Security key management for dual connection operation

By equipping user equipment with key counter information for autonomous security key updates, the challenges of RRC signaling overhead and limited mobility in 5G dual connectivity are addressed, enabling efficient and high-speed transitions between SCGs.

JP2025529753AActive Publication Date: 2025-09-09NOKIA TECHNOLOGIES OY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025507572
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-09
Filing Date
2023-06-21
Publication Date
2025-09-09
Estimated Expiration
2043-06-21

AI Technical Summary

Technical Problem

In 5G dual connectivity operations, the frequent conditional addition or change of secondary cell groups (SCGs) leads to significant RRC signaling overhead and limits high-speed mobility due to the need for new configuration messages after each cell group change.

Method used

User equipment is equipped with key counter information to autonomously generate multiple security keys for future target SCGs, allowing it to perform security key updates without network intervention, thereby reducing RRC signaling overhead and enhancing mobility between SCGs.

Benefits of technology

This approach reduces RRC signaling overhead and significantly improves the user equipment's fast mobility between different SCGs by enabling autonomous security key updates, allowing for potentially infinite mobility events without the need for continuous network involvement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025529753000001_ABST
    Figure 2025529753000001_ABST
Patent Text Reader

Abstract

The present disclosure relates, inter alia, to a user equipment configured to support dual connection operation to a master node and a secondary node of a radio access network, the user equipment comprising at least one processor and at least one memory, the at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to at least: establish a connection to the master node; and receive configuration information from the master node, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure relates to, but is not limited to, dual connectivity operation in the context of radio access networks defined by 3rd Generation Partnership Project (3GPP) standards, such as the 5G standard also known as New Radio (NR). This disclosure relates particularly to security key management in such dual connectivity operation, and more specifically to security key management for secondary nodes in dual connectivity operation. [Background technology]

[0002] Dual Connectivity (DC) is an operating mode in which a user equipment (UE) capable of multiple transmissions and receptions is configured to utilize resources provided by two different radio nodes. One node functions as a master node (MN) and the other node functions as a secondary node (SN). The MN and SN are connected via a network interface, and at least the MN is connected to a core network. A master cell group (MCG) is a group of at least one serving cell associated with an MN, and a secondary cell group (SCG) is a group of at least one serving cell associated with an SN (see, for example, References [1] and [2]).

[0003] Integrity protection and encryption of Radio Resource Control (RRC) signaling and user data is performed using a security key K, which is generated based on a Non-Access Stratum (NAS) level key. gNB is used. gNB can be updated to ensure lateral mobility between nodes without modifying the core network (see, for example, [3]).

[0004] In the case of DC, radio bearers can be allocated to MCGs and SCGs, and UE mobility through SCGs may be independent of mobility within MCGs. Therefore, to update the security keys of SCG bearers without affecting ongoing security procedures of MCG bearers, a new security key K for the SCG bearer is generated. SNが Introduced. K SN is updated by the UE based on the SN counter value provided to the UE by the MN (see, for example, reference [4]). Summary of the Invention

[0005] However, in the current 5G standard, after a conditional addition or change (CPAC) of a primary cell (PSCell) in a secondary cell group or a conditional handover (CHO), the CPAC or CHO configuration data is removed by the UE after the CPAC or CHO is performed. Furthermore, a CPAC or CHO configuration message can only contain one SN counter value. Therefore, whenever a UE moves from a previous serving SCG to a current serving SCG, a new configuration message must be sent by the MN to prepare the UE for a subsequent cell group change to a potential future target SCG. In this context, the UE must also prepare to switch to the previous serving SCG, so the potential future target SCG also includes the previous serving SCG. Because the configuration message is sent via RRC signaling, a large RRC signaling overhead is generated, especially when a large number of CPAC or CHO operations are performed within a short period of time. Furthermore, the need to send a new configuration message before performing a subsequent cell group change limits the UE's high-speed mobility between different SCGs.

[0006] In view of the above, example embodiments of the present disclosure may have the effect of, among other things, enabling user equipment to perform autonomous security key updates without network involvement, thus reducing RRC signaling overhead and significantly improving UE fast mobility between different SCGs, since new CPAC or CHO configuration messages can be omitted in certain situations.

[0007] According to a first exemplary aspect, a user equipment is disclosed. The user equipment may be configured to support dual connection operation to a master node and a secondary node of a radio access network. The user equipment may include at least one processor and at least one memory. The at least one memory, when executed by the at least one processor, provides the user equipment with at least: - establishing a connection to a master node; receiving configuration information from the master node, where the configuration information may comprise key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes.

[0008] The user equipment may be a fixed device or a mobile device. In particular, the user equipment may be a mobile device such as a smartphone, a tablet, a wearable, a smartwatch, a low-power device, an IoT device, an IIoT device, a vehicle, a truck, a drone, or an airplane. The user equipment may, in particular, be capable of communicating with (transmitting and receiving signals and / or data from) one or more other user equipments. Additionally or alternatively, the user equipment may, in particular, be capable of communicating with (transmitting and receiving signals and / or data from) at least one master node of a radio access network, the master node being configured to support dual-connection operation to a secondary node of the radio access network and to the user equipment. Additionally or alternatively, the user equipment may, in particular, be capable of communicating with (transmitting and receiving signals and / or data from) at least one secondary node of the radio access network, the secondary node being configured to support dual-connection operation to a master node of the radio access network and to the user equipment. In general, the user equipment may be any device capable of communicating with a communication network and / or another user equipment.

[0009] A radio node (e.g., a master node or a secondary node) may be understood as a wireless communication station installed at a fixed or mobile location, and may in particular be or comprise an entity of a radio access network of a wireless communication system. For example, a radio node may be, comprise, or be part of a base station of a wireless communication network of any generation of 3GPP standards (e.g., gNB, ng-eNB, eNodeB, NodeB, BTS, etc.). In general, a radio node may be or comprise hardware or software components that perform a specific function. In one example, a radio node may be a Location Management Function (LMF). In one example, a radio node may be an entity defined by the 3GPP 5G or NR standards (also referred to as gNB). Thus, although a radio node may be implemented in or be understood to be a single device or module, a radio node may be implemented across or comprise multiple devices or modules. Thus, a radio node may in particular be implemented in or be a fixed device. The multiple radio nodes may establish, in particular, a wireless communication system or network, which may in particular be an NR or 5G system or any other wireless communication system defined by past or future standards, in particular successors of current 3GPP standards. In particular, the multiple radio nodes, e.g., a master node and one or more secondary nodes, may be configured to support dual-connection operation to one or more user equipment. The radio nodes may communicate directly and / or indirectly with other radio nodes or user equipment.

[0010] Configuration information as used herein may be understood as any type of information based on which a user equipment is or may be configured with respect to dual connectivity operation and / or security key management, for example, configuration information may be, among other things, RRC reconfiguration information as part of an RRC reconfiguration request to the user equipment.

[0011] As used herein, key counter information may be understood as any type of information that defines at least one value of a key counter, the key counter being associated with a security key. For example, the key counter information may be, comprise, indicate, be determinable, or similarly explicitly or implicitly specify at least one previous, current, or future value of a key counter. For example, the key counter value may define the value of an SN counter.

[0012] As used herein, a sequence may be understood as an ordered series of similar elements that follows a particular pattern. As an example, a sequence may have a first element and a last element, particularly if the sequence is a finite sequence. As another example, a sequence may have a first element but not a last element, particularly if the sequence is an infinite sequence. For example, a sequence may be an ordered series of numbers or values ​​that follow a particular pattern. For example, a sequence may be an ordered series of integers, particularly non-negative integers, where subsequent elements may be obtained from previous elements by repeatedly adding a predefined step value. For example, the predefined step value may be equal to 1.

[0013] A key counter value as used herein may be understood as the value of a key counter associated with a security key. For example, the key counter value may be used as a freshness input to a subsequent derivation of the security key. For example, the key counter value may be the value of the SN counter. For example, the key counter value is a numeric value, in particular a non-negative integer.

[0014] As used herein, key counter information defining a sequence of at least two distinct key counter values ​​may be understood to mean that the at least two distinct key counter values ​​are derivable from the key counter information in any conceivable manner, now or in the future. For example, the key counter information may define a sequence of at least two distinct key counter values ​​by explicitly or implicitly specifying whether the key counter information is, comprises, indicates, or is determinable as the first element of the sequence, along with rules for the derivation of further elements of the sequence. For example, the elements of the sequence may form a monotonically increasing sequence, in particular a sequence of non-negative integers that monotonically increase by one. This provides a very simple way to prevent a key counter value from being used multiple times to generate a security key.

[0015] A security key as used herein may be understood as information, particularly a character string, used for security purposes in a radio access network. For example, the character string may comprise numbers, letters, symbols, special characters, etc. For example, the security key may be secret. For example, the security key may be a security key for data integrity protection and / or encryption, particularly encryption of data exchanged between a user equipment and a secondary node of the radio access network. For example, the security key may be a higher-level security key based on which multiple lower-level security keys for integrity protection and / or encryption are determined, particularly a first lower-level security key for integrity protection of RRC signaling, a second lower-level security key for encryption of RRC signaling, a third lower-level security key for integrity protection of user data, and a fourth lower-level security key for encryption of user data. For example, the security key may be K SN It may also be a security key.

[0016] Encryption, as used herein, may be understood as the general concept of converting information between a decrypted form of information in a form that is easily readable by humans or computers, called plaintext, and a encrypted form of information in a form that is unreadable by humans or computers without proper decryption, called ciphertext. Encryption therefore includes both the encryption of information from plaintext to ciphertext and the decryption of information from ciphertext to plaintext.

[0017] A target secondary node, as used herein, may be understood as a secondary node of a radio access network whose associated secondary cell group (SCG) qualifies or may qualify for a conditional PSCell addition or modification (CPAC) or a conditional handover (CHO) toward the SCG associated with the target secondary node, respectively, at a current or future time. For example, a target secondary node may differ from a source secondary node, and a source secondary node, as used herein, may be understood as a secondary node associated with a current serving SCG. However, the target secondary node may be identical to the source secondary node in that after a CPAC or CHO is performed from an SCG associated with the source secondary node toward an SCG associated with a target secondary node different from the source secondary node, the SCG associated with the source secondary node qualifies or may qualify, at a future time, for a subsequent CPAC or CHO back to the SCG associated with the source secondary node.

[0018] According to a first exemplary aspect, a user equipment may establish a connection to a master node, thereby enabling data exchange between the UE and the MN. For example, the connection may be a secure connection, in particular a secure RRC signaling connection.

[0019] Further, according to the first exemplary aspect, a user equipment may receive configuration information from the master node, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes. Compared to a scenario in which a CPAC or CHO configuration message includes only one key counter value and the CPAC or CHO configuration data is released by the UE after performing the CPAC or CHO, an exemplary embodiment of the first exemplary aspect may be advantageous in that a new CPAC or CHO configuration message may be omitted in certain circumstances. For example, after the UE performs a CPAC or CHO from an SCG associated with a source SN to an SCG associated with a first target SN and uses a first key counter value derived from the key counter information to generate a first security key for data exchange with the first target SN, the UE may derive a second key counter value from the key counter information and use the second key counter value to generate a second security key for data exchange with the second target SN. Therefore, the UE can autonomously perform security key updates of the CPAC or CHO towards the SCG associated with the second target SN without the MN needing to send new configuration information of this CPAC or CHO to the UE, which may reduce RRC signaling overhead and significantly improve the fast mobility of the UE between different SCGs.

[0020] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to generate a first security key using a first key counter value derived from the key counter information. As used herein, deriving a first key counter value from key counter information may be understood as the first key counter value being obtained by the user equipment based on the key counter information in any conceivable manner. For example, the user equipment may derive the first key counter value by obtaining a first key counter value that is identical to, included in, indicated by, determinable by, or similarly explicitly or implicitly specified in the key counter information. As used herein, generating a first security key using a first key counter value may be understood as the first security key being generated by the user equipment based on the first key counter value in any conceivable manner. For example, the user equipment may calculate the first security key using the first key counter value as a freshness input for the calculation. Generating the first security key using the first key counter value derived from the key counter information may enable the UE to obtain a first security key for integrity protection and / or encryption of data, particularly data exchanged between the UE and the first target SN.

[0021] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to cause the first security key to be used for integrity protection and / or encryption of data exchanged between the user equipment and the first target secondary node. This may allow a secure exchange of data between the UE and the first target SN, in particular a secure exchange of data in accordance with the security architecture of the 5G standard.

[0022] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to cause the user equipment to process the key counter information such that the user equipment is able to derive from the processed key counter information at least a second key counter value different from the first key counter value. As used herein, processing key counter information may be understood as the key counter information being modified by the user equipment in any conceivable manner. For example, processing the key counter information may comprise modifying a sequence of key counter values ​​defined by the key counter information. For example, processing the key counter information may comprise preventing a first key counter value from being reused for generating security keys other than the first security key. Processing the key counter information may enable the UE to derive a second key counter value from the processed key counter information and use the second key counter value to generate a second security key for data exchange with the second target SN. Thus, the UE can autonomously perform future CPAC or CHO security key updates for the SCG associated with the second target SN without the MN needing to send new configuration information for this CPAC or CHO to the UE. This may reduce RRC signaling overhead and significantly improve UE high-speed mobility between different SCGs.

[0023] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to generate a second security key different from the first security key using a second key counter value derived from the processed key counter information. As used herein, deriving a second key counter value from the processed key counter information may be understood as the second key counter value being obtained by the user equipment based on the processed key counter information in any conceivable manner. For example, the user equipment may derive the second key counter value by obtaining a second key counter value that is identical to, comprised in, indicated by, determinable by, or similarly explicitly or implicitly specified in the processed key counter information. As used herein, generating a second security key using the second key counter value may be understood as the second security key being generated by the user equipment based on the second key counter value in any conceivable manner. For example, the user equipment may calculate the second security key using the second key counter value as a freshness input for the calculation. Generating the second security key using the second key counter value derived from the processed key counter information may enable the UE to obtain a second security key for integrity protection and / or encryption of data, particularly data exchanged between the UE and the second target SN.

[0024] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to cause the second security key to be used for integrity protection and / or encryption of data exchanged between the user equipment and a second target secondary node different from the first target secondary node. This may allow a secure exchange of data between the UE and the second target SN, in particular a secure exchange of data in accordance with the security architecture of the 5G standard.

[0025] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: may further store instructions to cause the user equipment to further process the key counter information such that from the further processed key counter information at least a further key counter value is derived, the further key counter value being different from the first key counter value and different from the second key counter value. As used herein, further processing the key counter information may be understood as the key counter information being further modified by the user equipment in any conceivable manner. For example, further processing the key counter information may comprise further modifying a sequence of key counter values ​​defined by the key counter information. For example, further processing the key counter information may comprise preventing the second key counter value from being reused for generating security keys other than the second security key. Further processing the key counter information may enable the UE to derive further key counter values ​​from the further processed key counter information and use the further key counter values ​​to generate further security keys for data exchanges with further target SNs. Thus, the UE can autonomously perform security key updates for future CPAC or CHOs toward SCGs associated with further target SNs without the MN needing to send new configuration information for these CPACs or CHOs to the UE. This may reduce RRC signaling overhead and significantly improve UE high-speed mobility between different SCGs.

[0026] In an exemplary embodiment of the first exemplary aspect, the key counter information received from the master node may define at least two different lists of key counter values. As used herein, a list may be understood as a sequence having a final element. Thus, a list may be understood as a finite sequence. As used herein, key counter information defining a list of key counter values ​​may be understood to mean that the list of key counter values ​​is derivable from the key counter information in any conceivable manner, currently or in the future. For example, the key counter information may be, comprise, indicate, be determinable, or similarly explicitly or implicitly specify a list of key counter values. For example, the key counter information may define a list of key counter values ​​by the key counter information explicitly specifying individual key counter values ​​of the list, particularly all individual key counter values ​​of the list. For example, the key counter information may define a list of key counter values ​​by the key counter information specifying a first key counter value and a maximum number of additions, where a first element of the list is obtained by selecting the first key counter value, and the remaining elements of the list are obtained by repeatedly adding a step value to the first key counter value until the maximum number of additions is reached. For example, the step value may be predetermined by the user equipment or specified in the key counter information. For example, the step value may be equal to 1. For example, the key counter information may define a list of key counter values ​​by specifying a range from a first non-negative integer key counter value to a last non-negative integer key counter value, and the list is obtained by selecting each non-negative integer in the specified range as one element of the list of key counter values. Key counter information received from the master node defining a list of at least two different key counter values ​​may enable a particularly simple definition of the at least two different key counter values, e.g., eliminating the need for complex calculation operations and saving respective processor resources.

[0027] In an exemplary embodiment of the first exemplary aspect, generating the first security key may comprise using a first list element in the list of key counter values ​​as the first key counter value, whereby a particularly simple derivation of the first key counter value from the key counter information may be achieved, since e.g. complex calculation operations are not required and respective processor resources are saved.

[0028] In an exemplary embodiment of the first exemplary aspect, processing the key counter information may comprise deleting a first list element from the list of key counter values, whereby a particularly simple processing of the key counter information may be achieved, since e.g. complex calculation operations are not required and respective processor resources are saved.

[0029] In an exemplary embodiment of the first exemplary aspect, generating the second security key may comprise using a current first list element in the list of key counter values ​​as the second key counter value, whereby a particularly simple derivation of the second key counter value from the processed key counter information may be achieved, since e.g. complex calculation operations are not required and respective processor resources are saved.

[0030] In an exemplary embodiment of the first exemplary aspect, further processing the key counter information may comprise deleting the current first list element from the list of key counter values, whereby a particularly simple further processing of the key counter information may be achieved, since e.g. complex calculation operations are not required and respective processor resources are saved.

[0031] In an exemplary embodiment of the first exemplary aspect, the configuration information includes at least two different K SNThe key counter information may include a list of at least two different SN counter values ​​for generating the security key. The first key counter value may be a first SN counter value. The second key counter value may be a second SN counter value. The first security key may be a first K SN The second security key may be a second K SN It may also be a security key.

[0032] In an exemplary embodiment of the first exemplary aspect, the configuration information may comprise a radio resource control reconfiguration request.

[0033] In an exemplary embodiment of the first exemplary aspect, the configuration information may comprise information related to a conditional addition or modification of a primary cell of a secondary cell group associated with the first target secondary node, or information related to a conditional handover to the first target secondary node.

[0034] In an exemplary embodiment of the first exemplary aspect, the configuration information may comprise information related to a conditional addition or modification of a primary cell of a secondary cell group associated with the second target secondary node, or information related to a conditional handover to the second target secondary node.

[0035] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, causes the user equipment to: - determining whether at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the first target secondary node or at least one condition for a conditional handover to the first target secondary node is satisfied; and - the first K packets via a random access channel SNand initiating a random access procedure to the first target secondary node using the security key. In particular, in response to determining that at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the first target secondary node or at least one condition for a conditional handover to the first target secondary node is satisfied, the first K SN Initiating a random access procedure to the first target secondary node using the security key may be performed.

[0036] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, causes the user equipment to: - determining whether at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the second target secondary node or at least one condition for a conditional handover to the second target secondary node is satisfied; and - the second K via a random access channel SN and initiating a random access procedure to the second target secondary node using the security key. In particular, in response to determining that at least one condition for a conditional addition or change of a primary cell of a secondary cell group associated with the second target secondary node or at least one condition for a conditional handover to the second target secondary node is satisfied, transmit via a random access channel (RACH) to the second K SN Initiating a random access procedure to the second target secondary node using the security key may be performed.

[0037] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The device may further store instructions to cause the device to send information indicating the connection failure to the master node. For example, the connection failure may be a failure of the connection between the user equipment and the target secondary node. For example, the connection failure may be a failure of a random access procedure from the user equipment to the target secondary node, in particular a random access procedure via RACH. By transmitting information indicating the connection failure to the master node, the MN may be notified of the connection failure, allowing the MN to take appropriate measures if necessary.

[0038] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to receive at least one additional list element of the list of key counter values ​​from the master node. In particular, receiving at least one additional list element of the list of key counter values ​​from the master node may be performed after determining whether the number of list elements of the list of key counter values ​​is below a predefined threshold and in response to determining that the number of list elements of the list of key counter values ​​is below the predefined threshold. For example, the predefined threshold may be equal to 1. By receiving at least one additional list element of the list of key counter values ​​from the master node, the number of list elements of the list of key counter values ​​can be prevented from reaching an extremely low value, in particular, zero. Accordingly, after one or more key counter values ​​are used to generate security keys for one or more target SNs and are removed from the list, additional key counter values ​​can be provided to the user equipment, thereby enabling generation of additional security keys for additional target SNs. Therefore, the ability of the UE to perform CPAC or CHO toward SCGs associated with additional target SNs can be maintained. In particular, continuously receiving at least one additional list element of the list of key counter values ​​from the master node can enable the UE to perform a theoretically infinite number of CPAC or CHO, and therefore a theoretically infinite number of autonomous mobility events.

[0039] In an exemplary embodiment of the first exemplary aspect, the key counter information received from the master node may comprise a key counter value and instructions for maintaining the key counter value. As used herein, "key counter information comprising a key counter value" may be understood as comprising information that explicitly specifies the key counter value. As used herein, "instructions to maintain a key counter value" may be understood as instructions to the user equipment to continuously process the key counter value rather than releasing it. In particular, the user equipment may be instructed to process the key counter value after a security key is generated using the key counter value and / or after the security key is used for the target secondary node. The key counter information received from the master node comprising the key counter value and instructions for maintaining the key counter value may enable a particularly simple derivation of a first key counter value from the key counter information, thereby, for example, eliminating the need for complex calculation operations and saving respective processor resources. Furthermore, potential target SNs do not need to be pre-provisioned with multiple security keys.

[0040] In an exemplary embodiment of the first exemplary aspect, generating the first security key may comprise using a key counter value received from the master node as the first key counter value, whereby a particularly simple derivation of the first key counter value from key counter information may be achieved, since e.g. complex calculation operations are not required and respective processor resources are saved.

[0041] In an exemplary embodiment of the first exemplary aspect, processing the key counter information may comprise adding a predefined step value to the key counter value received from the master node. For example, the predefined step value may be a positive integer, in particular 1. By adding the predefined step value to the key counter value, a particularly simple processing of the key counter information may be achieved, since, for example, complex calculation operations are not required and respective processor resources are saved.

[0042] In an exemplary embodiment of the first exemplary aspect, generating the second security key may comprise using the current key counter value as the second key counter value, whereby a particularly simple derivation of the second key counter value from the processed key counter information may be achieved, such that e.g. complex calculation operations are not required and respective processor resources are saved.

[0043] In an exemplary embodiment of the first exemplary aspect, further processing the key counter information may comprise adding a predefined step value to the current key counter value, whereby a particularly simple further processing of the key counter information may be achieved, since e.g. complex calculation operations are not required and respective processor resources are saved.

[0044] In an exemplary embodiment of the first exemplary aspect, the configuration information includes at least two different K SN The key counter information may comprise a sequence of at least two different SN counter values ​​for generating the security key. The key counter information received from the master node may comprise an SN counter value and instructions for maintaining the SN counter values. The first key counter value may be a first SN counter value. The second key counter value may be a second SN counter value. The first security key may be a first K SN The second security key may be a second KSN It may also be a security key.

[0045] In an exemplary embodiment of the first exemplary aspect, the key counter information received from the master node may define a maximum allowable number of additions of a predefined step value to the key counter value received from the master node. The at least one memory, when executed by the at least one processor, may provide to the user equipment at least: - determining whether the maximum number of allowable additions has been reached; and - preventing further addition of the predefined step value to the current key counter value in response to determining that the maximum allowed number of additions has been reached. Thereby, the number of CPACs or CHOs that may be performed by the UE can be specified by the MN when the MN first sends configuration information comprising key counter information to the UE, thus limiting the number of autonomous mobility events of the UE.

[0046] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: and generating a further security key using a further key counter value derived from the further processed key counter information, the further security key being distinct from the first security key and distinct from the second security key. As used herein, deriving a further key counter value from the further processed key counter information may be understood as the further key counter value being obtained by the user equipment based on the further processed key counter information in any conceivable manner. For example, the user equipment may derive the further key counter value by obtaining a further key counter value that is identical to, comprised in, indicated by, determinable by, or similarly explicitly or implicitly specified in the further processed key counter information. As used herein, generating a further security key using a further key counter value may be understood as the further security key being generated by the user equipment based on the further key counter value in any conceivable manner. For example, the user equipment may calculate the further security key using the further key counter value as a freshness input for the calculation. Generating a further security key using a further key counter value derived from the further processed key counter information may enable the UE to obtain a further security key for integrity protection and / or encryption of data, particularly data exchanged between the UE and a further target SN.

[0047] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: The method may further store instructions to cause the further security key to be used for integrity protection and / or encryption of data exchanged between the user equipment and the further target secondary node different from the second target secondary node. This may allow a secure exchange of data between the UE and the further target SN, in particular in accordance with the security architecture of the 5G standard. With regard to the further target secondary node, in particular in the exemplary case where the user equipment performs CPAC or CHO from an SCG associated with a second target secondary node towards an SCG associated with a further target secondary node, it is only required that the further target secondary node be different from the second target secondary node. However, for example, in particular when the user equipment first performs CPAC or CHO from an SCG associated with the first target secondary node towards an SCG associated with the second target secondary node and then performs CPAC or CHO back from the SCG associated with the second target secondary node towards an SCG associated with the first (or further) target secondary node, the further target secondary node may be identical to the first target secondary node.

[0048] In an exemplary embodiment of the first exemplary aspect, the at least one memory, when executed by the at least one processor, provides the user equipment with at least: may further store instructions to cause the user equipment to further process the key counter information such that the user equipment is able to derive from the further processed key counter information at least one further key counter value that is different from the first key counter value, that is different from the second key counter value, and that is different from any other key counter value previously derived from the unprocessed, processed, or further processed key counter information. As used herein, further processing the key counter information may be understood as the key counter information being further modified by the user equipment in any conceivable manner. For example, further processing the key counter information may comprise further modifying a sequence of key counter values ​​defined by the key counter information. For example, further processing the key counter information may comprise preventing a particular further key counter value from being reused for generating security keys other than a particular further security key. Further processing the key counter information may enable the UE to derive at least one further key counter value from the further processed key counter information and use the at least one further key counter value to generate at least one further security key for data exchange with the at least one further target SN. Thus, the UE can autonomously perform security key updates for future CPACs or CHOs toward the SCG associated with the at least one further target SN without the MN needing to send new configuration information for this CPAC or CHO to the UE. This may reduce RRC signaling overhead and significantly improve fast UE mobility between different SCGs.

[0049] By repeatedly performing the actions of generating further security keys, using the further security keys for integrity protection and / or encryption, and further processing the key counter information, a theoretically infinite number of CPACs or CHOs, and therefore a theoretically infinite number of autonomous mobility events, may be possible by the UE. This may significantly reduce RRC signaling overhead and significantly improve the high-speed mobility of the UE between different SCGs. However, in some situations it may be desirable to limit the maximum number of possible CPACs or CHOs, and therefore the maximum number of autonomous mobility events. This can be achieved, for example, by defining a list of key counter values ​​with a finite number of list elements, or by defining a maximum allowed number of additions of a pre-defined step value to a key counter value received from the master node.

[0050] In an exemplary embodiment of the first exemplary aspect, the configuration information may further comprise information indicating at least one target secondary cell for which generating a security key is not required. A cell, as used herein, may, for example, cover at least a portion of a geographical area served by a radio access network, such that wireless service is provided in at least a portion of that geographical area, among other things. For example, a cell may be associated with (e.g., served by) at least one radio node. Serving a cell may, for example, be understood as providing wireless service within the cell. For example, a network node may be associated with (e.g., serves) at least one cell. For example, at least two cells may form a cell group, in particular an SCG. The configuration information comprising information indicating at least one target secondary cell for which generating a security key is not required may avoid unnecessary derivation of a key counter value from key counter information, unnecessary generation of a security key, and / or unnecessary processing of key counter information, among other things, when a user equipment moves or switches between cells in the same SCG. Such movement or switching between cells in the same SCG may, for example, be referred to as intra-SN selective activation. They may be performed by the UE without the need for, for example, new security keys, since the target secondary cell is still associated with the same SN.

[0051] According to a first exemplary aspect, a respective method is also disclosed. The method according to the first exemplary aspect may be performed by a user equipment. The user equipment may be configured to support dual connection operation to a master node and a secondary node of a radio access network. The method includes at least: - establishing a connection to a master node; receiving configuration information from the master node, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes. In the first exemplary aspect, disclosure of any instructions that, when executed by at least one processor of a user equipment, cause the user equipment to perform an action shall also be considered a disclosure of the respective action of the method.

[0052] According to the first exemplary aspect, a respective apparatus is also disclosed. The apparatus according to the first exemplary aspect may include means for performing the method according to the first exemplary aspect. In the first exemplary aspect, disclosure of any method action shall also be considered as disclosure of means for performing the respective method action. Similarly, disclosure of any means for performing the method action shall also be considered as disclosure of the method action itself. The apparatus according to the first exemplary aspect may be a user equipment. The user equipment may be configured to support dual connection operation to a master node and a secondary node of a radio access network.

[0053] The means or functions of the user equipment according to the first exemplary aspect can be implemented in hardware and / or software. They may comprise one or more modules or units providing the respective functions. They may comprise, for example, at least one processor for executing computer program code for performing the required functions, at least one memory for storing the program code, or both. Alternatively, they may comprise circuits designed to perform the required functions, for example, embodied in a chipset or chip such as an integrated circuit. In general, the means may comprise, for example, one or more processing means or processors.

[0054] According to the first exemplary aspect, a respective non-transitory computer-readable medium is also disclosed. The non-transitory computer-readable medium according to the first exemplary aspect may comprise program instructions that, when executed by a user equipment, cause the user equipment to perform at least a method according to the first exemplary aspect. The user equipment may be configured to support dual connection operation to a master node and a secondary node of a radio access network.

[0055] The non-transitory computer-readable medium according to the first exemplary aspect may be, for example, a disk or a memory. The program instructions may be stored in the computer-readable medium in the form of instructions encoding the computer-readable medium. The computer-readable medium may be intended to participate in the operation of a device, such as an internal or external memory, such as a computer read-only memory (ROM) or a hard disk, or may be intended to distribute the program, such as an optical disk.

[0056] According to the first exemplary aspect, a respective computer program is also disclosed. The computer program according to the first exemplary aspect may comprise instructions that, when executed by a user equipment, cause the user equipment to perform at least a method according to the first exemplary aspect. The user equipment may be configured to support dual connection operation to a master node and a secondary node of a radio access network.

[0057] The computer program according to the first exemplary aspect may be stored on a computer-readable storage medium, in particular a tangible and / or non-transitory computer-readable storage medium, in particular a computer program according to the first exemplary aspect may be stored on a non-transitory computer-readable medium according to the first exemplary aspect.

[0058] According to a second exemplary aspect, a master node of a radio access network is disclosed. The master node may be configured to support dual connection operation to a secondary node of the radio access network and a user equipment. The master node may include at least one processor and at least one memory. The at least one memory, when executed by the at least one processor, provides the master node with at least: - establishing a connection to a user equipment; - transmitting configuration information to the user equipment, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes.

[0059] The master node may establish a connection to the user equipment to enable data exchange between the UE and the MN. For example, the connection may be a secure connection, in particular a secure RRC signaling connection.

[0060] By transmitting configuration information to the user equipment, where the configuration information comprises key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes, exemplary embodiments of the second exemplary aspect may enable the user equipment to perform autonomous security key updates and may therefore be advantageous in that new configuration messages for CPAC or CHO may be omitted in certain circumstances, as already described in the context of the first exemplary aspect, thereby reducing RRC signaling overhead and potentially enabling significantly improved fast UE mobility between different SCGs.

[0061] In an exemplary embodiment of the second exemplary aspect, the key counter information transmitted to the user equipment may define a list of at least two different key counter values, whereby a particularly simple definition of the at least two different key counter values ​​may be realized by the key counter information, such that no complex calculation operations are required and respective processor resources are saved.

[0062] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: generating a list of at least two different security keys corresponding to the list of at least two different key counter values ​​defined by the key counter information transmitted to the user equipment. As used herein, a list of security keys corresponding to a list of key counter values ​​may be understood to associate at least one element in the list of security keys with each element in the list of key counter values, and vice versa. In particular, each element in the list of security keys may be associated with each element in the list of key counter values, and vice versa. For example, the correspondence may be such that for each number n between 1 and N, where N is the total number of list elements, the nth element in the list of security keys is a security key generated, particularly by the master node, using the nth element in the list of key counter values. Conversely, for each number n between 1 and N, where N is the total number of list elements, the nth element in the list of key counter values ​​is used or was used to generate the nth element in the list of security keys. However, the order of corresponding elements in both lists does not necessarily have to be identical. For example, an element at position n in one list may correspond to an element at position n+x in the other list, where x is different from 0. A corresponding list of security keys may be provided by generating a list of at least two different security keys corresponding to a list of at least two different key counter values ​​defined by the key counter information transmitted to the user equipment.

[0063] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions to cause the device to send request information to at least one target secondary node, the request information comprising the list of generated security keys. The request information used herein may be understood as any type of information related to dual connectivity operation and / or security key management with respect to at least one target secondary node. For example, the request information may be identical to or comprised in an SN addition or modification request for at least one target secondary node. For example, the at least one target secondary node may comprise at least one target secondary node associated with an SCG for which CPAC or CHO will be performed. For example, the at least one target secondary node may also comprise a source secondary node associated with a current serving SCG, which source secondary node qualifies or may qualify, at a future point in time, for a subsequent CPAC or CHO back to the SCG associated with the source secondary node. Sending request information to at least one target secondary node, where the request information comprises a list of generated security keys, may provide at least one target SN with security keys that match the security keys generated by the UE using elements in the list of key counter values, thereby enabling the at least one target SN to securely exchange data with the UE, particularly after the UE has performed CPAC or CHO for the SCG associated with the at least one target SN. Furthermore, a particular advantage of transmitting at least two different lists of security keys to the target SN is that it allows the target SN to autonomously select a security key from the list when a CPAC or CHO is performed towards an SCG associated with the target SN, thereby eliminating the need for further involvement of the MN, in particular an SN modification procedure by the MN. Furthermore, the time requirement for preparing the target SN for a CPAC or CHO execution is reduced, thus further significantly improving the fast mobility of UEs between different SCGs.

[0064] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions to receive, from the first target secondary node, information indicative of a security key switch. As used herein, a security key switch may be understood as an event in which a previous security key, particularly a previous security key for data integrity protection and / or encryption exchanged between the user equipment and a secondary node associated with a previously serving SCG, is replaced with a current security key, particularly a current security key for data integrity protection and / or encryption exchanged between the user equipment and a secondary node associated with a currently serving SCG. Information indicating a security key switch, as used herein, may be understood as any information providing an indication of a security key switch in any conceivable manner. For example, the information indicating a security key switch may be information sent by the first target secondary node indicating that a CPAC or CHO has been performed for an SCG associated with the first target secondary node. By receiving information indicating a security key switch from the first target secondary node, the MN can track the occurrence of a security key switch, and thus, for example, a CPAC or CHO, and take action to ensure that security key management between the UE and the target SN is maintained.

[0065] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: - may further store instructions to cause at least one other target secondary node to send an instruction to remove the first list element from the list of security keys, the at least one other target secondary node being different from the first target secondary node. As used herein, removing a first list element from the list of security keys may be understood as any action performed by at least one other target secondary node that prevents the first list element in the list of security keys from being used as a security key for integrity protection and / or encryption. For example, the first list element may be removed from the list of security keys because the first list element is completely deleted, thereby reducing the number of list items by one. For example, the first list element may be removed from the list of security keys because the first list element is modified to become an empty list element. For example, the first list element may be removed from the list of security keys because the first list element is marked as deactivated or unavailable. In the above context, the at least one other target secondary node may comprise, for example, at least one other target secondary node associated with an SCG for which a CPAC or CHO may be performed at a future time. sending an instruction to at least one other target secondary node to delete the first list element from the list of security keys, where the at least one other target secondary node is different from the first target secondary node, so that the at least one other target SN may modify its list of security keys to make the list of security keys consistent with the list of key counter values ​​processed by the UE.

[0066] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions to receive, from a second target secondary node, information indicative of a security key switch, the second target secondary node being different from the first target secondary node. For example, the information indicating the security key switch may be information sent by a second target secondary node indicating that a CPAC or CHO has been performed for an SCG associated with the second target secondary node. By receiving information indicating the security key switch from the second target secondary node, where the second target secondary node is different from the first target secondary node, the MN can track the occurrence of the security key switch, and thus, for example, the CPAC or CHO, and take action to ensure that security key management between the UE and the target SN is maintained.

[0067] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: - may further store instructions to send to at least one further target secondary node an instruction to remove the current first list element from the list of security keys, wherein the at least one further target secondary node is different from the second target secondary node. As used herein, a current first list element may be understood as the first active or available list element in the list of security keys at a given current time. For example, the first active or available list element in the list of security keys may not necessarily match the first element in the list, particularly if the first element in the list is an empty list element or a list element marked as deactivated or unavailable. As used herein, removing a current first list element from the list of security keys may be understood as any action performed by at least one other target secondary node that prevents the current first list element in the list of security keys from being used as a security key for integrity protection and / or encryption. For example, the current first list element may be removed from the list of security keys because it is completely deleted, thereby reducing the number of list items by one. For example, the current first list element may be removed from the list of security keys because it is modified to become an empty list element. For example, the current first list element may be removed from the list of security keys because it is marked as deactivated or unavailable. In the above context, the at least one further target secondary node may, for example, comprise at least one further target secondary node associated with an SCG for which a CPAC or CHO may be performed at a future point in time. For example, the at least one further target secondary node may also comprise the first target secondary node, particularly if the SCG associated with the first target secondary node qualifies or may, at a future point in time, qualify for a CPAC or CHO back to the SCG associated with the first target secondary node.sending an instruction to at least one further target secondary node to delete the current first list element from the list of security keys, where the at least one further target secondary node is different from the second target secondary node, which may enable the at least one further target SN to modify its list of security keys to make it consistent with the list of key counter values ​​processed by the UE.

[0068] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions to receive information indicative of a connection failure from the user equipment. For example, the connection failure may be a failure of the connection between the user equipment and the target secondary node. For example, the connection failure may be a failure of a random access procedure from the user equipment to the target secondary node, in particular a random access procedure via RACH. By receiving information indicating the connection failure from the user equipment, the MN may be informed of the connection failure and may be able to take appropriate measures, if necessary.

[0069] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions for causing the at least one target secondary node to send an instruction to remove the current first list element from the list of security keys. For example, in response to receiving information indicating a connection failure from the user equipment, sending to at least one target secondary node an instruction to delete the current first list element from the list of security keys may be executed. In this context, the at least one target secondary node may comprise, for example, a target secondary node associated with an SCG for which a CPAC or CHO was not possible due to the connection failure, particularly the connection failure between the user equipment and the target secondary node. For example, the at least one target secondary node may also comprise at least one target secondary node associated with an SCG for which a CPAC or CHO may be performed at a future time. For example, the at least one target secondary node may also comprise a source secondary node associated with a current serving SCG, which source secondary node will or may be eligible at a future time for a subsequent CPAC or CHO back to the SCG associated with the source secondary node. By sending an instruction to at least one target secondary node to delete the current first list element from the list of security keys, the list of security keys of the at least one target SN may become consistent with the list of key counter values ​​processed by the UE, particularly in the event that a connection failure occurs and the UE has already processed the list of key counter values ​​and irrecoverably deleted the previous first key counter value.

[0070] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions to cause the user equipment to transmit at least one additional list element of the list of key counter values. In particular, transmitting at least one additional list element of the list of key counter values ​​to the user equipment may be performed after determining whether the number of list elements of the list of key counter values ​​is below a predefined threshold and in response to determining that the number of list elements of the list of key counter values ​​is below a predefined threshold. For example, the predefined threshold may be equal to 1. Transmitting at least one additional list element of the list of key counter values ​​to the user equipment may result in the UE maintaining the ability to perform CPAC or CHO, as already described in the context of the first exemplary aspect.

[0071] In an exemplary embodiment of the second exemplary aspect, the at least one memory, when executed by the at least one processor, provides the master node with at least: The method may further store instructions to cause the at least one target secondary node to transmit at least one additional list element of the list of security keys to the at least one target secondary node. For example, at least one additional list element of the list of security keys transmitted to the at least one target secondary node may correspond to at least one additional list element of the list of key counter values ​​transmitted to the user equipment. For example, the correspondence may be such that the at least one additional list element of the list of security keys is a security key generated, particularly by the master node, using the at least one additional list element of the list of key counter values. By transmitting the at least one additional list element of the list of security keys to the at least one target secondary node, the list of security keys of the at least one target SN may be kept consistent with the list of key counter values ​​processed by the UE. Furthermore, it may be possible to prevent the number of list elements of the list of security keys from reaching an extremely low value, particularly zero. Therefore, it may be possible to maintain the ability of the UE to perform CPAC or CHO towards the SCG associated with the at least one target SN.

[0072] In an exemplary embodiment of the second exemplary aspect, the key counter information transmitted to the user equipment may comprise a key counter value and instructions for maintaining the key counter value, whereby a particularly simple derivation of the first key counter value from the key counter information may be achieved, such that e.g. complex calculation operations are not required and respective processor resources are saved.

[0073] In an exemplary embodiment of the second exemplary aspect, the master node may comprise a gNB-CU-CP node. The gNB-CU-CP node may comprise at least one processor and at least one memory, and instructions may be stored in the at least one memory of the gNB-CU-CP node for execution by the at least one processor of the gNB-CU-CP node. As used herein, the gNB-CU-CP node may be understood as a logical node that hosts the RRC and Packet Data Convergence Protocol (PDCP) control plane portions of the gNB Central Unit (gNB-CU) of the en-gNB or gNB.

[0074] In an exemplary embodiment of the second exemplary aspect, the configuration information may further comprise information indicating at least one target secondary cell for which generating a security key is not required, thereby avoiding unnecessary derivation of key counter values ​​from key counter information, unnecessary generation of security keys, and / or unnecessary processing of key counter information, as already described in the context of the first exemplary aspect.

[0075] According to a second exemplary aspect, a respective method is also disclosed. The method according to the second exemplary aspect may be performed by a master node of a radio access network. The master node may be configured to support dual connection operation to a secondary node of the radio access network and a user equipment. The method includes at least: - establishing a connection to a user equipment; transmitting configuration information to the user equipment, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes. In the second exemplary aspect, disclosure of any instructions that, when executed by at least one processor of the master node, cause the master node to perform an action shall also be deemed a disclosure of the respective action of the method.

[0076] According to the second exemplary aspect, a respective apparatus is also disclosed. The apparatus according to the second exemplary aspect may include means for performing the method according to the second exemplary aspect. In the second exemplary aspect, disclosure of any method action shall also be considered as disclosure of means for performing the respective method action. Similarly, disclosure of any means for performing a method action shall also be considered as disclosure of the method action itself. The apparatus according to the second exemplary aspect may be a master node. The master node may be configured to support dual connection operation to a secondary node of a radio access network and a user equipment.

[0077] The means or functions of the master node according to the second exemplary aspect can be implemented in hardware and / or software. They may comprise one or more modules or units providing the respective functions. They may comprise, for example, at least one processor for executing computer program code to perform the required functions, at least one memory for storing the program code, or both. Alternatively, they may comprise circuitry designed to perform the required functions, for example, embodied in a chipset or chip such as an integrated circuit. In general, the means may comprise, for example, one or more processing means or processors.

[0078] According to a second exemplary aspect, a respective non-transitory computer-readable medium is also disclosed. The non-transitory computer-readable medium according to the second exemplary aspect may comprise program instructions that, when executed by a master node, cause the master node to perform at least a method according to the second exemplary aspect. The master node may be configured to support dual connection operation to a secondary node of a radio access network and to user equipment.

[0079] The non-transitory computer-readable medium according to the second exemplary embodiment may be, for example, a disk or a memory. The program instructions may be stored in the computer-readable medium in the form of instructions encoding the computer-readable medium. The computer-readable medium may be intended to participate in the operation of a device, such as an internal or external memory, such as a computer read-only memory (ROM) or a hard disk, or may be intended for distribution of a program, such as an optical disk.

[0080] According to a second exemplary aspect, a respective computer program is also disclosed. The computer program according to the second exemplary aspect may comprise instructions that, when executed by a master node, cause the master node to perform at least a method according to the second exemplary aspect. The master node may be configured to support dual connection operation to a secondary node of a radio access network and to user equipment.

[0081] The computer program according to the second exemplary embodiment may be stored on a computer-readable storage medium, in particular a tangible and / or non-transitory computer-readable storage medium, in particular a computer program according to the second exemplary embodiment may be stored on a non-transitory computer-readable medium according to the second exemplary embodiment.

[0082] According to a third exemplary aspect, a secondary node of a radio access network is disclosed. The secondary node may be configured to support dual connection operation to a master node of the radio access network and to a user equipment. The secondary node may include at least one processor and at least one memory. The at least one memory, when executed by the at least one processor, may provide the secondary node with at least: receiving request information from a master node, the request information comprising a list of at least two different security keys. This may enable the secondary node to exchange data securely with the user equipment after the user equipment has performed a CPAC or CHO towards the SCG associated with the secondary node, in particular as already explained in the context of the second exemplary aspect. Furthermore, a particular advantage of the SN receiving a list of at least two different security keys is that it allows the SN to autonomously select a security key from the list when a CPAC or CHO has been performed towards the SCG associated with the SN, thereby avoiding further involvement of the MN, in particular an SN modification procedure by the MN. Furthermore, the time requirement for preparing a target SN for a CPAC or CHO execution is reduced, thus further significantly improving the fast mobility of UEs between different SCGs.

[0083] In an exemplary embodiment of the third exemplary aspect, the at least one memory, when executed by the at least one processor, provides the secondary node with at least: - determining whether the user equipment has established or is about to establish a connection to a secondary node; - in response to determining that the user equipment has established or is about to establish a connection to the secondary node, using a current first list element in the list of security keys for integrity protection and / or encryption of data exchanged between the secondary node and the user equipment. This may enable a secure exchange of data between the UE and the SN, in particular in accordance with the security architecture of the 5G standard.

[0084] In an exemplary embodiment of the third exemplary aspect, the at least one memory, when executed by the at least one processor, provides the secondary node with at least: The device may further store instructions to cause the device to transmit information indicative of the security key switch to the master node. This allows the MN to also track the occurrence of security key switches, and thus e.g. CPAC or CHO, and take action to ensure that security key management between the UE and the SN is maintained, as already explained in the context of the second exemplary aspect.

[0085] In an exemplary embodiment of the third exemplary aspect, the at least one memory, when executed by the at least one processor, provides the secondary node with at least: The method may further store instructions to cause the deletion of the current first list element from the list of security keys. Deleting the current first list element from the list of security keys may be performed, for example, in response to using the current first list element in the list of security keys for integrity protection and / or encryption of data exchanged between the secondary node and the user equipment, or in response to sending information indicating a security key switch to the master node. Deleting the current first list element from the list of security keys may cause the list of security keys of the SN to be consistent with the list of key counter values ​​processed by the UE.

[0086] In an exemplary embodiment of the third exemplary aspect, the at least one memory, when executed by the at least one processor, provides the secondary node with at least: The method may further store instructions to: receive, from the master node, an instruction to delete the current first list element from the list of security keys. This allows the secondary node to modify its list of security keys, as already described in the context of the second exemplary aspect, so that the SN's list of security keys is consistent with the list of key counter values ​​processed by the UE.

[0087] In an exemplary embodiment of the third exemplary aspect, the at least one memory, when executed by the at least one processor, provides the secondary node with at least: The method may further store instructions to cause the deletion of the current first list element from the list of security keys. The deleting of the current first list element from the list of security keys may be performed in response to receiving, from the master node, an instruction to delete the current first list element from the list of security keys. Deleting the current first list element from the list of security keys may cause the list of security keys of the SN to be consistent with the list of key counter values ​​processed by the UE.

[0088] In an exemplary embodiment of the third exemplary aspect, the at least one memory, when executed by the at least one processor, provides the secondary node with at least: The method may further store instructions to receive, from the master node, at least one additional list element of the list of security keys. For example, at least one additional list element of the list of security keys received by the secondary node from the master node may correspond to at least one additional list element of the list of key counter values ​​transmitted from the master node to the user equipment. For example, the correspondence may be such that the at least one additional list element of the list of security keys is a security key generated, particularly by the master node, using the at least one additional list element of the list of key counter values. Receiving the at least one additional list element of the list of security keys from the master node may similarly ensure that the list of security keys of the SN remains consistent with the list of key counter values ​​processed by the UE, particularly when the MN transmits the at least one additional list element of the list of key counter values ​​to the UE. Furthermore, it may be possible to prevent the number of list elements of the list of security keys from reaching an extremely low value, particularly zero. This may also maintain the UE's ability to perform CPAC or CHO toward the SCG associated with the SN.

[0089] According to a third exemplary aspect, a respective method is also disclosed. The method according to the third exemplary aspect may be performed by a secondary node of a radio access network. The secondary node may be configured to support dual connection operation to a master node of the radio access network and to a user equipment. The method includes at least: receiving request information from the master node, the request information comprising a list of at least two different security keys. In the third exemplary aspect, disclosure of any instructions that, when executed by at least one processor of a secondary node, cause the secondary node to perform an action shall also be deemed a disclosure of the respective action of the method.

[0090] According to the third exemplary aspect, a respective apparatus is also disclosed. The apparatus according to the third exemplary aspect may include means for performing the method according to the third exemplary aspect. In the third exemplary aspect, disclosure of any method action shall also be considered as disclosure of means for performing the respective method action. Similarly, disclosure of any means for performing a method action shall also be considered as disclosure of the method action itself. The apparatus according to the third exemplary aspect may be a secondary node. The secondary node may be configured to support dual connection operation to a master node of a radio access network and to a user equipment.

[0091] The means or functions of the secondary node according to the third exemplary aspect can be implemented in hardware and / or software. They may comprise one or more modules or units providing the respective functions. They may comprise, for example, at least one processor for executing computer program code for performing the required functions, at least one memory for storing the program code, or both. Alternatively, they may comprise circuits designed to perform the required functions, for example, embodied in a chipset or chip such as an integrated circuit. In general, the means may comprise, for example, one or more processing means or processors.

[0092] According to a third exemplary aspect, a respective non-transitory computer-readable medium is also disclosed. The non-transitory computer-readable medium according to the third exemplary aspect may comprise program instructions that, when executed by a secondary node, cause the secondary node to perform at least a method according to the third exemplary aspect. The secondary node may be configured to support dual-connection operation to a master node of a radio access network and to user equipment.

[0093] The non-transitory computer-readable medium according to the third exemplary aspect may be, for example, a disk or a memory. The program instructions may be stored in the computer-readable medium in the form of instructions encoding the computer-readable medium. The computer-readable medium may be intended to participate in the operation of a device, such as an internal or external memory, such as a computer read-only memory (ROM) or a hard disk, or may be intended to distribute the program, such as an optical disk.

[0094] According to a third exemplary aspect, a respective computer program is also disclosed. The computer program according to the third exemplary aspect may comprise instructions that, when executed by a secondary node, cause the secondary node to perform at least a method according to the third exemplary aspect. The secondary node may be configured to support dual connection operation to a master node of a radio access network and to a user equipment.

[0095] The computer program according to the third exemplary aspect may be stored on a computer-readable storage medium, in particular a tangible and / or non-transitory computer-readable storage medium, in particular a computer program according to the third exemplary aspect may be stored on a non-transitory computer-readable medium according to the third exemplary aspect.

[0096] It should be understood that the representations of the embodiments disclosed herein are intended to be illustrative and not limiting.

[0097] Other features of the present disclosure will become apparent from the following detailed description considered in conjunction with the accompanying drawings. It should be understood, however, that the drawings are designed for illustrative purposes only and do not define the limits of the present disclosure, for which reference should be made to the appended claims. It should also be understood that the drawings are not drawn to scale and that they are intended only to conceptually illustrate the structures and procedures described herein.

[0098] Some example embodiments will now be described with reference to the accompanying drawings. [Brief explanation of the drawings]

[0099] [Figure 1] FIG. 1 is a schematic diagram illustrating an exemplary wireless environment in which exemplary embodiments of the present disclosure may be implemented. [Figure 2] 1 shows an exemplary embodiment of a method according to the first, second and third aspects in a signaling flow chart. [Figure 3] 1 shows an exemplary embodiment of the method according to the first and second aspects in a signaling flow chart. [Figure 4] 1 shows, in a schematic block diagram, an exemplary embodiment of a user equipment according to a first aspect; [Figure 5] FIG. 1 shows, in a schematic diagram, an exemplary embodiment of a wireless node, such as a master node or a secondary node, according to the second or third aspect. [Figure 6] In a schematic diagram, examples of tangible and non-transitory computer-readable storage media are shown. DETAILED DESCRIPTION OF THE INVENTION

[0100] The following description will aid in the understanding of the present disclosure and is intended to complement and be read in conjunction with the description of exemplary embodiments of the present disclosure set forth in the Summary section herein above.

[0101] An example of a wireless environment to which the present invention may be applied will be described below with reference to Figure 1. The specific wireless system in the following example is a 5G system, but this is merely an unrealistic example.

[0102] 1 illustrates a user equipment (UE) 101 as an example of a UE according to a first exemplary aspect, a master node (MN) 102 as an example of an MN according to a second exemplary aspect, and a source secondary node (S-SN) 103, a first target secondary node (T-SN1) 104, and a second target secondary node (T-SN2) 105 as examples of SNs according to a third exemplary aspect. The MN 102, the S-SN 103, the T-SN1 104, and the T-SN2 105 may together establish a wireless communication system or network serving a geographic area in which the UE 101 is located. The UE 101, the MN 102, and the SNs 103, 104, and 105 may operate in a dual connection mode.

[0103] The UE 101 may be connected to the MN 102 and one or more of the SNs 103, 104, 105 by wireless links (not shown), which may correspond to, for example, a 5G / NR Uu interface. The MN 102 may be connected to one or more of the SNs 103, 104, 105 by wireless links (not shown), which may correspond to, for example, a 5G / NR Xn interface. The wireless links may enable transmission and / or reception of information and / or signals between the respective devices.

[0104] At some point in time, the UE 101 moves from a first location to a second location, as indicated by arrow 110. At the first location, the UE may have been served by a serving cell associated with S-SN 103, while at the second location, the UE may be served by a cell associated with T-SN1 104. Thus, while the UE 101 is moving along arrow 110, a CPAC or CHO of the UE 101 from S-SN 103 to T-SN1 104 may have been performed.

[0105] 2, a signaling flowchart of an exemplary embodiment of the method according to the first, second, and third aspects is shown. More specifically, a sequence of actions and signaling is shown between a user equipment (UE) 201, a master node (MN) 202, a source secondary node (S-SN) 203, a first target secondary node (T-SN1) 204, and a second target secondary node (T-SN2) 205. The UE 201, MN 202, and SNs 203, 204, and 205 may typically operate in dual connectivity mode.

[0106] At specific times indicated by 210a, 210b, and 210c, the UE 201 establishes a connection to the MN 202 and is then connected to the MN 202. Furthermore, the UE 201 is connected to the S-SN 203 and is served by a serving cell associated with the S-SN 203. The UE 201, the MN 202, and the S-SN 203 are operating in a dual connection mode with each other.

[0107] Within action 211, the UE 201 transmits first status information to the MN 202. In this exemplary embodiment, the first status information comprises measurement information related to measurements of signal strength of one or more SNs, in particular the S-SN 202.

[0108] In action 212, the MN 202 determines to configure selective activation of the T-SN1 204 and the T-SN2 205 based on the first status information received from the UE 201. Furthermore, the MN 202 determines the security key K SN A list of SN counter values ​​of, SN Generate a list of security keys, where the SN counter value constitutes a non-limiting example of a key counter value according to the present disclosure, and the security key K SN constitute a non-limiting example of a security key according to the present disclosure. In this particular exemplary embodiment, a list of three different SN counter values, as well as three different corresponding K SN A list of security keys is generated. However, this is merely a non-limiting example, and in general both lists may have fewer or more list elements. In this particular exemplary embodiment, K SN The first, second, and third Ks in the list of security keys SN The security key is calculated using the first, second, and third elements in the list of SN counter values, respectively, thus K SN The first (second, third) K in the list of security keys SN The security key corresponds to the first (second, third) SN counter value in the list of SN counter values. In general, however, the correspondence between both lists may also be different.

[0109] In action 213, the MN 202 sends request information to the T-SN1 204, where the request information comprises a request to add or change an SN. Further, the request information includes the K generated in action 212. SN A list of security keys is provided.

[0110] In action 214, the MN 202 also sends request information to the T-SN2 205, where the request information also comprises a request to add or change the SN. Further, the request information also comprises the K generated in action 212. SN A list of security keys is provided.

[0111] In action 215, the MN 202 transmits configuration information to the UE 201, where the configuration information comprises an RRC reconfiguration request along with CPAC or CHO configuration information for each of T-SN1 204 and T-SN2 205. In particular, the configuration information comprises a list of SN counter values ​​generated in action 212. Because the list of SN counter values ​​defines a sequence of key counter values, more precisely, three different key counter values ​​in this particular, non-limiting, exemplary embodiment, the list of SN counter values ​​constitutes an example of key counter information according to the present disclosure.

[0112] The following describes the first CPAC or CHO performed by the UE 201.

[0113] In action 230, UE 201 determines whether the CPAC or CHO requirements for one or more possible target SNs are satisfied. In response to determining that the CPAC or CHO requirements for T-SN1 204 are satisfied, UE 201 derives a first SN counter value by selecting a first element in a list of SN counter values. In this context, the list of key counter values ​​is advantageous in that it allows for the derivation of the first SN counter value in a particularly simple manner, resulting in, for example, no complex calculation operations being required and respective processor resources being saved. UE 201 then derives a first K SN counter value for T-SN1 204 using the first SN counter value as a freshness input. SN Calculate the security key.

[0114] In action 231, the UE 201 transmits second status information to the MN 202. In this exemplary embodiment, the second status information indicates completion of the RRC reconfiguration. After transmitting the second status information, the UE 201 may attempt to establish a connection to the T-SN1 204.

[0115] Within action 232, the MN 202 transmits third status information to the T-SN1 204. In this exemplary embodiment, the third status information indicates completion of the reconfiguration, in particular the RRC reconfiguration of the UE 201.

[0116] In action 233, the T-SN1 204 determines whether the UE 201 is attempting to establish a connection to the T-SN1 204. In response to determining that the UE 201 is attempting to establish a connection to the T-SN1 204, the T-SN1 204 stores its K received from the MN 202 in action 213 in preparation for subsequent data exchange. SN The first K in the list of security keys SN Select a security key.

[0117] In action 234, the UE 201 and the T-SN1 204 establish a connection. In this particular exemplary embodiment, the connection is established by the UE 201 initiating a random access procedure over the RACH towards the T-SN1 204. After establishing the connection, the UE 201 and the T-SN1 204 use a first K SN The UE 201 uses the security key to exchange data with each other. The UE 201 calculates this first K by using the first SN counter value as a freshness input. SN Although the security key is obtained, T-SN1 204 does not SN Select the first list element in the list of security keys to find this first K SN In this particular exemplary embodiment, the UE 201 and the T-SN1 204 have obtained a first K SNA total of four subordinate security keys are calculated based on the security key. The first subordinate security key is used for integrity protection of the RRC signaling. The second subordinate security key is used for encryption of the RRC signaling. The third subordinate security key is used for integrity protection of user data. The fourth subordinate security key is used for encryption of user data. By establishing a connection and exchanging data, the UE 201 may then be served by a serving cell associated with the T-SN1 204. The UE 201, the MN 202, and the T-SN1 204 may be operating in a dual connection mode with each other.

[0118] In action 235, the UE 201 processes the list of SN counter values ​​by deleting the first element in the list. Thus, the previous second element in the list of SN counter values ​​becomes the new first element, the previous third element becomes the new second element, etc. However, it is generally contemplated that the first element in the list will not be deleted entirely, but rather will simply be modified, for example, to become an empty list element or marked as unavailable. By processing the list of SN counter values, the UE 201 may, at a later point in time, create a second K element for data exchange with a second target SN. SN A second SN counter value can be derived from the list of processed SN counter values ​​to generate a security key. In this context, the second target SN may be T-SN2 205 or S-SN 203. Thus, the UE 201 can derive the K of the CPAC or CHO towards the SCG associated with the second target SN without the MN 202 having to send new configuration information for this CPAC or CHO. SN The updates can be performed autonomously, which may reduce the RRC signaling overhead and significantly improve the fast mobility of the UE 201 between different SCGs.

[0119] In action 236, the T-SN1 204 transmits information indicating a key switch to the MN 202. In this particular example, the key switch indicates a first K key to be used for integrity protection and / or encryption of data exchanged between the UE 201 and the T-SN1 204. SN This is the switch to the security key.

[0120] Within action 237, the T-SN1 204 may generate a first K SN In response to using a security key, SN The first K from the list of security keys SN Delete the security key. SN The previous second element in the list of security keys becomes the new first element, and the previous third element becomes the new second element. However, it is generally expected that the first element in the list will not be deleted entirely, but will simply be modified, for example, to become an empty list element or marked as unavailable. SN By deleting the security key, you can remove the T-SN1 204 K SN The list of security keys may be made consistent with the list of SN counter values ​​processed by the UE 201.

[0121] In action 238, the MN 202 receives the K received from the MN 202 in action 214. SN The first K in the list of security keys SN A command to delete the security key is sent to the T-SN2 205.

[0122] In action 239, the T-SN2 205, in response to receiving the respective command from the MN 202, SN The first K in the list of security keys SN Delete the security key. SNThe previous second element in the list of security keys becomes the new first element, and the previous third element becomes the new second element. However, it is generally expected that the first element in the list will not be deleted entirely, but will simply be modified, for example, to become an empty list element or marked as unavailable. SN By deleting the security key, you can remove the T-SN2 205 K SN The list of security keys is T-SN1 204 K SN It may be possible to maintain consistency with the list of security keys and with the list of SN counter values ​​processed by the UE 201.

[0123] The following describes the second CPAC or CHO performed by the UE 201.

[0124] In action 250, UE 201 determines whether the CPAC or CHO requirements for one or more possible target SNs are satisfied. In response to determining that the CPAC or CHO requirements for T-SN2 205 are satisfied, UE 201 derives a second SN counter value by selecting the current first element in the list of SN counter values. In this context, the list of key counter values ​​is advantageous in that it allows for the derivation of the second SN counter value in a particularly simple manner, resulting in, for example, no complex calculation operations being required and respective processor resources being saved. UE 201 then derives a second SN counter value for T-SN2 205 using the second SN counter value as a freshness input. SN Calculate the security key.

[0125] In action 251, the UE 201 transmits fourth status information to the MN 202. In this exemplary embodiment, the fourth status information indicates completion of the RRC reconfiguration. After transmitting the fourth status information, the UE 201 may attempt to establish a connection to the T-SN2 205.

[0126] Within action 252, the MN 202 transmits fifth status information to the T-SN2 205. In this exemplary embodiment, the fifth status information indicates completion of the reconfiguration, in particular the RRC reconfiguration of the UE 201.

[0127] Within action 253, T-SN2 205 determines whether UE 201 is attempting to establish a connection to T-SN2 205. In response to determining that UE 201 is attempting to establish a connection to T-SN2 205, T-SN2 205 may configure its K SN The current first key in the list of security keys SN Select a security key. This current first K SN The security key is the original K received from the MN 202 in action 214. SN The second K in the list of security keys SN It is the same as the security key.

[0128] In action 254, the UE 201 and the T-SN2 205 establish a connection. In this particular exemplary embodiment, the connection is established by the UE 201 initiating a random access procedure towards the T-SN2 205 via the RACH. After establishing the connection, the UE 201 and the T-SN2 205 use a second K SN The UE 201 exchanges data with each other using the security key. The UE 201 calculates this second K by using the second SN counter value as a freshness input. SN Although the security key is obtained, T-SN1 204 does not SN This second K is chosen by selecting the current first list element in the list of security keys. SN In this particular exemplary embodiment, the UE 201 and the T-SN2 205 have obtained a second K SNA total of four subordinate security keys are calculated based on the security key. The first subordinate security key is used for integrity protection of the RRC signaling. The second subordinate security key is used for encryption of the RRC signaling. The third subordinate security key is used for integrity protection of user data. The fourth subordinate security key is used for encryption of user data. By establishing a connection and exchanging data, the UE 201 may then be served by a serving cell associated with the T-SN2 205. The UE 201, the MN 202, and the T-SN2 205 may be operating in a dual connection mode with each other.

[0129] In action 255, UE 201 further processes the list of SN counter values ​​by deleting the current first element in the list. In this way, the previous second element in the list of SN counter values ​​becomes the new first element. However, it is generally contemplated that the current first available element in the list will not be deleted entirely, but will simply be modified, for example, to become an empty list element or marked as unavailable. By further processing the list of SN counter values, UE 201 may identify additional Ks for data exchange with additional target SNs at a later point in time. SN Further SN counter values ​​can be derived from the list of further processed SN counter values ​​to generate security keys. In this context, the further target SN may be T-SN1 204, S-SN 203, or an additional T-SN not shown in Figure 2. Thus, the UE 201 can retrieve the K of the CPAC or CHO towards the SCG associated with the further target SN without the MN 202 having to send new configuration information for this CPAC or CHO. SN The refresh can be performed autonomously, which may reduce the RRC signaling overhead and greatly improve the fast mobility of the UE 201 between different SCGs.

[0130] In action 256, the T-SN2 205 transmits information indicating a key switch to the MN 202. In this particular example, the key switch is a second K key used for integrity protection and / or encryption of data exchanged between the UE 201 and the T-SN2 205. SN This is the switch to the security key.

[0131] Within action 257, the T-SN2 205 uses this K for integrity protection and / or encryption of data exchanged between the UE 201 and the T-SN2 205. SN In response to using a security key, the current first K key from the list of security keys is SN Delete the security key. SN The previous second element in the list of security keys becomes the new first element. However, it is generally expected that the current first available element in the list will not be completely deleted, but will simply be modified, for example, to become an empty list element or marked as unavailable. SN By deleting the security key, you can remove the T-SN2 205 K SN The list of security keys may be made consistent with the list of SN counter values ​​processed by the UE 201.

[0132] In action 258, the MN 202 receives the K received from the MN 202 in action 213. SN The current first key in the list of security keys SN A command to delete the security key is sent to T-SN1 204.

[0133] In action 259, the T-SN1 204, in response to receiving the respective command from the MN 202, updates the current first K in its list of security keys. SN Delete the security key. SNThe previous second element in the list of security keys becomes the new first element. However, it is generally expected that the current first available element in the list will not be completely deleted, but will simply be modified, for example, to become an empty list element or marked as unavailable. SN By deleting the security key, you can remove the T-SN1 204 K SN The list of security keys is T-SN2 205 K SN This may be consistent with the list of security keys and with the list of SN counter values ​​that are further processed by the UE 201.

[0134] Although not shown in FIG. 2, the UE 201 may perform additional CPACs or CHOs similar to the first and second CPACs or CHOs described above.

[0135] At any appropriate time, in particular, one or more of the UE 201 or T-SN1 204 and T-SN2 205 may generate a list of SN counter values, or K SN After it is determined that the list of security keys is below a predefined threshold, the UE 201 or one or more of the T-SN1 204 and T-SN2 205 may transmit the respective information to the MN 202. The list of SN counter values, or K, respectively, may be transmitted to the MN 202. SN In response to receiving information indicating that the list of security keys is below a threshold, the MN 202 transmits at least one additional list element of the list of SN counter values ​​to the UE 201, and SN At least one additional list element of the list of security keys may be sent to SN1 204 and / or T-SN2 205, which may maintain the UE's ability to perform CPAC or CHO towards the SCG associated with the target SN.

[0136] 3 shows a signaling flowchart of an exemplary embodiment of the method according to the first and second aspects. More specifically, a sequence of actions and signaling is shown between a user equipment (UE) 301, a master node (MN) 302, a source secondary node (S-SN) 303, a first target secondary node (T-SN1) 304, and a second target secondary node (T-SN2) 305. The UE 301, the MN 302, and the SNs 303, 304, and 305 may typically operate in a dual-connection mode.

[0137] At specific times indicated by 310a, 310b, and 310c, UE 301 establishes a connection to MN 302 and is then connected to MN 302. Furthermore, UE 301 is connected to S-SN 303 and is served by a serving cell associated with S-SN 303. UE 301, MN 302, and S-SN 303 are operating in a dual connection mode with each other.

[0138] In action 311, the S-SN 303 transmits first status information to the MN 302. In this exemplary embodiment, the first status information indicates that a CPAC or a CHO is required.

[0139] Within action 312, the MN 302 sends request information to the T-SN1 304. In this exemplary embodiment, the request information comprises a request to add or change an SN.

[0140] In action 313, T-SN1 304 sends second status information to MN 302. In this exemplary embodiment, the second status information indicates confirmation of the SN addition or modification request.

[0141] Within action 314, the MN 302 sends request information to the T-SN2 305. In this exemplary embodiment, the request information comprises a request to add or change an SN.

[0142] In action 315, T-SN2 305 sends third status information to MN 302. In this exemplary embodiment, the third status information indicates confirmation of the SN addition or modification request.

[0143] In action 316, the MN 302 sends configuration information to the UE 301, where the configuration information comprises an RRC reconfiguration request together with the respective CPAC or CHO configuration information. In particular, the configuration information includes the security key K SNの The method comprises: an SN counter value and instructions for maintaining the SN counter value, i.e., for continuously processing the SN counter value rather than releasing it, where the SN counter value constitutes an example of a key counter value according to the present disclosure; SN constitutes an example of a security key in accordance with the present disclosure. Furthermore, the SN counter value, together with instructions for maintaining the SN counter value, constitutes an example of key counter information in accordance with the present disclosure, thereby providing at least two different K SN This is because a sequence of at least two different SN counter values ​​for generating security keys is defined, as will be explained in more detail below. A particular advantage of the configuration information comprising SN counter values ​​and instructions for maintaining the SN counter values ​​is that the possible target SNs can be set to multiple K SN Security keys do not need to be pre-provisioned. In action 317, the UE 301 transmits the fourth status information to the MN 302. In this exemplary embodiment, the fourth status information indicates the completion of the RRC reconfiguration.

[0144] In the following, the first CPAC or CHO performed by the UE 301 will be described.

[0145] Within action 330, UE 301 determines whether the CPAC or CHO requirements for one or more possible target SNs are met.

[0146] In action 331, the UE 301 determines that the CPAC or CHO requirement for T-SN1 304 is satisfied. In response to determining that the CPAC or CHO requirement for T-SN1 304 is satisfied, the UE 301 derives a first SN counter value by using the SN counter value received from the MN 302 in action 316 as the first SN counter value. In this context, the SN counter information received from the MN 302 in action 316 comprising the SN counter value and instructions for maintaining the SN counter value may enable a particularly simple derivation of the first SN counter value, such that, for example, complex calculation operations are not required and respective processor resources are saved.

[0147] In action 332, the UE 301 uses the derived first SN counter value as a freshness input to calculate the first K of T-SN1 304. SN Calculates a security key. Furthermore, UE301 processes the SN counter information by adding a predefined step value, here specifically a step value of 1, to the SN counter value received from the master node. In other words, UE301 increments the SN counter by the step value, which in this particular non-limiting example is equal to 1. However, in general, a step value different from 1 is easily conceivable. By adding the predefined step value to the SN counter value received from the master node, a second element in the sequence of SN counter values ​​is obtained. In this way, UE301 can obtain a second K element for data exchange with a second target SN at a later point in time. SN A second SN counter value can be derived from the processed SN counter to generate a security key. In this context, the second target SN may be T-SN2 305 or S-SN 303. Thus, the UE 301 can derive the K of the CPAC or CHO towards the SCG associated with the second target SN without the MN 302 needing to send new configuration information for this CPAC or CHO. SNThe refresh can be performed autonomously, which may reduce the RRC signaling overhead and significantly improve the fast mobility of the UE 301 between different SCGs.

[0148] In action 333, the UE 301 transmits the fifth status information to the MN 302. In this exemplary embodiment, the fifth status information indicates CPAC or CHO toward the T-SN1 304.

[0149] In action 334, the MN 302 transmits further request information to the T-SN1 304. In this exemplary embodiment, the further request information comprises an SN modification request, and includes the first K SN Comes with a security key.

[0150] In action 335, the T-SN1 304 sends the sixth status information to the MN 302. In this exemplary embodiment, the sixth status information indicates confirmation of the SN modification request.

[0151] In action 336, the MN 302 transmits seventh status information to the S-SN 303. In this exemplary embodiment, the seventh status information indicates a CPAC or CHO, specifically a CPAC or CHO, directed to the T-SN1 304.

[0152] In action 337, the MN 302 sends the eighth status information to the T-SN1 304. In this exemplary embodiment, the eighth status information indicates the completion of the SN modification.

[0153] In action 338, the UE 301 and the T-SN1 304 establish a connection. The UE 301 and the T-SN1 304 use a first K SN In this particular exemplary embodiment, the UE 301 and the T-SN1 304 use a first security key to exchange data with each other. SNA total of four subordinate security keys are calculated based on the security key. The first subordinate security key is used for integrity protection of RRC signaling. The second subordinate security key is used for encryption of RRC signaling. The third subordinate security key is used for integrity protection of user data. The fourth subordinate security key is used for encryption of user data. By establishing a connection and exchanging data, the UE 301 can then be served by the serving cell associated with the T-SN1 304, thus completing the CPAC or CHO. The UE 301, the MN 302, and the T-SN1 304 may be operating in dual connection mode with each other.

[0154] The following describes the second CPAC or CHO performed by the UE 301.

[0155] Within action 350, the UE 301 determines whether the CPAC or CHO requirements for one or more possible target SNs are met.

[0156] In action 351, the UE 301 determines that the requirement for a CPAC or CHO to be returned to the S-SN 303 is satisfied. In response to determining that the requirement for a CPAC or CHO to be returned to the S-SN 303 is satisfied, the UE 301 derives a second SN counter value by using the current SN counter value, i.e., the SN counter value received from the MN 302, plus one as the second SN counter value. In this context, the SN counter information received from the MN 302 in action 316 comprising the SN counter value and instructions for maintaining the SN counter value may enable a particularly simple derivation of the second SN counter value, such that, for example, complex calculation operations are not required and respective processor resources are saved.

[0157] In action 352, the UE 301 uses the derived second SN counter value as a freshness input to determine the second K of the S-SN 303. SNUE301 further processes the SN counter information by again adding the predefined step value to the current SN counter value. In other words, UE301 again increments the SN counter by the step value, which in this particular, non-limiting example, is equal to 1. By adding the predefined step value to the current SN counter value, a third element in the sequence of SN counter values ​​is obtained. In this way, UE301 can obtain further K elements for data exchange with further target SNs at a later point in time. SN Further SN counter values ​​can be derived from the further processed SN counters to generate security keys. In this context, the further target SN may be T-SN1 304, T-SN2 305, or an additional T-SN not shown in Figure 3. Thus, the UE 301 can update the K of the CPAC or CHO towards the SCG associated with the further target SN without the MN 302 needing to send new configuration information for this CPAC or CHO. SN The refresh can be performed autonomously, which may reduce the RRC signaling overhead and significantly improve the fast mobility of the UE 301 between different SCGs.

[0158] In action 353, the UE 301 transmits the ninth status information to the MN 302. In this exemplary embodiment, the ninth status information indicates CPAC or CHO toward the S-SN 303.

[0159] In action 354, the MN 302 transmits further request information to the S-SN 303. In this exemplary embodiment, the further request information comprises an SN modification request, and includes a second K SN Comes with a security key.

[0160] In action 355, the S-SN 303 transmits tenth status information to the MN 302. In this exemplary embodiment, the tenth status information indicates confirmation of the SN modification request.

[0161] In action 356, the MN 302 transmits eleventh status information to the T-SN1 304. In this exemplary embodiment, the eleventh status information indicates the CPAC or CHO, particularly the CPAC or CHO, toward the S-SN 303.

[0162] In action 357, the MN 302 transmits twelfth status information to the S-SN 303. In this exemplary embodiment, the twelfth status information indicates the completion of the SN modification.

[0163] In action 358, the UE 301 and the S-SN 303 establish a connection. The UE 301 and the S-SN 303 may use a second K SN In this particular exemplary embodiment, the UE 301 and the S-SN 303 exchange data with each other using a security key. SN A total of four subordinate security keys are calculated based on the security key. The first subordinate security key is used for integrity protection of RRC signaling. The second subordinate security key is used for encryption of RRC signaling. The third subordinate security key is used for integrity protection of user data. The fourth subordinate security key is used for encryption of user data. By establishing a connection and exchanging data, the UE 301 can then be served again by a serving cell associated with the S-SN 303, thus completing CPAC or CHO. The UE 301, MN 302, and S-SN 303 may be operating in dual connection mode with each other.

[0164] Although not shown in FIG. 3, UE 301 may perform additional CPACs or CHOs similar to the first and second CPACs or CHOs described above.

[0165] In an exemplary embodiment, the key counter information provided by the reconfiguration information transmitted from the MN 302 to the UE 301 in action 316 may define a maximum allowable number of additions of a predefined step value to the SN counter value received from the master node. For example, the key counter information may provide a stop value of the SN counter that cannot be exceeded. The UE 301 may then determine whether the maximum allowable number of additions has been reached, particularly when processing or further processing the SN counter. For example, the UE 301 may determine whether the stop value has been reached. If it is determined that the maximum allowable number of additions has been reached, the UE 301 may prevent further additions of the predefined step value to the current SN counter value. Furthermore, the UE 301 may transmit the respective information to the MN 302. Through the above procedure, the number of CPACs or CHOs that may be performed by the UE 301 can be specified by the MN 302 when the MN 302 initially transmits configuration information to the UE 301, thereby limiting the number of autonomous mobility events of the UE 301.

[0166] In the exemplary embodiment described in connection with FIGS. 2 and 3, the configuration information also includes SN The UE 201, 301 may be indicated at least one target secondary cell for which security keys do not need to be generated, thereby avoiding unnecessary derivation of the SN counter value, K, especially when the UE 201, 301 moves or switches between cells in the same SCG. SN This may avoid unnecessary generation of security keys and / or unnecessary processing of key counter information.

[0167] In the exemplary embodiments described in connection with Figures 2 and 3, the MN 202, 302 may comprise a gNB-CU-CP node that performs the described actions of the MN 202, 302.

[0168] 4, there is shown a block diagram of an exemplary embodiment of a UE 400 according to a first aspect. For example, the UE 400 may be any of a smartphone, a tablet computer, a notebook computer, a smart watch, a smart band, an IoT device, and / or a vehicle.

[0169] The UE 400 comprises a processor 401. The processor 401 may represent a single processor or two or more processors, e.g., at least partially coupled, e.g., via a bus. The processor 401 executes program code stored in a program memory 402 (e.g., program code that, when executed on the processor 401, causes the UE 400 connected to the wireless node 500 to perform one or more, or portions thereof, of the method embodiments according to the present disclosure) and interfaces with a main memory 403. The program memory 402 may also include an operating system for the processor 401. Some or all of the memories 402 and 403 may also be included in the processor 401.

[0170] One or both of the main memory and program memory of a processor (e.g., program memory 402 and main memory 403) may be permanently connected to the processor (e.g., processor 401) or may be at least partially removable from the processor, for example in the form of a memory card or memory stick.

[0171] The program memory (e.g., program memory 402) may be, for example, a non-volatile memory. To name a few, the program memory may be, for example, a flash memory (or a portion thereof), a ROM, PROM, EPROM, MRAM, or FeRAM (or a portion thereof), or a hard disk (or a portion thereof). For example, the program memory may comprise a first memory section that is permanently installed and a second memory section that is removable, for example in the form of a removable SD memory card.

[0172] The main memory (e.g., main memory 403) may be, for example, a volatile memory. The main memory may be, for example, a DRAM memory, as a non-limiting example. The main memory may be used, for example, as a working memory for the processor 401 when executing an operating system, applications, programs, etc.

[0173] The processor 401 may further control a communication interface 404 (e.g., a wireless interface) configured to receive and / or transmit data and / or information. For example, the communication interface 404 may be configured to transmit and / or receive wireless signals from a wireless node, such as a master node or a secondary node, as described herein, among others. It should be understood that any computer program code-based processing necessary for receiving and / or evaluating the wireless signals may be stored in a memory of the communication interface 404 and executed by a processor of the communication interface 404, and / or it may be stored in, for example, the memory 403 and executed by, for example, the processor 401.

[0174] The communication interface 404 may be configured to communicate in accordance with a cellular communication system, such as 2G / 3G / 4G / 5G, or a future generation cellular communication system, among others. The UE 400 may use the wireless interface 404 to communicate with a wireless node, such as a master node or a secondary node, among others, as described herein.

[0175] For example, the communication interface 404 may further comprise a BLE and / or Bluetooth wireless interface including a BLE transmitter, receiver, or transceiver. For example, the wireless interface 404 may additionally or alternatively comprise a WLAN wireless interface including at least a WLAN transmitter, receiver, or transceiver.

[0176] Components 402, 403, and 404 of UE 400 may be connected to processor 401 by, for example, one or more serial and / or parallel buses.

[0177] It should be appreciated that the UE 400 may include various other components. For example, the UE 400 may optionally include a user interface (e.g., a touch-sensitive display, a keyboard, a touchpad, a display, etc.).

[0178] 5 is a block diagram of an example embodiment of a wireless node 500, such as a master node 500 or a secondary node 500. For example, the wireless node 500 may be configured to schedule and / or transmit signals to the UE 400 and / or one or more additional wireless nodes 500, as described above.

[0179] The wireless node 500 comprises a processor 501. The processor 501 may represent a single processor or two or more processors, e.g., at least partially coupled, e.g., via a bus. The processor 501 executes program code stored in a program memory 502 (e.g., program code that, when executed on the processor 501, causes the wireless node 500, alone, in conjunction with a UE 400, and / or in conjunction with one or more further wireless nodes 500, to perform one or more, or portions of, embodiments of methods according to the present disclosure) and interfaces with a main memory 503.

[0180] Program memory 502 may also include an operating system for processor 501. Some or all of memories 502 and 503 may also be included in processor 501.

[0181] Furthermore, the processor 501 may control a communication interface 504 configured to communicate according to a cellular communication system, such as a 2G / 3G / 4G / 5G cellular communication system, for example. The communication interface 504 of the wireless node 500 may be realized by, for example, a radio head and may be provided for communication between a network device and a terminal device.

[0182] Components 502, 503, and 504 of wireless node 500 may be connected to processor 501 by, for example, one or more serial and / or parallel buses.

[0183] It should be appreciated that the wireless node 500 may include various other components.

[0184] Figure 6 is a schematic diagram of example tangible and non-transitory computer-readable storage media according to the present disclosure that may be used, for example, to implement memory 402 of Figure 4 or memory 502 of Figure 5. To this end, Figure 6 illustrates a flash memory 600, which may be soldered or glued to, for example, a printed circuit board, a solid-state drive 601 comprising multiple memory chips (e.g., flash memory chips), a magnetic hard drive 602, a Secure Digital (SD) card 603, a Universal Serial Bus (USB) memory stick 604, an optical storage medium 605 (e.g., a CD-ROM or DVD), and a magnetic storage medium 606.

[0185] Connections presented in the described embodiments are to be understood in terms of the associated components being operatively coupled. As such, connections may be direct or indirect, with any number or combination of intervening elements, and may only have a functional relationship between the components.

[0186] Furthermore, the term "circuit" as used in this text refers to either: (a) a hardware-only circuit implementation (e.g., an analog and / or digital-only implementation); (b) A combination of circuitry and software (and / or firmware) that: (i) a combination of processors; or (ii) sections of processors / software (including digital signal processors), software, and memory that work together to cause a device, such as a mobile phone, to perform various functions; and (c) A circuit that requires software or firmware for its operation, even though the software or firmware is not physically present, such as a microprocessor or a section of a microprocessor.

[0187] This definition of "circuit" applies to all uses of the term in this text, including any claims. As a further example, the term "circuit" as used in this text also covers simply a processor (or processors) or part of a processor and its (or their) accompanying software and / or firmware implementation. The term "circuit" also covers, for example, a baseband integrated circuit or an application processor integrated circuit in a mobile phone.

[0188] Any processors referred to in this text are not limited to processor 401 of Figure 4 and processor 501 of Figure 5 specifically, but may be any suitable type of processor. Any processor may comprise, but is not limited to, one or more microprocessors, one or more processors with digital signal processors, one or more processors without digital signal processors, one or more special purpose computer chips, one or more field programmable gate arrays (FPGAs), one or more controllers, one or more application specific integrated circuits (ASICs), or one or more computers. The associated structure / hardware is programmed to perform the described functions.

[0189] Additionally, any of the actions or steps described or illustrated herein may be performed using executable instructions in a general-purpose or special-purpose processor and stored on a computer-readable storage medium (e.g., disk, memory, etc.) for execution by such a processor. References to a "computer-readable storage medium" should be understood to encompass specialized circuitry such as FPGAs, ASICs, signal processing devices, and other devices.

[0190] As used herein, "at least one of the following <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases where a list of two or more elements is joined by "and" or "or" mean at least any of the elements, or at least two or more of any of the elements, or at least all of the elements.

[0191] The phrase "A, or B, or C, or combinations thereof" or "at least one of A, B, and C" is not exhaustive and may be understood to include at least (i) A, or (ii) B, or (iii) C, or (iv) A and B, or (v) A and C, or (vi) B and C, or (vii) A, B, and C.

[0192] It will be understood that the embodiments disclosed herein are exemplary only, and that any feature presented with respect to a particular exemplary embodiment may be used with any aspect of the disclosure by itself, or in combination with any feature presented with the same or another particular exemplary embodiment, and / or in combination with any other feature not mentioned. Furthermore, it will be understood that any feature presented with exemplary embodiments in a particular category may be used in a corresponding manner with exemplary embodiments in any other category.

[0193] Abbreviation 3GPP 3rd Generation Partnership Project CHO Conditional Handover CPAC Conditional PSCell Addition or Change DC Dual Connection LMF location management function MCG Master Cell Group MN Master Node NAS non-access layer NR New Radio PSCell Primary cell of SCG (Primary SCG cell) RACH Random Access Channel SCG Secondary Cell Group SN Secondary Node S-SN Source Secondary Node RRC Radio Resource Control T-SN Target Secondary Node UE User Equipment

[0194] References [1]3GPP TS 36.300 V 17.1.0 "Evolved Universal Terrestrial Radio Access (E-UTRA) and Evolved Universal Terrestrial Radio Access Network (E-UTRAN); Overall description; Stage 2 (Release 17)", June 2022. [2]3GPP TS 37.340 V17.1.0 "Evolved Universal Terrestrial Radio Access (E-UTRA) and NR; Multi-connectivity; Stage 2 (Release 17)", June 2022. [3]3GPP TS 38.331 V17.1.0 "NR; Radio Resource Control (RRC) protocol specification (Release 17)2", June 2022. [4]3GPP TS 33.501 V17.6.0 "Security architecture and procedures for 5G system (Release 17)", June 2022.

Claims

1. 1. A user equipment configured to support dual connection operation to a master node and a secondary node of a radio access network, the user equipment comprising: at least one processor and at least one memory, the at least one memory, when executed by the at least one processor, providing the user equipment with at least: - establishing a connection to said master node; receiving configuration information from the master node, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes; A user device that stores instructions to execute the above.

2. The at least one memory, when executed by the at least one processor, causes the user equipment to generating a first security key using a first key counter value derived from said key counter information; - using said first security key for integrity protection and / or encryption of data exchanged between said user equipment and a first target secondary node; processing the key counter information such that the user equipment is able to derive from the processed key counter information at least a second key counter value different from the first key counter value; The user equipment of claim 1 , further storing instructions to cause the user equipment to perform at least one of the following:

3. The at least one memory, when executed by the at least one processor, causes the user equipment to generating a second security key different from the first security key using the second key counter value derived from the processed key counter information; - using the second security key for integrity protection and / or encryption of data exchanged between the user equipment and a second target secondary node different from the first target secondary node; further processing the key counter information such that the user equipment is able to derive from the further processed key counter information at least a further key counter value which is different from the first key counter value and which is also different from the second key counter value. The user equipment of claim 2 , further storing instructions to cause the user equipment to perform at least one of:

4. The user equipment of claim 1 , wherein the key counter information received from the master node defines a list of at least two different key counter values.

5. 5. The user equipment of claim 2, wherein generating the first security key comprises using a first list element in the list of key counter values ​​as the first key counter value, and processing the key counter information comprises removing the first list element from the list of key counter values.

6. 6. The user equipment of claims 3 and 5, wherein generating the second security key comprises using a current first list element in the list of key counter values ​​as the second key counter value, and further processing the key counter information comprises removing the current first list element from the list of key counter values.

7. The configuration information includes at least two different K SN providing key counter information defining a list of at least two different SN counter values ​​for generating security keys; The first key counter value is a first SN counter value, the second key counter value is a second SN counter value, and the first security key is a first K SN security key, and the second security key is a second K SN It is a security key, the configuration information further comprises a radio resource control reconfiguration request; the configuration information further comprises information related to a conditional addition or modification of a primary cell of a secondary cell group associated with the first target secondary node, or information related to a conditional handover to the first target secondary node; the configuration information further comprises information related to a conditional addition or modification of a primary cell of a secondary cell group associated with the second target secondary node, or information related to a conditional handover to the second target secondary node; The at least one memory, when executed by the at least one processor, causes the user equipment to determining whether at least one condition for a conditional addition or modification of a primary cell of a secondary cell group associated with said first target secondary node or at least one condition for a conditional handover to said first target secondary node is satisfied; and via a random access channel, SN initiating a random access procedure to the first target secondary node using a security key; determining whether at least one condition for a conditional addition or modification of a primary cell of a secondary cell group associated with the second target secondary node or at least one condition for a conditional handover to the second target secondary node is satisfied; and via a random access channel, SN initiating a random access procedure to the second target secondary node using a security key; The user equipment of claim 6 , further storing instructions to cause the user equipment to perform at least one of:

8. The at least one memory, when executed by the at least one processor, causes the user equipment to 5. The user equipment of claim 4, further storing instructions to cause the user equipment to receive at least one additional list element of the list of key counter values ​​from the master node.

9. 10. The user equipment of claim 1, wherein the key counter information received from the master node comprises a key counter value and instructions for maintaining the key counter value.

10. 10. The user equipment of claims 2 and 9, wherein generating the first security key comprises using the key counter value received from the master node as the first key counter value, and processing the key counter information comprises adding a predefined step value to the key counter value received from the master node.

11. 11. The user equipment of claim 3 and 10, wherein generating the second security key comprises using a current key counter value as the second key counter value, and further processing the key counter information comprises adding the predefined step value to the current key counter value.

12. The configuration information includes at least two different K SN providing key counter information defining a sequence of at least two different SN counter values ​​for generating a security key; the key counter information received from the master node comprises an SN counter value and instructions for maintaining the SN counter value; The first key counter value is a first SN counter value, the second key counter value is a second SN counter value, and the first security key is a first K SN security key, and the second security key is a second K SN It is a security key, the configuration information further comprises a radio resource control reconfiguration request; the configuration information further comprises information related to a conditional addition or modification of a primary cell of a secondary cell group associated with the first target secondary node, or information related to a conditional handover to the first target secondary node; the configuration information further comprises information related to a conditional addition or modification of a primary cell of a secondary cell group associated with the second target secondary node, or information related to a conditional handover to the second target secondary node; The at least one memory, when executed by the at least one processor, causes the user equipment to determining whether at least one condition for a conditional addition or modification of a primary cell of a secondary cell group associated with said first target secondary node or at least one condition for a conditional handover to said first target secondary node is satisfied; and via a random access channel, SN initiating a random access procedure to the first target secondary node using a security key; determining whether at least one condition for a conditional addition or modification of a primary cell of a secondary cell group associated with the second target secondary node or at least one condition for a conditional handover to the second target secondary node is satisfied; and via a random access channel, SN initiating a random access procedure to the second target secondary node using a security key; The user equipment of claim 11 , further storing instructions to cause the user equipment to perform at least one of the following:

13. the key counter information received from the master node defines a maximum allowable number of additions of the predefined step value to the key counter value received from the master node, and the at least one memory, when executed by the at least one processor, provides the user equipment with at least: determining whether said maximum permitted number of additions has been reached; - preventing further addition of said predefined step value to said current key counter value in response to determining that said maximum allowable number of additions has been reached; The user equipment of claim 10 , further storing instructions to cause the user equipment to execute:

14. The at least one memory, when executed by the at least one processor, causes the user equipment to generating a further security key different from the first security key and different from the second security key using the further key counter value derived from the further processed key counter information; - using said further security key for integrity protection and / or encryption of data exchanged between said user equipment and a further target secondary node different from said second target secondary node; further processing the key counter information such that the user equipment is able to derive from the further processed key counter information at least one further key counter value that is different from the first key counter value, that is different from the second key counter value, and that is different from any other key counter value previously derived from the unprocessed, processed, or further processed key counter information; The user equipment of claim 3 , further storing instructions to cause the user equipment to perform at least one of the following:

15. The user equipment of claim 1 , wherein the configuration information further comprises information indicating at least one target secondary cell for which security keys do not need to be generated.

16. 1. A method performed by a user equipment configured to support dual connectivity operation to a master node and a secondary node of a radio access network, the method comprising at least: - establishing a connection to said master node; receiving configuration information from the master node, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes; A method comprising:

17. When executed by a user equipment configured to support dual connectivity operation to a master node and a secondary node of a radio access network, the method causes the user equipment to at least: - establishing a connection to said master node; receiving configuration information from the master node, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes; 1. A non-transitory computer-readable medium comprising program instructions for executing:

18. A master node of a radio access network, the master node configured to support dual connection operation to a secondary node of the radio access network and a user equipment, the master node comprising at least one processor and at least one memory, the at least one memory, when executed by the at least one processor, providing the master node with at least: - establishing a connection to said user equipment; transmitting configuration information to the user equipment, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes; A master node of a radio access network that stores instructions to execute the above.

19. 17. The master node of claim 16, wherein the key counter information transmitted to the user equipment defines a list of at least two different key counter values.

20. The at least one memory, when executed by the at least one processor, provides the master node with at least: generating a list of at least two different security keys corresponding to the list of at least two different key counter values ​​defined by the key counter information transmitted to the user equipment; sending request information to at least one target secondary node, said request information comprising said list of generated security keys; 20. The master node of claim 17, further storing instructions to cause the master node to execute:

21. The at least one memory, when executed by the at least one processor, causes the master node to: receiving information from a first target secondary node indicative of a security key switch; sending an instruction to at least one other target secondary node to delete said first list element from said list of security keys, said at least one other target secondary node being different from said first target secondary node; 20. The master node of claim 18, further storing instructions to cause it to perform at least one of:

22. The at least one memory, when executed by the at least one processor, causes the master node to: receiving information indicative of a security key switch from a second target secondary node, the second target secondary node being different from the first target secondary node; sending to at least one further target secondary node an instruction to delete said current first list element from said list of security keys, said at least one further target secondary node being different from said second target secondary node; 20. The master node of claim 19, further storing instructions to cause it to perform at least one of:

23. The at least one memory, when executed by the at least one processor, provides the master node with at least: transmitting at least one additional list element of said list of key counter values ​​to said user equipment; sending at least one additional list element of said list of security keys to at least one target secondary node; 20. The master node of claim 18, further storing instructions to cause the master node to execute:

24. 17. The master node of claim 16, wherein the key counter information transmitted to the user equipment comprises a key counter value and instructions for maintaining the key counter value.

25. The master node of claim 16, wherein the master node comprises a gNB-CU-CP node comprising at least one processor and at least one memory, and the instructions are stored in the at least one memory of the gNB-CU-CP node to be executed by the at least one processor of the gNB-CU-CP node.

26. The master node of claim 16 , wherein the configuration information further comprises information indicating at least one target secondary cell for which generating a security key is not required.

27. 1. A method performed by a master node of a radio access network, the master node being configured to support dual connectivity operation to a secondary node of the radio access network and to a user equipment, the method comprising at least: - establishing a connection to said user equipment; transmitting configuration information to the user equipment, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes; A method comprising:

28. The program instructions, when executed by a master node of a radio access network configured to support dual connectivity operations to a secondary node of the radio access network and to a user equipment, cause the master node to: - establishing a connection to said user equipment; transmitting configuration information to the user equipment, the configuration information comprising key counter information defining a sequence of at least two different key counter values ​​for generating at least two different security keys for at least two different target secondary nodes; 1. A non-transitory computer-readable medium comprising program instructions for executing:

29. A secondary node of a radio access network, the secondary node configured to support dual connection operation to a master node of the radio access network and to a user equipment, the secondary node comprising at least one processor and at least one memory, the at least one memory, when executed by the at least one processor, providing the secondary node with at least: a secondary node of the radio access network storing instructions to receive request information from said master node, said request information comprising a list of at least two different security keys;

30. The at least one memory, when executed by the at least one processor, causes the secondary node to determining whether the user equipment has established or is about to establish a connection to the secondary node; - in response to the user equipment determining that it has established or is about to establish a connection to the secondary node, using a current first list element in the list of security keys for integrity protection and / or encryption of data exchanged between the secondary node and the user equipment; sending information indicative of a security key switch to said master node; - removing said current first list element from said list of security keys; 28. The secondary node of claim 27, further storing instructions to cause it to perform at least one of:

31. The at least one memory, when executed by the at least one processor, causes the secondary node to receive at least: receiving an instruction from the master node to remove the current first list element from the list of security keys; - removing said current first list element from said list of security keys; 28. The secondary node of claim 27, further storing instructions to cause it to execute:

32. The at least one memory, when executed by the at least one processor, causes the secondary node to receive at least:

28. A secondary node according to claim 27, further storing instructions to cause it to receive from said master node at least one additional list element of said list of security keys.

33. 1. A method performed by a secondary node of a radio access network, the secondary node being configured to support dual connectivity operation to a master node of the radio access network and to a user equipment, the method comprising at least: receiving request information from the master node, the request information comprising a list of at least two different security keys.

34. The program instructions, when executed by a secondary node of a radio access network, are configured to support dual connectivity operation to a master node of the radio access network and to a user equipment, and cause the secondary node to receive at least: a non-transitory computer-readable medium comprising program instructions to cause receiving request information from the master node, the request information comprising a list of at least two different security keys.

Citation Information

Patent Citations

  • Determining security keys

    WO2021064032A1

  • Method, device and computer storage medium of communication

    WO2023155103A1