MN does not support selective SCG.
[0105] In step 335, the UE can determine whether the base station supports selective SCG based on the transmission of multiple SN counter values.
[0106] Selective SCG can refer to a technique in which the UE receives SN RRC condition configuration information for one or more SNs from the MN and performs repeated SN changes based on the received information without receiving additional information from the MN.
[0107] More specifically, this can refer to a process in which, when the MN makes a resource allocation request for a UE's PDU (Protocol Data Unit) session or QoS (Quality of Service) stream to one or more SNs, and the MN sends an RRC reconfiguration message including SN RRC condition configuration information for each SN, the UE uses the received condition information to repeatedly make change requests to SNs that meet specific conditions, provided that certain conditions are met.
[0108] In other words, this could mean that if the MN has already sent an indication that the MN supports selective SCG, then whenever the conditions are met, the UE that has already received SN RRC condition configuration information for multiple SNs can make an SN change request to the MN without receiving additional configuration information from the MN.
[0109] This could mean that if the UE has already sent an indication that it supports selective SCG, the UE can repeatedly make SN changes after receiving SN RRC condition configuration information for multiple SNs.
[0110] In step 315, MN 303 may assign one or more SN counter values for each of at least one SN, and generate K by using one SN counter value assigned to each SN.SN Key.
[0111] More specifically, if MN 303 has determined to perform selective SCG, then MN can assign multiple SN counter values to each SN for which it requests resource allocation. After assigning multiple SN counter values to each SN, MN 303 can generate multiple K values by using the SN counter values. SN Key.
[0112] MN 303 can know in advance whether an SN supports selective SCG before assigning an SN counter value to the SN. To generate K SN MN 303 can use K SN The input values include 0x79, the SN counter value, and the SN counter length. Additionally, MN can use the SN counter to generate a representation for each K. SN The key ID. For example, a method for generating a key ID for MN using an SN counter may include utilizing K MN K SN A value similar to 0x79, MN, or at least one of the known UE ID or SN counters.
[0113] K SN It is the key used by the secondary node (SN), and the SN can use K SN This is used to generate keys for encrypting and protecting the integrity of user plane (UP) data exchanged between the UE and SN.
[0114] In step 320, MN 303 may send an SN add request message to at least one SN. The at least one SN may include a target SN (T-SN) 307 and / or other potential T-SNs 309 shown in Figure 3.
[0115] More specifically, the MN 303 can make resource allocation requests to one or more PDU (Protocol Data Unit) sessions or QoS (Quality of Service) streams to the SN by using SN add request messages.
[0116] MN 303 can send an SN add request message, which includes: one or more K SN The keys, and at least one of the following: SN counter values used to generate these keys, key IDs identifying these keys, UP security capabilities (a list of encryption and integrity protection algorithms supported by the UE), or UP security policies (factors indicating whether UP data encryption and integrity protection are performed, and each of encryption and integrity protection can have one of "necessary," "preferred," and "unnecessary" values). When multiple K keys are sent to each SN... SNWhen using keys, MN 303 can place a marker on one of the multiple keys assigned to each SN.
[0117] To enable the UE to perform repeated conditional SN changes, the process by which the MN makes a resource allocation request to the SN via an SN Add Request message is not limited to making a resource allocation request to a single SN. For example, the MN can make resource allocation requests to multiple SNs. The MN can also request whether the SN has the capability for selective SCG.
[0118] MN 303 can store the SN counter values assigned to each SN separately. That is, MN 303 can store the SN counter values assigned to each SN in a manner associated with the SN. In the future, in the event of a new SN counter value being assigned to the UE or an update to the secondary node key, MN 303 can retain the maximum value among the assigned SN counter values. Alternatively, MN 303 can retain the value obtained by adding 1 to the maximum value among the assigned SN counter values.
[0119] In step 325, at least one SN can generate a Radio Resource Control (RRC) key or a User Plane (UP) key.
[0120] More specifically, if an SN (which may include T-SN 307 and / or other potential T-SN 309) needs to generate an RRC key or an UP key, then each SN may select K according to the agreed rules. SN A key, such as K corresponding to the minimum SN counter value. SN K labeled separately by MN SN Or the first K received SN And by using the selected key, an RRC key and an UP key are generated.
[0121] In step 330, at least one SN can send an SN add request confirmation message to MN 303.
[0122] More specifically, if the SN (which may include T-SN 307 and / or other potential T-SN 309) can accept the resource allocation request from MN 303 in step 325, then the SN can send an SN add request confirmation message in response to step 320.
[0123] The SN-added request confirmation message may also include at least one indication of the algorithm selected by the SN, whether the UP data is protected for integrity, and whether the UP data is encrypted.
[0124] In addition, the SN add request confirmation message may include an SN RRC configuration message, which includes radio resource configuration.
[0125] If MN 303 requests the capability for selective SCG in step 320, SN can respond by indicating whether SN has the capability. For example, SN can respond via a selective SCG capability indication. If SN does not respond to the selective SCG capability, this can indicate that SN does not support selective SCG.
[0126] In step 335, MN 303 may send an RRC reconfiguration message to UE 301.
[0127] More specifically, MN 303 may send an RRC reconfiguration message (e.g., an RRC connection reconfiguration message or an RRC reconfiguration message) to the UE, which may include the SN RRC configuration message received from the SN at step 330.
[0128] RRC reconfiguration messages (e.g., RRC connection reconfiguration messages or RRC reconfiguration messages) may include conditional PSCell change (CPC) configuration information (a list of RRC connection reconfiguration messages sent by the SN).
[0129] Additionally, RRC reconfiguration messages (e.g., RRC connection reconfiguration messages or RRC reconfiguration messages) may include at least one of the following information for each SN: SN counter value, SN selection algorithm, indication of whether UP data is encrypted, or indication of whether UP data is protected for integrity.
[0130] If, in step 320, MN 303 has already sent multiple keys, including a tagging key, to each SN, MN can also tag the SN counter values used to generate the corresponding keys and send the keys to UE 301. This can be in cases where the SN does not support selective SCG when sending an SN counter corresponding to one SN. MN can store only the maximum value among the SN counter values that have been sent, or it can store only the result obtained by adding 1 to the maximum value. Alternatively, MN can store all the SN counter values that have been sent, or it can store only the maximum value among the values already assigned to each SN. This can be used for updating K. SN Information about the key or information for future use of the corresponding functions.
[0131] In step 340, UE 301 may apply the RRC reconfiguration message (e.g., RRC connection reconfiguration message or RRC reconfiguration message) sent by MN 303, and may store CPC configuration information and SN counter value for each SN sent by MN 303 in step 335.
[0132] In step 345, MN 303 can notify source SN 303 via the Xn-U address indication process that CPC information has been configured for the UE.
[0133] In step 350, UE 301 may begin to evaluate execution conditions based on the CPC configuration information received from MN 303 in step 335. If the execution conditions associated with the candidate SN are met, UE 301 may prepare to connect to the SN that meets its execution conditions.
[0134] Among the multiple SN counter values used for the corresponding SN received from MN 303 in step 335, UE 301 can select an unused SN counter value, the minimum SN counter value, or a separately marked SN counter value, and can use the SN counter value, K MN 0x79, SN counter length, etc. are used as inputs to generate K SN Key.
[0135] In step 355, UE 301 may send an RRC reconfiguration complete message to MN 303 to notify the selected SN.
[0136] More specifically, in step 335, UE 301 may send an RRC reconfiguration complete message (e.g., an RRC connection reconfiguration complete message or an RRC reconfiguration complete message) based on CPC configuration information received from MN 303 to notify MN of the SN selected after evaluating the execution conditions.
[0137] The RRC reconfiguration completion message may include information used by the UE to generate K. SN The SN counter value, the order of the SN counter values used among the multiple SN counter values received for the corresponding SN, or the key ID generated in the same way as MN by using the SN counters used.
[0138] If the SN counter value sent by UE 301 is the last remaining or last unused value among the SN counter values for the corresponding SN that UE 301 has received from MN 303, then UE 301 may send an indication that all SN counters have been used for the corresponding SN. This indication can be sent by including it in the RRC reconfiguration complete message.
[0139] If MN 303 stores all SN counters assigned to each SN, then MN 303 can determine whether the SN counter value sent by UE 301 matches (or is the same as) the value assigned by MN 303 to the corresponding SN, and can identify whether it is necessary to assign a new SN counter value to the corresponding SN. Thereafter, MN 303 can assign a new SN counter value and transmit it to UE 301 if necessary.
[0140] In step 360, UE 301 may delete the SN counter value corresponding to the value sent in step 355 after performing step 355, or may place a mark on the corresponding SN counter value to indicate that the value has been used.
[0141] In the accompanying drawings, step 360 is indicated to be performed immediately after step 355, but the scope of this disclosure is not limited thereto, and step 360 may be performed at any time after step 355.
[0142] In step 365, MN 303 may send an SN release request message to the source SN (S-SN) 305.
[0143] In step 370, S-SN can send an SN release request confirmation message to MN 303.
[0144] In step 375, MN 303 may add the value received from UE 301 in step 355 or the key ID generated using the received SN counter to the SN reconfiguration completion message and send the message to the SN.
[0145] The SN that has already received the message can find K based on the received value. SN The key, then the SN can use the found K SN Communicate with the UE.
[0146] MN 303 can compare the SN counter value received from UE 301 in step 355 with the SN counter value held by MN 303.
[0147] For example, if the SN counter value sent by UE 301 is less than the value held by MN 303, then MN 303 can retain the held SN counter value as is.
[0148] On the other hand, if the SN counter value sent by UE 301 is greater than or equal to the value held by MN 303, then MN 303 may send an error message to UE 301.
[0149] When MN 303 generates K using the SN counter value SN When using a key, if the SN counter value used is less than the SN counter value held by MN303, then MN303 can retain the held SN counter as is (SN counter retention).
[0150] When MN 303 generates K using the SN counter value SNWhen generating a key, if the SN counter value used is equal to the SN counter value held by MN303, then after generating the key or sending the SN counter used to UE 301, MN 403 can increment the held SN counter by 1 and maintain the counter (secondary node key update).
[0151] Additionally, if K in MN 303 gNB (i.e., K) MN If the key has changed, for selective SCG activation, MN303 can reset the SN counter (e.g., reset it to 0), assign a new SN counter value to each SN, and send it to UE301. If in K gNB (i.e., K) MN If there is a change in the SN counter value, UE 301 can delete the received SN counter value used for selective SCG activation, even if the value is an unused SN counter value, and wait to receive the SN counter value again from MN 303.
[0152] Although if there is an unused K SN If a new K is received from MN 303 via an add request via SN SN If the SN counter or key ID is used, then the SN can delete the previously stored value (e.g., K). SN (SN counter or key ID).
[0153] Steps 350 to 375 can be repeated without the need to perform steps 310 to 340.
[0154] In step 380, if the UE selects and connects to one of the other potential T-SNs 309, the selected T-SN 307 can be connected to the K received in step 320. SN Delete K from the key corresponding to the value received in step 375. SN and its value.
[0155] Figures 4A and 4B illustrate a process for performing security key synchronization according to another embodiment of the present disclosure.
[0156] More specifically, Figures 4A and 4B illustrate, according to embodiments of the present disclosure, that when repeated conditional SN changes are performed in a dual-connectivity scenario, synchronization will be used in the K-series between the UE and the secondary node (SN). SN A sequence diagram of the process.
[0157] Referring to Figures 4A and 4B, in step 410, the user equipment (UE) 401 and the master node (MN) 403 may share with each other their respective capabilities or capability information for repeated conditional SN changes (selective SCG). The capability or capability information for repeated conditional SN changes may include an indication of whether selective SCG is supported.
[0158] The sharing of capabilities or capability information for repeated conditional SN changes can be performed via registration messages or Access Layer (AS) SMC messages. As described above, SMC messages may include AS security mode command messages sent from the base station to the UE, and AS security mode completion messages sent from the UE to the base station.
[0159] The AS security mode command message is a message sent from the base station to the UE, and can be the first integrity protection message in the AS message.
[0160] The AS security mode completion message is a message sent from the UE to the base station and can be the first encryption and integrity protection message in the AS message.
[0161] If UE 401 or MN 403 does not send capability or capability information for repeated conditional SN changes, this in itself may mean that the UE or MN does not support selective SCG.
[0162] In step 435, the UE can determine whether the base station supports selective SCG based on the transmission of multiple SN counter values.
[0163] Selective SCG can refer to a technique in which the UE receives SN RRC condition configuration information for one or more SNs from the MN and repeatedly makes SN changes based on the received information without receiving additional information from the MN.
[0164] More specifically, this can refer to a process in which, when the MN makes a resource allocation request for a UE's PDU (Protocol Data Unit) session or QoS (Quality of Service) stream to one or more SNs, and the MN sends an RRC reconfiguration message including SN RRC condition configuration information for each SN, the UE uses the received condition information to repeatedly make change requests to SNs that meet specific conditions, provided that the conditions are met.
[0165] In other words, this could mean that if the MN has already sent an indication that the MN supports selective SCG, then whenever the conditions are met, the UE that has already received SN RRC condition configuration information for multiple SNs can make an SN change request to the MN without receiving additional configuration information from the MN.
[0166] This could mean that if the UE has already sent an indication that it supports selective SCG, the UE can repeatedly make SN changes after receiving SN RRC condition configuration information for multiple SNs.
[0167] In step 415, MN 403 may send an SN add request message to at least one SN. The at least one SN may include the target SN (T-SN) 407 shown in FIG. 3 and / or other potential T-SN 409.
[0168] More specifically, if MN 401 has determined to perform selective SCG, the MN can send an SN Add Request to the SN for which it requests resource allocation. The MN can use the SN Add Request message to make resource allocation requests for one or more PDU sessions or QoS flows to the SN.
[0169] MN 403 can know in advance whether SN supports selective SCG. MN can send a K to SN via an add request message. SN In order to generate K SN MN can use K SN The input values include 0x79, the SN counter value, and the SN counter length. The MN can generate a key by assigning different SN counter values to various SNs. The MN can send the key without using an SN add-in request. SN .
[0170] K SN It is the key used by the secondary node (SN), and the SN can use K. SN This is used to generate keys for encrypting and protecting the integrity of user plane (UP) data exchanged between the UE and SN.
[0171] MN 403 can send an SN add request message, which includes a K SN The key, and at least one of the following: SN counter value or key ID used to generate the key, UP security capabilities (a list of encryption and integrity protection algorithms supported by the UE), or UP security policy (a factor indicating whether UP data encryption and integrity protection are performed, and each of the encryption and integrity protection can have one of the values of "required", "preferred" and "undesired").
[0172] To enable the UE to perform repeated conditional SN changes, the process by which the MN makes a resource allocation request to the SN via an SN Add Request message is not limited to making a resource allocation request to a single SN. For example, the MN can make resource allocation requests to multiple SNs. The MN can also request whether the SN has the capability for selective SCG.
[0173] More specifically, if MN 403 has determined to perform selective SCG, then MN can allocate multiple SN counter values to each SN for which it requests resource allocation. MN 403 can store the SN counter values allocated to each SN separately. That is, MN 403 can store the SN counter values allocated to each SN in a manner associated with the SN. In the future, in the event of a new allocation of SN counter values to the UE or an update of the secondary node key, MN 403 can retain the maximum value among the allocated SN counter values. Alternatively, MN 403 can retain the value obtained by adding 1 to the maximum value among the allocated SN counter values.
[0174] In step 420, at least one SN can generate a Radio Resource Control (RRC) key or a User Plane (UP) key.
[0175] More specifically, if an SN (which may include T-SN 407 and / or other potential T-SN 409) needs to generate an RRC key or an UP key, each SN can do so by using the received K SN To generate them. If no key is received in step 415, the SN may not be able to generate an RRC key or an UP key.
[0176] In step 425, at least one SN can send an SN add request confirmation message to MN 403.
[0177] More specifically, if the SN (which may include T-SN 407 and / or other potential T-SN 409) can accept the resource allocation request from MN 403 in step 415, then the SN can send an SN add request confirmation message in response to step 415.
[0178] The SN add request confirmation message may also include at least one indication of the algorithm selected by the SN, whether the UP data is protected for integrity, and whether the UP data is encrypted.
[0179] In addition, the SN add request confirmation message may include an SN RRC configuration message, which includes radio resource configuration.
[0180] If MN 403 requests the capability for selective SCG in step 415, SN can respond by indicating whether SN has that capability. For example, SN can respond via a selective SCG capability indication. If SN does not respond to the selective SCG capability, this can indicate that SN does not support selective SCG.
[0181] In step 430, MN 403 may send an RRC reconfiguration message to UE 401.
[0182] More specifically, MN 403 may send an RRC reconfiguration message (e.g., an RRC connection reconfiguration message or an RRC reconfiguration message) to the UE, which may include the SN RRC configuration message received from the SN in step 425.
[0183] RRC reconfiguration messages (e.g., RRC connection reconfiguration messages or RRC reconfiguration messages) may include conditional PSCell change (CPC) configuration information (a list of RRC connection reconfiguration messages sent by the SN).
[0184] Additionally, RRC reconfiguration messages (e.g., RRC connection reconfiguration messages or RRC reconfiguration messages) may include at least one of the following information for each SN: SN counter value, SN selection algorithm, indication of whether UP data is encrypted, or indication of whether UP data is protected for integrity.
[0185] MN 403 can place a marker on one of the SN counter values corresponding to each SN (which may be the SN counter value used to generate the key sent in step 415) and send it. Alternatively, if no separate marker exists, the UE may first use the smallest SN counter value. This can be in cases where the SN does not support selective SCG when sending an SN counter corresponding to one SN. MN can store only the maximum value of the SN counter values that have been sent, can store the result obtained by adding 1 to the maximum value, or can store all the SN counter values that have been sent. This can be used for future updates to K. SN Key information. If UE 401 needs to generate an RRC key or an UP key, the UE can use the minimum value of the SN counter values corresponding to the SN (which may include T-SN 407 and / or other potential T-SN 409), a tagged value received from the MN, or a value determined by separately agreed rules.
[0186] In step 435, UE 401 may apply the RRC reconfiguration message (e.g., RRC connection reconfiguration message or RRC reconfiguration message) sent by MN 403, and may store CPC configuration information and SN counter value for each SN sent by MN 403 in step 430.
[0187] In step 440, MN 403 can notify the source SN that CPC information has been configured for the UE through the Xn-U address indication process.
[0188] In step 445, the UE may begin to evaluate execution conditions based on the CPC configuration information received from the MN in step 430. If the execution conditions associated with the candidate SN are met, the UE 401 may prepare to connect to the SN that meets its execution conditions.
[0189] Among the multiple SN counter values used for the corresponding SN received from the MN in step 430, UE 401 can select an unused SN counter value, the minimum SN counter value, or a separately marked SN counter value, and can use the SN counter value, K MN 0x79, SN counter length, etc. are used as inputs to generate K SN Key.
[0190] In step 450, UE 401 may send an RRC reconfiguration complete message (e.g., an RRC connection reconfiguration complete message or an RRC reconfiguration complete message) that notifies the MN of the selected SN after evaluating the execution conditions, based on the CPC configuration information received from MN 403 in step 430. This message may include information used by the UE to generate K. SN The SN counter value.
[0191] If the SN counter value sent by UE 401 is the last remaining or last unused value among the SN counter values for the corresponding SN that UE 401 has received from MN 403, then UE 401 can send an indication that all SN counters have been used for the corresponding SN. This indication can be sent by including it in the RRC reconfiguration complete message.
[0192] In step 455, UE 401 may delete the SN counter value corresponding to the value sent in step 450 after performing step 450, or may place a mark on the corresponding SN counter value to indicate that the value has been used.
[0193] In the accompanying drawings, step 455 is indicated to be performed immediately after step 450, but the scope of this disclosure is not limited thereto, and step 455 may be performed at any time after step 450.
[0194] In step 460, MN 403 can generate the same K by using the SN counter value sent by the UE in step 450. SN Key.
[0195] Although step 460 is indicated as shown in the accompanying drawings, the scope of this disclosure is not limited thereto, and step 460 can be performed at any time before step 475. An additional key may not be generated if the SN counter value received from the UE corresponds to the value of the key sent to the corresponding SN in step 415, or if an SN counter value has not yet been received from the UE.
[0196] MN 403 can compare the SN counter value received from UE 401 in step 450 with the SN counter value held by MN 403.
[0197] For example, if the SN counter value sent by UE 401 is less than the value held by MN 403, then MN 403 can retain the held SN counter value as is.
[0198] On the other hand, if the SN counter value sent by UE 401 is greater than or equal to the value held by MN 403, then MN403 can send an error message to UE 401.
[0199] Alternatively, if MN 403 stores all SN counters assigned to each SN, MN 403 can determine whether the SN counter value sent by UE 401 matches (or is the same as) the value assigned by MN 403 to the corresponding SN, and can identify whether it is necessary to assign a new SN counter value to UE 401 for the corresponding SN. Thereafter, MN 403 can assign the new SN counter value and transmit it to UE 401 if necessary.
[0200] In step 465, MN 403 may send an SN release request message to the source SN (S-SN) 405.
[0201] In step 470, S-SN 405 can send an SN release request confirmation message to MN.
[0202] In step 475, MN 403 can send an SN reconfiguration complete message to T-SN 407. MN 403 can then use the K generated in step 460... SN Add (or include) to the SN reconfiguration complete message. Although T-SN 407 has already received the K corresponding to UE 401 in step 415. SN However, if T-SN 407 receives the same or a different key in step 475, T-SN 407 can use the most recently received key. In this case, T-SN 407 may choose not to use the key received in step 415 or may delete it.
[0203] Steps 445 to 475 can be repeated without the need to perform steps 410 to 440 separately.
[0204] When MN 403 generates K using the SN counter value SN When using a key, if the SN counter value used is less than the SN counter value held by MN403, then MN403 can retain the held SN counter as is (SN counter retention).
[0205] When MN 403 generates K using the SN counter value SNWhen generating a key, if the SN counter value used is equal to the SN counter value held by MN403, then after generating the key or sending the SN counter used to UE 401, MN 403 can increment the held SN counter by 1 and maintain the counter (secondary node key update).
[0206] Additionally, if K in MN 403 gNB (i.e., K) MN If the key has changed, for selective SCG activation, MN403 can reset the SN counter (e.g., reset it to 0), assign the new SN counter value to each SN, and send it to UE401. If in K gNB (i.e., K) MN If there is a change in the SN counter value, UE 401 can delete the received SN counter value used for selective SCG activation, even if the counter value is an unused SN counter value, and wait to receive the SN counter value again from MN 403.
[0207] It should be noted that the block diagrams, schematic diagrams of control / data signal transmission and reception methods, and illustrative operation process diagrams shown in Figures 1A to 4B are not intended to limit the scope of the embodiments of this disclosure. That is, any component, entity, or operational step shown in Figures 1A to 4B should not be construed as a necessary element for implementing this disclosure, and this disclosure may be implemented using only some components that do not prejudice the subject matter.
[0208] The operations described above in the embodiments can be implemented by providing a memory that stores the corresponding program code in a specific component of the device. That is, the device controller can perform the above operations by causing the processor or CPU (central processing unit) to read and execute the program code stored in the memory.
[0209] Various components and modules of the entities or terminals described herein can be implemented or operated using hardware (e.g., logic circuits based on complementary metal-oxide-semiconductor), firmware, software, or software embedded in a machine-readable medium, or any combination thereof. For example, various electrical structures and methods can be implemented using circuits such as transistors, logic gates, or application-specific integrated circuits.
[0210] The methods described in the claims or specification of this disclosure may be implemented in hardware, software, or a combination thereof.
[0211] When implemented in software, a computer-readable storage medium may be provided to store one or more programs (software modules). The one or more programs stored in the computer-readable storage medium may be configured to be executed by one or more processors of an electronic device. The one or more programs may include instructions to cause the electronic device to perform a method according to an embodiment described in the claims or specification of this disclosure.
[0212] Such programs (software modules, software) can be stored in random access memory, non-volatile memory (e.g., flash memory), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), disk storage devices, optical disc ROM (CD-ROM), digital versatile discs (DVDs), other types of optical storage devices, or magnetic tape cassettes. Alternatively, such programs can be stored in a memory consisting of some or all of these. Furthermore, multiple component memories may be included.
[0213] Furthermore, such a program can be stored in a connectable storage device that can be accessed via a communication network such as the Internet, intranet, local area network (LAN), wide area network (WAN), or storage area network (SAN), or via a communication network consisting of a combination of these. This storage device can access the device executing embodiments of this disclosure via an external port. Additionally, a separate storage device on the communication network can access the device executing embodiments of this disclosure.
[0214] In the embodiments disclosed above, elements included in this disclosure are represented in singular or plural form according to the specific embodiments presented. However, the singular or plural expressions are suitably chosen for ease of description as presented, and this disclosure is not limited to a single element or a plural element. Those elements described in plural form may be configured as a single element, and those elements described in singular form may be configured as multiple elements.
[0215] Furthermore, while specific embodiments have been described in the detailed description of this disclosure, various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the embodiments described above, but should be determined based on the patent claims described below and their equivalents.
[0216] Although this disclosure has been described with reference to various embodiments, those skilled in the art may suggest various changes and modifications. This disclosure is intended to include such changes and modifications that fall within the scope of the appended claims.
Claims
1. A method executed by a master node MN in a communication system, the method comprising: Send an SN add request message to at least one target secondary node SN, the SN add request message including at least one SN counter value corresponding to each target SN and K. SN The key, wherein each target SN includes a first target SN and a second target SN; Send a first Radio Resource Control (RRC) reconfiguration message to the User Equipment (UE), the first RRC reconfiguration message including at least one SN counter value corresponding to each target SN and the K SN Key; and Send an SN reconfiguration complete message to the first target SN, the SN reconfiguration complete message including the SN counter value received from the UE.
2. The method according to claim 1, further comprising: Receive an SN add request confirmation message from the at least one target SN, the SN add request confirmation message including at least one algorithm information or user plane UP integrity and encryption information; as well as The UE receives an RRC reconfiguration complete message including the SN counter value. The SN counter value is used to derive the K. SN Key, and Wherein, the MN holds the largest SN counter value among the at least one SN counter values, each of the at least one SN counter values corresponding to each target SN.
3. The method according to claim 1, further comprising: With the new key established, derive the new SN counter value for each target SN; as well as A second RRC reconfiguration message is sent to the UE, including the new SN counter value for each target SN.
4. A method executed by a first target secondary node SN in a communication system, the method comprising: Receive an SN add request message from the master node MN. The SN add request message includes at least one SN counter value corresponding to each target SN and K. SN The key, wherein each target SN includes a first target SN and a second target SN; Send an SN add request confirmation message to the MN, the SN add request confirmation message including at least one algorithm information or user plane UP integrity and encryption information; and The MN receives an SN reconfiguration complete message, which includes an SN counter value received from the user equipment (UE).
5. The method according to claim 4, further comprising: Receive at least one second K corresponding to the first target SN from the MN. SN Key and second SN counter value; Delete at least one stored SN counter value and the K SN Key; as well as Store the at least one second K SN The key and the second SN counter value; The SN counter value received from the UE is used for communication between the UE and the first target SN.
6. The method according to claim 4, further comprising: The UP key is calculated based on the smallest SN counter value among the at least one SN counter values.
7. A method performed by a user equipment (UE) in a communication system, the method comprising: Receive a first Radio Resource Control (RRC) reconfiguration message from the master node MN. The first RRC reconfiguration message includes at least one SN counter value corresponding to each target secondary node SN and K. SN Key; Calculate the K based on the SN counter value among the at least one SN counter values. SN Key; as well as Send an RRC reconfiguration complete message to the MN, the RRC reconfiguration complete message including the method for deriving the K SN The SN counter value of the key.
8. The method according to claim 7, further comprising: Receive a second RRC reconfiguration message from the MN, including new SN counter values for each target SN; Delete at least one SN counter value received from the first RRC reconfiguration message; as well as Store the new SN counter value received from the second RRC reconfiguration message.
9. A master node MN in a communication system, the MN comprising: transceiver; as well as A controller, operably connected to the transceiver, is configured to: Send an SN add request message to at least one target secondary node SN, the SN add request message including at least one SN counter value corresponding to each target SN and K. SN The key, wherein each target SN includes a first target SN and a second target SN, Send a first Radio Resource Control (RRC) reconfiguration message to the User Equipment (UE), the first RRC reconfiguration message including at least one SN counter value corresponding to each target SN and the K SN Key, and Send an SN reconfiguration complete message to the first target SN, the SN reconfiguration complete message including the SN counter value received from the UE.
10. The MN according to claim 9, wherein, The controller is also configured to: Receive an SN add request confirmation message from the at least one target SN, the SN add request confirmation message including at least one algorithm information or user plane UP integrity and encryption information; as well as The UE receives an RRC reconfiguration complete message including the SN counter value. The SN counter value is used to derive the K. SN Key, and Wherein, the MN holds the largest SN counter value among the at least one SN counter values, each of the at least one SN counter values corresponding to each target SN.
11. The MN according to claim 9, wherein, The controller is also configured to: With the new key established, derive the new SN counter value for each target SN, and A second RRC reconfiguration message is sent to the UE, including the new SN counter value for each target SN.
12. A first target auxiliary node SN in a communication system, the first SN comprising: transceiver; as well as A controller, operably connected to the transceiver, is configured to: Receive an SN add request message from the master node MN. The SN add request message includes at least one SN counter value corresponding to each target SN and K. SN The key, wherein each target SN includes a first target SN and a second target SN, Send a SN add request confirmation message to the MN. The SN add request confirmation message includes at least one algorithm information or user plane UP integrity and encryption information, and The MN receives an SN reconfiguration complete message, which includes an SN counter value received from the user equipment (UE).
13. The first target SN according to claim 12, wherein, The controller is also configured to: Receive at least one second K corresponding to the first target SN from the MN. SN Key and second SN counter value, Delete at least one stored SN counter value and the K SN Key, and Store the at least one second K SN The key and the second SN counter value, The SN counter value received from the UE is used for communication between the UE and the first target SN. The controller calculates the UP key based on the smallest SN counter value among the at least one SN counter values.
14. A user equipment (UE) in a communication system, the UE comprising: transceiver; as well as The controller is configured as follows: Receive a first Radio Resource Control (RRC) reconfiguration message from the master node MN. The first RRC reconfiguration message includes at least one SN counter value corresponding to each target secondary node SN and K. SN Key Calculate the K based on the SN counter value among the at least one SN counter values. SN Key, and Send an RRC reconfiguration complete message to the MN, the RRC reconfiguration complete message including the method for deriving the K SN The SN counter value of the key.
15. The UE according to claim 14, wherein, The controller is also configured to: Receive a second RRC reconfiguration message from the MN, including new SN counter values for each target SN; Delete at least one SN counter value received from the first RRC reconfiguration message; as well as Store the new SN counter value received from the second RRC reconfiguration message.