Security keys for function split in wireless network architecture

By generating KDU and KCU-UP keys based on key derivation functions and parameters in the wireless network architecture, the forward secrecy problem in the initial security key generation and switching process caused by function splitting is solved, thereby enhancing the security and reliability of the wireless network.

CN122496813APending Publication Date: 2026-07-31NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2026-01-29
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In wireless network architecture, the forward confidentiality problem in the initial security key generation and switching process caused by functional splitting, especially during the switching between RAN nodes, makes it difficult for existing technologies to effectively generate and manage security keys, resulting in insufficient communication security.

Method used

By generating distributed unit (KDU) and central unit user plane (KCU-UP) keys based on key derivation functions and key derivation parameters, and utilizing key derivation functions and various input parameters such as KgNB, fixed constant values, and identifiers, a security key for RAN nodes is generated, ensuring the effective export and updating of keys during handover.

Benefits of technology

This approach enhances security by decomposing functions within the wireless network architecture, ensuring secure communication during handover between RAN nodes, resolving forward confidentiality issues, and improving system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122496813A_ABST
    Figure CN122496813A_ABST
Patent Text Reader

Abstract

One method includes: accessing key derived parameters, including: the key (source K) of the source distributed unit (DU) of the radio access network (RAN) node. DU ) and a fixed constant value (FC), where the source DU is the source of the handover to the target distributed unit (DU) of the RAN node; and the key (target K) for generating the target DU for the RAN node. DU ), where the target K DU Based on the key derivation function and at least source K DU And generated by FC.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-references to related applications

[0001] The following applications are relevant: U.S. Provisional Application No. 335550-US-PSP (44665-547); U.S. Provisional Application No. 335707-US-PSP (44665-545); U.S. Provisional Application No. 335708-US-PSP (44665-546); and U.S. Provisional Application No. 335909-US-PSP (44665-556). Technical Field

[0002] Various example implementations involve security keys, and more specifically, security keys for functional splitting in wireless network architectures. Background Technology

[0003] Wireless networks offer significant advantages to user mobility. The ability to maintain connectivity while on the move not only benefits users but also contributes to greater efficiency and productivity across society. As expectations for connection reliability, data speed, and lower power consumption become more demanding, the technologies used in wireless networks must keep pace. For example, where certain functional decompositions within the wireless network architecture are possible, the impact of such decompositions can be considered. Therefore, continuous focus on improving wireless network technologies is essential. Summary of the Invention

[0004] In various aspects of this disclosure, one method includes: accessing key derivation parameters; generating a first key (K) for a distributed unit of a radio access network (RAN) node. DU The first key is generated based on a key derivation function and at least some of the key derivation parameters; and the second key (K) is generated for the user plane of the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0005] On one hand, the key derivation parameters include: the RAN node's key (K gNB ), and a fixed constant value (FC), in which the first key (K DU ) is based on K gNB And generated by FC, and in which the second key (K) CU-UP ) is based on K gNB And generated by FC.

[0006] On one hand, the key derivation parameters also include the string "DU", and the first key (K) DU It is also generated based on the string "DU".

[0007] On one hand, the key export parameters also include the string "CU-UP", and the second key (K CU-UP It is also generated based on the string "CU-UP".

[0008] In one aspect, the key derivation parameters also include an identifier, the first key (K). DU It is also generated based on an identifier, and the second key (K) CU-UP It is also generated based on identifiers.

[0009] On one hand, the key derivation parameters also include the identifier of the distributed unit (DU-ID) of the RAN node, and the first key (K DU It is also generated based on DU-ID.

[0010] On one hand, the key derivation parameters also include the user plane identifier (CU-UP-ID) of the central unit of the RAN node, and the second key (K CU-UP It is also generated based on the CU-UP-ID.

[0011] On one hand, the key derivation parameters also include the Radio Network Temporary Identifier (RNTI) and the first key (K DU It is also generated based on RNTI.

[0012] On one hand, the key derivation parameters also include the Radio Network Temporary Identifier (RNTI) and the second key (K). CU-UP It is also generated based on RNTI.

[0013] On one hand, the key derivation parameters also include the Radio Resource Control User Equipment Identifier (RRC-UE-ID) and the first key (K DU It is also generated based on RRC-UE-ID.

[0014] In one aspect, the key derivation parameters also include the user plane user equipment identifier (UP-UE-ID) and the second key (K CU-UP It is also generated based on UP-UE-ID.

[0015] On one hand, the method also includes: based on the first key (K DU To generate the Radio Resource Control (RRC) integrity key (K) RRCint ).

[0016] On one hand, the method also includes: based on the first key (K DU To generate Radio Resource Control (RRC) encryption keys (K) RRCenc ).

[0017] On one hand, the method also includes: based on a second key (K CU-UP To generate the User Plane (UP) Integrity Key (K) UPint ).

[0018] On one hand, the method also includes: based on a second key (K CU-UP To generate the user plane (UP) encryption key (K) UPenc ).

[0019] In various aspects of this disclosure, one method includes: accessing key derivation parameters, the key derivation parameters including: the key (K) of the radio access network (RAN) node. gNB ), a fixed constant value (FC), a first random number and a second random number; generate the first key (K) for the distributed unit of the RAN node. DU The first key is generated based on a key derivation function and at least some of the key derivation parameters; and the second key (K) is generated for the user plane of the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0020] On the one hand, the first key (K) DU ) is based on K gNB FC and the first random number are generated.

[0021] On the one hand, the second key (K) CU-UP ) is based on K gNB FC and the second random number are generated.

[0022] In one aspect, the method also includes receiving a first random number and a second number from a network device.

[0023] In one aspect, the method also includes: generating a third key (target K) for the target distributed unit to be switched. DU The third key is based on the key derivation function and the first key (K). DU ), FC and a third random number are used to generate.

[0024] In one aspect, the method also includes receiving a third random number from a network device.

[0025] On one hand, the method also includes: based on the first key (K DU To generate the Radio Resource Control (RRC) integrity key (K) RRCint ).

[0026] On one hand, the method also includes: based on the first key (K DUTo generate Radio Resource Control (RRC) encryption keys (K) RRCenc ).

[0027] On one hand, the method also includes: based on a second key (K CU-UP To generate the User Plane (UP) Integrity Key (K) UPint ).

[0028] On one hand, the method also includes: based on a second key (K CU-UP To generate the user plane (UP) encryption key (K) UPenc ).

[0029] In various aspects of this disclosure, one method includes: accessing key derivation parameters, the key derivation parameters including: the key (K) of the radio access network (RAN) node. gNB ), a fixed constant value (FC), a first random number and a second random number; generate the first key (K) for the distributed unit of the RAN node. DU The first key is generated based on a key derivation function and at least some of the key derivation parameters; and the second key (K) is generated for the user plane of the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0030] On the one hand, the first key (K) DU ) is based on K gNB It is generated using FC and the first random number.

[0031] On the one hand, the second key (K) CU-UP ) is based on K gNB It is generated using FC and a second random number.

[0032] In one aspect, the method also includes receiving a first random number and a second number from a network device.

[0033] In one aspect, the method also includes: generating a third key (target K) for the target distributed unit to be switched. DU The third key is based on the key derivation function and the first key (K). DU It is generated by , FC and a third random number.

[0034] In one aspect, the method also includes receiving a third random number from a network device.

[0035] On one hand, the method also includes: based on the first key (K DU To generate the Radio Resource Control (RRC) integrity key (K) RRCint ).

[0036] On one hand, the method also includes: based on the first key (K DU To generate Radio Resource Control (RRC) encryption keys (K) RRCenc ).

[0037] On one hand, the method also includes: based on a second key (K CU-UP To generate the User Plane (UP) Integrity Key (K) UPint ).

[0038] On one hand, the method also includes: based on a second key (K CU-UP To generate the user plane (UP) encryption key (K) UPenc ).

[0039] In various aspects of this disclosure, one method includes: accessing key derivation parameters, the key derivation parameters including: a key (source K) of the source distributed unit (DU) of a radio access network (RAN) node. DU ) and a fixed constant value (FC), where the source DU is the source of the handover to the target distributed unit (DU) of the RAN node; and the key (target K) for generating the target DU for the RAN node. DU ), the target K DU Based on the key derivation function and at least source K DU And generated by FC.

[0040] On one hand, the key derivation parameters also include the identifier of the target DU of the RAN node, and the target K DU It is also generated based on the identifier of the target DU of the RAN node.

[0041] On one hand, the key derivation parameters also include: the string "DU" and the Radio Resource Control User Equipment Identifier (RRC-UE-ID), and the target K DU It is also generated based on the string "DU" and RRC-UE-ID.

[0042] In one aspect, the key derivation parameters also include random numbers, and the target K DU It is also based on random numbers.

[0043] In one aspect, the method also includes receiving random numbers from a network device.

[0044] In one aspect, the method further includes: incrementing the counter from its original value by a predetermined amount to an incremented counter value. The key-derived parameters also include the incremented counter value, and the target K... DU It is also generated based on an incrementing counter value.

[0045] On the one hand, source K DUIt is derived based on the counter value.

[0046] In one aspect, the method also includes transmitting an incremented counter value to the target DU.

[0047] On one hand, the method also includes: based on source K DU To generate Radio Resource Control (RRC) integrity keys (K RRCint ).

[0048] On one hand, the method also includes: based on source K DU To generate Radio Resource Control (RRC) encryption keys (K RRCenc ).

[0049] On one hand, the method also includes: based on target K DU To generate Radio Resource Control (RRC) integrity keys (K RRCint ).

[0050] On one hand, the method also includes: based on target K DU To generate Radio Resource Control (RRC) encryption keys (K RRCenc ).

[0051] On the one hand, any of the aforementioned methods is executed by the UE.

[0052] On the one hand, any of the aforementioned methods is executed by the RAN node.

[0053] In various aspects of this disclosure, an apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform a method according to any of the foregoing methods.

[0054] In various aspects of this disclosure, a non-transitory processor-readable medium storage instruction, when executed by at least one processor of the device, causes the device to perform a method according to any of the foregoing methods.

[0055] The independent claims and examples are provided for some aspects. Other aspects are defined in the dependent claims and examples. Attached Figure Description

[0056] Some exemplary embodiments will now be described with reference to the accompanying drawings.

[0057] Figure 1 This is a diagram illustrating an exemplary embodiment of a wireless network between a network system and a user equipment (UE) according to an exemplary aspect of this disclosure; Figure 2This is a diagram of an example component of a network system according to an exemplary aspect of this disclosure; Figure 3 This is a diagram of an example embodiment of a functional breakdown of a wireless network architecture according to an exemplary aspect of this disclosure; Figure 4 This is a diagram of an example embodiment of a key hierarchy of a wireless network according to an exemplary aspect of this disclosure; Figure 5 This is a diagram of an example embodiment of input parameters for generating a security key according to an exemplary aspect of this disclosure; Figure 6 This is a diagram of another example embodiment of input parameters for generating a security key according to an exemplary aspect of this disclosure; Figure 7 This is a diagram of an example embodiment of vertical and horizontal key derivation for inter-RAN node handover according to an exemplary aspect of this disclosure; Figure 8 This is a diagram of an example embodiment of vertical and horizontal key derivation for distributed unit handover within a RAN node, based on an exemplary aspect of this disclosure; Figure 9 This is a diagram of an example embodiment of input parameters for generating a security key for a target distributed unit, according to an exemplary aspect of this disclosure; Figure 10 A diagram is shown as an example embodiment of an operation for generating a security key according to an exemplary aspect of this disclosure; and Figure 11 This is a diagram illustrating an example of a component of a user equipment or network device according to an exemplary aspect of this disclosure. Detailed Implementation

[0058] This disclosure relates to security keys for functional splitting in wireless network architectures, such as the functional splitting between (multiple) central units (CUs) and (multiple) distributed units (DUs) in a wireless network architecture. In various respects, the security key (K... DU The distributed unit (DU) is generated for use in radio access network (RAN) nodes. In various aspects, the security key (K...) CU-UP A security key is generated for the central cell-user plane (CU-UP) of the RAN node. In various aspects, a security key is generated for the target node during handover. The security key can be generated using a key derivation function (KDF) and various input parameters, which will be described below.

[0059] In the following description, certain specific details are set forth in order to provide a thorough understanding of the disclosed aspects. However, those skilled in the art will recognize that the aspects can be practiced without one or more of these specific details or using other methods, components, materials, etc. In other instances, well-known structures associated with transmitters, receivers, or transceivers are not shown or described in detail to avoid unnecessarily obscuring the description of the aspects.

[0060] Throughout this specification, references to "an aspect" or "an aspect" mean that a particular feature, structure, or characteristic described in connection with that aspect is included in at least one aspect. Therefore, the phrases "in an aspect" or "in a particular aspect" appearing in various places throughout this specification do not necessarily refer to the same aspect. Furthermore, a particular feature, structure, or characteristic may be combined in one or more aspects in any suitable manner.

[0061] The embodiments described in this disclosure can be implemented in wireless network devices, such as, but not limited to, devices utilizing: Global Microwave Access Interoperability (WiMAX), Global System for Mobile Communications (GSM, 2G), GSM EDGE Radio Access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunications System based on Basic Wideband Code Division Multiple Access (W-CDMA) (UMTS, 3G), High-Speed ​​Packet Access (HSPA), Long Term Evolution (LTE), Advanced LTE, Enhanced LTE (eLTE), 5G New Radio (5G NR), 5G Advanced, 6G (and higher), and 802.11ax (Wi-Fi 6), and other wireless network systems. The term 'eLTE' here refers to LTE evolution connected to a 5G core. LTE is also known as Evolved UMTS Terrestrial Radio Access (EUTRA) or Evolved UMTS Terrestrial Radio Access Network (EUTRAN).

[0062] This disclosure may use the term "serving network device" to refer to a network node or network device (or part thereof) serving a UE. As used herein, the terms "transmit to," "transmit to," "receive from," and "cooperate with" (and variations thereof) include communication that may or may not involve communication through one or more intermediate devices or nodes. The term "acquire" (and variations thereof) includes acquiring in a first instance or re-acquiring after a first instance. The term "connection" may mean a physical connection or a logical connection.

[0063] This disclosure uses 5G NR as an example of a wireless network, and may use smartphones and / or extended reality headsets as examples of UEs. It should be understood that such examples are merely illustrative, and this disclosure applies to other wireless networks and user equipment.

[0064] Figure 1 This is a diagram illustrating an example of a wireless network between network system 100 and user equipment (UE) 150. Network system 100 may include one or more network nodes 120, one or more servers 110, and / or one or more network devices 130 (e.g., test devices). Network node 120 will be described in more detail below. As used herein, the term "network apparatus" may refer to any component of network system 100, such as server 110, network node 120, network device 130, any of the foregoing components(s), and / or any other components(s) of network system 100. Examples of network apparatus include, but are not limited to, apparatuses for implementing various aspects of 5G NR. This disclosure describes embodiments related to 5G NR and embodiments relating to aspects defined by the 3rd Generation Partnership Project (3GPP). However, embodiments related to other wireless network technologies are contemplated to be included within the scope of this disclosure.

[0065] The following description provides further details of examples of network nodes. In a 5G NR network, for example, according to Section 3.2 of 3GPP TS 38.300 V16.6.0 (2021-06) (which is incorporated herein by reference), a gNodeB (also known as a gNB) may include, for example, nodes that provide new radio (NR) user plane and control plane protocol termination to the UE and are connected to the 5G core (5GC) via an NG interface.

[0066] gNB supports various protocol layers, such as Layer 1 (L1) - the physical layer, Layer 2 (L2) and Layer 3 (L3).

[0067] NR's Layer 2 (L2) is divided into the following sublayers: Media Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP), and Service Data Adaptation Protocol (SDAP), among which, for example: The physical layer provides a transmission channel to the MAC sublayer; The MAC sublayer provides logical channels to the RLC sublayer; The RLC sublayer provides RLC channels to the PDCP sublayer; The PDCP sublayer provides radio bearers to the SDAP sublayer; The SDAP sublayer provides Quality of Service (QoS) flows to 5GC; The control channels include the Broadcast Control Channel (BCCH) and the Physical Control Channel (PCCH).

[0068] For example, according to Section 6 of 3GPP TS 38.300 V16.6.0 (2021-06) (which is incorporated herein by reference), Layer 3 (L3) includes, for example, Radio Resource Control (RRC).

[0069] The gNB Central Unit (gNB-CU) includes, for example, a logical node that hosts the Service Data Adaptation Protocol (SDAP) and the gNB Packet Data Convergence Protocol (PDCP) or en-gNB PDCP, which controls the operation of one or more gNB Distributed Units (gNB-DUs). The gNB-CU terminates at the F1 interface connected to the gNB-DU. The gNB-CU may also be referred to herein as a CU, Central Unit, Centralized Unit, or Control Unit.

[0070] A gNB Distributed Unit (gNB-DU) comprises a logical node that hosts, for example, the Radio Link Control (RLC), Media Access Control (MAC), and Physical (PHY) layers of a gNB or en-gNB, and its operation is partially controlled by the gNB-CU. One gNB-DU supports one or more cells. A cell is supported by only one gNB-DU. The gNB-DU terminates at the F1 interface connected to the gNB-CU. The gNB-DU may also be referred to herein as a DU or Distributed Unit.

[0071] The gNB-CU-Control Plane (gNB-CU-CP) includes, for example, logical nodes. The gNB-CU-CP terminates the E1 interface connected to the gNB-CU-User Plane (gNB-CU-UP) and the F1-C interface connected to the gNB-DU.

[0072] The gNB-CU-User Plane (gNB-CU-UP) includes, for example, the user plane portion of the gNB-CU's PDCP protocol that hosts, for example, the en-gNB, as well as the logical nodes of the gNB's PDCP protocol and the gNB-CU's SDAP protocol. For example, according to Section 3.1 of 3GPP TS 38.401 V 16.6.0 (2021-07) (which is incorporated herein by reference), the gNB-CU-UP terminates the E1 interface connected to the gNB-CU-CP and the F1-U interface connected to the gNB-DU.

[0073] As used herein, the term "network node" may refer to any one or any combination thereof of gNB, gNB-CU, gNB-DU, gNB-CU-CP, or gNB-CU-UP.

[0074] RAN (Radio Access Network) nodes or network nodes (such as, for example, gNB, gNB-CU, or gNB-DU, or portions thereof) can be implemented using means, for example, having at least one processor and / or at least one memory and / or at least one protocol (sub)layer (e.g., layer 2 and / or layer 3) of the RAN (Radio Access Network), wherein the at least one memory has processor-readable instructions (“programs”) configured to support and / or provide and / or process CU and / or DU related functions and / or features. The following will be combined with… Figure 11 Examples of such devices and components are described below. Different functional divisions between central and distributed units are possible, and will be discussed in conjunction with these examples. Figure 3 Example description.

[0075] The gNB-CU and gNB-DU portions can, for example, be co-located or physically separated. The gNB-DU can even be further divided into two parts, for example, one including processing equipment and the other including an antenna. The Central Unit (CU) can also be referred to as a Baseband Unit / Radio Equipment Controller / Cloud-RAN / Virtual-RAN (BBU / REC / C-RAN / V-RAN), Open-RAN (O-RAN), or a portion thereof. The Distributed Unit (DU) can also be referred to as a Remote Radio Head / Remote Radio Unit / Radio Equipment / Radio Unit (RRH / RRU / RE / RU), or a portion thereof. In the various exemplary embodiments of this disclosure, a network node supporting at least one of the Central Unit functionality or Layer 3 protocols of a radio access network can be, for example, a gNB-CU. Similarly, a network node supporting at least one of the Distributed Unit functionality or Layer 2 protocols of a radio access network can be, for example, a gNB-DU.

[0076] A gNB-CU can support one or more gNB-DUs. A gNB-DU can support one or more cells, and therefore can support serving cells for user equipment (UE) or candidate cells for handover, dual connectivity and / or carrier aggregation and other procedures.

[0077] User equipment (UE) 150 may be or include wireless or mobile devices, devices having a radio interface for interacting with a RAN (Radio Access Network), smartphones, in-vehicle devices, IoT devices, or M2M devices, and other types of user equipment. Such a UE 150 may include: at least one processor; and at least one memory including program code; wherein the at least one memory and the computer program code are configured, together with the at least one processor, to cause the device to perform at least certain operations, such as establishing an RRC connection to the RAN. Figure 11Examples of components describing the UE are provided. In an embodiment, UE 150 may be configured to generate messages (e.g., including a cell ID) to be transmitted via radio to the RAN (e.g., to reach and communicate with the serving cell). In an embodiment, UE 150 may generate, transmit, and receive RRC messages containing one or more RRC PDUs (Packet Data Units). Those skilled in the art will understand the RRC protocol and other processes that the UE may perform.

[0078] Continue to refer to Figure 1 In an example of a 5G NR network, network system 100 provides one or more cells that define the coverage area of ​​network system 100. As described above, network system 100 may include a gNB of the 5G NR network, or may include any other means configured to control radio communications and manage radio resources within the cell. As used herein, the term "resource" may refer to radio resources such as resource blocks (RBs), physical resource blocks (PRBs), radio frames, subframes, time slots, subbands, frequency regions, subcarriers, beams, etc. In embodiments, network node 120 may be referred to as a base station.

[0079] Figure 1 Examples are provided, and are merely illustrative of network system 100 and UE 150. Those skilled in the art will understand that network system 100 includes... Figure 1 Components not shown in the diagram, and it will be understood that other user equipment can communicate with network system 100.

[0080] Figure 2 yes Figure 1 A block diagram of example components of network system 100. A 5G NR network can be described as an example of network system 100, and the aspects described below should also be applicable to other types of network systems. The network system can be configured according to... Figure 1 The signaling and connection operations shown enable UE 150 to communicate with network system 100 via radio access network 225. Additionally, the network system can be divided into user plane components and functions and control plane components and functions, as shown and described herein. Unless otherwise stated, the terms “component,” “function,” and “service” are used interchangeably herein and can refer to instructions executed by and implemented by one or more processors.

[0081] The following describes example functionality of the components. This example functionality is merely illustrative, and it should be understood that additional operations and functions can be performed by the components described herein. Furthermore, connections between components can be virtual connections based on service interfaces, allowing any component to communicate with any other component. In this way, any component can act as a service "producer" for any other component acting as a service "consumer" to provide services for network functionality.

[0082] For example, a core network 210 is described in the control plane of the network system. The core network 210 may include an Authentication Server Function (AUSF) 211, an Access and Mobility Management Function (AMF) 212, and a Session Management Function (SMF) 213. The core network 210 may also include a Network Slice Selection Function (NSSF) 214, a Network Exposure Function (NEF) 215, a Network Repository Function (NRF) 216, and a Unified Data Management Function (UDM) 217, which may include a Unified Data Repository (UDR) 224.

[0083] Additional components and functions of the core network 210 may include application functions 218, policy control functions (PCF) 219, network data analysis functions (NWDAF) 220, analytical data repository functions (ADRF) 221, management data analysis functions (MDAF) 222, and operation and management functions (OAM) 223.

[0084] The user plane includes UE 150, Radio Access Network (RAN) 225, User Plane Function (UPF) 226, and Data Network (DN) 227. RAN 225 may include a combination of Figure 1 The RAN 225 describes one or more components, such as one or more network nodes. However, the RAN 225 may not be limited to such components. The UPF 226 provides connectivity for data transmitted on the RAN 225. For example, DN227 identifies services from service providers, internet access, and third-party services.

[0085] AMF 212 handles connectivity and mobility tasks. AUSF 211 receives authentication requests from AMF 212 and interacts with UDM 217 to authenticate and verify network responses to determine successful authentication. SMF 213 performs Packet Data Unit (PDU) session management and manages session context with UPF 226.

[0086] NSSF 214 can select a Network Slice Instance (NSI) and determine the allowed Network Slice Selection Assistance Information (NSSAI). This selection and determination are used to configure AMF 212 to provide services to UE 150. NEF 215 guarantees access to network services for third parties to create private network services. NRF 216 acts as a repository for storing network functions to allow functions to register and discover each other.

[0087] UDM 217 generates authentication vectors for use by AUSF 211 and ADM 212 and provides user identity processing. UDM 217 can connect to UDR 224, which stores data associated with authentication, applications, etc. AF 218 provides application services (e.g., streaming services) to users. PCF 219 provides policy control functions. For example, PCF 219 can assist in network slicing and mobility management, as well as provide Quality of Service (QoS) and accounting functions.

[0088] NWDAF 220 collects data (e.g., from UE 150 and network systems) to perform network analytics and provide insights into the capabilities that utilize analytics when providing services. ADRF 221 allows consumers to store, retrieve, and remove data and analytics. MDAF 222 provides additional data analytics services for network functions. OAM 223 provides configuration and management processing capabilities to manage elements in or connected to the network (e.g., UE 150, network nodes, etc.).

[0089] Figure 2 These are merely examples of components of a network system, and variations are contemplated within the scope of this disclosure. In embodiments, the network system may include... Figure 2 Other components not shown. In embodiments, the network system may not include... Figure 2 Each component is shown. In embodiments, components and connections can utilize [the following]. Figure 2 The connections shown are implemented using different connections. These and other embodiments are contemplated within the scope of this disclosure.

[0090] As described above, in various respects, this disclosure relates to security keys for functional splitting in wireless network architectures, such as functional splitting between (multiple) central units (CUs) and (multiple) distributed units (DUs) in a wireless network architecture.

[0091] Figure 3 An example of functional splitting is shown, where the DU includes logical nodes that, in addition to hosting the RLC and MAC, host, for example, the control plane portion of the Radio Resource Control (RRC) and PDCP (PDCP-c). Various aspects of this functional splitting and architecture will now be described.

[0092] The CU is a centralized part of the RAN node (e.g., gNB) and is further divided into two sub-units: Central Unit-Control Plane (CU-CP): Manages signaling and control functions; Central Unit - User Plane (CU-UP): Handles user data processing and forwarding.

[0093] Figure 3The architecture shown includes a core network 310 (e.g., the control portion of the core network) and a user plane function (UPF) 320. Figure 3 In this architecture, both core network 310 and UPF 320 communicate with multiple radio access network (RAN) nodes, including a first RAN node 330 and a second RAN node 340. Each of the first RAN node 330 and the second RAN node 340 includes a CU-UP (central CU-UP). The first RAN node 330 includes a first DU 332, a second DU 334, and a radio unit (RU) for each DU. The second RAN node 340 includes a first DU 342, a second DU 344, and an RU for each DU. In the illustrated architecture, a common CU-CP is used for both the first RAN node 330 and the second RAN node 340. Each of these is further described below.

[0094] The CU-CP is responsible for control plane tasks, primarily focusing on signaling and session management between the User Equipment (UE) and the network. CU-CP operations may include: Control signaling management: Interface with the core network (e.g., AMF and SMF) via the N2 interface.

[0095] Coordinate mobility and paging functions.

[0096] Policy and QoS Implementation: Ensure compliance with the Quality of Service (QoS) policy in accordance with PCF and SMF.

[0097] Load balancing: Optimize resource allocation across multiple DUs and / or CU-UPs.

[0098] interface: The E1 interface is used to communicate with the CU-UP, and the logical connection enables the separation of control plane functions and user plane functions.

[0099] It interacts with the DU (Distributed Unit) via the F1-C interface.

[0100] CU-UP focuses on user plane tasks and handles the transfer of user data. CU-UP operations may include: Packet Data Convergence Protocol (PDCP): Perform header compression, encryption, and integrity protection.

[0101] Reordering and retransmission of user data packets.

[0102] Data routing and forwarding: The transmission of data packets to / from the core network is managed through User Plane Functions (UPF).

[0103] Implement data buffering during the switchover.

[0104] QoS processing: The application applies QoS rules for user plane services defined by SMF and PCF.

[0105] Mobility anchoring: Ensure seamless data transmission during mobility between cells or gNBs.

[0106] interface: It communicates with CU-CP via the E1 interface.

[0107] Use the F1-U interface to interact with the DU for user data transmission.

[0108] The benefits of splitting CU-CP and CU-UP can include: Scalability: Independently scale control plane and user plane functions according to demand (e.g., high signaling in dense areas or high data throughput in hotspots).

[0109] Centralization: Centralized processing facilitates control functions, which improves resource coordination and system efficiency.

[0110] Flexibility: Deploy CU-UP closer to the edge for latency-sensitive applications, while CU-CP can remain centralized.

[0111] Network slicing: Supports network slices with different QoS and latency requirements by dynamically allocating CU-CP and CU-UP resources.

[0112] The DU is the intermediate processing unit in the 5G RAN architecture. It is closer to the cell site than the central unit (CU), but still away from the physical antenna. The operation of the DU can include: Real-time processing: Perform time-critical operations on the Media Access Control (MAC), Radio Link Control (RLC), and Physical Layer (PHY) components.

[0113] Radio resource management: Dynamically allocate radio resources to ensure efficient spectrum use.

[0114] Error correction: Implement Hybrid Automatic Repeat Request (HARQ) for error recovery in the data link layer.

[0115] Interface interaction: It acts as a bridge between the central unit (CU) and the radio unit (RU).

[0116] Coordinate with the CU via the F1 interface (F1-C for control signaling, F1-U for user data).

[0117] Interact with the RU interface via the Lower Layer Split (LLS) interface, for example, using protocols such as the Common Public Radio Interface (CPRI) or eCPRI.

[0118] A radio unit (RU) is a hardware component located at a cell site. It is responsible for transmitting and receiving radio frequency (RF) signals and converting them for transmission to the duplex unit (DU). The operation of the RU may include: Radio frequency (RF) processing: RF transmission and reception are handled through antennas.

[0119] Implement digital front-end functions, such as digital beamforming (e.g., for the use of massive multiple-input multiple-output (MIMO) technology).

[0120] Analog-to-digital conversion: The RF signal is converted into a digital format for transmission to the DU, and vice versa.

[0121] synchronous: Maintain precise timing synchronization for advanced features such as CoMP (Co-Multi-Point Synchronization).

[0122] Antenna Management: It supports advanced antenna configurations, such as massive MIMO and millimeter-wave (mmWave) operation.

[0123] In the illustrated architecture, RRC functionality is provided in each DU, while user plane (UP) related functions are centralized in the CU-UP. Radio resource control (RRC) operations may include managing UE connection establishment, release, and mobility (handover), as well as processing RRC signaling messages between the UE and the RAN node.

[0124] Figure 3 The functional breakdown and architecture shown are merely examples, and variations are expected within the scope of this disclosure.

[0125] Now for reference Figure 4 This demonstrates the use of wireless architectures (such as...) Figure 3 The security key (for the wireless architecture). Various aspects of the security key and security architecture are described in 3GPP TS33.501 (the entire contents of which are incorporated herein by reference). As will be understood by those skilled in the art, the security key can be used for, for example, authentication, encryption, and decryption. As used herein, the security key will generally be represented by the symbol K.

[0126] This disclosure addresses two security issues.

[0127] First, this disclosure addresses the generation / export of initial security keys for functional splitting and architecture.

[0128] Second, this disclosure addresses the impact on key generation / derivation during handover when the forward secrecy principle is violated, because the source RAN node (e.g., gNB) during the handover process can use the UP key to decrypt communications in the target RAN node (e.g., gNB).

[0129] Based on all aspects of this disclosure: From key K gNB Export DU-specific key (K) DU 410.

[0130] K DU Key 410 is used to derive the RRC integrity and RRC encryption keys.

[0131] From key K gNB Export CU-UP specific key (K CU-UP 420.

[0132] K CU-UP Key 420 is used to export UP integrity and UP encryption keys.

[0133] During handover between RAN nodes (e.g., between gNBs), from the existing next-hop (NH) parameter value or K gNB After the target RAN node (e.g., gNB) key is generated, the target RAN node (e.g., gNB) will generate the DU and CU-UP keys, thus solving the forward secrecy problem.

[0134] DU Specific Key (K) DU)410 and CU-UP specific key (K CU-UP )420 can be exported separately by the UE and network device.

[0135] Figure 4 The illustrations are merely examples, and variations are expected within the scope of this disclosure.

[0136] Figure 5 and Figure 6 This illustrates the methods used to compute the initial key K using the Key Derivation Function (KDF) and various input parameters to the KDF. DU and K CU-UP Six embodiments are described. The initial key is generated in a non-handover scenario. Aspects of the KDF are described in 3GPP TS33.501. Other KDFs are anticipated within the scope of this disclosure. As described above, the DU-specific key (K... DU ) and CU-UP specific key (K CU-UP This can be exported separately by the UE and the network device.

[0137] Figure 5 Examples A, B, C, and D are shown, and Figure 6 Examples E and F are shown. In each example, when a specific key (K) is used... DU ) and CU-UP specific key (K CU-UP When generated by the UE or network, it is assumed that the UE and network already have the input parameters for generating such keys. The signaling aspects of the various embodiments are described in Table 1 below.

[0138] In embodiment A, in order to generate key K DU The input parameters to KDF include the key K. gNB A fixed constant value (FC) and the string "DU". This is used to generate the key K. CU-UP The input parameters include the key K. gNB Fixed constant value (FC) and the string "CU-UP".

[0139] In embodiment B, in order to generate key K DU The input parameters to KDF include the key K. gNB Fixed constant value (FC) and DU identifier (DU-ID). To generate key K CU-UP The input parameters include the key K. gNB Fixed constant value (FC) and CU-UP identifier (CU-UP-ID). Those skilled in the art will understand the DU identifier (DU-ID) and CU-UP identifier (CU-UP-ID). For example, the RAN node can define DU-ID and CU-UP-ID and transmit DU-ID and CU-UP-ID to the UE for the UE to use in generating keys.

[0140] In embodiment C, in order to generate key K DU The input parameters to KDF include the key K. gNB Fixed constant value (FC), Radio Network Temporary Identifier (RNTI), and the string "DU". To generate the key K... CU-UP The input parameters include the key K. gNB The fixed constant value (FC), the radio network temporary identifier (RNTI), and the string "CU-UP" are used. Those skilled in the art will understand the radio network temporary identifier (RNTI).

[0141] In embodiment D, in order to generate key K DU The input parameters to KDF include the key K. gNB Fixed constant value (FC), Radio Resource Control-UE ID (RRC-UE-ID), and the string "DU". To generate the key K... CU-UP The input parameters include the key K. gNB The values ​​are: Fixed Constant Value (FC), User Plane-UE ID (UP-UE-ID), and the string "CU-UP". Those skilled in the art will understand RRC-UE-ID and UP-UE-ID. For example, RRC-UE-ID is associated with a DU within a RAN node (e.g., gNB), not limited to hardware, and can be used for RRC connectivity between the RAN and the UE. UP-UE-ID is associated with a CU-UP within a RAN node (e.g., gNB), not limited to hardware, and can be used for user plane connectivity between the RAN and the UE.

[0142] In embodiment E, in order to generate key K DU The input parameters to KDF include the key K. gNB Fixed constant value (FC) and key K for generation DU Random numbers (RAND) DU To generate key K CU-UP The input parameters include the key K. gNB Fixed constant value (FC) and key K for generation CU-UP Random numbers (RAND) CU-UP In an embodiment, when the UE generates a key, the random number RAND... DU and RAND CU-UP It can be transmitted from the network to the UE.

[0143] In embodiment F, in order to generate key K DU The input parameters to KDF include the key K. gNB Fixed constant value (FC) and key K for generation DUThe counter value (COUNT) DU To generate key K CU-UP The input parameters include the key K. gNB Fixed constant value (FC) and key K for generation CU-UP The counter value (COUNT) CU-UP In this embodiment, when the UE generates a key, the UE can maintain a counter value COUNT. DU and COUNT CU-UP .

[0144] Figure 5 and Figure 6 The effects of the various embodiments shown are as follows, including the impact on security during handover (HO) and the impact on signaling.

[0145]

[0146] Figure 5 and Figure 6 The embodiments shown are merely examples, and variations are contemplated within the scope of this disclosure.

[0147] Figure 7 It is a graph of various aspects of key generation for handover scenarios between RAN nodes (e.g., between gNBs), such as Figure 3 The handover from RAN node 330 to RAN node 340. During the handover between RANs (e.g., between gNBs), K... AMF The key is used to derive K gNB Key and next-hop (NH) value, for example, Figure 4 As shown in the diagram. Those skilled in the art will understand the NH value and will understand the method used to derive K. gNB This process involves the key and the next-hop (NH) value.

[0148] Continue to refer to Figure 7 For inter-RAN node handover to a target RAN node (e.g., gNB), the source RAN node (e.g., gNB) can use vertical key derivation or horizontal key derivation to generate the key for the target RAN node (target K). gNB ).like Figure 7 As shown, the vertical key derivation uses the NH value received from the AMF to generate the key for the target RAN node (target K). gNB ), while horizontal key derivation uses the Physical Cell Identifier (PCI) and downlink (DL) frequency to generate the key for the target RAN node (target K). gNB After a successful switchover, the key of the target RAN node (target K) gNB ) used to generate DU key (K DU ) and CU-UP key (KCU-UP This is then used to generate the UP key and RRC key for the target RAN node, such as Figure 4 As shown in the image.

[0149] Figure 7 This is merely an example, and variations are expected within the scope of this disclosure.

[0150] Figure 8 This is a diagram illustrating various aspects of key generation for DU handover scenarios within a RAN node (e.g., within a gNB). As an example, DU handover within a RAN node can involve (about...) Figure 3 The handover from DU 332 to DU 334 in RAN node 330, or from DU 342 to DU 344 in RAN node 340. During DU handover within a RAN node (e.g., within a gNB), K AMF The key is used to derive K gNB Key and next-hop (NH) value, for example, Figure 4 As shown. Those skilled in the art will understand the NH value and will understand the use of it to derive K. gNB This process involves the key and the next-hop (NH) value.

[0151] Continue to refer to Figure 8 For intra-RAN node handover to the target DU, the source DU and / or UE can use vertical key export or horizontal key export to export the target DU's key (target K). DU ).like Figure 8 As shown, the vertical key derivation uses the NH value received from the AMF to generate the key (target K) for the target DU. DU ), while horizontal key derivation uses the Physical Cell Identifier (PCI) and downlink (DL) frequencies to generate the key for the target DU (target K). DU Since the handover is a DU handover within the RAN node, no new UP key will be generated; only the RRC integrity and RRC encryption key for the target DU will be generated.

[0152] According to various aspects of this disclosure, other parameters may be used by the UE and / or the source DU to generate the key for the target DU, instead of using the PCI and DL frequencies for horizontal key derivation. Figure 9 Four embodiments are shown below.

[0153] In Example 1, in order to generate the key (target K) for the target DU DU The input parameters to the KDF include the key of the source DU (source K). DUThe target DU identifier (DU-ID) consists of a fixed constant value (FC) and a target DU identifier. Those skilled in the art will understand the target DU identifier (DU-ID). For example, a RAN node can define a target DU identifier (DU-ID) and transmit it to the UE for use in generating the key for the target DU.

[0154] In Example 2, in order to generate the key (target K) for the target DU DU The input parameters to the KDF include the key of the source DU (source K). DU The parameters are: a fixed constant value (FC), a radio resource control-UE ID (RRC-UE-ID), and the string "DU". Those skilled in the art will understand the RRC-UE-ID. For example, a RAN node can define the RRC-UE-ID and transmit it to the UE to be used as a key for generating the target DU.

[0155] In Example 3, in order to generate the key (target K) for the target DU DU The input parameters to the KDF include the key of the source DU (source K). DU ), a fixed constant value (FC), and a key (target K) used to generate the target DU. DU Random numbers (RAND) DU In this embodiment, when the UE generates a key, a random number RAND can be transmitted from the network to the UE. DU .

[0156] In Example 4, in order to generate the key (target K) for the target DU DU The input parameters to the KDF include the key of the source DU (source K). DU ), a fixed constant value (FC), and a key (target K) used to generate the target DU. DU The counter value (COUNT) DU In this embodiment, when the UE generates a key, the UE can maintain the counter value COUNT. DU For example, COUNT DU The value of COUNT can initially be 0 or some other initial value. For each switch to the target DU, COUNT can be... DU The value is incremented by 1 or some other predetermined increment, and the resulting COUNT is... DU It can be provided to the target DU. For other switching, COUNT DU The value can be similarly incremented and provided to another target DU.

[0157] Figure 9 The embodiments shown are merely illustrative, and variations are contemplated within the scope of this disclosure.

[0158] Now for reference Figure 10The flowchart illustrates an example of operation in a UE or network device.

[0159] At box 1010, the operation involves accessing key export parameters. Key export parameters may include combinations of... Figure 5 , Figure 6 and Figure 9 Any of the parameters described.

[0160] In box 1020, this operation involves generating a first key (K) for the distributed unit of the radio access network (RAN) node. DU The first key is generated using a key derivation function and at least some of the key derivation parameters. Aspects of the key derivation function are described in 3GPP TS 33.501. Other key derivation functions are expected to be within the scope of this disclosure. The first key (K...) DU ) can be used, for example, in combination Figure 5 , Figure 6 or Figure 9 Any of the embodiments described can be used to generate it.

[0161] At box 1030, the operation involves generating a second key (K) for the user plane of the central unit of the RAN node. CU-UP The second key is generated using a key derivation function and at least some of the key derivation parameters. CU-UP ) can be used, for example, in combination Figure 5 or Figure 6 Any of the embodiments described can be used to generate it.

[0162] Figure 10 The operations described are merely examples, and variations are contemplated within the scope of this disclosure. In embodiments, the operations may include... Figure 10 Other boxes not shown in the diagram. In embodiments, the operation may not include... Figure 10 Each box is shown. These and other embodiments are contemplated within the scope of this disclosure.

[0163] Now for reference Figure 11The diagram illustrates a block diagram of example components of a UE or network device. The device includes electronic memory (e.g., a non-transitory processor-readable medium) 1110, a processor 1120, memory 1150, and a network interface 1140. The various components can be communicatively coupled to each other. Processor 1120 can be and may include any type of processor, such as a single-core central processing unit (CPU), a multi-core CPU, a microprocessor, a digital signal processor (DSP), a system-on-a-chip (SoC), or any other type of processor. Memory 1150 can be a volatile type of memory, such as RAM, or a non-volatile type of memory, such as NAND flash memory. Memory 1150 includes operations executable by processor 1120 to cause the device to perform various operations (including those mentioned herein, such as combination). Figure 3-10 The processor-readable instructions (described in the instructions).

[0164] Electronic storage device 1110 can be and includes any type of electronic storage device for storing data, such as hard disk drives, solid-state drives, and / or optical disks, as well as other types of electronic storage devices. Electronic storage device 1110 stores processor-readable instructions for causing the device to perform its operations and storing data associated with such operations (such as storing data related to the 5G NR standard). Network interface 1140 can implement wireless network technologies, such as 5G NR and / or other wireless network technologies.

[0165] Figure 11 The components shown are merely examples, and those skilled in the art will understand that the apparatus includes other components not shown, and may include multiple components of any shown. These and other embodiments are contemplated within the scope of this disclosure.

[0166] Other embodiments of this disclosure include the following examples. In the following text, any "component" may be implemented by at least one processor and processor-executable instructions, unless the context otherwise indicates. Any "component" for receiving or transmitting may be implemented by a transceiver. The symbol example nx refers to any example having a value for n and a value for x.

[0167] Example 1.1. A method comprising: Access key export parameters; Generate the first key (K) for the distributed cell used in the Radio Access Network (RAN) node. DU The first key is generated based on the key derivation function and at least some of the key derivation parameters; and Generate a second key (K) for the user plane of the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0168] Example 1.2. The method of Example 1.1, The key export parameters include: RAN node key (K gNB ),as well as Fixed constant value (FC). The first key (K) DU ) is based on K gNB And generated by FC, and The second key (K) CU-UP ) is based on K gNB And generated by FC.

[0169] Example 1.3. The method of Example 1.2, The key export parameters also include the string "DU", and Among them, the first key (K) DU It is also generated based on the string "DU".

[0170] Example 1.4. The method of Example 1.2 or Example 1.3, The key export parameters also include the string "CU-UP", and The second key (K) CU-UP It is also generated based on the string "CU-UP".

[0171] Example 1.5. A method from any of Examples 1.2 to 1.4, wherein the key-derived parameter further includes an identifier. Among them, the first key (K) DU It is also generated based on identifiers, and Among them, the second key (K) CU-UP () is also generated based on identifiers.

[0172] Example 1.6. The method of Example 1.2, The key export parameters also include the identifier of the distributed unit (DU-ID) of the RAN node. Among them, the first key (K) DU It is also generated based on DU-ID.

[0173] Example 1.7. The method of Example 1.2 or Example 1.6, The key export parameters also include the user plane identifier (CU-UP-ID) of the central unit of the RAN node. Among them, the second key (K) CU-UP It is also generated based on CU-UP-ID.

[0174] Example 1.8. The method of either Example 1.3 or Example 1.4, The key derivation parameters also include the Radio Network Temporary Identifier (RNTI). Among them, the first key (K) DU It is also generated based on RNTI.

[0175] Example 1.9. The method of any one of Examples 1.3, 1.4, or 1.8. The key derivation parameters also include the Radio Network Temporary Identifier (RNTI). The second key (K) CU-UP It is also generated based on RNTI.

[0176] Example 1.10. The method of either Example 1.3 or Example 1.4, Among them, the key export parameters also include the Radio Resource Control User Equipment Identifier (RRC-UE-ID). Among them, the first key (K) DU It is also generated based on RRC-UE-ID.

[0177] Example 1.11. The method of any one of Example 1.3, Example 1.4, or Example 1.10, The key export parameters also include the user plane user equipment identifier (UP-UE-ID). Among them, the second key (K) CU-UP It is also generated based on UP-UE-ID.

[0178] Example 1.12. The method of any one of Examples 1.1 through 1.11 also includes: Based on the first key (K) DU Generate Radio Resource Control (RRC) Integrity Key (K) RRCint ).

[0179] Example 1.13. The method of any one of Examples 1.1 to 1.12 also includes: Based on the first key (K) DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0180] Example 1.14. The method of any one of Examples 1.1 through 1.13 also includes: Based on the second key (K) CU-UP Generate User Plane (UP) Integrity Key (K) UPint ).

[0181] Example 1.15. The method of any one of Examples 1.1 through 1.14 also includes: Based on the second key (K) CU-UP Generate user plane (UP) encryption key (K) UPenc ).

[0182] Example 1.16. A method of any one of Examples 1.1 through 1.15, wherein the method is performed in a User Equipment (UE).

[0183] Example 1.17. A method of any one of Examples 1.1 to 1.15, wherein the method is executed in a RAN node.

[0184] Example 1.18. An apparatus comprising: At least one processor; and At least one memory storing instructions that, when executed by at least one processor, cause the device to perform a method as described in any one of Examples 1.1 to 1.17.

[0185] Example 1.19. A non-transitory processor-readable medium storing instructions that, when executed by at least one processor of a device, cause the device to perform a method as described in any of Examples 1.1 to 1.17.

[0186] Example 2.1. An apparatus comprising: A component used to access key export parameters; The first key (K) used to generate the distributed unit for Radio Access Network (RAN) nodes. DU The first key is generated based on at least some of the key-derived parameters in the key-derived function and key-derived parameters; and The second key (K) used to generate the user plane for the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0187] Example 2.2. The apparatus of Example 2.1, The key export parameters include: RAN node key (K gNB ),as well as Fixed constant value (FC). The first key (K) DU ) is based on K gNB And generated by FC, and The second key (K) CU-UP ) is based on K gNB And generated by FC.

[0188] Example 2.3. The apparatus of Example 2.2, The key export parameters also include the string "DU", and The first key (K) DU It is also generated based on the string "DU".

[0189] Example 2.4. The apparatus of Example 2.2 or Example 2.3, The key export parameters also include the string "CU-UP", and The second key (K) CU-UP It is also generated based on the string "CU-UP".

[0190] Example 2.5. An apparatus of any one of Examples 2.2-2.4, wherein the key-derived parameters further include an identifier. Among them, the first key (K) DU It is also generated based on identifiers, and Among them, the second key (K) CU-UP () is also generated based on identifiers.

[0191] Example 2.6. The apparatus of Example 2.2, The key export parameters also include the identifier of the distributed unit (DU-ID) of the RAN node. Among them, the first key (K) DU It is also generated based on DU-ID.

[0192] Example 2.7. The apparatus of Example 2.2 or Example 2.6, The key export parameters also include the user plane identifier (CU-UP-ID) of the central unit of the RAN node. Among them, the second key (K) CU-UP It is also generated based on CU-UP-ID.

[0193] Example 2.8. An apparatus of any one of Example 2.3 or Example 2.4, The key derivation parameters also include the Radio Network Temporary Identifier (RNTI). Among them, the first key (K) DU It is also generated based on RNTI.

[0194] Example 2.9. An apparatus of any one of Examples 2.3, 2.4, or 2.8. The key derivation parameters also include the Radio Network Temporary Identifier (RNTI). The second key (K) CU-UP It is also generated based on RNTI.

[0195] Example 2.10. An apparatus of any one of Example 2.3 or Example 2.4, Among them, the key export parameters also include the Radio Resource Control User Equipment Identifier (RRC-UE-ID). Among them, the first key (K) DU It is also generated based on RRC-UE-ID.

[0196] Example 2.11. An apparatus of any one of Example 2.3, Example 2.4, or Example 2.10, The key export parameters also include the user plane user equipment identifier (UP-UE-ID). Among them, the second key (K) CU-UP It is also generated based on UP-UE-ID.

[0197] Example 2.12. The apparatus of any one of Examples 2.1 to 2.11 further includes: Used based on the first key (K) DU To generate the Radio Resource Control (RRC) integrity key (K) RRCint ) components.

[0198] Example 2.13. The apparatus of any one of Examples 2.1 to 2.12 further includes: Used based on the first key (K) DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ) components.

[0199] Example 2.14. The apparatus of any one of Examples 2.1 to 2.13 further includes: Used based on the second key (K) CU-UP Generate User Plane (UP) Integrity Key (K) UPint ) components.

[0200] Example 2.15. The apparatus of any one of Examples 2.1 to 2.14 further includes: Used based on the second key (K) CU-UP Generate user plane (UP) encryption key (K) UPenc ) components.

[0201] Example 3.1. A method comprising: Access the key export parameters, which include: Key (K) of Radio Access Network (RAN) nodes gNB ), Fixed constant value (FC). The first random number, and Second random number; Generate the first key (K) for the distributed unit of the RAN node. DU The first key is generated based on a key derivation function and at least some key derivation parameters; and Generate a second key (K) for the user plane of the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0202] Example 3.2. The method of Example 3.1, wherein the first key (K) DU ) is based on K gNB FC and the first random number are generated.

[0203] Example 3.3. The method of Example 3.1 or Example 3.2, wherein the second key (K) CU-UP ) is based on K gNB FC and the second random number are generated.

[0204] Example 3.4. The method of any one of Examples 3.1 to 3.3 also includes: Receive a first random number and a second random number from the network device.

[0205] Example 3.5. The method of any one of Examples 3.1 to 3.4 also includes: Generate a third key (target K) for the target distributed unit used for switching. DU The third key is based on the key derivation function and the first key (K). DU ), FC, and third random number generation.

[0206] Example 3.6. The methods in Example 3.5 also include: Receive a third random number from the network device.

[0207] Example 3.7. The method of any one of Examples 3.1 through 3.6 also includes: Based on the first key (K) DU Generate Radio Resource Control (RRC) Integrity Key (K) RRCint ).

[0208] Example 3.8. The method of any one of Examples 3.1 through 3.7, further includes: Based on the first key (K) DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0209] Example 3.9. The method of any one of Examples 3.1 through 3.8 also includes: Based on the second key (K) CU-UP Generate User Plane (UP) Integrity Key (K) UPint ).

[0210] Example 3.10. The method of any one of Examples 3.1 through 3.9 also includes: Based on the second key (K) CU-UP Generate user plane (UP) encryption key (K) UPenc ).

[0211] Example 3.11. A method of any one of Examples 3.1 to 3.10, wherein the method is performed in a User Equipment (UE).

[0212] Example 3.12. A method of any one of Examples 3.1 through 3.10, wherein the method is executed in a RAN node.

[0213] Example 3.13. An apparatus comprising: At least one processor; and At least one memory storing instructions that, when executed by at least one processor, cause the device to perform a method as described in any one of Examples 3.1 to 3.12.

[0214] Example 3.14. A non-transitory processor-readable medium storing instructions that, when executed by at least one processor of a device, cause the device to perform the methods of any one of Examples 3.1 to 3.12.

[0215] Example 4.1. An apparatus comprising: The component for accessing key export parameters includes: Key (K) of Radio Access Network (RAN) nodes gNB ), Fixed constant value (FC). The first random number, and Second random number; Used to generate the first key (K) for the distributed unit of the RAN node. DU The first key is generated based on at least some of the key-derived parameters in the key-derived function and key-derived parameters; and The second key (K) used to generate the user plane for the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0216] Example 4.2. The apparatus of Example 4.1, wherein the first key (K) DU ) is based on K gNB FC and the first random number are generated.

[0217] Example 4.3. An apparatus of Example 4.1 or Example 4.2, wherein the second key (K) CU-UP ) is based on K gNB FC and the second random number are generated.

[0218] Example 4.4. The apparatus of any one of Examples 4.1 to 4.3 further includes: A component for receiving a first random number and a second random number from a network device.

[0219] Example 4.5. The apparatus of any one of Examples 4.1 to 4.4 further includes: The third key (target K) used to generate the target distributed unit for switching. DU The third key is based on the key derivation function and the first key (K). DU ), FC, and third random number generation.

[0220] Example 4.6. The apparatus of Example 4.5 further includes: A component used to receive a third random number from a network device.

[0221] Example 4.7. The apparatus of any one of Examples 4.1 to 4.6 further includes: Used based on the first key (K) DU To generate the Radio Resource Control (RRC) integrity key (K) RRCint ) components.

[0222] Example 4.8. The apparatus of any one of Examples 4.1 to 4.7 further includes: Used based on the first key (K) DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ) components.

[0223] Example 4.9. The apparatus of any one of Examples 4.1 to 4.8 further includes: Used based on the second key (K) CU-UP Generate User Plane (UP) Integrity Key (K) UPint ) components.

[0224] Example 4.10. The apparatus of any one of Examples 4.1 to 4.9 further includes: Used based on the second key (K) CU-UP Generate user plane (UP) encryption key (K)UPenc ) components.

[0225] Example 5.1. A method comprising: Access key export parameters include: Key (K) of Radio Access Network (RAN) nodes gNB ), Fixed constant value (FC). The first counter value provided by the first counter, and The second counter value is provided by the second counter; Generate the first key (K) for the distributed unit of the RAN node. DU The first key is generated based on the key derivation function and at least some of the key derivation parameters; and Generate a second key (K) for the user plane of the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0226] Example 5.2. The method of Example 5.1, wherein the first key (K) DU ) is based on K gNB It is generated from FC and the first counter value.

[0227] Example 5.3. The method of Example 5.1 or Example 5.2, wherein the second key (K) CU-UP ) is based on K gNB It is generated from the values ​​of the FC and the second counter.

[0228] Example 5.4. The method of any one of Examples 5.1 to 5.3 also includes: Increment the first counter by a predetermined amount to provide the incremented first counter value; and Generate a third key (target K) for secure communication with the target distributed unit (DU) during the handover. DU The third key is based on the key derivation function and the first key (K). DU It is generated by FC and the incremented first counter value.

[0229] Example 5.5. The method in Example 5.4 also includes: The incremented first counter value is transmitted to the target DU.

[0230] Example 5.6. The method of any one of Examples 5.1 to 5.5 also includes: Based on the first key (K) DU Generate Radio Resource Control (RRC) Integrity Key (K)RRCint ).

[0231] Example 5.7. The method of any one of Examples 5.1 through 5.6 also includes: Based on the first key (K) DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0232] Example 5.8. The method of any one of Examples 5.1 through 5.7, further includes: Based on the second key (K) CU-UP Generate User Plane (UP) Integrity Key (K) UPint ).

[0233] Example 5.9. The method of any one of Examples 5.1 through 5.8, further includes: Based on the second key (K) CU-UP Generate user plane (UP) encryption key (K) UPenc ).

[0234] Example 5.10. A method of any one of Examples 5.1 through 5.9, wherein the method is performed in a User Equipment (UE).

[0235] Example 5.11. A method of any one of Examples 5.1 through 5.9, wherein the method is executed in a RAN node.

[0236] Example 5.12. An apparatus comprising: At least one processor; and At least one memory storing instructions that, when executed by at least one processor, cause the device to perform a method as described in any one of Examples 5.1 to 5.11.

[0237] Example 5.13. A non-transitory processor-readable medium storing instructions that, when executed by at least one processor of a device, cause the device to perform a method as described in any of Examples 5.1 to 5.11.

[0238] Example 6.1. An apparatus comprising: The component for accessing key export parameters includes: Key (K) of Radio Access Network (RAN) nodes gNB ), Fixed constant value (FC). The first counter value provided by the first counter, and The second counter value is provided by the second counter; Used to generate the first key (K) for the distributed unit of the RAN node.DU The first key is generated based on at least some of the key-derived parameters in the key-derived function and key-derived parameters; and The second key (K) used to generate the user plane for the central unit of the RAN node. CU-UP The second key is generated based on the key derivation function and at least some of the key derivation parameters.

[0239] Example 6.2. The apparatus of Example 6.1, wherein the first key (K) DU ) is based on K gNB It is generated from FC and the first counter value.

[0240] Example 6.3. An apparatus of Example 6.1 or Example 6.2, wherein the second key (K) CU-UP ) is based on K gNB It is generated from the values ​​of the FC and the second counter.

[0241] Example 6.4. The apparatus of any one of Examples 6.1 to 6.3 further includes: Components for incrementing a first counter by a predetermined amount to provide a first incremented counter value; and A third key (target K) is used to generate secure communication with the target distributed unit (DU) during switching. DU The third key is based on the key derivation function and the first key (K). DU It is generated by FC and the first incremented counter value.

[0242] Example 6.5. The apparatus of Example 6.4 further includes: A component used to transmit the first incremented counter value to the target DU.

[0243] Example 6.6. The apparatus of any one of Examples 6.1 to 6.5 further includes: Used based on the first key (K) DU To generate the Radio Resource Control (RRC) integrity key (K) RRCint ) components.

[0244] Example 6.7. The apparatus of any one of Examples 6.1 to 6.6 further includes: Used based on the first key (K) DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ) components.

[0245] Example 6.8. The apparatus of any one of Examples 6.1 to 6.7 further includes: Used based on the second key (K)CU-UP Generate User Plane (UP) Integrity Key (K) UPint ) components.

[0246] Example 6.9. The apparatus of any one of Examples 6.1 to 6.8 further includes: Used based on the second key (K) CU-UP Generate user plane (UP) encryption key (K) UPenc ) components.

[0247] Example 7.1. A method includes: Access key export parameters, which include: The key (source K) of the source distributed unit (DU) of the radio access network (RAN) node. DU ),as well as Fixed constant value (FC). Here, the source DU is the source of the handover to the target distributed unit (DU) of the RAN node; and Generate the key (target K) for the target DU of the RAN node. DU ), target K DU Based on the key derivation function and at least source K DU And FC generation.

[0248] Example 7.2. The method of Example 7.1, The key export parameters also include the identifier of the target DU for the RAN node. The target KDU is also generated based on the identifier of the target DU of the RAN node.

[0249] Example 7.3. The method of Example 7.1, The key export parameters also include: The string "DU", and Radio Resource Control User Equipment Identifier (RRC-UE-ID) Where the target K DU It is also generated based on the string "DU" and RRC-UE-ID.

[0250] Example 7.4. The method of Example 7.1, The key derivation parameters also include random numbers. Where the target K DU It is also based on random number generation.

[0251] Example 7.5. The method in Example 7.4 also includes: Receive random numbers from network devices.

[0252] Example 7.6. The method in Example 7.1 also includes: The counter is incremented from its original value by a predetermined amount to the incremented counter value. The key derivation parameters also include an incremented counter value. Where the target K DU It is also generated based on an incrementing counter value.

[0253] Example 7.7. The method of Example 7.6, where the source K DU It is derived based on the counter value.

[0254] Example 7.8. The methods in Example 7.6 or Example 7.7 also include: Transmit the incremented counter value to the target DU.

[0255] Example 7.9. The method of any one of Examples 7.1 through 7.8, further includes: Based on source K DU Generate Radio Resource Control (RRC) Integrity Key (K) RRCint ).

[0256] Example 7.10. The method of any one of Examples 7.1 through 7.9 also includes: Based on source K DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0257] Example 7.11. The method of any one of Examples 7.1 through 7.10 also includes: Based on target K DU Generate Radio Resource Control (RRC) Integrity Key (K) RRCint ).

[0258] Example 7.12. The method of any one of Examples 7.1 through 7.11 also includes: Based on target K DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0259] Example 7.13. A method of any one of Examples 7.1 to 7.12, wherein the method is executed in a user equipment (UE).

[0260] Example 7.14. A method of any one of Examples 7.1 through 7.12, wherein the method is executed in a RAN node.

[0261] Example 7.15. An apparatus comprising: At least one processor; and At least one memory storing instructions that, when executed by at least one processor, cause the device to perform a method as described in any one of Examples 7.1 to 7.14.

[0262] Example 7.16. A non-transitory processor-readable medium storing instructions that, when executed by at least one processor of a device, cause the device to perform a method as described in any of Examples 7.1 to 7.14.

[0263] Example 8.1. An apparatus comprising: The component for accessing key export parameters includes: The key (source K) of the source distributed unit (DU) of the radio access network (RAN) node. DU ),as well as Fixed constant value (FC). Here, the source DU is the source of the handover to the target distributed unit (DU) of the RAN node; and The key (target K) used to generate the target DU for the RAN node. DU ) of the component, target K DU Based on the key derivation function and at least source K DU And generated by FC.

[0264] Example 8.2. The apparatus of Example 8.1, The key derivation parameters also include the identifier of the target DU of the RAN node. Among them, target K DU It is also generated based on the identifier of the target DU of the RAN node.

[0265] Example 8.3. The apparatus of Example 8.1, The key export parameters also include: The string "DU", and Radio Resource Control User Equipment Identifier (RRC-UE-ID) Among them, target K DU It is also generated based on the string "DU" and RRC-UE-ID.

[0266] Example 8.4. The apparatus of Example 8.1, The key derivation parameters also include random numbers. Where the target K DU It is also based on random number generation.

[0267] Example 8.5. The apparatus of Example 8.4 further includes: A component used to receive random numbers from network devices.

[0268] Example 8.6. The apparatus of Example 8.1 further includes: A component used to increment a counter from its original value by a predetermined amount to the incremented counter value. The key derivation parameters also include an incremented counter value. Where the target K DU It is also generated based on an incrementing counter value.

[0269] Example 8.7. The apparatus of Example 8.6, wherein source K DU It is derived based on the counter value.

[0270] Example 8.8. The apparatus of Example 8.6 or Example 8.7 further includes: A component used to transmit an incremented counter value to the target DU.

[0271] Example 8.9. The apparatus of any one of Examples 8.1 to 8.8 further includes: Used for source K DU To generate Radio Resource Control (RRC) integrity keys (K RRCint ) components.

[0272] Example 8.10. The apparatus of any one of Examples 8.1 to 8.9 further includes: Used for source K DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ) components.

[0273] Example 8.11. The apparatus of any one of Examples 8.1 to 8.10 further includes: Used for target K DU To generate Radio Resource Control (RRC) integrity keys (K RRCint ) components.

[0274] Example 8.12. The apparatus of any one of Examples 8.1 to 8.11 further includes: Used for target K DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ) components.

[0275] The embodiments and aspects disclosed herein are examples of this disclosure and may be embodied in various forms. For example, although some embodiments herein are described as separate embodiments, each of the embodiments herein may be combined with one or more of the other embodiments herein. The specific structural and functional details disclosed herein should not be construed as limiting, but rather serve as the basis for the claims and as a representative basis for teaching those skilled in the art to adopt this disclosure differently from virtually any suitable detailed structure. Throughout the description of the drawings, the same reference numerals may refer to similar or identical elements.

[0276] The phrases “in one aspect,” “in all aspects,” “in all dimensions,” “in some aspects,” or “in other aspects” may each refer to one or more of the same or different aspects under this disclosure. The phrase “multiple” may refer to two or more.

[0277] The phrases “in embodiments,” “in various embodiments,” “in various embodiments,” “in some embodiments,” or “in other embodiments” may each refer to one or more of the same or different embodiments according to this disclosure. A phrase in the form of “A or B” means “(A), (B), or (A and B).” A phrase in the form of “at least one of A, B, or C” means “(A); (B); (C); (A and B); (A and C); (B and C); or (A, B, and C).”

[0278] Any of the methods, programs, algorithms, or code described herein can be converted into or expressed in a programming language or computer program. As used herein, the terms “programming language” and “computer program” each include any language used to specify instructions to a computer, and include (but are not limited to) the following languages ​​and their derivatives: assembler, Basic, batch file, BCPL, C, C++, Delphi, Fortran, Java, JavaScript, machine code, operating system command languages, Pascal, Perl, PL1, Python, scripting languages, Visual Basic, meta-languages ​​that specify their own programs, and all first, second, third, fourth, fifth, or later generation computer languages. Databases and other data schemas, as well as any other meta-languages, are also included. There is no distinction between languages ​​that are interpreted, compiled, or use both compilation and interpretation methods. There is no distinction between a compiled version and a source version of a program. Therefore, a reference to a program in which a programming language may exist in more than one state (such as source, compilation, object, or linking) is a reference to any and all such states. A reference to a program may encompass the actual instructions and / or the intent of those instructions.

[0279] While various aspects of this disclosure have been shown in the accompanying drawings, they are not intended to be limited thereto, as the intention is to make the scope of the disclosure as broad as is permissible in the art, and the specification should be interpreted in the same manner. Therefore, the foregoing description should not be construed as restrictive, but merely as an example of certain aspects. Other modifications will be contemplated by those skilled in the art within the scope and spirit of the appended claims.

[0280] Furthermore, the various implementations of this disclosure can be described with reference to the following terms, and their features can be combined in any reasonable manner.

[0281] Clause 1. A method comprising: accessing key derivation parameters, the key derivation parameters including: a source distributed unit (DU) key (source K) of a radio access network (RAN) node. DU ), and a fixed constant value (FC), where the source DU is the source for switching to the target distributed unit (DU) of the RAN node; and a key (target K) for generating the target DU for the RAN node. DU ), target K DU Based on the key derivation function and at least source K DU It is generated by FC.

[0282] Clause 2. According to the method of Clause 1, the key derivation parameters further include the identifier of the target DU of the RAN node, wherein the target K DU It is also generated based on the identifier of the target DU of the RAN node.

[0283] Clause 3. According to the method of Clause 1, the key derivation parameters further include: the string "DU", and the Radio Resource Control User Equipment Identifier (RRC-UE-ID), wherein the target K DU It is also generated based on the string "DU" and RRC-UE-ID.

[0284] Clause 4. The method according to Clause 1, wherein the key derivation parameter further includes a random number, wherein the target K DU It is also generated based on random numbers.

[0285] Clause 5. The method pursuant to Clause 4 also includes: receiving a random number from a network device.

[0286] Clause 6. The method according to Clause 1 further includes: incrementing the counter from a counter value by a predetermined amount to an incremented counter value, wherein the key derivation parameter further includes the incremented counter value, wherein the target K DU It is also generated based on an incremented counter value.

[0287] Clause 7. According to the method of Clause 6, where source K DUIt is derived based on the counter value.

[0288] Clause 8. The method according to Clause 6 or Clause 7 also includes: transmitting an incremented counter value to the target DU.

[0289] Clause 9. The method pursuant to any one of Clauses 1 to 8 further includes: based on source K DU Generate Radio Resource Control (RRC) Integrity Key (K) RRCint ).

[0290] Clause 10. The method pursuant to any one of Clauses 1 to 9 further includes: based on source K DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0291] Clause 11. The method according to any one of Clauses 1 to 10 further includes: based on target K DU Generate Radio Resource Control (RRC) Integrity Key (K) RRCint ).

[0292] Clause 12. The method according to any one of Clauses 1 to 11 further includes: based on target K DU Generate Radio Resource Control (RRC) encryption key (K) RRCenc ).

[0293] Clause 13. The method according to any one of Clauses 1 to 12, wherein the method is performed in a user equipment (UE).

[0294] Clause 14. The method according to any one of Clauses 1 to 12, wherein the method is performed in the RAN node.

[0295] Clause 15. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform a method according to any one of Clauses 1 to 14.

[0296] Clause 16. A non-transitory processor-readable medium storing instructions that, when executed by at least one processor of the apparatus, cause the apparatus to perform a method according to any one of Clauses 1 to 14.

Claims

1. A method for key derivation, comprising: Access key export parameters, which include: The key source K of the source distributed unit (DU) of the radio access network (RAN) node. DU ,as well as Fixed constant value FC, The source DU is the source of the switching to the target distributed unit DU of the RAN node; and Generate key target K for the target DU of the RAN node. DU The target K DU Based on the key derivation function and at least the source K DU It is generated by the FC.

2. The method according to claim 1, The key export parameters also include the identifier of the target DU of the RAN node. The target K DU It is also generated based on the identifier of the target DU of the RAN node.

3. The method according to claim 1, The key export parameters also include: The string "DU", and Radio Resource Control User Equipment Identifier (RRC-UE-ID) The target K DU It is also generated based on the string "DU" and the RRC-UE-ID.

4. The method according to claim 1, The key derivation parameters also include random numbers. The target K DU It is also generated based on the random number.

5. The method according to claim 4, further comprising: Receive the random number from the network device.

6. The method according to claim 1, further comprising: The counter is incremented from its original value by a predetermined amount to the incremented counter value. The key derivation parameters also include the incremented counter value. The target K DU It is also generated based on the incremented counter value.

7. The method of claim 6, wherein the source K DU It is derived based on the counter value.

8. The method according to claim 6 or claim 7, further comprising: The incremented counter value is transmitted to the target DU.

9. The method according to any one of claims 1 to 7, further comprising: Based on the source K DU Generate Radio Resource Control (RRC) Integrity Key K RRCint .

10. The method according to any one of claims 1 to 7, further comprising: Based on the source K DU Generate Radio Resource Control (RRC) encryption key K RRCenc .