Radio link recovery for user equipment

Secure radio link recovery in NB-IoT networks is achieved by utilizing the NAS security context between user equipment and the mobility management entity, addressing vulnerabilities in existing RRC connection re-establishment procedures and ensuring reliable communication.

JP2025098003APending Publication Date: 2025-07-01NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025028855
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2017-09-11
Filing Date
2025-02-26
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Current communication systems face security vulnerabilities during radio link recovery in Narrowband IoT (NB-IoT) networks, particularly for machine-type communication, as existing proposals for Radio Resource Control (RRC) connection re-establishment procedures are susceptible to attacks without adequate protection of the UE-eNB link.

Method used

The solution involves enabling secure radio link recovery through a mobility management node using a previously established Non-Access Stratum (NAS) security context between the user equipment and the mobility management entity, leveraging existing NAS keys to protect the link without setting up a new context.

Benefits of technology

This approach enhances security by protecting the link between the user equipment and the eNB, mitigating attack risks and maintaining continuous connection without introducing new context setups, thus ensuring secure and reliable radio link recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025098003000001_ABST
    Figure 2025098003000001_ABST
Patent Text Reader

Abstract

To provide a method of recovering a radio link for given user equipment through a target access node of a communication system in response to a radio link failure between given user equipment of the communication system during a data transfer operation on a control plane.SOLUTION: Radio link recovery is made possible through a mobility management node of a communication system using a non-access layer security context established in the past between given user equipment and the mobility management node.SELECTED DRAWING: Figure 1A
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims priority to U.S. Provisional Patent Application No. 62 / 488,179, entitled "Cellular Internet of Things (CIoT) UE Radio Link Recovery Using NAS Keys," filed on April 21, 2017, the disclosure of which is incorporated herein by reference in its entirety.

[0002] This field generally relates to communication systems, and more particularly, but not exclusively, to security within such systems.

Background Art

[0003] This section outlines aspects that may be useful to facilitate a better understanding of the present invention. Thus, what is stated in this section should be read from this perspective and should not be construed as an admission as to what is included or not included in the prior art.

[0004] The 4th generation (4G) wireless mobile telecommunications technology, also known as Long Term Evolution (LTE) technology, is designed to provide high-capacity mobile multimedia with high data rates, particularly with respect to human interaction. The next generation, i.e., the 5th generation (5G) technology, is intended to be used not only for human interaction but also for machine-type communication in so-called Internet of Things (IoT) networks.

[0005] In a communication system such as an LTE example, a user equipment (UE) such as a mobile device communicates with a base station called an evolved Node B (eNB) over a radio interface. By way of example, the eNB is part of an access network of a system such as, for example, an evolved Universal Terrestrial Radio Access Network (E-UTRAN). The eNB provides access to the UE to a core network (CN), and the CN provides access to the UE to a data network such as a packet data network (e.g., a PDN such as the Internet).

[0006] Narrowband IoT (NB-IoT) is a low-power wide-area network (LPWAN) radio technology developed to enable the connection of a wide variety of devices (e.g., mobile devices, sensors, smart meters, etc.) and services using a cellular communication network. For example, in the aforementioned LTE network, the E-UTRAN connects a cellular IoT (CIoT) UE to the CN and ultimately to services available through a PDN or other data network. However, in currently proposed examples, there are security issues regarding CIoT UEs in the NB-IoT network, for example, during operations such as wireless link recovery.

Prior Art Documents

Non-Patent Documents

[0007]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

Non-Patent Document 4

Non-Patent Document 5

Non-Patent Document 6

SUMMARY OF THE INVENTION

MEANS FOR SOLVING THE PROBLEM

[0008] Exemplary embodiments provide techniques for providing secure radio link recovery to user equipment in a communication system.

[0009] In one embodiment, a method includes recovering, in response to a radio link failure between a given user equipment and a source access node in a communication system during a data transfer operation on a control plane, a radio link for the given user equipment through a target access node of the communication system. The radio link recovery is enabled through a mobility management node of the communication system using a previously established non-access stratum security context between the given user equipment and the mobility management node.

[0010] In another embodiment, a method includes recovering, in response to a radio link failure between a given user equipment and a source access node in a communication system during a data transfer operation on a control plane, a radio link for the given user equipment through a target access node of the communication system. The radio link recovery is initiated by the given user equipment by sending a message to a mobility management node of the communication system through the target access node using a previously established non-access stratum security context between the given user equipment and the mobility management node.

[0011] Advantageously, in an exemplary embodiment, secure wireless link recovery is achieved using only the non-access stratum security context between a given user equipment and a mobility management node, and its associated cryptographic keys, without setting up a new context to protect the link between the given user equipment and a target access node. For key separation, the new key may be calculated using existing non-access stratum security parameters or non-access stratum message counts in either the uplink or the downlink.

[0012] Further embodiments are provided in the form of a non-transitory computer-readable storage medium embodying executable program code that, when executed by a processor, causes the processor to perform the aforementioned steps. Further embodiments comprise an apparatus having a processor and a memory configured to perform the aforementioned steps.

[0013] These and other features and advantages of the embodiments described herein will become more apparent from the accompanying drawings and the detailed description set forth below.

Brief Description of the Drawings

[0014]

Figure 1A

Figure 1B

Figure 2

Figure 3

Figure 4

Figure 5A

Figure 5B

[0015] Embodiments are illustrated herein in conjunction with an exemplary communication system and related techniques for wireless link recovery for user equipment. However, it should be understood that the claims are not limited to the specific types of communication systems and / or processes disclosed. Embodiments can be implemented in a wide variety of other types of communication systems using alternative processes and operations. For example, although illustrated in the context of a wireless cellular system utilizing 3GPP system elements such as LTE evolved packet core (EPC), the disclosed embodiments can be readily adapted to a variety of other types of communication systems including, but not limited to, WiMAX systems and Wi-Fi systems. Also, although the exemplary embodiments are particularly well-suited for implementation in an NB-IoT network, embodiments can be implemented in other networks where secure wireless link recovery is desired or required.

[0016] Next, various exemplary embodiments will be described with reference to the drawings, and like reference numerals are used to refer to like elements throughout all the drawings. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of one or more exemplary embodiments. However, it will be apparent that such exemplary embodiments may be practiced without these specific details or with functionally similar or equivalent alternatives.

[0017] As used illustratively in this specification, the Non-Access Stratum (NAS) is a functional layer of a communication network that provides non-radio signaling for some control plane functions between a UE and a Core Network (CN) transparently to a Radio Access Network (RAN). Such functions include, but are not limited to, mobility management, authentication, and others. Compare the NAS functional layer with the Access Stratum (AS), a functional layer below NAS that provides functions between the UE and the RAN, including but not limited to data transport over a radio connection and radio resource management.

[0018] Support for radio link recovery and mobility for NB-IoT UEs using CIoT optimization solutions is being considered by relevant standardization bodies. This optimization solution for data transfer over the NAS layer is also referred to as Data over NAS (DoNAS). Some proposals include the use of a Radio Resource Control (RRC) connection re-establishment procedure that enables context fetching and data transfer from a serving (or source) eNB to a target eNB in a mobility scenario, similar to a conventional active mode handover scenario. However, such proposals can introduce security risks that must be addressed to reduce potential harm from malicious actors.

[0019] More specifically, a UE's use of a Radio Resource Control (RRC) connection re-establishment procedure for CIoT control plane optimization (DoNAS) can be vulnerable to attacks because the RRC connection of the CIoT UE to the eNB is not secure. Various aspects of the following description can be clarified by reference to TS23.401, Rel.14, 2016-12, §5.3.4B.2, TS24.301, TS33.401, each of which is incorporated herein by reference in its entirety.

[0020] At least one current proposal for CIoT control plane optimization strategies includes a strategy of a single short data packet. However, in this specification, it is recognized that such a strategy can be at risk in terms of security. Threat analysis demonstrates that it is vulnerable to attacks unless the UE-eNB link is protected. The following findings result from such threat analysis:

[0021] (i) If the UE has a large amount of data to transmit or receive, the UE may have an access stratum (AS) context established with the eNB and a NAS context established with the mobility management entity (MME). In such cases, the RRC message must be protected. Without such context and protection, it may not be possible to maintain a continuous connection between the eNB and the UE. For example, the UE connection may be hijacked or closed by an attacker UE. Also, the eNB may be subject to attacks using fake data and / or control packets in the uplink (UL).

[0022] (ii) In some current proposals, it is not clear how mobility (e.g., handover of the UE from a serving or source eNB to a target eNB) is established without establishing the AS context in a trustworthy manner. Therefore, the AS context needs to be established for a trustworthy X2 or S1 handover.

[0023] (iii) Without the AS security context in the serving or source eNB and the target eNB, there are attack scenarios on the downlink (DL) to, and the UL from, the DoNAS UE, as well as to the S1 application protocol (S1AP) link of the DoNAS UE.

[0024] In various exemplary embodiments, one or more of the aforementioned security risks may be mitigated by enabling security for radio link recovery by protecting the link between the UE and the eNB using the NAS context between the UE and the MME element (node) of the CN and the NAS key associated with that context.

[0025] Before describing such a secure radio link recovery process according to an exemplary embodiment, an exemplary communication system in which such a process may be executed is described in connection with FIGS. 1A and 1B.

[0026] FIG. 1A shows a communication system 100 including a user equipment (UE) 102 that communicates with an evolved Node B (eNB) 104 via a radio interface 103. In this exemplary embodiment, the communication system 100 includes a wireless cellular system, and more particularly, an LTE system. The communication system 100 shows at least a part of an NB-IoT network.

[0027] The user equipment 102 may be a mobile station, and such a mobile station may include, by way of example, a mobile phone, a computer, a sensor, a smart meter, or any other type of communication device. Thus, the term "user equipment" as used herein is intended to be broadly construed to include communication devices, including examples such as various different types of combinations of mobile stations, subscriber stations, or more generally, data cards inserted into communication devices. It is also intended that such communication devices include devices commonly referred to as access terminals. In this exemplary embodiment, the UE 102 is considered a CIoT UE.

[0028] The eNB 104 is, by way of example, part of the access network of the communication system 100. Such a radio access network may comprise, for example, an E-UTRAN having a plurality of base stations and one or more associated radio network controllers (RNCs). The base stations and the RNCs are logically separate entities, but in a given embodiment may be implemented in the same physical network element, such as a base station router or a femtocell access point. The eNB may more generally be referred to as an access node.

[0029] Figure 1A illustrates 4G network nomenclature, but it should be understood that the communication 100 may be a 5G network or a hybrid 4G / 5G network. For this reason, the access point referred to as an eNB in a 4G network is referred to as a gNB in a 5G network. The access node (e.g., gNB / eNB) is, by way of example, part of the radio access network of the communication system. The 4G network utilizes the E-UTRAN as the radio access network, but in a 5G network, the access network is referred to as a 5G system and is described in 5G Technical Specification (TS) 23.501, V0.4.0, entitled "Technical Specification Group Services and System Aspects; System Architecture for the 5G System", the disclosure of which is hereby incorporated by reference in its entirety. Generally, the access node (e.g., gNB / eNB) provides access to the CN for the UE, and the CN then provides access to other UEs and / or a data network, such as the Internet, for the UE. In this exemplary embodiment, the CIoT UE may access the CIoT service via the data packet network.

[0030] In this exemplary embodiment, eNB 104 is operationally coupled to a Mobility Management Entity (MME) 106. MME 106 is an example of what is referred to as a "Mobility Management Entity element", "Mobility Management Entity function", or more generally, a "Mobility Management Node". A Mobility Management Node as used herein is an element or function in a communication system that enables, among other network operations, radio link recovery operations with a UE (through the eNB). Also, eNB 104 is operationally coupled to a Serving Gateway (SGW) 108 which is operationally coupled to a Packet Data Network (PDN) Gateway (PGW) 110. PGW 110 is operationally coupled to a packet data network, such as the Internet 112. Also, MME 106 is operationally coupled to SGW 108. MME 106 and SGW 108 are considered part of the CN. In some embodiments, PGW 110 is also considered part of the CN.

[0031] It should be recognized that this particular arrangement of system elements is merely an example, and that in other embodiments, additional or alternative elements of other types or arrangements may be used to implement a communication system. For example, in other embodiments, system 100 may include authentication elements and other elements not explicitly shown herein.

[0032] Accordingly, the arrangement of FIG. 1A is merely one exemplary configuration of a wireless cellular system, and numerous alternative configurations of system elements may be used. For example, while a single UE, eNB, MME, SGW, and PGW element are shown in the embodiment of FIG. 1A, this is merely for simplicity and clarity of explanation. Any given alternative embodiment may, of course, include a greater number of such system elements, functions, and / or nodes, as well as additional or alternative elements, functions, and / or nodes of the types commonly associated with conventional system implementations.

[0033] Also, although FIG. 1A illustrates system elements, functions, and / or nodes as individual functional blocks, it should also be noted that the various sub-networks that make up the 5G network are divided into so-called network slices. A network slice (network partition) comprises a set of functions (i.e., a function chain) for each corresponding service type that uses network function virtualization (NFV) on a common physical infrastructure. Network slices are instantiated as needed for a given service, such as an enhanced mobile broadband (eMBB) service, a massive IoT service, and a mission-critical IoT service. For this reason, a network slice or set of functions is instantiated when an instance of that network slice or set of functions is created. In some embodiments, this includes installing a network slice or set of functions on one or more host devices of the underlying physical infrastructure, or otherwise running a network slice or set of functions on such devices. UE102 accesses one or more of these services through the CN via eNB104.

[0034] As described above, it is possible for a radio link failure to occur where UE102 loses its connection to eNB104 for various typical reasons. In such a case, as shown in FIG. 1B, when UE102 loses its connection to eNB104 (shown as the source eNB), UE102 may re-establish a connection (radio interface 103) with eNB114 (shown as the target eNB) by means of a radio link recovery process according to an exemplary embodiment.

[0035] It should be recognized that in the communication system 100 illustrated in FIGS. 1A and 1B, both eNB 104 and eNB 114 are operatively coupled to the same MME 106 and SGW 108. However, in alternative embodiments, eNB 104 and eNB 114 can each be operatively coupled to different MMEs and / or different SGWs. As will also be explained later, eNB 104 and eNB 114 can actually be the same eNB.

[0036] When UE 102 loses its connection with source eNB 104 and requests to re - establish a connection with target eNB 114, an exemplary embodiment provides a secure radio link recovery operation for UE 102 using the existing NAS security context and keys established between UE 102 and MME 106.

[0037] FIG. 2 shows a more detailed view of UE 102 and MME 106 in an exemplary embodiment. UE 102 includes a processor 200 coupled to a memory 202 and an interface circuit 204. The processor 200 of UE 102 includes a recovery processing module 210, which may be implemented, at least in part, in the form of software executed by the processor. By "recovery processing" is meant to refer to the processing steps (operations, processes, executed instructions, etc.) associated with radio link recovery according to one or more exemplary embodiments. More specifically, the recovery processing module 210 performs the user equipment operations of the radio link recovery process as described in connection with subsequent figures and otherwise described herein. The memory 202 of UE 102 includes a recovery storage module 212 that stores data generated during radio link recovery operations with MME 106 through target eNB 114.

[0038] The MME 106 includes a processor 220 coupled to a memory 222 and an interface circuit 224. The processor 220 of the MME 106 includes a recovery processing module 230, which may be implemented, at least in part, in the form of software executed by the processor. The recovery processing module 230 performs MME operations in the context of a radio link recovery process between the UE and the target eNB, as described in connection with subsequent figures and otherwise described herein. The memory 222 of the MME 106 includes a recovery storage module 232 that stores data generated during radio link recovery operations with the UE 102 through the target eNB 114.

[0039] The processors 200 and 220 of the respective UE 102 and MME 106 may comprise, for example, a microprocessor, an application specific integrated circuit (ASIC), a digital signal processor (DSP), or other type of processing device, as well as portions or combinations of such elements.

[0040] The memories 202 and 222 of the respective UE 102 and MME 106 may be used to store one or more software programs executed by the respective processors 200 and 220 to implement at least a portion of the functions described herein. For example, radio link recovery operations and other functions, as described in connection with subsequent figures and otherwise described herein, may be implemented in a straightforward manner using software code executed by the processors 200 and 220.

[0041] Accordingly, a given one of memories 202 or 222 may be regarded, in this specification, as an example of what is more generally referred to herein as a computer program product, or more generally as a processor-readable (or computer-readable) storage medium embodying executable program code. Other examples of processor-readable storage media may include disks, or other types of magnetic or optical media in any combination. Exemplary embodiments can include a manufactured product that includes such a computer program product or other processor-readable storage medium.

[0042] Memory 202 or 222 may more particularly comprise, for example, an electronic random access memory (RAM) such as static RAM (SRAM), dynamic RAM (DRAM), or other types of volatile or non-volatile electronic memory. Non-volatile electronic memory may include, for example, non-volatile memory such as flash memory, magnetic RAM (MRAM), phase change RAM (PC-RAM), or ferroelectric RAM (FRAM (registered trademark)). The term "memory" as used herein is intended to be construed broadly and may further or alternatively include, for example, read only memory (ROM), disk-based memory, or other types of storage devices, as well as portions or combinations of such devices.

[0043] The interface circuits 204 and 224 of respective UEs 102 and MMEs 106 comprise, by way of example, a transceiver or other communication hardware or communication firmware that enables associated system elements to communicate with each other in the manner described herein.

[0044] From FIG. 2, it is clear that UE102 is configured for communication with MME106 via interface circuit 204, and MME106 is configured for communication with UE102 via interface circuit 224. UE102 communicates with MME106 via eNB114. This communication includes UE102 transmitting data to MME106 via eNB114 and MME106 transmitting data to UE102 via eNB114. However, in alternative embodiments, other network elements may be operatively coupled between the UE and the MME. The term "data" as described herein is intended to be broadly construed to include, but not limited to, radio link recovery data, control data, audio, video, multimedia, data from any sensor device, and any other type of information that may be transmitted between a user equipment and a core network via a base station element.

[0045] It should be recognized that the particular arrangement of components shown in FIG. 2 is merely an example, and numerous alternative arrangements may be used in other embodiments. For example, the user equipment and the mobile management entity may be configured to incorporate additional or alternative components and to support other communication protocols.

[0046] Other system elements such as eNB104, eNB114, SGW108, and PGW110 may each be configured to include components such as a processor, a memory, and a network interface. These elements need not be implemented on separate stand-alone processing platforms, and instead, for example, may represent different functional portions of a single common processing platform. Such a processing platform may further comprise at least a portion of an eNB and an associated RNC.

[0047] Exemplary embodiments provide radio link recovery for a CIoT UE (e.g., UE102) that seeks to lose connection with a serving or source eNB (e.g., eNB104) and re - establish connection with a target eNB (e.g., eNB114). More specifically, as will be further described later, exemplary embodiments use existing NAS keys and NAS contexts between the UE and the MME (e.g., MME106). In a radio link failure (RLF) scenario at the source eNB104, a temporary AS context may be created at the eNB until the UE102 directly sends NAS messages to the MME106 through the target eNB114. Some other embodiments may use an alternative key calculated from existing NAS context parameters or NAS message counts between the UE and the MME for key separation between normal NAS messages and radio link recovery procedures to re - establish connection with the target eNB.

[0048] In some embodiments, it should be noted that the target eNB114 may be the same as the source eNB104, i.e., the UE seeks to re - establish connection with the same eNB it lost connection with. In such a case, that same eNB is the serving or source access node and thus the target access node.

[0049] The MME106 retrieves packets buffered at the source eNB104. The MME106 sets up a new S1AP with the target eNB114 and transmits further packets (including the packets retrieved from the source eNB104). S1AP is the S1 application protocol that serves as the E - UTRAN radio network layer signaling protocol for the S1 interface. S1AP supports the functions of the S1 interface by signaling procedures defined in 3GPP TS36.413, the disclosure of which is hereby incorporated by reference in its entirety.

[0050] Advantageously, according to an exemplary embodiment, there is no other key calculation except for one set of NAS keys. The MME 106 uses the normal NAS integrity key K NASint to verify NAS messages indicating RLF. The NAS integrity key K NASint and the NAS encryption key K NASenc are included, but not limited to, the NAS security context establishment and key generation described in 3GPP TS 24.301 and 3GPP TS 33.401, the disclosure of which is hereby incorporated by reference in its entirety. The radio link recovery procedure and key calculation are described in detail in 3GPP TS 36.300, 3GPP TS 36.413, and 3GPP TS 33.401, the disclosure of which is hereby incorporated by reference in its entirety.

[0051] An exemplary radio link recovery embodiment is described in FIG. 3. More specifically, FIG. 3 shows the message flow regarding the radio link recovery process for a user equipment. It should be recognized that the system elements, functions, and / or nodes (UE, eNB (source), eNB (target), and MME) shown in FIG. 3 correspond to the system elements, functions, and / or nodes with similar labels in FIGS. 1A, 1B, and 2. The numbered steps below correspond to the message flow numbers in FIG. 3.

[0052] 1. The CIoT UE 102 (note that "CIoT" may also be referred to as "NBIoT" in the figures and other parts of this specification) that requests to perform control plane (CP) data transfer establishes a NAS link (security context) with the MME 106 for data transfer in either UL or DL. The MME 106 sets up an S1AP path to the source eNB 104 for packet transfer. Note that the source eNB 104 has no further context regarding the UE 102.

[0053] 2. During data transfer, UE 102 detects a radio link failure (RLF). Additionally, or alternatively, RLF can be detected by eNB 104 in some cases.

[0054] 2a. If eNB 104 detects an RLF, eNB 104 may proactively send the packet data units (PDUs associated with the data transfer mentioned in step 1) for UE 102 that are in its buffer and not yet transmitted to MME 106, and report the RLF to UE 102 as shown in S1AP.

[0055] 3 / 3a. When UE 102 detects an RLF, UE 102 selects a target eNB 114 (note that in this case, it is possible that this is the same eNB as the source eNB 104), and sends a NAS message reporting the encounter with the RLF. The NAS message is protected using the normal NAS integrity key K NASint created as part of the NAS security context with MME 106 mentioned in step 1.

[0056] 4. MME 106 verifies the NAS message using the normal K NASint created as part of the NAS security context with MME 106 mentioned in step 1.

[0057] 5. If the integrity check is successful, MME 106 retrieves the remaining unsent packets for UE 102 from source eNB 104. If source eNB 104 has proactively sent the remaining data in step 2a, this packet transfer is not required in this step. MME 106 cancels the S1AP context and path to source eNB 104.

[0058] 6a / 6b. MME 106 sends a new S1AP context setup to target eNB 114. MME 106 sends a NAS RLF positive acknowledgment to UE 102 together with the new data via target eNB 114. The NAS message uses the same normal KNASint is protected for integrity, and the data is encrypted using the NAS encryption key K NASenc (both created as part of the NAS security context with the MME106 mentioned in step 1).

[0059] Many advantages are realized from the wireless link recovery techniques according to the exemplary embodiments. For example, some of these advantages include, but are not limited to:

[0060] i) There is no new context set up to protect the link between the UE102 and the target eNB114, and only the NAS context and NAS keys between the UE102 and the MME106 are used. If key separation from normal NAS messages is desired during wireless link recovery, alternative keys may be calculated from the current NAS context.

[0061] ii) The assumption is that for CIoT UEs, the RLF (RRC connection re - establishment request) is processed by the eNB protected by the NAS context parameters. When CIoT UEs encounter an RLF, since they only have the NAS context, they either send a NAS message (indicating the RLF) to the MME or a RRC connection re - establishment request message protected by the NAS context parameters to the target eNB.

[0062] iii) Since the NAS messages or the RRC connection re - establishment request messages are protected, neither attacks using these messages nor path switching to another eNB are possible.

[0063] iv) If only NAS messages are used, the changes in the existing elements, functions, and / or nodes of the network are minimal, i.e., two NAS messages between the UE 102 that reports RLF and returns a positive response and the MME 106, and two S1AP messages between the MME 106 and the eNB for buffer packet extraction and S1AP path change.

[0064] v) The UE 102 uses only the NAS context throughout the operation.

[0065] vi) The MME 106 does not need to transfer the NAS algorithm or the NAS identifier to other nodes.

[0066] Therefore, generally, during the data transfer operation on the control plane, in response to a radio link failure between a given user equipment (e.g., UE 102) and a source access node (e.g., eNB 104) of the communication system, the process recovers the radio link for the given user equipment through the target access node (e.g., eNB 114) of the communication system. The radio link recovery is enabled through the mobility management node (e.g., MME 106) of the communication system using the previously established NAS security context between the given user equipment and the mobility management node.

[0067] For example, as shown in FIG. 4, the radio link recovery process according to the exemplary embodiment includes the following steps.

[0068] Step 400 receives a first NAS message from a given user equipment at the mobility management node. The first NAS message indicates that the given user equipment has experienced RLF with the source access node, and is protected using the encryption key (e.g., NAS integrity key K NASint ) created during the previous establishment of the NAS security context between the given user equipment and the mobility management node.

[0069] Step 402 verifies a given user equipment at the mobility management node using the encryption key (K NASint ).

[0070] Step 404 starts the setup of a target access node and a signaling interface (e.g., S1AP) at the mobility management node.

[0071] Step 406 sends a second NAS message from the mobility management node to a given user equipment through the target access node. The second NAS message indicates a positive response to RLF and is protected using the encryption key (K NASint ) created during the previous establishment of the NAS security context between the given user equipment and the mobility management node. The second NAS message accommodates data associated with data transfer. The data is previously buffered data and / or new data. The data is encrypted using another encryption key (NAS encryption key K NASenc ) created during the previous establishment of the NAS security context between the given user equipment and the mobility management node.

[0072] Also in some embodiments, for key separation between different procedures, an alternative key may be calculated using NAS context parameters together with an uplink message count or a downlink message count.

[0073] In this alternative key embodiment, the NBIoT UE uses another key "K RLFint " to protect the uplink NAS message to the MME reporting RLF. As shown in the key derivation function (KDF) in Figure 5A, the key calculation uses the NAS uplink count parameter and K NASint together with the current K ASME . Since the NAS uplink count is included in all uplink NAS messages, the receiving side can calculate the integrity key K RLFintTo calculate and avoid synchronization errors in message counts in a radio link failure situation, it is possible to use the count value in the received message. This can help with proper security and count verification of radio link failure messages when multiple messages are transmitted during unstable radio conditions. It is also possible for the MME 106 to use the "NAS downlink count" in the downlink message for better synchronization during RLF occurrence.

[0074] For this reason, the message flow shown in Figure 5B is the same as that shown in Figure 3 for steps 1, 2, 2a, 3a, 5, 6a, and 6b, but for steps 3 and 4, the UE 102 uses K NASint instead of the normal key K RLFint (derived as shown in Figure 5A for example).

[0075] It should be recognized that the naming of the network elements referred to in this specification is for illustrative purposes only. Therefore, neither the specific names nor the acronyms given to these network elements in this specification are intended to limit the embodiments in any way.

[0076] As described above, the embodiments are not limited to the context of LTE, and the disclosed techniques can be adapted in a straightforward manner to the context of a wide variety of other communication systems, including but not limited to other 3GPP systems and non-3GPP systems.

[0077] The processors, memories, controllers, and other components of the user equipment elements or base station elements of the communication systems disclosed herein may include well-known circuits appropriately modified to implement at least a portion of the radio link recovery functions described above.

[0078] As described above, embodiments may be realized in the form of a manufactured article each comprising one or more software programs executed by a processing circuit of a user equipment, a base station, or other elements of a communication system. Conventional aspects of such circuits are well known to those skilled in the art and, accordingly, will not be described in detail herein.

[0079] Also, embodiments may be implemented in one or more ASICs, FPGSs, or other types of integrated circuit devices in any combination. Such integrated circuit devices, as well as portions or combinations of such integrated circuit devices, are examples of "circuits" as the term is used herein.

[0080] A wide variety of other hardware arrangements, and associated software or firmware, may be used in implementing the exemplary embodiments.

[0081] Accordingly, it should be emphasized that the various embodiments described herein are presented by way of example only and should not be construed as limiting the claims. For example, alternative embodiments may utilize communication system configurations, user equipment configurations, base station configurations, wireless link recovery processes, messaging protocols, and message formats that are different from those described above in the context of the exemplary embodiments. These, and many other alternative embodiments, within the scope of the appended claims will be readily apparent to those skilled in the art.

Claims

1. 1. A method comprising: In a communications system, in response to a radio link failure between a given user equipment of the communications system and a source access node during a data forwarding operation on a control plane, recovering a radio link for the given user equipment through a target access node of the communication system, the radio link recovery being enabled via the mobility management node of the communication system using a non-access stratum security context previously established between the given user equipment and the mobility management node; A method, wherein a mobility management node comprises a processor and a memory configured to enable radio link recovery.

2. 2. The method of claim 1, wherein recovering the radio link further comprises receiving, at a mobility management node, a first non-access stratum message from a given user equipment.

3. 3. The method of claim 2, wherein the first non-access stratum message indicates that the given user equipment has experienced a radio link failure with the source access node and is protected using an encryption key created from a non-access stratum security context between the given user equipment and the mobility management node.

4. Recovering the radio link Validating a given user equipment using a cryptographic key at a mobility management node; initiating, at a mobility management node, a setup of a signaling interface with a target access node; sending a second non-access stratum message from the mobility management node to the given user equipment through the target access node; Retrieving buffered data associated with the data forwarding from the source access node by the mobility management node; The method of claim 3 further comprising:

5. 2. The method of claim 1, wherein the communication system comprises a Narrowband Internet of Things (NB-IoT) network and further wherein the given user equipment comprises a Cellular IoT (CIoT) user equipment.

6. 13. An article of manufacture comprising a non-transitory computer readable storage medium having embodied thereon executable program code that, when executed by a processor, causes the processor to perform the method of claim 1.

7. An apparatus comprising: In a communications system, in response to a radio link failure between a given user equipment of the communications system and a source access node during a data forwarding operation on a control plane, A network node in a communication system configured to act as a mobility management entity and further configured to enable recovering a radio link for a given user equipment through a target access node of the communication system, An apparatus, wherein radio link recovery is enabled via a mobility management entity using a non-access stratum security context previously established between a given user equipment and the mobility management entity.

8. 1. A method comprising: In a communications system, in response to a radio link failure between a given user equipment of the communications system and a source access node during a data forwarding operation on a control plane, recovering a radio link for a given user equipment through a target access node of the communication system, the radio link recovery being initiated by the given user equipment by sending a message through the target access node to a mobility management node of the communication system using a non-access stratum security context previously established between the given user equipment and the mobility management node; A method, in which a given user equipment comprises a processor and memory configured to initiate radio link recovery.

9. An article of manufacture comprising a non-transitory computer readable storage medium having embodied thereon executable program code that, when executed by a processor, causes the processor to perform the method of claim 8.

10. An apparatus comprising: In a communications system, in response to a radio link failure between a given user equipment of the communications system and a source access node during a data forwarding operation on a control plane, 1. An apparatus comprising: a given user equipment configured to enable recovery of a radio link for the given user equipment through a target access node of a communication system, wherein the radio link recovery is initiated by the given user equipment by sending a message through the target access node to a mobility management node of the communication system using a non-access stratum security context that has been previously established between the given user equipment and the mobility management node.