Access control in centralized unit split architecture

CN122580908APending Publication Date: 2026-08-14ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-12
Publication Date
2026-08-14

Smart Images

  • Figure CN122580908A_ABST
    Figure CN122580908A_ABST
Patent Text Reader

Abstract

Example embodiments of this disclosure relate to methods, apparatus, devices, and computer-readable storage media for access control in a centralized unit (CU) split architecture. The method includes: after a connection is established between a second device and a third device, determining at a first device one or more parameters associated with mobility restrictions for the third device; and transmitting the one or more parameters associated with the mobility restrictions and one or more connection keys to the second device as part of at least one connection-related message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various exemplary embodiments of this disclosure generally relate to the telecommunications field, and more specifically to methods, apparatuses, devices, and computer-readable storage media for access control in a centralized unit (CU) split architecture. Background Technology

[0002] In the current 5G gNB split architecture or Central Unit-Distributed Unit (CU-DU) split architecture, access control for various scenarios is performed at the CU based on a Mobility Restriction List (MRL) specific to each User Equipment (UE). This is because Radio Resource Control (RRC) signaling terminates at the CU. The MRL helps determine the access permissions and restrictions for each UE, thereby ensuring efficient management of network resources and maintaining control over UE mobility. Summary of the Invention

[0003] In a first aspect of this disclosure, a first apparatus is provided. The first apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus to at least: determine one or more parameters associated with mobility restrictions for the third apparatus after a connection is established between the second apparatus and the third apparatus; and transmit the one or more parameters associated with the mobility restrictions and one or more associated connection keys to the second apparatus as part of at least one connection-related message.

[0004] In a second aspect of this disclosure, a second apparatus is provided. The second apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second apparatus to at least: receive from a first apparatus one or more parameters associated with mobility restrictions and one or more associated connection keys as part of at least one connection-related message; and store one or more parameters associated with mobility restrictions and one or more connection keys.

[0005] In a third aspect of this disclosure, a method is provided. The method includes: after establishing a connection between a second device and a third device, determining one or more parameters associated with mobility restrictions for the third device at the first device; and transmitting the one or more parameters associated with the mobility restrictions and one or more associated connection keys to the second device as part of at least one connection-related message.

[0006] In a fourth aspect of this disclosure, a method is provided. The method includes: receiving, at a second device, one or more parameters associated with mobility restrictions and one or more associated connection keys from a first device as part of at least one connection-related message; and storing the one or more parameters associated with mobility restrictions and the one or more connection keys.

[0007] In a fifth aspect of this disclosure, a first apparatus is provided. The first apparatus includes: components for determining one or more parameters associated with mobility restrictions for the third apparatus after a connection is established between the second apparatus and the third apparatus; and components for transmitting the one or more parameters associated with the mobility restrictions and one or more associated connection keys to the second apparatus as part of at least one connection-related message.

[0008] In a sixth aspect of this disclosure, a second apparatus is provided. The second apparatus includes: components for receiving one or more parameters associated with mobility restrictions and one or more associated connection keys from a first apparatus as part of at least one connection-related message; and components for storing one or more parameters associated with mobility restrictions and one or more connection keys.

[0009] In a seventh aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to at least execute the method according to a third aspect.

[0010] In an eighth aspect of this disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon for causing a device to at least execute the method according to the fourth aspect.

[0011] It should be understood that the summary section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0012] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which: Figure 1 An example environment is shown that can implement example embodiments of this disclosure; Figure 2 An example diagram of the gNB-CU split architecture is shown; Figure 3 A signaling diagram illustrating an example procedure for access control in a CU split architecture according to some example embodiments of the present disclosure is shown; Figure 4 A signaling diagram illustrating an example procedure for access control in a CU split architecture according to some example embodiments of the present disclosure is shown; Figure 5 A signaling diagram illustrating an example procedure for access control in a CU split architecture according to some example embodiments of the present disclosure is shown; Figure 6 A flowchart is shown illustrating a method implemented at a first device according to some exemplary embodiments of the present disclosure; Figure 7 A flowchart is shown illustrating a method implemented at a second device according to some example embodiments of the present disclosure; Figure 8 A simplified block diagram of a device suitable for implementing example embodiments of the present disclosure is shown; and Figure 9 A block diagram of an example computer-readable medium according to some example embodiments of the present disclosure is shown.

[0013] In all the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0014] The principles of this disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described for illustrative purposes only, and that these embodiments help those skilled in the art to understand and implement this disclosure, without implying any limitation on the scope of this disclosure. The embodiments described herein can be implemented in various ways other than those described below.

[0015] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0016] In this disclosure, terms such as "an embodiment," "embodiment," and "example embodiment" refer to a described embodiment that may include a particular feature, structure, or characteristic, but not every embodiment must include that particular feature, structure, or characteristic. Furthermore, these phrases do not necessarily refer to the same embodiment. Additionally, when a particular feature, structure, or characteristic is described in connection with an embodiment, whether explicitly described or not, those skilled in the art will understand how to apply that feature, structure, or characteristic in conjunction with other embodiments.

[0017] It should be understood that although the preceding terms such as “first,” “second,” etc., may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and do not restrict the order of the terms. For example, a first element may be referred to as a second element without departing from the scope of the exemplary embodiments, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0018] As used herein, “at least one of the following: a list of two or more elements”, “at least one of the following: a list of two or more elements”, and similar wording (where the list of two or more elements is connected by “and” or “or”) means at least any one element, at least any two or more elements, or at least all elements.

[0019] As used herein, unless explicitly stated otherwise, the execution step “in response to A” does not indicate that the step is performed immediately after “A” occurs, and may include one or more intermediate steps.

[0020] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “the” are also intended to include the plural forms. It should also be understood that, when used herein, the terms “comprises,” “comprising,” “has,” “having,” “includes,” and / or “including” indicate the presence of the stated features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0021] As used in this application, the term "circuit" may refer to one or more of the following: (a) Hardware circuit implementation only (such as implementation using only analog and / or digital circuits); and (b) a combination of hardware circuitry and software, such as (where applicable): (i) A combination of one or more analog and / or digital hardware circuits with software / firmware; and (ii) Any part of one or more hardware processors having software (including one or more digital signal processors), software, and one or more memories, which work together to enable a device (such as a mobile phone or server) to perform various functions; and (c) One or more hardware circuits and / or one or more processors, such as one or more microprocessors or a portion thereof, which require software (e.g. firmware) to operate, but may be absent when the software is not required to operate.

[0022] This definition of "circuit" applies to all uses of the term in this application (including in any claim). As another example, as used herein, the term "circuit" also covers implementations of hardware circuitry or processors (or processors in general) or a portion thereof and their accompanying software and / or firmware. Where applicable to elements of a particular claim, the term "circuit" also covers, for example, baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices, or other computing or network devices.

[0023] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-A Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any suitable generation of communication protocols, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G), sixth-generation (6G) communication protocols and / or any other currently known or future-developed protocols. Embodiments of this disclosure can be applied to various communication systems. Given the rapid development of communication technologies, future types of communication technologies and systems embodying this disclosure will naturally emerge. The scope of this disclosure should not be construed as limited to the systems described above.

[0024] As used herein, the term "network device" refers to a node in a communication network through which terminal devices access the network and receive services. Depending on the terminology and technology employed, a network device can refer to a base station (BS) or access point (AP), such as a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), an NR NB (also known as a gNB), a remote radio unit (RRU), a radio head unit (RH), a remote radio head unit (RRH), a relay, an integrated access and backhaul (IAB) node, a low-power node (such as a femtonode or piconode), a non-terrestrial network (NTN) or non-terrestrial network equipment (such as satellite network equipment), low Earth orbit (LEO) satellites and geostationary orbit (GEO) satellites, spacecraft network equipment, etc. In some example embodiments, the radio access network (RAN) split architecture includes a centralized unit (CU) and a distributed unit (DU) at the IAB host node. The IAB node includes a mobile terminal (IAB-MT) portion that behaves like a UE relative to the parent node, and the DU portion of the IAB node behaves like a base station relative to the next-hop IAB node.

[0025] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not a limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), USB dongles, smart devices, wireless customer premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (such as remote surgery), industrial devices and applications (such as robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronics devices, devices operating on commercial and / or industrial wireless networks, etc. Terminal equipment may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "terminal equipment," "communication equipment," "terminal," "user equipment," and "UE" are used interchangeably.

[0026] As used herein, the terms “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” can refer to any resource used to perform communication, such as communication between a terminal device and a network device, including resources in the time domain, frequency domain, spatial domain, code domain, or any other combination of time, frequency, spatial, and / or code domain resources used to enable communication. In the following, unless explicitly stated otherwise, resources in the frequency and time domains will be used as examples of transmission resources used to describe some exemplary embodiments of this disclosure. Note that the exemplary embodiments of this disclosure are equally applicable to other resources in other domains.

[0027] As mentioned above, in a 5G environment, access control for various scenarios is performed at the CU based on the MRL specific to each UE. However, for the upcoming 6G, efforts are underway to simplify the F1 Application Protocol (AP) and reduce UE Control Plane (CP) latency by improving CU-DU splitting, which refers to distributing responsibilities / functions between the two nodes.

[0028] The performance gap in CP latency between monolithic gNBs and decomposed gNBs (CU-CP-DU splitting) is primarily attributed to the large number of round-trip messages exchanged between the CU and DU during RRC mobility and access-related procedures. To address this challenge, new solutions are being explored to optimize existing RRC procedures and reduce the number of F1 AP messages. These efforts aim to improve the efficiency and performance of 6G network architectures.

[0029] Network access control is a key mechanism for restricting unauthorized users (UEs) from accessing network resources during mobility, RRC connection establishment, or re-establishment. The core challenge of network access control lies in determining which cell a UE is attempting to access and whether that cell is included in the UE's "restricted" or "allowed" cell list.

[0030] Because this check is specific to each UE, it must be performed in real time during certain UE CP procedures. Although the DU within the gNB owns the cell and radio resources, the CP for these cells is primarily located in the Centralized Cell-Control Plane (CU-CP). In terms of access control, this means that the CU-CP performs the aforementioned check, as RRC signaling terminates at the CU-CP.

[0031] To facilitate this process, the Access and Mobility Management Function (AMF) can deliver the MRL to the CU-CP, and the AMF is responsible for maintaining this information for the UE. The MRL can be provided during initial context establishment and during a handover request initiated by the source CU-CP. This ensures that the CU-CP has the information necessary to effectively perform access control.

[0032] If the MRL is available, it is stored in the UE context. The MRL is then utilized in subsequent mobility actions, such as selecting the appropriate target cell during handover. Additionally, the MRL helps select the correct RAN-based Notification Area (RNA) cell when the UE transitions to an RRC inactive state. These actions of selecting the target cell and RNA cell are performed by the CU-CP.

[0033] In 5G, there are specific examples of access control. For instance, for intra-gNB mobility in the RRC_CONNECTED state, access control (i.e., which cells the UE can access at the target gNB) is performed at the source CU-CP. For inter-gNB mobility, when the UE moves between different gNBs, access control is processed at the source CU-CP. For the RRC inactive state, when the UE transitions from the RRC inactive state to the RRC_CONNECTED state, the DU transmits the RRC message to the CU. The CU is responsible for processing the RRC message and performing access control in this state.

[0034] In the current 3GPP specification, RRC signaling terminates at the CU, specifically at the CU-CP. Furthermore, access control in the three scenarios mentioned above is also performed at the CU-CP. This arrangement can be achieved by forwarding UE RRC messages, which include UE cell signal measurements (e.g., UE-specific F1 messages), from the DU to the CU. These functions can be efficiently handled by centralizing RRC termination and access control at the CU-CP.

[0035] Furthermore, the CU-CP acts as the owner of necessary information, such as the MRL, which is used to restrict the UE's access to certain cells or RNAs. Even if the cell itself is "owned" by the DU, the CU-CP has the right to make access control decisions based on the information provided.

[0036] The current specification presents challenges in access control because, in a decomposed architecture, access control is not performed at the DU, which is the first network element (NE). This issue does not arise in a monolithic gNB design because there is no F1 interface, and the CU and DU essentially function as the same NE within the gNB.

[0037] However, the rise of cloud RAN technology is expected to lead to an increase in decomposed gNB deployments, where the CU (Content Unit) is centralized, while the RU (Radio Unit) and DU (Decentralized Unit) are distributed. In such deployments, access control processes may need to be reconsidered and optimized to address the challenges introduced by the decomposed architecture.

[0038] Several technical scenarios are expected to require improvement. For example, when a UE performs mobility in the RRC_CONNECTED (RRC connected) or RRC_INACTIVE (RRC inactive) state, the DU acts as a proxy, relaying RRC messages between the UE and CU for access control within the CU. However, this approach introduces latency into access control decisions and consumes unnecessary resources in both the DU and CU due to redundant signaling procedures.

[0039] For example, in the case of inactive mobility, when a UE wants to restore an RRC connection by sending an RRC recovery request, these request messages should be avoided from being unnecessarily forwarded to the CU, especially if these requests are subsequently rejected.

[0040] For example, depending on the scenario, access control may be performed on Closed Access Group (CAG) UEs in later stages of the process (such as at gNB-CU or AMF). Optimizing this process would be beneficial.

[0041] Therefore, this disclosure proposes a mechanism for access control in a CU-split architecture. In this solution, during the context establishment process associated with the UE, the CU transmits one or more parameters associated with mobility restrictions to the DU via an F1 message in the UE context establishment request. The DU stores one or more parameters associated with mobility restrictions. In this way, the DU can perform early access control in different scenarios.

[0042] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0043] Figure 1 An example environment 100 in which exemplary embodiments of the present disclosure may be implemented is shown. In environment 100, a CU split architecture is shown. In this CU split architecture, a first device 110 and a second device 120 are shown, and they can communicate with each other. In some example embodiments, at least a portion of the functionality of a network device (e.g., a gNB) may be configured to be performed by the first device 110, and at least another portion of the functionality of the network device may be configured to be performed by the second device 120.

[0044] In some example embodiments, the first device 110 may include a centralized unit control plane (CU-CP) of the network device, or may be a centralized unit control plane such as gNB-CU-CP. In some example embodiments, the second device 120 may include a distributed unit (DU) of the network device, such as gNB-DU.

[0045] In some example embodiments, example environment 100 may also include a third device 130, which may operate, for example, as a terminal device (e.g., UE). The third device 130 may communicate with the second device 120.

[0046] In an example embodiment, the first device 110 may communicate with a plurality of second devices 120. For example, a gNB-CU-CP may communicate with one or more gNB-DUs via an F1 connection. The following will combine... Figure 2 Let's discuss more details on this.

[0047] It should be understood that Figure 1 The number of second and first devices shown is given for illustrative purposes only and does not imply any limitation. The communication environment 100 may include any appropriate number of second and first devices.

[0048] In the following description, for illustrative purposes, some example embodiments are described where the first device 110 operates as gNB-CU-CP and the second device 120 operates as gNB-DU. However, in some example embodiments, the operations described in conjunction with gNB-CU-CP can be implemented at other suitable devices, and the operations described in conjunction with gNB-DU can also be implemented at other suitable devices.

[0049] Communication between network devices and other devices in environment 100 can be achieved according to any suitable communication protocol, including but not limited to cellular communication protocols such as first-generation (1G), second-generation (2G), third-generation (3G), fourth-generation (4G), fifth-generation (5G), and sixth-generation (6G), wireless local area network communication protocols such as IEEE 802.11, and / or any other currently known or future-developed protocols. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiplexing (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other currently known or future-developed technologies.

[0050] Figure 2 An example diagram of a gNB-CU split architecture 200 is shown. As illustrated, architecture 200 involves a gNB-CU-CP 210, multiple gNB-CU-UPs 220, and multiple gNB-DUs 230. Architecture 200 can be implemented as a gNB-split CU-DU architecture. In some examples, the gNB-CU-CP 210, multiple gNB-CU-UPs 220, and multiple gNB-DUs 230 may be associated with a cloud gNB or a cloud RAN.

[0051] In some scenarios, a gNB-DU 230 can be connected to only one gNB-CU-CP 210, and a gNB-CU-UP 210 can be connected to only one gNB-CU-CP 210. In other scenarios, for flexibility, a gNB-DU 230 and / or a gNB-CU-UP 220 can be connected to multiple gNB-CU-CP 210s through appropriate implementation. In these cases, a gNB-DU 230 can be connected to multiple gNB-CU-UP 220s under the control of the same gNB-CU-CP 210, and a gNB-CU-UP 220 can be connected to multiple gNB-DU 230s under the control of the same gNB-CU-CP 210.

[0052] In some examples, the connection between gNB-CU-UP 220 and gNB-DU 230 is established by gNB-CU-CP 210 using bearer context management functions. gNB-CU-CP 210 selects the appropriate gNB-CU-UP(s) for the service requested by the UE.

[0053] In some examples, the gNB-CU-CP 210 can communicate with multiple gNB-CU-UP 220s via E1 connections. The gNB-CU-CP 210 can communicate with multiple gNB-DU 230s via F1 connections (also known as F1-C connections).

[0054] In some examples, the gNB-CU-UP 220 can communicate with multiple gNB-DU230s via an F1 connection (also known as an F1-U connection).

[0055] In some examples, (multiple) gNB-CU-UPs can report load status to gNB-CU-CP 210 via (multiple) E1 connections. In some cases, if gNB-CU-UP 220 is overloaded, it can use a GNB-CU-UP STATUSINDICATION message to indicate the overload status. gNB-CU-CP 210 can then take overload mitigation actions until a new GNB-CU-UP STATUSINDICATION message indicates the overload has ended. In this way, gNB-CU-UP 220 can proactively report to gNB-CU-CP 210.

[0056] In other cases, gNB-CU-CP 210 can obtain the load status of gNB-CU-UP 220 by explicitly initiating a RESOURCE STATUS REQUEST message to start or stop measurements. If gNB-CU-UP 220 can provide all requested resource status information, it can initiate measurements as requested by gNB-CU-CP 210 and respond to gNB-CU-CP 210 with a RESOURCE STATUS RESPONSE message. In this way, gNB-CU-CP 210 can request gNB-CU-UP 220 to measure and report load status.

[0057] In some examples, (multiple) gNB-DUs can report load status to the gNB-CU-CP via an F1 connection. In some cases, the gNB-DU 230 can transmit overload information (IE) in a GNB-DU STATUS INDICATION message to indicate that the gNB-DU 230 is overloaded, and the gNB-CU-CP 210 can take overload mitigation actions until a new GNB-DU STATUS INDICATION message indicates that the overload has ended.

[0058] In some other cases, the gNB-CU-CP 210 initiates a process by transmitting a RESOURCE STATUSREQUEST message to the gNB-DU 230 to start a measurement, stop a measurement, or add cells to be reported for the measurement. In other cases, the gNB-DU 230 may report the results of permitted measurements in a RESOURCE STATUS UPDATE message. Permitted measurements may be measurements successfully initiated during a previous resource status reporting initiation process.

[0059] Now for reference Figure 3 This document illustrates a signaling diagram of an example process 300 for access control in a CU split architecture according to some example embodiments of the present disclosure. Process 300 may involve a first device 110, a second device 120, and a third device 130. Furthermore, example process 300 may also involve a fourth device 301, which may be considered a network function in the core network, such as an AMF.

[0060] like Figure 3 As shown, a (304)F1 AP connection is established between a first device 110, for example, operating as a CU, and a second device 120, for example, operating as a DU.

[0061] During a connection establishment process (e.g., an RRC connection establishment process), a third device 130 operating as a UE may transmit an RRC establishment request (306) to a second device 120. After signaling exchanges such as initial UL RRC message transmission and DL RRC message transmission (actions 308 and 310) between the second device 120 and the first device 110, the second device 120 may transmit an RRC establishment message (312) to the third device 130 to establish a signaling radio bearer.

[0062] After the RRC is established at the third device 130, the third device 130 can transmit an RRC establishment completion message (314) to the second device 120. The second device 120 can indicate to the first device 110 (316) that the RRC establishment has been completed via a UL RRC message transmission.

[0063] Then, the first device 110 may notify the fourth device 301 (318) of the access of the third device 130 via an initial UE message. The fourth device 301 may transmit (320) an initial UE context establishment request to the first device 110.

[0064] During the UE context establishment process, the first device 110 may, for example, transmit (322) one or more parameters associated with UE mobility restrictions to the second device 120 via a UE context establishment request. The UE context establishment request from the first device 110 to the second device 120 may be transmitted via an F1 message.

[0065] In addition to one or more parameters associated with UE mobility restrictions, the first device 110 may also transmit one or more connection keys to the second device 120 as part of at least one connection-related message. The connection-related message may be transmitted to the second device 120 via the F1 interface.

[0066] For example, one or more RRC keys for at least one RRC message can be transmitted to the second device 120 via a UE context establishment request. The second device 120 can use the one or more RRC keys to open the RRC message.

[0067] For example, one or more parameters associated with UE mobility restrictions may include at least one parameter in the MRL. As an example, the MRL can be viewed as a New Information Element (IE) in a UE Context Establishment Request. Below is an example of the format of a UE Context Establishment Request message: Table 1

[0068] Several parameters are defined in the MRL. One or more parameters associated with UE mobility restrictions can be selected from the following MRLs:

[0069] In some embodiments, one or more parameters associated with UE mobility restrictions may include a list of allowed CAGs. As described above, the MRL includes "NPN Mobility Information". The UE's allowed CAGs may be included in the "NPN Mobility Information" IE.

[0070] Specifically, "NPN mobility information" may include PNI-NPN mobility information, which contains a list of allowed PNI-NPNs, as shown below: Table 3

[0071] The list of allowed PNI-NPNs can include a list of allowed CAGs for each PLMN, as shown below: Table 4

[0072] In addition, the "List of Allowed CAGs for Each PLMN" can include the "CAG ID", as shown below: Table 5

[0073] Upon receiving one or more parameters and one or more RRC keys associated with UE mobility restrictions, the second device 120 may store (324) these parameters and keys for use in subsequent access control.

[0074] After transmission (326) to the third device 130, the second device 120 transmits a UE context establishment response, which is extended by adding an MRL. An example of a UE context establishment response is shown below.

[0075] Table 6

[0076] It should be understood that MRLs can be used as example content for a list of restrictions. Restrictions used to reject certain measurements can also be triggered by any other reason.

[0077] Based on reference Figure 3 The described solution allows gNB-CU-CP to deliver MRL parameters received from the AMF, or a portion thereof (at least the list of allowed CAGs), to gNB-DU via the F1-C interface during UE context establishment. Furthermore, gNB-CU-CP delivers the restriction rules along with the security key required by gNB-DU to open measurement results in the DU, thereby allowing both the DU and CU to access the necessary RRC messages.

[0078] Once the DU has used the key and subsequently receives a measurement report or any other RRC message that does not require filtering, the DU delivers the RRC message along with the updated key content to the CU, allowing the CU to continue the RRC process. In other words, the CU requests the DU to process RRC messages until a message arises that requires processing within the CU.

[0079] The second device 120 can perform access control using one or more parameters associated with UE mobility restrictions in different scenarios. For example, the gNB-DU determines whether to allow the UE to access the network based on one or more received parameters, such as in the case of a handover where the UE's initial registration is completed at the DU. Furthermore, access control can also be performed when the UE requests RRC recovery.

[0080] The following will refer to Figure 4 and Figure 5 The access control performed by the second device 120 is described in further detail.

[0081] Figure 4 A signaling diagram of an example process 400 for access control in a CU split architecture according to some example embodiments of the present disclosure is shown. Process 400 may involve a first device 110, a second device 120, and a third device 130. Furthermore, example process 400 may also involve another second device 401 as another DU operation, which can manage the target cell during the handover process of the third device 130.

[0082] For reference Figure 3 As described, the second device 120 has been configured with one or more parameters associated with UE mobility restrictions and one or more RRC keys associated with at least one RRC message.

[0083] Now for reference Figure 4 The third device 130 can transmit a measurement report (404) to the second device 120. The measurement report may include a target cell identifier (ID), such as the ID of a target cell controlled by another second device 401. The measurement report may also include a CAG ID and other information associated with the handover of the third device 130.

[0084] Upon receiving a measurement report, the second device 120 may determine (406) whether the third device 130 is permitted to access the target cell indicated in the measurement report. For example, the second device 120 may check whether the third device 130 is permitted to access the target cell based on one or more parameters previously acquired by the first device 110 that are associated with UE mobility restrictions. In other words, the second device 120 may check whether the ID of the target cell indicated in the measurement report belongs to the list of cells that the third device 130 is permitted to access.

[0085] If the second device 120 determines that the third device 130 is not allowed to access the target cell indicated by the measurement report, the second device 120 may refuse access and not deliver a message to the first device 110.

[0086] Additionally or optionally, the second device 120 may transmit an (408) RRC reconfiguration message to the third device 130 to instruct the removal of the target cell indicated in the measurement report. The second device 120 may also, for example, instruct the third device 130 to remove the target cell from the measurement report via the RRC reconfiguration message, and / or to stop or restart the measurement of the target cell after a time interval.

[0087] If the second device 120 determines that the third device 130 is allowed to access the target cell indicated by the measurement report, the second device 120 may deliver (410) the measurement results of the measurement report and the latest RRC key to the first device 110 to indicate that the filtering task has been completed and to move the RRC message processing back to the first device 110.

[0088] Subsequently, the first device 110 may transmit a (412) UE context modification request to the second device 120, and the second device 120 may respond to the first device 110 using the UE context modification response. Subsequent procedures / signaling associated with the handover are not described here.

[0089] It should be understood that modifications initiated by gNB-CU, such as UE CONTEXT MODIFICATION REQUEST and UE CONTEXT MODIFICATION RESPONSE, can be extended to include MRL IE. Modifications initiated by gNB-DU, such as UE CONTEXT MODIFICATION REQUIRED and UE CONTEXT MODIFICATION CONFIRM, can be extended to include MRL IE.

[0090] Figure 5 A signaling diagram of an example process 500 for access control in a CU split architecture according to some example embodiments of the present disclosure is shown. Process 500 may involve a first device 110, a second device 120, and a third device 130. Furthermore, example process 500 may also involve a fourth device 501, which may be considered a network function in the core network, such as an AMF.

[0091] For reference Figure 3 As described, the second device 120 has been configured with one or more parameters associated with UE mobility restrictions and one or more RRC keys associated with at least one RRC message.

[0092] Now for reference Figure 5 A (502)F1 AP connection is established between a first device 110, for example, operating as a CU, and a second device 120, for example, operating as a DU. The third device 130 is currently inactive.

[0093] The third device 130 may transmit (504) an RRC recovery request to the second device 120. Then, the second device 120 may use one or more parameters stored in the second device 120 that are associated with UE mobility restrictions to check (506) whether the third device 130 is allowed to access the network, such as the first device 110.

[0094] As an option, if the second device 120 determines that the third device 130 is not allowed to access the network, the second device 120 can, for example, send a message to the third device 130. RRCReject (RRC Reject) message to reject (512) access.

[0095] The second device 120 may also transmit (514) a UE context release request to the first device 110 to instruct the first device 110 to release the context of the third device 130. Then, the first device 110 may deliver the UE context release request to the fourth device 501 to instruct the fourth device 501 to release the context of the third device 130.

[0096] As an alternative, if the second device 120 determines that the third device 130 is allowed to access the network, a normal RRC recovery process will be performed, which is omitted here.

[0097] Based on the solution disclosed herein, the gNB-DU determines whether to allow the UE to access the network based on the MRL or a subset of MRL parameters received from the CU, and by checking the RRC signaling or a portion thereof during UE connection establishment via the CAG cell. In other words, in the decomposed architecture, access control is performed at the DU rather than the CU / CU-CP, which reduces the network load on the F1 interface.

[0098] Figure 6 A flowchart of an example method 600 implemented at a first device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1 Method 600 is described by the angle of the first device 110 in the middle.

[0099] At box 610, after the connection between the second and third devices is established, the first device 110 determines one or more parameters associated with the mobility restriction of the third device.

[0100] At box 620, the first device 110 transmits one or more parameters and one or more connection keys associated with mobility restrictions to the second device as part of at least one connection-related message.

[0101] In some example embodiments, the connection key is a Radio Resource Control (RRC) key, and at least one connection is associated with an RRC connection.

[0102] In some example embodiments, connection-related messages are transmitted to a second device via the F1 interface.

[0103] In some example embodiments, one or more parameters associated with mobility restrictions include at least a list of permitted Closed Access Groups (CAGs).

[0104] In some example embodiments, one or more parameters associated with mobility restrictions include at least one parameter from the Mobility Restriction List (MRL).

[0105] In some example embodiments, method 600 further includes transmitting one or more parameters associated with mobility restrictions and one or more connection keys to a second device as part of a context establishment request.

[0106] In some example embodiments, method 600 further includes receiving from the second device a measurement report associated with the third device's access to the target cell and one or more connection keys.

[0107] In some example embodiments, method 600 further includes receiving from the second device a context release request indicating that the context of the third device will be released by the first device.

[0108] In some example embodiments, the first device includes a centralized network node, the second device includes a distributed network node, and the third device includes a UE.

[0109] Figure 7 A flowchart of an example method 700 implemented at a second device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1 Method 700 is described by the angle of the second device 120 in the middle.

[0110] At box 710, the second device 120 receives one or more parameters and one or more connection keys associated with mobility restrictions from the first device as part of at least one connection-related message.

[0111] At box 720, the second device 120 stores one or more parameters and one or more connection keys associated with mobility restrictions.

[0112] In some example embodiments, the connection key is a Radio Resource Control (RRC) key, and at least one connection is associated with an RRC connection.

[0113] In some example embodiments, connection-related messages are received from the first device via the F1 interface.

[0114] In some example embodiments, one or more parameters include at least a list of allowed Closed Access Groups (CAGs).

[0115] In some example embodiments, one or more parameters include at least one parameter from the Mobility Restriction List (MRL).

[0116] In some example embodiments, method 700 further includes receiving, as part of a context establishment request, one or more parameters associated with mobility restrictions and one or more connection keys from the first device.

[0117] In some example embodiments, method 700 further includes: receiving a measurement report from a third device; determining, based on one or more parameters associated with mobility restrictions, whether the third device is permitted to access the target cell indicated by the measurement report; and denying the third device access to the target cell if it is determined that the third device is not permitted to access the target cell.

[0118] In some example embodiments, method 700 further includes transmitting an RRC reconfiguration message to a third device, the RRC reconfiguration message instructing the third device to remove the target cell from the measurement report and / or to stop or restart the measurement of the target cell after a time interval.

[0119] In some example embodiments, method 700 further includes: delivering a measurement report and one or more RRC keys to the first device based on determining that the third device is allowed to access the target cell.

[0120] In some example embodiments, method 700 further includes: receiving an RRC recovery request from a third device; determining, based on one or more parameters associated with mobility restrictions, whether to allow the third device to resume connection with the first device; and transmitting an RRC rejection message to the third device if it is determined that the third device is not allowed to resume connection.

[0121] In some example embodiments, method 700 further includes transmitting to the first device a context release request indicating that the context of the third device will be released by the first device.

[0122] In some example embodiments, the first device includes a centralized network node, the second device includes a distributed network node, and the third device includes a UE.

[0123] In some example embodiments, a first device capable of performing any of method 600 (e.g. Figure 1 The first device 110 may include a component for performing a corresponding operation of method 600. This component may be implemented in any suitable form. For example, the component may be implemented as a circuit or a software module. The first device may be implemented as... Figure 1 The first device 110 is included in the first device 110.

[0124] In some example embodiments, the first device includes: components for determining one or more parameters associated with mobility restrictions for the third device after a connection is established between the second device and the third device; and components for transmitting one or more parameters associated with the mobility restrictions and one or more connection keys to the second device as part of at least one connection-related message.

[0125] In some example embodiments, the connection key is a Radio Resource Control (RRC) key, and at least one connection is associated with an RRC connection.

[0126] In some example embodiments, connection-related messages are transmitted to a second device via the F1 interface.

[0127] In some example embodiments, one or more parameters associated with mobility restrictions include at least a list of permitted Closed Access Groups (CAGs).

[0128] In some example embodiments, one or more parameters associated with mobility restrictions include at least one parameter from the Mobility Restriction List (MRL).

[0129] In some example embodiments, the first device further includes a component for transmitting one or more parameters associated with mobility restrictions and one or more connection keys to the second device as part of a context establishment request.

[0130] In some example embodiments, the first device further includes a component for receiving from the second device a measurement report associated with the third device's access to the target cell and one or more connection keys.

[0131] In some example embodiments, the first device further includes a component for receiving from the second device a context release request indicating that the context of the third device will be released by the first device.

[0132] In some example embodiments, the first device includes a centralized network node, the second device includes a distributed network node, and the third device includes a UE.

[0133] In some example embodiments, the first device further includes components for performing other operations in some example embodiments of method 600 or the first device 110. In some example embodiments, the components include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the first device.

[0134] In some example embodiments, a second means capable of performing any of the methods 700 (e.g. Figure 1The second device 120 may include components for performing the corresponding operations of method 700. These components may be implemented in any suitable form. For example, the components may be implemented as a circuit or a software module. The second device may be implemented as... Figure 1 The second device 120 is included in or is part of the second device 120.

[0135] In some example embodiments, the second device includes: a component for receiving one or more parameters and one or more connection keys associated with mobility restrictions from the first device as part of at least one connection-related message; and a component for storing one or more parameters and one or more connection keys associated with mobility restrictions.

[0136] In some example embodiments, the connection key is a Radio Resource Control (RRC) key, and at least one connection is associated with an RRC connection.

[0137] In some example embodiments, connection-related messages are received from the first device via the F1 interface.

[0138] In some example embodiments, one or more parameters include at least a list of allowed Closed Access Groups (CAGs).

[0139] In some example embodiments, one or more parameters include at least one parameter from the Mobility Restriction List (MRL).

[0140] In some example embodiments, the second device further includes a component for receiving one or more parameters associated with mobility restrictions and one or more connection keys from the first device as part of a context establishment request.

[0141] In some example embodiments, the second device further includes: components for receiving a measurement report from the third device; components for determining whether the third device is permitted to access the target cell indicated by the measurement report based on one or more parameters associated with mobility restrictions; and components for denying the third device access to the target cell if it is determined that the third device is not permitted to access the target cell.

[0142] In some example embodiments, the second device further includes a component for transmitting an RRC reconfiguration message to the third device, the RRC reconfiguration message instructing the third device to remove the target cell from the measurement report and / or to stop or restart the measurement of the target cell after a time interval.

[0143] In some example embodiments, the second device further includes a component for delivering a measurement report and one or more RRC keys to the first device based on determining that the third device is allowed to access the target cell.

[0144] In some example embodiments, the second device further includes: components for receiving an RRC recovery request from the third device; components for determining whether the third device is permitted to resume connection with the first device based on one or more parameters associated with mobility restrictions; and components for transmitting an RRC rejection message to the third device if it is determined that the third device is not permitted to resume connection.

[0145] In some example embodiments, the second device further includes a component for transmitting to the first device a context release request indicating that the context of the third device will be released by the first device.

[0146] In some example embodiments, the first device includes a centralized network node, the second device includes a distributed network node, and the third device includes a UE.

[0147] In some example embodiments, the second device further includes components for performing other operations in some example embodiments of method 700 or the second device 120. In some example embodiments, the components include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the second device.

[0148] Figure 8 This is a simplified block diagram of a device 800 suitable for implementing exemplary embodiments of the present disclosure. The device 800 can be provided to implement a communication device, such as... Figure 1 The first device 110 or the second device 120 shown. As shown, the device 800 includes one or more processors 810, one or more memories 820 coupled to the processors 810, and one or more communication modules 840 coupled to the processors 810.

[0149] Communication module 840 is used for bidirectional communication. Communication module 840 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface can represent any interface required for communication with other network elements. In some example embodiments, communication module 840 may include at least one antenna.

[0150] As a non-limiting example, processor 810 can be any type suitable for a local technology network and can include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), and processor based on a multi-core processor architecture. Device 800 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock that synchronizes with the main processor.

[0151] Memory 820 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 824, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact optical disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 822 and other volatile memories that cannot retain data during power loss.

[0152] Computer program 830 includes computer-executable instructions that are executed by an associated processor 810. The instructions of program 830 may include instructions for performing operations / actions of some example embodiments of this disclosure. Program 830 may be stored in memory (e.g., ROM 824). Processor 810 can perform any suitable actions and processes by loading program 830 into RAM 822.

[0153] Example embodiments of this disclosure can be implemented by program 830, enabling device 800 to perform as described in the reference. Figures 2 to 7 Any process discussed in this disclosure. Exemplary embodiments of this disclosure may also be implemented by hardware or by a combination of software and hardware.

[0154] In some example embodiments, program 830 may be tangibly contained in a computer-readable medium, which may be included in device 800 (such as in memory 820) or in other storage devices accessible to device 800. Device 800 may load program 830 from the computer-readable medium into RAM 822 for execution. In some example embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. As used herein, the term "non-transitory" is a limitation on the medium itself (i.e., a tangible medium, not a signal), not a limitation on the persistence of data storage (e.g., RAM and ROM).

[0155] Figure 9 An example of a computer-readable medium 900 is shown, which may be in the form of a CD, DVD, or other optical storage disc. A program 830 is stored on the computer-readable medium 900.

[0156] Generally, the various embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, as non-limiting examples, the blocks, apparatuses, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0157] Some exemplary embodiments of this disclosure also provide at least one computer program product tangibly stored on a computer-readable medium, such as a non-transitory computer-readable medium. The computer program product includes computer-executable instructions (such as instructions included in a program module) that are executed by a target physical or virtual processor in a device to implement any of the methods described above. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform a specific task or implement a specific abstract data type. In various embodiments, the functionality of a program module can be combined or split as needed. The machine-executable instructions of a program module can execute within a local device or a distributed device. In a distributed device, the program module can reside in both local and remote storage media.

[0158] Program code used to perform the methods of this disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0159] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0160] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0161] Furthermore, although operations are shown in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all shown operations to be performed in order to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the foregoing discussion, these details should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless otherwise expressly stated, certain features described in the context of different embodiments may also be implemented in combination in a single embodiment. Conversely, unless otherwise expressly stated, various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination.

[0162] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.

Claims

1. A first device, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the first device to at least: After the connection is established between the second and third devices, one or more parameters associated with mobility restrictions for the third device are determined. as well as The second device is transmitted one or more parameters associated with the mobility restriction and one or more associated connection keys as part of at least one connection-related message.

2. The first apparatus of claim 1, wherein the connection key is a Radio Resource Control (RRC) key, and the at least one connection is associated with an RRC connection.

3. The first device according to claim 1, wherein the connection-related messages are transmitted to the second device via the F1 interface.

4. The first device according to any one of claims 1-3, wherein the one or more parameters associated with the mobility restriction include at least a list of permitted Closed Access Groups (CAGs).

5. The first apparatus according to any one of claims 1-3, wherein the one or more parameters associated with the mobility restriction include at least one parameter included in the mobility restriction list (MRL).

6. The first device according to any one of claims 1-5, wherein the first device is configured to: The one or more parameters associated with the mobility restriction and the one or more connection keys are transmitted to the second device as part of the context establishment request.

7. The first device according to claim 6, wherein the first device is configured such that: The second device receives a measurement report associated with the third device's access to the target cell, as well as one or more connection keys.

8. The first device according to any one of claims 1-5, wherein the first device is configured to: The third device receives a context release request from the second device, the context release request indicating that the context of the third device will be released by the first device.

9. The first device according to any one of claims 1-8, wherein the first device comprises a centralized network node, the second device comprises a distributed network node, and the third device comprises a UE.

10. A second device, comprising: At least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the second device to at least: Receive one or more parameters associated with mobility restrictions and one or more associated connection keys from the first device as part of at least one connection-related message; as well as Store the one or more parameters associated with the mobility restrictions and the one or more connection keys.

11. The second apparatus of claim 10, wherein the connection key is a Radio Resource Control (RRC) key, and the at least one connection is associated with an RRC connection.

12. The second apparatus of claim 10, wherein the connection-related message is received from the first apparatus via an F1 interface.

13. The second apparatus according to any one of claims 10-12, wherein the one or more parameters include at least a list of permitted Closed Access Groups (CAGs).

14. The second apparatus according to any one of claims 10-12, wherein the one or more parameters include at least one parameter included in the Mobility Restriction List (MRL).

15. The second device according to any one of claims 10-14, wherein the second device is configured to: The first device receives one or more parameters and one or more connection keys associated with the mobility restriction as part of the context establishment request.

16. The second device according to claim 15, wherein the second device is configured to: Receive measurement reports from the third device; Whether the third device is permitted to access the target cell indicated by the measurement report is determined based on one or more parameters associated with the mobility restriction; as well as Based on the determination that the third device is not allowed to access the target cell, access to the target cell by the third device is denied.

17. The second device according to claim 16, wherein the second device is configured to: The third device is transmitted an RRC reconfiguration message, which instructs the third device to remove the target cell from the measurement report and / or to stop or restart the measurement of the target cell after a time interval.

18. The second device according to claim 16, wherein the second device is configured to: Based on the determination that the third device is allowed to access the target cell, the measurement report and the one or more RRC keys are delivered to the first device.

19. The second device according to any one of claims 10-14, wherein the second device is configured to: Receive an RRC recovery request from the third device; Determining whether the third device is permitted to re-establish connection with the first device based on one or more parameters associated with mobility restrictions; and Based on the determination that the third device is not allowed to restore the connection, an RRC rejection message is transmitted to the third device.

20. The second device according to claim 19, wherein the second device is configured to: A context release request is transmitted to the first device, the context release request indicating that the context of the third device will be released by the first device.

21. The second apparatus according to any one of claims 10-20, wherein the first apparatus comprises a centralized network node, the second apparatus comprises a distributed network node, and the third apparatus comprises a UE.

22. A method comprising: After the connection is established between the second and third devices, one or more parameters associated with mobility restrictions for the third device are determined at the first device; as well as The second device is transmitted one or more parameters associated with the mobility restriction and one or more associated connection keys as part of at least one connection-related message.

23. The method of claim 22, wherein the connection key is a Radio Resource Control (RRC) key, and the at least one connection is associated with an RRC connection.

24. The method of claim 22, wherein the connection-related messages are transmitted to the second device via the F1 interface.

25. The method of any one of claims 22-24, wherein the one or more parameters associated with the mobility restriction include at least a list of permitted Closed Access Groups (CAGs).

26. The method of any one of claims 22-24, wherein the one or more parameters associated with the mobility restriction include at least one parameter included in the mobility restriction list (MRL).

27. The method according to any one of claims 22-26, further comprising: The one or more parameters associated with the mobility restriction and the one or more connection keys are transmitted to the second device as part of the context establishment request.

28. The method of claim 27, further comprising: The second device receives a measurement report associated with the third device's access to the target cell, as well as one or more connection keys.

29. The method according to any one of claims 22-26, further comprising: The third device receives a context release request from the second device, the context release request indicating that the context of the third device will be released by the first device.

30. The method according to any one of claims 22-29, wherein the first device comprises a centralized network node, the second device comprises a distributed network node, and the third device comprises a UE.

31. A method comprising: Receive one or more parameters associated with mobility restrictions and one or more associated connection keys from the first device as part of at least one connection-related message; as well as Store the one or more parameters associated with the mobility restrictions and the one or more connection keys.

32. The method of claim 31, wherein the connection key is a Radio Resource Control (RRC) key, and the at least one connection is associated with an RRC connection.

33. The method of claim 31, wherein the connection-related message is received from the first device via an F1 interface.

34. The method according to any one of claims 31-33, wherein the one or more parameters include at least a list of permitted Closed Access Groups (CAGs).

35. The method according to any one of claims 31-33, wherein the one or more parameters include at least one parameter included in the Mobility Restriction List (MRL).

36. The method according to any one of claims 31-35, further comprising: The first device receives one or more parameters and one or more connection keys associated with the mobility restriction as part of the context establishment request.

37. The method of claim 36, further comprising: Receive measurement reports from the third device; Whether the third device is permitted to access the target cell indicated by the measurement report is determined based on one or more parameters associated with the mobility restriction; as well as Based on the determination that the third device is not allowed to access the target cell, access to the target cell by the third device is denied.

38. The method of claim 37, further comprising: The third device is transmitted an RRC reconfiguration message, which instructs the third device to remove the target cell from the measurement report and / or to stop or restart the measurement of the target cell after a time interval.

39. The method of claim 37, further comprising: Based on the determination that the third device is allowed to access the target cell, the measurement report and the one or more RRC keys are delivered to the first device.

40. The method according to any one of claims 31-35, further comprising: Receive an RRC recovery request from the third device; Whether the third device is permitted to re-establish connection with the first device is determined based on one or more parameters associated with mobility restrictions; as well as Based on the determination that the third device is not allowed to restore the connection, an RRC rejection message is transmitted to the third device.

41. The method of claim 40, further comprising: A context release request is transmitted to the first device, the context release request indicating that the context of the third device will be released by the first device.

42. The method according to any one of claims 31-41, wherein the first device comprises a centralized network node, the second device comprises a distributed network node, and the third device comprises a UE.

43. A first device, comprising: A component for determining one or more parameters associated with mobility restrictions for the third device after a connection has been established between the second and third devices; as well as A component for transmitting one or more parameters associated with the mobility restriction and one or more associated connection keys to the second device as part of at least one connection-related message.

44. A second device, comprising: A component for receiving one or more parameters associated with mobility restrictions and one or more associated connection keys from a first device as part of at least one connection-related message; as well as A component for storing the one or more parameters and the one or more connection keys associated with the mobility restrictions.

45. A computer-readable medium comprising instructions stored thereon, the instructions being configured to cause a device to perform at least the method according to any one of claims 22-30 or the method according to any one of claims 31-42.