Security handling of EPC reselection from 5GS

JP2024519200A5Active Publication Date: 2025-05-12QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023565953
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-11
Filing Date
2022-05-12
Publication Date
2025-05-12
Estimated Expiration
2042-05-12

AI Technical Summary

Technical Problem

Existing wireless communication systems face inconsistencies in security handling during reselection from one radio access technology (RAT) to another, particularly in scenarios involving radio link failures and retransmission of tracking area update requests, leading to potential communication failures.

Method used

The proposed solution involves modifying the handling of tracking area update (TAU) request messages by ensuring consistent security context mapping and integrity protection across different RATs, using uplink counts to maintain secure communication during reselection from 5G to Evolved Packet Core (EPC) networks.

Benefits of technology

This approach enhances mobility support by eliminating inconsistencies in security handling during RAT reselection, ensuring reliable communication and improved network connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Aspects disclosed herein facilitate security handling of EPC reselection from 5GS. An exemplary method in a UE includes transmitting a first TAU ​​request, where the first TAU ​​request is encoded using a first security context associated with a first RAT, where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with a first network entity. The exemplary method also includes transmitting a second TAU request, where the second TAU request includes the first set of information, and where the second TAU request is integrity protected using a second uplink count. The exemplary method also includes communicating based on the first security context and the mapped security context based on at least one of the first uplink count or the second uplink count.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of and priority to U.S. Provisional Application No. 63 / 187,784, entitled "SECURITY HANDLING OF 5GS TO EPC RESELECTION," filed May 12, 2021, and U.S. Nonprovisional Application No. 17 / 662,978, entitled "SECURITY HANDLING OF 5GS TO EPC RESELECTION," filed May 11, 2022, which are expressly incorporated by reference in their entireties.

[0002] The present disclosure relates generally to communication systems, and more particularly, to security features and mechanisms employed in communication systems. [Background technology]

[0003] Wireless communication systems have been widely deployed to provide various telecommunication services, such as telephony, video, data, messaging, and broadcast. A typical wireless communication system may employ multiple access technologies capable of supporting communication with multiple users by sharing available system resources. Examples of such multiple access technologies include Code Division Multiple Access (CDMA) systems, Time Division Multiple Access (TDMA) systems, Frequency Division Multiple Access (FDMA) systems, Orthogonal Frequency Division Multiple Access (OFDMA) systems, Single Carrier Frequency Division Multiple Access (SC-FDMA) systems, and Time Division Synchronous Code Division Multiple Access (TD-SCDMA) systems.

[0004] These multiple access technologies are being adopted in various telecommunications standards to provide common protocols that allow different wireless devices to communicate on a city, national, regional, or even global scale. An exemplary telecommunications standard is 5G New Radio (NR). 5G NR is part of the continuing mobile broadband evolution promulgated by the 3rd Generation Partnership Project (3GPP) to meet new requirements related to latency, reliability, security, scalability (e.g., with the Internet of Things (IoT)), and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine type communications (mMTC), and ultra-reliable low latency communications (URLLC). Some aspects of 5G NR may be based on the 4G Long Term Evolution (LTE) standard. Further improvements are needed for 5G NR technology. These improvements may also be applicable to other multiple access technologies and telecommunications standards that employ these technologies. Summary of the Invention [Means for solving the problem]

[0005] The following presents a simplified summary of one or more aspects in order to provide a basic understanding of such aspects. This summary is not an extensive overview of all contemplated aspects. It is not intended to identify key or critical elements of all aspects, nor is it intended to delineate the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description that is presented later.

[0006] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus for wireless communication are provided. The apparatus may include a user equipment (UE). The exemplary apparatus may send a first tracking area update (TAU) request to a first network entity, where the first TAU ​​request is encoded using a first security context associated with a first radio access technology (RAT), where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also send a second TAU request to the first network entity, where the second TAU request includes the first set of information, and where the second TAU request is integrity protected using a second uplink count. The exemplary apparatus may also derive a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count. Further, the exemplary apparatus may communicate with the first network entity based on the mapped security context.

[0007] In one aspect of the disclosure, a method, a computer-readable medium, and an apparatus for wireless communication are provided. The apparatus may include a UE. The exemplary apparatus may send a first TAU ​​request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT, where the first network entity is associated with the second RAT, the first TAU ​​request is encoded using a first security context associated with the first RAT, and the first TAU ​​request is integrity protected using a first uplink count based on the first security context. The exemplary apparatus may also derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. Furthermore, the exemplary apparatus may send a repetition of the first TAU ​​request to the first network entity, where the repetition of the first TAU ​​request is integrity protected using a second uplink count different from the first uplink count. The exemplary apparatus may also derive a second integrity key based on the first security context, the second uplink count, and the second mapped security context. The exemplary apparatus may also receive a downlink transmission from the first network entity. Additionally, the exemplary apparatus may perform an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key. The exemplary apparatus may also set a master security key for the UE when an integrity check on the downlink transmission is successful using the derived integrity key, where the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.

[0008] In another aspect of the present disclosure, a method, a computer-readable medium, and an apparatus for wireless communication are provided. The apparatus may include a first network entity, such as a mobility management entity (MME). The exemplary apparatus may receive a first TAU ​​request generated by a UE, where the first TAU ​​request is encoded using a first security context associated with a first RAT, where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also output a first context request for a second network entity based on the first TAU ​​request, where the second network entity is associated with the first RAT. Furthermore, the exemplary apparatus may receive a first mapped security context based on the first context request, where the first mapped security context is derived from the first security context and the first uplink count. The exemplary apparatus may also receive a second TAU request, where the second TAU request is encoded using the first security context, where the second TAU request is integrity protected using a second uplink count different from the first uplink count, and where the second TAU request includes the first set of information. The exemplary apparatus may also output a second context request for the second network entity based on the second TAU request. The exemplary apparatus may also receive a second mapped security context based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count. Further, the exemplary apparatus may transmit a downlink message based on the second mapped security context.

[0009] In another aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided for wireless communication. The apparatus may include a second network entity, such as an Access and Mobility Management Function (AMF). An example apparatus may receive a first context request, where the first context request includes at least a first TAU ​​request generated by a UE, where the first TAU ​​request is integrity protected using a first uplink count, where the first TAU ​​request is encoded using a first security context associated with a first RAT, where the first RAT is different from a second RAT associated with the first network entity. The example apparatus may also derive a first mapped security context when a first integrity check in the first TAU ​​request is successful. The example apparatus may output the first mapped security context for the first network entity. Further, the exemplary apparatus may receive a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count. The exemplary apparatus may also derive a second mapped security context when a second integrity check in the second TAU request is successful. Further, the exemplary apparatus may output the second mapped security context for the first network entity.

[0010] In one aspect of the disclosure, a method, a computer-readable medium, and an apparatus are provided for wireless communication in a first network entity, such as an MME. The exemplary apparatus may receive a first TAU ​​request from a UE, where the first TAU ​​request is encoded using a first security context associated with a first RAT, where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also send a first context request to a second network entity based on the first TAU ​​request, where the second network entity is associated with the first RAT. Furthermore, the exemplary apparatus may receive a first mapped security context from the second network entity based on the first context request, where the first mapped security context is derived from the first security context and the first uplink count. Further, the exemplary apparatus may receive a second TAU request from the UE, where the second TAU request is encoded using the first security context, where the second TAU request is integrity protected using a second uplink count different from the first uplink count, and where the second TAU request includes the first set of information. The exemplary apparatus may also send a second context request to a second network entity based on the second TAU request. The exemplary apparatus may also receive a second mapped security context from the second network entity based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count. Further, the exemplary apparatus may send a downlink message to the UE based on the second mapped security context.

[0011] In another aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided for wireless communication in a second network entity, such as an AMF. An exemplary apparatus may receive a first context request from a first network entity, the first context request including at least a first TAU ​​request generated by a UE, the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first RAT, the first RAT being different from a second RAT associated with the first network entity. The exemplary apparatus may also derive a first mapped security context when an integrity check on the first TAU ​​request is successful. Furthermore, the exemplary apparatus may transmit the first mapped security context to the first network entity. The exemplary apparatus may also receive a second context request from the first network entity, where the second context request includes at least a second TAU request generated by the UE, where the second TAU request is integrity protected using a second uplink count different from the first uplink count. Further, the exemplary apparatus may derive a second mapped security context when an integrity check on the second TAU request is successful. The exemplary apparatus may also transmit the second mapped security context to the first network entity.

[0012] In another aspect of the present disclosure, a method, a computer-readable medium, and an apparatus for wireless communication in a UE are provided. An exemplary apparatus may send a first TAU ​​request to a first network entity, where the first TAU ​​request is encoded using a first security context associated with a first RAT, where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also derive a first mapped security context based on the first security context and the first uplink count. Furthermore, the exemplary apparatus may send a second TAU request to the first network entity, where the second TAU request is encoded using the first security context, where the second TAU request is integrity protected using a second uplink count different from the first uplink count, and where the second TAU request includes the first set of information. The exemplary apparatus may also derive a second mapped security context based on the first security context and the second uplink count. Further, the exemplary apparatus may communicate with the first network entity based on the second mapped security context.

[0013] In another aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided for wireless communication in a UE. An exemplary apparatus may send a first TAU ​​request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT, the first network entity being associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, the first TAU ​​request being integrity protected using a first uplink count based on the first security context, and the first TAU ​​request including a first set of information including an identifier mapped to the second RAT associated with the first network entity. The exemplary apparatus may also send a repetition of the first TAU ​​request to the first network entity, the repetition of the first TAU ​​request including the first set of information, and the repetition of the first TAU ​​request being integrity protected using the first uplink count. Further, the exemplary apparatus may derive a mapped security context based on the first security context and the first uplink count. The exemplary apparatus may also communicate with the first network entity based on the mapped security context.

[0014] In another aspect of the present disclosure, a method, a computer-readable medium, and an apparatus are provided for wireless communication in a UE. The exemplary apparatus may send a first TAU ​​request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT, the first network entity being associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, and the first TAU ​​request being integrity protected using a first uplink count based on the first security context. The exemplary apparatus may also derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. Furthermore, the exemplary apparatus may send a repetition of the first TAU ​​request to the first network entity, the first TAU ​​request being integrity protected using a second uplink count different from the first uplink count. The exemplary apparatus may also derive a second integrity key based on the first security context, the second uplink count, and the second mapped security context. Further, the exemplary apparatus may receive a downlink transmission from the first network entity. The exemplary apparatus may also perform an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key. Further, the exemplary apparatus may set a master security key for the UE when performing an integrity check on the downlink transmission using the derived integrity key successfully, where the master security key is set based on the respective integrity key.

[0015] To the accomplishment of the foregoing and related ends, the one or more aspects comprise the features hereinafter fully described and particularly pointed out in the claims. The following description and drawings set forth in detail certain illustrative features of the one or more aspects. These features are indicative, however, of but a few of the various ways in which the principles of the various aspects may be employed. [Brief description of the drawings]

[0016] [Figure 1] FIG. 1 illustrates an example of a wireless communication system and access network. [Figure 2A] FIG. 2 illustrates an example of a first frame in accordance with various aspects of the present disclosure. [Figure 2B] FIG. 1 illustrates an example of a DL channel in a subframe in accordance with various aspects of the present disclosure. [Figure 2C] FIG. 2 illustrates an example of a second frame, according to various aspects of the present disclosure. [Figure 2D] FIG. 1 illustrates an example of a UL channel in a subframe in accordance with various aspects of the present disclosure. [Diagram 3] FIG. 1 illustrates an example of a base station and user equipment (UE) in an access network. [Figure 4] FIG. 1 illustrates an example of a wireless communications system and access network including a first network node, a second network node, a UE, an evolved packet core (EPC), and a core network (e.g., 5G core (5GC)) in accordance with the teachings disclosed herein. [Diagram 5] FIG. 2 illustrates examples of different security contexts in accordance with the teachings disclosed herein. [Figure 6] FIG. 1 illustrates an example communication flow diagram illustrating idle mode mobility from a first RAT to a second RAT in accordance with the teachings disclosed herein. [Figure 7] 1 is a flowchart of a method of wireless communication in a UE in accordance with the teachings disclosed herein. [Figure 8]1 is a flowchart of a method of wireless communication in a UE in accordance with the teachings disclosed herein. [Figure 9] 1 is a flowchart of a method of wireless communication in a UE in accordance with the teachings disclosed herein. [Figure 10] 1 is a flowchart of a method of wireless communication in a UE in accordance with the teachings disclosed herein. [Figure 11] FIG. 2 illustrates an example of a hardware implementation for an exemplary apparatus in accordance with the teachings disclosed herein. [Figure 12] 1 is a flowchart of a method of wireless communication in a network entity in accordance with the teachings disclosed herein. [Figure 13] 1 is a flowchart of a method of wireless communication in a network entity in accordance with the teachings disclosed herein. [Figure 14] 1 is a flowchart of a method of wireless communication in a network entity in accordance with the teachings disclosed herein. [Figure 15] 1 is a flowchart of a method of wireless communication in a network entity in accordance with the teachings disclosed herein. [Figure 16] FIG. 2 illustrates an example of a hardware implementation for an exemplary network entity. [Figure 17] FIG. 2 illustrates an example of a hardware implementation for an exemplary network entity. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0017] Any number of wireless networks may be deployed within a given geographic area. Each wireless network may support a particular radio access technology (RAT) and may operate on one or more frequencies. In some examples, a UE may be connected to a first cell associated with a first RAT, such as 5G. The first cell may not be able to provide support to the UE. For example, 5G coverage may not be ubiquitous in some deployment scenarios. In other examples, the first RAT may not be able to provide a service, such as voice-over, where the voice-over service is initiated via the first RAT. To provide support to the UE, the UE and the first RAT may support reselection from the first RAT to a second RAT that may provide support to the UE for the service. For example, to support voice-over support, the UE and the first cell may support a fallback procedure, where the UE falls back to a second cell associated with the second RAT.

[0018] When the UE falls back from the first cell to the second cell, the UE may perform a reselection procedure. For example, the UE may perform a 5G to Evolved Packet Core (EPC) reselection procedure. When the UE performs the reselection procedure, the UE may initiate a TAU procedure to register itself in the tracking area of ​​the second cell and the associated second RAT.

[0019] To provide security for communications across a wireless communication system, messages exchanged between devices of the wireless communication system may be integrity protected. The integrity protection may be based on a security context including one or more security keys. In some examples, the security context may include one or more security parameters for authentication, integrity protection, and encryption and may be identifiable by a key set identifier (KSI). In some examples, each RAT may be associated with a respective security context. To facilitate reselection from a first cell to a second cell, a network entity of the respective RAT may facilitate mapping a first security context associated with one RAT to a second security context associated with another RAT. For example, a network entity associated with 5G may facilitate mapping a 5G security context to an EPC security context. In some examples, mapping the 5G security context to an EPC security context may include deriving an EPC security context using the 5G security context. The EPC security context may enable the UE to communicate with the second cell associated with the EPC network after switching from the first cell to the second cell.

[0020] In some scenarios, after the UE establishes a connection with the second cell and transmits a TAU request message, a radio link failure (RLF) may occur. In such an example, the UE may retransmit the TAU request message. However, it may be possible that the mapping of the first security context to the second security context may be inconsistent, which may cause a communication failure.

[0021] Examples disclosed herein provide techniques for removing inconsistencies in handling repetitions of a TAU request message described above. In a first aspect, the disclosed techniques may remove the inconsistencies by modifying how a network handles repetitions of a TAU request message. In a second aspect, the disclosed techniques may remove the inconsistencies by modifying how a UE integrity protects a TAU request message. In a third aspect, the disclosed techniques may remove the inconsistencies by modifying how a UE performs integrity verification of a message.

[0022] Aspects presented herein may enable devices of a wireless communication system to facilitate security handling of reselection of EPC from 5GS in case of RLF and retransmission of Evolved Packet System (EPS) TAU requests that facilitate improved mobility support.

[0023] The detailed description set forth below with respect to the drawings describes various configurations and does not represent the only configurations in which the concepts described herein may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of the various concepts. However, these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form in order to avoid obscuring such concepts.

[0024] Certain aspects of a telecommunications system are presented with respect to various apparatus and methods that are described in the following detailed description and illustrated in the accompanying drawings by various blocks, components, circuits, processes, algorithms, and the like (collectively referred to as "elements"). These elements may be implemented using electronic hardware, computer software, or any combination thereof. Whether such elements are implemented as hardware or software depends on the particular application and design constraints imposed on the overall system.

[0025] As an example, an element or any portion of an element or any combination of elements may be implemented as a "processing system" including one or more processors. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, systems on chips (SoCs), baseband processors, field programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gate logic, discrete hardware circuits, and other suitable hardware configured to perform various functions described throughout this disclosure. One or more processors in a processing system may execute software. Software should be broadly construed to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.

[0026] Thus, in one or more exemplary aspects, implementations, and / or use cases, the functions described may be implemented in hardware, software, or any combination thereof. If implemented in software, the functions may be stored on a computer-readable medium or encoded as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media. Storage media may be any available medium that can be accessed by a computer. By way of example, such computer-readable media may comprise random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage, other magnetic storage devices, combinations of types of computer-readable media, or any other medium that can be used to store computer-executable code in the form of instructions or data structures that can be accessed by a computer.

[0027] Although aspects, implementations, and / or use cases are described in this application by illustrating some examples, additional or different aspects, implementations, and / or use cases may occur in many different configurations and scenarios. The aspects, implementations, and / or use cases described herein may be implemented across many different platform types, devices, systems, shapes, sizes, and packaging configurations. For example, the aspects, implementations, and / or use cases may occur with integrated chip implementations and other non-modular component-based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, artificial intelligence (AI)-enabled devices, etc.). Some examples may or may not be specifically targeted to a use case or application, but a wide variety of applicability of the described examples may occur. The aspects, implementations, and / or use cases may range from chip-level or modular components to non-modular, non-chip-level implementations, and even aggregated, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more techniques herein. In some practical settings, devices incorporating the described aspects and features may also include additional components and features for implementing and practicing the claimed and described aspects. For example, transmitting and receiving wireless signals necessarily includes several components for analog and digital purposes (e.g., hardware components including antennas, RF chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). The techniques described herein may be practiced in a wide variety of devices, chip-level components, systems, distributed configurations, aggregated or disaggregated components, end-user devices, etc. of various sizes, shapes, and configurations.

[0028] The deployment of a communication system such as a 5G NR system may be configured in multiple ways with various components or components. In a 5G NR system, or network, a network node, network entity, mobility element of a network, radio access network (RAN) node, core network node, network element, or network equipment, such as a base station (BS), or one or more units (or one or more components) performing a base station function, may be implemented in an aggregated or disaggregated architecture. For example, a BS (such as a Node B (NB), evolved NB (eNB), NR BS, 5G NB, access point (AP), transmit reception point (TRP), or cell) may be implemented as an aggregated base station (also known as a standalone BS or monolithic BS) or a disaggregated base station.

[0029] An aggregated base station may be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. A disaggregated base station may be configured to utilize a protocol stack that is physically or logically distributed among two or more units, such as one or more centralized units (CU), one or more distributed units (DU), or one or more radio units (RU). In some aspects, a CU may be implemented within a RAN node, and one or more DUs may be co-located with the CU or alternatively geographically or virtually distributed across one or more other RAN nodes. A DU may be implemented to communicate with one or more RUs. Each of the CU, DU, and RU may be implemented as a virtual unit, i.e., a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).

[0030] Base station operation or network design may take into account aggregation characteristics of base station functions. For example, disaggregated base stations may be utilized in an integrated access backhaul (IAB) network, an open radio access network (O-RAN, such as a network configuration sponsored by the O-RAN Alliance), or a virtualized radio access network (vRAN, also known as a cloud radio access network (C-RAN)). Disaggregation may include distributing functions across two or more units in various physical locations, as well as distributing functions for at least one unit virtually, thereby enabling flexibility in network design. Various units of a disaggregated base station or disaggregated RAN architecture may be configured for wired or wireless communication with at least one other unit.

[0031] FIG. 1 is a diagram 100 illustrating an example of a wireless communication system and an access network. The illustrated wireless communication system includes a disaggregated base station architecture. The disaggregated base station architecture may include one or more CUs (e.g., CU 110) that may communicate directly with the core network 120 via a backhaul link or indirectly with the core network 120 through one or more disaggregated base station units (a Near-RT RAN Intelligent Controller (RIC) (e.g., Near-RT RIC 125) via an E2 link, or a Non-RT RIC 115 associated with a Service Management and Orchestration (SMO) framework (e.g., SMO framework 105), or both). The CU 110 may communicate with one or more DUs (e.g., DU 130) via respective midhaul links, such as an F1 interface. The DU 130 may communicate with one or more RUs (e.g., RU 140) via respective fronthaul links. The RU 140 may communicate with a respective UE (e.g., the UE 104) via one or more radio frequency (RF) access links. In some implementations, the UE 104 may be served by multiple RUs simultaneously.

[0032] Each of the units, i.e., the CU (e.g., CU 110), DU (e.g., DU 130), RU (e.g., RU 140), and Near-RT RIC (e.g., Near-RT RIC 125), Non-RT RIC (e.g., Non-RT RIC 115), and SMO framework 105, may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) over a wired or wireless transmission medium. Each of the units, or an associated processor or controller that instructs the unit's communication interface, may be configured to communicate with one or more of the other units over a transmission medium. For example, a unit may include a wired interface configured to receive or transmit signals to one or more of the other units over a wired transmission medium. Further, the unit may include a wireless interface, which may include a receiver, transmitter, or transceiver (such as an RF transceiver) configured to receive and / or transmit signals to one or more of the other units over a wireless transmission medium.

[0033] In some aspects, the CU 110 may host one or more upper layer control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptation Protocol (SDAP), etc. Each control function may be implemented with an interface configured to communicate signals with other control functions hosted by the CU 110. The CU 110 may be configured to handle user plane functions (i.e., Central Unit - User Plane (CU-UP)), control plane functions (i.e., Central Unit - Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 110 may be logically divided into one or more CU-UP units and one or more CU-CP units. The CU-UP units, when implemented in an O-RAN configuration, may bidirectionally communicate with the CU-CP units via an interface, such as an E1 interface. The CU 110 may be implemented to communicate with the DU 130, as needed, for network control and signaling.

[0034] The DU 130 may correspond to a logical unit, including one or more base station functions, to control the operation of one or more RUs. In some aspects, the DU 130 may host one or more of a radio link control (RLC) layer, a medium access control (MAC) layer, and one or more higher physical (PHY) layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation, demodulation, etc.), at least in part according to a functional division such as that defined by 3GPP. In some aspects, the DU 130 may further host one or more lower PHY layers. Each layer (or module) may be implemented with an interface configured to communicate signals with other layers (or modules) hosted by the DU 130 or with a control function hosted by the CU 110.

[0035] The lower layer functions may be implemented by one or more RUs. In some deployments, the RU 140 controlled by the DU 130 may correspond to a logical node hosting RF processing functions, or lower PHY layer functions (such as performing Fast Fourier Transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering, etc.), or both, based at least in part on a functional division such as a lower layer functional division. In such an architecture, the RU 140 may be implemented to handle over-the-air (OTA) communications with one or more UEs (e.g., the UE 104). In some implementations, real-time and non-real-time aspects of control and user plane communications with the RU 140 may be controlled by a corresponding DU. In some scenarios, this configuration may enable the DU and CU 110 to be implemented in a cloud-based RAN architecture, such as a vRAN architecture.

[0036] The SMO framework 105 may be configured to support RAN deployment and provisioning of non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 105 may be configured to support deployment of dedicated physical resources for RAN coverage requirements that may be managed via an operation and maintenance interface (such as an O1 interface). For virtualized network elements, the SMO framework 105 may be configured to interact with a cloud computing platform (such as an open cloud (O-Cloud) 190) to perform network element lifecycle management (such as to instantiate virtualized network elements) via a cloud computing platform interface (such as an O2 interface). Such virtualized network elements may include, but are not limited to, a CU, a DU, a RU, and a Near-RT RIC. In some implementations, the SMO framework 105 may communicate with hardware aspects of a 4G RAN, such as an open eNB (O-eNB) 111, via an O1 interface. Additionally, in some implementations, the SMO framework 105 may communicate directly with one or more RUs via an O1 interface. The SMO framework 105 may also include a Non-RT RIC 115 configured to support the functionality of the SMO framework 105.

[0037] The Non-RT RIC 115 may be configured to include logic functions that enable non-real-time control and optimization of RAN elements and resources, artificial intelligence (AI) / machine learning (ML) (AI / ML) workflows including model training and updates, or policy-based guidance of applications / functions in the Near-RT RIC 125. The Non-RT RIC 115 may be coupled to or in communication with the Near-RT RIC 125 (e.g., via an A1 interface). The Near-RT RIC 125 may be configured to include logic functions that enable near-real-time control and optimization of RAN elements and resources through data collection and action over interfaces (e.g., via an E2 interface) that connect one or more CUs, one or more DUs, or both, and the O-eNB with the Near-RT RIC 125.

[0038] In some implementations, the Non-RT RIC 115 may receive parameters or external enrichment information from an external server to generate the AI / ML models to be deployed in the Near-RT RIC 125. Such information may be utilized by the Near-RT RIC 125 and may be received in the SMO framework 105 or the Non-RT RIC 115 from non-network data sources or from network functions. In some examples, the Non-RT RIC 115 or the Near-RT RIC 125 may be configured to adjust RAN behavior or performance. For example, the Non-RT RIC 115 may monitor long-term trends and patterns for performance and employ the AI / ML models to take corrective actions through the SMO framework 105 (e.g., reconfiguration via O1) or through the creation of RAN management policies (e.g., A1 policies).

[0039] At least one of the CU 110, the DU 130, and the RU 140 may be referred to as a base station 102. Thus, the base station 102 may include one or more of the CU 110, the DU 130, and the RU 140 (each component shown with a dotted line to indicate that each component may or may not be included in the base station 102). The base station 102 provides an access point to the core network 120 for the UE 104. The base station 102 may include a macro cell (a high-power cellular base station) and / or a small cell (a low-power cellular base station). Small cells include femto cells, pico cells, and micro cells. A network including both small cells and macro cells may be known as a heterogeneous network. A heterogeneous network may also include a Home Evolved Node B (eNB) (HeNB) that may serve restricted groups known as Closed Subscriber Groups (CSGs). A communication link between a RU (e.g., RU 140) and a UE (e.g., UE 104) may include uplink (UL) (also referred to as reverse link) transmissions from the UE 104 to the RU 140, and / or downlink (DL) (also referred to as forward link) transmissions from the RU 140 to the UE 104. The communication link may use multiple-input multiple-output (MIMO) antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be through one or more carriers. The base station 102 / UE 104 may use spectrum with a bandwidth of up to Y MHz (e.g., 5, 10, 15, 20, 100, 400 MHz, etc.) per carrier allocated in carrier aggregation with up to a total of Yx MHz (x component carriers) used for transmission in each direction. The carriers may or may not be adjacent to each other. The allocation of carriers may be asymmetric with respect to DL and UL (e.g., more or fewer carriers may be allocated for DL ​​than for UL). The component carriers may include a primary component carrier and one or more secondary component carriers.The primary component carrier may be referred to as a primary cell (PCell), and the secondary component carrier may be referred to as a secondary cell (SCell).

[0040] Several UEs may communicate with each other using device-to-device (D2D) communication (e.g., D2D communication link 158). The D2D communication link 158 may use DL / UL wireless wide area network (WWAN) spectrum. The D2D communication link 158 may use one or more sidelink channels, such as a physical sidelink broadcast channel (PSBCH), a physical sidelink discovery channel (PSDCH), a physical sidelink shared channel (PSSCH), and a physical sidelink control channel (PSCCH). The D2D communication may be through various wireless D2D communication systems, such as, for example, Bluetooth, Wi-Fi based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, LTE, or NR.

[0041] The wireless communication system may further include a Wi-Fi AP 150 (also referred to as a Wi-Fi Station (STA)) in communication with the UE 104 via a communication link 154, such as in the 5 GHz unlicensed frequency spectrum. When communicating in the unlicensed frequency spectrum, the UE 104 / Wi-Fi AP 150 may perform clear channel assessment (CCA) prior to communicating to determine if a channel is available.

[0042] The electromagnetic spectrum is often subdivided into various classes, bands, channels, etc. based on frequency / wavelength. In 5G NR, two initial operating bands have been identified with the frequency range designations FR1 (410 MHz-7.125 GHz) and FR2 (24.25 GHz-52.6 GHz). Although a portion of FR1 is higher than 6 GHz, FR1 is often referred to (interchangeably) as the "sub-6 GHz" band in various documents and papers. Similar nomenclature issues may arise with respect to FR2, which is often referred to (interchangeably) as the "mmWave" band in documents and papers, even though it is different from the extremely high frequency (EHF) band (30 GHz-300 GHz) identified as the "mmWave" band by the International Telecommunications Union (ITU).

[0043] Frequencies between FR1 and FR2 are often referred to as mid-band frequencies. Recent 5G NR studies have identified operating bands for these mid-band frequencies as frequency range designation FR3 (7.125 GHz to 24.25 GHz). Frequency bands that fall within FR3 may inherit FR1 and / or FR2 characteristics, and thus may effectively extend the features of FR1 and / or FR2 to the mid-band frequencies. In addition, higher frequency bands are currently being considered to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as frequency range designations FR2-2 (52.6 GHz to 71 GHz), FR4 (71 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands falls within the EHF band.

[0044] With the above aspects in mind, unless otherwise specified, terms such as "sub-6 GHz," as used herein, may broadly refer to frequencies that may be below 6 GHz, may be within FR1, or may include mid-band frequencies. Additionally, unless otherwise specified, terms such as "mm-wave," as used herein, may broadly refer to frequencies that may include mid-band frequencies, may be within FR2, FR4, FR2-2, and / or FR5, or may be within the EHF band.

[0045] The base station 102 and the UE 104 may each include multiple antennas, such as antenna elements, antenna panels, and / or antenna arrays to facilitate beamforming. The base station 102 may transmit a beamformed signal 182 to the UE 104 in one or more transmit directions. The UE 104 may receive the beamformed signal from the base station 102 in one or more receive directions. The UE 104 may also transmit a beamformed signal 184 to the base station 102 in one or more transmit directions. The base station 102 may receive the beamformed signal from the UE 104 in one or more receive directions. The base station 102 / UE 104 may perform beam training to determine the best receive and transmit directions for each of the base station 102 / UE 104. The transmit and receive directions for the base station 102 may be the same or different. The transmit and receive directions for the UE 104 may be the same or different.

[0046] The base station 102 may include and / or be referred to as a gNB, Node B, eNB, access point, base transceiver station, radio base station, radio transceiver, transceiver function, basic service set (BSS), extended service set (ESS), transmit reception point (TRP), network node, network entity, network equipment, or some other suitable terminology. The base station 102 may be implemented as an integrated access and backhaul (IAB) node, a relay node, a sidelink node, an aggregated (monolithic) base station with a baseband unit (BBU) (including a CU and a DU) and a RU, or as a disaggregated base station including one or more of a CU, a DU, and / or a RU. The set of base stations, which may include disaggregated and / or aggregated base stations, may be referred to as a Next Generation (NG) RAN (NG-RAN).

[0047] The core network 120 may include an Access and Mobility Management Function (AMF) (e.g., AMF 161), a Session Management Function (SMF) (e.g., SMF 162), a User Plane Function (UPF) (e.g., UPF 163), a Unified Data Management (UDM) (e.g., UDM 164), one or more location servers 168, and other functional entities. The AMF 161 is a control node that handles signaling between the UE 104 and the core network 120. The AMF 161 supports registration management, connection management, mobility management, and other functions. The SMF 162 supports session management and other functions. The UPF 163 supports packet routing, packet forwarding, and other functions. The UDM 164 supports authentication and key agreement (AKA) credential generation, user identity handling, access authorization, and subscription management. The one or more location servers 168 are shown as including a Gateway Mobile Location Center (GMLC) (e.g., GMLC 165) and a Location Management Function (LMF) (e.g., LMF 166). In general, however, the one or more location servers 168 may include one or more location / positioning servers, which may include one or more of the GMLC 165, LMF 166, Position Determination Entity (PDE), Serving Mobile Location Center (SMLC), Mobile Positioning Center (MPC), etc. The GMLC 165 and LMF 166 support UE location services. The GMLC 165 provides an interface for clients / applications (e.g., emergency services) to access UE positioning information. The LMF 166 receives measurements and assistance information from the NG-RAN and the UE 104 via the AMF 161 to calculate the position of the UE 104. The NG-RAN may utilize one or more positioning methods to determine the position of the UE 104. Positioning the UE 104 may involve signal measurements, a position estimate, and any velocity calculations based on the measurements. The signal measurements may be performed by the UE 104 and / or a serving base station (e.g., base station 102).The measured signals may be based on one or more of a satellite positioning system (SPS) 170 (e.g., one or more of a global navigation satellite system (GNSS), a global positioning system (GPS), a non-terrestrial network (NTN), or other satellite position / location system), LTE signals, wireless local area network (WLAN) signals, Bluetooth signals, a terrestrial beacon system (TBS), sensor-based information (e.g., barometric pressure sensors, motion sensors), NR enhanced cell ID (NR E-CID) methods, NR signals (e.g., multi-round trip time (Multi-RTT), DL Angle of Launch (DL-AoD), DL Time Difference of Arrival (DL-TDOA), UL Time Difference of Arrival (UL-TDOA), and UL Angle of Arrival (UL-AoA) positioning), and / or other systems / signals / sensors.

[0048] Examples of UEs include cellular phones, smartphones, session initiation protocol (SIP) phones, laptops, personal digital assistants (PDAs), satellite radios, global positioning systems, multimedia devices, video devices, digital audio players (e.g., MP3 players), cameras, game consoles, tablets, smart devices, wearable devices, vehicles, electric meters, gas pumps, large or small cooking appliances, healthcare devices, implants, sensors / actuators, displays, or any other similarly functional devices. Some of the UEs may be referred to as IoT devices (e.g., parking meters, gas pumps, toasters, vehicles, heart monitors, etc.). The UE 104 may also be referred to as a station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, or any other suitable terminology. In some scenarios, the term UE may also be applied to one or more companion devices in a device constellation configuration, etc. One or more of these devices may collectively access the network and / or individually access the network.

[0049] Referring again to FIG. 1, in some aspects, a device in communication with a base station, such as the UE 104, may be configured to manage one or more aspects of wireless communication. For example, the UE 104 may include a UE security handling component 198 configured to facilitate security handling of EPC reselection from 5GS in case of RLF and retransmission of EPS TAU requests. In some aspects, the UE security handling component 198 may be configured to send a first TAU ​​request to a first network entity, where the first TAU ​​request is encoded using a first security context associated with the first RAT, where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The uplink count may indicate an amount of uplink messages communicated. The example UE security handling component 198 may also be configured to send a second TAU request to the first network entity, where the second TAU request includes the first set of information and where the second TAU request is integrity protected using the second uplink count. Further, the example UE security handling component 198 may be configured to derive a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count. The example UE security handling component 198 may also be configured to communicate with the first network entity based on the mapped security context.

[0050] In another aspect, the UE security handling component 198 may be configured to send a first TAU ​​request to a first network entity when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT different from the first RAT, the first network entity being associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, and the first TAU ​​request being integrity protected using a first uplink count based on the first security context. The example UE security handling component 198 may also be configured to derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. The integrity key may be a key used to perform an integrity check on the communication. Further, the example UE security handling component 198 may be configured to send a repetition of the first TAU ​​request to the first network entity, where the repetition of the first TAU ​​request is integrity protected using a second uplink count different from the first uplink count. The example UE security handling component 198 may also be configured to derive a second integrity key based on the first security context, the second uplink count, and the second mapped security context. Further, the example UE security handling component 198 may be configured to receive a downlink transmission from the first network entity. The example UE security handling component 198 may also be configured to perform an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key. The integrity check may be performed using the integrity key to verify the integrity of the downlink transmission.Additionally, the example UE security handling component 198 may be configured to set a master security key for the UE when an integrity check on a downlink transmission using the derived integrity key is successful, where the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key. The master security key may be a key used to derive other security keys.

[0051] In some aspects, the UE security handling component 198 may be configured to send a first TAU ​​request to the first network entity. The first TAU ​​request may be encoded using a first security context associated with the first RAT. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, and the first TAU ​​request may include a first set of information including an identifier mapped to a second RAT associated with the first network entity. The example UE security handling component 198 may also be configured to derive a first mapped security context based on the first security context and the first uplink count. The example UE security handling component 198 may also be configured to send a second TAU request to the first network entity. The second TAU request may be encoded using the first security context, and the second TAU request may be integrity protected using a second uplink count different from the first uplink count, and the second TAU request may include the first set of information. The example UE security handling component 198 may also be configured to derive a second mapped security context based on the first security context and the second uplink count. The example UE security handling component 198 may also be configured to communicate with the first network entity based on the second mapped security context.

[0052] In another aspect, the UE security handling component 198 may be configured to send a first TAU ​​request to a first network entity when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT different from the first RAT. The first network entity may be associated with the second RAT. The first TAU ​​request may be encoded using a first security context associated with the first RAT, the first TAU ​​request may be integrity protected using a first uplink count based on the first security context, and the first TAU ​​request may include a first set of information including an identifier mapped to the second RAT associated with the first network entity.

[0053] The example UE security handling component 198 may also be configured to send a first TAU ​​request iteration to the first network entity. The first TAU ​​request iteration may include the first set of information, and the first TAU ​​request iteration may be integrity protected using the first uplink count. The example UE security handling component 198 may also be configured to derive a mapped security context based on the first security context and the first uplink count. Furthermore, the example UE security handling component 198 may be configured to communicate with the first network entity based on the mapped security context.

[0054] In another aspect, the UE security handling component 198 may be configured to send a first TAU ​​request to a first network entity when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT different from the first RAT. The first network entity may be associated with the second RAT. The first TAU ​​request may be encoded using a first security context associated with the first RAT, and the first TAU ​​request may be integrity protected using a first uplink count based on the first security context. The example UE security handling component 198 may also be configured to derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. The example UE security handling component 198 may also be configured to send a repetition of the first TAU ​​request to the first network entity. The repetition of the first TAU ​​request may be integrity protected using a second uplink count different from the first uplink count. Further, the example UE security handling component 198 may also be configured to derive a second integrity key based on the first security context, the second uplink count, and the second mapped security context. The example UE security handling component 198 may also be configured to receive a downlink transmission from the first network entity. The example UE security handling component 198 may also be configured to perform an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key. The example UE security handling component 198 may also be configured to set a master security key for the UE when the performance of the integrity check on the downlink transmission using the derived integrity key is successful. The master security key is set based on the respective integrity key.

[0055] In another configuration, a network entity may be configured to manage one or more aspects of wireless communications by facilitating security handling of EPC reselection from 5GS in case of RLF and retransmission of EPS TAU requests that facilitate improved mobility support. For example, the network entity may include a network security handling component 199. Aspects of the network security handling component 199 may be implemented by an MME, an AMF (e.g., AMF 161), and / or a base station (e.g., base station 102).

[0056] The network security handling component 199 may be configured to receive a first TAU ​​request generated by the UE, where the first TAU ​​request is encoded using a first security context associated with the first RAT, where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. Further, the network security handling component 199 may be configured to output a first context request for a second network entity based on the first TAU ​​request, where the second network entity is associated with the first RAT. The network security handling component 199 may also be configured to receive a first mapped security context based on the first context request, where the first mapped security context is derived from the first security context and the first uplink count. Further, the network security handling component 199 may be configured to receive a second TAU request, where the second TAU request is encoded using the first security context, where the second TAU request is integrity protected using a second uplink count different from the first uplink count, and where the second TAU request includes the first set of information. The network security handling component 199 may also be configured to output a second context request for the second network entity based on the second TAU request. Further, the network security handling component 199 may be configured to receive a second mapped security context based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count.The network security handling component 199 may also be configured to transmit the downlink message based on the second mapped security context.

[0057] In another aspect, the network security handling component 199 may be configured to receive a first context request, the first context request including at least a first TAU ​​request generated by the UE, the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first RAT, the first RAT being different from a second RAT associated with the first network entity. Further, the network security handling component 199 may be configured to derive a first mapped security context when a first integrity check in the first TAU ​​request is successful. The network security handling component 199 may also be configured to output the first mapped security context for the first network entity. Further, the network security handling component 199 may be configured to receive a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count. The network security handling component 199 may also be configured to derive a second mapped security context when a second integrity check in the second TAU request is successful. Further, the network security handling component 199 may be configured to output the second mapped security context for the first network entity.

[0058] In some aspects, the network security handling component 199 may be configured to receive a first TAU ​​request from the UE. The first TAU ​​request may be encoded using a first security context associated with the first RAT, the first TAU ​​request may be integrity protected using a first uplink count based on the first security context, and the first TAU ​​request may include a first set of information including an identifier mapped to a second RAT associated with the first network entity. The example network security handling component 199 may also be configured to send a first context request to a second network entity based on the first TAU ​​request. The second network entity may be associated with the first RAT. The example network security handling component 199 may also be configured to receive a first mapped security context from the second network entity based on the first context request. The first mapped security context may be derived from the first security context and the first uplink count. Further, the example network security handling component 199 may be configured to receive a second TAU request from the UE. The second TAU request may be encoded using the first security context, the second TAU request may be integrity protected using a second uplink count different from the first uplink count, and the second TAU request may include the first set of information. The example network security handling component 199 may also be configured to send a second context request to a second network entity based on the second TAU request. Further, the example network security handling component 199 may be configured to receive a second mapped security context from the second network entity based on the second context request. The second mapped security context may be derived from the first security context and the second uplink count.The example network security handling component 199 may also be configured to send a downlink message to the UE based on the second mapped security context.

[0059] In another aspect, the network security handling component 199 may be configured to receive a first context request from a first network entity, the first context request including at least a first TAU ​​request generated by the UE. The first TAU ​​request may be integrity protected using a first uplink count, and the first TAU ​​request may be encoded using a first security context associated with a first RAT, which may be different from a second RAT associated with the first network entity. The example network security handling component 199 may also be configured to derive a first mapped security context when an integrity check on the first TAU ​​request is successful. The example network security handling component 199 may also be configured to transmit the first mapped security context to the first network entity. Furthermore, the example network security handling component 199 may be configured to receive a second context request from the first network entity. The second context request may include at least a second TAU request generated by the UE, where the second TAU request is integrity protected using a second uplink count different from the first uplink count. The example network security handling component 199 may also be configured to derive a second mapped security context when an integrity check on the second TAU request is successful. The example network security handling component 199 may also be configured to transmit the second mapped security context to the first network entity.

[0060] Aspects presented herein may enable devices of a wireless communication system to facilitate security handling of EPC reselection from 5GS in case of RLF and retransmission of EPS TAU requests that facilitate improved mobility support.

[0061] Although the following description provides examples directed to 5G NR (and, in particular, 5G to EPC reselection), the concepts described herein may be applicable to other similar fields, such as LTE, LTE-A, CDMA, GSM, and / or other wireless technologies, where a UE may perform reselection from a cell associated with a first RAT to a second cell associated with a second RAT.

[0062] FIG. 2A is a diagram 200 illustrating an example of a first subframe in a 5G NR frame structure. FIG. 2B is a diagram 230 illustrating an example of a DL channel in a 5G NR subframe. FIG. 2C is a diagram 250 illustrating an example of a second subframe in a 5G NR frame structure. FIG. 2D is a diagram 280 illustrating an example of a UL channel in a 5G NR subframe. The 5G NR frame structure may be frequency division duplex (FDD) where for a particular set of subcarriers (carrier system bandwidth), subframes within the set of subcarriers are dedicated to either DL or UL, or may be time division duplex (TDD) where for a particular set of subcarriers (carrier system bandwidth), subframes within the set of subcarriers are dedicated to both DL and UL. In the example provided by FIG. 2A, FIG. 2C, the 5G NR frame structure is assumed to be TDD, subframe 4 is configured with slot format 28 (mostly DL), where D is DL, U is UL, and F is flexible for DL / UL use, and subframe 3 is configured with slot format 1 (all UL). Subframes 3 and 4 are shown with slot formats 1 and 28, respectively, although any particular subframe may be configured with any of the various available slot formats 0-61. Slot formats 0 and 1 are all DL and UL, respectively. The other slot formats 2-61 include a mix of DL, UL, and flexible symbols. The UE is configured with the slot format through a received slot format indicator (SFI) (dynamically through DL control information (DCI) or semi-statically / statically through radio resource control (RRC) signaling). Note that the following description also applies to the 5G NR frame structure, which is TDD.

[0063] 2A-2D show a frame structure, the embodiments of the present disclosure may be applicable to other wireless communication technologies that may have different frame structures and / or different channels. A frame (10 ms) may be divided into 10 equally sized subframes (1 ms). Each subframe may include one or more time slots. A subframe may also include a minislot that may include 7, 4, or 2 symbols. Each slot may include 14 or 12 symbols depending on whether the cyclic prefix (CP) is normal or extended. For normal CP, each slot may include 14 symbols, and for extended CP, each slot may include 12 symbols. Symbols on the DL may be CP Orthogonal Frequency Division Multiplexing (OFDM) (CP-OFDM) symbols. Symbols on the UL may be CP-OFDM symbols (for high throughput scenarios) or Discrete Fourier Transform (DFT) Spread OFDM (DFT-s-OFDM) symbols (also called Single Carrier Frequency Division Multiple Access (SC-FDMA) symbols) (for power limited scenarios, limited to single stream transmission). The number of slots in a subframe is based on the CP and numerology. The numerology defines the subcarrier spacing (SCS), which effectively defines the symbol length / duration, which is equal to 1 / SCS.

[0064] [Table 1]

[0065] For normal CP (14 symbols / slot), the different numerologies μ0-4 allow 1, 2, 4, 8, and 16 slots per subframe, respectively. For extended CP, numerology 2 allows 4 slots per subframe. Thus, for normal CP and numerology μ, there are 14 symbols / slot and 2μ slots / subframe. As shown in Table 1, the subcarrier spacing is 2 μ* may be equal to 15 kHz, where μ is a numerology 0-4. Thus, numerology μ=0 has a subcarrier spacing of 15 kHz, and numerology μ=4 has a subcarrier spacing of 240 kHz. The symbol length / duration is inversely related to the subcarrier spacing. Figures 2A-2D provide an example of a normal CP with 14 symbols per slot and a numerology μ=2 with 4 slots per subframe. The slot duration is 0.25 ms, the subcarrier spacing is 60 kHz, and the symbol duration is approximately 16.67 μs. Within a set of frames, there may be one or more different bandwidth parts (BWPs) (see Figure 2B) that are frequency division multiplexed. Each BWP may have a specific numerology and CP (normal or extended).

[0066] A resource grid can be used to represent the frame structure. Each time slot contains a resource block (RB), also called a physical RB (PRB), that spans 12 consecutive subcarriers. The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.

[0067] As shown in Figure 2A, some of the REs carry reference (pilot) signals (RS) for the UE. The RS may include demodulation RS (DM-RS) (shown as R for one particular configuration, but other DM-RS configurations are possible) and channel state information reference signals (CSI-RS) for channel estimation at the UE. The RS may also include beam measurement RS (BRS), beam improvement RS (BRRS), and phase tracking RS (PT-RS).

[0068] FIG. 2B illustrates an example of various DL channels in a subframe of a frame. A physical downlink control channel (PDCCH) carries DCI in one or more control channel elements (CCEs) (e.g., 1, 2, 4, 8, or 16 CCEs), each CCE including 6 RE groups (REGs), each REG including 12 consecutive REs in an OFDM symbol of an RB. The PDCCHs in one BWP may be referred to as a control resource set (CORESET). A UE is configured to monitor PDCCH candidates in a PDCCH search space (e.g., common search space, UE-specific search space) during a PDCCH monitoring opportunity on the CORESET, where the PDCCH candidates have different DCI formats and different aggregation levels. Additional BWPs may be located at higher and / or lower frequencies across the channel bandwidth. A primary synchronization signal (PSS) may be in symbol 2 of a particular subframe of a frame. The PSS is used by the UE 104 to determine subframe / symbol timing and physical layer identity. The secondary synchronization signal (SSS) may be in symbol 4 of a particular subframe of a frame. The SSS is used by the UE to determine the physical layer cell identity group number and radio frame timing. Based on the physical layer identity and the physical layer cell identity group number, the UE can determine the physical cell identifier (PCI). Based on the PCI, the UE can determine the location of the DM-RS. The physical broadcast channel (PBCH), which carries the master information block (MIB), may be logically grouped with the PSS and SSS to form a synchronization signal (SS) / PBCH block (also called SS block (SSB)). The MIB provides the number of RBs in the system bandwidth and the system frame number (SFN). The physical downlink shared channel (PDSCH) carries user data, broadcast system information not transmitted over the PBCH, such as the system information block (SIB), and paging messages.

[0069] As shown in FIG. 2C, some of the REs carry DM-RS (denoted as R for one particular configuration, but other DM-RS configurations are possible) for channel estimation at the base station. The UE may transmit DM-RS for the physical uplink control channel (PUCCH) and DM-RS for the physical uplink shared channel (PUSCH). The PUSCH DM-RS may be transmitted in the first one or two symbols of the PUSCH. The PUCCH DM-RS may be transmitted in different configurations depending on whether a short or long PUCCH is transmitted and depending on the particular PUCCH format used. The UE may transmit a sounding reference signal (SRS). The SRS may be transmitted in the last symbol of a subframe. The SRS may have a comb structure, and the UE may transmit the SRS in one of the combs. The SRS may be used by the base station for channel quality estimation to enable frequency-dependent scheduling on the UL.

[0070] FIG. 2D illustrates an example of various UL channels within a subframe of a frame. The PUCCH, in one configuration, may be located as shown. The PUCCH carries uplink control information (UCI) such as scheduling requests, channel quality indicators (CQIs), precoding matrix indicators (PMIs), rank indicators (RIs), and hybrid automatic repeat request (HARQ) acknowledgment (ACK) (HARQ-ACK) feedback (i.e., one or more HARQ ACK bits indicating one or more ACKs and / or negative ACKs (NACKs)). The PUSCH carries data and may additionally be used to carry buffer status reports (BSRs), power headroom reports (PHRs), and / or UCIs.

[0071] 3 is a block diagram illustrating an example of a first wireless device configured to exchange wireless communications with a second wireless device. In the illustrated example of FIG. 3, the first wireless device may include a base station 310, and the second wireless device may include a UE 350, and the base station 310 may be in communication with the UE 350 in an access network. As shown in FIG. 3, the base station 310 includes a transmit processor (TX processor 316), a transmitter 318Tx, a receiver 318Rx, an antenna 320, a receive processor (RX processor 370), a channel estimator 374, a controller / processor 375, and a memory 376. The exemplary UE 350 includes an antenna 352, a transmitter 354Tx, a receiver 354Rx, a RX processor 356, a channel estimator 358, a controller / processor 359, a memory 360, and a TX processor 368. In other examples, the base station 310 and / or the UE 350 may include additional or alternative components.

[0072] In the DL, Internet Protocol (IP) packets may be provided to a controller / processor 375. The controller / processor 375 implements Layer 3 and Layer 2 functionality. Layer 3 includes a Radio Resource Control (RRC) layer, and Layer 2 includes a Service Data Adaptation Protocol (SDAP) layer, a Packet Data Convergence Protocol (PDCP) layer, a Radio Link Control (RLC) layer, and a Medium Access Control (MAC) layer. The controller / processor 375 provides RRC layer functions associated with broadcasting system information (e.g., MIBs, SIBs), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-radio access technology (RAT) mobility, and measurement configuration for UE measurement reporting; PDCP layer functions associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functions associated with transfer of upper layer packet data units (PDUs), error correction via ARQ, concatenation, segmentation, and reassembly of RLC service data units (SDUs), re-segmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority handling, and logical channel prioritization.

[0073] The TX processor 316 and the RX processor 370 implement Layer 1 functions associated with various signal processing functions. Layer 1, including the physical (PHY) layer, may include error detection on transport channels, forward error correction (FEC) coding / decoding of transport channels, interleaving, rate matching, mapping onto physical channels, modulation / demodulation of physical channels, and MIMO antenna processing. The TX processor 316 handles mapping to signal constellations based on various modulation schemes (e.g., binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), M-phase shift keying (M-PSK), M-quadrature amplitude modulation (M-QAM)). The coded and modulated symbols may then be split into parallel streams. Each stream may then be mapped to OFDM subcarriers, multiplexed with reference signals (e.g., pilots) in the time and / or frequency domains, and then combined together using an inverse fast Fourier transform (IFFT) to generate a physical channel carrying a time-domain OFDM symbol stream. The OFDM stream is spatially precoded to generate multiple spatial streams. Channel estimates from a channel estimator 374 may be used to determine the coding and modulation scheme, as well as for spatial processing. The channel estimates may be derived from a reference signal and / or channel condition feedback transmitted by the UE 350. Each spatial stream may then be provided to a different one of the antennas 320 via a separate transmitter (e.g., transmitter 318Tx). Each transmitter 318Tx may modulate a radio frequency (RF) carrier with a respective spatial stream for transmission.

[0074] At the UE 350, each receiver 354Rx receives a signal through its respective one of the antennas 352. Each receiver 354Rx recovers information modulated onto an RF carrier and provides the information to the RX processor 356. The TX processor 368 and the RX processor 356 implement Layer 1 functionality associated with various signal processing functions. The RX processor 356 may perform spatial processing on the information to recover any spatial streams destined for the UE 350. If multiple spatial streams are destined for the UE 350, two or more of the multiple spatial streams may be combined into a single OFDM symbol stream by the RX processor 356. The RX processor 356 then converts the OFDM symbol stream from the time domain to the frequency domain using a Fast Fourier Transform (FFT). The frequency domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, as well as the reference signal, are recovered and demodulated by determining the most likely signal constellation point transmitted by the base station 310. These soft decisions may be based on channel estimates calculated by a channel estimator 358. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally transmitted by the base station 310 on the physical channel. The data and control signals are then provided to a controller / processor 359, which implements Layer 3 and Layer 2 functions.

[0075] The controller / processor 359 may be associated with a memory 360 that stores program codes and data. The memory 360 may be referred to as a computer-readable medium. In the UL, the controller / processor 359 provides demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets. The controller / processor 359 is also responsible for error detection using ACK and / or NACK protocols to support HARQ operations.

[0076] Similar to the functionality described with respect to DL transmission by the base station 310, the controller / processor 359 provides RRC layer functionality associated with system information (e.g., MIBs, SIBs) collection, RRC connection, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with transfer of upper layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto the TB, demultiplexing of MAC SDUs from the TB, scheduling information reporting, error correction via HARQ, priority handling, and logical channel prioritization.

[0077] Channel estimates derived by the channel estimator 358 from a reference signal or feedback transmitted by the base station 310 may be used by the TX processor 368 to select an appropriate coding and modulation scheme and to facilitate spatial processing. The spatial streams generated by the TX processor 368 may be provided to different ones of the antennas 352 via separate transmitters (e.g., transmitters 354Tx). Each transmitter 354Tx may modulate an RF carrier with a respective spatial stream for transmission.

[0078] The UL transmissions are processed at the base station 310 in a manner similar to that described with respect to the receiver functions at the UE 350. Each receiver 318Rx receives a signal through its respective one of the antennas 320. Each receiver 318Rx recovers the information modulated onto the RF carrier and provides the information to the RX processor 370.

[0079] The controller / processor 375 may be associated with a memory 376 that stores program codes and data. The memory 376 may be referred to as a computer-readable medium. In the UL, the controller / processor 375 performs demultiplexing between transport and logical channels, packet reassembly, decryption, header decompression, and control signal processing to recover IP packets. The controller / processor 375 is also responsible for error detection using ACK and / or NACK protocols to support HARQ operations.

[0080] At least one of the TX processor 368, the RX processor 356, and the controller / processor 359 may be configured to perform aspects associated with the UE security handling component 198 of FIG.

[0081] At least one of the TX processor 316, the RX processor 370, and the controller / processor 375 may be configured to perform aspects associated with the network security handling component 199 of FIG.

[0082] 4 is a diagram 400 illustrating an example of a wireless communication system and access network including a first network node 402a, a second network node 402b, a UE 404, an evolved packet core (e.g., EPC 410), and a core network 430 (e.g., 5G Core (5GC)) as presented herein. Aspects of the first network node 402a and / or the second network node 402b, which may be collectively referred to herein as "network nodes 402a / 402b", may be implemented by the base station 102 of FIG. 1, and / or components of the base station 102, such as the CU 110, the DU 130, and / or the RU 140. Aspects of the UE 404 may be implemented by the UE 104 of FIG. 1.

[0083] 4, the first network node 402a may be configured for 4G LTE (collectively referred to as Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN)) and may interface with the EPC 410 through a first backhaul link 452 (e.g., an S1 interface). The second network node 402b may be configured for 5G NR (collectively referred to as Next Generation RAN (NG-RAN)) and may interface with the core network 430 through a second backhaul link 454. In addition to other functions, the network nodes 402a / 402b may perform one or more of the following functions: forwarding user data, encryption and decryption of radio channels, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection setup and release, load balancing, distribution for non-access stratum (NAS) messages, NAS node selection, synchronization, radio access network (RAN) sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracking, RAN information management (RIM), paging, positioning, and delivery of alert messages. The network nodes 402a / 402b may communicate with each other directly or indirectly (e.g., through the EPC 410 or the core network 430) via a third backhaul link 456 (e.g., an X2 interface). The first backhaul link 452, the second backhaul link 454, and the third backhaul link 456 may be wired or wireless.

[0084] The network nodes 402a / 402b may wirelessly communicate with the UE 404. Each of the network nodes 402a / 402b may provide communication coverage in a respective geographic coverage area 406. There may be overlapping geographic coverage areas. In the example of FIG. 4, the communication link 408 between the network nodes 402a / 402b and the UE 404 may include uplink (UL) (also referred to as reverse link) transmissions from the UE 404 to the respective network node, and / or downlink (DL) (also referred to as forward link) transmissions from the respective network node to the UE 404. The communication link 408 may use MIMO antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be over one or more carriers.

[0085] The EPC 410 may include a mobility management entity (e.g., MME 412), other MMEs 414, a serving gateway 416, a multimedia broadcast multicast service (MBMS) gateway (e.g., MBMS GW 418), a broadcast multicast service center (e.g., BM-SC 420), and a packet data network (PDN) gateway (e.g., PDN gateway 422). The MME 412 may be in communication with a home subscriber server (e.g., HSS 424). The MME 412 is a control node that handles signaling between the UE 404 and the EPC 410. In general, the MME 412 provides bearer and connection management. All user Internet Protocol (IP) packets are forwarded through the serving gateway 416, which is itself connected to the PDN gateway 422. The PDN gateway 422 provides UE IP address allocation as well as other functions. The PDN gateway 422 and the BM-SC 420 are connected to the IP services 426. The IP services 426 may include Internet, Intranet, IP Multimedia Subsystem (IMS), PS streaming services, and / or other IP services. The BM-SC 420 may provide functionality for MBMS user service provisioning and delivery. The BM-SC 420 may act as an entry point for content provider MBMS transmissions, may be used to authorize and start MBMS bearer services in a Public Land Mobile Network (PLMN), and may be used to schedule MBMS transmissions. The MBMS GW 418 may be used to deliver MBMS traffic to network nodes 402a / 402b that belong to a Multicast Broadcast Single Frequency Network (MBSFN) area that broadcasts a particular service, and may be responsible for session management (start / stop) and collecting eMBMS-related charging information.

[0086] The core network 430 may include an access and mobility management function (e.g., AMF 432), other AMFs 434, a session management function (e.g., SMF 436), and a user plane function (e.g., UPF 438). The AMF 432 may be in communication with an integrated data management (e.g., UDM 440). The AMF 432 is a control node that handles signaling between the UE 404 and the core network 430. In general, the AMF 432 provides QoS flow and session management. All user IP packets are forwarded through the UPF 438. The UPF 438 provides IP address allocation for the UE as well as other functions. The UPF 438 is connected to the IP services 442. The IP services 442 may include the Internet, intranet, IP multimedia subsystem (IMS), packet switched (PS) streaming (PSS) services, and / or other IP services.

[0087] In the example of FIG. 4, the MME 412 and / or AMF 432 may be configured to manage one or more aspects of wireless communications by facilitating security handling of EPC reselection from 5GS in case of RLF and retransmission of EPS TAU requests to facilitate improved mobility support. For example, the MME 412 and / or AMF 432 may be configured to facilitate handover from a 5G network associated with the second network node 402b to an EPS network associated with the first network node 402a. The MME 412 and / or AMF 432 may include a network security handling component 497. Aspects of the network security handling component 497 may be similar to the network security handling component 199 of FIG. 1 and / or FIG. 3.

[0088] The Non-Access Stratum (NAS) forms the highest layer of the control plane between the UE and the MME in the radio interface. Protocols that are part of the NAS provide support for UE mobility. NAS security is an additional feature of the NAS that provides services to the NAS protocols. For example, NAS security may provide integrity protection and encryption of NAS signaling messages.

[0089] The security parameters for authentication, integrity protection, and encryption may be referred to as a security context and may be identified by a key set identifier (KSI). Information representing the security context may be stored in the UE and in a network serving the UE (e.g., a serving network). With respect to communicating NAS signaling messages, the security context may be referred to as a "NAS security context" and may include a key, a key set identifier associated with the key, a UE security capability (e.g., a set of identifiers corresponding to encryption and integrity algorithms implemented by the UE), an uplink NAS count, and a downlink NAS count. When a security context is activated, the uplink NAS count and the downlink NAS count may each be set to 0 and may be sequentially incremented as the respective NAS messages are communicated. Thus, the uplink NAS count value may indicate the amount of communicated uplink NAS messages, and the downlink NAS count value may indicate the amount of communicated downlink NAS messages associated with the active security context.

[0090] When the UE is connected to the 5G network, the 5G security context is generated by the 5G NAS master security key (K ), which is identified by a 5G key set identifier (ngKSI). AMF) The 5G NAS master security key may also be referred to herein as the “5G NAS key” or “5G master security key.” When the UE is attached to the EPS network, the EPS security context may include the EPS NAS master security key (K ) identified by a key set identifier for EPS (eKSI). ASME ). The EPS NAS master security key may also be referred to herein as the "EPS NAS key" or the "EPS master security key."

[0091] FIG. 5 illustrates an example of different security contexts as presented herein. For example, FIG. 5 includes a first security context 500, a second security context 520 associated with a 5G network, and a third security context 540 associated with an EPS network. The security contexts include data that may be used to integrity protect NAS signaling, for example, when transmitting and / or receiving NAS messages. The security context data may be associated with integrity protecting NAS signaling associated with a respective RAN. For example, the second security context 520 may include 5G security context data used to transmit and / or validate 5G NAS messages. The third security context 540 may include EPS security context data used to transmit and / or validate EPS NAS messages.

[0092] In the example of FIG. 5, the first security context 500 includes a master security key 502 and a KSI 504 associated with the master security key 502. For example, the KSI 504 may indicate the master security key 502. The first security context 500 also includes a UE security capabilities 506, which may include a set of identifiers corresponding to encryption and integrity algorithms implemented by the UE. For example, the UE security capabilities 506 may include an integrity key and an encryption key, and associated identifiers of selected integrity and encryption algorithms. The first security context 500 also includes a NAS count pair, including an uplink NAS count 508 and a downlink NAS count 510. The uplink NAS count 508 indicates an amount of uplink NAS messages communicated, and the downlink NAS count 510 indicates an amount of downlink NAS messages communicated associated with the active security context. When the security context is activated, the uplink NAS count 508 and the downlink NAS count 510 may be set to a starting value (e.g., may be set to 0). After the NAS count value is set to a starting value, the NAS count value may be incremented as each NAS message is communicated.

[0093] As described above, the second security context 520 includes 5G security context data to facilitate integrity protecting 5G NAS messages. For example, the second security context 520 includes a 5G key 522 (K AMF ), 5G KSI 524 (ngKSI), 5G UE security capabilities 526, 5G uplink NAS count 528, and 5G downlink NAS count 530. The 5G security context data of the second security context 520 may be similar to the security context data of the first security context 500, but may be configured for a 5G network.

[0094] The third security context 540 includes EPS security context data to facilitate integrity protecting EPS NAS messages. For example, the third security context 540 includes an EPS key 542 (K ASME ), EPS KSI 544 (eKSI), EPS UE security capabilities 546, EPS uplink NAS count 548, and EPS downlink NAS count 550. The EPS security context data of the third security context 540 may be similar to the security context data of the first security context 500, but may be configured for the EPS network.

[0095] A security context may be associated with a state, such as a "current" state or a "non-current" state. A current security context is a security context that is activated. A non-current security context is a security context that is not current (e.g., a security context that is not activated). A security context may be associated with a type, such as a "native" type or a "mapped" type. A native security context includes a "fully native" security context or a "partially native" security context. A security context may be of one type and one state at a time. However, the type of a particular security context may change over time. For example, a partially native security context may convert to a fully native security context.

[0096] The native security context is created by the primary authentication procedure and contains keys (e.g., EPS key K ASME or 5G key K AMF) is a security context that has a unique authentication mechanism that is associated with the UE. For example, a primary authentication procedure may enable mutual authentication between the UE and the network and provide keying material that may be used between the UE and the network in subsequent security procedures. When the UE registers with the network, the UE and the network may perform a primary authentication procedure, and if the primary authentication procedure is successful, a native security context may be generated. The UE may store a copy of the native security context, and the network may store a copy of the native security context associated with the UE in a network entity such as the MME and / or the AMF.

[0097] The native security context may include a native KSI that identifies a native key. The native KSI may be derived during a primary authentication procedure and may enable the UE and the network to identify the native security context without invoking an authentication procedure. Thus, the native KSI may enable reuse of the native security context during subsequent connection setup between the UE and the network without the need to perform an authentication procedure.

[0098] The native security context may be a partial native security context or a full native security context. A partial native security context is a security context that includes a key (e.g., 5G key 522 or EPS key 542) with an associated key set identifier (e.g., 5G KSI 524 or EPS KSI 544), UE security capabilities, and a NAS count pair (e.g., uplink NAS count value and downlink NAS count value). A partial native security context may be created by primary authentication and is in a "non-current" state. A full native security context is a security context that includes the security context data of a partial native security context and also includes the NAS integrity key and encryption key, as well as the associated key set identifiers of the selected NAS integrity and encryption algorithms. A full native security context may be in a "current" state or a "non-current" state.

[0099] A mapped security context is a security context for which a key is derived from a key associated with a different RAN. For example, a mapped 5G security context may be a security context for which a key is derived from a mapped 5G key (K AMF The mapped EPS security context includes a mapped EPS key (K) that is derived from a 5G key (e.g., 5G key 522). ASME ).

[0100] The mapped security context may include a mapped KSI of the first network associated with a mapped key derived from a native key of the second network. For example, the mapped 5G security context includes a mapped 5G KSI associated with a mapped 5G key derived from an EPS key of the EPS network. The mapped KSI may be generated in the UE and the network when deriving the mapped key. Thus, the mapped KSI may indicate the use of the mapped key.

[0101] In some aspects, a security context mismatch may occur between the UE and the first network, for example, during reselection from the second network to the first network (e.g., 5GS to EPS reselection). The number of 5GS to EPS reselection procedures performed in a deployment may be large, for example, due to non-ubiquitous coverage of 5G in the deployment scenario. Furthermore, the 5G network may not initially support IP Multimedia Subsystem (IMS) voice calls. In such a scenario, a UE camped on a cell associated with a 5G network may be redirected to a cell associated with an EPS network, for example, to attempt to establish a voice call.

[0102] FIG. 6 illustrates an example communication flow 600 between a network node 602, a UE 604, an MME 606, and an AMF 608 as presented herein. In the illustrated example, the communication flow 600 facilitates performing idle mode mobility from 5GS to EPS. For example, the UE 604 may be connected and / or camped on a first cell associated with a first RAT (e.g., a 5G network) and may be redirected to a second cell associated with a second RAT (e.g., an EPS network or an LTE network). In the example of FIG. 6, the MME 606 may be associated with an EPS network 607 and the AMF 608 may be associated with a 5G network 609. The example communication flow 600 may be associated with performing a tracking area update (TAU) request procedure after being redirected to the second cell (e.g., the EPS network 607) or an initial attach procedure with the second cell.

[0103] Aspects of the network node 602 may be implemented by the base station 102 of FIG. 1 and / or components of the base station 102, such as a CU, a DU, and / or a RU. Aspects of the UE 604 may be implemented by the UE 104 of FIG. 1. Aspects of the MME 606 may be implemented by the MME 412 of FIG. 4. Aspects of the AMF 608 may be implemented by the AMF 161 of FIG. 1, the AMF 432 of FIG. 4, and / or other AMFs 434. In the example of FIG. 6, the UE 604 communicates with the MME 606 via the network node 602. For example, the UE 604 may send an uplink message that is received by the network node 602, which then forwards the uplink message to the MME 606. In the downlink direction, the MME 606 may send a message that is received by the network node 602 and then forwarded by the network node 602 to the UE 604.

[0104] In the example of Figure 6, the UE 604 is undergoing reselection from the 5G network 609 to the EPS network 607. Thus, the UE 604 is configured with a 5G security context 690, such as the second security context 520 of Figure 5, which is a current (or active) 5G security context. The UE 604 may derive a mapped EPS security context based on the 5G security context data of the current 5G security context to facilitate communication with the MME 606 and the EPS network 607.

[0105] 6, the UE 604 sends a first TAU ​​request message 610 that is received by the MME 606. The UE 604 may send the first TAU ​​request message 610 to update a registration of the UE 604's actual tracking area in the EPS network 607. The UE 604 may send the first TAU ​​request message 610 via an EPS NAS message. Thus, the first TAU ​​request message 610 may include parameters associated with the EPS network 607.

[0106] For example, the first TAU ​​request message 610 includes a mapped EPS Globally Unique Temporary UE Identity (e.g., a mapped EPS GUTI 612) and an EPS security capability of the UE 604, such as the EPS UE security capability 546 of FIG. 5. The mapped EPS GUTI 612 may be derived from a 5G GUTI. The UE 604 may be configured with a 5G GUTI when registering with the 5G network 609. The 5G GUTI may point to an AMF where a 5G key associated with the UE 604 is stored. Thus, the mapped EPS GUTI 612 may include information of an AMF having the latest security context of the UE 604 in the 5G network 609 and an identifier of the UE within the AMF. For example, the mapped EPS GUTI 612 may include an address associated with the AMF 608 and a Temporary Mobile Subscription Identifier (e.g., TMSI 613) associated with the UE 604.

[0107] The UE 604 may integrity protect the first TAU ​​request message 610 using the 5G security context 690 identified by the 5G GUTI used to derive the mapped EPS GUTI 612. For example, the UE 604 may calculate a NAS message authentication code (e.g., NAS-MAC 614) for the first TAU ​​request message 610. The UE 604 may calculate a NAS-MAC 614 similar to the calculation of the NAS-MAC for the 5G NAS message. The uplink NAS count for integrity protection of the first TAU ​​request message 610 may be the same value as the 5G uplink NAS count (e.g., the same value as the 5G uplink NAS count 528 of FIG. 5). As a result, the uplink NAS count value across the communication system is increased. The first TAU ​​request message 610 may include an eKSI parameter 616, and the UE 604 may include a 5G KSI (ngKSI) corresponding to the 5G security context 690 in the eKSI parameter 616.

[0108] In the example of FIG. 6, after sending the first TAU ​​request message 610, the UE 604 may increment 618 the 5G uplink NAS count of the 5G security context 690 by one.

[0109] At 620, the MME 606 may obtain an AMF address of the AMF that stores the 5G security context associated with the UE 604. For example, the MME 606 may obtain the AMF address of the AMF 608 using the mapped EPS GUTI 612 of the first TAU ​​request message 610.

[0110] 6, the MME 606 may send a context request message 622 that is received by the AMF 608. The context request message 622 may include all of the information of the first TAU ​​request message 610, or a portion of the information. For example, the context request message 622 may include the NAS-MAC 614 and the eKSI parameters 616. The context request message 622 may also include a mapped EPS GUTI 612.

[0111] At 630, the AMF 608 may identify a 5G NAS security context 692 associated with the UE 604, for example, based on the context request message 622. The AMF 608 may identify the 5G NAS security context 692 associated with the UE 604 using the 5G KSI included in the eKSI parameter 616 of the context request message 622.

[0112] At 632, the AMF 608 may validate the first TAU ​​request message 610 using the 5G NAS security context 692. The AMF 608 may validate the first TAU ​​request message 610 as if the first TAU ​​request message 610 was a 5G NAS message. If the AMF 608 succeeds in validating the first TAU ​​request message 610, the AMF 608 may generate a mapped EPS security context 636 at 634. For example, the AMF 608 may derive the mapped EPS security context 636 using the 5G NAS security context 692. The AMF 608 may derive a 5G key (K AMF ) to the mapped EPS key (K ASMEFor example, the UE 604 may integrity protect the first TAU ​​request message 610 using the 5G uplink NAS count. Once the AMF 608 identifies the 5G NAS security context 692 of the UE 604 and validates the first TAU ​​request message 610, the AMF 608 may have the capability to determine the 5G uplink NAS count.

[0113] The AMF 608 derives the mapped EPS key (K ASME The AMF 608 may determine a mapped EPS KSI (eKSI) for the 5G NAS security context 636. The EPS uplink and downlink NAS count values ​​in the mapped EPS security context 636 may be set to the uplink and downlink NAS count values ​​of the 5G NAS security context 692, respectively. The AMF 608 may set the EPS NAS algorithm to one that was previously indicated to the UE 604 (e.g., during a connection establishment or re-establishment procedure).

[0114] 6, the AMF 608 may output a context response message 638 that is received by the MME 606. The context response message 638 may include the mapped EPS security context 636. In some examples, the AMF 608 may destroy (or erase) the 5G NAS security context 692 used to derive the mapped EPS security context 636 after sending the context response message 638. In some examples, the AMF 608 may start a timer after sending the context response message 638 and destroy the 5G NAS security context 692 after the timer expires.

[0115] In the depicted example of FIG. 6, the UE 604 may generate 640 a UE mapped EPS security context 642. For example, the UE 604 may derive the UE mapped EPS security context 642 in a manner similar to the derivation of the mapped EPS security context 636 by the AMF 608. The UE 604 may set the EPS NAS algorithms to those previously received from the AMF 608 (e.g., during a connection establishment or re-establishment procedure). The UE 604 may activate the UE mapped EPS security context 642 for use for processing EPS NAS messages received from the MME 606.

[0116] At 650, the MME 606 may compare the UE security algorithm to the security algorithm information 694. The MME 606 may be configured with the security algorithm information 694 via network management. The security algorithm information 694 may include a list of algorithms enabled for use. The algorithms in the security algorithm information 694 may be ordered according to priority. The MME 606 may compare the EPS NAS algorithms included in the mapped EPS security context 636 of the context response message 638 to the security algorithm information 694. The MME 606 may compare the security algorithms to determine whether to select another EPS NAS algorithm at 650. If the MME 606 decides to perform an algorithm change, the MME 606 may select the EPS NAS algorithm from the security algorithm information 694 that has the highest priority and is also available to the UE 604. For example, the MME 606 may use the UE security capabilities of the UE, such as EPS UE security capabilities 546 in FIG. 5, to determine which EPS NAS algorithm to select from the security algorithm information 694.

[0117] If the MME 606 determines to select another EPS NAS algorithm, the UE 604 and the MME 606 may perform a NAS security mode command (SMC) procedure (e.g., a NAS SMC procedure 660) to derive new NAS keys with the selected EPS NAS algorithm. If the MME 606 determines not to perform the algorithm change at 650 or after the MME 606 and the UE 604 perform the NAS SMC procedure 660, the MME 606 may output a TAU accepted message 662 that is received by the UE 604. The MME 606 may output (e.g., transmit or communicate) the TAU accepted message 662 via an EPS NAS message.

[0118] At 664, the UE 604 may perform integrity verification of the TAU accept message 662. For example, the UE 604 may verify the integrity of the TAU accept message 662 by verifying the mapped EPS key (K ASME UE 604 may perform integrity verification of the TAU accept message 662 using the UE_ID 604_ID ') if the integrity verification is successful, the UE 604 may send a TAU complete message 666 that is received by the MME 606. If the integrity verification fails, the UE 604 may discard the TAU complete message 666.

[0119] As described above, the UE 604 may initiate the procedure of Figure 6 upon reselection from a first cell associated with the 5G network 609 to a second cell associated with the EPS network 607. However, there may be cases where the security context at the UE 604 and the MME 606 do not match.

[0120] For example, after establishing a connection with a second cell associated with the EPS network 607 and transmitting the first TAU ​​request message 610, the UE 604 may experience a radio link failure (RLF). In such an example, the UE 604 may retransmit the first TAU ​​request message 610, for example, after establishing a new RRC connection with another cell associated with the EPS network 607 or after re-establishing an RRC connection with the second cell. For example, the UE 604 may transmit a second TAU request message 670 that is received by the MME 606. The second TAU request message 670 may include the same information as the first TAU ​​request (e.g., the first TAU ​​request message 610).

[0121] However, when sending the second TAU request message 670, the UE 604 may use an updated 5G NAS uplink count value to integrity protect the second TAU request message 670. For example, the 5G NAS uplink count value used to integrity protect the first TAU ​​request message 610 may be 5, and the 5G NAS uplink count value used to integrity protect the second TAU request message 670 may be 6.

[0122] In some examples, when the MME 606 receives the second TAU request message 670, the MME 606 may be configured to compare 672 content of the first TAU ​​request message 610 and the second TAU request message 670. In some examples, when the content (e.g., information elements) of the first TAU ​​request message 610 and the second TAU request message 670 are the same, the MME 606 may discard the second TAU request message 670 and continue performing the TAU request procedure of Figure 6 based on the first TAU ​​request message 610. In such examples, the MME 606 may refrain from sending another context request message to the AMF 608 based on the second TAU request message 670.

[0123] It will be appreciated that refraining from sending another context request message may be sufficient in an inter-MME scenario since there is no security context mapping that may occur. Furthermore, refraining from sending another context request message may be sufficient when performing UMTS to EPS reselection since freshness according to NONCE_UE may be used for context mapping. As used herein, "NONCE_UE" refers to a 32-bit pseudo-random number generated by the UE to facilitate freshness of UMTS to EPS security mapping. NONCE_UE may be used to determine the freshness of the mapped EPS key (K ASME This may be used as input, along with an existing security key, such as a 3G security key, to compute

[0124] However, as described in the example of FIG. 6, when performing a 5G-to-EPS reselection (e.g., when performing a reselection from the 5G network 609 to the EPS network 607), the AMF 608 may generate (e.g., at 634) a mapped EPS security context 636 using the 5G NAS uplink count associated with the TAU request message. For example, the AMF 608 may use a value of 5 of the 5G NAS uplink count associated with the first TAU ​​request message 610 to generate a mapped EPS security context 636 that the AMF 608 provides to the MME 606 through a context response message 638. The mapped EPS security context 636 may include an MME EPS key (K ASME '_MME). Thus, the MME 606 may generate an MME EPS key (K ASME '_MME).

[0125] Similarly, the UE 604 may generate (e.g., at 640) a UE mapped EPS security context 642 using the same 5G NAS uplink count associated with the TAU request message. For example, for the first TAU ​​request message 610, the UE 604 may generate 640 a first UE EPS key (K ASME '_UE).

[0126] However, after sending the second TAU request message 670, the UE 604 may generate 680 a new UE mapped EPS security context 682. The new UE mapped EPS security context 682 may be based at least in part on the 5G NAS uplink count value associated with the second TAU request message 670. For example, the new UE mapped EPS security context 682 may be based on the 5G NAS uplink count value of 6 associated with the second TAU request message 670. In such an example, the new UE mapped EPS security context 682 may be based on the second UE EPS key (K ASME Since the mapped EPS security context 636 and the new UE mapped EPS security context 682 may be derived in the AMF 608 and the UE 604, respectively, using different 5G NAS uplink count values, the MME EPS key (K ASME '_MME) and the second UE EPS key (K ASME It will be appreciated that the EPS key K '_UE2) may also be different. ASME '_MME, K ASMEBecause '_UE2 are different, the UE 604 may drop EPS NAS messages received from the MME 606. That is, because the UE 604 and the MME 606 are using mismatched mapped EPS security contexts and mapped EPS keys, the UE 604 may drop or reject EPS NAS messages (e.g., TAU accepted message 662, and / or messages associated with the NAS SMC procedure 660) from the MME 606 due to the inconsistency in the integrity calculation. Such a scenario may result in service interruption and / or dropped call.

[0127] The examples disclosed herein provide techniques for removing the inconsistency in handling repetitions of the TAU request message described above. In a first aspect, the disclosed techniques may remove the inconsistency by modifying how the MME 606 handles repetitions of the TAU request message. In a second aspect, the disclosed techniques may remove the inconsistency by modifying how the UE 604 performs integrity protection of the TAU request message. In a third aspect, the disclosed techniques may remove the inconsistency by modifying how the UE 604 performs integrity verification of the EPS NAS message.

[0128] As described above, when the MME 606 receives the second TAU request message 670, the MME 606 may discard the second TAU request message 670 and refrain from sending another context request message to the AMF 608 when the contents (e.g., information elements) of the first TAU ​​request message 610 and the second TAU request message 670 are the same. In a first example aspect, the disclosed techniques may remove the inconsistency described above by modifying how the MME handles repetitions of TAU request messages.

[0129] For example, the MME 606 may be configured to determine whether to send a context request message to the AMF 608 when the MME 606 can obtain an AMF address from the TAU request. That is, rather than refraining from sending a second context request message based on the first TAU ​​request message 610 and the second TAU request message 670 including the same content (e.g., the same information element) as described in 672, the MME 606 may determine whether to send a second context request message 674 based on whether the MME 606 can obtain an AMF address. Thus, if the second TAU request message 670 includes a mapped EPS GUTI including an AMF address, such as the mapped EPS GUTI 612, the MME 606 may determine to send a second context request message 674 to the AMF 608 requesting a new mapped EPS security context.

[0130] In such an example, the AMF 608 may generate the mapped EPS security context 636 based on the 5G NAS uplink count (e.g., value 6) associated with the second TAU request message 670 included in the second context request message 674. As a result, the mapped EPS security context 636 and the new UE mapped EPS security context 682 may be derived based on the same 5G NAS uplink count (e.g., value 6), thereby generating the respective mapped EPS keys K ASME '_MME, K ASME In some examples, the UE 604 may update 684 the security context of the UE 604 from the UE mapped EPS security context 642 to the new UE mapped EPS security context 682 based on the derivation of the new UE mapped EPS security context 682 (e.g., in 680).

[0131] In some examples, when the MME 606 receives a mapped EPS security context from the AMF 608, the MME 606 may be configured to update the mapped security context. For example, in some scenarios, the MME 606 may generate an EPS NAS message for transmission to the UE 604 and may receive a new mapped EPS security context while transmission of one or more of the generated EPS NAS messages is pending. In such examples, the MME 606 may be configured to discard the pending EPS NAS message that is integrity protected using the older mapped EPS security context.

[0132] It will be appreciated that as long as the MME 606 can obtain an address for transmitting the second context request message 674, the MME 606 may transmit a context request message requesting a mapped EPS security context. Thus, in some examples, the address included in the mapped EPS GUTI may correspond to an AMF (e.g., the AMF 608). In other examples, the address included in the mapped EPS GUTI of the first TAU ​​request message 610 and the second TAU request message 670 may map to an MME.

[0133] In some examples, the MME 606 may receive a second TAU request message 670 with the same information element before sending the TAU accept message 662 to the UE 604. In some such examples, the MME 606 may forward the second TAU request message 670 to the AMF 608 (e.g., via a second context request message 674), as described above. In other examples, the MME 606 may perform authentication and activate a new native EPS security context to be used to protect subsequent NAS messages to the UE 604. For example, the MME 606 may use the same EPS key (K ) for the MME 606 and the UE 604 to perform integrity validation of EPS NAS messages. ASME) may decide to perform a NAS SMC procedure 660 with the UE 604.

[0134] In some examples, the MME 606 may receive a second TAU request message 670 with the same information element after sending the TAU accept message 662 to the UE 604. In some such examples, the MME 606 may determine to perform authentication and activate a new native EPS security context to be used to protect subsequent NAS messages to the UE 604. For example, the MME 606 may determine that the same EPS key (K ASME ) may decide to perform a NAS SMC procedure 660 with the UE 604.

[0135] In some examples, the MME 606 may receive a second TAU request message 670 with the same information element after sending the TAU accept message 662 and before receiving the TAU complete message 666 from the UE 604. In aspects other than an inter-system change from N1 mode to S1 mode in IDLE mode with the UE 604 operating in single registration mode, the MME 606 may resend the TAU accept message 662. In some such examples, the MME 606 may restart a timer (e.g., a T3450 timer) when the TAU complete message 666 is expected. In aspects of an inter-system change from N1 mode to S1 mode in IDLE mode with the UE 604 operating in single registration mode, the MME 606 may initiate an authentication procedure with the UE 604, followed by performing a security mode control procedure (e.g., a NAS SMC procedure 660) to attempt to bring the new partial native EPS security context into use. If bringing the new partial native EPS security context into use is successful, the MME 606 may set the new partial native EPS security context as the full native EPS security context. The MME 606 may also retransmit the TAU accept message 662 and integrity protect the retransmission of the TAU accept message 662 using the (new) full native EPS security context. In some examples, the MME 606 may also restart the T3450 timer. In such examples, the retransmission counter for the T3450 timer may not be incremented.

[0136] In some examples, the MME 606 may receive the first TAU ​​request message 610 and the second TAU request message 670 and may not have yet sent the TAU accepted message 662 or the TAU reject message. If one or more of the information elements in the first TAU ​​request message 610 and the second TAU request message 670 are different, the TAU procedure initiated based on the first TAU ​​request message 610 may be aborted and a new TAU procedure initiated based on the second TAU request message 670 may proceed (e.g., may proceed).

[0137] In an aspect other than an inter-system change from N1 mode to S1 mode in IDLE mode with the UE 604 operating in a single-registration mode, if the information elements in the first TAU ​​request message 610 and the second TAU request message 670 are the same (e.g., not different), the MME 606 may continue the previously initiated TAU procedure (e.g., based on the first TAU ​​request message 610) and discard the second TAU request message 670. That is, the MME 606 may refrain from sending a second context request message 674 to the AMF 608 to request a new mapped EPS security context based on the second TAU request message 670.

[0138] In an aspect of an inter-system change from N1 mode to S1 mode in IDLE mode with the UE 604 operating in a single registration mode, the MME 606 may forward a new TAU request message to the AMF 608 (e.g., through another context request message) to perform an integrity check and to obtain an updated mapped EPS security context and to continue the previous TAU procedure. For example, the MME 606 may forward a second TAU request message 670 to the AMF 608 (e.g., through a second context request message 674). As an example, the integrity check may be based on an integrity key, an uplink count, a direction of the transmission (e.g., a one-bit indicator indicating the downlink direction of a downlink transmission), and a payload of the downlink transmission. The AMF 608 may verify the second TAU request message 670 (e.g., at 632). The AMF 608 may then generate a new mapped EPS security context based on the second TAU request message 670. For example, the new mapped EPS security context may be based at least in part on the 5G NAS uplink count (e.g., value 6) associated with the second TAU request message 670. As a result, a new MME EPS key (e.g., K ASME The mapped EPS security context 636 provided to the MME 606, including the new UE EPS key (K ASME '_UE2). As a result, the MME 606 may obtain a new MME EPS key (e.g., K ASMEWhen the UE 604 integrity protects a subsequent NAS message (e.g., TAU accept message 662) using the UE'_MME, the UE 604 may successfully perform integrity verification on the subsequently received NAS message (e.g., TAU accept message 662), at 664. In some examples, the UE 604 may update 684 the security context of the UE 604 from the mapped EPS security context 642 to the new UE mapped EPS security context 682 based on the derivation of the new UE mapped EPS security context 682 (e.g., at 680).

[0139] In some examples, rather than forwarding to the AMF 608 the second TAU request message 670 containing the same information elements as the first TAU ​​request message 610, the MME 606 may decide to initiate an authentication procedure followed by a security mode control procedure to bring the new partial native EPS security context into use. If the bringing the new partial native EPS security context into use is successful (e.g., the NAS SMC procedure 660 is successful), the MME 606 may set the new partial native EPS security context to a full native EPS security context, and full native EPS security may be used to protect any future NAS messages sent to the UE 604, such as the TAU accept message 662.

[0140] As described above, when the UE 604 transmits the first TAU ​​request message 610 and the second TAU request message 670, the UE 604 uses the respective 5G NAS uplink count to integrity protect the respective TAU request messages. In a second example aspect, the disclosed techniques may remove the inconsistency by modifying how the UE 604 performs integrity protection of the TAU request messages. For example, the UE 604 may be configured to use the same 5G NAS uplink count value when transmitting two consecutive TAU request messages, such as the first TAU ​​request message 610 and a repeat of the first TAU ​​request message (e.g., the second TAU request message 670). For example, the UE 604 may skip incrementing the 5G uplink NAS count of the 5G security context 690 by one at 618.

[0141] By transmitting the first TAU ​​request message 610 and the second TAU request message 670 without incrementing the 5G NAS uplink count, the first TAU ​​request message 610 and the second TAU request message 670 may be integrity protected using the same 5G NAS uplink COUNT value. As a result, the mapped EPS security context 636 generated by the AMF 608 (e.g., at 634) and the new UE mapped EPS security context 682 generated by the UE 604 (e.g., at 680) may be the same. Thus, the integrity verification performed on the subsequent NAS message received at the UE 604 (e.g., at 664) may be successful, and the continuation of the communication between the UE 604 and the cell associated with the EPS network 607 may be successful. In some examples, the UE 604 may update, at 684, the security context of the UE 604 from the UE mapped EPS security context 642 to the new UE mapped EPS security context 682 based on the derivation of the new UE mapped EPS security context 682 (e.g., at 680).

[0142] That is, because the 5G NAS UPLINK COUNT value is the same for the first TAU ​​request message 610 and the second TAU request message 670, the respective TAU request messages contain the same content (e.g., the same information elements) and are each integrity protected using the same 5G NAS UPLINK COUNT value. In some examples, when the MME 606 receives the first TAU ​​request message 610 and the second TAU request message 670, the MME 606 may discard the second TAU request message 670 and continue the TAU procedure based on the first TAU ​​request message 610. In another example where the MME 606 does not receive the first TAU ​​request message 610 (e.g., if a radio link failure occurs and the network node 602 misses one or more RLC packets containing RRC connection setup completion information), but the MME 606 receives a second TAU request message 670, the MME 606 may use the second TAU request message 670 to perform the TAU procedure of FIG. 6 (e.g., to request a mapped EPS security context from the AMF 608). In either scenario, the mapped EPS key (K ASME '_MME, K ASME '_UE2) are the same, and therefore, continued communication between the UE 604 and the cell associated with the EPS network 607 may be successful.

[0143] In a third example aspect, the disclosed techniques may eliminate inconsistencies in handling repetitions of TAU request messages by modifying how UE 604 performs integrity verification of EPS NAS messages. For example, UE 604 may attempt to perform integrity verification based on different EPS keys (e.g., at 664).

[0144] For example, the UE604 is AMF), and a 5G NAS uplink count (e.g., value 5) associated with the first TAU ​​request message 610, a first EPS key (K ASME UE 604 may then derive a first EPS key (K ASME '1) to derive a first NAS integrity key (NAS_IK1).

[0145] The UE604 also supports 5G key (K AMF ), and the 5G NAS uplink count (e.g., value 6) associated with the second TAU request message 670, a second EPS key (K ASME UE 604 may then derive a second EPS key (K ASME '2) a second NAS integrity key (NAS_IK2).

[0146] When the UE 604 receives an EPS NAS integrity protected message (e.g., TAU accept message 662) from the MME 606, the UE 604 may attempt to perform (e.g., at 664) an integrity verification using the NAS integrity keys (e.g., NAS_IK1 and NAS_IK2). If one of the NAS integrity keys allows the integrity verification to pass, the UE 604 selects a respective NAS integrity key and proceeds to communicate with a cell associated with the EPS network 607 based on the respective NAS integrity key. For example, if the integrity verification is successful using the first NAS integrity key (NAS_IK1), the UE 604 may select the first EPS key (NAS_IK2) to verify the integrity. ASME '1) to the EPS key (K ASME ) The UE 604 may also set a second EPS key (K ASME '2), and the second EPS key (K ASME Similarly, if the integrity verification is successful using the second NAS integrity key (NAS_IK2), the UE 604 may erase any other keys derived from the second EPS key (K ASME '2) to the EPS key (KASME ) as the first EPS key (K ASME '1), and the first EPS key (K ASME UE 604 may erase any other keys derived from NAS_IK1). If performing integrity verification using both NAS integrity keys (NAS_IK1, NAS_IK2) fails (e.g., none of the NAS integrity keys successfully performed integrity verification), UE 604 may drop the EPS NAS message.

[0147] While the above description provides an example including two TAU request messages, it will be appreciated that other examples may include any suitable amount of TAU request messages. For example, there may be z possible NAS uplink COUNT values ​​(e.g., x, x+1, x+2, ... z). Integrity verification may be performed using 5G NAS uplink COUNT y to generate y EPS keys (K ASME UE 604 uses a NAS integrity key (NAS_IK_y) derived from the y EPS key (K′y), where y is one of z possible NAS uplink COUNT values ​​(e.g., x, x+1, x+2, ... z), to complete the completion. ASME 'y) to the EPS key (K ASME ) and all other EPS keys (K ASME ') and their respective derived keys.

[0148] 7 is a flowchart 700 of a method of wireless communication. The method may be performed by a UE (e.g., the UE 104, the UE 350, the UE 404, and / or the apparatus 1104 of FIG. 11). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0149] At 702, the UE transmits a first TAU ​​request to a first network entity, as described with respect to the first TAU ​​request message 610 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, such as the 5G uplink NAS count 528 of FIG. 5. The first TAU ​​request may include a first set of information including an identifier mapped to a second RAT associated with the first network entity, such as the mapped EPS GUTI 612 of FIG. 6. The transmission of the first TAU ​​request at 702 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0150] In some examples, the UE may transmit the first TAU ​​request when performing a change from a first cell associated with the first RAT to connect to a second cell associated with the second RAT. For example, the UE may transmit the first TAU ​​request when performing EPS reselection from 5GS. As described with respect to the MME 606, EPS network 607, and 5G network 609 of FIG. 6, the second RAT may be different from the first RAT, and the first network entity may be associated with the second RAT.

[0151] At 704, the UE transmits a second TAU request to the first network entity, as described with respect to the second TAU request message 670 of FIG. 6. The second TAU request may include a first set of information, as described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameters 616 of FIG. 6. The second TAU request may be integrity protected using the second uplink count. The transmission of the second TAU request at 704 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0152] At 706, the UE derives a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count, as described with respect to the UE mapped EPS security context 642 and / or the new UE mapped EPS security context 682 of Figure 6. The derivation of the mapped security context at 706 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0153] At 708, the UE communicates with the first network entity based on the mapped security context, as described with respect to the TAU complete message 666 of Figure 6. The communication based on the mapped security context at 714 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0154] 8 is a flowchart 800 of a method of wireless communication. The method may be performed by a UE (e.g., the UE 104, the UE 350, the UE 404, and / or the apparatus 1104 of FIG. 11). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0155] At 802, the UE transmits a first TAU ​​request to a first network entity, as described with respect to the first TAU ​​request message 610 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, such as the 5G uplink NAS count 528 of FIG. 5. The first TAU ​​request may include a first set of information including an identifier mapped to a second RAT associated with the first network entity, such as the mapped EPS GUTI 612 of FIG. 6. The transmission of the first TAU ​​request at 802 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0156] In some examples, the UE may transmit the first TAU ​​request when performing a change from a first cell associated with the first RAT to connect to a second cell associated with the second RAT. For example, the UE may transmit the first TAU ​​request when performing EPS reselection from 5GS. As described with respect to the MME 606, EPS network 607, and 5G network 609 of FIG. 6, the second RAT may be different from the first RAT, and the first network entity may be associated with the second RAT.

[0157] At 804, the UE transmits a second TAU request to the first network entity, as described with respect to the second TAU request message 670 of FIG. 6. The second TAU request may include a first set of information, as described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameters 616 of FIG. 6. The second TAU request may be integrity protected using the second uplink count. The transmission of the second TAU request at 804 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0158] At 806, the UE derives a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count, as described with respect to the UE mapped EPS security context 642 and / or the new UE mapped EPS security context 682 of Figure 6. The derivation of the mapped security context at 806 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0159] At 814, the UE communicates with the first network entity based on the mapped security context, as described with respect to the TAU complete message 666 of Figure 6. The communication based on the mapped security context at 814 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0160] In some examples, the second TAU request may include a repetition of the first TAU ​​request at 804, and the second uplink count may be the same value as the first uplink count, as described with respect to the second aspect of FIG. 6, in which the UE 604 removes inconsistencies in the repetition of the TAU request by modifying how the UE 604 performs integrity protection of the TAU request message. In some examples, the UE may transmit the second TAU request based on the occurrence of a radio link failure. In some examples, the mapped security context may be associated with the second RAT. For example, the mapped security context may be associated with the UE mapped EPS security context 642 or the new UE mapped EPS security context 682 of FIG. 6.

[0161] In some examples, as described with respect to the UE mapped EPS security context 642 of FIG. 6, the second TAU request may include a repetition of the first TAU ​​request, the second uplink count may differ from the first uplink count, at 804, and the mapped security context may be the first mapped security context.

[0162] In some such examples, the UE may derive 808 a second mapped security context based on the first security context and the first uplink count, as described with respect to the new UE mapped EPS security context 682 of FIG. 6. The UE may encode the second TAU request using the first security context, and the second TAU request may be integrity protected using the second uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The derivation of the second mapped security context at 808 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0163] At 810, the UE may update the UE's security context from the second mapped security context to the first mapped security context based on the derivation of the first mapped security context, as described with respect to 684 of Figure 6. The updating of the UE's security context at 810 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0164] At 812, the UE may discard the pending transmission that is integrity protected using the second mapped security context after updating the UE's security context. The discarding of the pending transmission at 812 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0165] 9 is a flowchart 900 of a method of wireless communication. The method may be performed by a UE (e.g., the UE 104, the UE 350, the UE 404, and / or the apparatus 1104 of FIG. 11). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0166] At 902, the UE transmits a first TAU ​​request to a first network entity when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT different from the first RAT, as described with respect to the first TAU ​​request message 610 of FIG. 6. The first network entity may be associated with the second RAT, as described with respect to the MME 606 and the EPS network 607 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context. The transmission of the first TAU ​​request at 902 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0167] At 904, the UE derives a first integrity key based on the first security context, the first uplink count, and the first mapped security context, as described with respect to the first NAS integrity key (NAS_IK1). For example, the UE derives a 5G key (K AMF), and a 5G NAS uplink count (e.g., value 5) associated with the first TAU ​​request message 610, a first EPS key (K ASME The UE may then derive a first EPS key (K ASME The UE may derive a first NAS integrity key (NAS_IK1) from NAS_IK1′1). The derivation of the first integrity key in 904 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0168] At 906, the UE sends a repetition of the first TAU ​​request to the first network entity as described with respect to the second TAU request message 670 of FIG. 6. The repetition of the first TAU ​​request may be integrity protected using a second uplink count that is different from the first uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The sending of the repetition of the first TAU ​​request at 906 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0169] At 908, the UE receives a second EPS key (K ASME The UE derives the second integrity key based on the first security context, the second uplink count, and the second mapped security context, as described above with respect to the second NAS integrity key (NAS_IK2) from 5G key (K AMF ), and a second EPS key (K ASME The UE may then derive a second EPS key (K ASMEThe UE may derive a second NAS integrity key (NAS_IK2) from NAS_IK1′2). The derivation of the second integrity key at 908 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0170] At 910, the UE receives a downlink transmission from the first network entity, as described with respect to the TAU accept message 662 of Figure 6. The reception of the downlink transmission at 910 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0171] At 912, the UE performs an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key, as described with respect to 664 of Figure 6. The performance of the integrity check at 912 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0172] At 914, the UE uses the derived integrity key to set a master security key for the UE when the integrity check on the downlink transmission is successful. The master security key may be set based on the respective integrity key used to successfully perform the integrity check. The setting of the master security key at 914 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0173] 10 is a flowchart 1000 of a method of wireless communication. The method may be performed by a UE (e.g., the UE 104, the UE 350, the UE 404, and / or the apparatus 1104 of FIG. 11). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0174] In 1002, the UE transmits a first TAU ​​request to a first network entity when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT different from the first RAT, as described with respect to the first TAU ​​request message 610 of FIG. 6. The first network entity may be associated with the second RAT, as described with respect to the MME 606 and the EPS network 607 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context. The transmission of the first TAU ​​request in 1002 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0175] In some examples, the UE may derive 1004 a first mapped security context based on the first security context and the first uplink count, as described with respect to the UE mapped EPS security context 642 of Figure 6. The derivation of the first mapped security context at 1004 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0176] At 1006, the UE derives a first integrity key based on the first security context, the first uplink count, and the first mapped security context, as described with respect to the first NAS integrity key (NAS_IK1). For example, the UE derives a 5G key (K AMF ), and a 5G NAS uplink count (e.g., value 5) associated with the first TAU ​​request message 610, a first EPS key (K ASME The UE may then derive a first EPS key (K ASMEThe UE may derive a first NAS integrity key (NAS_IK1) from NAS_IK1′1. The derivation of the first integrity key in 1006 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0177] At 1008, the UE sends a repetition of the first TAU ​​request to the first network entity as described with respect to the second TAU request message 670 of FIG. 6. The repetition of the first TAU ​​request may be integrity protected using a second uplink count that is different from the first uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The sending of the repetition of the first TAU ​​request at 1008 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0178] At 1010, the UE receives a second EPS key (K ASME The UE derives the second integrity key based on the first security context, the second uplink count, and the second mapped security context, as described above with respect to the second NAS integrity key (NAS_IK2) from 5G key (K AMF ), and a second EPS key (K ASME The UE may then derive a second EPS key (K ASME The second NAS integrity key (NAS_IK2) may be derived from NAS_IK1′2. The derivation of the second integrity key in 1010 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0179] At 1012, the UE receives the downlink transmission from the first network entity, as described with respect to the TAU accept message 662 of Figure 6. Receiving the downlink transmission at 1012 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0180] At 1014, the UE performs an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key, as described with respect to 664 of Figure 6. The performance of the integrity check at 1014 may be performed by the UE security handling component 198 of the apparatus 1104 of Figure 11.

[0181] At 1016, the UE uses the derived integrity key to set a master security key for the UE when the integrity check on the downlink transmission is successful. The master security key may be set based on the respective integrity key used to successfully perform the integrity check. The setting of the master security key at 1016 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0182] In some examples, the UE may then discard information related to other derived integrity keys after setting the master security key. For example, the UE may set the master security key to the first mapped security context at 1016. In such examples, the UE may erase the second mapped security context and any keys derived using the second mapped security context at 1018 when the integrity check on the downlink transmission is successful using the first integrity key. The erasure of the second mapped security context at 1018 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG. 11.

[0183] In other examples, the UE may set the master security key to the second mapped security context at 1016. In such examples, the UE may clear the first mapped security context and any keys derived using the first mapped security context when an integrity check on the downlink transmission succeeds using the second integrity key at 1020. Clearing the first mapped security context at 1020 may be performed by the UE security handling component 198 of the apparatus 1104 of FIG.

[0184] FIG. 11 is a diagram 1100 illustrating an example of a hardware implementation for the device 1104. The device 1104 may be a UE, may be a component of a UE, or may implement UE functionality. In some aspects, the device 1104 may include a cellular baseband processor 1124 (also referred to as a modem) coupled to one or more transceivers (e.g., a cellular RF transceiver 1122). The cellular baseband processor 1124 may include on-chip memory 1124'. In some aspects, the device 1104 may further include one or more subscriber identity module (SIM) cards 1120 and an application processor 1106 coupled to the secure digital (SD) card 1108 and the screen 1110. The application processor 1106 may include on-chip memory 1106'. In some aspects, the device 1104 may further include a Bluetooth module 1112, a WLAN module 1114, an SPS module 1116 (e.g., a GNSS module), one or more sensor modules 1118 (e.g., a barometric sensor / altimeter, an inertial management unit (IMU), a motion sensor such as a gyroscope, and / or an accelerometer, light detection and ranging (LIDAR), radio assisted detection and ranging (RADAR), sound navigation and ranging (SONAR), magnetometer, audio and / or other technologies used for positioning), an additional memory module 1126, a power source 1130, and / or a camera 1132. The Bluetooth module 1112, the WLAN module 1114, and the SPS module 1116 may include an on-chip transceiver (TRX) (or in some cases simply a receiver (RX)). The Bluetooth module 1112, the WLAN module 1114, and the SPS module 1116 may include their own dedicated antennas and / or may utilize one or more antennas 1180 for communications.The cellular baseband processor 1124 communicates with the UE 104 and / or with RUs associated with the network entity 1102 through a transceiver (e.g., a cellular RF transceiver 1122) via one or more antennas 1180. The cellular baseband processor 1124 and the application processor 1106 may each include a computer-readable medium / memory, such as an on-chip memory 1124' and an on-chip memory 1106', respectively. The additional memory module 1126 may also be considered a computer-readable medium / memory. Each computer-readable medium / memory (e.g., the on-chip memory 1124', the on-chip memory 1106', and / or the additional memory module 1126) may be non-transitory. The cellular baseband processor 1124 and the application processor 1106 are each responsible for general processing, including the execution of software stored on the computer-readable medium / memory. The software, when executed by the cellular baseband processor 1124 / application processor 1106, causes the cellular baseband processor 1124 / application processor 1106 to perform the various functions described above. The computer-readable medium / memory may also be used to store data that is manipulated by the cellular baseband processor 1124 / application processor 1106 when executing the software. The cellular baseband processor 1124 / application processor 1106 may be a component of the UE 350 and may include the memory 360 and / or at least one of the TX processor 368, the RX processor 356, and the controller / processor 359. In one configuration, the device 1104 may be a processor chip (modem and / or application) and may include only the cellular baseband processor 1124 and / or the application processor 1106, and in another configuration, the device 1104 may be an entire UE (e.g., see UE 350 in FIG. 3) and may include additional modules of the device 1104.

[0185] As described above, the UE security handling component 198 is configured to: send a first tracking area update (TAU) request to a first network entity, where the first TAU ​​request is encoded using a first security context associated with a first radio access technology (RAT), where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, and where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; send a second TAU request to the first network entity, where the second TAU request includes the first set of information, and where the second TAU request is integrity protected using the second uplink count; derive a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count; and communicate with the first network entity based on the mapped security context.

[0186] In another aspect, the UE security handling component 198 is configured to: send a first tracking area update (TAU) request to a first network entity when the UE performs a change from a first cell associated with a first radio access technology (RAT) to connect to a second cell associated with a second RAT different from the first RAT, the first network entity being associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, the first TAU ​​request being integrity protected using a first uplink count based on the first security context; derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context; and send a repetition of the first TAU ​​request to the first network entity. the first iteration of the TAU request is integrity protected using a second uplink count different from the first uplink count; deriving a second integrity key based on the first security context, the second uplink count, and the second mapped security context; receiving a downlink transmission from the first network entity; performing an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key; and setting a master security key for the UE when the integrity check on the downlink transmission is successful using the derived integrity key, where the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.

[0187] The UE security handling component 198 may be within the cellular baseband processor 1124, the application processor 1106, or both the cellular baseband processor 1124 and the application processor 1106. The UE security handling component may be one or more hardware components specifically configured to execute the described processes / algorithms, implemented by one or more processors configured to execute the described processes / algorithms, stored in a computer-readable medium for implementation by one or more processors, or some combination thereof.

[0188] As shown, the apparatus 1104 may include various components configured for various functions. For example, a UE security handling component may include one or more hardware components that perform each of the algorithmic blocks in the flowcharts of FIG. 7, FIG. 8, FIG. 9, and / or FIG. 10.

[0189] In one configuration, the apparatus 1104, and in particular the cellular baseband processor 1124 and / or the application processor 1106, comprises means for transmitting a first tracking area update (TAU) request to a first network entity, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, and the first TAU ​​request being mapped to a second RAT associated with the first network entity. the second TAU request includes a first set of information including a mapped identifier; means for sending a second TAU request to the first network entity, the second TAU request including the first set of information, the second TAU request being integrity protected using the second uplink count; means for deriving a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count; and means for communicating with the first network entity based on the mapped security context.

[0190] In another configuration, the example apparatus 1104 also includes means for transmitting a first TAU ​​request when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT, where the second RAT is different from the first RAT and the first network entity is associated with the second RAT.

[0191] In another configuration, the second TAU request includes a repeat of the first TAU ​​request, and the second uplink count is the same value as the first uplink count.

[0192] In another configuration, the example apparatus 1104 also includes means for transmitting a second TAU request based on the occurrence of a radio link failure.

[0193] In another configuration, the mapped security context is associated with a second RAT.

[0194] In another configuration, the second uplink count is different from the first uplink count and the mapped security context is the first mapped security context, and the example apparatus 1104 also includes means for deriving a second mapped security context based on the first security context and the first uplink count, where the second TAU request is encoded using the first security context and integrity protected using the second uplink count, and the first mapped security context is derived based on the first security context and the second uplink count.

[0195] In another configuration, the example apparatus 1104 also includes means for updating a security context of the UE from the second mapped security context to the first mapped security context based on the derivation of the first mapped security context, and means for discarding a pending transmission that is integrity protected using the second mapped security context after updating the security context of the UE.

[0196] In another configuration, the second TAU request includes a repetition of the first TAU ​​request.

[0197] In one configuration, the apparatus 1104, and in particular the cellular baseband processor 1124 and / or the application processor 1106, includes means for transmitting a first tracking area update (TAU) request to a first network entity when performing a change from a first cell associated with a first radio access technology (RAT) to connect to a second cell associated with a second RAT different from the first RAT, where the first network entity is associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, and the first TAU ​​request being integrity protected using a first uplink count based on the first security context; means for deriving a first integrity key based on the first security context, the first uplink count, and the first mapped security context; and means for transmitting a first integrity key to the first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT, where the first network entity is associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, and the first TAU ​​request being integrity protected using a first uplink count based on the first security context. the first uplink count is different from the first uplink count; means for deriving a second integrity key based on the first security context, the second uplink count, and the second mapped security context; means for receiving a downlink transmission from the first network entity; means for performing an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key; and means for setting a master security key for the UE when the integrity check on the downlink transmission is successful using the derived integrity key, the master security key being set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.

[0198] In another configuration, the example apparatus 1104 also includes means for erasing the second mapped security context and any keys derived using the second mapped security context when an integrity check on the downlink transmission is successful using the first integrity key, where the master security key includes the first mapped security context.

[0199] In another configuration, the example apparatus 1104 also includes means for erasing the first mapped security context and any keys derived using the first mapped security context when an integrity check on the downlink transmission is successful using the second integrity key, where the master security key includes the second mapped security context.

[0200] In another configuration, the example apparatus 1104 also includes means for deriving a first mapped security context based on the first security context and the first uplink count.

[0201] The means may be the UE security handling component 198 of the apparatus 1104 configured to perform the functions recited by the means. As described above, the apparatus 1104 may include the TX processor 368, the RX processor 356, and the controller / processor 359. Thus, in one configuration, the means may be the TX processor 368, the RX processor 356, and / or the controller / processor 359 configured to perform the functions recited by the means.

[0202] 12 is a flowchart 1200 of a method of wireless communication. The method may be performed by a first network entity (e.g., the base station 102 or a component of the base station 102, the MME 412, the AMF 432, the network entity 1602 of FIG. 16, and / or the network entity 1760 of FIG. 17). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0203] The first network entity may be in communication with the UE and the second network entity. In some examples, the first network entity may include an MME, such as the MME 606 of FIG. 6, and the second network entity may include an AMF, such as the AMF 608 of FIG. 6.

[0204] At 1202, the first network entity obtains a first TAU ​​request generated by the UE, as described with respect to the first TAU ​​request message 610 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU ​​request message 610. The first TAU ​​request may include a first set of information including an identifier mapped to a second RAT associated with the first network entity, as described with respect to the mapped EPS GUTI 612 of FIG. 6. The obtaining of the first TAU ​​request at 1202 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0205] At 1204, the first network entity outputs a first context request for the second network entity based on the first TAU ​​request, as described with respect to the context request message 622 and the AMF 608 of FIG. 6. The second network entity may be associated with a first RAT, such as the AMF 608 associated with the 5G network 609. In some examples, the first context request may include an identifier mapped to the second RAT, such as the mapped EPS GUTI 612 of the first TAU ​​request message 610 of FIG. 6. In some examples, the first TAU ​​request may be integrity protected using the first uplink count. The output of the first context request at 1204 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0206] At 1206, the first network entity obtains a first mapped security context based on the first context request, as described with respect to the mapped EPS security context 636 of Figure 6. The first mapped security context may be derived from the first security context and the first uplink count. The obtaining of the first mapped security context at 1206 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0207] At 1208, the first network entity obtains a second TAU request, as described with respect to the second TAU request message 670 of FIG. 6. The second TAU request may be encoded using the first security context. The second TAU request may be integrity protected using a second uplink count that is different from the first uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The second TAU request may include a first set of information, as described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameters 616 of FIG. 6. In some examples, the second TAU request may include a repetition of the first TAU ​​request. Obtaining the second TAU request at 1208 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG.

[0208] At 1210, the first network entity outputs a second context request for the second network entity based on the second TAU request, as described with respect to the second context request message 674 of Figure 6. The output of the second context request at 1210 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0209] At 1212, the first network entity obtains a second mapped security context based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count. The manner of obtaining the second mapped security context may be similar to obtaining the first mapped security context as described with respect to the mapped EPS security context 636 of Figure 6. The obtaining of the second mapped security context at 1212 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0210] At 1214, the first network entity outputs a downlink message based on the second mapped security context, as described with respect to the TAU accept message 662 of Figure 6. The output of the downlink message at 1214 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0211] 13 is a flowchart 1300 of a method of wireless communication. The method may be performed by a first network entity (e.g., the base station 102 or a component of the base station 102, the MME 412, the AMF 432, the network entity 1602 of FIG. 16, and / or the network entity 1760 of FIG. 17). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0212] The first network entity may be in communication with the UE and the second network entity. In some examples, the first network entity may include an MME, such as the MME 606 of FIG. 6, and the second network entity may include an AMF, such as the AMF 608 of FIG. 6.

[0213] At 1302, the first network entity obtains a first TAU ​​request generated by the UE, as described with respect to the first TAU ​​request message 610 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU ​​request message 610. The first TAU ​​request may include a first set of information including an identifier mapped to a second RAT associated with the first network entity, as described with respect to the mapped EPS GUTI 612 of FIG. 6. The obtaining of the first TAU ​​request at 1302 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0214] In some examples, the first network entity may derive 1304 an address of the second network entity based on the identifier mapped to the second RAT, as described with respect to 620 of Figure 6. The derivation of the address of the second network entity in 1304 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0215] At 1306, the first network entity outputs a first context request for the second network entity based on the first TAU ​​request, as described with respect to the context request message 622 and the AMF 608 of FIG. 6. The second network entity may be associated with a first RAT, such as the AMF 608 associated with the 5G network 609. In some examples, the first context request may include an identifier mapped to the second RAT, such as the mapped EPS GUTI 612 of the first TAU ​​request message 610 of FIG. 6. In some examples, the first TAU ​​request may be integrity protected using the first uplink count. The output of the first context request at 1306 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0216] At 1308, the first network entity obtains a first mapped security context based on the first context request, as described with respect to the mapped EPS security context 636 of Figure 6. The first mapped security context may be derived from the first security context and the first uplink count. The obtaining of the first mapped security context at 1308 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0217] At 1310, the first network entity obtains a second TAU request, as described with respect to the second TAU request message 670 of FIG. 6. The second TAU request may be encoded using the first security context. The second TAU request may be integrity protected using a second uplink count that is different from the first uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The second TAU request may include a first set of information, as described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameters 616 of FIG. 6. In some examples, the second TAU request may include a repetition of the first TAU ​​request. Obtaining the second TAU request at 1310 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG.

[0218] At 1312, the first network entity outputs a second context request for the second network entity based on the second TAU request, as described with respect to the second context request message 674 of Figure 6. The output of the second context request at 1312 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0219] At 1314, the first network entity obtains a second mapped security context based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count. The manner of obtaining the second mapped security context may be similar to obtaining the first mapped security context as described with respect to the mapped EPS security context 636 of Figure 6. The obtaining of the second mapped security context at 1314 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0220] At 1316, the first network entity outputs a downlink message based on the second mapped security context, as described with respect to the TAU accept message 662 of Figure 6. The output of the downlink message at 1316 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0221] In some examples, the first network entity may update the security context of the first network entity from the first mapped security context to the second mapped security context based on obtaining the second mapped security context at 1318. The updating of the security context of the first network entity at 1318 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0222] Further, at 1320, the first network entity may discard pending downlink transmissions that are integrity protected using the first mapped security context after updating the security context of the first network entity. The discarding of pending downlink transmissions at 1320 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0223] In some examples, the first network entity may obtain a second TAU request message with the same information element, at 1310, after outputting the downlink message and before obtaining an uplink message in response to the downlink message, at 1316. For example, the first network entity may obtain the second TAU request message after outputting the TAU accept message 662 and before obtaining the TAU completion message 666.

[0224] In some examples where the first network entity obtains the first TAU ​​request at 1302 based on a non-inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU accept message, and the first network entity may resend the downlink message. In some examples, the first network entity may restart the T3450 timer when a TAU completion message is expected from the UE, such as the TAU completion message 666 of FIG. 6. The first network entity may also skip incrementing a retransmission counter for the T3450 timer.

[0225] In some examples where the first network entity obtains the first TAU ​​request at 1302 based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU accept message, and the first network entity may initiate an authentication procedure with the UE. The first network entity may also perform a security mode control procedure to transition the new partial native EPS security context to the current full native EPS security context. For example, the first network entity may perform a NAS SMC procedure 660 with the UE to transition the partial native EPS security context to the full native EPS security context to facilitate communicating EPS NAS messages with the UE.

[0226] In some examples where the security mode control procedure is successful, the first network entity may output a downlink message repetition, where the downlink message repetition is integrity protected using the current full native EPS security context. The first network entity may also restart the T3450 timer when a TAU completion message is expected from the UE, such as the TAU completion message 666 of FIG. 6. The first network entity may also skip incrementing a retransmission counter for the T3450 timer.

[0227] In some examples where the first network entity obtains the first TAU ​​request at 1302 based on the non-inter-system change from the N1 mode to the S1 mode and the UE is configured to operate in the single registration mode, the first network entity may skip initiating the TAU procedure based on the second TAU request. The first network entity may also integrity protect the downlink message based on the first mapped security context.

[0228] In some examples where the first network entity obtains the first TAU ​​request, at 1302, based on the inter-system change from the N1 mode to the S1 mode and the UE is configured to operate in a single registration mode, the first network entity may determine to initiate a second TAU procedure. For example, the first network entity may output a second context request, at 1312, to the second network entity. The first network entity may also integrity protect the downlink message based on the second mapped security context.

[0229] In some examples, the first network entity may receive a TAU request message and may not have yet sent a TAU accepted message or a TAU reject message. If one or more of the information elements in the TAU request message are different, the TAU procedure initiated based on the first TAU ​​request message may be aborted, and the TAU procedure initiated based on the second TAU request message may proceed (e.g., advance).

[0230] In an aspect other than an inter-system change from N1 mode to S1 mode in IDLE mode with a UE operating in single registration mode, if the information elements in the TAU request message are the same (e.g., not different), the first network entity may continue the previously initiated TAU procedure (e.g., based on the first TAU ​​request message) and discard the second TAU request message. That is, the first network entity may refrain from sending a second context request message to the second network entity to request a new mapped EPS security context based on the second TAU request message.

[0231] In an aspect of an inter-system change from N1 mode to S1 mode in IDLE mode with a UE operating in single registration mode, the first network entity may forward a new TAU request message to the second network entity (e.g., through another context request message) to perform an integrity check, to obtain an updated mapped EPS security context, and to continue the previous TAU procedure. For example, the first network entity may forward a second TAU request message to the second network entity (e.g., through a second context request message). The second network entity may validate the second TAU request message. The second network entity may then generate a new mapped EPS security context based on the second TAU request message. For example, the new mapped EPS security context may be based at least in part on a 5G NAS uplink COUNT value (e.g., 6) associated with the second TAU request message. As a result, a new MME EPS key (e.g., K ASME The mapped EPS security context provided to the first network entity, including the UE'_MME, is updated with the new UE EPS key (K ASME As a result, the first network entity may obtain a new MME EPS key (e.g., K ASME When the UE integrity protects a subsequent NAS message (e.g., a TAU accept message) using the '_MME', the UE may successfully perform integrity verification on the subsequently received NAS message (e.g., a TAU accept message). In some examples, the UE may update the UE's security context from the mapped EPS security context to the new mapped EPS security context based on the derivation of the new mapped EPS security context.

[0232] 14 is a flowchart 1400 of a method of wireless communication. The method may be performed by a second network entity (e.g., the base station 102 or a component of the base station 102, the MME 412, the AMF 432, the network entity 1602 of FIG. 16, and / or the network entity 1760 of FIG. 17). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0233] The second network entity may be in communication with the first network entity. In some examples, the first network entity may include an MME, such as the MME 606 of FIG. 6, and the second network entity may include an AMF, such as the AMF 608 of FIG. 6.

[0234] At 1402, the second network entity obtains a first context request, the first context request including at least a first TAU ​​request generated by the UE as described with respect to the context request message 622 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU ​​request message 610. The first RAT may be different from a second RAT associated with the first network entity. For example, the first RAT may correspond to a 5G network 609, and the second RAT associated with the first network entity may correspond to an EPS network 607 associated with the MME 606 of FIG. 6. The obtaining of the first context request in 1402 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG.

[0235] At 1404, the second network entity derives the first mapped security context when the first integrity check in the first TAU ​​request is successful, as described with respect to 632, 634, and the mapped EPS security context 636 in Figure 6. The derivation of the first mapped security context at 1404 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0236] At 1406, the second network entity outputs the first mapped security context for the first network entity as described with respect to the mapped EPS security context 636 and the context response message 638 of Figure 6. The output of the first mapped security context at 1406 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0237] At 1408, the second network entity obtains a second context request, where the second context request includes at least a second TAU request generated by the UE as described with respect to the second context request message 674 including the TAU request of FIG. 6. The second TAU request may be integrity protected using a second uplink count different from the first uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The obtaining of the second context request at 1408 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0238] At 1410, the second network entity derives a second mapped security context when the second integrity check in the second TAU request is successful. The manner of deriving the second mapped security context may be similar to deriving the first mapped security context as described with respect to 632, 634, and the mapped EPS security context 636 of Figure 6. The derivation of the second mapped security context at 1410 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0239] At 1412, the second network entity outputs a second mapped security context for the first network entity. The manner of outputting the second mapped security context may be similar to outputting the first mapped security context as described with respect to the mapped EPS security context 636 and the context response message 638 of Figure 6. The output of the second mapped security context at 1412 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0240] 15 is a flowchart 1500 of a method of wireless communication. The method may be performed by a second network entity (e.g., the base station 102 or a component of the base station 102, the MME 412, the AMF 432, the network entity 1602 of FIG. 16, and / or the network entity 1760 of FIG. 17). The method may facilitate improving communication performance by improving security handling of reselection from a first cell to a second cell, in examples including retransmission of RLF and TAU request messages.

[0241] The second network entity may be in communication with the first network entity. In some examples, the first network entity may include an MME, such as the MME 606 of FIG. 6, and the second network entity may include an AMF, such as the AMF 608 of FIG. 6.

[0242] At 1502, the second network entity obtains a first context request, the first context request including at least a first TAU ​​request generated by the UE as described with respect to the context request message 622 of FIG. 6. The first TAU ​​request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 of FIG. 6. The first TAU ​​request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU ​​request message 610. The first RAT may be different from a second RAT associated with the first network entity. For example, the first RAT may correspond to a 5G network 609, and the second RAT associated with the first network entity may correspond to an EPS network 607 associated with the MME 606 of FIG. 6. The obtaining of the first context request in 1502 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG.

[0243] In some examples, the first context request may further include an identifier mapped to the second RAT, such as the example mapped EPS GUTI 612 of FIG. 6.

[0244] At 1504, the second network entity derives the first mapped security context when the first integrity check in the first TAU ​​request is successful, as described with respect to 632, 634, and the mapped EPS security context 636 in Figure 6. The derivation of the first mapped security context at 1504 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0245] In some examples, the second network entity may perform a first integrity check in the first TAU ​​request based on the first security context, as described with respect to 632 in FIG. 6 and the 5G NAS security context 692.

[0246] At 1506, the second network entity outputs the first mapped security context for the first network entity as described with respect to the mapped EPS security context 636 and the context response message 638 of Figure 6. The output of the first mapped security context at 1506 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0247] In some examples, the second network entity may start a timer after outputting the first mapped security context at 1508. The starting of the timer at 1508 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0248] In some examples, the second network entity may clear the first mapped security context after the timer expires, at 1510. The clearing of the first mapped security context, at 1510, may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0249] At 1512, the second network entity obtains a second context request, where the second context request includes at least a second TAU request generated by the UE as described with respect to the second context request message 674 including the TAU request of FIG. 6. The second TAU request may be integrity protected using a second uplink count different from the first uplink count. For example, the first TAU ​​request may be integrity protected using an uplink NAS count value of 5, and the second TAU request may be integrity protected using an uplink NAS count value of 6. The obtaining of the second context request at 1512 may be performed by the network security handling component 199 of the network entity 1602 of FIG. 16 and / or the network security handling component 497 of the network entity 1760 of FIG. 17.

[0250] In some examples, the second TAU request may include a repetition of the first TAU ​​request.

[0251] At 1514, the second network entity derives a second mapped security context when the second integrity check in the second TAU request is successful. The manner of deriving the second mapped security context may be similar to deriving the first mapped security context as described with respect to 632, 634, and the mapped EPS security context 636 of Figure 6. The derivation of the second mapped security context at 1514 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0252] At 1516, the second network entity outputs a second mapped security context for the first network entity. The manner of outputting the second mapped security context may be similar to outputting the first mapped security context as described with respect to the mapped EPS security context 636 and the context response message 638 of Figure 6. The output of the second mapped security context at 1516 may be performed by the network security handling component 199 of the network entity 1602 of Figure 16 and / or the network security handling component 497 of the network entity 1760 of Figure 17.

[0253] FIG. 16 is a diagram 1600 illustrating an example of a hardware implementation for a network entity 1602. The network entity 1602 may be a BS, may be a component of a BS, or may implement BS functionality. The network entity 1602 may include at least one of a CU 1610, a DU 1630, or a RU 1640. For example, depending on the layer functionality handled by the network security handling component 199, the network entity 1602 may include a CU 1610, both the CU 1610 and the DU 1630, each of the CU 1610, the DU 1630, and the RU 1640, the DU 1630, both the DU 1630 and the RU 1640, or the RU 1640. The CU 1610 may include a CU processor 1612. The CU processor 1612 may include an on-chip memory 1612′. In some aspects, the CU 1610 may further include an additional memory module 1614 and a communication interface 1618. The CU 1610 communicates with the DU 1630 through a midhaul link, such as an F1 interface. The DU 1630 may include a DU processor 1632. The DU processor 1632 may include an on-chip memory 1632′. In some aspects, the DU 1630 may further include an additional memory module 1634 and a communication interface 1638. The DU 1630 communicates with the RU 1640 through a fronthaul link. The RU 1640 may include a RU processor 1642. The RU processor 1642 may include an on-chip memory 1642′. In some aspects, the RU 1640 may further include an additional memory module 1644, one or more transceivers 1646, an antenna 1680, and a communication interface 1648. The RU 1640 communicates with the UE 104. The on-chip memory (e.g., on-chip memory 1612′, on-chip memory 1632′, and / or on-chip memory 1642′) and / or additional memory modules (e.g., additional memory module 1614, additional memory module 1634, and / or additional memory module 1644) may each be considered a computer-readable medium / memory. Each computer-readable medium / memory may be non-transitory.Each of the CU processor 1612, DU processor 1632, and RU processor 1642 is responsible for general processing, including the execution of software stored on a computer-readable medium / memory. The software, when executed by the corresponding processor, causes the processor to perform various functions described above. The computer-readable medium / memory may also be used to store data that is manipulated by the processor when executing the software.

[0254] As described above, the network security handling component 199 may include receiving a first tracking area update (TAU) request generated by a user equipment (UE), the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, the first TAU ​​request including a first set of information including an identifier mapped to a second RAT associated with the first network entity; outputting a first context request for a second network entity based on the first TAU ​​request, the second network entity being associated with the first RAT; receiving a first mapped security context based on the first context request, the first mapped security context being received by the first network entity; the mapped security context is derived from the first security context and the first uplink count; receiving a second TAU request, where the second TAU request is encoded using the first security context and is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information; outputting a second context request for the second network entity based on the second TAU request; receiving a second mapped security context based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count; and transmitting a downlink message based on the second mapped security context.

[0255] In another aspect, the network security handling component 199 is configured to receive a first context request, the first context request including at least a first Tracking Area Update (TAU) request generated by a user equipment (UE), the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first RAT being different from a second RAT associated with the first network entity, and when a first integrity check on the first TAU ​​request is successful, the first mapped security context is encoded using a first uplink count. the second context request includes at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count that is different from the first uplink count; when a second integrity check in the second TAU request is successful, deriving a second mapped security context; and outputting the second mapped security context for the first network entity.

[0256] The network security handling component 199 may be within one or more processors of one or more of the CU 1610, DU 1630, and RU 1640. The network security handling component 199 may be one or more hardware components specifically configured to execute the described processes / algorithms, may be implemented by one or more processors configured to execute the described processes / algorithms, may be stored in a computer-readable medium for implementation by one or more processors, or some combination thereof.

[0257] In one configuration, the network entity 1602 may be a first network entity and may include means for obtaining a first tracking area update (TAU) request generated by a user equipment (UE), where the first TAU ​​request is encoded using a first security context associated with a first radio access technology (RAT), where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; means for outputting a first context request for a second network entity based on the first TAU ​​request, where the second network entity is associated with the first RAT; and means for obtaining a first mapped security context based on the first context request, where the first RAT is associated with the first RAT. the mapped security context is derived from the first security context and the first uplink count; means for obtaining a second TAU request, the second TAU request being encoded using the first security context, the second TAU request being integrity protected using a second uplink count that is different from the first uplink count, and the second TAU request including a first set of information; means for outputting a second context request for the second network entity based on the second TAU request; means for obtaining a second mapped security context based on the second context request, the second mapped security context being derived from the first security context and the second uplink count; and means for outputting a downlink message based on the second mapped security context.

[0258] In another configuration, the first context request includes an identifier mapped to the second RAT, and the first TAU ​​request is integrity protected using the first uplink count.

[0259] In another configuration, the example network entity 1602 also includes means for deriving an address of the second network entity based on the identifier mapped to the second RAT.

[0260] In another configuration, the example network entity 1602 also includes means for updating a security context of the first network entity from the first mapped security context to the second mapped security context based on obtaining the second mapped security context, and means for discarding pending downlink transmissions that are integrity protected using the first mapped security context after updating the security context of the first network entity.

[0261] In another configuration, the second TAU request includes a repetition of the first TAU ​​request.

[0262] In another configuration, the first TAU ​​request is obtained based on a non-inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU accept message, and the example network entity 1602 also includes means for retransmitting the downlink message.

[0263] In another configuration, the example network entity 1602 also includes means for restarting the T3450 timer and means for skipping incrementing a retransmission counter for the T3450 timer when a TAU completion message is expected from the UE.

[0264] In another configuration, the first TAU ​​request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, and the downlink message includes a TAU accept message, and the example network entity 1602 also includes means for initiating an authentication procedure and means for performing a security mode control procedure to transition the new partial-native evolved packet system (EPS) security context to the current fully-native EPS security context.

[0265] In another configuration, the example network entity 1602 also includes means for outputting a downlink message repetition when the security mode control procedure is successful, where the downlink message repetition is integrity protected using the current full native EPS security context, and means for restarting a T3450 timer when a TAU completion message is expected from the UE, and means for skipping incrementing a retransmission counter for the T3450 timer.

[0266] In another configuration, the first TAU ​​request is obtained based on a non-inter-system change from the N1 mode to the S1 mode, and the UE is configured to operate in a single registration mode, and the example network entity 1602 also includes means for skipping initiation of a TAU procedure based on the second TAU request and means for integrity protecting the downlink message based on the first mapped security context.

[0267] In another configuration, the first TAU ​​request is obtained based on an inter-system change from N1 mode to S1 mode, and the UE is configured to operate in a single registration mode, and the example network entity 1602 also includes means for determining to initiate a second TAU procedure, the means including outputting a second context request to the second network entity and integrity protecting the downlink message based on the second mapped security context.

[0268] In another configuration, the first network entity includes a mobility management entity (MME) and the second network entity includes an access and mobility management function (AMF).

[0269] In one configuration, the network entity 1602 may be a second network entity and includes means for obtaining a first context request, the first context request including at least a first Tracking Area Update (TAU) request generated by a user equipment (UE), the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first RAT being different from a second RAT associated with the first network entity; and means for verifying a first mapped security context when a first integrity check on the first TAU ​​request is successful. the first network entity; means for obtaining a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count; means for deriving a second mapped security context when a second integrity check in the second TAU request is successful; and means for outputting the second mapped security context for the first network entity.

[0270] In another configuration, the first context request further includes an identifier mapped to the second RAT.

[0271] In another configuration, the second TAU request includes a repetition of the first TAU ​​request.

[0272] In another configuration, the example network entity 1602 also includes means for starting a timer after outputting the first mapped security context, and means for clearing the first mapped security context after the timer expires.

[0273] In another configuration, the example network entity 1602 also includes means for performing a first integrity check on the first TAU ​​request based on the first security context.

[0274] In another configuration, the first network entity includes a mobility management entity (MME) and the second network entity includes an access and mobility management function (AMF).

[0275] The means may be a network security handling component 199 of the network entity 1602 configured to perform the functions recited by the means. As described above, the network entity 1602 may include the TX processor 316, the RX processor 370, and the controller / processor 375. Thus, in one configuration, the means may be the TX processor 316, the RX processor 370, and / or the controller / processor 375 configured to perform the functions recited by the means.

[0276] FIG. 17 is a diagram 1700 illustrating an example of a hardware implementation for a network entity 1760. In one example, the network entity 1760 may be in the core network 120. The network entity 1760 may include a network processor 1712. The network processor 1712 may include an on-chip memory 1712′. In some aspects, the network entity 1760 may further include an additional memory module 1714. The network entity 1760 communicates with the CU 1702 directly (e.g., a backhaul link) or indirectly (e.g., through a RIC) via a network interface 1780. The on-chip memory 1712′ and the additional memory module 1714 may each be considered a computer-readable medium / memory. Each computer-readable medium / memory may be non-transitory. The network processor 1712 is responsible for general processing, including the execution of software stored on the computer-readable medium / memory. The software, when executed by a corresponding processor, causes the processor to perform various functions described above. The computer-readable medium / memory may also be used for storing data that is manipulated by the processor when executing the software.

[0277] As described above, the network security handling component 497 may include receiving a first tracking area update (TAU) request generated by a user equipment (UE), the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, the first TAU ​​request including a first set of information including an identifier mapped to a second RAT associated with the first network entity; outputting a first context request for a second network entity based on the first TAU ​​request, the second network entity being associated with the first RAT; receiving a first mapped security context based on the first context request, the first mapped security context being received by the first network entity; the mapped security context is derived from the first security context and the first uplink count; receiving a second TAU request, where the second TAU request is encoded using the first security context and is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information; outputting a second context request for the second network entity based on the second TAU request; receiving a second mapped security context based on the second context request, where the second mapped security context is derived from the first security context and the second uplink count; and transmitting a downlink message based on the second mapped security context.

[0278] In another aspect, the network security handling component 497 is configured to receive a first context request, the first context request including at least a first tracking area update (TAU) request generated by a user equipment (UE), the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first RAT being different from a second RAT associated with the first network entity, and when a first integrity check on the first TAU ​​request is successful, the first mapped security context is encoded using a first uplink count. the second context request includes at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count that is different from the first uplink count; when a second integrity check in the second TAU request is successful, deriving a second mapped security context; and outputting the second mapped security context for the first network entity.

[0279] The network security handling component 497 may be within the network processor 1712. The network security handling component 497 may be one or more hardware components specifically configured to execute the described processes / algorithms, implemented by one or more processors configured to execute the described processes / algorithms, stored in a computer readable medium for implementation by one or more processors, or some combination thereof. The network entity 1760 may include various components configured for various functions.

[0280] In one configuration, the network entity 1760 may be a first network entity and include means for obtaining a first tracking area update (TAU) request generated by a user equipment (UE), where the first TAU ​​request is encoded using a first security context associated with a first radio access technology (RAT), where the first TAU ​​request is integrity protected using a first uplink count based on the first security context, where the first TAU ​​request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; means for outputting a first context request for a second network entity based on the first TAU ​​request, where the second network entity is associated with the first RAT; and means for obtaining a first mapped security context based on the first context request, where the first RAT is associated with the first RAT. the mapped security context is derived from the first security context and the first uplink count; means for obtaining a second TAU request, the second TAU request being encoded using the first security context, the second TAU request being integrity protected using a second uplink count that is different from the first uplink count, and the second TAU request including a first set of information; means for outputting a second context request for the second network entity based on the second TAU request; means for obtaining a second mapped security context based on the second context request, the second mapped security context being derived from the first security context and the second uplink count; and means for outputting a downlink message based on the second mapped security context.

[0281] In another configuration, the first context request includes an identifier mapped to the second RAT, and the first TAU ​​request is integrity protected using the first uplink count.

[0282] In another configuration, the example network entity 1760 also includes means for deriving an address of the second network entity based on the identifier mapped to the second RAT.

[0283] In another configuration, the example network entity 1760 also includes means for updating a security context of the first network entity from the first mapped security context to the second mapped security context based on obtaining the second mapped security context, and means for discarding pending downlink transmissions that are integrity protected using the first mapped security context after updating the security context of the first network entity.

[0284] In another configuration, the second TAU request includes a repetition of the first TAU ​​request.

[0285] In another configuration, the first TAU ​​request is obtained based on a non-inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU accept message, and the example network entity 1760 also includes means for retransmitting the downlink message.

[0286] In another configuration, the example network entity 1760 also includes means for restarting the T3450 timer and means for skipping incrementing a retransmission counter for the T3450 timer when a TAU completion message is expected from the UE.

[0287] In another configuration, the first TAU ​​request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, and the downlink message includes a TAU accept message, and the example network entity 1760 also includes means for initiating an authentication procedure and means for performing a security mode control procedure to transition the new partial-native evolved packet system (EPS) security context to the current fully-native EPS security context.

[0288] In another configuration, the example network entity 1760 also includes means for outputting a downlink message repetition when the security mode control procedure is successful, where the downlink message repetition is integrity protected using the current full native EPS security context, and means for restarting a T3450 timer when a TAU completion message is expected from the UE, and means for skipping incrementing a retransmission counter for the T3450 timer.

[0289] In another configuration, the first TAU ​​request is obtained based on a non-inter-system change from the N1 mode to the S1 mode, and the UE is configured to operate in a single registration mode, and the example network entity 1760 also includes means for skipping initiation of a TAU procedure based on the second TAU request and means for integrity protecting the downlink message based on the first mapped security context.

[0290] In another configuration, the first TAU ​​request is obtained based on an inter-system change from N1 mode to S1 mode, and the UE is configured to operate in a single registration mode, and the example network entity 1760 also includes means for determining to initiate a second TAU procedure, the means including outputting a second context request to the second network entity and integrity protecting the downlink message based on the second mapped security context.

[0291] In another configuration, the first network entity includes a mobility management entity (MME) and the second network entity includes an access and mobility management function (AMF).

[0292] In one configuration, the network entity 1760 may be a second network entity and includes means for obtaining a first context request, the first context request including at least a first Tracking Area Update (TAU) request generated by a user equipment (UE), the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first RAT being different from a second RAT associated with the first network entity; and means for verifying a first mapped security context when a first integrity check on the first TAU ​​request is successful. the first network entity; means for obtaining a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count; means for deriving a second mapped security context when a second integrity check in the second TAU request is successful; and means for outputting the second mapped security context for the first network entity.

[0293] In another configuration, the first context request further includes an identifier mapped to the second RAT.

[0294] In another configuration, the second TAU request includes a repetition of the first TAU ​​request.

[0295] In another configuration, the example network entity 1760 also includes means for starting a timer after outputting the first mapped security context, and means for clearing the first mapped security context after the timer expires.

[0296] In another configuration, the example network entity 1760 also includes means for performing a first integrity check in the first TAU ​​request based on the first security context.

[0297] In another configuration, the first network entity includes a mobility management entity (MME) and the second network entity includes an access and mobility management function (AMF).

[0298] The means may be a network security handling component 497 of the network entity 1760 configured to perform the functions recited by the means. As described above, the network entity 1760 may include a network processor 1712. Thus, in one configuration, the means may be a network processor 1712 configured to perform the functions recited by the means.

[0299] Examples disclosed herein provide techniques for removing inconsistencies in handling repetitions of the TAU request message described above. For example, the disclosed techniques may remove the inconsistencies by modifying how the network handles repetitions of the TAU request message. The disclosed techniques may additionally or alternatively remove the inconsistencies by modifying how the UE integrity protects the TAU request message. Furthermore, the disclosed techniques may remove the inconsistencies by modifying how the UE performs integrity verification of the message.

[0300] It is understood that the particular order or hierarchy of blocks in the disclosed processes / flowcharts is illustrative of example approaches. Based on design preferences, it is understood that the particular order or hierarchy of blocks in the processes / flowcharts may be rearranged. Further, some blocks may be combined or omitted. The accompanying method claims present elements of the various blocks in an example order, and are not limited to the particular order or hierarchy presented.

[0301] The above description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Thus, the claims are not limited to the aspects described herein, but are to be accorded the full scope consistent with the claim language. Reference to an element in the singular does not mean "one and only one" unless so expressly stated, but means "one or more." Terms such as "if," "when," and "while" do not imply an immediate temporal relationship or reaction. That is, these phrases, for example, "when," do not imply an immediate action in response to or during the occurrence of an action, but merely imply that an action will occur if a condition is satisfied, but does not require a specific or immediate time constraint for the action to occur. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any aspect described herein as "exemplary" should not necessarily be construed as preferred or advantageous over other aspects. Unless otherwise specified, the term "several" refers to one or more. Combinations such as "at least one of A, B, or C," "one or more of A, B, or C," "at least one of A, B, and C," "one or more of A, B, and C," and "A, B, C, or any combination thereof" include any combination of A, B, and / or C and may include multiple As, multiple Bs, or multiple Cs. Specifically, combinations such as "at least one of A, B, or C," "one or more of A, B, or C," "at least one of A, B, and C," "one or more of A, B, and C," and "A, B, C, or any combination thereof" may be A only, B only, C only, A and B, A and C, B and C, or A and B and C, and any such combination may include one or more members of A, B, or C.A set should be interpreted as a set of elements, where an element consists of one or more. Thus, for a set of X, X will include one or more elements. When a first device receives data from or transmits data to a second device, the data may be received / transmitted directly between the first device and the second device, or indirectly between the first device and the second device through a set of devices. All structural and functional equivalents of the elements of the various embodiments described throughout this disclosure that are known or that later become known to those skilled in the art are expressly incorporated herein by reference and are encompassed by the claims. Furthermore, nothing disclosed herein is made public, regardless of whether such disclosure is expressly recited in the claims. Words such as "module," "mechanism," "element," "device," and the like may not be substitutes for the word "means." Thus, no claim element should be interpreted as a means plus function unless the element is expressly recited using the phrase "means for."

[0302] As used herein, the phrase "based on" should not be construed as referring to a closed set of information, one or more conditions, one or more factors, etc. In other words, the phrase "based on A" (where "A" can be information, a condition, a factor, etc.) should be construed as "based at least on A," unless expressly stated otherwise.

[0303] The following aspects are illustrative only and can be combined with, but not limited to, other aspects or teachings described herein.

[0304] Aspect 1 is a method of wireless communication in a UE, the method including: sending a first tracking area update (TAU) request to a first network entity, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, and the first TAU ​​request including a first set of information including an identifier mapped to a second RAT associated with the first network entity; sending a second TAU request to the first network entity, the second TAU request including the first set of information, and the second TAU request being integrity protected using a second uplink count; deriving a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count; and communicating with the first network entity based on the mapped security context.

[0305] Aspect 2 is the method of aspect 1, further including a step of transmitting a first TAU ​​request when performing a change from a first cell associated with the first RAT to connect to a second cell associated with a second RAT, where the second RAT is different from the first RAT and the first network entity is associated with the second RAT.

[0306] Example 3 is the method of any of Examples 1 and 2, further including: the second TAU request includes a repetition of the first TAU ​​request, and the second uplink count is the same value as the first uplink count.

[0307] Example 4 is the method of any of Examples 1 to 3, further comprising transmitting a second TAU request based on an occurrence of a radio link failure.

[0308] Example 5 is the method of any of examples 1 and 2, further comprising: the mapped security context being associated with a second RAT.

[0309] Example 6 is the method of any of Examples 1 and 2, further including: the second uplink count is different from the first uplink count; and the mapped security context is the first mapped security context; the method further includes: deriving a second mapped security context based on the first security context and the first uplink count; wherein the second TAU request is encoded using the first security context and integrity protected using the second uplink count; and the first mapped security context is derived based on the first security context and the second uplink count.

[0310] Example 7 is the method of any of Examples 1 and 6, further including: updating a security context of the UE from the second mapped security context to the first mapped security context based on derivation of the first mapped security context; and discarding pending transmissions that are integrity protected using the second mapped security context after updating the security context of the UE.

[0311] Example 8 is the method of any of examples 1, 6, and 7, further including the second TAU request including a repetition of the first TAU ​​request.

[0312] Aspect 9 is an apparatus for wireless communication in a UE including at least one processor coupled to a memory and configured to implement any of aspects 1-8.

[0313] In example 10, the apparatus of example 9 further includes at least one antenna coupled to the at least one processor.

[0314] In example 11, the apparatus of example 9 or 10 further includes a transceiver coupled to the at least one processor.

[0315] Example 12 is an apparatus for wireless communication, the apparatus including means for implementing any of Examples 1 to 8.

[0316] In an embodiment 13, the apparatus of embodiment 12 further comprises at least one antenna coupled to the means for performing the method of any of embodiments 1-8.

[0317] In an embodiment 14, the apparatus of embodiments 12 or 13 further comprises a transceiver coupled to the means for performing the method of any of embodiments 1-8.

[0318] Aspect 15 is a non-transitory computer-readable storage medium storing computer-executable code that, when executed, causes a processor to implement any of aspects 1 through 8.

[0319] Aspect 16 is a method of wireless communication in a UE, comprising: when performing a change from a first cell associated with a first radio access technology (RAT) to connect to a second cell associated with a second RAT different from the first RAT, the step of transmitting a first tracking area update (TAU) request to a first network entity, the first network entity being associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, the first TAU ​​request being integrity protected using a first uplink count based on the first security context; deriving a first integrity key based on the first security context, the first uplink count, and the first mapped security context; and transmitting a repetition of the first TAU ​​request to the first network entity. and wherein a first iteration of the TAU request is integrity protected using a second uplink count different from the first uplink count; deriving a second integrity key based on the first security context, the second uplink count, and the second mapped security context; receiving a downlink transmission from the first network entity; performing an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key; and setting a master security key for the UE when the integrity check on the downlink transmission is successful using the derived integrity key, wherein the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.

[0320] Example 17 is the method of example 16, further comprising the step of erasing the second mapped security context and any keys derived using the second mapped security context when an integrity check on the downlink transmission is successful using the first integrity key, wherein the master security key includes the first mapped security context.

[0321] Example 18 is the method of example 16, further including the step of erasing the first mapped security context and any keys derived using the first mapped security context when an integrity check on the downlink transmission is successful using the second integrity key, wherein the master security key includes the second mapped security context.

[0322] Example 19 is the method of any of Examples 16-18, further including deriving a first mapped security context based on the first security context and the first uplink count.

[0323]

[0031] Aspect 20 is an apparatus for wireless communication in a UE including at least one processor, coupled to a memory and configured to implement any of aspects 16-19.

[0324] In example 21, the apparatus of example 20 further includes at least one antenna coupled to the at least one processor.

[0325] In example 22, the apparatus of example 20 or 21 further includes a transceiver coupled to the at least one processor.

[0326] Example 23 is an apparatus for wireless communication, the apparatus including means for implementing any of Examples 16 to 19.

[0327] In example 24, the apparatus of example 23 further comprises at least one antenna coupled to the means for performing the method of any of examples 16-19.

[0328] In embodiment 25, the apparatus of embodiment 23 or 24 further comprises a transceiver coupled to the means for performing the method of any of embodiments 16-19.

[0329] Aspect 26 is a non-transitory computer-readable storage medium storing computer-executable code that, when executed, causes a processor to implement any of aspects 16-19.

[0330] Aspect 27 is a method of wireless communication in a first network entity, comprising the steps of: obtaining a first tracking area update (TAU) request generated by a user equipment (UE), the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, the first TAU ​​request including a first set of information including an identifier mapped to a second RAT associated with the first network entity; outputting a first context request for a second network entity based on the first TAU ​​request, the second network entity being associated with the first RAT; and obtaining a first mapped security context based on the first context request, the first mapping information being a first mapping information. obtaining a second TAU request, the second TAU request being encoded using the first security context, the second TAU request being integrity protected using a second uplink count different from the first uplink count, and the second TAU request including a first set of information; outputting a second context request for a second network entity based on the second TAU request; obtaining a second mapped security context based on the second context request, the second mapped security context being derived from the first security context and the second uplink count; and outputting a downlink message based on the second mapped security context.

[0331] Example 28 is the method of example 27, further including: the first context request includes an identifier mapped to the second RAT; and the first TAU ​​request is integrity protected using the first uplink count.

[0332] Example 29 is the method of any of Examples 27 and 28, further comprising deriving an address of the second network entity based on the identifier mapped to the second RAT.

[0333] Example 30 is the method of any of Examples 27 to 29, further including: updating a security context of the first network entity from the first mapped security context to the second mapped security context based on obtaining the second mapped security context; and discarding pending downlink transmissions that are integrity protected using the first mapped security context after updating the security context of the first network entity.

[0334] Example 31 is the method of any of examples 27 to 30, further including the second TAU request including a repetition of the first TAU ​​request.

[0335] Example 32 is the method of any of Examples 27 to 31, further including that the first TAU ​​request is obtained based on a non-inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, and the downlink message includes a TAU accept message, the method further including the step of retransmitting the downlink message.

[0336] Example 33 is the method of any of Examples 27 to 32, further comprising the steps of restarting the T3450 timer and skipping incrementing a retransmission counter for the T3450 timer when a TAU completion message is expected from the UE.

[0337] Example 34 is the method of any of Examples 27 to 31, further including that the first TAU ​​request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, and the downlink message includes a TAU accept message, the method further including a step of initiating an authentication procedure and a step of performing a security mode control procedure to transition the new partial-native evolved packet system (EPS) security context to the current fully-native EPS security context.

[0338] Example 35 is the method of any of Examples 27 and 34, further comprising the steps of: outputting a downlink message repetition when the security mode control procedure is successful, where the downlink message repetition is integrity protected using the current full native EPS security context; and restarting a T3450 timer when a TAU completion message is expected from the UE; and skipping incrementing a retransmission counter for the T3450 timer.

[0339] Example 36 is the method of any of Examples 27 to 31, further including that the first TAU ​​request is obtained based on a non-inter-system change from N1 mode to S1 mode and the UE is configured to operate in a single registration mode, the method further including a step of skipping initiation of a TAU procedure based on the second TAU request and a step of integrity protecting the downlink message based on the first mapped security context.

[0340] Example 37 is the method of any of Examples 27 to 31, further including that the first TAU ​​request is obtained based on an inter-system change from N1 mode to S1 mode and the UE is configured to operate in a single registration mode, and the method further includes a step of determining to initiate a second TAU procedure, the step including outputting a second context request to a second network entity and integrity protecting the downlink message based on the second mapped security context.

[0341] Example 38 is the method of any of examples 27 to 37, further including: the first network entity includes a mobility management entity (MME) and the second network entity includes an access and mobility management function (AMF).

[0342] Example 39 is an apparatus for wireless communication in a UE including at least one processor, coupled to a memory, configured to implement any of examples 27-38.

[0343] In example 40, the apparatus of example 39 further includes at least one antenna coupled to the at least one processor.

[0344] In example 41, the apparatus of example 39 or 40 further includes a transceiver coupled to the at least one processor.

[0345] Example 42 is an apparatus for wireless communication comprising means for implementing any of examples 27 to 38.

[0346] In example 43, the apparatus of example 42 further includes at least one antenna coupled to the means for performing the method of any of examples 27-38.

[0347] In embodiment 44, the apparatus of embodiment 42 or 43 further includes a transceiver coupled to the means for performing the method of any of embodiments 27-38.

[0348] Aspect 45 is a non-transitory computer-readable storage medium storing computer-executable code that, when executed, causes a processor to implement any of aspects 27-38.

[0349] Aspect 46 is a method of wireless communication in a second network entity, comprising the steps of: obtaining a first context request, the first context request including at least a first Tracking Area Update (TAU) request generated by a user equipment (UE), the first TAU ​​request being integrity protected using a first uplink count, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first RAT being different from a second RAT associated with the first network entity; and, when a first integrity check on the first TAU ​​request is successful, encoding the first mapped security context. a first mapped security context for the first network entity; obtaining a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count; when a second integrity check in the second TAU request is successful, deriving a second mapped security context; and outputting the second mapped security context for the first network entity.

[0350] Example 47 is the method of example 46, further comprising: the first context request further including an identifier mapped to the second RAT.

[0351] Example 48 is the method of any of examples 46 and 47, further including the second TAU request including a repetition of the first TAU ​​request.

[0352] Example 49 is the method of any of examples 46 to 48, further including the steps of starting a timer after outputting the first mapped security context, and clearing the first mapped security context after the timer expires.

[0353] Example 50 is the method of any of examples 46 to 49, further comprising performing a first integrity check in the first TAU ​​request based on the first security context.

[0354] Example 51 is the method of any of examples 46 to 50, further including: the first network entity includes a mobility management entity (MME); and the second network entity includes an access and mobility management function (AMF).

[0355]

[0031] Aspect 52 is an apparatus for wireless communication in a UE including at least one processor coupled to a memory and configured to implement any of aspects 46 to 51.

[0356] In embodiment 53, the apparatus of embodiment 52 further includes at least one antenna coupled to the at least one processor.

[0357] In embodiment 54, the apparatus of embodiment 52 or 53 further includes a transceiver coupled to the at least one processor.

[0358] Example 55 is an apparatus for wireless communication comprising means for implementing any of examples 46 to 51.

[0359] In embodiment 56, the apparatus of embodiment 55 further includes at least one antenna coupled to the means for performing the method of any of embodiments 46-51.

[0360] In embodiment 57, the apparatus of embodiment 55 or 56 further comprises a transceiver coupled to the means for performing the method of any of embodiments 46-51.

[0361] Aspect 58 is a non-transitory computer-readable storage medium storing computer-executable code that, when executed, causes a processor to implement any of aspects 46 to 51. [Explanation of symbols]

[0362] 102, 310 base station 104, 350, 404, 604 UE 105 SMO Framework 110, 1610, 1702 CU 111 Open eNB (O-eNB) 115 Non-Real-Time (Non-RT) RIC, Non-RT RIC 120, 430 Core Network 125 Near-RT RIC 130, 1630 DU 140, 1640 RU 150 Wi-Fi AP 154 Communication Links 158 D2D communication links 161, 432, 608 AMF 162, 436 SMF 163,438 UPF 164,440 UDM 165 GMLC 166 LMF 168 Location Server 170 Satellite Positioning System (SPS) 182, 184 Beamformed Signals 190 Open Cloud (O-Cloud) 198 UE Security Handling Components 199, 497 Network security handling components 316, 368 TX Processor 318Tx, 354Tx Transmitters 318Rx, 354Rx Receivers 320, 352, 1180, 1680 Antenna 356, 370 RX processor 358, 374 Channel Estimator 359, 375 Controller / Processor 360, 376 Memory 402a first network node, network node 402b second network node, network node 406 Geographic Coverage Area 408 Communication Links 410 EPC 412, 606 MME 414 Other MMEs 416 Serving Gateway 418 MBMS GW 420BM-SC 422 PDN Gateway 424 HSS 426, 442 IP Services 434 Other AMF 452 1st Backhaul Link 454 Second Backhaul Link 456 3rd Backhaul Link 500 First Security Context 502 Master Security Key 504 KSI 506 UE Security Capabilities 508 Uplink NAS Count 510 Downlink NAS Count 520 Secondary Security Context 522 5G key 524 5G KSI 526 5G UE Security Capabilities 528 5G uplink NAS count 530 5G Downlink NAS Count 540 Third Security Context 542 EPS key 544 EPS KSI 546 EPS UE Security Capabilities 548 EPS Uplink NAS Count 550 EPS Downlink NAS Count 602 Network Node 607 EPS Network 609 5G Network 610 First TAU ​​Request Message 612 Mapped EPS GUTI 613 TMSI 614 NAS-MAC 616 eKSI parameters 622 Context Request Message 636 Mapped EPS Security Context 638 Context Response Message 642 UE Mapped EPS Security Context, Mapped EPS Security Context 660 NAS SMC Procedure 662 TAU Reception Message 666 TAU Completion Message 670 Second TAU Request Message 674 Second Context Request Message 682 New UE Mapped EPS Security Context 690 5G Security Context 692 5G NAS Security Context 694 Security Algorithm Information 1102, 1602, 1760 Network Entities 1104 Equipment 1106 Application Processor 1106', 1124', 1612', 1632', 1642', 1712' On-chip memory 1108 Secure Digital (SD) Card 1110 Screen 1112 Bluetooth Module 1114 WLAN Module 1116 SPS Module 1118 Sensor Module 1120 Subscriber Identity Module (SIM) Card 1122 Cellular RF Transceiver 1124 Cellular Baseband Processor 1126, 1614, 1634, 1644, 1714 Additional Memory Modules 1130 Power supply 1132 Camera 1612 CU processor 1618, 1638, 1648 Communication Interface 1632DU Processor 1642RU processor 1646 Transceiver 1712 Network Processor 1780 Network Interface

Claims

1. An apparatus for wireless communication in a user equipment (UE), comprising: Memory, at least one processor coupled to the memory; the at least one processor coupled to the memory: sending a first tracking area update (TAU) request to a first network entity, the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, and the first TAU ​​request including a first set of information including an identifier mapped to a second RAT associated with the first network entity; sending a second TAU request to the first network entity, the second TAU request including the first set of information, the second TAU request being integrity protected using a second uplink count; deriving a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count; and communicating with the first network entity based on the mapped security context. configured to: the second TAU request includes a repetition of the first TAU ​​request, and the second uplink count is the same value as the first uplink count.

2. The apparatus, 2. The apparatus of claim 1, further comprising: at least one antenna coupled to the at least one processor, wherein the at least one processor coupled to the memory is configured to: send the first TAU ​​request when performing a change from a first cell associated with the first RAT to connect to a second cell associated with the second RAT, where the second RAT is different from the first RAT and the first network entity is associated with the second RAT.

3. 3. The apparatus of claim 2, wherein the at least one processor coupled to the memory is configured to send the second TAU request based on an occurrence of a radio link failure.

4. The apparatus of claim 2 , wherein the mapped security context is associated with the second RAT.

5. the second uplink count is different from the first uplink count, the mapped security context is a first mapped security context, and the at least one processor coupled to the memory: deriving a second mapped security context based on the first security context and the first uplink count, wherein the second TAU request is encoded using the first security context and integrity protected using the second uplink count, and the first mapped security context is derived based on the first security context and the second uplink count. The apparatus of claim 1 , further configured to:

6. An apparatus for wireless communication in a user equipment (UE), comprising: Memory, at least one processor coupled to the memory; the at least one processor coupled to the memory: sending a first tracking area update (TAU) request to a first network entity when performing a change from a first cell associated with a first radio access technology (RAT) to connect to a second cell associated with a second RAT different from the first RAT, the first network entity being associated with the second RAT, the first TAU ​​request being encoded using a first security context associated with the first RAT, and the first TAU ​​request being integrity protected using a first uplink count based on the first security context; deriving a first integrity key based on the first security context, the first uplink count, and a first mapped security context; sending a repetition of the first TAU ​​request to the first network entity, wherein the repetition of the first TAU ​​request is integrity protected using a second uplink count different from the first uplink count; deriving a second integrity key based on the first security context, the second uplink count, and a second mapped security context; receiving a downlink transmission from the first network entity; performing an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key; and setting a master security key for the UE when the integrity check on the downlink transmission is successful using a derived integrity key, and clearing the first mapped security context or the second mapped security context and all keys derived using the first mapped security context or all keys derived using the second mapped security context, wherein the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key. An apparatus configured to:

7. The apparatus, at least one antenna coupled to the at least one processor; Further equipped with The apparatus of claim 6 , wherein the master security key comprises the first mapped security context.

8. The apparatus of claim 6, wherein the master security key includes the second mapped security context.

9. the at least one processor coupled to the memory; deriving the first mapped security context based on the first security context and the first uplink count; The apparatus of claim 6, further configured to:

10. An apparatus for wireless communication in a first network entity, comprising: Memory, at least one processor coupled to the memory; the at least one processor coupled to the memory: obtaining a first tracking area update (TAU) request generated by a user equipment (UE), the first TAU ​​request being encoded using a first security context associated with a first radio access technology (RAT), the first TAU ​​request being integrity protected using a first uplink count based on the first security context, and the first TAU ​​request including a first set of information including an identifier mapped to a second RAT associated with the first network entity; outputting a first context request for a second network entity based on the first TAU ​​request, the second network entity being associated with the first RAT; obtaining a first mapped security context based on the first context request, the first mapped security context being derived from the first security context and the first uplink count; obtaining a second TAU request, the second TAU request being encoded using the first security context, the second TAU request being integrity protected using a second uplink count different from the first uplink count, and the second TAU request including the first set of information; outputting a second context request for the second network entity based on the second TAU request; obtaining a second mapped security context based on the second context request, the second mapped security context being derived from the first security context and the second uplink count; and outputting a downlink message based on the second mapped security context; An apparatus configured to:

11. 11. The apparatus of claim 10, wherein the first context request includes the identifier mapped to the second RAT, and the first TAU ​​request is integrity protected using the first uplink count.

12. The apparatus, at least one antenna coupled to the at least one processor; and wherein the at least one processor coupled to the memory further comprises: deriving an address of the second network entity based on the identifier mapped to the second RAT. The apparatus of claim 10 , further configured to:

13. the at least one processor coupled to the memory; updating a security context of the first network entity from the first mapped security context to the second mapped security context based on obtaining the second mapped security context; and discarding pending downlink transmissions that are integrity protected using the first mapped security context after updating the security context of the first network entity. The apparatus of claim 10 , further configured to:

14. 11. The apparatus of claim 10, wherein the second TAU request comprises a repetition of the first TAU ​​request.

15. The first TAU ​​request is obtained based on a non-inter-system change from an N1 mode to an S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU accept message, and the at least one processor coupled to the memory: retransmitting the downlink message. The apparatus of claim 10 , further configured to: