Preventing service node security key mismatch

By exchanging and verifying SN keys or counters between network nodes and user equipment, the key mismatch problem in SCPAC mobility is solved, ensuring successful secure communication.

CN121925880APending Publication Date: 2026-04-24NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2024-08-14
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In subsequent Conditional PSCell Add/Change (SCPAC) Mobility, the User Equipment (UE) may fail to make handover due to a key mismatch caused by selecting the wrong Serving Node (SN) Security Key Counter.

Method used

Network nodes and user equipment ensure that the generated SN key or counter matches the network node's expectations by exchanging and verifying SN keys or counters, and adjust the counter index by sending instruction messages and configuration procedures to avoid mismatches.

Benefits of technology

This effectively prevents handover failures due to SN key mismatch and ensures secure communication between the UE and the target SN.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121925880A_ABST
    Figure CN121925880A_ABST
Patent Text Reader

Abstract

According to one aspect, a network node is provided that supports dual connectivity of a user equipment to the network node and to a secondary network node. The network node may receive a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node. The network node may determine whether the generated second secondary network node key or secondary network node counter matches a second secondary network node key or second secondary network node counter that the network node desires to use by the user equipment. The network node may send a second message including an indication associated with the match to the user equipment based on the determination.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The various example embodiments generally relate to the field of telecommunications systems. In particular, some example embodiments relate to solutions for preventing any failures due to service node security key mismatches in subsequent Conditional PSCell Add / Change (SCPAC) mobility. Background Technology

[0002] User equipment (UE) can be configured to apply dual connectivity in wireless communication networks, for example, in networks applying Post-Conditional PSCell Add / Change (SCPAC) mobility. When a UE establishes dual connectivity, it requires a serving node (SN) key K_SN to protect and encrypt its connection with the serving SN. The SN key is generated by the UE using an SN counter provided by the master node (MN), the length of the SN counter, and the MN key K_gNB.

[0003] The MN shares the UE's counters and generates an SN key to access the SN's list of sk counters. The MN can also notify candidate SNs of the SN key the UE will use based on the extracted sk counters. The serving SN should know the SN key the UE will use for end-to-end encryption.

[0004] The MN can initiate SCPAC preparation, where SN1 and SN2 provide candidate SCPAC configurations for SN1 and SN2, respectively. The MN provides a list of sk counters for each SN; that is, one list for SN1 and another for SN2. To perform SCPAC on the PSCell provided by SN2, the UE needs to use a new key different from the key used with SN1. To do this, the UE extracts sk counters from the sk counter list of SN2 and generates the SN2 key.

[0005] The UE decodes the candidate SCPAC configuration and sends an RRC Reconfiguration Complete message to the MN to indicate which candidate configuration was executed. Therefore, the MN notifies SN2 about the SCPAC execution.

[0006] However, if the UE selects an incorrect sk counter that differs from the expected values ​​of the MN and the target SN, a mismatch occurs between the security keys of the UE and the target SN. This means that the target SN cannot decode the encrypted message, and this will cause the handover between the UE and the target SN to fail.

[0007] There are several reasons why a UE might select an incorrect sk counter. For example, an incorrect UE implementation could cause sk counter index shifting (i.e., selecting an incorrect sk counter), or a failure scenario could cause the network to lose track of the sk counter being used. Furthermore, if the UE starts retrieving an incorrect sk counter, subsequent sk counter selections will also follow the same error because sk counter selection is sequential. Summary of the Invention

[0008] The present invention is provided to present, in a simplified form, the selection of concepts further described below in the detailed description. The present invention is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.

[0009] The exemplary embodiments disclosed herein provide a solution to prevent any failures due to service node security key mismatches in subsequent Conditional PSCell Add / Change (SCPAC) mobility. This and other benefits can be realized through the features of the independent claims. Further exemplary embodiments are provided in the dependent claims, the specification, and the drawings.

[0010] According to a first aspect, a network node supports dual connectivity from a user equipment to the network node and to a secondary network node, and may include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network node to at least: receive a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; determine whether the generated second secondary network node key or the secondary network node counter matches a second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use; and based on the determination, send a second message to the user equipment including an indication associated with the match.

[0011] In an example embodiment of the first aspect, the instruction includes approving a second auxiliary network node key or a second auxiliary network node counter generated by the user equipment.

[0012] In an example embodiment of the first aspect, the indication includes disapproval of the generated second auxiliary network node key or second auxiliary network node counter for the user equipment, as well as an index of the correct counter.

[0013] In an example embodiment of the first aspect, the second message includes an index to the correct counter to be used by the user equipment.

[0014] In an example embodiment of the first aspect, the instructions, when executed by at least one processor, cause the network node to at least: receive a third message from a user equipment, the third message including a regenerated second secondary network node key or a newly used second secondary network node counter associated with the second secondary network node; determine that the regenerated second secondary network node key or the newly used second secondary network node counter matches a second secondary network node key or second secondary network node counter that the network node expects the user equipment to use; and based on the determination, send a fourth message to the user equipment, the fourth message including approval of the regenerated second secondary network node key or the newly used second secondary network node counter.

[0015] In an example embodiment of the first aspect, the instructions, when executed by at least one processor, cause the network node to at least: send a fifth message to the user equipment before receiving the first message, the fifth message including a configuration for the user equipment to wait for approval of a second secondary network node key or a second secondary network node counter before use.

[0016] In an example embodiment of the first aspect, the first message includes a Radio Resource Control (RRC) reconfiguration complete message.

[0017] According to a second aspect, a user equipment is configured to operate in a dual-connection mode with a network node and a secondary network node, the user equipment being served by a first secondary network node, the user equipment may include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to at least: send a first message to the network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; and receive a second message from the network node, the second message including an indication of whether the generated second secondary network node key or the secondary network node counter matches a second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use.

[0018] In an example embodiment of the second aspect, the instruction includes approving a generated second secondary network node key or a second secondary network node counter for the user equipment, and wherein the instruction, when executed by at least one processor, causes the user equipment to at least: initiate a random access procedure to the second secondary network node in response to the approval.

[0019] In an example embodiment of the second aspect, the instruction includes disapproving the generated second secondary network node key or second secondary network node counter and an index of the correct counter for the user equipment, and wherein the instruction, when executed by at least one processor, causes the user equipment to at least: adjust the counter index; send a third message to the network node, the third message including a regenerated second secondary network node key or a newly used second secondary network node counter associated with the adjusted counter index and associated with the second secondary network node, the newly used second secondary network node counter being associated with the adjusted counter index; receive a fourth message from the network node, the fourth message including approving the regenerated second secondary network node key or the newly used second secondary network node counter for the user equipment; and, in response to the approval, initiate a random access procedure to the second secondary network node.

[0020] In an example embodiment of the second aspect, the second message includes an index of the correct counter to be used by the user equipment, and wherein the instructions, when executed by at least one processor, cause the user equipment to at least: adjust the counter index based on the index received from the network node.

[0021] In an example embodiment of the second aspect, the instructions, when executed by at least one processor, cause the user equipment to at least: receive a fifth message from a network node before sending a first message, the fifth message including a configuration for the user equipment to wait for approval of a second secondary network node key or a second secondary network node counter before use.

[0022] In an example embodiment of the second aspect, the first message includes a Radio Resource Control (RRC) reconfiguration complete message.

[0023] In an example embodiment of the second aspect, the instructions, when executed by at least one processor, cause the user equipment to at least: immediately initiate a random access procedure to a second auxiliary network node after sending the first message to the network node.

[0024] According to a third aspect, a method performed by a network node supporting dual connectivity from a user equipment to the network node and to a secondary network node, the method may include: receiving a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; determining whether the generated second secondary network node key or the secondary network node counter matches a second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use; and based on the determination, sending a second message to the user equipment including an indication associated with the match.

[0025] In an example embodiment of the third aspect, the instruction includes approving the generated second auxiliary network node key or second auxiliary network node counter for the user equipment.

[0026] In an example embodiment of the first aspect, the indication includes disapproval of the generated second auxiliary network node key or second auxiliary network node counter for the user equipment, as well as an index of the correct counter.

[0027] In an example embodiment of the third aspect, the second message includes an index to the correct counter to be used by the user equipment.

[0028] In an example embodiment of the third aspect, the method further includes: receiving a third message from a user equipment, the third message including a regenerated second secondary network node key or a newly used second secondary network node counter associated with the second secondary network node; determining that the regenerated second secondary network node key or the newly used second secondary network node counter matches a second secondary network node key or second secondary network node counter that the network node expects the user equipment to use; and based on the determination, sending a fourth message to the user equipment, the fourth message including approval of the regenerated second secondary network node key or the newly used second secondary network node counter.

[0029] In an example embodiment of the third aspect, the method further includes: sending a fifth message to the user equipment before receiving the first message, the fifth message including a configuration for the user equipment to wait for approval of the second secondary network node key or the second secondary network node counter before use.

[0030] In an example embodiment of the third aspect, the first message includes a Radio Resource Control (RRC) reconfiguration completion message.

[0031] According to a fourth aspect, a method performed by a user equipment configured to operate in a dual-connectivity mode with a network node and a secondary network node, the user equipment being served by a first secondary network node, the method comprising: sending a first message to the network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; and receiving a second message from the network node, the second message including an indication of whether the generated second secondary network node key or the secondary network node counter matches a second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use.

[0032] In an example embodiment of the second aspect, the instruction includes approving the generated second secondary network node key or second secondary network node counter for the user equipment, and the method further includes: initiating a random access procedure to the second secondary network node in response to the approval.

[0033] In an example embodiment of the fourth aspect, the indication includes disapproving the generated second secondary network node key or second secondary network node counter for the user equipment and an index of the correct counter, and the method further includes: adjusting the counter index; sending a third message to the network node, the third message including a regenerated second secondary network node key or a newly used second secondary network node counter associated with the second secondary network node and associated with the adjusted counter index, the newly used second secondary network node counter being associated with the adjusted counter index; receiving a fourth message from the network node, the fourth message including approving the regenerated second secondary network node key or the newly used second secondary network node counter for the user equipment; and in response to approval, initiating a random access procedure to the second secondary network node.

[0034] In an example embodiment of the fourth aspect, the second message includes an index of the correct counter to be used by the user equipment, and the method further includes adjusting the counter index based on the index received from the network node.

[0035] In an example embodiment of the fourth aspect, the method further includes: receiving a fifth message from a network node before sending the first message, the fifth message including a configuration for the user equipment to wait for approval of a second secondary network node key or a second secondary network node counter before use.

[0036] In an example embodiment of the fourth aspect, the first message includes a Radio Resource Control (RRC) reconfiguration complete message.

[0037] In an example embodiment of the fourth aspect, the method further includes: immediately after sending the first message to the network node, initiating a random access procedure to the second auxiliary network node.

[0038] According to a fifth aspect, a computer program is disclosed. This computer program may include instructions that, when executed by a device, cause the device to perform the method according to the third or fourth aspect or any example embodiment thereof.

[0039] According to a sixth aspect, a (non-transitory) computer-readable medium is disclosed. The (non-transitory) computer-readable medium may include program instructions that, when executed by a device, cause the device to perform the method according to the third or fourth aspect or any example embodiment thereof.

[0040] According to a seventh aspect, a network node supporting dual connectivity between a user equipment (UE) and a secondary network node may include components for: receiving a first message from a UE served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; determining whether the generated second secondary network node key or the secondary network node counter matches a second secondary network node key or the second secondary network node counter that the network node expects the UE to use; and based on the determination, sending a second message to the UE including an indication associated with the match.

[0041] According to an eighth aspect, a user equipment configured to operate in a dual-connection mode with a network node and a secondary network node, the user equipment being served by a first secondary network node, the user equipment may include components for: sending a first message to the network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; and receiving a second message from the network node, the second message including an indication of whether the generated second secondary network node key or the secondary network node counter matches a second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use.

[0042] Many of the accompanying features will be easier to understand as they become clearer with reference to the following detailed description taken in conjunction with the accompanying drawings. Attached Figure Description

[0043] The accompanying drawings illustrate exemplary embodiments, which are included to provide a further understanding of the exemplary embodiments and form part of this specification, and together with the description aid in understanding the exemplary embodiments. In the drawings: Figure 1 An example of a SN key mismatch is shown for a UE operating in dual-connectivity mode.

[0044] Figure 2 An example of a device configured to practice one or more example embodiments is shown.

[0045] Figure 3 An example of a device configured to practice one or more example embodiments is shown.

[0046] Figure 4A A signaling diagram according to an example embodiment is shown.

[0047] Figure 4B A signaling diagram according to an example embodiment is shown.

[0048] Figure 4C A signaling diagram according to an example embodiment is shown.

[0049] Figure 4D A signaling diagram according to an example embodiment is shown.

[0050] Figure 4E A signaling diagram according to an example embodiment is shown.

[0051] Figure 4F A signaling diagram according to an example embodiment is shown.

[0052] Figure 5 An example of a method according to an example embodiment is shown.

[0053] Figure 6 An example of a method according to another example embodiment is shown.

[0054] In the accompanying drawings, the same reference numerals are used to denote the same parts. Detailed Implementation

[0055] Reference will now be made in detail to exemplary embodiments, examples of which are illustrated in the accompanying drawings. The detailed description provided below, in conjunction with the drawings, is intended as a description of the present example and is not intended to represent the only form in which the present example can be constructed or utilized. The specification sets forth the functionality of the example and the sequence of steps for constructing and operating the example. However, the same or equivalent functionality and sequence can be implemented through different examples.

[0056] Figure 1 An example of a SN key mismatch is shown for a UE operating in dual-connectivity mode.

[0057] At 108, UE 100 is in dual connectivity (DC) with master node (MN) 102 and service node 1 (SN1) 104.

[0058] At locations 110 and 112, MN 102 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 104 and SN2 106. MN 102 can share the SN key or list of SN keys that UE 100 will use to access SN1 and SN2.

[0059] At locations 114 and 116, both SN1 104 and SN2 106 can be prepared for confirmation by SCPAC in response to MN 102.

[0060] At position 118, MN 102 can provide UE 100 with candidate SCPAC configurations for SN1 104 and SN2 106 in an RRC Reconfiguration message. MN 102 can also provide a list of sk counters for each SN, i.e., one list for SN1 102 and another list for SN2 106.

[0061] At 120, the UE can decode the RRC reconfiguration received from MN 102 and send an RRC reconfiguration completion message to MN 102 to approve the reception of the configuration.

[0062] At point 122, once the SCPAC conditions for Primary / Secondary Cell 2 (PSCell-2) (under SN2 106) are met, UE100 can perform SCPAC for PSCell-2. Since the PSCell-2 handover is an inter-SN handover (from SN1 104 to SN2 106), UE100 needs to use a new key with SN2 106, which is different from the key used with SN1 104. To do this, UE100 extracts the sk counters from the sk counter list of SN2 106 and generates the SN2 key.

[0063] At position 124, UE 100 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 102 to indicate which candidate configuration to execute.

[0064] At position 126, MN 102 notifies SN2 106 of SCPAC execution. At this time, MN 102 may also share the SN key that UE 100 expects to use for accessing SN2 106 in this message.

[0065] At 128, UE 100 can initiate a random access channel (RACH) procedure to SN2 106, and UE 100 uses the generated SN2 key to access SN2 106.

[0066] If UE 100 retrieves a different sk counter at 122 than expected by MN 102 and SN2 106, this will result in a mismatch in security keys between UE 100 and SN2 106. As a result, SN2 106 cannot decode encrypted messages received from UE 100, and this leads to a handover failure between UE 100 and SN2 106.

[0067] There may be several reasons for an incorrect sk counter selection, such as an incorrect UE implementation that causes the sk counter index to shift, or a sk counter usage scenario or failure scenario that causes the network to lose tracking of the sk counter being used.

[0068] Figure 2An example of a device 200 configured to practice one or more exemplary embodiments is shown. Device 200 may include a network node, master node, or general network device configured to implement the functions described herein. Device 200 may include at least one processor 202. At least one processor 202 may include one or more of various processing devices, such as a coprocessor, microprocessor, controller, digital signal processor (DSP), processing circuitry with or without an accompanying DSP, or various other processing devices including integrated circuits such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), microcontroller units (MCUs), hardware accelerators, dedicated computer chips, etc.

[0069] The device 200 may also include at least one memory 204. Memory 204 may be configured to store, for example, computer program code, such as operating system software and application software. Memory 204 may include one or more volatile memory devices, one or more non-volatile memory devices, and / or combinations thereof. For example, memory may be embodied as a magnetic storage device (such as a hard disk drive, magnetic tape, etc.), an optical magnetic storage device, or a semiconductor memory (such as a mask ROM, PROM (programmable ROM), EPROM (erasable PROM), flash ROM, RAM (random access memory), etc.). An example of providing memory 204 as a (non-transitory) computer-readable medium is provided. As used herein, the term "non-transitory" is a limitation on the medium itself (i.e., tangible, not tactile), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM).

[0070] The device 200 may also include a communication interface 208, which is configured to enable the device 200 to send and / or receive information.

[0071] When device 200 is configured to perform a certain function, one or more components of device 200 (e.g., at least one processor 202 and / or at least one memory 204) may be configured to perform that function. Furthermore, when at least one processor 202 is configured to perform a certain function, that function may be implemented using, for example, program code 206 included in at least one memory 204.

[0072] The functions described herein can be performed, at least in part, by one or more computer program product components, such as software components. According to an example embodiment, device 200 includes a processor or processor circuitry, such as a microcontroller, configured by program code 206 to perform embodiments of the operations and functions described herein when executed. Program code 206 is provided as an example of instructions that, when executed by at least one processor 202, cause execution of device 200.

[0073] Alternatively or additionally, the functions described herein may be performed at least in part by one or more hardware logic components. For example, but not limited to, illustrative types of hardware logic components that may be used include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), Graphics Processing Units (GPUs), etc.

[0074] The apparatus 200 may be configured to perform the methods described herein, or may include components for performing the methods described herein. In one example, the components may include: at least one processor 202, and at least one memory 204 including program code 206 configured to cause the apparatus 200 to perform (multiple) methods when executed by at least one processor 202.

[0075] Although device 200 is shown as a single device, it should be understood that, where applicable, the functionality of device 200 can be distributed across multiple devices.

[0076] In an example embodiment, device 200 may be a network node or master node configured to provide dual connectivity to user equipment.

[0077] A network node can be configured to: receive a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; determine whether the generated second secondary network node key or secondary network node counter matches a second secondary network node key or second secondary network node counter that the network node expects the user equipment to use; and based on the determination, send a second message to the user equipment including an indication associated with the match.

[0078] The instruction may include a second auxiliary network node key or a second auxiliary network node counter generated for approval of the user equipment.

[0079] The indication may include disapproval of the generated second auxiliary network node key or second auxiliary network node counter for the user equipment, as well as an index of the correct counter.

[0080] The second message may include the index of the correct counter to be used by the user equipment.

[0081] A network node can be configured to: receive a third message from a user equipment, the third message including a regenerated second auxiliary network node key or a newly used second auxiliary network node counter associated with the second auxiliary network node; determine that the regenerated second auxiliary network node key or the newly used second auxiliary network node counter matches a second auxiliary network node key or second auxiliary network node counter that the network node expects the user equipment to use; and based on the determination, send a fourth message to the user equipment, the fourth message including approval of the regenerated second auxiliary network node key or the newly used second auxiliary network node counter.

[0082] The network node can be configured to send a fifth message to the user equipment before receiving the first message, the fifth message including a configuration for the user equipment to wait for approval of the second auxiliary network node key or the second auxiliary network node counter before use.

[0083] The first message may include a Radio Resource Control (RRC) reconfiguration complete message.

[0084] Figure 3 An example of a device 300 configured to practice one or more exemplary embodiments is shown. Device 300 may include a user node, user equipment, or general user device configured to implement the functions described herein. Device 300 may include at least one processor 302. At least one processor 302 may include one or more of various processing devices, such as a coprocessor, microprocessor, controller, digital signal processor (DSP), processing circuitry with or without an accompanying DSP, or various other processing devices including integrated circuits such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), microcontroller units (MCUs), hardware accelerators, dedicated computer chips, etc.

[0085] The device 300 may also include at least one memory 304. Memory 304 may be configured to store, for example, computer program code, such as operating system software and application software. Memory 304 may include one or more volatile memory devices, one or more non-volatile memory devices, and / or combinations thereof. For example, memory may be embodied as a magnetic storage device (such as a hard disk drive, magnetic tape, etc.), an optical magnetic storage device, or a semiconductor memory (such as a mask ROM, PROM (programmable ROM), EPROM (erasable PROM), flash ROM, RAM (random access memory), etc.). Examples of memory 304 provided as a (non-transitory) computer-readable medium are provided. As used herein, the term "non-transitory" is a limitation on the medium itself (i.e., tangible, not tactile), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM).

[0086] The device 300 may also include a communication interface 308, which is configured to enable the device 300 to send and / or receive information.

[0087] When device 300 is configured to perform a certain function, one or more components of device 300 (e.g., at least one processor 302 and / or at least one memory 304) may be configured to perform that function. Furthermore, when at least one processor 302 is configured to perform a certain function, that function may be implemented using, for example, program code 306 included in at least one memory 304.

[0088] The functions described herein can be performed, at least in part, by one or more computer program product components, such as software components. According to an example embodiment, device 200 includes a processor or processor circuitry, such as a microcontroller, configured by program code 306 to perform embodiments of the operations and functions described herein when executed. Program code 306 is provided as an example of instructions that, when executed by at least one processor 302, cause device 300 to perform.

[0089] Alternatively or additionally, the functions described herein may be performed at least in part by one or more hardware logic components. For example, but not limited to, illustrative types of hardware logic components that may be used include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), Graphics Processing Units (GPUs), etc.

[0090] The apparatus 300 may be configured to perform the methods described herein, or may include components for performing the methods described herein. In one example, the components may include: at least one processor 302, and at least one memory 304 including program code 306 configured to cause the apparatus 300 to perform (multiple) methods when executed by at least one processor 302.

[0091] In an example embodiment, apparatus 300 may be a user equipment (UE) configured to operate in a dual-connectivity mode with a network node and a secondary network node, the user equipment being served by a first secondary network node.

[0092] The UE can be configured to send a first message to a network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; and to receive a second message from the network node, the second message including an indication of whether the generated second secondary network node key or secondary network node counter matches a second secondary network node key or second secondary network node counter that the network node expects the user equipment to use.

[0093] The instruction may include the approval of the second secondary network node key or the second secondary network node counter generated by the user equipment, and the user equipment may be configured to initiate a random access procedure to the second secondary network node in response to the approval.

[0094] The instruction may include disapproving the generated second secondary network node key or second secondary network node counter for the user equipment, as well as an index of the correct counter, and the user equipment may be configured to: adjust the counter index; send a third message to the network node, the third message including a regenerated second secondary network node key or a newly used second secondary network node counter associated with the adjusted counter index and associated with the second secondary network node, the newly used second secondary network node counter being associated with the adjusted counter index; receive a fourth message from the network node, the fourth message including approving the regenerated second secondary network node key or the newly used second secondary network node counter for the user equipment; and, in response to approval, initiate a random access procedure to the second secondary network node.

[0095] The second message may include the index of the correct counter to be used by the user equipment, and the user equipment may be configured to adjust the counter index based on the index received from the network node.

[0096] The user equipment can be configured to receive a fifth message from the network node before sending the first message, the fifth message including a configuration for the user equipment to wait for approval of the second secondary network node key or the second secondary network node counter before use.

[0097] The first message may include a Radio Resource Control (RRC) reconfiguration complete message.

[0098] The user equipment can be configured to initiate a random access procedure to the second auxiliary network node immediately after sending the first message to the network node.

[0099] Figure 4A A signaling diagram according to an example embodiment is shown.

[0100] At 404, UE 300 is in dual connectivity (DC) with master node (MN) 200 and service node 1 (SN1) 400.

[0101] At positions 406 and 408, MN 200 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 400 and SN2 402. MN 200 can share the SN key or list of SN keys that UE 300 will use to access SN1 400 and SN2 402.

[0102] At locations 410 and 412, both SN1 400 and SN2 402 can be prepared to respond to MN 200 using SCPAC.

[0103] At 414, MN 200 provides candidate SCPAC configurations for SN1 400 and SN2 402 in the RRC reconfiguration message. MN 200 also provides a list of sk counters for each SN, i.e., one list for SN1 400 and another list for SN2 404. In an example embodiment, MN 200 may also provide a configuration for UE 300 to wait for approval of the SN node key or SN counters before use. In other words, the effect of the configuration is that when the SCPAC conditions are met, UE 300 will send the extracted sk counters to MN 200 and wait for MN 200's approval before accessing the candidate SN. In an example embodiment, the configuration can be sent to UE 300 in the RRC reconfiguration message. In another example embodiment, instead of explicitly indicating the configuration to UE 300, UE 300 may have to implement default behavior (without explicit configuration from MN 200), i.e., indicating to MN 200 the sk counters to be used and waiting for approval from MN 200 before accessing the candidate SN.

[0104] At 416, the UE decodes the RRC reconfiguration message received from MN 200 and sends an RRC reconfiguration complete message to MN 200 to approve the reception of the configuration.

[0105] At point 418, when the SCPAC conditions for the PSCell under SN2 402 are met, the UE performs SCPAC on the PSCell. Since the PSCell handover is an inter-SN handover from SN1 400 to SN2 402, the UE 300 needs to use a new key, which is different from the key used with SN1 400. Therefore, the UE 300 extracts the sk counters from the sk counter list of SN2 402 and generates the SN2 key.

[0106] At 420, UE 300 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute. UE 300 also includes the sk counter or SN key that UE 300 will use to access SN2 402.

[0107] At 422, MN 200 determines whether the generated SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. If the sk counter or SN key matches the sk counter or SN key that MN 200 expects UE 300 to use, at 424, MN 200 sends approval for the sk counter or SN key to be used and authorizes access SN2 402.

[0108] At position 426, MN 200 uses an SN reconfiguration complete message to notify SN2 404 of SCPAC execution. In the example embodiment, MN 200 may share the SN key that UE 300 expects to use for accessing SN2 402 in this message.

[0109] At 428, UE 300 can initiate a random access channel (RACH) procedure to SN2 402 and use the generated SN2 key to access SN2 402.

[0110] Since the sk counter and SN key used for SN access are controlled and approved by MN 200, any mismatch between UE 300 and SN2 402 will be prevented, and UE 300 will not experience any failures due to security key mismatch.

[0111] Figure 4B A signaling diagram according to an example embodiment is shown.

[0112] At 404, UE 300 is in dual connectivity (DC) with master node (MN) 200 and service node 1 (SN1) 400.

[0113] At positions 406 and 408, MN 200 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 400 and SN2 402. MN 200 can share the SN key or list of SN keys that UE 300 will use to access SN1 400 and SN2 402.

[0114] At locations 410 and 412, both SN1 400 and SN2 402 can be prepared to respond to MN 200 using SCPAC.

[0115] At 414, MN 200 provides candidate SCPAC configurations for SN1 400 and SN2 402 in the RRC reconfiguration message. MN 200 also provides a list of sk counters for each SN, i.e., one list for SN1 400 and another list for SN2 404. In an example embodiment, MN 200 may also provide a configuration for UE 300 to wait for approval of the SN node key or SN counters before use. In other words, the effect of the configuration is that when the SCPAC conditions are met, UE 300 will send the extracted sk counters to MN 200 and wait for MN 200's approval before accessing the candidate SN. In an example embodiment, the configuration can be sent to UE 300 in the RRC reconfiguration message. In another example embodiment, instead of explicitly indicating the configuration to UE 300, UE 300 may have to implement default behavior (without explicit configuration from MN 200), i.e., indicating to MN 200 the sk counters to be used and waiting for approval from MN 200 before accessing the candidate SN.

[0116] At 416, the UE decodes the RRC reconfiguration message received from MN 200 and sends an RRC reconfiguration complete message to MN 200 to approve the reception of the configuration.

[0117] At point 418, when the SCPAC conditions for the PSCell under SN2 402 are met, the UE performs SCPAC on the PSCell. Since the PSCell handover is an inter-SN handover from SN1 400 to SN2 402, the UE 300 needs to use a new key, which is different from the key used with SN1 400. Therefore, the UE 300 extracts the sk counters from the sk counter list of SN2 402 and generates the SN2 key.

[0118] At 420, UE 300 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute. UE 300 also includes the sk counter or SN key that UE 300 will use to access SN2 402.

[0119] At 430, MN 200 determines whether the generated SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. In this example embodiment, the generated SN key or sk counter received from UE 300 does not match the SN key or sk counter that MN 200 expects UE 300 to use, and MN 200 refuses to use the sk counter or SN key received from UE 300.

[0120] At position 432, MN 200 sends a message to UE 300 that includes disapproval of the SN key or sk counter. In the example embodiment, this message may also include the index of the correct sk counter to be used by UE 300 to retrieve a new sk counter.

[0121] At position 434, UE 300 adjusts the counter index to obtain a new sk counter and generates a new SN key. In the example embodiment, UE 300 can use the new sk counter index to retrieve the correct sk counter and may also generate a new SN key.

[0122] At position 436, UE 300 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute. UE 300 also includes a new sk counter or a new SN key that UE 300 will use to access SN2 402.

[0123] At 438, MN 200 determines that the new SN key or new sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use, and sends approval for the sk counter or SN key to be used at 440, and authorizes access to SN2 402 at 442.

[0124] At 442, MN 200 uses an SN reconfiguration complete message to notify SN2 404 of the SCPAC execution. In the example embodiment, MN 200 may share the SN key that UE 300 expects to use for accessing SN2 402 in this message.

[0125] At 444, UE 300 can initiate a Random Access Channel (RACH) procedure to SN2 402 and use the generated SN2 key to access SN2 402.

[0126] Since the sk counter and SN key used for SN access are controlled and approved by MN 200, any mismatch between UE 300 and SN2 402 will be prevented, and UE 300 will not experience any failures due to security key mismatch.

[0127] Figure 4C A signaling diagram according to an example embodiment is shown.

[0128] At 404, UE 300 is in dual connectivity (DC) with master node (MN) 200 and service node 1 (SN1) 400.

[0129] At positions 406 and 408, MN 200 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 400 and SN2 402. MN 200 can share the SN key or list of SN keys that UE 300 will use to access SN1 400 and SN2 402.

[0130] At locations 410 and 412, both SN1 400 and SN2 402 can be prepared to respond to MN 200 using SCPAC.

[0131] At 414, MN 200 provides candidate SCPAC configurations for SN1 400 and SN2 402 in the RRC reconfiguration message. MN 200 also provides a list of sk counters for each SN, i.e., one list for SN1 400 and another list for SN2 404. In an example embodiment, MN 200 may also provide a configuration for UE 300 to wait for approval of the SN node key or SN counters before use. In other words, the effect of the configuration is that when the SCPAC conditions are met, UE 300 will send the extracted sk counters to MN 200 and wait for MN 200's approval before accessing the candidate SN. In an example embodiment, the configuration can be sent to UE 300 in the RRC reconfiguration message. In another example embodiment, instead of explicitly indicating the configuration to UE 300, UE 300 may have to implement default behavior (without explicit configuration from MN 200), i.e., indicating to MN 200 the sk counters to be used and waiting for approval from MN 200 before accessing the candidate SN.

[0132] At 416, the UE decodes the RRC reconfiguration message received from MN 200 and sends an RRC reconfiguration complete message to MN 200 to approve the reception of the configuration.

[0133] At point 418, when the SCPAC conditions for the PSCell under SN2 402 are met, the UE performs SCPAC on the PSCell. Since the PSCell handover is an inter-SN handover from SN1 400 to SN2 402, the UE 300 needs to use a new key, which is different from the key used with SN1 400. Therefore, the UE 300 extracts the sk counters from the sk counter list of SN2 402 and generates the SN2 key.

[0134] At 420, UE 300 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute. UE 300 also includes the sk counter or SN key that UE 300 will use to access SN2 402.

[0135] At 446, UE 300 can initiate the Random Access Channel (RACH) procedure immediately after step 420, instead of waiting for approval of the SN key or sk counter from MN 200.

[0136] Simultaneously, after UE 300 sends an RRC reconfiguration complete message at 420, at 448, MN 200 determines whether the generated SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. In this example embodiment, the generated SN key or sk counter received from UE 300 does not match the SN key or sk counter that MN 200 expects UE 300 to use, and MN 200 refuses to use the sk counter or SN key received from UE 300.

[0137] At 450, MN 200 sends a message to UE 300 that includes disapproval of the SN key or sk counter. In the example embodiment, this message may also include the index of the correct sk counter to be used by UE 300 to retrieve a new sk counter.

[0138] At position 452, UE 300 adjusts the counter index to obtain a new sk counter and generates a new SN key. In the example embodiment, UE 300 can use the new sk counter index to extract the correct sk counter and may also generate a new SN key.

[0139] At position 454, UE 300 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute. UE 300 also includes a new sk counter or a new SN key that UE 300 will use to access SN2 402.

[0140] At 456, MN 200 determines that the new SN key or new sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use, and sends approval for the sk counter or SN key to be used at 458, and authorizes access to SN2 402 at 442.

[0141] At 460, MN 200 uses an SN reconfiguration complete message to notify SN2 404 of the SCPAC execution. In the example embodiment, MN 200 may share the SN key that UE 300 expects to use for accessing SN2 402 in this message.

[0142] At 462, UE 300 can initiate a random access channel (RACH) procedure to SN2 402 and use the generated SN2 key to access SN2 402.

[0143] Figure 4D A signaling diagram according to an example embodiment is shown.

[0144] At 404, UE 300 is in dual connectivity (DC) with master node (MN) 200 and service node 1 (SN1) 400.

[0145] At positions 406 and 408, MN 200 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 400 and SN2 402. MN 200 can share the SN key or list of SN keys that UE 300 will use to access SN1 400 and SN2 402.

[0146] At locations 410 and 412, both SN1 400 and SN2 402 can be prepared to respond to MN 200 using SCPAC.

[0147] At 414, MN 200 provides candidate SCPAC configurations for SN1 400 and SN2 402 in the RRC reconfiguration message. MN 200 also provides a list of sk counters for each SN, i.e., one list for SN1 400 and another list for SN2 404. In an example embodiment, MN 200 may also provide a configuration for UE 300 to wait for approval of the SN node key or SN counters before use. In other words, the effect of the configuration is that when the SCPAC conditions are met, UE 300 will send the extracted sk counters to MN 200 and wait for MN 200's approval before accessing the candidate SN. In an example embodiment, the configuration can be sent to UE 300 in the RRC reconfiguration message. In another example embodiment, instead of explicitly indicating the configuration to UE 300, UE 300 may have to implement default behavior (without explicit configuration from MN 200), i.e., indicating to MN 200 the sk counters to be used and waiting for approval from MN 200 before accessing the candidate SN.

[0148] At 416, the UE decodes the RRC reconfiguration message received from MN 200 and sends an RRC reconfiguration complete message to MN 200 to approve the reception of the configuration.

[0149] At point 418, when the SCPAC conditions for the PSCell under SN2 402 are met, the UE performs SCPAC on the PSCell. Since the PSCell handover is an inter-SN handover from SN1 400 to SN2 402, the UE 300 needs to use a new key, which is different from the key used with SN1 400. Therefore, the UE 300 extracts the sk counters from the sk counter list of SN2 402 and generates the SN2 key.

[0150] At 420, UE 300 decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute. UE 300 also includes the sk counter or SN key that UE 300 will use to access SN2 402.

[0151] At 446, UE 300 can initiate the Random Access Channel (RACH) procedure immediately after step 420, instead of waiting for approval of the SN key or sk counter from MN 200.

[0152] Simultaneously, after UE 300 sends an RRC reconfiguration complete message at 420, at 464, MN 200 determines whether the generated SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. In this example embodiment, the generated SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use, and MN 200 approves the use of the sk counter or SN key received from UE 300.

[0153] At 466, MN 200 can send approval for the sk counter or SN key to be used and authorize access to SN2402. This information may be redundant for UE 300 if UE 300 has started or completed the RACH procedure, and therefore can optionally be sent by MN 200. Alternatively, at 466, MN 200 can send the determined sk counter or the determined SN key to be used by UE 300 and authorize access to SN2402.

[0154] At 468, MN 200 can use an SN reconfiguration complete message to notify SN2 404 of the SCPAC execution. In an example embodiment, MN 200 may share in this message the SN key (or sk counter) that UE 300 expects to use for accessing SN2 402, or a determined SN key (or sk counter). The determined sk counter or the determined SN key may be, for example, newly determined, newly generated, expected (in the case of a mismatch between the received and expected values), etc.

[0155] The benefit of the solution disclosed above is that, if the UE selects the correct sk counter, the UE does not have to wait for the MN's approval and can continue to access the candidate SN.

[0156] Figure 4E A signaling diagram according to an example embodiment is shown.

[0157] At 404, UE 300 is in dual connectivity (DC) with master node (MN) 200 and service node 1 (SN1) 400.

[0158] At positions 406 and 408, MN 200 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 400 and SN2 402. MN 200 can share the SN key or list of SN keys that UE 300 will use to access SN1 400 and SN2 402.

[0159] At locations 410 and 412, both SN1 400 and SN2 402 can be prepared to respond to MN 200 using SCPAC.

[0160] At 414, MN 200 provides candidate SCPAC configurations for SN1 400 and SN2 402 in the RRC reconfiguration message. MN 200 also provides a list of sk counters for each SN, i.e., one list for SN1 400 and another list for SN2 404. In an example embodiment, MN 200 may also provide a configuration for UE 300 to wait for approval of the SN node key or SN counters before use. In other words, the effect of the configuration is that when the SCPAC conditions are met, UE 300 will send the extracted sk counters to MN 200 and wait for MN 200's approval before accessing the candidate SN. In an example embodiment, the configuration can be sent to UE 300 in the RRC reconfiguration message. In another example embodiment, instead of explicitly indicating the configuration to UE 300, UE 300 may have to implement default behavior (without explicit configuration from MN 200), i.e., indicating to MN 200 the sk counters to be used and waiting for approval from MN 200 before accessing the candidate SN.

[0161] At 416, the UE decodes the RRC reconfiguration message received from MN 200 and sends an RRC reconfiguration complete message to MN 200 to approve the reception of the configuration.

[0162] At point 418, when the SCPAC conditions for the PSCell under SN2 402 are met, the UE performs SCPAC on the PSCell. Since the PSCell handover is an inter-SN handover from SN1 400 to SN2 402, the UE 300 needs to use a new key, which is different from the key used with SN1 400. Therefore, the UE 300 extracts the sk counters from the sk counter list of SN2 402 and generates the SN2 key.

[0163] At 470, UE 300 sends the SN key or sk counter and the selected candidate SCPAC configuration to MN 200 before decoding the candidate SCPAC configuration, and thus shares such information with MN 200 before sending the RRC reconfiguration complete message.

[0164] At 472, MN 200 determines whether the SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. If the sk counter or SN key matches the sk counter or SN key that MN 200 expects UE 300 to use, at 474, MN 200 sends approval for the sk counter or SN key to be used and authorizes access to SN2 402.

[0165] At 476, the UE decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute.

[0166] At position 478, MN 200 uses an SN reconfiguration complete message to notify SN2 404 of SCPAC execution. In the example embodiment, MN 200 may share the SN key that UE 300 expects to use for accessing SN2 402 in this message.

[0167] At 480, UE 300 can initiate a Random Access Channel (RACH) procedure to SN2 402 and use the generated SN2 key to access SN2 402.

[0168] Figure 4F A signaling diagram according to an example embodiment is shown.

[0169] At 404, UE 300 is in dual connectivity (DC) with master node (MN) 200 and service node 1 (SN1) 400.

[0170] At positions 406 and 408, MN 200 can initiate preparation for subsequent conditional PSCell add / change (SCPAC) with SN1 400 and SN2 402. MN 200 can share the SN key or list of SN keys that UE 300 will use to access SN1 400 and SN2 402.

[0171] At locations 410 and 412, both SN1 400 and SN2 402 can be prepared to respond to MN 200 using SCPAC.

[0172] At 414, MN 200 provides candidate SCPAC configurations for SN1 400 and SN2 402 in the RRC reconfiguration message. MN 200 also provides a list of sk counters for each SN, i.e., one list for SN1 400 and another list for SN2 404. In an example embodiment, MN 200 may also provide a configuration for UE 300 to wait for approval of the SN node key or SN counters before use. In other words, the effect of the configuration is that when the SCPAC conditions are met, UE 300 will send the extracted sk counters to MN 200 and wait for MN 200's approval before accessing the candidate SN. In an example embodiment, the configuration can be sent to UE 300 in the RRC reconfiguration message. In another example embodiment, instead of explicitly indicating the configuration to UE 300, UE 300 may have to implement default behavior (without explicit configuration from MN 200), i.e., indicating to MN 200 the sk counters to be used and waiting for approval from MN 200 before accessing the candidate SN.

[0173] At 416, the UE decodes the RRC reconfiguration message received from MN 200 and sends an RRC reconfiguration complete message to MN 200 to approve the reception of the configuration.

[0174] At point 418, when the SCPAC conditions for the PSCell under SN2 402 are met, the UE performs SCPAC on the PSCell. Since the PSCell handover is an inter-SN handover from SN1 400 to SN2 402, the UE 300 needs to use a new key, which is different from the key used with SN1 400. Therefore, the UE 300 extracts the sk counters from the sk counter list of SN2 402 and generates the SN2 key.

[0175] At 470, UE 300 sends the SN key or sk counter and the selected candidate SCPAC configuration to MN 200 before decoding the candidate SCPAC configuration, and thus shares such information with MN 200 before sending the RRC reconfiguration complete message.

[0176] At 482, MN 200 determines whether the generated SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. In this example embodiment, the generated SN key or sk counter received from UE 300 does not match the SN key or sk counter that MN 200 expects UE 300 to use, and MN 200 refuses to use the sk counter or SN key received from UE 300.

[0177] At position 484, MN 200 sends a message to UE 300 that includes disapproval of the SN key or sk counter. In the example embodiment, this message may also include the index of the correct sk counter to be used by UE 300 to retrieve a new sk counter.

[0178] At position 486, UE 300 adjusts the counter index to obtain a new sk counter and generates a new SN key. In the example embodiment, UE 300 can use the new sk counter index to retrieve the correct sk counter and may also generate a new SN key.

[0179] At 488, UE 300 sends the SN key or sk counter and the selected candidate SCPAC configuration to MN 200 before decoding the candidate SCPAC configuration, and thus shares such information with MN 200 before sending the RRC reconfiguration complete message.

[0180] At 490, MN 200 determines whether the SN key or sk counter received from UE 300 matches the SN key or sk counter that MN 200 expects UE 300 to use. If the sk counter or SN key matches the sk counter or SN key that MN 200 expects UE 300 to use, at 492, MN 200 sends approval for the sk counter or SN key to be used and authorizes access to SN2 402.

[0181] At 494, the UE decodes the candidate SCPAC configuration and sends an RRC reconfiguration complete message to MN 200 to indicate which candidate configuration to execute.

[0182] At position 496, MN 200 uses an SN reconfiguration complete message to notify SN2 404 of the SCPAC execution. In the example embodiment, MN 200 may share the SN key that UE 300 expects to use for accessing SN2 402 in this message.

[0183] At 498, UE 300 can initiate a Random Access Channel (RACH) procedure to SN2 402 and use the generated SN2 key to access SN2 402. In another example embodiment, UE 300 can alternatively initiate RACH-free access to SN 402, for example, if UE 300 has previously initiated an advance timing advance or other procedure, or based on information that RACH procedure is not required to access SN 402.

[0184] Figure 5 An example of a method according to an exemplary embodiment is shown. This method can be performed by a network node configured to support dual connections from a user equipment to a network node and to a first secondary network node.

[0185] At 500, the method may include: receiving a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node.

[0186] At 502, the method may include: determining whether the generated second auxiliary network node key or auxiliary network node counter matches the second auxiliary network node key or second auxiliary network node counter that the network node expects the user equipment to use.

[0187] At 504, the method may include: based on the determination, sending a second message to the user equipment including an indication associated with a match.

[0188] Figure 6 An example of a method according to another exemplary embodiment is shown. This method can be performed by a user equipment configured to operate in a dual-connectivity mode with a network node and a secondary network node, the user equipment being served by a first secondary network node.

[0189] At 600, the method may include: sending a first message to a network node, the first message including a generated second auxiliary network node key or a second auxiliary network node counter associated with a second auxiliary network node.

[0190] At 602, the method may include: receiving a second message from a network node, the second message including an indication of whether a generated second secondary network node key or secondary network node counter matches a second secondary network node key or second secondary network node counter that the network node expects the user equipment to use.

[0191] Further features of the method arise directly from the functionality of the network node or user equipment, as described throughout the specification, claims, and drawings, and therefore will not be repeated here. An apparatus may be configured to perform or cause performance of any aspect of the method described herein. Furthermore, a computer program or computer program product may include instructions for causing the apparatus to perform any aspect of the method described herein when executed by the apparatus. Additionally, an apparatus may include components for performing any aspect of the method described herein. According to an example embodiment, the components include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform at least any aspect of the method.

[0192] The ranges or device values ​​given herein may be extended or modified without losing the desired effect. Furthermore, any embodiment may be combined with another embodiment unless expressly permitted.

[0193] Although the subject matter has been described in language specific to structural features and / or actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as examples of implementing the claims, and other equivalent features and actions are intended to fall within the scope of the claims.

[0194] It should be understood that the above benefits and advantages may relate to one embodiment or several embodiments. Embodiments are not limited to embodiments that solve any or all of the described problems or that have any or all of the described benefits and advantages. It will also be understood that references to "a" may refer to one or more of those items.

[0195] The steps or operations of the methods described herein can be performed in any suitable order, or simultaneously where appropriate. Furthermore, individual boxes can be removed from any method without departing from the scope of the subject matter described herein. Aspects of any of the example embodiments described above can be combined with aspects of any other example embodiments described to form further example embodiments without losing the desired effect.

[0196] The term “comprising” is used herein to mean including the identified method, frame, or element, but such frame or element does not include an exclusive list, and the method or apparatus may include additional frames or elements.

[0197] As used herein, “at least one of the following: a list of two or more elements” and “at least one of the following: a list of two or more elements” and similar wording (where the list of two or more elements is connected by “and” or “or”) means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0198] Although a topic may be referred to as "first" or "second" topic, this does not necessarily indicate any order or importance of the topics. Rather, such an attribute can be used simply for the purpose of distinguishing between topics.

[0199] As used herein, the term "circuit" may refer to one or more or all of the following: (a) implemented solely by hardware circuitry (e.g., implemented with purely analog and / or digital circuitry); and (b) a combination of hardware circuitry and software, such as (if applicable): (i) a combination of analog and / or digital hardware circuitry and software / firmware; and (ii) any part of a hardware processor having software (including (multiple) digital signal processors, software, and (multiple) memories that work together to enable a device such as a mobile phone or server to perform various functions); and (c) (multiple) hardware circuitry and / or (multiple) processors that require software (e.g., firmware) for operation, such as being part of (multiple) microprocessors, but where the software may be absent when operation does not require it. This definition of circuitry applies to all uses of the term herein (including in any claim).

[0200] As another example, as used in this application, the term "circuit" also covers only hardware circuitry or processors (or processors), or a portion of hardware circuitry or processors and their accompanying software and / or firmware. For example, where applicable to certain claim elements, the term "circuit" also covers baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices or other computing or network devices.

[0201] It should be understood that the above description is given by way of example only, and various modifications can be made by those skilled in the art. The above specification, examples, and data provide a complete description of the structure and use of exemplary embodiments. Although various embodiments have been described above with a degree of specificity or by reference to one or more individual embodiments, many changes can be made to the disclosed embodiments by those skilled in the art without departing from the scope of this specification.

Claims

1. A network node supporting dual connectivity from a user equipment to the network node and to a secondary network node, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the network node to at least: Receive a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; Determine whether the generated second secondary network node key or the secondary network node counter matches the second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use; and Based on the determination, a second message including an indication associated with the match is sent to the user equipment.

2. The network node of claim 1, wherein the indication includes the second auxiliary network node key or the second auxiliary network node counter generated for the approval of the user equipment.

3. The network node of claim 1, wherein the indication includes disapproval of the generated second auxiliary network node key or the second auxiliary network node counter for the user equipment and an index of the correct counter.

4. The network node of claim 3, wherein the second message includes an index of the correct counter to be used by the user equipment.

5. The network node according to claim 3 or 4, wherein the instructions, when executed by the at least one processor, cause the network node to at least: Receive a third message from the user equipment, the third message including a regenerated second auxiliary network node key or a newly used second auxiliary network node counter associated with the second auxiliary network node; Determine that the regenerated second secondary network node key or the newly used second secondary network node counter matches the second secondary network node key or second secondary network node counter that the network node expects the user equipment to use; and Based on the determination, a fourth message is sent to the user equipment, the fourth message including approval of the regenerated second auxiliary network node key or the newly used second auxiliary network node counter.

6. The network node according to any one of claims 1 to 5, wherein the instructions, when executed by the at least one processor, cause the network node to at least: Before receiving the first message, a fifth message is sent to the user equipment, the fifth message including a configuration for the user equipment to wait for approval of the second secondary network node key or the second secondary network node counter before use.

7. The network node according to any one of claims 1 to 6, wherein the first message includes a Radio Resource Control (RRC) reconfiguration completion message.

8. A user equipment configured to operate in a dual-connectivity mode with a network node and a secondary network node, the user equipment being served by a first secondary network node, the user equipment comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to at least: Send a first message to the network node, the first message including a generated second auxiliary network node key or a second auxiliary network node counter associated with the second auxiliary network node; as well as A second message is received from the network node, the second message including an indication of whether the generated second auxiliary network node key or the auxiliary network node counter matches the second auxiliary network node key or the second auxiliary network node counter that the network node expects the user equipment to use.

9. The user equipment of claim 8, wherein the instruction includes approving the generated second secondary network node key or the second secondary network node counter for the user equipment, and wherein the instruction, when executed by the at least one processor, causes the user equipment to at least: In response to the approval, a random access procedure is initiated to the second auxiliary network node.

10. The user equipment of claim 8, wherein the instruction includes an index to the generated second secondary network node key or the second secondary network node counter and a correct counter, and wherein the instruction, when executed by the at least one processor, causes the user equipment to at least: Adjust the counter index; A third message is sent to the network node, the third message including a regenerated second auxiliary network node key or a newly used second auxiliary network node counter associated with the adjusted counter index and associated with the second auxiliary network node; Receive a fourth message from the network node, the fourth message including approval of the regenerated second auxiliary network node key or the newly used second auxiliary network node counter for the user equipment; and In response to the approval, a random access procedure is initiated to the second auxiliary network node.

11. The user equipment of claim 9 or 10, wherein the second message includes an index to a correct counter to be used by the user equipment, and wherein the instruction, when executed by the at least one processor, causes the user equipment to at least: The counter index is adjusted based on the index received from the network node.

12. The user equipment according to any one of claims 8 to 11, wherein the instructions, when executed by the at least one processor, cause the user equipment to at least: Before sending the first message, a fifth message is received from the network node, the fifth message including a configuration for the user equipment to wait for approval of the second auxiliary network node key or the second auxiliary network node counter before use.

13. The user equipment of claim 8, wherein the instructions, when executed by the at least one processor, cause the user equipment to at least: After sending the first message to the network node, a random access procedure is immediately initiated to the second auxiliary network node.

14. The user equipment according to any one of claims 8 to 13, wherein the first message includes a Radio Resource Control (RRC) reconfiguration completion message.

15. A method performed by a network node, the network node supporting dual connectivity from a user equipment to the network node and to a secondary network node, the method comprising: Receive a first message from a user equipment served by a first secondary network node, the first message including a generated second secondary network node key or a second secondary network node counter associated with a second secondary network node; Determine whether the generated second secondary network node key or the secondary network node counter matches the second secondary network node key or the second secondary network node counter that the network node expects the user equipment to use; and Based on the determination, a second message including an indication associated with the match is sent to the user equipment.

16. A method performed by a user equipment, the user equipment being configured to operate in a dual-connectivity mode with a network node and a secondary network node, the user equipment being served by a first secondary network node, the method comprising: Send a first message to the network node, the first message including a generated second auxiliary network node key or a second auxiliary network node counter associated with the second auxiliary network node; as well as A second message is received from the network node, the second message including an indication of whether the generated second auxiliary network node key or the auxiliary network node counter matches the second auxiliary network node key or the second auxiliary network node counter that the network node expects the user equipment to use.

17. A computer program comprising instructions for causing a device to perform the method of any one of claims 15 to 16.