Secure L1 / L2-centric inter-cell mobility implementation
By mapping physical cell identifiers to unique indices and securely transmitting these in 5G networks, the method addresses security risks in handovers, ensuring secure L1/L2-centric inter-cell mobility and adhering to industry standards.
Patent Information
- Application Number
- JP2025504135
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-28
- Filing Date
- 2023-02-23
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2043-02-23
AI Technical Summary
In 5G cellular networks, unsecured messages during handover between distributed units (DUs) of a base station can pose security risks, potentially exposing user routes or locations to tracking.
A method involving mapping physical cell identifiers (PCIs) of target cells to unique indices and securely transmitting these mappings from the aggregation unit control plane (CU-CP) to user equipment (UE) and serving DUs, ensuring secure L1/L2-centric inter-cell mobility without compromising security.
Enables secure handover processes in 5G networks by protecting user information and location privacy during inter-cell mobility, adhering to 3GPP standards and O-RAN Alliance protocols.
Smart Images

Figure 2025528731000001_ABST
Abstract
Description
[Technical Field]
[0001] [CROSS REFERENCE TO RELATED APPLICATIONS] This application claims priority to Indian Patent Application No. 202221061428, titled "Method and System for Secure L1 / L2 Centric Inter-Cell Mobility Execution," filed on October 28, 2022, which is incorporated herein by reference in its entirety.
[0002] [Technical field] In some implementations, the present subject matter relates to communication systems, and in particular to secure Layer 1 / Layer 2 (L1 / L2)-centric inter-cell mobility implementations. [Background technology]
[0003] In today's world, cellular networks provide on-demand communication capabilities to individuals and business entities. Typically, cellular networks are wireless networks that can be distributed over a terrestrial area called a cell. Each such cell is served by at least one fixed-location transceiver, referred to as a cell site or base station. Each cell can use a different set of frequencies from its neighboring cells to avoid interference and provide improved service within each cell. Together, the cells provide wireless coverage over a wide geographic area, allowing numerous mobile phones and / or other wireless devices or portable transceivers to communicate with each other and with fixed transceivers and phones anywhere in the network. Such communication is performed through base stations, even when a communicating mobile transceiver passes through more than one cell. Major wireless communication providers deploy such cell sites worldwide, allowing communicating mobile phones and mobile computing devices to connect to public switched telephone networks and the public Internet.
[0004] A mobile phone is a portable telephone that can receive and / or make telephone and / or data calls through a cell site or communication tower by using radio waves to transmit signals to and from the mobile phone. From the perspective of a large number of mobile phone users, current mobile phone networks offer limited and shared resources. In this regard, cell sites and handsets can change frequencies and use low-power transmitters to allow simultaneous use of the network by many callers with less interference. Coverage by a cell site can depend on the particular geographic location and / or the number of users that can potentially use the network. For example, in a city, a cell site may have a range of up to about 1 / 2 mile. In suburban areas, the range may be as long as 5 miles. In some areas, users can receive signals from cell sites as far away as 25 miles.
[0005] The following are some examples of digital cellular technologies used by communications providers: Global System for Mobile Communications ("GSM"), General Packet Radio Service ("GPRS"), cdmaOne, CDMA2000, Evolution-Data Optimized ("EV-DO"), Enhanced Data Rates for GSM Evolution ("EDGE"), Universal Mobile Telecommunications System ("UMTS"), Digital Enhanced Cordless Telecommunications ("DECT"), Digital AMPS ("IS-136 / TDMA"), and Integrated Digital Enhanced Network ("iDEN"). Long Term Evolution or 4G LTE, developed by the Third Generation Partnership Project ("3GPP") standards organization, is a standard for high-speed data wireless communications for mobile phones and data terminals. 5G standards are currently being developed and deployed. 3GPP cellular technologies such as LTE and 5G NR are evolutions of previous generations of 3GPP technologies such as GSM / EDGE and UMTS / HSPA digital cellular technologies, and allow for increased capacity and speeds by using different air interfaces along with core network improvements.
[0006] A cellular network may be divided into a radio access network and a core network. The radio access network (RAN) may include network functions capable of handling radio layer communication processing. The core network may include network functions capable of handling higher layer communication (e.g., Internet Protocol (IP), transport layer, and application layer). In some cases, the RAN function may be divided into a baseband unit function and a radio unit function. Here, the radio unit connected to the baseband unit via a fronthaul network may be responsible for lower layer processing, for example, of the radio physical layer, and the baseband unit may be responsible for higher layer radio protocols (e.g., MAC, RLC, etc.). Summary of the Invention [Problem to be solved by the invention]
[0007] A base station for a 5G cellular network may include a centralized unit (CU), one or more distributed units (DUs) communicatively coupled to the CU, and one or more radio units (RUs), each communicatively coupled to at least one of the one or more DUs and each configured to be communicatively coupled to one or more mobile phones and / or other user equipment (UE). The CU may be logically separated into a control plane portion (CU-CP) and one or more user plane portions (CU-UP). During a UE's communicative coupling with the base station, the DU supporting the UE may change. To accomplish such a handover from one DU to another, unsecured messages may be sent to the UE 802, which may pose a security breach with the risk of the user's route being tracked or the user's location being traced. [Means for solving the problem]
[0008] In some implementations, the present subject matter relates to a computer-implemented method, which may include mapping a physical cell identifier (PCI) of at least one L1 / L2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for a user equipment (UE) to an index, and securely transmitting the mapping from an aggregation unit control plane (CU CP) of the base station to the UE and a serving DU of the base station currently serving the UE for at least one service.
[0009] The method may enable L1 / L2 centric inter-cell mobility without compromising on security.
[0010] In some implementations, the current subject may include one or more of the following optional features:
[0011] In some implementations, the index for each of the at least one LTM target cells may be unique in the mapping such that each index is uniquely associated with one of the at least one LTM target cells by the PCI.
[0012] In some implementations, the method may also include securely transmitting the mapping from the CU-CP to a target DU that includes one of the at least one LTM target cell selected for HO.
[0013] In some implementations, the mapping may be sent to the UE in a radio resource control (RRC) reconfiguration message, and the mapping may be sent to the serving DU in an F1 UE context modification request message.
[0014] In some implementations, the method may also include updating the mapping in response to at least one of one of the at least one LTM target cells being excluded for the UE and one of the at least one LTM target cells being replaced for the UE, and securely transmitting the updated mapping from the CU CP to the UE and the serving DU.
[0015] In some implementations, the method may also include mapping PCIs of at least one LTM target cell of at least one target DU that is a candidate for HO for the second UE to an index such that a second mapping is generated, and securely transmitting the second mapping from the CU CP to the second UE.
[0016] In some implementations, the serving DU may use the index received from the CU-CP when sending the LTM HO command to the UE.
[0017] In some implementations, each index may be one of a number, an alphabet, and an alphanumeric.
[0018] In some implementations, the method may also include storing the mapping in at least one non-transitory storage medium.
[0019] In some implementations, the base station may include a Next Generation Radio Access Network (NG-RAN) node, which may further include a gNodeB or an ng-eNodeB.
[0020] In some implementations, a base station may include at least one processor and at least one non-transitory storage medium, and a CU-CP may include at least one processor and at least one non-transitory storage medium.
[0021] Non-transitory computer program products (i.e., physically embodied computer program products) storing instructions that, when executed by one or more data processors of one or more computing systems, cause at least one data processor to perform the operations described herein are also described. Similarly, computer systems are described that may include one or more data processors and memory coupled to the one or more data processors. The memory may store, on a temporary or permanent basis, instructions that cause at least one processor to perform one or more of the operations described herein. In addition, methods may be implemented by one or more data processors within a single computing system or distributed across two or more computing systems. Such computing systems may be connected to exchange data and / or commands or other instructions, etc., over one or more connections (including, but not limited to, connections over a network (e.g., the Internet, a wireless wide area network, a local area network, a wide area network, a wired network, etc.)), such as via a direct connection between one or more of the multiple computing systems.
[0022] Details of one or more variations of the subject matter described herein are set forth in the accompanying drawings and the description below. Other features and advantages of the subject matter described herein will be apparent from the description and drawings, and from the claims. [Brief explanation of the drawings]
[0023] The following accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate certain aspects of the presently disclosed subject matter and, together with the description, serve to explain some of the principles associated with the disclosed implementations.
[0024] FIG. 1a illustrates an exemplary conventional "long term evolution" ("LTE") communications system.
[0025] FIG. 1b shows further details of the exemplary LTE system shown in FIG. 1a.
[0026] FIG. 1c shows additional details of the "evolved packet core" of the exemplary LTE system shown in FIG. 1a.
[0027] FIG. 1d illustrates an exemplary "evolved Node B" for the exemplary LTE system shown in FIG. 1a.
[0028] FIG. 2 illustrates further details of the "evolved Node B" shown in FIGS. 1a-d.
[0029] FIG. 3 illustrates an exemplary virtual radio access network according to some implementations of the current subject matter.
[0030] FIG. 4 shows an exemplary 3GPP split architecture for providing its users with use of higher frequency bands.
[0031] FIG. 5a illustrates an exemplary 5G wireless communication system.
[0032] FIG. 5b shows an example layer architecture for a split gNB and / or a split ng-eNB (e.g., a “next generation eNB” that may be connected to 5GC).
[0033] Figure 5c shows an exemplary functional split in the gNB architecture shown in Figures 5a-b.
[0034] FIG. 6a illustrates an exemplary system according to some implementations of the current subject matter.
[0035] FIG. 6b shows an exemplary alternate configuration of the system of FIG. 6a according to some implementations of the current subject matter.
[0036] FIG. 7 illustrates an exemplary method according to some implementations of the current subject matter.
[0037] FIG. 8 shows an exemplary signaling diagram according to some implementations of the current subject matter.
[0038] Figure 9 shows an example architecture of the gNB-CU-CP in the signaling diagram of Figure 8 according to some implementations of the current subject matter.
[0039] FIG. 10 illustrates an exemplary system according to some implementations of the current subject matter.
[0040] FIG. 11 illustrates an exemplary method according to some implementations of the current subject matter. DETAILED DESCRIPTION OF THE INVENTION
[0041] The present subject matter can provide systems and methods that can be implemented in wireless communication systems. Such systems can include various wireless communication systems, including 5G New Radio communication systems, "long term evolution" communication systems, and the like.
[0042] Generally, the current subject matter relates to secure Layer 1 / Layer 2 (L1 / L2) centric inter-cell mobility implementation.
[0043] In some implementations of the present subject matter, the gNB-CU-CP (the control plane part of the aggregation unit of the gNB (gNodeB)) is configured to generate indices for all cells configured as candidates for L1 / L2-centric inter-cell mobility targets. Currently, according to the 3GPP standard (RAN2 agreement), up to eight Layer 1 / Layer 2 Triggered Mobility (LTM) target cells can be prepared for a given user equipment (UE). The gNB-CU-CP is configured to store a mapping between target cell physical cell identifiers (PCIs) and target cell indices for future use. Thus, L1 / L2-centric inter-cell mobility may be performed without compromising security.
[0044] 3GPP standards may relate to one or more aspects of the present subject matter. O-RAN Alliance standards may also relate to one or more aspects of the present subject matter.
[0045] One or more aspects of the present subject matter may be integrated into transmitter and / or receiver components of a base station (e.g., gNodeB, eNodeB, etc.) in such communication systems. The following is a general discussion of long-term evolution communication systems and 5G New Radio communication systems. I. "Long-term evolution" communication systems
[0046] 1a-c and 2 illustrate an exemplary conventional long-term evolution ("LTE") communication system 100 along with its various components. LTE systems, or 4G LTE, as they are commercially known, conform to standards for high-speed data wireless communications for mobile phones and data terminals. The standards are an evolution of GSM / EDGE ("Global System for Mobile Communications" / "Enhanced Data rates for GSM Evolution") and UMTS / HSPA ("Universal Mobile Telecommunications System" / "High Speed Packet Access") network technologies. The standards were developed by 3GPP ("3rd Generation Partnership Project").
[0047] As shown in FIG. 1a, system 100 may include an “evolved universal terrestrial radio access network” (“EUTRAN”) 102, an “evolved packet core” (“EPC”) 108, and a “packet data network” (“PDN”) 101 through which EUTRAN 102 and EPC 108 provide communication between user equipment 104 and PDN 101. EUTRAN 102 may include multiple “evolved Node Bs” (“eNodeBs” or “ENODEBs” or “enodeb” or “eNBs”) or base stations 106(a, b, c) (as shown in FIG. 1b) that provide communication capabilities to multiple user equipment 104(a, b, c). User equipment 104 may be a mobile phone, a smartphone, a tablet, a personal computer, a personal digital assistant (“PDA”), a server, a data terminal, and / or any other type of user equipment, and / or any combination thereof. User equipment 104 can connect to the EPC 108 and therefore the PDN 101 via any eNodeB 106. Typically, user equipment 104 can connect to the eNodeB 106 that is closest in distance. In the LTE system 100, the EUTRAN 102 and the EPC 108 cooperate to provide connectivity, mobility, and services to user equipment 104.
[0048] Figure 1b illustrates further details of the network 100 shown in Figure 1a. As previously mentioned, the EUTRAN 102 includes multiple eNodeBs 106, also known as cell sites. The eNodeBs 106 provide radio functionality and perform key control functions, including scheduling of air link resources or radio resource management, active mode mobility or handover, and admission control for services. The eNodeBs 106 are responsible for selecting which mobility management entity (MME, as shown in Figure 1c) serves the user equipment 104 and for protocol features such as header compression and encryption. The eNodeBs 106 that make up the EUTRAN 102 cooperate with each other for radio resource management and handover.
[0049] Communication between the user equipment 104 and the eNodeB 106 occurs over an air interface 122 (also known as the "LTE-Uu" interface). As shown in FIG. 1b, the air interface 122 provides communication between the user equipment 104b and the eNodeB 106a. The air interface 122 uses Orthogonal Frequency Division Multiple Access ("OFDMA") and Single-Carrier Frequency Division Multiple Access ("SC-FDMA"), an OFDMA variant, on the downlink and uplink, respectively. OFDMA enables the use of multiple known antenna technologies, such as "Multiple Input Multiple Output" ("MIMO").
[0050] The air interface 122 uses various protocols, including radio resource control ("RRC") for signaling between the user equipment 104 and the eNodeB 106 and non-access stratum ("NAS") for signaling between the user equipment 104 and the MME (as shown in FIG. 1c). In addition to signaling, user traffic is transferred between the user equipment 104 and the eNodeB 106. Both signaling and traffic in the system 100 are carried by physical layer ("PHY") channels.
[0051] Multiple eNodeBs 106 may be interconnected with each other using X2 interfaces 130(a, b, c). As shown in FIG. 1b, X2 interface 130a provides interconnection between eNodeB 106a and eNodeB 106b, X2 interface 130b provides interconnection between eNodeB 106a and eNodeB 106c, and X2 interface 130c provides interconnection between eNodeB 106b and eNodeB 106c. The X2 interfaces may be established between two eNodeBs to provide for the exchange of signals that may include load- or interference-related information and handover-related information. The eNodeBs 106 communicate with the “evolved packet core” 108 via S1 interfaces 124(a, b, c). The S1 interface 124 may be divided into two interfaces: One is the control plane (shown in FIG. 1c as control plane interface (S1-MME interface) 128) and the other is the user plane (shown in FIG. 1c as user plane interface (S1-U interface) 125).
[0052] The EPC 108 establishes and enables "Quality of Service" ("QoS") for user services and allows the user equipment 104 to maintain a consistent Internet Protocol ("IP") address while moving, where each node in the network 100 has its own IP address. The EPC 108 is designed to work with legacy wireless networks. The EPC 108 is also designed to separate the control plane (i.e., signaling) and user plane (i.e., traffic) in the core network architecture, allowing for greater flexibility in implementation and independent scalability of control and user data functions.
[0053] The architecture of the EPC 108, which is for packet data, is shown in more detail in Figure 1c. The EPC 108 includes a Serving Gateway (S-GW) 110, a PDN Gateway (P-GW) 112, a Mobility Management Entity ("MME") 114, a Home Subscriber Server ("HSS") 116 (the subscriber database for the EPC 108), and a Policy Control and Charging Rules Function ("PCRF") 118. Some of these (such as the S-GW, P-GW, MME, and HSS) are often combined into a node according to the manufacturer's implementation.
[0054] The S-GW 110 functions as an IP packet data router and is the user equipment's bearer path anchor in the EPC 108. Thus, as the user equipment moves from one eNodeB 106 to another during mobility operation, the S-GW 110 remains the same, and the bearer path towards the EUTRAN 102 is switched to talk to the new eNodeB 106 serving the user equipment 104. If the user equipment 104 moves to the domain of another S-GW 110, the MME 114 forwards all of the user equipment's bearer paths to the new S-GW. The S-GW 110 establishes bearer paths for the user equipment to one or more P-GWs 112. When downstream data is received for an idle user equipment, the S-GW 110 buffers the downstream packets and requests the MME 114 to identify and re-establish the bearer path to and through the EUTRAN 102.
[0055] The P-GW 112 is the gateway between the EPC 108 (and thus the user equipment 104 and EUTRAN 102) and the PDN 101 (shown in FIG. 1a). The P-GW 112 acts as a router for user traffic and performs functions on behalf of the user equipment. These include IP address allocation for the user equipment, packet filtering of downstream user traffic to ensure it is placed on the appropriate bearer path, and enabling downstream QoS, including data rate. Depending on the services a subscriber is using, there may be multiple user data bearer paths between the user equipment 104 and the P-GW 112. A subscriber can use services on PDNs served by different P-GWs. In this case, the user equipment has at least one bearer path established to each P-GW 112. During handover of a user equipment from one eNodeB to another, if the S-GW 110 also changes, the bearer path from the P-GW 112 is switched to the new S-GW.
[0056] The MME 114 manages the user equipment 104 in the EPC 108 (including managing subscriber authentication, maintaining context for authenticated user equipment 104, establishing a data bearer path in the network for user traffic, and keeping track of the location of idle mobiles that have not detached from the network). For idle user equipment 104 that needs to reconnect to the access network to receive downstream data, the MME 114 initiates paging to identify the user equipment and reestablish a bearer path to and through the EUTRAN 102. The MME 114 for a particular user equipment 104 is selected by the eNodeB 106 from which the user equipment 104 initiates system access. The MME is typically part of a collection of MMEs in the EPC 108 for load sharing and redundancy purposes. In establishing a user's data bearer path, the MME 114 is responsible for selecting the P-GW 112 and S-GW 110 that constitute the ends of the data path through the EPC 108.
[0057] The PCRF 118 is responsible for policy control decision making and controlling the flow-based charging functionality in the Policy Control Activation Function ("PCEF") residing in the P-GW 110. The PCRF 118 provides QoS authorization (QoS Class Identifier ("QCI") and bitrate) that determines how a particular data flow is treated in the PCEF and ensures that this is in line with the user's subscription profile.
[0058] As previously mentioned, IP services 119 are provided by PDN 101 (shown in FIG. 1a).
[0059] 1d shows an example configuration of an eNodeB 106. The eNodeB 106 may include at least one "remote radio head" ("RRH") 132 (typically, there may be three RRHs 132) and a baseband unit ("BBU") 134. The RRHs 132 may be connected to an antenna 136. The RRHs 132 and BBU 134 may be connected using an optical interface compliant with the "common public radio interface" ("CPRI") / "enhanced CPRI" ("eCPRI") 142 specification, using an RRH-specific custom control and user plane framing method or an O-RAN Alliance-compliant control and user plane framing method. The operation of the eNodeB 106 may be characterized using the following standard parameters (and specifications): radio frequency band (Band 4, Band 9, Band 17, etc.), bandwidth (5, 10, 15, 20 MHz), access scheme (downlink: OFDMA; uplink: SC-OFDMA), antenna technology (single-user and multi-user MIMO; uplink: single-user and multi-user MIMO), number of sectors (up to 6), maximum transmission rate (downlink: 150 Mb / s; uplink: 50 Mb / s), S1 / X2 interface (1000Base-SX, 1000Base-T), and mobile environment (up to 350 km / h). The BBU 134 may be responsible for digital baseband signal processing, S1 line termination, X2 line termination, call processing, and monitoring and control processing. IP packets received from the EPC 108 (not shown in FIG. 1d) may be modulated into digital baseband signals and transmitted to the RRH 132. Conversely, digital baseband signals received from the RRH 132 may be demodulated into IP packets for transmission to the EPC 108.
[0060] The RRH 132 can transmit and receive wireless signals using an antenna 136. The RRH 132 can convert digital baseband signals from the BBU 134 to radio frequency ("RF") signals (using a converter ("CONV") 140) and can power amplify (using an amplifier ("AMP") 138) for transmission to the user equipment 104 (not shown in FIG. 1d). Conversely, RF signals received from the user equipment 104 are amplified (using AMP 138) and converted (using CONV 140) to digital baseband signals for transmission to the BBU 134.
[0061] Figure 2 shows additional details of an exemplary eNodeB 106. The eNodeB 106 includes multiple layers: "LTE Layer 1" 202, "LTE Layer 2" 204, and "LTE Layer 3" 206. LTE Layer 1 includes the physical layer ("PHY"). LTE Layer 2 includes media access control ("MAC"), radio link control ("RLC"), and packet data convergence protocol ("PDCP"). LTE Layer 3 includes various functions and protocols, including radio resource control ("RRC"), dynamic resource allocation, eNodeB measurement configuration and provisioning, radio admission control, connection mobility control, and radio resource management ("RRM"). The RLC protocol is an "automatic repeat request" ("ARQ") fragmentation protocol used over the cellular air interface. The RRC protocol handles LTE Layer 3 control plane signaling between user equipment and the EUTRAN. The RRC includes functions for connection establishment and release, system information broadcast, radio bearer establishment / reconfiguration and release, RRC connection mobility procedures, paging notification and release, and outer loop power control. The PDCP performs IP header compression and decompression, user data transfer, and sequence number maintenance for radio bearers. The BBU 134 shown in FIG. 1d may include LTE layers L1-L3.
[0062] One of the primary functions of the eNodeB 106 is radio resource management, including scheduling of both uplink and downlink air interface resources for the user equipment 104, control of bearer resources, and admission control. As an agent for the EPC 108, the eNodeB 106 is responsible for forwarding paging messages used to identify idle mobiles. The eNodeB 106 also communicates over-the-air common control channel information, header compression, encryption and decryption of over-the-air user data, and establishes handover reporting and trigger criteria. As previously mentioned, the eNodeB 106 can cooperate with other eNodeBs 106 over the X2 interface for handover and interference management purposes. The eNodeB 106 communicates with the MME of the EPC via the S1-MME interface and with the S-GW over the S1-U interface. Furthermore, the eNodeB 106 exchanges user data with the S-GW over the S1-U interface. The eNodeBs 106 and the EPC 108 have a many-to-many relationship to support load sharing and redundancy among the MMEs and S-GWs. The eNodeB 106 selects an MME from a group of MMEs so that the load can be shared by multiple MMEs to avoid congestion. II. 5G NR wireless communication network
[0063] In some implementations, the current subject matter relates to 5G new radio ("NR") communication systems. 5G NR is the next communication standard after the 4G / IMT-Advanced standard. 5G networks offer higher capacity than current 4G, allowing more mobile broadband users per unit area and enabling consumption of higher and / or unlimited data volumes in gigabytes per month and per user. This may enable users to stream high-resolution media using their mobile devices much of each day (even when it is not possible to do the same with Wi-Fi networks). 5G networks have improved support for device-to-device communication, lower cost, lower latency than 4G equipment, and lower battery consumption. Such networks have data rates of tens of megabits per second for many users, data rates of 100 Mb / s for metropolitan areas, simultaneous 1 Gb / s for users in a restricted area (e.g., an office floor), many simultaneous connections for wireless sensor networks, improved spectral efficiency, improved coverage, improved signaling efficiency, and 1-10 ms latency, a reduced latency compared to existing systems.
[0064] 3 illustrates an exemplary virtual radio access network 300. The network 300 can provide communication between various components, including a base station (e.g., eNodeB, gNodeB) 301, radio equipment 303, aggregation unit 302, digital unit 304, and wireless device 306. The components in the system 300 can be communicatively coupled to the core using backhaul links 305. The aggregation unit ("CU") 302 can be communicatively coupled to the distributed unit ("DU") 304 using midhaul connections 308. The radio frequency ("RU") component 306 can be communicatively coupled to the DU 304 using fronthaul connections 310.
[0065] In some implementations, the CU 302 can provide intelligent communication capabilities to one or more DU units 304. The units 302, 304 can include one or more base stations, macro base stations, micro base stations, "remote radio heads," etc., and / or any combination thereof.
[0066] In a lower layer split architecture environment, the CPRI bandwidth requirements for NR can be several hundred Gb / s. CPRI compression can be implemented in the DU and RU (shown in Figure 3). In 5G communication systems, compressed CPRI over Ethernet frames is denoted as eCPRI and is the recommended fronthaul network. The architecture can enable fronthaul / midhaul standardization, which can include fronthaul with higher layer splits (e.g., "Option 2" or "Option 3-1" (higher / lower RLC split architecture)) and L1 split architectures ("Option 7").
[0067] In some implementations, a lower layer split architecture (e.g., "Option 7") may include a receiver in the uplink, joint processing across multiple transmission points (TPs) for both DL / UL, and transport bandwidth and latency requirements for ease of deployment. Additionally, the subject lower layer split architecture may include a split between cell-level and user-level processing, which may include cell-level processing in a remote unit ("RU") and user-level processing in a DU. Additionally, using the subject lower layer split architecture, frequency-domain samples may be transported over the Ethernet fronthaul, which may be compressed to reduce fronthaul bandwidth.
[0068] 4 illustrates an example communication system 400 that can implement 5G technology and provide users with access to higher frequency bands (e.g., above 10 GHz). The system 400 can include a macrocell 402 and small cells 404, 406.
[0069] The mobile device 408 may be configured to communicate with one or more of the small cells 404, 406. The system 400 may enable separation of the control plane (C-plane) and user plane (U-plane) between the macrocell 402 and the small cells 404, 406 using different frequency bands. In particular, the small cells 404, 406 may be configured to utilize higher frequency bands when communicating with the mobile device 408. The macrocell 402 may utilize existing cellular bands for C-plane communications. The mobile device 408 may be communicatively coupled via the U-plane 412, where the small cell (e.g., the small cell 406) may provide higher data rates and more flexible, cost-effective, and energy-efficient operation. The macrocell 402 may maintain good connectivity and mobility via the C-plane 410. Furthermore, in some cases, LTE and NR may be transmitted on the same frequency.
[0070] FIG. 5a illustrates an exemplary 5G wireless communication system 500 according to some implementations of the present subject matter. The system 500 may be configured to have a lower layer split architecture in accordance with "Option 7-2." The system 500 may include a core network 502 (e.g., 5G Core) and one or more gNodeBs (or gNBs), which may have an aggregation unit (gNB-CU). The gNB-CU may be logically separated into a control plane portion (gNB-CU-CP) 504 and one or more user plane portions (gNB-CU-UP) 506. The control plane portion 504 and the user plane portion 506 may be configured to be communicatively coupled using an E1 communication interface 514 (defined in the 3GPP standard). The control plane portion 504 may be configured to be responsible for executing the RRC and PDCP protocols of the radio stack.
[0071] The control plane and user plane portions 504, 506 of the aggregation unit of the gNB may be configured to be communicatively coupled to one or more distributed units (DUs) 508, 510 according to a higher layer split architecture. The distributed units 508, 510 may be configured to execute the upper RLC, MAC, and PHY layer protocols of the radio stack. The control plane portion 504 may be configured to be communicatively coupled to the distributed units 508, 510 using an F1-C communication interface 516, and the user plane portion 506 may be configured to be communicatively coupled to the distributed units 508, 510 using an F1-U communication interface 518. The distributed units 508, 510 may be coupled to one or more remote radio units (RUs) 512 via a fronthaul network 520 (which may include one of a switch, a link, etc.) and may communicate with one or more user equipment (not shown in FIG. 5a). The remote radio unit 512 may be configured to execute the lower portions of the PHY layer protocol and provide antenna capabilities to the remote unit for communication with user equipment (similar to the discussion above with respect to FIGS. 1a-2).
[0072] Figure 5b shows an example layer architecture 530 for a split gNB. The architecture 530, which may be configured as a virtualized and disaggregated radio access network (RAN) architecture (layers L1, L2, L3 and radio processing may be virtualized and disaggregated in the aggregation unit, distributed unit, and radio unit), may be implemented in the communication system 500 shown in Figure 5a. As shown in Figure 5b, the gNB-DU 508 may be communicatively coupled to the gNB-CU-CP control plane portion 504 (also shown in Figure 5a) and the gNB-CU-UP user plane portion 506. Each of the components 504, 506, 508 may be configured to include one or more layers.
[0073] The gNB-DU 508 may include RLC, MAC, and PHY layers, as well as various communication sublayers. These may include an F1-Application Protocol (F1-AP) sublayer, a GPRS Tunneling Protocol (GTPU) sublayer, a Stream Control Transmission Protocol (SCTP) sublayer, a User Datagram Protocol (UDP) sublayer, and an Internet Protocol (IP) sublayer. As previously described, the distribution unit 508 may be communicatively coupled to the control plane portion 504 of the aggregation unit, which may include the F1-AP, SCTP, and IP sublayers, and the Radio Resource Control and PDCP Control (PDCP-C) sublayers. Furthermore, the distribution unit 508 may be communicatively coupled to the user plane portion 506 of the aggregation unit of the gNB. The user plane portion 506 may include the Service Data Adaptation Protocol (SDAP), PDCP User (PDCP-U), GTPU, UDP, and IP sublayers.
[0074] Figure 5c shows an example functional split in the gNB architecture shown in Figures 5a-b. As shown in Figure 5c, the gNB-DU 508 may be communicatively coupled to the gNB-CU-CP 504 and the GNB-CU-UP 506 using an F1-C communication interface. The gNB-CU-CP 504 and the GNB-CU-UP 506 may be communicatively coupled using an E1 communication interface. A higher portion of the PHY layer (or Layer 1) may be performed by the gNB-DU 508, and a lower portion of the PHY layer may be performed by the RU (not shown in Figure 5c). As shown in Figure 5c, the RRC and PDCP-C portions may be performed by the control plane portion 504, and the SDAP and PDCP-U portions may be performed by the user plane portion 506.
[0075] Some of the functions of the PHY layer in a 5G communication network may include error detection on transport channels and suggestion to higher layers, FEC encoding / decoding of transport channels, hybrid ARQ soft combining, rate matching of coded transport channels to physical channels, mapping of coded transport channels onto physical channels, power weighting of physical channels, modulation and demodulation of physical channels, frequency and time synchronization, radio characteristic measurements and suggestion to higher layers, MIMO antenna processing, digital and analog beamforming, RF processing, and other functions.
[0076] The MAC sublayer of Layer 2 may perform beam management, random access procedures, mapping between logical channels and transport channels, concatenation of multiple MAC service data units (SDUs) belonging to one logical channel into transport blocks (TBs), multiplexing / demultiplexing of SDUs belonging to logical channels to / from TBs delivered on transport channels to / from the physical layer, scheduling of reporting information, error correction via HARQ, priority handling between logical channels for one UE, priority handling between UEs via dynamic scheduling, transport format selection, and other functions. The RLC sublayer's functions may include forwarding upper layer packet data units (PDUs), error correction via ARQ, reordering of data PDUs, duplication and protocol error detection, reestablishment, etc. The PDCP sublayer may be responsible for forwarding user data, various functions during reestablishment procedures, retransmission of SDUs, discarding SDUs in the uplink, forwarding of control plane data, and others.
[0077] The RRC sublayer of Layer 3 may perform functions such as broadcasting system information to the NAS and AS, establishing, maintaining and releasing RRC connections, security, establishing, configuring, maintaining and releasing point-to-point radio bearers, mobility functions, reporting, and other functions. III. Secure L1 / L2-centric inter-cell mobility implementation
[0078] Some companies in RAN2 have expressed concerns about the security of low layer mobility (LLM) execution. MAC Control Element (CE) messages in the downlink issued by the serving gNB-DU are unsecured (unencrypted), which could expose them to security breaches. For example, a specific MAC CE is associated with the execution of a mobility event, allowing a user's route to be tracked or their location to be traced. During a handover (HO), in which one or more services of a UE are handed over from a serving cell (also referred to herein as a "source cell") to a target cell, the serving gNB-DU may send a MAC CE to the UE that includes the target cell's physical cell identifier (PCI) or other identifier that identifies the target cell to the UE. Because the MAC CE message to the UE is unsecured, information about the UE and / or the target cell is at risk of security breaches.
[0079] Layer 1 / Layer 2 Triggered Mobility (LTM) is an updated item for LLM. RAN2 has agreed on the definition of LTM. Generally, LTM is a mobility procedure that allows the network to switch a UE from a source cell to a target cell without necessarily requiring a "sync" reconfiguration. In particular, the network can suggest in L2 signaling (e.g., messages such as MAC CE) beams belonging to LTM candidate cells on which the UE should perform the LTM cell switch procedure based on received L1 measurement results. The UE is provided with at least one LTM candidate cell configuration by the network prior to performing the LTM cell switch procedure.
[0080] In some implementations of the present subject matter, the gNB-CU-CP is configured to generate indices for all cells configured as candidates for L1 / L2-centric inter-cell mobility targets. Currently, according to the 3GPP standard (RAN2 agreement), up to eight LTM target cells can be prepared for a given UE. The gNB-CU-CP is configured to store the mapping between the target cell PCI and the target cell index for future use. Thus, L1 / L2-centric inter-cell mobility may be performed without compromising security.
[0081] In some implementations of the current subject matter, a base station (e.g., a next generation RAN (NG-RAN) node such as a gNodeB, eNodeB, or gNodeB in FIG. 5a) of a wireless communication system (e.g., a 5G wireless communication system, a 6G, or later generation wireless communication system, etc.) may have a segmented architecture in which the base station includes one gNB-CU-CP (e.g., gNB-CU-CP 504 in FIGS. 5a-5c) and multiple CU-UPs (e.g., gNB-CU-UP 506 in FIGS. 5a-5c) and gNB-DUs (e.g., gNB-DUs 508, 510 in FIGS. 5a-5c). The base station may be configured to perform secure L1 / L2-centric inter-cell mobility when a UE is handed off from one cell of the base station (a serving cell) to another cell of the base station (a target cell).
[0082] FIG. 6a illustrates an exemplary system 600 configured to perform secure L1 / L2-centric inter-cell mobility. The base station 602 in this illustrated implementation is a gNB configured to be in a 5G wireless communication system similar to the previously described 5G wireless communication system 500 of FIG. 5a, although other base stations may be similarly configured and used in performing secure L1 / L2-centric inter-cell mobility. In the illustrated implementation of FIG. 6a, the base station 602 includes multiple CU-UPs 606a, 606b, and 606c. In this illustrated implementation, the base station 602 includes three CU-UPs 606a, 606b, and 606c, but may include multiple other CU-UPs. The CUs of the base station 602, including the multiple CU-UPs 606a, 606b, and 606c, are configured to be communicatively coupled to a core network (not shown in FIG. 6a), such as the 5G 5G communication system 502 of FIG. 5a.
[0083] The CU of the base station 602 also includes a CU-CP 604 that is configured to be communicatively coupled to the user plane portions 606a, 606b, 606c of the CU using an E1 communication interface 614. In this illustrated implementation, the E1 interface 614 includes three communication links to reflect the fact that there are three CU-UPs 606a, 606b, 606c with which the CU-CP 604 may be configured to communicate.
[0084] The base station 602 also includes multiple DUs 608, 610. In this illustrated implementation, the base station 602 includes two DUs 608, 610, but may include multiple other DUs. The CU-CP 604 is configured to be communicatively coupled to the DUs 608, 610 using an F1-C communication interface 616. The CU-UPs 606a, 606b, 606c are configured to be communicatively coupled to the DUs 608, 610 using an F1-U communication interface 618. In this illustrated implementation, the F1-U interface 618 associated with each of the DUs 608, 610 includes three communication links to reflect the three CU-UPs 606a, 606b, 606c with which each DU 608, 610 may be configured to communicate.
[0085] The base station 602 also includes multiple RUs 612. In this illustrated implementation, the base station 602 includes five RUs 612, but may include other multiple RUs. The RUs 612 are configured to be communicatively coupled to the DUs 608, 610 via a fronthaul network 620. In addition, each of the RUs 612 is configured to be communicatively coupled to one or more UEs 622. In this illustrated implementation, two of the RUs 612 are shown communicatively coupled to one UE 622, two of the RUs 612 are shown communicatively coupled to two UEs 622, and one RU 612 is shown communicatively coupled to three UEs 622, but each of the RUs 612 may be coupled to other numbers of UEs, the same or different from any of the other RUs 612.
[0086] Secure L1 / L2-centric inter-cell mobility execution can be configured to occur when one of the UEs communicatively coupled to the base station 602 is handed off from one of the DUs 608, 610 of the base station 602 to another of the DUs 608, 610 of the same base station 602. One of the DUs 608, 610 currently providing service to the UE 622 is referred to as the "serving DU" because it is currently providing service to (e.g., currently serving) the UE 622. The other of the DUs 608, 610 to which the UE's service is handed off is referred to as the "target DU" because it is targeted to provide service to the UE 622.
[0087] A system in which secure L1 / L2-centric inter-cell mobility may be configured to occur is further described with respect to Figure 6b. Figure 6b illustrates the CU-CP 604 and CU-UPs 606a, 606b, 606b of Figure 6a, but in the illustrated implementation of Figure 6b, the base station 602 includes more than two DUs. In the illustrated implementation of Figure 6b, the base station 602 includes 66 DUs. Three of the DUs 628a, 628b, and 628c are macro cells (labeled macro1, macro2, and macro3 in FIG. 6b), and the 63 DUs 626 are small cells (nine of which are labeled gNB-DU10, gNB-DU20, gNB-DU30, gNB-DU40, gNB-DU50, gNB-DU60, gNB-DU70, gNB-DU80, and gNB-DU90 in FIG. 6b). The base station 602 may include other numbers of macro cells and / or other numbers of small cells. The 21 small cell DUs 626, including the "macro1" DU 628a, the "macro2" DU 628b, and gNB-DU10, gNB-DU20, and gNB-DU30, are configured to be served by the first CU-UP 606a (labeled CU-UP1 in FIG. 6b). The 21 small cell DUs 626, including the "macro1" DU 628a, the "macro2" DU 628b, the "macro3" DU 628c, and gNB-DU40, gNB-DU50, and gNB-DU60, are configured to be served by the second CU-UP 606b (labeled CU-UP2 in FIG. 6b). The 21 small cell DUs 626, including "macro2" DU 628b, "macro3" DU 628c, and gNB-DU70, gNB-DU80, and gNB-DU90, are configured to be served by the third CU-UP 606c (labeled CU-UP3 in FIG. 6b).
[0088] In the implementation shown in Figure 6b, each CU-UP 606a, 606b, 606c serves a subset of the DUs 626, 628a, 628, 628c for all services, although a CU-UP can serve all DUs of the base station for one service (e.g., enhanced mobile broadband (eMBB)) while serving a subset of DUs for another service (e.g., vehicle-to-everything (V2X) or ultra-reliable low latency communication (URLLC)).
[0089] FIG. 7 illustrates an exemplary method 700 according to some implementations of the present subject matter. The method 700 of FIG. 7 will be described with reference to the exemplary system 800 illustrated in FIG. 8, but may similarly be implemented with other systems, such as the system 100 of FIGS. 1a-1c and 2, the system 400 of FIG. 4, the system 500 of FIG. 5a, and the systems of FIGS. 6a and 6b. The system 800 of FIG. 8 is a 5G system, but as previously mentioned, performing secure L1 / L2-centric inter-cell mobility as described herein may also be performed in other types of wireless communication systems, such as an LTE wireless communication system or a 6G or later generation wireless communication system. While various elements in FIG. 8 are numbered as sequential steps, such numbering is not intended to suggest that these numbered steps may be performed solely in this sequential order in the system 800. One or more additional steps may be present before and / or after any one or more sequentially numbered steps illustrated in FIG. 8.
[0090] In the system 800, a UE 802 (e.g., UE 104 of FIGS. 1a-1c, UE 622 of FIG. 6a, etc.) is configured 810 with LTM with one or more target cells in one or more DUs 804, 806 (e.g., DU 508 of FIGS. 5a-5c, DU 510 of FIG. 5a, DU 608 of FIG. 6a, DU 610 of FIG. 6a, DU 626 of FIG. 6b, DU 628a, 628b, 628c of FIG. 6b, etc.) of a base station, e.g., a gNB (e.g., gNodeB of FIG. 5a, gNodeB 602 of FIGS. 6a and 6b, etc.). For simplicity of explanation, the system 800 is shown in FIG. 8 with a base station including one UE 802 and two DUs 804, 806 communicatively coupled with the base station, although multiple UEs can be communicatively coupled with the base station and / or the base station may include more than two DUs. The base station of the system 800 also includes a CU including a CU-CP 808 (e.g., gNB-CU-CP 504 of FIGS. 5a-5c, CU-CP 604 of FIGS. 6a and 6b, etc.) and one or more CU-UPs (e.g., gNB-CU-UP 506 of FIGS. 5a-5c, CU-UPs 606a, 606b, 606c of FIGS. 6a and 6b, etc.) (not shown in FIG. 8), and multiple RUs (e.g., RU 512 of FIG. 5a, RU 612 of FIG. 6a, etc.) (not shown in FIG. 8). The UE 802 is currently served by the serving DU 804. In addition, the base station of FIG. 8 is communicatively coupled to a core network (e.g., EPC 108 of FIGS. 1a-1c and 2, 5GC 502 of FIG. 5a, etc.) (not shown in FIG. 8).
[0091] In response to determining 702 that a serving cell change should occur, the serving DU 804 notifies 704 the UE 802 of the serving cell change. Notifying 704 the UE 802 may include the serving DU 804 sending a serving cell change command, such as a MAC CE, to the UE 802.
[0092] Also, in response to determining (702) that a cell service change should occur, the serving DU 804 notifies (704) the CU-CP 808 that a serving cell change has occurred for the UE 802. In this manner, the notification (704) may identify the UE 802 to the CU-CP 808 by an identifier known to the serving DU 804, such as an identifier according to a 3GPP standard, that uniquely identifies the UE 802 to the CU-CP 808. The notification (704) to the CU-CP 808 may include the serving DU 804 sending a serving cell change notification message to the CU-CP 808 using the F1 communication interface. The serving cell change notification message may include a cell identifier (ID) that uniquely identifies the UE 802 that has undergone the serving cell change.
[0093] In response to receiving the serving cell change command from the serving DU 804, the UE 802 sends a radio resource control (RRC) reconfiguration confirm message to the CU-CP 808. The CU-CP 808 recognizes from the RRC reconfiguration confirm message that the UE 802, which is uniquely identified to the CU-CP 808 by the serving DU 804, has confirmed the completion (success) of the serving cell change.
[0094] Also, in response to receiving the Layer 3 RRC measurement configuration, the UE 802 sends 812 an RRC measurement report to the CU-CP 808 in accordance with 3GPP standards. In accordance with 3GPP standards, the RRC measurement report may include Layer 3 (L3) measurement results that may be analyzed by the CU-CP 808 in making resource control decisions, which may include a decision to prepare at least one target DU cell for LTM from the target DU (also referred to herein as a "neighbor DU") 806 to prepare to serve the UE 802 for at least one service on behalf of the serving DU 804.
[0095] In response to determining to prepare at least one target cell for LTM, the CU-CP 808 prepares the at least one target cell for LTM (706). As shown in FIG. 8, in this illustrated embodiment, each of the at least one target cell is an inter-DU target cell, for example, such that the same CU (e.g., the CU including the CU-CP 808) serves each DU 804, 806 (part of a different DU from the serving DU 804, but the same base station as the serving DU 804). Also, in this illustrated embodiment, because there are only two gNB-DUs, the at least one target cell includes only the target DU 806. However, as described above, a base station may include more than two target cells. Currently, according to the 3GPP standard, up to eight LTM target cells can be prepared for a given UE.
[0096] Preparing 706 the at least one target cell for LTM may include notifying 814 the at least one target DU 806 that the at least one target DU 806 may be notified later to begin serving the UE 802 for at least one service, thereby allowing the target DU 806 to reserve necessary resources for the UE 802. As shown in FIG. 8 , preparing 706 the at least one target cell, which in this illustrated implementation is only the target DU 806, may include the CU-CP 808 sending 814 a UE Context Setup Request message to the target DU 806 using an F1 communication interface according to the 3GPP standard.
[0097] In response to receiving the UE context setup request message from the CU-CP 808, the target DU 806 prepares each of one or more target cells for LTM (e.g., reserves necessary resources for the UE 802) and notifies the CU-CP 808 that the preparation (828) is complete. In this illustrated implementation, the at least one target cell includes only the target DU 806 preparing the target cell. In an inter-DU LTM scenario, one or more of the target cells prepared for at least one LTM belong to a DU different from the serving DU 806. For example, with reference to the system of FIG. 6b, the serving DU may be the small cell 626 of the "macro1" DU 628a, and one or more of the target cells may be one or more small cells 626 of the "macro2" DU 628b and / or the "macro3" DU 628c. As shown in Figure 8, the notification to the CU-CP 808 may include the target DU 806 sending (816) a UE context setup response message to the CU-CP 808 using an F1 communication interface according to the 3GPP standard. Also as shown in Figure 8, the UE context setup response message includes integrated cell group configuration information for one or more target cells prepared by the target DU 806. The integrated cell group configuration information includes PCI (or other unique identifier) for each of the one or more prepared target cells.
[0098] In response to being notified by the target DU 806 that at least one target cell has been prepared for LTM, the CU-CP 808 maps each of the at least one prepared target cell to an index (708, 818). Mapping (708) includes the CU-CP 808 generating (818) indices for all target cells configured for the UE 802 as candidates for L1 / L2-centric inter-cell mobility targets, as shown in FIG. 8. The maximum number of target cells that may be prepared for the UE 802 is eight according to current 3GPP standards. Thus, the CU-CP 808 maps (708) a maximum of eight target cells under current 3GPP standards.
[0099] Mapping (708, 818) the at least one target cell includes correlating each of the at least one target cell to an index. As described above, the CU-CP 808 is informed by the target DU 806 of the PCI (or other unique identifier) for each of the one or more prepared target cells. In this manner, the CU-CP 808 can map each of the one or more target cells by its PCI (or other unique identifier) to an index such that each of the one or more prepared target cells can be uniquely identified by its index. The CU-CP 808 stores the mapping between the target cell PCI (or other unique identifier) and the target cell index for future use, for example, by storing the mapping as a table in memory.
[0100] In some implementations, the index may be a numeric value such that each of one or more target cells is associated with a unique numeric value by a PCI (or other unique identifier). According to current 3GPP standards, the maximum number of target cells provisioned for a UE 802 is eight, so eight different numeric values (e.g., integers 1-8, integers 0-7, even numbers 2-16, or other numeric values) may be used for the index. For example, in an implementation where three target cells are provisioned for LTM, the mapping (708, 818) may include correlating the first PCI of the first target to index 1, the second PCI of the second target to index 2, and the third PCI of the third target to index 3.
[0101] In some implementations, the index may be an alphabetic value such that each of one or more target cells is associated with a unique alphabetic value by a PCI (or other unique identifier). According to current 3GPP standards, the maximum number of target cells provisioned for a UE 802 is eight, so eight different alphabetic values (e.g., letters AH, terms 1-8, or other alphabetic values) may be used for the index. For example, in an implementation where three target cells are provisioned for LTM, the mapping (708, 818) may include correlating a first PCI of a first target to index A, a second PCI of a second target to index B, and a third PCI of a third target to index C.
[0102] In some implementations, the index may be an alphanumeric value such that each of one or more target cells is associated with a unique alphanumeric value by a PCI (or other unique identifier). According to current 3GPP standards, the maximum number of target cells provisioned for a UE 802 is eight, so eight different alphanumeric values (e.g., cell1-cell8 terms, C1-C8 terms, or other alphanumeric values) may be used for the index. For example, in an implementation where three target cells are provisioned for LTM, the mapping (708, 818) may include correlating a first PCI of a first target to index "cell1," correlating a second PCI of a second target to index "cell2," and correlating a third PCI of a third target to index "cell3."
[0103] The CU-CP 808 can generate a mapping for each of a plurality of UEs, where the UE 802 is one of the plurality of UEs. In this manner, multiple mappings may be stored simultaneously. Because each UE of the plurality of UEs has its own mapping generated such that different UEs may have different LTM target cell candidates, the same target cell may be associated with different indices in different mappings (e.g., associated with index A in the first mapping for a first UE, associated with index D in the second mapping for a second UE, associated with index 3 in the first mapping for the first UE, and associated with index 5 in the second mapping for the second UE, etc.). Because each mapping is associated with and used in relation to a specific UE, different indices in different mappings for the same PCI do not cause confusion for the CU-CP 808, the serving DU 804, the target DU 806, or the plurality of UEs.
[0104] After the mapping (708, 818) is performed, the CU-CP 808 notifies the serving DU 804 of the mapping (708, 818) and at least one target cell prepared for LTM (710). Thus, the serving DU 804 recognizes each of the prepared target cells by a PCI (or other unique identifier) and an index. As shown in FIG. 8, notifying the serving DU 804 (710) may include the CU-CP 808 sending a UE context modification request message to the serving DU 804 (820) using the F1 communication interface. Also shown in FIG. 8, the UE context modification request message may include, for example, as an information element (IE), a mapping correlating the PCI (or other unique identifier) of each of the prepared target cells to an index. In this manner, the serving DU 804 securely receives the identity of each of one or more target cells that are configured as potential L1 / L2-centric inter-cell mobility targets for the UE 802.
[0105] In response to being notified of at least one LTM-prepared target DU cell (710), the serving cell 804 stores received information about the at least one LTM target cell (e.g., stores a mapping). Also, in response to being notified of at least one target DU (710), the serving cell 804 sends a UE context modification response message to the CU-CP 808 using the F1 communication interface (822). As shown in FIG. 8, the UE context modification response message may include integrated cell group configuration information for each of the one or more target cells identified for the UE 802 by the CU-CP 808. The UE context modification request message and the UE context modification response message are each defined by 3GPP. In this manner, the serving DU 804 can receive information about the at least one target cell from the CU-CP 808 and acknowledge the information to the CU-CP 808 using a message already sent for HO according to the 3GPP standard.
[0106] In response to receiving the UE context modification response message, the CU-CP 808 transmits 824 an RRC reconfiguration message to the UE 802 in accordance with the 3GPP standard. Also shown in FIG. 8 , the RRC reconfiguration message includes LTM target cell configuration information (e.g., provided by the target DU 806 to the CU-CP 808 in the transmitted 830 UE context setup response message) and includes an index generated by the CU-CP 808 for one or more target cells configured as L1 / L2-centric inter-cell mobility target candidates for the UE 802. Thus, the UE 802 is informed 712 of the LTM target cell configuration information and index by the CU-CP 808. Furthermore, because the index is transmitted 824 to the UE 802 in a secure message, the UE 802 securely receives the respective identities of one or more target cells configured as L1 / L2-centric inter-cell mobility target candidates for the UE 802.
[0107] In response to receiving the target cell configuration in the RRC reconfiguration message, the UE 802 sends 826 an L1 measurement report according to the 3GPP standard to the serving DU 804. The L1 measurement report provides the serving DU 804 with UE measured radio condition information of the configured target cell(s).
[0108] In response to receiving the L1 measurement report transmitted (826) from the UE 802, the serving cell 804 selects (714, 828) a target cell from among one or more LTM-prepared target cells identified for the serving DU 804. In this illustrated embodiment, the serving cell selection (714, 828) is simple (the serving DU 804 selects (714, 828) the target DU 806) because only one target cell (the target DU 806) is identified for the serving DU 804 by the CU-CP 808 as a target cell prepared for LTM. If there are multiple target cells prepared for LTM that satisfy the handover criteria for the serving DU 804, the serving DU 804 is configured to select a target cell for handover.
[0109] In implementations where there are multiple target cells identified by the CU-CP 808 for the serving DU 804, the serving cell's target cell selection (714, 828) may include determining which of the multiple target cells has a radio quality above a predetermined radio quality threshold, as shown in FIG. 8. The predetermined radio quality threshold is determined by the UE's radio conditions, which the serving DU 804 receives in an L1 measurement report from the UE 802. In this manner, the serving DU 804 can take into account the specific needs of the particular UE 802 involved in the HO when selecting (710, 828) a target cell for HO. Additionally, the L1 measurement report sent (826) by the UE 802 to the serving DU 804 reports L1 measurement results, which may include reference signal received power (RSRP), as defined by 3GPP, for each of the multiple target cells (whose identities are known to the UE 802 because they were provided to the UE 802 by the CU-CP 808 in an RRC reconfiguration message). To this end, the serving DU 804 can analyze the L1 measurement reports received from the UE 802 to determine which of one or more of the multiple target cells has a radio quality above a predetermined radio quality threshold.
[0110] If only one of the target cells satisfies the UE's radio conditions, e.g., if the radio quality of only one target cell exceeds a predetermined radio quality threshold, the serving cell 804 selects the target cell (714, 828). If more than one of the target cells satisfies the UE's radio conditions, e.g., if the radio quality of each target cell exceeds a predetermined radio quality threshold, any one of these target cells can serve the UE's needs, randomly or according to other desired criteria.
[0111] Upon selecting (710, 828) a target cell (e.g., target DU 806 in the illustrated implementation of FIG. 8 ), the serving DU 804 triggers (716) a serving cell change to the selected (714, 828) target cell. The serving DU 804 identifies the selected (714, 828) target cell to the UE 802 by an index (e.g., a numeric, alphabetic value, etc.) associated with the selected (714, 828) target cell by the mapping performed by the CU-CP 808. In this manner, the serving DU 804 need never transmit the PCI (or other unique identifier) of the selected (714, 828) target cell to the UE 802 in an unsecure message or otherwise. Even in the event of a security breach in which the index of the selected (714, 828) target cell becomes known to an unauthorized party, security is improved because the index, as a value that does not uniquely identify the target cell or the UE 802 (except to an authorized party having the mapping), does not allow the user's route to be tracked or the user's location to be traced. As shown in FIG. 8, triggering 716 the serving cell change can include the serving DU 804 sending 844 a MAC CE to the UE 802 that includes a serving cell change command and identifies the selected (714, 828) target cell to the UE 802. In this way, the selected (714, 828) target cell can be identified to the UE 802 without compromising security, even if the MAC CE is an unsecure message.
[0112] Also, after selecting the target cell (710, 828), the serving DU 804 sends a serving cell change (SCC) notification to the CU-CP 808 via the F1 communication interface (832), identifying the target DU 806 as the new current serving cell for the UE 802 for at least one service, for example, by PCI (or other unique identifier).
[0113] The UE's receipt of the MAC CE indicates to the UE 802 that an LTM serving cell change (SCC) to the identified target cell for the UE 802 (e.g., the target DU 806 in the illustrated implementation of FIG. 8) should be performed. Thus, in response to receiving the MAC CE from the serving cell 804, the UE 802 initiates HO to the target cell (718). The HO may be performed in accordance with 3GPP standards. The UE uses the index received from the serving DU 804 to determine the identity of the target cell for HO. Because the UE 802 has received the mapping from the CU-CP 808, the UE 802 can search the index received from the serving DU 804 in the mapping to determine the target cell corresponding to the index and identify the target cell for HO. As shown in FIG. 8a, the UE 802 initiating HO to the target cell (718) may include the UE 802 accessing the target cell in a RACH procedure for RACH-based HO (834), which may be performed in accordance with 3GPP standards. As shown in FIG. 8, the UE accessing the target cell (834) may include the UE 802 transmitting a preamble to the target DU 806.
[0114] Also, in response to receiving the MAC CE from the serving cell 804, the UE 802 sends 840 an RRC reconfiguration confirm message to the CU-CP 808. In this manner, the CU-CP 808 receives confirmation from both the UE 802 (via the RRC reconfiguration confirm message indicating successful RRC reconfiguration at the UE 802) and the serving DU 804 (via the serving cell change notification that the target DU 806 is now serving the UE 802 for at least one service handed over from the serving DU 804).
[0115] In response to receiving the SCC notification from the serving DU 804, the CU-CP 808 notifies the target DU 806 of the mapping generated by the CU-CP 808 for one or more target cells configured as L1 / L2-centric inter-cell mobility target candidates for the UE 802 (720). In this manner, the target DU 806 securely receives the identity information of each of the one or more target cells configured as L1 / L2-centric inter-cell mobility target candidates for the UE 802. The target DU 806 can use the mapping in the case where a HO for the UE 802 occurs from the target DU 806, similar to that described above with respect to the serving DU 804 handing over to the target DU 806. As shown in FIG. 8, the notification (820) may include the CU-CP 808 sending a UE context modification request message to the target DU 806 using the F1 communication interface (836). 8, the UE context modification request message to the target DU 806 may include the mapping, for example, as an information element (IE). In response to receiving the UE context modification request message from the CU-CP 808, the target DU 806 sends a UE context modification response message to the CU-CP 808 using the F1 communication interface (838).
[0116] After the CU-CP 808 generates (708, 818) a mapping for one or more target cells configured as L1 / L2-centric inter-cell mobility target candidates for the UE 802, the CU-CP 808 is configured to update the mapping. Updating the mapping allows the mapping to be dynamic and a real-time reflection of the target cells that are LTM candidates for HO for the UE 802. The CU-CP 808 is configured to provide the updated mapping to the UE 802 in a secure message similar to that described above for the CU-CP 808 sending (824) the mapping to the UE 802. The CU-CP 808 is also configured to provide the updated mapping to the serving DU 804 (which may also be the target DU 806 if the mapping was updated after the HO to the selected (714, 828) target cell has already occurred) in secure messages similar to those described above with respect to the CU-CP 808, which sends 820 the mapping to the serving DU 804 and sends 836 the mapping to the target DU 806. In this way, the UE 802 and the serving DU 804 (which may also be the target DU 806) can obtain the current mapping for the UE 802 if the HO for the UE 802 occurs after the mapping is updated.
[0117] The CU-CP 808 is configured to update the mapping for one or more target cells configured as potential L1 / L2-centric inter-cell mobility targets for the UE 802 in response to the occurrence of a triggering event. One example of a triggering event is a target cell being excluded for the UE 802, such as when the target cell goes offline or is excluded from a wireless communication system that includes the CU-CP 808. The CU-CP 808 is configured to remove an index for the excluded target cell from the mapping (e.g., remove an entry for the target cell from a table that correlates the target cell to an index).
[0118] Another example of a triggering event is a target cell being replaced for the UE 802, such as when a target cell that was not previously a candidate becomes a better candidate than a target cell currently identified as a candidate due to a change in the requirements of the UE 802. The CU-CP 808 is configured to remove an index for the replaced target cell from the mapping (e.g., remove the entry for that target cell from a table correlating target cells to indices and associating that index with the target cell that has instead been added as a candidate).
[0119] When the mapping is updated for one or more target cells configured as potential L1 / L2-centric inter-cell mobility targets for the UE 802, the indices may become non-sequential. Because the indices are still valid, PCI reassignment for the indices is not required to make them sequential. For example, if integers 1-8 are used for eight target cells and the target cell associated with index 2 is removed, the indices will no longer be sequential for the remaining target cells associated with indices 1, 3, 4, 5, 6, 7, and 8. If another target cell is added to this mapping, the added target cell may be associated with the now-used index 2.
[0120] FIG. 9 illustrates an example architecture of the gNB-CU-CP 808 of FIG. 8. As shown in FIG. 9, the gNB-CU-CP 808 includes a memory 900, a processor 902, a communicator 904, and a security management controller 906. The communicator 906 is configured to communicate internally among the internal hardware components of the CU-CP 808 and to communicate with external devices via one or more networks. The communicator 904 may include standard-specific electronic circuitry that enables wired or wireless communication. The security management controller 906 is configured to perform the mapping described above, and the memory 900 is configured to store the mapping. Multiple mappings (one mapping per UE) may be stored in the memory 900 such that the CU-CP 808 maintains mappings for multiple UEs. While FIG. 9 illustrates the hardware components of the gNB-CU-CP 808, other implementations of the CU-CP 808 are possible. For example, the gNB-CU-CP 808 may include fewer or more components.
[0121] In some implementations, the present subject matter may be configured to be implemented in a system 1000 as shown in FIG. 10. The system 1000 may include one or more of a processor 1010, a memory 1020, a storage device 1030, and an input / output device 1040. Each of the components 1010, 1020, 1030, and 1040 may be interconnected using a system bus 1050. The processor 1010 may be configured to process instructions for execution within the system 600. In some implementations, the processor 1010 may be a single-threaded processor. In alternative implementations, the processor 1010 may be a multi-threaded processor. The processor 1010 may be further configured to process instructions stored in the memory 1020 or the storage device 1030, including receiving or transmitting information through the input / output device 1040. The memory 1020 may store information within the system 1000. In some implementations, the memory 1020 may be a computer-readable medium. In alternative implementations, memory 1020 may be a volatile memory unit. Additionally, in some implementations, memory 1020 may be a non-volatile memory unit. Storage device 1030 may provide mass storage for system 1000. In some implementations, storage device 1030 may be a computer-readable medium. In alternative implementations, storage device 1030 may be a floppy disk device, a hard disk device, an optical disk device, a tape device, a non-volatile solid-state memory, or any other type of storage device. Input / output device 1040 may be configured to provide input / output operations for system 1000. In some implementations, input / output device 1040 may include a keyboard and / or a pointing device. In alternative implementations, input / output device 1040 may include a display unit for displaying a graphical user interface.
[0122] 11 illustrates an exemplary method 1100 for performing secure Layer 1 / Layer 2 (L1 / L2)-centric inter-cell mobility according to some implementations of the present subject matter. Method 1100 may be performed, for example, using the implementations shown and described with respect to FIGS.
[0123] The method 1100 includes mapping (1102) the PCI of at least one LTM target cell of at least one target DU of a base station that is a candidate for HO for the UE to an index, and securely transmitting (1104) the mapping from a CU CP of the base station to the UE and a serving DU of the base station that is currently serving the UE for at least one service.
[0124] In some implementations, the current subject may include one or more of the following optional features:
[0125] In some implementations, the index for each of the at least one LTM target cells may be unique in the mapping such that each index is uniquely associated with one of the at least one LTM target cells by the PCI.
[0126] In some implementations, the method may also include securely transmitting the mapping from the CU-CP to a target DU that includes one of the at least one LTM target cell selected for HO.
[0127] In some implementations, the mapping may be sent to the UE in a radio resource control (RRC) reconfiguration message, and the mapping may be sent to the serving DU in an F1 UE context modification request message.
[0128] In some implementations, the method may also include updating the mapping in response to at least one of one of the at least one LTM target cells being excluded for the UE and one of the at least one LTM target cells being replaced for the UE, and securely transmitting the updated mapping from the CU CP to the UE and the serving DU.
[0129] In some implementations, the method may also include mapping PCIs of at least one LTM target cell of at least one target DU that is a candidate for HO for the second UE to an index such that a second mapping is generated, and securely transmitting the second mapping from the CU CP to the second UE.
[0130] In some implementations, the serving DU may use the index received from the CU-CP when sending the LTM HO command to the UE.
[0131] In some implementations, each index may be one of a number, an alphabet, and an alphanumeric.
[0132] In some implementations, the method may also include storing the mapping in at least one non-transitory storage medium.
[0133] In some implementations, the base station may include a Next Generation Radio Access Network (NG-RAN) node, which may further include a gNodeB or an ng-eNodeB.
[0134] In some implementations, a base station may include at least one processor and at least one non-transitory storage medium, and a CU-CP may include at least one processor and at least one non-transitory storage medium.
[0135] The systems and methods disclosed herein may be embodied in various forms, including, for example, a data processor such as a computer including a database, digital electronic circuitry, firmware, software, or any combination thereof. Furthermore, the above-described features and other aspects and principles of the disclosed implementations may be implemented in various environments. Such environments and associated applications may be specially configured to perform the various processes and operations of the disclosed implementations, or they may include general-purpose computers or computing platforms selectively activated or reconfigured by code to provide the required functionality. The processes disclosed herein are not inherently related to any particular computer, network, architecture, environment, or other apparatus, but may be implemented by any suitable combination of hardware, software, and / or firmware. For example, various general-purpose devices may be used with programs written in accordance with the teachings of the disclosed implementations, or it may be more convenient to configure specialized devices or systems to perform the required methods and techniques.
[0136] The systems and methods disclosed herein may be implemented as a computer program product (i.e., a computer program tangibly embodied in an information carrier (e.g., a machine-readable storage device or a propagated signal) for execution by or to control the operation of a data processing apparatus (e.g., a programmable processor, computer, or multi-computer)). The computer program may be written in any form of programming language, including compiled or interpreted languages, and may be deployed in any form, including a stand-alone program or a module, component, subroutine, or other unit suitable for use in a computing environment. The computer program may be deployed to be executed on one computer or on multiple computers at one site or distributed across multiple sites and interconnected by a communications network.
[0137] As used herein, the term "user" may refer to any entity, including a person or a computer.
[0138] Although ordinal numbers such as first, second, etc. may refer to an order in some circumstances, ordinal numbers used in this document do not necessarily imply an order. For example, ordinal numbers may be used simply to distinguish one item from another. For example, distinguishing a first event from a second event does not necessarily imply a chronological order or a fixed reference system (just as the first event in one paragraph of a description may be different from the first event in another paragraph of the description).
[0139] The above description is intended to be illustrative, but not limiting, of the scope of the invention, which is defined by the appended claims. Other implementations are within the scope of the following claims.
[0140] These computer programs, software, software applications, applications, components, or codes, which may also be referred to as programs, include machine instructions for a programmable processor and may be implemented in a high-level procedural and / or object-oriented programming language and / or assembly / machine language. As used herein, the term "machine-readable medium" refers to any computer program product, apparatus, and / or device (e.g., magnetic disks, optical disks, memory, and programmable logic devices (PLDs)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor. A machine-readable medium may non-transitory store such machine instructions (e.g., non-transitory solid-state memory or a magnetic hard drive or any equivalent storage medium). Alternatively or additionally, a machine-readable medium may store such machine instructions in a transitory manner (e.g., processor cache or other random access memory associated with one or more physical processor cores).
[0141] To provide for user interaction, the subject matter described herein may be implemented on a computer having a display device, such as a cathode ray tube (CRT) or liquid crystal display (LCD) monitor, for displaying information to the user, and a keyboard and pointing device, such as a mouse or trackball, through which the user can provide input to the computer. Other types of devices may also be used to provide for user interaction. For example, feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback. Input from the user may be received in any form, including, but not limited to, acoustic, speech, or tactile input.
[0142] The subject matter described herein may be implemented in a computing system that includes back-end components such as one or more data servers, or middleware components such as one or more application servers, or front-end components such as one or more client computers having a graphical user interface or web browser through which a user can interact with an implementation of the subject matter described herein, or any combination of such back-end, middleware, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication, such as a communications network. Examples of communications networks include, but are not limited to, a local area network ("LAN"), a wide area network ("WAN"), and the Internet.
[0143] A computing system may include clients and servers. Clients and servers are generally, but not limited to, remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.
[0144] The implementations presented in the foregoing description do not represent all implementations consistent with the subject matter described herein. Rather, they are merely some examples consistent with aspects related to the described subject matter. While a few variations have been described in detail above, other modifications or additions are possible. In particular, additional features and / or variations may be provided in addition to those presented herein. For example, the implementations described above may be directed to various combinations and subcombinations of the disclosed features and / or combinations and subcombinations of some additional features disclosed above. In addition, the logic flow depicted in the accompanying figures and / or described herein does not necessarily require the particular order depicted or sequential order to achieve desirable results. Other implementations may also be within the scope of the following claims.
Claims
1. at least one processor; When executed by the at least one processor, Mapping a physical cell identifier (PCI) of at least one Layer 1 / Layer 2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for a user equipment (UE) to an index; securely transmitting the mapping from an aggregation unit control plane (CU CP) of the base station to the UE and a serving DU of the base station currently serving the UE for at least one service; at least one non-transitory storage medium storing instructions that cause the at least one processor to perform operations comprising: An apparatus comprising:
2. 2. The apparatus of claim 1, wherein the index for each of the at least one LTM target cells is unique in the mapping such that each index is uniquely associated with one of the at least one LTM target cells by a PCI.
3. 2. The apparatus of claim 1, wherein the operations further comprise securely transmitting the mapping from the CU CP to a target DU that includes one of the at least one LTM target cell selected for the HO.
4. the mapping is sent to the UE in a radio resource control (RRC) reconfiguration message; The mapping is sent to the serving DU in an F1 UE context modification request message.
10. The apparatus of claim 1.
5. The operation one of the at least one LTM target cells is excluded for the UE; and one of the at least one LTM target cells is replaced for the UE; and updating the mapping in response to at least one of: Securely transmitting the updated mapping from the CU CP to the UE and the serving DU; The apparatus of claim 1 further comprising:
6. The operation Mapping PCIs of at least one LTM target cell of the at least one target DU that is a candidate for HO for a second UE to an index such that a second mapping is generated; securely transmitting the second mapping from the CU CP to the second UE; The apparatus of claim 1 further comprising:
7. The apparatus of claim 1 , wherein the serving DU uses the index received from the CU CP when sending an LTM HO command to the UE.
8. The apparatus of claim 1 , wherein each index is one of a number, an alphabet, and an alphanumeric character.
9. The apparatus of claim 1 , wherein the operations further comprise storing the mapping on the at least one non-transitory storage medium.
10. 10. The apparatus of claim 1, wherein the base station comprises a Next Generation Radio Access Network (NG-RAN) node.
11. The apparatus of claim 10 , wherein the NG-RAN node comprises a gNodeB or an ng-eNodeB.
12. The apparatus of claim 1 , wherein the base station includes the at least one processor and the at least one non-transitory storage medium.
13. The apparatus of claim 12 , wherein the CU CP includes the at least one processor and the at least one non-transitory storage medium.
14. When executed by at least one processor, Mapping a physical cell identifier (PCI) of at least one Layer 1 / Layer 2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for a user equipment (UE) to an index; securely transmitting the mapping from an aggregation unit control plane (CU CP) of the base station to the UE and a serving DU of the base station currently serving the UE for at least one service; and at least one non-transitory storage medium storing instructions that cause the at least one processor to perform operations comprising:
15. 15. The non-transitory storage medium of claim 14, wherein the index for each of the at least one LTM target cells is unique in the mapping such that each index is uniquely associated with one of the at least one LTM target cells by a PCI.
16. 15. The non-transitory storage medium of claim 14, wherein the operations further comprise securely transmitting the mapping from the CU CP to a target DU that includes one of the at least one LTM target cell selected for the HO.
17. Mapping a physical cell identifier (PCI) of at least one Layer 1 / Layer 2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for a user equipment (UE) to an index; securely transmitting the mapping from an aggregation unit control plane (CU CP) of the base station to the UE and a serving DU of the base station currently serving the UE for at least one service; A computer-implemented method comprising:
18. 18. The method of claim 17, wherein the index for each of the at least one LTM target cells is unique in the mapping such that each index is uniquely associated with one of the at least one LTM target cells by a PCI.
19. 18. The method of claim 17, further comprising securely transmitting the mapping from the CU CP to a target DU that includes one of the at least one LTM target cell selected for the HO.
Citation Information
Patent Citations
Mapping a control resource to a physical cell
US20210344436A1
Security key in layer 1 (L1) and layer 2 (L2) based mobility
US20220007242A1