A ue-specific dynamic resource pool construction and mobility management method and system based on a dynamic security root

By constructing a UE-specific dynamic resource pool based on dynamic security, the problems of interruption and signaling overhead caused by handover in wireless communication are solved. This enables seamless movement with zero signaling and dynamic adjustment of the resource pool, adapting to the extreme requirements of future 6G networks and improving spectrum efficiency and resource utilization.

CN122120922APending Publication Date: 2026-05-29SHANGHAI HUAPAITE TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI HUAPAITE TECHNOLOGY CO LTD
Filing Date
2026-03-16
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies have failed to effectively address the interruption and signaling overhead issues caused by handover in wireless communication. Especially in non-terrestrial network scenarios where satellites move at high speeds, the interruption time of traditional handover procedures is too long, which cannot meet the extreme requirements of future 6G networks. Furthermore, they do not fully utilize the dual-radio capability of the UE and do not systematically consider the resource management and mobility processing of idle-state UEs.

Method used

The method of constructing a UE-specific dynamic resource pool based on Dynamic Security Foundation (DSF) is adopted. By establishing a dedicated dynamic resource pool for each UE, the logical resources and physical resources are decoupled. Combined with the separation architecture of LPC and PAN, the independent evolution of PSSM and L-PSSM is utilized. Technologies such as sticky scheduling, pre-conversion and overlay map are adopted to achieve zero signaling and seamless mobility, and the resource pool size is dynamically adjusted according to the service type.

Benefits of technology

It enables seamless UE movement with no handover and zero signaling, reduces communication interruption time, improves spectrum efficiency and resource utilization, adapts to the needs of different service types and networking scenarios, supports the optimization of single/dual radio frequency capabilities, and reduces network deployment and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

A UE-specific dynamic resource pool construction and mobility management method and system based on dynamic security root. The network side establishes a specific dynamic resource pool for each UE, and the UE and the network side run PSSM based on the DSF, and independently calculate the pool index R_pool at the logical decision moment. The LPC maintains a dynamic mapping table, which maps R_pool to the physical resources of PAN. According to the networking same frequency / different frequency, UE single / dual radio frequency capability and business demand, differential mobility management is adopted: under the same frequency, only the mapping table is updated to realize the no-sense migration; when the frequency is different, the single radio frequency UE needs signaling migration, and the dual radio frequency UE can realize zero interruption and no-sense migration. In the idle state, two kinds of mapping table types are used to support accurate tracking and fuzzy tracking, realize signal level paging and implicit location update. The resource pool size is dynamically adjusted, and two-step arbitration is used to realize centralized interference coordination. The application realizes the complete decoupling of the UE and the physical network, eliminates the switching signaling, greatly reduces the location update overhead, and is suitable for ground and non-ground networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of wireless communication technology, specifically relating to network architecture, resource management, and mobility management in fifth-generation (5G) and sixth-generation (6G) mobile communication systems. In particular, it is a communication method and system that takes user equipment (UE) as the center, constructs a UE-specific dynamic resource pool based on Dynamic Security Foundation (DSF), realizes handover-free, zero-signaling, and seamless UE movement, and optimizes for co-frequency / different-frequency networking, single / dual radio frequency capabilities, service types, and connected / idle states. Background Technology

[0002] Since the birth of the first generation of mobile communication systems, wireless networks have always followed a cell-centric architecture. Each generation of technological evolution has involved optimization and refinement within this cell framework. However, this paradigm, which has persisted for sixty years, is facing fundamental challenges: the interruptions and signaling overhead caused by handover cannot meet the extreme requirements of future 6G networks, resulting in complex network topologies and high deployment and maintenance costs. Particularly in non-terrestrial network (NTN) scenarios, the high-speed movement of low-Earth orbit satellites leads to frequent base station handovers, further exacerbating these problems. Analysis in 3GPP TR 38.821 shows that in satellite communication scenarios, the interruption time of traditional handover procedures can reach 810–1080 ms, which is completely unacceptable for real-time services.

[0003] The applicant has previously filed a series of patents based on Dynamic Security Foundation (DSF), constructing a complete DSF technology system from the physical layer to the protocol layer. Among them, the two core patent applications, "A Communication Method and System for UE-Dedicated Dynamic Resource Pool Based on Dynamic Security Foundation" and "A Communication Method and System for UE-Dedicated Dynamic Resource Pool for Non-Terrestrial Networks," innovatively proposed an architecture centered on the UE and separating the LPC (Logical Processing Center) and PAN (Physical Access Node). By establishing a dedicated dynamic resource pool for each UE, the decoupling of logical resources and physical resources is achieved, initially solving the problems of handover interruption and signaling overhead.

[0004] However, the above solutions still have room for improvement: First, they do not systematically consider resource management and mobility handling for idle-state UEs; second, they do not clearly distinguish the different behaviors of UEs under co-frequency / hetero-frequency networking, especially the physical layer overhead issues of single-radio UEs moving between frequencies; third, they do not fully utilize the dual-radio capability of UEs to enhance performance; fourth, they do not explicitly explain the inherent interference coordination (ICIC) advantages of this architecture; and fifth, they do not dynamically adjust the resource pool size according to service type. Therefore, a unified and systematic approach is urgently needed to integrate resource management in connected and idle states, co-frequency / hetero-frequency networking adaptation, utilization of single / dual-radio capability, and service-driven dynamic resource adjustment into a complete UE-specific dynamic resource pool technical solution. Summary of the Invention

[0005] I. Definition of Core Concepts To facilitate understanding of this invention, the following core concepts are first defined. These definitions constitute the technical basis of this invention, and any person skilled in the art can understand and implement this invention after reading them.

[0006] Concept 1: Dynamic Security Foundation (DSF) DSF is a cryptographically secure triple `(K_sec, Init_Anchor, Rule_ID)` shared by both communicating parties, used for the generation of all deterministic parameters and state synchronization. Wherein: - `K_sec` is a shared key, at least 128 bits in length, which can be established through secure negotiation during the initial access process.

[0007] - `Init_Anchor` defines the starting point of the logical time axis, which can be an absolute time value (such as UTC time) or a relative logical time number, and includes the initial logical state `S(0)`.

[0008] - `Rule_ID` identifies the evolution rules of the protocol security state machine, including the logical tick length `T_step`, state update function, hash algorithm type, etc.

[0009] Concept 2: Protocol Security State Machine (PSSM) The PSSM is a deterministic state machine based on the DSF (Digital Sequence Flow). It evolves independently between the communicating parties, outputting a time-varying logic state `S(t)`, where `t` is the number of logical steps elapsed since startup (`t = 0, 1, 2, ...`). The evolution of the PSSM is independent of the physical clock and is driven solely by the logical steps defined by `Rule_ID`. After each logical step `T_step`, the state machine evolves to the next state according to the predefined update function `S(t+1) = Update(S(t), K_sec)`. As long as the communicating parties share the same DSF, their PSSMs remain synchronized on the logical timeline.

[0010] Concept 3: Paging PSSM (P-PSSM) and Location PSSM (L-PSSM) To differentiate between paging and location update functions, this invention defines two PSSM instances, which can be distinguished based on the same DSF triples but using different context parameters, or they can be configured with independent evolution rules: - P-PSSM: Used for generating downlink paging-related parameters, including the sequence of paging messages (which can be pure pilots, pilots with modulated data, pilots plus content fusion modes, etc.), paging monitoring resource indexes, etc. Its state is denoted as `S_p(t)`.

[0011] - L-PSSM: Used for generating uplink position update related parameters, including position update pilot sequences, transmission resource indexes, etc. Its state is denoted as `S_l(t)`.

[0012] P-PSSM and L-PSSM can be configured independently for logic clock length. For example, the paging clock can be set to align with the DRX cycle, and the position update clock can be set to a longer cycle to save power.

[0013] Concept 4: The Moment of Logical Decision-Making Discrete moments on the logical timeline defined by `Rule_ID` correspond to specific logical time indices `t`. At each logical decision moment, the PSSM outputs the current state `S(t)` and triggers physical layer operations. Regardless of whether data or control signaling needs to be sent, logical decision moments arrive periodically at predefined ticks `T_step`.

[0014] Concept 5: Unified Anchor Time (T_anchor) At the logical decision moment, the node instantaneously reads the value obtained from its local physical clock, denoted as `T_anchor`. This operation uniquely and instantaneously binds the abstract logical moment to a specific physical time point, providing a unified physical time reference for all subsequent physical layer operations based on this logical moment. While the local physical clock may have errors, these errors are isolated within a single transmission and will not affect the synchronization of the logical state.

[0015] Concept 6: Fixed Offsets `Δ_dl` and `Δ_ul` are pre-configured fixed time offsets used to calculate the downlink listening / transmission time and uplink transmission time from the unified anchor time `T_anchor`, respectively. The value of the fixed offset should be at least greater than the sum of the maximum propagation delay and the UE processing time to ensure that the expected arrival times of the downlink signal at the UE side and the uplink signal at the network side fall within the correct reception window. Typical value range: - `Δ_dl`: 0.1ms ~ 1ms (depending on propagation latency and UE processing capability) - `Δ_ul`: `Δ_dl + 0.5ms ~ 2ms` (adjusting the timing in advance) Fixed offsets can be pre-configured via system broadcast, RRC signaling, or DSF parameter generation, and can be updated on the network side.

[0016] Concept 7: Downlink listening time `T_DL` and uplink transmission time `T_UL` At the logical decision-making moment, the UE and the network side each read their local physical clocks to obtain a unified anchor time `T_anchor`, and then calculate based on a pre-configured fixed offset: - Downlink listening / transmission timing: `T_DL = T_anchor + Δ_dl` - Uplink transmission time: `T_UL = T_anchor + Δ_ul` The UE listens for downlink signals in `T_DL` and transmits uplink signals in `T_UL`; the network transmits downlink signals in `T_DL` and receives uplink signals in `T_UL`. Since both sides are based on the same `T_anchor` and offset, the calculated physical time is consistent within the error range.

[0017] Concept 8: Logic Processing Center (LPC) and Physical Access Node (PAN) The LPC is centrally deployed at ground stations or the core network, responsible for centralized processing functions such as logical resource management, mapping table maintenance, and arbitration. The PAN is deployed on satellites, base stations, or UAVs, responsible for physical layer transmission and reception, measurement reporting, etc. The LPC and PAN are connected through a high-precision synchronous fronthaul network, supporting IEEE 1588v2 or GNSS time synchronization to ensure microsecond-level time synchronization.

[0018] Concept 9: UE-specific dynamic resource pool A logical resource space of size `M_pool` is established for each UE, containing logical resource indices from 0 to `M_pool-1`. The UE calculates the in-pool index based on the PSSM state. `R_pool = F(K_sec, S(t), Context) mod M_pool` Where `F` is a cryptographic deterministic function, such as HMAC-SHA256, AES-CMAC, etc.; `Context` is context information used to distinguish different purposes, and may include service flow identifiers (such as LCID), UE temporary identities (such as TMSI), purpose identifiers (such as "DATA", "PAGING", "LOCATION", "HO"), etc. The network side maps the index to physical resources through a mapping table.

[0019] Concept 10: Mapping Table The data structure maintained by LPC uses `(UE_ID, R_pool)` as the key to map the logical resource index calculated by the UE to physical resource descriptors. The physical resource descriptor contains at least: `(PAN_ID, frequency point, baseband parameters, time-frequency resource coordinates)`. The mapping table supports two types: - First mapping table type (one-to-one): Each logical resource index maps to a physical resource of a single PAN, and different indices can map to physical resources of different PANs. Suitable for scenarios requiring precise UE positioning, as well as connected communication.

[0020] - Second mapping table type (one-to-many): Each logical resource index maps to the physical resources of multiple PANs simultaneously, with each PAN corresponding to a physical resource descriptor. Suitable for scenarios requiring multi-PAN collaboration, such as idle-state fuzzy tracking, dual-radio diversity reception, or load balancing.

[0021] When using the second mapping table type, the value of `M_pool` is limited to the minimum number of physical resources available to the UE in all PANs involved in the mapping, to ensure that each `R_pool` has a corresponding physical resource on each PAN.

[0022] Concept 11: Sticky Scheduling LPC, by configuring a first-type mapping table, ensures that different logical resource indices calculated by the UE at multiple consecutive logical decision moments are mapped to the same PAN's physical resources, thereby achieving long-term stability of the UE serving the PAN. This mechanism is particularly suitable for single-radio UEs in inter-frequency networking scenarios, avoiding physical layer overhead caused by frequency migration due to logical index changes. For intra-frequency networking, even if the UE uses resources across different PANs (due to logical index changes), since the frequency is the same, the UE does not need radio frequency tuning, so sticky scheduling is not necessary, but can be used as an auxiliary means of load balancing or interference management. The sticky scheduling process is completely transparent to the UE.

[0023] Concept 12: Pre-Conversion When the target PAN and the current PAN share the same frequency but have different baseband parameters, the network side uses a pre-conversion technique: the downlink signal is first generated based on the UE's reference parameters (e.g., a subcarrier spacing of 15kHz), and then converted into a form conforming to the actual parameters of the target PAN (e.g., a subcarrier spacing of 60kHz) through resampling, frequency domain mapping, etc., before transmission. When the UE receives the signal, the pre-converted signal conforms to the reference parameters and can be directly demodulated by the reference receiver. The pre-conversion parameters are calculated by LPC and configured for the target PAN.

[0024] Concept 13: Coverage Map The data structure, maintained by the network side and optionally sent to the UE, includes geographical coverage information of the surrounding PANs and corresponding physical layer parameters. The coverage map can be constructed based on satellite ephemeris, beam pointing, base station locations, etc. Example format: ``` PAN_ID: PAN_A, Frequency: f1, Baseband parameters: {SCS=15kHz, CP=normal}, Coverage area: {Center coordinates (lat_a, lon_a), Radius 50km} PAN_ID: PAN_B, Frequency: f2, Baseband parameters: {SCS=30kHz, CP=normal}, Coverage area: {Center coordinates (lat_b, lon_b), Radius 60km} ``` Overlay maps are used by UEs to autonomously predict migration timing.

[0025] Concept 14: Idle State Key Derivation When the UE transitions from connected state to idle state, a private key `K_sec_idle` is derived from the existing security context and used for all cryptographic operations in the idle state. Example of the derivation formula: `K_sec_idle = KDF(K_gNB, "IDLE_DSF" || UE_ID)` KDF stands for Key Derivation Function (e.g., HKDF). The derivation process requires no over-the-air signaling, ensuring backward compatibility and security.

[0026] Concept 15: Downlink Monitoring Timing The physical time reserved by the UE for receiving downlink signals includes: - Connection state: The downlink listening time `T_DL` at each logical decision moment is calculated from concept 7.

[0027] - Idle state: One of the following two methods can be used: - Method 1 (based on PSSM logic beat): P-PSSM periodically outputs the logic decision time `t_p` according to its logic beat `T_step_p`. The UE calculates `T_DL` at each `t_p` and wakes up to listen.

[0028] - Method 2 (compatible with traditional PO): The traditional paging occasion (PO) is used, which is defined by the DRX cycle and paging mechanism. The UE wakes up and listens at the PO.

[0029] Concept 16: Two-Step Deterministic Arbitration Because multiple UEs may calculate the same logical resource intention at the same logical decision moment, conflicts may occur on physical resources of the same PAN. To resolve such conflicts, the network side performs a two-step deterministic arbitration at the granularity of a single PAN: - Step 1: User conflict arbitration. From the set of conflicting UEs, a winning UE is deterministically selected according to preset rules (such as priority, polling, service level).

[0030] - Step 2: Resource Availability Check. Check whether the physical resources corresponding to the winning UE are available at the scheduled time (whether they have been occupied by other UEs or service flows).

[0031] The execution order of the two steps is adjustable; arbitration can be performed before inspection, or inspection can be performed before arbitration. The arbitration result is sent to the corresponding PAN via the power supply link in the form of an authorization instruction. The authorization instruction only contains the winning UE identifier or physical resource index and does not contain pilot content.

[0032] Concept 17: UE Radio Frequency Capability This invention distinguishes between two types of UEs: - Single-RF UE: Equipped with only one RF link, it can only transmit and receive on one frequency at a time. In the same-frequency networking scenario, since multiple PANs use the same frequency, the UE can be assigned through the LPC mapping table to communicate with different PANs at different logical times or on different resources, without the UE being aware of it. However, in the inter-frequency networking scenario, the UE must migrate its frequency to communicate with different PANs. The migration process requires RF tuning and synchronization reconstruction, which will generate some interruption overhead.

[0033] - Dual-RF UE: Equipped with two or more RF links, it can transmit and receive simultaneously on different frequency points, thus maintaining connections with multiple PANs at the same time, enabling diversity reception, load sharing, or zero-interruption migration.

[0034] II. Three Architecture Paths This invention supports a smooth evolution from existing networks to future architectures, defining three independently implementable architectural paths. Each path can be deployed independently or in a hybrid network configuration. A comparison of the three architectural paths is provided below. Figure 2 As shown.

[0035] Path A: Traditional base station architecture + broadcast timing-based cryptographic paging - Use existing 5G base stations (gNB) without introducing LPC and PSSM.

[0036] - The UE establishes a shared key `K_sec` with the core network during initial attachment and retains it after entering the idle state.

[0037] - Paging messages are generated based on broadcast timing (such as SFN, time slot number) and can use pure pilot, pilot with modulated data, or pilot plus content fusion mode. For example: `P_paging = HMAC-SHA256(K_sec, (SFN||Slot) ||UE_ID)`.

[0038] - The paging timing follows the traditional PF / PO. The gNB sends the paging message on the PO, and the UE wakes up on the PO and performs a matched filter detection.

[0039] Location updates still go through the traditional TAU process.

[0040] - This approach achieves signal-level paging with minimal modifications, reducing UE power consumption.

[0041] Path B: Enhanced base station architecture + PSSM (without LPC) - The base station introduces PSSM functionality, but not LPC. The base station maintains copies of P-PSSM and L-PSSM for each UE.

[0042] - The base station maintains a logical resource pool and mapping table (Type 1) and performs two-step arbitration.

[0043] - The UE sends location update pilots according to rules based on L-PSSM. The base station receives and calculates the UE's location through wide-window blind detection and updates the local UE context.

[0044] - When paging, the base station generates a paging message based on P-PSSM (which can be a pilot, modulated pilot, or fusion mode) and sends it on the predicted resources.

[0045] - This approach is suitable for scenarios that require implicit position tracking but do not require a centralized LPC.

[0046] Path C: Complete DSF Architecture (LPC+PAN) - It adopts an architecture that separates LPC and PAN, with LPC deployed centrally and PAN deployed in a distributed manner.

[0047] - LPC maintains P-PSSM and L-PSSM copies, a dedicated dynamic resource pool, and a dynamic mapping table for each UE, and the mapping table type can be selected according to the scenario.

[0048] - The UE runs PSSM based on DSF to achieve zero signaling parameter generation.

[0049] - Supports all advanced features such as connected-state sticky scheduling, idle-state A / B strategy, and dual-RF enhancement.

[0050] - This is the target architecture of the present invention, and subsequent embodiments are mainly based on this path.

[0051] III. Connected Mobility Management In connected mode, the UE has active data transmission. This invention achieves seamless UE movement and resource optimization by centrally configuring the mapping table through LPC.

[0052] 3.1 Sticky Scheduling For single-radio UEs, especially in inter-frequency networking scenarios, LPC configures a first-type mapping table to ensure that different logical resource indices calculated by the UE at multiple consecutive logical decision moments are mapped to the same PAN. This allows the UE to remain stably residing on that PAN for a long time, avoiding frequency migration due to changes in logical indices. For example, if the UE's dedicated pool size is 100, LPC can map all indices 0-99 to the physical resources of PAN A. Different indices calculated by the UE consecutively (such as 10, 25, 80) all correspond to PAN A, so the UE's radio frequency is always locked to PAN A without adjustment.

[0053] In a co-frequency network, since multiple PANs use the same frequency, UEs can use the resources of different PANs at different logical times without radio frequency tuning. Therefore, sticky scheduling is not mandatory, but it can be used as an auxiliary means of load balancing or interference management. For dual-radio UEs, sticky scheduling can be enabled or disabled as needed to fully utilize multi-radio capabilities.

[0054] 3.2 Dynamic Updates of Resource Mapping When UE movement or network topology changes (such as satellite overpass or load balancing) cause the current serving PAN to become less optimal, LPC adjusts the physical resources actually used by the UE by updating the mapping table. Based on the network topology and UE capabilities, the mapping update method is divided into the following three categories: Figure 3 As shown: - Type A: Smooth migration at the same frequency Applicable conditions: The target PAN and the current PAN use the same frequency, regardless of whether the baseband parameters are the same.

[0055] LPC adjusts the mapping table gradually or all at once based on UE location, measurement reports, or coverage map predictions, transferring the mapping targets of some or all logical indices from the current PAN to the target PAN. Since the frequency points are the same, the UE requires no RF adjustments, and baseband parameter differences can be resolved through pre-conversion technology. This process is completely transparent to the UE, requires no air interface signaling, and causes no service interruption. LPC can migrate indices in batches as needed, for example, migrating indices used during low-load periods first, and then migrating those used during high-load periods, achieving a smooth transition.

[0056] Type B: Smooth Migration of Dual-Frequency Radio Frequency Applicable conditions: The target PAN has a different frequency than the current PAN, and the UE is a dual-radio device.

[0057] Dual-radio UEs can monitor multiple frequencies simultaneously, so LPC can also achieve smooth migration by updating the mapping table without requiring active adjustment from the UE. The UE's primary radio frequency can continue to operate on its original frequency, while the secondary radio frequency is pre-synchronized with the target PAN. After LPC updates the mapping table, service flows can seamlessly switch to the secondary radio frequency without the UE noticing. This process also requires no air interface signaling.

[0058] - Type C: Different frequency single radio frequency migration Applicable conditions: The target PAN is on a different frequency than the current PAN, and the UE is a single-radio device. This is the only scenario that requires active participation from the UE.

[0059] Since a single-radio UE cannot simultaneously monitor two frequency points, it must be guided to migrate its frequency point via signaling. The LPC sends a migration indication to the UE via downlink signaling, including the target PAN's frequency point, baseband parameters, and migration execution time. The migration indication can be carried in one of the following ways: - Method 1: Dedicated Implicit Pilot A dedicated pilot sequence is generated by the PSSM, with a context identifier distinguishing it from paging pilots or service data, for example, `P_ho = F(K_sec, S(t), "HO" || target_PAN_id)`. During downlink listening, the UE uses multiple locally generated pilot copies for matched filtering detection during `T_DL`, and obtains migration information upon detecting `P_ho`.

[0060] - Method 2: Safety Pilot Frame The migration command is carried as control information in a security pilot frame, which is generated by the PSSM corresponding to the service flow. The frame structure includes a frame type indicator and specific migration parameters. The UE obtains the command after demodulation.

[0061] The migration execution time can be determined through fixed offset, logical time binding, or explicit indication. At the specified time, the UE adjusts its radio frequency to the target frequency, updates its baseband parameters, and continues to calculate the index based on the DSF. At the same time, the LPC updates the mapping table to ensure that subsequent resources point to the target PAN. This process results in extremely short service interruption time (controllable within one logical cycle), far superior to the hundreds of milliseconds of interruption in traditional 5G.

[0062] 3.3 Migration Triggering Conditions The conditions that trigger mapping updates for LPC include, but are not limited to: - The UE measurement report indicates a current degradation in PAN signal quality; - LPC predicts when a UE will leave the current PAN coverage area based on the coverage map and the UE's location; - Network load balancing requirements; - Changes in QoS requirements for UE services.

[0063] 3.4 Dual-RF UE Enhancement Function For dual-radio UEs, in addition to the seamless migration of Type B mentioned above, the following enhanced functions can also be implemented, such as... Figure 6 As shown: - Diversity reception: LPC uses a second mapping table type to map the same logical index to the physical resources of two PANs simultaneously. The two PANs send the same data to the UE at the same time, and the UE receives the data by merging them, which improves reliability.

[0064] - Load balancing: LPC uses the first mapping table type to map the indexes of different service flows to different PANs, and the UE processes them separately on both radios to achieve load balancing.

[0065] - Multi-PAN random scheduling: LPC randomly maps different indices to multiple PANs, and the UE obtains resources from multiple PANs at the same time, maximizing resource utilization.

[0066] IV. Idle Mobility Management In idle state, the UE has no active data transmission, but the network needs to be able to page the UE at any time and optionally track the UE's location to optimize paging.

[0067] 4.1 Idle Resource Pool and Key Derivation When a UE transitions from connected state to idle state, it performs the following operations: 1. Derive the idle key `K_sec_idle` from the current security context, for example, `K_sec_idle =HKDF-Expand(K_gNB, "IDLE_DSF", 256)`.

[0068] 2. A dedicated dynamic resource pool is retained, but LPC can reduce the pool size `M_pool` to a preset idle value (e.g., from 100 to 10) to save resources. The reduced pool size still ensures that each logical index has a corresponding physical resource on each possible PAN.

[0069] 3. The UE continues to run P-PSSM and L-PSSM (if location updates are enabled). P-PSSM and L-PSSM can use `K_sec_idle` as the key, and their logical ticks can be configured independently.

[0070] 4.1.1 Idle-state downlink monitoring timing The downlink listening timing for an idle UE can be achieved using one of the following methods: - Method 1 (Based on PSSM logical beat): The P-PSSM periodically outputs the logical decision time `t_p` according to its logical beat `T_step_p`. At each `t_p`, the UE calculates the downlink listening time `T_DL = T_anchor + Δ_dl` according to Concepts 5 and 6, and wakes up at that time to receive downlink signals. In this method, the listening cycle is completely controlled by the PSSM, decoupled from the traditional DRX / PO, and is the core of achieving zero-signaling paging.

[0071] - Method 2 (Compatible with Traditional PO): To ensure compatibility with existing networks, the listening timing can also follow the traditional paging timing (PO), defined by the DRX cycle and paging mechanism. The UE wakes up at the PO and generates a copy of the paging message based on the P-PSSM for matched filtering detection. This method is applicable to both path A and path B.

[0072] Regardless of the method used, the UE performs the same operation during the listening period: generating a copy of the paging message based on P-PSSM and performing matched filtering detection on the received signal.

[0073] 4.1.2 Format of Paging Messages In this invention, "paging message" is a broader concept and may include the following specific forms: - Pure pilot mode: Only the pilot sequence generated by P-PSSM is sent. The UE determines whether it is being paging by detecting the presence or absence of the pilot.

[0074] - Pilot format for modulated data: A small amount of information (such as a 1-bit paging indication) is modulated onto the pilot sequence. The UE detects the pilot and demodulates the modulated information.

[0075] - Pilot plus content fusion mode: The pure pilot segment and the modulation segment carrying the paging content are multiplexed in the time domain, frequency domain or code domain. The UE first uses the pilot segment to perform channel estimation, and then demodulates the content segment to obtain complete paging information.

[0076] All of the above forms are within the protection scope of this invention, and the specific form used can be configured by the network.

[0077] 4.2 Mapping Table Types and Location Tracking Strategies LPC configures different mapping table types and corresponding location tracking policies for the UE based on the network scenario and UE characteristics, such as Figure 4 As shown: - Strategy A (Precise location tracking, using the first mapping table type) Suitable for UEs that move frequently or require rapid paging (such as smartphones).

[0078] On the UE side: At specific logical moments according to predefined rules (periodic or event-triggered), a location update pilot is generated based on the L-PSSM and transmitted on the currently camped PAN. Location update pilot generation formula: `P_loc = HMAC-SHA256(K_sec_idle, S_l(t) || "LOCATION" || UE_ID)` The sending resources are obtained from `R_pool = F(K_sec_idle, S_l(t), "LOCATION") mod M_pool` via a mapping table.

[0079] On the network side: The LPC runs L-PSSM copies for all UEs and predicts the transmission time. Near the predicted time, the LPC issues a wide-window blind detection command to the candidate PAN set (including the current PAN and its adjacent PANs), requesting blind detection of `P_loc` within the time window `[T_UL - W / 2, T_UL + W / 2]`. The typical value for the wide window length `W` is 2ms~5ms (considering propagation delay variations and clock drift). PANs that successfully detect the pilot report to the LPC, reporting information including the UE_ID and signal measurements (such as RSRP and angle of arrival). The LPC integrates the reported information from multiple PANs to determine the best serving PAN for the UE.

[0080] Context transition: If the new PAN is different from the current PAN, LPC triggers a context transition. 1. The LPC sends the UE's complete PSSM context to the new PAN, including `K_sec_idle`, the current logical time index `t`, P-PSSM / L-PSSM status, etc.

[0081] 2. The LPC notifies the old PAN to delete the context of the UE.

[0082] 3. The LPC update mapping table points all logical indices of the UE to the new PAN.

[0083] 4. The LPC instructs the new PAN to send a service PAN confirmation pilot on the downlink pairing resources. The confirmation pilot is generated by the P-PSSM: `P_confirm = HMAC-SHA256(K_sec_idle, S_p(t_confirm) || "CONFIRM" || UE_ID)`. After receiving the confirmation pilot at its calculated downlink listening time, the UE formally binds its local mapping to the new PAN.

[0084] Effect: The UE can update its location using a small number of uplink pilots, the LPC can accurately determine the UE's serving PAN, and paging can be accurately directed to a single PAN.

[0085] - Strategy B (fuzzy location tracking, using the second mapping table type) Suitable for a large number of silent IoT devices, and requires PAN to be on the same frequency.

[0086] Prerequisite: Multiple PANs participating in the mapping must use the same frequency to ensure that each logical index has physical resources on each PAN. `M_pool` takes the minimum number of physical resources available to the UE from these PANs.

[0087] On the UE side: Never proactively send location update pilots. Only when a service needs to be initiated will a service request be sent on the currently camped PAN. The service request resource is obtained from `R_pool = F(K_sec_idle, S_l(t), "REQUEST") mod M_pool` via a second mapping table. Since the mapping table is one-to-many, multiple co-frequency PANs will listen on the same physical resources.

[0088] Network side: - When a UE initiates a service, the PAN that receives the service request (i.e., the PAN where the UE is currently camped) reports it to the LPC, and the LPC learns the UE's current location from this information.

[0089] When the LPC needs to page a UE, it maintains a "set of possible UE locations" `S = {PAN_1, PAN_2, ..., PAN_k}` based on ephemeris and UE history. If the UE remains inactive for an extended period, the LPC gradually expands the range of set `S` (e.g., starting with the most recently active PAN and gradually adding adjacent PANs until the entire TA is covered). The LPC sends a paging authorization instruction to all PANs in set `S`, containing the UE identifier and logical resource index `R_pool` (predicted by P-PSSM). Each PAN sends a paging message (which can be a pure pilot, modulated pilot, or fused mode) on the physical resource mapped to `R_pool`, based on the locally stored UE context (if previously served) or a temporary context obtained from the LPC. After the UE hears the paging message on its currently camped PAN, it responds, and the responding PAN reports to the LPC. The LPC learns the UE's current location from this response and can update the set of possible locations.

[0090] Effect: Completely eliminates air interface location update signaling; the UE can remain silent indefinitely, only being discovered naturally when communication is needed. Paging overhead gradually increases with the UE's silence time, but remains acceptable.

[0091] 4.3 Strategy Switching LPC can dynamically switch policies based on service requirements. For example, when a UE is activated from a silent state for emergency services, LPC notifies the UE to switch to policy A via downlink signaling (which may send implicit pilot or security pilot frames during monitoring). After the switch, LPC reconfigures the first mapping table type for the UE and may trigger a context transition to ensure accurate location.

[0092] 4.4 Different frequency shifting processing in idle state Idle UE movement may cause a change in its serving PAN. LPC learns of UE location changes and triggers necessary mapping updates through the following mechanisms: - When the UE is configured with policy A (precise tracking): The UE sends location update pilots according to predefined rules. The LPC learns the UE's new serving PAN through wide-window blind detection, triggers context migration, and updates the mapping table. If the new PAN is on a different frequency than the old PAN, the LPC simultaneously sends a migration instruction (same as type C) to the UE during the context migration process, guiding the UE to adjust its radio frequency to the new frequency before the next listening opportunity. The UE then listens for paging messages directly on the new frequency during subsequent listening opportunities.

[0093] - When the UE is configured with policy B (fuzzy tracking) and the PAN is on the same frequency: the LPC does not actively track the UE's location. After the UE moves, it can still listen for paging on the new PAN (due to the same frequency) without any additional operation. When the UE initiates a service or network paging, the LPC naturally learns the UE's new location through the response.

[0094] - When a UE is configured with policy B but moves to a different frequency PAN coverage area: Due to the different frequency, the UE cannot continue to listen for paging messages on its original frequency. Network intervention is required in this case. The LPC predicts the possible different frequency area the UE might enter based on ephemeris data and the UE's historical location information (such as last active location, movement speed, etc.). At the UE's original listening time, a migration instruction (same type C) is sent through the original PAN to guide the UE to migrate to the target frequency. If the LPC cannot accurately predict, a gradual expansion of the paging range can be used: first, paging is performed on the original frequency; if this fails, a paging message is sent on an adjacent different frequency PAN. After the UE responds on any different frequency PAN, the LPC learns the UE's current location and updates the mapping table, while simultaneously guiding the UE to subsequently listen on the new frequency.

[0095] Throughout all the above processes, the UE's NAS layer and upper-layer applications are unaware of the frequency migration at the physical layer, and service continuity is guaranteed by LPC and underlying mechanisms.

[0096] 4.5 Same-frequency movement processing in idle state For co-frequency networking, when an idle-state UE moves, causing a change in the serving PAN, the UE does not need to adjust its radio frequency because the frequency points are the same. After the LPC learns the UE's new location through the uplink pilot of Policy A or the service / paging response of Policy B, it can update the mapping table without the UE noticing.

[0097] V. Dynamic Adjustment of Resource Pool LPC can dynamically adjust the size `M_pool` of the UE-specific resource pool based on factors such as service type, mobility speed, and channel quality. For example... Figure 5 As shown, the adjustment principles include, but are not limited to: - Business type: - URLLC services require low latency and high reliability, and can be configured with a smaller pool size (e.g., `M_pool=10`) to reduce the probability of collisions.

[0098] - eMBB services: require high speed, require a larger pool size (e.g., `M_pool=200`), and support more resource options.

[0099] - mMTC services: massive connections but low power consumption, with a moderate pool size (e.g., `M_pool=50`) to balance resource utilization and collision probability.

[0100] - Movement speed: - High-speed mobile UEs (such as high-speed rail, satellite terminals): The pool size can be increased (e.g., `M_pool=300`) to tolerate more frequent mapping updates.

[0101] - For stationary UEs (such as IoT sensors): the pool size can be reduced (e.g., `M_pool=1`) to achieve precise resource allocation.

[0102] - Channel quality: - Poor channel quality (e.g., low RSRP, high BLER): The pool size can be appropriately increased to provide more resource options to combat fading.

[0103] - Network load: - When a PAN is overloaded, LPC can increase the pool size of the UE and increase the indexes mapped to other PANs to achieve load balancing.

[0104] The adjustment information is notified to the UE via downlink signaling: - Connected state: Implicit pilots can be sent via `T_DL` (`P_resize = F(K_sec, S(t), "RESIZE"|| new_M)`) or via secure pilot frames, RRC reconfiguration, MAC-CE, etc.

[0105] - Idle state: Implicit pilot or security pilot frames can be sent during the listening period, and the UE will take effect in the next listening cycle.

[0106] Upon receiving the data, the UE updates its local `M_pool`, using the new value for subsequent calculations. The LPC also updates its mapping table to ensure that the new index range corresponds to physical resources.

[0107] VI. Interference Coordination and Resource Conflict Resolution Multiple UE-specific pools are allowed to overlap in terms of physical resources. LPC runs copies of the P-PSSM and L-PSSM for all UEs, predicting the resource intentions of each UE at future logical decision moments for each PAN (i.e., the physical resources obtained by mapping `R_pool`). When it is predicted that multiple UEs intend to use the same physical resource on the same PAN at the same time, LPC performs a two-step deterministic arbitration at the PAN level: Step 1: Arbitration of user conflicts A winning UE is selected from the conflicting UEs according to preset rules. The rules may include: priority (determined by service QoS), polling (for fairness), historical failure count, etc.

[0108] Step 2: Resource Availability Check Check if the physical resources of the winning UE are available at the scheduled time (query the global resource calendar to confirm that they are not occupied by other UEs or service flows). If available, grant the resources; if unavailable, the arbitration fails, and the resources are not allocated this time.

[0109] - The two-step order is adjustable: checking before arbitration can filter out unavailable resources in advance and reduce the amount of computation; arbitration before checking is simpler to implement.

[0110] After successful arbitration, the LPC sends an authorization instruction to the PAN via the power supply link, with an example format: `(PAN_ID, Physical Resource Index, Winning UE_ID)`. Based on the authorization, the PAN generates a paging message (downlink) or opens a receive window (uplink) on the specified physical resource using the winning UE's PSSM. Unsuccessful UEs have no signal on the corresponding resource and back off, waiting for the next logical moment.

[0111] Because LPC has a global resource view, the arbitration process naturally avoids co-channel interference, achieving centralized interference coordination (ICIC), such as... Figure 7 As shown. Compared to traditional ICIC which requires negotiation between base stations, this solution is more efficient and deterministic. In co-frequency networking, multiple PANs can fully reuse frequency resources, and conflicts are avoided through LPC arbitration, significantly improving spectrum efficiency.

[0112] VII. Implicit Migration Based on Location Prediction (Enhancement Mechanism) For UEs with positioning capabilities and pre-configured coverage maps, signaling-free migration can be achieved across all scenarios, including inter-frequency scenarios. Specific process: 1. Pre-configuration phase: When the UE initially accesses the system or via system broadcast, it obtains the coverage map of the surrounding PANs. The coverage map includes the frequency point, baseband parameters, and geometric description of the coverage area for each PAN (such as center coordinates + radius, or coverage range based on satellite ephemeris + beam pointing).

[0113] 2. Location Awareness: The UE has positioning capabilities (such as GNSS or network-aware positioning) and can know its precise location in real time. The network side (LPC) can also know the UE's location through measurement or UE reporting.

[0114] 3. Independent Decision-Making: LPC and UE run the same prediction algorithm, independently determining when to migrate and to which PAN based on the UE's current location and coverage map. For example, the algorithm can be defined as: "When the distance between the UE and the target PAN is less than a threshold R, perform a mapping update at the next logical decision time." The threshold R can be set to 90% of the coverage radius to avoid edge ping-pong effects.

[0115] 4. Simultaneous Execution: Upon reaching a consensus on the migration time, both parties shall execute the following simultaneously: - LPC: Update the mapping table to point to the target PAN and establish a UE context with the target PAN (configure pre-conversion parameters if necessary).

[0116] - UE: If it is a single radio frequency and different frequencies, adjust the radio frequency to the target frequency point; if it is the same frequency or dual radio frequencies, no radio frequency adjustment is required.

[0117] 5. Effect: There is no air interface signaling throughout the entire process, and the UE is completely unaware of it, achieving the ultimate goal of zero signaling migration across all scenarios.

[0118] 8. State transition from connected state to idle state When the UE has no data transmission, and the network decides to put it into an idle state, the following steps are performed: 1. LPC retains the UE's dedicated resource pool, but reduces `M_pool` to a preset idle state size (e.g., from 100 to 10), and updates the mapping table to ensure that the indexes within the new `M_pool` range still have physical resource mappings.

[0119] 2. The UE derives the idle-state key `K_sec_idle` from the current security context and continues to run P-PSSM and L-PSSM (if enabled), switching the listening time to idle-state listening mode (mode one or mode two).

[0120] 3. LPC configures the idle state mapping table type (policy A or B) for the UE based on the UE service type and network scenario, and may issue an overlay map (if implicit migration is supported).

[0121] 4. The UE enters the idle state, listens for paging messages during the listening period, and sends a location update pilot (strategy A) or does not send it (strategy B) as required by the strategy.

[0122] When a connection needs to be restored, the UE initiates random access after detecting a paging message during the listening period. The LPC switches its mapping table type back to the connected state, restores the original `M_pool`, and optionally updates it to the connected state key, thus completing the state transition.

[0123] IX. Beneficial Effects Compared with the prior art, the present invention has the following beneficial effects: 1. A complete UE-specific resource pool system: unifies resource management in connected and idle states, covering the entire process from access and communication to paging.

[0124] 2. Seamless migration: In same-frequency scenarios and inter-frequency scenarios that support location prediction, the UE does not need any signaling interaction, achieving completely seamless migration.

[0125] 3. Extremely low signaling overhead: Through mapping table updates and implicit signaling, migration and location update signaling is reduced to a minimum, or even zero. The only signaling required is single-radio inter-frequency migration, with an interruption time that can be controlled within one logic cycle (e.g., 0.125ms), far superior to the 810-1080ms of traditional 5G.

[0126] 4. Natural ICIC: LPC centralized arbitration enables efficient interference coordination, supports co-frequency networking, and improves spectrum efficiency.

[0127] 5. UE capability adaptation: Simultaneously covering single-radio (mainstream) and dual-radio (future high-end), providing differentiated optimization solutions.

[0128] 6. Service Adaptive: The resource pool size can be dynamically adjusted to meet different QoS requirements and improve resource utilization.

[0129] 7. Flexible location tracking: Two mapping table types can be selected on demand, striking a balance between location update overhead and paging overhead.

[0130] 8. Intrinsic Security: Based on DSF cryptographic primitives, it ensures the determinism, privacy and resistance to attacks in communication.

[0131] 9. Multi-architecture compatibility: Provides three architecture paths to support a smooth evolution from existing networks to future architectures.

[0132] 10. Precise timing: By using a unified anchor point time and a fixed offset, the determinism of physical layer operations is ensured, supporting sub-millisecond cycles. Attached Figure Description

[0133] Figure 1 This is a schematic diagram of the overall architecture of the present invention.

[0134] Figure 2 This is a diagram comparing the three architecture paths.

[0135] Figure 3 A schematic diagram illustrating the dynamic updating of the classification for connected state resource mapping.

[0136] Figure 4 This is a schematic diagram of the idle state mapping table type and location tracking strategy.

[0137] Figure 5 A flowchart for dynamically adjusting the resource pool.

[0138] Figure 6 This is a schematic diagram of the dual-radio UE enhancement function.

[0139] Figure 7 The schematic diagram for implementing ICIC for LPC centralized arbitration. Detailed Implementation

[0140] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be described in detail below with reference to the accompanying drawings and embodiments. The described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0141] Example 1: System Overall Architecture and Mapping Table Construction (Path C) like Figure 1 As shown, the system of this invention includes one LPC, multiple PANs, and multiple UEs. The LPC is deployed at a ground station or core network and connects to each PAN through a high-precision fronthaul network. The PAN can be a ground base station, a low-Earth orbit satellite, a drone, etc. The UEs include single-radio UEs and dual-radio UEs.

[0142] LPC maintains the following core data structures: - UE-specific resource pool configuration: each UE's `M_pool`, physical layer baseline parameters, DSF triplet, etc.

[0143] - Dynamic mapping table: Maps to physical resource descriptors using `(UE_ID, R_pool)` as the key. The mapping table type can be one-to-one or one-to-many.

[0144] - Global Resource Calendar: Records resource status (idle / occupied), occupant, priority, etc., using `(PAN_ID, physical resource)` as the key.

[0145] - Coverage map (optional): Coverage area and parameters of surrounding PANs.

[0146] The UE runs P-PSSM and L-PSSM (if configured) in both connected and idle states, generating a logical resource index based on DSF. The UE obtains physical layer reference parameters by reading system messages from the current serving PAN to determine the location of physical resources.

[0147] Example of mapping table construction: Assuming UE_A is a single-radio UE with a dedicated pool size `M_pool=100`, LPC configures a first-type mapping table for it: - Indexes 0-49 are mapped to PRB 0-49 of PAN A (frequency f1=3.5GHz, SCS=15kHz). - Indexes 50-99 map to PRB 0-49 of PAN B (frequency f1=3.5GHz, SCS=30kHz). At this point, the logical pool of UE_A consists of resources from two PANs with the same frequency but different parameters. LPC can choose sticky scheduling (mapping all indices to the same PAN) or smooth migration (gradually adjusting the mapping targets of each index) as needed.

[0148] If the LPC configures a second mapping table type for another UE_B (dual-radio), and PAN A, PAN B, and PAN C are on the same frequency (f1=3.5GHz, SCS=15kHz), then each index maps to the corresponding PRB of the three PANs, for example: - Index 0 maps to: (PAN A, PRB0), (PAN B, PRB0), (PAN C, PRB0) - Index 1 maps to: (PAN A, PRB1), (PAN B, PRB1), (PAN C, PRB1) - ... - Index 49 maps to: (PAN A, PRB49), (PAN B, PRB49), (PAN C, PRB49) `M_pool` sets the minimum number of PAN resources, which is 50 in this case.

[0149] Example 2: Implementation of Path A (Traditional Base Station + Cryptographic Paging) This embodiment corresponds to Figure 2Path A. Assume a 5G gNB coverage area where the UE establishes a key `K_sec` upon attachment. The gNB broadcasts paging message generation rules: using HMAC-SHA256, the inputs are `K_sec`, the current SFN / timeslot number, and the UE's TMSI, generating a paging message in pure pilot form. When the core network needs to page the UE, the gNB calculates the UE's PF / PO (e.g., SFN mod T = UE_ID mod T). At the time corresponding to the PO, the gNB obtains the current SFN=1024, timeslot number=0, generates a pilot `P_paging = HMAC-SHA256(K_sec, (1024||0) || TMSI)`, and sends it on the PO resource. The UE wakes up at its PO, obtains the same SFN / timeslot, generates a copy for matched filtering. If a correlation peak is detected (correlation coefficient > 0.8), it is determined that it has been paged and initiates random access. Location updates still go through the TAU procedure. This path achieves signal-level paging with minimal modifications, reducing UE wake-up power consumption by approximately 30%.

[0150] Example 3: Implementation of Path B (Enhanced Base Station + PSSM) This embodiment corresponds to Figure 2 Path B. A certain gNB introduces PSSM functionality, maintaining P-PSSM and L-PSSM for each UE. The gNB internally maintains a logical resource pool size of `M_pool=64`, with a mapping table of type 1. In idle state, the UE sends a location update pilot every 100 logical cycles (each cycle is 10ms, i.e., once per second). The gNB runs L-PSSM to predict the transmission time and sends a wide-window blind detection command (via the X2 interface) to neighboring base stations. Base stations that successfully detect the pilot report to the gNB, which then determines the new serving base station and triggers context migration. During paging, the gNB generates a paging pilot (pure pilot form) based on the P-PSSM and transmits it on the predicted resources. When multiple UEs conflict, the gNB performs a two-step arbitration (priority: URLLC > eMBB > mMTC). This path achieves implicit location tracking, reducing TAU signaling by 90%.

[0151] Example 4: Dynamic Update of Connected-State Resource Mapping (Path C) This embodiment corresponds to Figure 3 Based on path C. Assuming the UE is a single-radio device, initially sticking to PAN A (f1=3.5GHz, SCS=15kHz). LPC predicts through measurement reports that the UE will enter the coverage area of ​​PAN B.

[0152] - Type A: Same-frequency smooth migration (PAN B same frequency, parameters are the same or different) LPC establishes a UE context with PAN B in advance. At logical time t=1000, LPC updates the mapping table, gradually changing the mapping target of some indices (such as 0-49) from PAN A to PAN B. At time t=1001, the UE continues to calculate indices based on DSF (such as R_pool=25). If index 25 has been migrated to PAN B at this time, PAN B resources are actually used; if not, PAN A resources are still used. Since the frequency points are the same, the UE radio frequency does not need to be adjusted, and the difference in baseband parameters is handled by the pre-conversion of PAN B. LPC can continue to migrate the remaining indices in subsequent logical times, achieving a completely smooth transition. The UE is unaware of the entire process.

[0153] - Type B: Smooth migration between different frequencies (PAN B frequency point f2=2.1GHz, UE is dual-frequency) The primary radio of a dual-radio UE resides on PAN A, while the secondary radio is pre-synchronized with PAN B. The LPC updates the mapping table at t=1000, pointing the index to PAN B. Service flows instantly switch to the secondary radio without interruption.

[0154] - Type C: Inter-frequency single-radio migration (PAN B frequency point f2=2.1GHz, UE is a single radio frequency) The LPC decides to migrate and sends a migration instruction using method one (dedicated implicit pilot). At t=1000, the UE sends a handover pilot `P_ho = HMAC-SHA256(K_sec, S_p(1000) || "HO" || PAN_B_ID)` via PANA at `T_DL` (assuming `Δ_dl=0.5ms`). The UE detects `P_ho` at `T_DL`, pre-configures `Δ_ho=2` logic periods (0.25ms), adjusts the radio frequency to 2.1GHz at t=1002, and updates the baseband parameters to 30kHz. The LPC points the mapping table to PAN B at t=1002. The migration is complete, with a service interruption time of 0.25ms, far superior to the 810ms of traditional 5G.

[0155] Example 5: Idle Resource Pool and Implicit Position Tracking (Path C) This embodiment corresponds to Figure 4 Based on path C, the UE transitions from connected state to idle state, deriving `K_sec_idle =HKDF-Expand(K_gNB, "IDLE_DSF", 256)`, and `M_pool` is reduced from 100 to 10.

[0156] - Strategy A (Precise Tracking): The UE is a smartphone, configured with the first mapping table type, and the listening timing adopts method one (based on PSSM logical beats, `T_step_p=320ms`). Every 100 logical beats (i.e., every 32 seconds), the UE updates the pilot signal at logical time t=5000. `P_loc = HMAC-SHA256(K_sec_idle, S_l(5000) || "LOCATION" || UE_ID)` LPC predicts t=5000 and issues a wide-window blind detection command to PAN A, PAN B, and PAN C, with a window width W=3ms. PAN B successfully detects the pilot and reports it (RSRP=-95dBm). LPC determines the new serving PAN is PAN B and triggers context migration: it sends the UE context (key, current t, state) to PAN B, notifies PAN A to delete it, updates the mapping table to point to PAN B, and instructs PAN B to send an acknowledgment pilot (pure pilot form) on downlink pairing resources. The UE completes the migration after receiving the acknowledgment.

[0157] - Strategy B (Fuzzy Tracking): The UE is a water meter, configured with a second mapping table type, PAN A / B / C on the same frequency (f1=3.5GHz). `M_pool` takes the minimum value of 50. The listening timing adopts method two (compatible with traditional PO, DRX period=1.28s). The UE never actively sends location updates. On a certain day, the UE needs to report data and sends a service request at logical time t=10000, resource index R=20. PAN A, B, and C are all listening on PRB20. PAN A (the actual UE camped) successfully receives and reports to LPC, and LPC records the UE in PAN A. Subsequently, LPC needs to page the UE, determines the possible location set S={PAN A, PAN B} based on historical records, and sends paging authorization instructions to both. PAN A and PAN B send paging pilots (pure pilot form) on the resource corresponding to R=20. The UE detects the pilot under PAN A and responds, and LPC learns the current location.

[0158] Example 6: Idle State Inter-Frequency Mobility Processing (Path C) This embodiment is based on Figure 4 This demonstrates a scenario where an idle single-radio UE moves to a different-frequency PAN under policy A.

[0159] The UE is configured with strategy A (precise tracking) and is currently camped on PAN A (f1=3.5GHz). After moving, the UE enters the coverage area of ​​PAN B (f2=2.1GHz). At the next predetermined location update time t=6000, the UE generates a location update pilot `P_loc` based on L-PSSM and transmits it on the currently camped PAN A. PAN A receives the signal and reports it to LPC, but because the UE has entered the coverage area of ​​PAN B, the received signal on PAN A is weak. LPC uses the UE's L-PSSM replica to predict t=6000 and issues a wide-window blind detection command to the candidate PAN set (PAN A, PAN B, PAN C). PAN B successfully detects the pilot and reports it (high RSRP), and LPC determines that the new serving PAN is PAN B.

[0160] Because PAN B and PAN A operate on different frequencies, and the UE operates on a single radio frequency, the LPC, while triggering context switching, sends a switching instruction (type C) through the original PAN A at the UE's next listening time, guiding the UE to switch to frequency f2. The switching instruction carries the target frequency f2, baseband parameters, and the switching execution time t_switch. At the t_switch time, the UE adjusts its radio frequency to 2.1GHz and then continues idle operation on PAN B, listening for paging messages. The LPC updates the mapping table to point to PAN B. The entire process is transparent to the UE's NAS layer.

[0161] Example 7: Dynamic Adjustment of Resource Pool (Path C) This embodiment corresponds to Figure 5 The UE initially uses eMBB service with `M_pool=200`. At a certain moment, the UE initiates an emergency URLLC command. The LPC detects the service type change and decides to adjust `M_pool` to 50 to reduce the probability of collisions. The LPC notifies the UE of the new M value via a downlink implicit pilot (sending `P_resize = HMAC-SHA256(K_sec, S(t), "RESIZE" || 50)` in `T_DL`). The new value takes effect at the next logical moment. The LPC simultaneously updates the mapping table to ensure that indices 0-49 have physical resources. After the emergency command is sent, the LPC restores `M_pool` to 200.

[0162] Example 8: Interference Coordination and Resource Conflict Resolution (Path C) This embodiment corresponds to Figure 7Assume UE1 and UE2 are in the same PAN coverage area, each with `M_pool=100`. At t=2000, UE1 calculates R=30, UE2 calculates R=30, and they map to the same physical resource PRB30. LPC, running PSSM, predicts a conflict and performs a two-step arbitration at the PAN level: first, it checks resource availability (PRB30 is idle), then selects UE1 as the winner based on priority (UE1 has higher priority). LPC sends an authorization instruction to the PAN: "PRB30 is authorized to UE1". The PAN sends UE1's paging message (downlink) or receives UE1's data (uplink) on PRB30. UE2 has no signal on PRB30 and backs off. Due to the global view of LPC, co-channel interference is avoided, achieving ICIC.

[0163] Example 9: Implicit Migration Based on Location Prediction (Path C Enhancement) The UE has GNSS and pre-configured coverage maps: PAN A (f1, radius 50km), PAN B (f2, radius 60km). The UE's current location is 55km from the center of PAN B. The algorithm determines that it is about to enter PAN B coverage and should update the mapping at the next logical time t+1. At time t+1, the UE automatically adjusts its radio frequency to f2 (if it is a single radio frequency and a different frequency), and LPC simultaneously updates the mapping table to point to PAN B. There is no signaling throughout the process.

[0164] Example 10: State transition from connected state to idle state (path C) Since the UE has no data transmission, the network decides to enter the idle state: 1. LPC reduces `M_pool` from 100 to 10 and updates the mapping table to ensure that resources are available for 0-9.

[0165] 2. UE derives `K_sec_idle`, adjusts P-PSSM tick to 320ms (mode 1 monitoring), and disables L-PSSM (strategy B).

[0166] 3. LPC configures strategy B (fuzzy tracking) for the UE and distributes the coverage map.

[0167] 4. The UE enters the idle state and listens for paging messages when the listening time is available.

[0168] When the connection needs to be restored, the UE detects a paging message (pure pilot form) during the listening period, initiates random access, and LPC restores the connected state configuration.

[0169] The above embodiments are merely preferred embodiments of the present invention and do not constitute a limitation on the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A UE-specific dynamic resource pool communication method based on dynamic security foundation, characterized in that, include: - The network side establishes and maintains a dedicated dynamic resource pool for each user equipment (UE). The dedicated dynamic resource pool has a dynamically adjustable pool size M_pool and provides the UE with a logically independent resource index space, with an index range of 0 to M_pool-1. - The UE and the network side operate the Protocol Security State Machine (PSSM) based on the shared Dynamic Security Foundation (DSF), and independently calculate the same in-pool resource index R_pool at the same logical decision time; - The network side maintains a dynamic mapping table, using (UE_ID, R_pool) as the key, to map the R_pool calculated by the UE to the physical resources of the physical access node (PAN); - The UE converts R_pool into a specific physical resource location and a physical transmission time based on a unified time base according to the physical layer parameters of the current serving PAN, and then communicates. - The method is applicable to both connected and idle states, and adopts different mobility management strategies based on the UE's radio frequency capabilities, network scenario, or service requirements.

2. The method according to claim 1, characterized in that, The dynamic mapping table includes a first mapping table type, which maps each R_pool to the physical resources of a single PAN. Different R_pools can be mapped to the physical resources of different PANs.

3. The method according to claim 1, characterized in that, The dynamic mapping table includes a second mapping table type, which maps each R_pool to the physical resources of multiple PANs simultaneously. That is, each R_pool corresponds to a set of physical resource descriptors, and each descriptor identifies a physical resource on a PAN.

4. The method according to claim 3, characterized in that, When using the second mapping table type, the value of M_pool is limited to the minimum number of physical resources available to the UE in all PANs involved in the mapping, to ensure that each R_pool has corresponding physical resources on each PAN.

5. The method according to any one of claims 1 to 3, characterized in that, The protocol security state machine includes a P-PSSM for downlink paging and an L-PSSM for uplink location updates, both based on the same DSF triplet but distinguished by different context parameters.

6. The method according to any one of claims 1 to 3, characterized in that, The physical transmission time based on a unified time base is determined in the following way: - At the logical decision-making moment, the UE and the network side read the local physical clock to obtain the unified anchor time T_anchor; - Based on the pre-configured fixed offsets Δ_dl and Δ_ul, calculate the downlink listening / transmitting time T_DL = T_anchor + Δ_dl and the uplink transmitting time T_UL = T_anchor + Δ_ul.

7. The method according to any one of claims 1 to 3, characterized in that, For idle UEs, downlink listening timing is determined using one of the following methods: - Method 1: Based on the logic tick of P-PSSM, calculate T_DL and listen at each logic decision moment; - Method 2: Based on traditional paging timing (PO), defined by the DRX cycle.

8. The method according to any one of claims 1 to 3, characterized in that, The paging message sent from the network side to the UE takes one of the following forms: pure pilot sequence, pilot sequence of modulated data, or frame structure of pilot and content fusion.

9. The method according to claim 2, characterized in that, For connected UEs, the network side implements sticky scheduling by configuring the first mapping table type, so that different R_pools calculated by the UE at multiple consecutive logical decision moments are mapped to the same PAN, thereby avoiding frequent frequency point migration of single radio frequency UEs in inter-frequency scenarios.

10. The method according to any one of claims 1 to 3, characterized in that, When it is necessary to adjust the UE's serving PAN, the network side achieves a smooth migration by updating the mapping table, using one of the following methods depending on the network scenario and UE capabilities: - Method A: In the same frequency scenario, only the mapping table is updated, and the UE is unaware of it; - Method B: In inter-frequency scenarios and when the UE is a dual-radio system, only the mapping table is updated, and the UE is unaware of it; - Method C: In inter-frequency scenarios and when the UE is a single radio frequency, the network side sends a migration instruction to the UE through downlink signaling. The UE adjusts the radio frequency and baseband parameters according to the instruction, and the network side updates the mapping table synchronously.

11. The method according to claim 10, characterized in that, In Method A, when the baseband parameters of the target PAN are different from those of the current PAN, the network side uses pre-conversion technology to make the signal sent by the target PAN conform to the UE's reference physical layer parameters at the UE.

12. The method according to claim 10, characterized in that, In method C, the downlink signaling is carried using one of the following methods: - Method 1: Dedicated implicit pilot, generated by PSSM, with context identifiers that distinguish it from paging pilots or service data, and detected by the UE through matched filtering; - Method 2: Security pilot frame, generated by the PSSM corresponding to the service flow. The frame structure contains frame type indication and migration command content. The UE obtains the migration information through demodulation.

13. The method according to claim 10, characterized in that, The migration instruction includes the physical layer parameters of the target PAN and the migration execution time, wherein the migration execution time is determined by one of the following methods: - Fixed offset method: If the UE receives a migration instruction at time t, it will perform the migration at time t + Δ_ho, where Δ_ho is the pre-configured offset; - Logical time binding method: The sending time of the migration indication corresponds to the logical time t_ho, and the UE performs the migration at the next logical decision time t_ho + 1; - Explicit indication method: The migration instruction directly carries the migration execution time.

14. The method according to any one of claims 1 to 3, characterized in that, It also includes implicit migration based on the UE's precise location and pre-configured overlay map: - UE pre-configured coverage map, including the coverage area of ​​surrounding PANs and the corresponding physical layer parameters; - The UE has positioning capabilities and can know its own location in real time; - The UE runs the same prediction algorithm as the network side, independently determining the migration timing and target PAN based on the UE location and coverage map; - Both parties synchronously update the mapping table at the agreed migration time, without the need for air interface signaling.

15. The method according to any one of claims 1 to 3, characterized in that, For idle UE: - When the UE transitions from the connected state to the idle state, it derives the idle state key K_sec_idle from the existing security context, which is used for all idle state cryptographic operations; - The UE retains a dedicated dynamic resource pool, the size of which can be reduced to the idle state preset value; - The UE generates a copy of the paging message based on P-PSSM for listening at the predetermined downlink listening time, and sends or does not send a location update pilot according to the configured location tracking policy.

16. The method according to claim 15, characterized in that, The location tracking strategy includes: - Strategy A: Using the first mapping table type, the UE generates a location update pilot based on L-PSSM at a specific logical decision time according to predefined rules and sends it on the currently camped PAN; the network side guides the candidate PAN set to perform wide-window blind detection, determines the UE's new serving PAN based on the detection results, triggers context migration and updates the mapping table; - Strategy B: Use the second mapping table type, and the PANs participating in the mapping are on the same frequency. The UE does not actively send location update pilots. When the UE initiates a service, the PAN receiving the service reports the location to the network side. When the network side pages the UE, it sends a paging authorization to all PANs in the UE's possible location set. The UE responds under one of the PANs, and the network side learns the location from the responding PAN. - The network side can dynamically switch between policy A and policy B as needed.

17. The method according to claim 15, characterized in that, For idle UEs, when inter-frequency shift occurs: - If the UE is configured with policy A, the network side will know the UE's new location through wide-window blind detection, and send a migration instruction to the UE at the same time as triggering context migration, guiding the UE to adjust the radio frequency to the new frequency point; - If the UE is configured with policy B and moves to the coverage area of ​​a different frequency PAN, the network side predicts its possible location based on the UE's historical location information, sends a migration instruction through the original PAN, or guides the UE to migrate after learning its new location by gradually expanding the paging range.

18. The method according to any one of claims 1 to 3, characterized in that, Multiple UEs’ dedicated dynamic resource pools are allowed to overlap in terms of physical resources. Resource conflicts caused by overlap are resolved by the network side through a two-step deterministic arbitration at the granularity of a single PAN. The two-step deterministic arbitration includes: - Step 1: User conflict arbitration, which determines the winning UE from the conflicting UEs according to preset rules; - Step 2: Resource availability check, check whether the physical resources of the winning UE are available at the scheduled time; - The execution order of the two steps is adjustable.

19. The method according to claim 18, characterized in that, Through the aforementioned two-step deterministic arbitration, centralized interference coordination (ICIC) is achieved on the network side, supporting co-frequency networking and improving spectrum efficiency.

20. The method according to any one of claims 1 to 3, characterized in that, The pool size M_pool is dynamically adjusted based on at least one of the following factors: - UE service types, including URLLC, eMBB, and mMTC; - UE's movement speed; - UE channel quality; - Network load status; The adjustment information is notified to the UE via downlink signaling, and the UE updates its local M_pool.

21. The method according to any one of claims 1 to 3, characterized in that, For a UE equipped with dual radio frequency links, the UE can maintain connections with multiple PANs simultaneously, achieving at least one of the following enhanced functions: - Zero-interruption migration: The main radio frequency resides in the current PAN, and the auxiliary radio frequency is pre-synchronized with the target PAN, so that the service flow switches instantly during migration; - Diversity reception: Using the second mapping table type, multiple PANs send the same data simultaneously, and the UE receives the data in a combined manner; - Load balancing: Using the first mapping table type, multiple PANs carry different service flows respectively; - Multi-PAN random scheduling: Using the first mapping table type, the UE obtains resources from multiple PANs simultaneously, maximizing resource utilization.

22. A UE-specific dynamic resource pool communication system based on dynamic security foundation, characterized in that, include: - At least one logical processing center (LPC), deployed at a ground station or core network, for performing the steps performed by the network side in the method of any one of claims 1 to 21; - Multiple physical access nodes (PANs) deployed at base stations, satellites, or drones for performing the steps performed by the physical access nodes in the method of any one of claims 1 to 21; - At least one user equipment (UE) for performing the steps performed by the UE in the method of any one of claims 1 to 21.

23. The system according to claim 22, characterized in that, The LPC includes: - Transceiver, used for communication with the core network and PAN; - The processor is configured to configure DSF triplet for each UE, maintain a UE-specific dynamic resource pool and dynamic mapping table, dynamically select the mapping table type according to the network scenario, run P-PSSM and L-PSSM copies of all UEs to predict UE behavior, predict and arbitrate physical layer resource conflicts at the granularity of each PAN, send authorization instructions or wide-window blind detection instructions to the PAN through the power supply link, update UE location information according to the PAN's report, and dynamically adjust the pool size M_pool. - Memory, used to store UE configuration information and mapping tables.

24. The system according to claim 22, characterized in that, The PAN includes: - Transceiver, used for air interface communication with the UE and communication with the LPC via the power supply link; - The processor is configured to run a copy of the PSSM of the serving UE based on the PSSM context of the UE received from the LPC, autonomously generate paging messages, migration indications, and uplink license pilots, send or receive on specified physical resources according to the authorization indication of the LPC, and perform blind detection on specific pilots. - Memory, used to store the PSSM context and mapping table information of the storage UE.

25. The system according to claim 22, characterized in that, The UE includes a single-radio UE or a dual-radio UE, and the UE includes: - Transceiver; - The processor is configured to derive the idle key K_sec_idle from the existing security context, run P-PSSM and L-PSSM to generate logical resource indexes and pilot copies, determine the physical resource location based on the physical layer parameters of the current serving PAN, perform matched filtering detection or demodulation at the predetermined downlink listening time, perform corresponding operations based on the detected signaling, and adjust the pool size M_pool and physical layer parameters according to the network side instructions. - Memory, used to store configuration information.

26. A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method of any one of claims 1 to 21.

27. A communication device, characterized in that, The apparatus includes a processor and a memory, the memory storing instructions that, when executed by the processor, cause the apparatus to perform the method of any one of claims 1 to 21.