Security handling of switching from 5GS to EPC
By addressing inconsistencies in security context mapping and integrity protection during transitions between 5G and EPC, the solution ensures reliable communication by modifying the handling of TAU request message repetitions and integrity protection, enhancing mobility support in wireless communication systems.
Patent Information
- Application Number
- JP2026086683
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-05-11
- Filing Date
- 2026-05-22
- Publication Date
- 2026-08-25
AI Technical Summary
Existing wireless communication systems face challenges in maintaining security consistency during transitions between different radio access technologies (RATs), particularly when switching from 5G to EPC, leading to potential communication failures due to inconsistencies in security context mapping and integrity protection of tracking area update (TAU) requests.
The proposed solution involves modifying how network entities handle TAU request message repetitions and integrity protection during reselection from 5G to EPC, ensuring consistent security context mapping and integrity verification to prevent communication failures.
This approach enhances mobility support by eliminating inconsistencies in security handling during radio link failures and retransmissions of TAU requests, thereby improving communication reliability and integrity across different RATs.
Smart Images

Figure 2026136250000001_ABST
Abstract
Description
[Technical Field]
[0001] Cross-reference of related applications This application claims the benefits and priority of U.S. Provisional Application No. 63 / 187,784, filed on 12 May 2021, entitled "SECURITY HANDLING OF 5GS TO EPC RESELECTION," and U.S. Non-Provisional Patent Application No. 17 / 662,978, filed on 11 May 2022, entitled "SECURITY HANDLING OF 5GS TO EPC RESELECTION."
[0002] This disclosure generally relates to communication systems, and more specifically to security functions and security mechanisms employed in communication systems. [Background technology]
[0003] Wireless communication systems are widely deployed to provide a variety of telecommunications services, including telephony, video, data, messaging, and broadcast. Typical wireless communication systems may employ multiple access technologies that enable communication with multiple users by sharing available system resources. Examples of such multiple access technologies include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single-carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems.
[0004] These multi-connectivity technologies are adopted in various telecommunications standards to provide a common protocol that enables different wireless devices to communicate at the urban, national, regional, and even global scale. An exemplary telecommunications standard is 5G New Radio (NR). 5G NR is part of the continuous mobile broadband evolution published by the 3rd Generation Partnership Project (3GPP) to meet new requirements related to latency, reliability, security, scalability (e.g., with the Internet of Things (IoT)), and other requirements. 5G NR includes services associated with enhanced mobile broadband (eMBB), massive machine type communication (mMTC), and ultra-reliable low latency communication (URLLC). Some aspects of 5G NR may be based on the 4G Long-Term Evolution (LTE) standard. Further improvements are needed for 5G NR technology. These improvements may also be applicable to other multi-connectivity technologies and the telecommunications standards that adopt these technologies.
Summary of the Invention
Means for Solving the Problems
[0005] The following presents a simplified overview of one or more aspects to provide a basic understanding of such aspects. This overview is not an extensive overview of all contemplated aspects. This overview does not identify the main or important elements of all aspects, nor does it define the scope of any or all aspects. Its sole purpose is to present some concepts of one or more aspects in a simplified form as a prelude to the more detailed description presented later.
[0006] In one aspect of the present disclosure, methods, computer-readable media, and apparatus for wireless communication are provided. The apparatus may include user equipment (UE). An exemplary apparatus may transmit a first tracking area update (TAU) request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. An exemplary apparatus may also transmit a second TAU request to a first network entity, wherein the second TAU request includes a first set of information, and the second TAU request is integrity protected using a second uplink count. The exemplary device may also derive a mapped security context based on a first security context and at least one of a first uplink count or a second uplink count. Furthermore, the exemplary device may communicate with a first network entity based on the mapped security context.
[0007] In one aspect of the present disclosure, a method, a computer-readable medium, and an apparatus for wireless communication are provided. The apparatus may include a UE. An exemplary apparatus may transmit a first TAU request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT, wherein the first network entity is associated with the second RAT, the first TAU request is encoded using a first security context associated with the first RAT, and the first TAU request is integrity protected using a first uplink count based on the first security context. The exemplary apparatus may also derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. Further, the exemplary apparatus may transmit a repetition of the first TAU request to the first network entity, wherein the repetition of the first TAU request is integrity protected using a second uplink count different from the first uplink count. The exemplary apparatus may also derive a second integrity key based on the first security context, the second uplink count, and the second mapped security context. The exemplary apparatus may also receive a downlink transmission from the first network entity. Further, the exemplary apparatus may perform an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key. The exemplary apparatus may also set a master security key of the UE when the integrity check on the downlink transmission is successful using the derived integrity key, wherein the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.
[0008] In another aspect of this disclosure, methods, computer-readable media, and apparatus for wireless communication are provided. The apparatus may include a first network entity, such as a Mobility Management Entity (MME). An exemplary apparatus may receive a first TAU request generated by a UE, wherein the first TAU request is encoded using a first security context associated with a first RAT, the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also output a first context request for a second network entity based on the first TAU request, wherein the second network entity is associated with the first RAT. Furthermore, the exemplary apparatus may receive a first mapped security context based on the first context request, wherein the first mapped security context is derived from the first security context and a first uplink count. The exemplary device may also receive a second TAU request, wherein the second TAU request is encoded using the first security context, is integrity protected using a second uplink count different from the first uplink count, and contains a first set of information. The exemplary device may also output a second context request for a second network entity based on the second TAU request. The exemplary device may also receive a second mapped security context based on the second context request, wherein the second mapped security context is derived from the first security context and the second uplink count. Furthermore, the exemplary device may send a downlink message based on the second mapped security context.
[0009] In another aspect of this disclosure, methods, computer-readable media, and apparatus for wireless communication are provided. The apparatus may include a second network entity, such as an Access and Mobility Management Function (AMF). An exemplary apparatus may receive a first context request, the first context request comprising at least a first TAU request generated by a UE, the first TAU request being integrity protected using a first uplink count, the first TAU request being encoded using a first security context associated with a first RAT, the first RAT being different from a second RAT associated with the first network entity. The exemplary apparatus may also derive a first mapped security context when a first integrity check in the first TAU request is successful. The exemplary apparatus may output a first mapped security context for the first network entity. Furthermore, the exemplary device may receive a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count. The exemplary device may also derive a second mapped security context when a second integrity check in the second TAU request is successful. Furthermore, the exemplary device may output a second mapped security context for the first network entity.
[0010] In one aspect of this disclosure, a method, a computer-readable medium, and an apparatus for wireless communication in a first network entity such as an MME are provided. An exemplary apparatus may receive a first TAU request from a UE, wherein the first TAU request is encoded using a first security context associated with a first RAT, the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also transmit a first context request to a second network entity based on the first TAU request, wherein the second network entity is associated with the first RAT. Furthermore, the exemplary apparatus may receive a first mapped security context from the second network entity based on the first context request, wherein the first mapped security context is derived from the first security context and a first uplink count. Furthermore, the exemplary device may receive a second TAU request from the UE, wherein the second TAU request is encoded using the first security context, the second TAU request is integrity protected using a second uplink count different from the first uplink count, and the second TAU request contains a first set of information. The exemplary device may also send a second context request to a second network entity based on the second TAU request. The exemplary device may also receive a second mapped security context from the second network entity based on the second context request, wherein the second mapped security context is derived from the first security context and the second uplink count. Furthermore, the exemplary device may send a downlink message to the UE based on the second mapped security context.
[0011] In another aspect of this disclosure, methods, computer-readable media, and apparatus for wireless communication in a second network entity such as an AMF are provided. An exemplary apparatus may receive a first context request from a first network entity, wherein the first context request includes at least a first TAU request generated by a UE, the first TAU request is integrity protected using a first uplink count, and the first TAU request is encoded using a first security context associated with a first RAT, the first RAT being different from a second RAT associated with the first network entity. The exemplary apparatus may also derive a first mapped security context when an integrity check in the first TAU request is successful. Furthermore, the exemplary apparatus may transmit the first mapped security context to the first network entity. The exemplary device may also receive a second context request from a first network entity, wherein the second context request includes at least a second TAU request generated by the UE, and the second TAU request is integrity protected using a second uplink count different from the first uplink count. Furthermore, the exemplary device may derive a second mapped security context when the integrity check in the second TAU request is successful. The exemplary device may also transmit the second mapped security context to the first network entity.
[0012] In another aspect of this disclosure, methods, computer-readable media, and apparatus for wireless communication in a UE are provided. An exemplary apparatus may transmit a first TAU request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first RAT, the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The exemplary apparatus may also derive a first mapped security context based on the first security context and the first uplink count. Furthermore, the exemplary apparatus may transmit a second TAU request to a first network entity, wherein the second TAU request is encoded using a first security context, the second TAU request is integrity-protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information. The exemplary device may also derive a second mapped security context based on a first security context and a second uplink count. Furthermore, the exemplary device may communicate with a first network entity based on the second mapped security context.
[0013] In another aspect of this disclosure, methods, computer-readable media, and apparatus for wireless communication in a UE are provided. An exemplary apparatus may transmit a first TAU request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from a first RAT, wherein the first network entity is associated with a second RAT, the first TAU request is encoded using a first security context associated with the first RAT, the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. An exemplary apparatus may also transmit an iteration of the first TAU request to a first network entity, wherein the iteration of the first TAU request includes a first set of information, and the iteration of the first TAU request is integrity-protected using a first uplink count. Furthermore, the exemplary device may derive a mapped security context based on a first security context and a first uplink count. The exemplary device may also communicate with a first network entity based on the mapped security context.
[0014] In another aspect of this disclosure, methods, computer-readable media, and apparatus for wireless communication in a UE are provided. An exemplary apparatus may transmit a first TAU request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from a first RAT, wherein the first network entity is associated with the second RAT, the first TAU request is encoded using a first security context associated with the first RAT, and the first TAU request is integrity-protected using a first uplink count based on the first security context. The exemplary apparatus may also derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. Furthermore, the exemplary apparatus may transmit iterations of the first TAU request to the first network entity, wherein the iterations of the first TAU request are integrity-protected using a second uplink count different from the first uplink count. The exemplary device may also derive a second integrity key based on a first security context, a second uplink count, and a second mapped security context. Furthermore, the exemplary device may receive a downlink transmission from a first network entity. The exemplary device may also perform an integrity check on the downlink transmission using at least one of the first and second integrity keys. Furthermore, the exemplary device may use the derived integrity key to set a master security key for the UE when the integrity check on the downlink transmission is successful, such that the master security key is set based on the respective integrity keys.
[0015] To achieve the above and related objectives, one or more embodiments shall have features that are fully described below and, in particular, pointed out in the claims. The following description and drawings detail some exemplary features of one or more embodiments. However, these features represent only a few of the various ways in which the principles of various embodiments may be employed. [Brief explanation of the drawing]
[0016] [Figure 1] This figure shows an example of a wireless communication system and access network. [Figure 2A] This figure shows an example of the first frame according to various aspects of the present disclosure. [Figure 2B] This figure shows an example of a DL channel within a subframe according to various aspects of this disclosure. [Figure 2C] This figure shows an example of a second frame according to various aspects of the present disclosure. [Figure 2D] This figure shows an example of a UL channel within a subframe according to various aspects of this disclosure. [Figure 3] This figure shows an example of a base station and user equipment (UE) in an access network. [Figure 4] This figure shows an example of a wireless communication system and access network, as disclosed herein, including a first network node, a second network node, an UE, an advanced packet core (EPC), and a core network (e.g., a 5G core (5GC)). [Figure 5] This figure shows examples of different security contexts based on the teachings disclosed herein. [Figure 6] This is a diagram illustrating an exemplary communication flow showing idle-mode mobility from a first RAT to a second RAT, as taught herein. [Figure 7] This is a flowchart of a wireless communication method in a UE, as disclosed herein. [Figure 8]This is a flowchart of a wireless communication method in a UE, as disclosed herein. [Figure 9] This is a flowchart of a wireless communication method in a UE, as disclosed herein. [Figure 10] This is a flowchart of a wireless communication method in a UE, as disclosed herein. [Figure 11] This figure shows an example of a hardware implementation for an exemplary device as taught herein. [Figure 12] This is a flowchart of a method for wireless communication in a network entity, as disclosed herein. [Figure 13] This is a flowchart of a method for wireless communication in a network entity, as disclosed herein. [Figure 14] This is a flowchart of a method for wireless communication in a network entity, as disclosed herein. [Figure 15] This is a flowchart of a method for wireless communication in a network entity, as disclosed herein. [Figure 16] This figure shows an example of a hardware implementation for an exemplary network entity. [Figure 17] This figure shows an example of a hardware implementation for an exemplary network entity. [Modes for carrying out the invention]
[0017] Any number of wireless networks can be deployed within a given geographical area. Each wireless network may support a specific radio access technology (RAT) and may operate on one or more frequencies. In some examples, a UE may connect to a first cell associated with a first RAT, such as 5G. The first cell may not be able to provide support to the UE. For example, 5G coverage may not be ubiquitous in some deployment scenarios. In other examples, the first RAT may not be able to provide services such as voiceover, where the voiceover service is initiated through the first RAT. To provide support to the UE, the UE and the first RAT may support re-selection from the first RAT to a second RAT that can provide support to the UE with respect to the service. For example, to support voiceover support, the UE and the first cell may support a fallback procedure in which the UE falls back to a second cell associated with a second RAT.
[0018] When a UE falls back from the first cell to the second cell, the UE may perform a reselection procedure. For example, a UE may perform a reselection procedure from 5G to an Advanced Packet Core (EPC). When a UE performs a reselection procedure, it may initiate a TAU procedure to register itself within the tracking area of the second cell and the associated second RAT.
[0019] To provide security for communications across a wireless communication system, messages exchanged between devices in the wireless communication system may be integrity protected. Integrity protection may be based on a security context that includes one or more security keys. In some examples, the security context may include one or more security parameters for authentication, integrity protection, and encryption, and may be identifiable by a key set identifier (KSI). In some examples, each RAT may be associated with its own security context. To facilitate re-selection from a first cell to a second cell, the network entity of each RAT may facilitate mapping a first security context associated with one RAT to a second security context associated with another RAT. For example, a network entity associated with 5G may facilitate mapping a 5G security context to an EPC security context. In some examples, mapping a 5G security context to an EPC security context may involve using the 5G security context to derive the EPC security context. The EPC security context may enable a UE to communicate with a second cell associated with the EPC network after switching from a first cell to a second cell.
[0020] In some scenarios, a radio link failure (RLF) may occur after the UE has established a connection with the second cell and sent a TAU request message. In such cases, the UE may resend the TAU request message. However, the mapping of the first security context to the second security context may result in inconsistencies, which could potentially cause a communication failure.
[0021] The examples disclosed herein provide techniques for eliminating inconsistencies in the handling of TAU request message repetitions as described above. In a first aspect, the disclosed techniques may eliminate inconsistencies by modifying how the network handles TAU request message repetitions. In a second aspect, the disclosed techniques may eliminate inconsistencies by modifying how the UE protects the integrity of TAU request messages. In a third aspect, the disclosed techniques may eliminate inconsistencies by modifying how the UE performs message integrity verification.
[0022] The embodiments presented herein may enable devices in a wireless communication system to facilitate security handling of the re-selection from 5GS to EPC in the case of RLF and the retransmission of Advanced Packet System (EPS) TAU requests, which facilitates improved mobility support.
[0023] The detailed descriptions of the drawings below illustrate various configurations and do not represent the only configurations in which the concepts described herein can be put into practice. The detailed descriptions include specific details for the purpose of providing a complete understanding of the various concepts. However, these concepts can be put into practice without these specific details. In some cases, well-known structures and components are shown in the form of block diagrams to avoid obscuring such concepts.
[0024] Several embodiments of telecommunications systems are presented with respect to various devices and methods. These devices and methods are described in the following detailed description and are illustrated in the accompanying drawings by various blocks, components, circuits, processes, algorithms, etc. (collectively referred to as “elements”). These elements may be implemented using electronic hardware, computer software, or any combination thereof. Whether such elements are implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system.
[0025] For example, an element, any part of an element, or any combination of elements may be implemented as a “processing system” comprising one or more processors. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, system-on-chip (SoCs), baseband processors, field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gate logic, discrete hardware circuits, and other suitable hardware configured to perform various functions described throughout this disclosure. One or more processors in a processing system may execute software. Software should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.
[0026] Accordingly, in one or more exemplary embodiments, implementations, and / or use cases, the functions described may be implemented in hardware, software, or any combination thereof. If implemented in software, the functions may be stored on a computer-readable medium or encoded on a computer-readable medium as one or more instructions or codes. Computer-readable medium includes computer storage medium. Storage medium may be any available medium that can be accessed by a computer. For example, such computer-readable medium may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), optical disk storage, magnetic disk storage, other magnetic storage devices, combinations of computer-readable medium types, or any other medium that can be used to store computer executable code in the form of instructions or data structures that can be accessed by a computer.
[0027] While this application describes several examples of embodiments, implementations, and / or use cases, additional or different embodiments, implementations, and / or use cases may arise in many different configurations and scenarios. The embodiments, implementations, and / or use cases described herein may be implemented across many different platform types, devices, systems, forms, sizes, and packaging configurations. For example, embodiments, implementations, and / or use cases may arise from integrated chip implementations and other non-modular component-based devices (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / purchasing devices, medical devices, artificial intelligence (AI)-enabled devices, etc.). Some examples may or may not specifically target use cases or applications, but a wide range of applicability of the examples described may arise. Embodiments, implementations, and / or use cases may range from chip-level or modular components to non-modular, non-chip-level implementations, and further to aggregated, distributed, or original equipment manufacturer (OEM) devices or systems incorporating one or more techniques described herein. In some practical settings, devices incorporating the embodiments and features described may also include additional components and features for the implementation and practice of the claims and embodiments described. For example, the transmission and reception of wireless signals necessarily include several components for analog and digital purposes (e.g., hardware components including antennas, RF chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). The techniques described herein can be practiced in a wide variety of devices, chip-level components, systems, distributed configurations, aggregated or disassembled components, end-user devices, and the like, in various sizes, shapes, and structures.
[0028] The deployment of communication systems such as 5G NR systems can be configured in multiple ways using various components or parts. In a 5G NR system or network, network nodes, network entities, network mobility elements, radio access network (RAN) nodes, core network nodes, network elements, or network equipment, such as base stations (BS), or one or more units (or one or more components) that perform base station functions, can be implemented in an aggregated or disassembled architecture. For example, a BS (such as a node B (NB), advanced NB (eNB), NR BS, 5G NB, access point (AP), transmit / receive point (TRP), or cell) can be implemented as an aggregated base station (also known as a standalone BS or monolithic BS) or a disassembled base station.
[0029] A clustered base station may be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. A disassembled base station may be configured to utilize a protocol stack that is physically or logically distributed among two or more units (such as one or more centralized or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs)). In some embodiments, a CU may be implemented within a RAN node, and one or more DUs may be collocated with the CU or, alternatively, geographically or virtually distributed across one or more other RAN nodes. A DU may be implemented to communicate with one or more RUs. Each of a CU, DU, and RU may be implemented as a virtual unit, i.e., a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).
[0030] Base station operation or network design may take into account the aggregation characteristics of base station functions. For example, disassembled base stations may be used in integrated access backhaul (IAB) networks, open radio access networks (O-RAN (such as network configurations sponsored by the O-RAN Alliance)), or virtualized radio access networks (vRAN, also known as cloud radio access networks (C-RAN)). Disassembly may involve distributing functions across two or more units in various physical locations, as well as virtually distributing functions for at least one unit, thereby enabling flexibility in network design. Various units of a disassembled base station or disassembled RAN architecture may be configured for wired or wireless communication with at least one other unit.
[0031] Figure 100 shows an example of a wireless communication system and access network. The shown wireless communication system includes a disassembled base station architecture. The disassembled base station architecture may include one or more CUs (e.g., CU110) that can communicate with the core network 120 directly via a backhaul link, or indirectly via one or more disassembled base station units (a Near-RT RAN intelligent controller (RIC) (e.g., Near-RT RIC125) via an E2 link, or a Non-RT RIC115 associated with a Service Management and Orchestration (SMO) framework (e.g., SMO framework 105), or both). CU110 may communicate with one or more DUs (e.g., DU130) via their respective midhaul links, such as an F1 interface. DU130 may communicate with one or more RUs (e.g., RU140) via their respective fronthaul links. RU140 can communicate with each UE (e.g., UE104) via one or more radio frequency (RF) access links. In some implementations, UE104 may be serviced simultaneously by multiple RUs.
[0032] Each unit, namely a CU (e.g., CU110), DU (e.g., DU130), RU (e.g., RU140), and a Near-RT RIC (e.g., Near-RT RIC125), a Non-RT RIC (e.g., Non-RT RIC115), and the SMO framework 105, may include, or be coupled to, one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) over a wired or wireless transmission medium. Each unit, or any associated processor or controller that gives instructions to a unit's communication interface, may be configured to communicate with one or more other units over a transmission medium. For example, a unit may include a wired interface configured to receive or transmit signals to one or more other units over a wired transmission medium. Furthermore, the unit may include a wireless interface which may include a receiver, transmitter, or transceiver (such as an RF transceiver) configured to receive or transmit signals, or both, to one or more other units on a wireless transmission medium.
[0033] In some embodiments, the CU110 may host one or more higher-layer control functions. Such control functions may include Radio Resource Control (RRC), Packet Data Convergence Protocol (PDCP), Service Data Adaptive Protocol (SDAP), etc. Each control function may be implemented with an interface configured to communicate signals with other control functions hosted by the CU110. The CU110 may be configured to handle user plane functions (i.e., Central Unit User Plane (CU-UP)), control plane functions (i.e., Central Unit Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU110 may be logically divided into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units can communicate bidirectionally with the CU-CP units via an interface such as the E1 interface. The CU110 may be implemented to communicate with the DU130 as needed for network control and signaling.
[0034] The DU130 may correspond to a logic unit, including one or more base station functions, for controlling the operation of one or more RUs. In some embodiments, the DU130 may host one or more of the following, at least in part, a functional decomposition as defined by 3GPP®: a radio link control (RLC) layer, a medium access control (MAC) layer, and one or more higher physical (PHY) layers (such as modules for forward error correction (FEC) coding and decoding, scrambling, modulation, demodulation, etc.). In some embodiments, the DU130 may further host one or more lower PHY layers. Each layer (or module) may be implemented with an interface configured to communicate signals with other layers (or modules) hosted by the DU130 or with control functions hosted by the CU110.
[0035] Lower-layer functions can be implemented by one or more RUs. In some deployments, RU140 controlled by DU130 may correspond to a logical node hosting RF processing functions, or lower PHY layer functions (such as performing fast Fourier transform (FFT), inverse FFT (iFFT), digital beamforming, physical random access channel (PRACH) extraction and filtering), or both, at least partially based on a functional partition such as lower-layer functional partitioning. In such an architecture, RU140 may be implemented to handle communication with one or more UEs (e.g., UE104) over the air (OTA). In some implementations, the real-time and non-real-time modes of control and user plane communication with RU140 may be controlled by the corresponding DU. In some scenarios, this configuration can enable DU and CU110 to be implemented in a cloud-based RAN architecture such as a vRAN architecture.
[0036] The SMO framework 105 may be configured to support RAN deployment and provisioning of non-virtualized and virtualized network elements. For non-virtualized network elements, the SMO framework 105 may be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via an operation and maintenance interface (such as the O1 interface). For virtualized network elements, the SMO framework 105 may be configured to interact with a cloud computing platform (such as the Open Cloud (O-Cloud) 190) to perform network element lifecycle management (such as instantiating virtualized network elements) via a cloud computing platform interface (such as the O2 interface). Such virtualized network elements may include, but are not limited to, CUs, DUs, RUs, and Near-RT RICs. In some implementations, the SMO framework 105 may communicate with hardware aspects of the 4G RAN, such as an Open eNB (O-eNB) 111, via the O1 interface. Furthermore, in some implementations, the SMO framework 105 may communicate directly with one or more RUs via the O1 interface. The SMO framework 105 may also include a Non-RT RIC 115 configured to support the functionality of the SMO framework 105.
[0037] Non-RT RIC115 may be configured to include logical functions that enable near real-time control and optimization of RAN elements and resources, artificial intelligence (AI) / machine learning (ML) workflows including model training and updates, or policy-based guidance for applications / functions in Near-RT RIC125. Non-RT RIC115 may be coupled to or communicate with Near-RT RIC125 (e.g., via the A1 interface). Near-RT RIC125 may be configured to include logical functions that enable near real-time control and optimization of RAN elements and resources via data acquisition and actions on interfaces (e.g., via the E2 interface) connecting one or more CUs, one or more DUs, or both, and O-eNBs to Near-RT RIC125.
[0038] In some implementations, Non-RT RIC115 may receive parameter or external enrichment information from an external server to generate an AI / ML model that will be deployed in Near-RT RIC125. Such information may be utilized by Near-RT RIC125 and may be received in SMO Framework 105 or Non-RT RIC115 from non-network data sources or from network functions. In some examples, Non-RT RIC115 or Near-RT RIC125 may be configured to tune RAN behavior or performance. For example, Non-RT RIC115 may monitor long-term trends and patterns for performance and employ an AI / ML model to take corrective action through SMO Framework 105 (e.g., reconfiguration via O1) or through the creation of RAN management policies (e.g., A1 policy).
[0039] At least one of CU110, DU130, and RU140 may be referred to as base station 102. Thus, base station 102 may include one or more of CU110, DU130, and RU140 (each component shown with a dotted line to indicate that each component may or may not be included in base station 102). Base station 102 provides UE104 with an access point to the core network 120. Base station 102 may include macrocells (high-power cellular base stations) and / or small cells (low-power cellular base stations). Small cells include femtocells, picocells, and microcells. A network that includes both small cells and macrocells may be known as a heterogeneous network. A heterogeneous network may also include home-evolved node B (eNB) (HeNB) that can serve restricted groups known as limited subscriber groups (CSGs). A communication link between a RU (e.g., RU140) and a UE (e.g., UE104) may include uplink (UL) transmissions (also called reverse link) from UE104 to RU140, and / or downlink (DL) transmissions (also called forward link) from RU140 to UE104. The communication link may utilize multiple-input multiple-output (MIMO) antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be via one or more carriers. The base station 102 / UE104 may use a spectrum with bandwidths up to Y MHz per carrier (e.g., 5, 10, 15, 20, 100, 400 MHz, etc.), allocated in carrier aggregation up to a total of Yx MHz (x component carriers) used for transmission in each direction. The carriers may or may not be adjacent to each other. Carrier allocation may be asymmetric with respect to DL and UL (for example, more or fewer carriers may be allocated to DL than to UL). Component carriers may include primary component carriers and one or more secondary component carriers.Primary component carriers are sometimes called primary cells (PCells), and secondary component carriers are sometimes called secondary cells (SCells).
[0040] Several UEs may communicate with each other using device-to-device (D2D) communication (e.g., D2D communication link 158). D2D communication link 158 may use the DL / UL Wireless Wide Area Network (WWAN) spectrum. D2D communication link 158 may use one or more sidelink channels, such as the Physical Sidelink Broadcast Channel (PSBCH), Physical Sidelink Discovery Channel (PSDCH), Physical Sidelink Sharing Channel (PSSCH), and Physical Sidelink Control Channel (PSCCH). D2D communication may be through various wireless D2D communication systems, such as Bluetooth, Wi-Fi based on the IEEE 802.11 standard, LTE, or NR.
[0041] The wireless communication system may further include a Wi-Fi AP150 (also called a Wi-Fi station (STA)) communicating with the UE104 via communication link 154, for example, in the 5GHz unlicensed frequency spectrum. When communicating in the unlicensed frequency spectrum, the UE104 / Wi-Fi AP150 may perform a clear channel assessment (CCA) before communicating to determine whether the channel is available.
[0042] The electromagnetic spectrum is often subdivided into various classes, bands, channels, etc., based on frequency / wavelength. In 5G NR, two initial operating bands are identified as frequency range designations FR1 (410 MHz to 7.125 GHz) and FR2 (24.25 GHz to 52.6 GHz). Although a portion of FR1 is above 6 GHz, FR1 is often referred to (interchangeably) as the "sub-6 GHz" band in various documents and papers. A similar nomenclature issue sometimes arises with FR2, which is often referred to (interchangeably) as the "millimeter wave" band in documents and papers, even though it is different from the extremely high frequency (EHF) band (30 GHz to 300 GHz) which is identified as the "millimeter wave" band by the International Telecommunication Union (ITU).
[0043] The frequencies between FR1 and FR2 are often referred to as intermediate band frequencies. In recent 5G NR research, the operating band for these intermediate band frequencies is identified as the frequency range designation FR3 (7.125 GHz to 24.25 GHz). The frequency bands within FR3 may inherit the FR1 and / or FR2 characteristics, and therefore the features of FR1 and / or FR2 may be effectively extended to the intermediate band frequencies. In addition, higher frequency bands are currently being considered to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating bands have been identified as the frequency range designations FR2-2 (52.6 GHz to 71 GHz), FR4 (71 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands falls within the EHF band.
[0044] With the above aspects in mind, unless otherwise specified, the term "sub-6GHz" and similar terms used herein may broadly refer to frequencies that may be below 6GHz, within FR1, or include intermediate band frequencies. Furthermore, unless otherwise specified, the term "millimeter wave" and similar terms used herein may broadly refer to frequencies that may include intermediate band frequencies, within FR2, FR4, FR2-2, and / or FR5, or within the EHF band.
[0045] Base station 102 and UE 104 may each include multiple antennas, such as antenna elements, antenna panels, and / or antenna arrays, to facilitate beamforming. Base station 102 may transmit beamformed signals 182 to UE 104 in one or more transmit directions. UE 104 may receive beamformed signals from base station 102 in one or more receive directions. UE 104 may also transmit beamformed signals 184 to base station 102 in one or more transmit directions. Base station 102 may receive beamformed signals from UE 104 in one or more receive directions. Base station 102 / UE 104 may perform beam training to determine the best receive and transmit directions for each of them. The transmit and receive directions for base station 102 may be the same or different. The transmit and receive directions for UE 104 may be the same or different.
[0046] Base station 102 may include and / or be referred to as gNB, node B, eNB, access point, transceiver base station, radio base station, radio transceiver, transceiver function, basic service set (BSS), extended service set (ESS), transmit / receive point (TRP), network node, network entity, network equipment, or any other preferred term. Base station 102 may be implemented as an aggregated (monolithic) base station with integrated access and backhaul (IAB) nodes, relay nodes, sidelink nodes, baseband units (BBUs) (including CUs and DUs) and RUs, or as a disassembled base station including one or more of CUs, DUs, and / or RUs. A set of base stations, which may include disassembled and / or aggregated base stations, may be referred to as next-generation (NG)RAN (NG-RAN).
[0047] The core network 120 may include access and mobility management functions (AMF) (e.g., AMF161), session management functions (SMF) (e.g., SMF162), user plane functions (UPF) (e.g., UPF163), integrated data management (UDM) (e.g., UDM164), one or more location servers 168, and other functional entities. AMF161 is a control node that handles signaling between UE104 and the core network 120. AMF161 supports registration management, connection management, mobility management, and other functions. SMF162 supports session management and other functions. UPF163 supports packet routing, packet forwarding, and other functions. UDM164 supports authentication and key matching (AKA) credential generation, user identity information handling, access authorization, and subscription management. One or more location servers 168 are shown to include a Gateway Mobile Location Center (GMLC) (e.g., GMLC165) and a Location Management Function (LMF) (e.g., LMF166). However, generally, one or more location servers 168 may include one or more location / positioning servers, which may include one or more of the following: GMLC165, LMF166, Location Determination Entity (PDE), Serving Mobile Location Center (SMLC), Mobile Positioning Center (MPC), etc. GMLC165 and LMF166 support UE location services. GMLC165 provides an interface for clients / applications (e.g., emergency services) to access UE positioning information. LMF166 receives measurements and support information from the NG-RAN and UE104 via AMF161 to calculate the location of the UE104. The NG-RAN may utilize one or more positioning methods to determine the location of the UE104. Positioning UE104 may involve signal measurement, position estimation, and arbitrary velocity calculations based on the measurements. Signal measurement may be performed by UE104 and / or a serving base station (e.g., base station 102).The measured signals may be based on one or more of the following: satellite positioning systems (SPS) 170 (e.g., one or more of the Global Navigation Satellite System (GNSS), Global Positioning System (GPS), Non-Terrestrial Network (NTN), or other satellite positioning / location systems), LTE signals, wireless local area network (WLAN) signals, Bluetooth signals, terrestrial beacon systems (TBS), sensor-based information (e.g., barometric pressure sensors, motion sensors), NR enhanced cell ID (NR E-CID) methods, NR signals (e.g., multi-round trip time (Multi-RTT), DL launch angle (DL-AoD), DL arrival time difference (DL-TDOA), UL arrival time difference (UL-TDOA), and UL angle of arrival (UL-AoA) positioning), and / or other systems / signals / sensors.
[0048] Examples of UEs include cellular phones, smartphones, Session Initiation Protocol (SIP) phones, laptops, personal digital assistants (PDAs), satellite radios, global positioning systems, multimedia devices, video devices, digital audio players (e.g., MP3 players), cameras, game consoles, tablets, smart devices, wearable devices, vehicles, electric meters, gas pumps, large or small kitchen appliances, healthcare devices, implants, sensors / actuators, displays, or any other similar functional devices. Some of the UEs are sometimes referred to as IoT devices (e.g., parking meters, gas pumps, toasters, vehicles, cardiac monitors, etc.). UEs may also be referred to as stations, mobile stations, subscriber stations, mobile units, subscriber units, wireless units, remote units, mobile devices, wireless devices, wireless communication devices, remote devices, mobile subscriber stations, access terminals, mobile terminals, wireless terminals, remote terminals, handsets, user agents, mobile clients, clients, or any other preferred term. In some scenarios, the term UE may also apply to one or more companion devices in a device constellation configuration, for example. One or more of these devices may access the network collectively, or / or individually.
[0049] Referring again to Figure 1, in some embodiments, a device communicating with a base station, such as UE104, may be configured to manage one or more aspects of wireless communication. For example, UE104 may include a UE security handling component 198 configured to facilitate security handling of the re-selection of EPC from 5GS in the case of RLF and the retransmission of EPS TAU requests. In some embodiments, the UE security handling component 198 may be configured to transmit a first TAU request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first RAT, the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. The uplink count may indicate the amount of uplink messages communicated. The exemplary UE security handling component 198 may also be configured to send a second TAU request to a first network entity, wherein the second TAU request includes a first set of information and the second TAU request is integrity protected using a second uplink count. Furthermore, the exemplary UE security handling component 198 may be configured to derive a mapped security context based on a first security context and at least one of a first uplink count or a second uplink count. The exemplary UE security handling component 198 may also be configured to communicate with the first network entity based on the mapped security context.
[0050] In another embodiment, the UE security handling component 198 may be configured to send a first TAU request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT, wherein the first network entity is associated with the second RAT, the first TAU request is encoded using a first security context associated with the first RAT, and the first TAU request is integrity protected using a first uplink count based on the first security context. The exemplary UE security handling component 198 may also be configured to derive a first integrity key based on the first security context, the first uplink count, and the first mapped security context. The integrity key may be a key used to perform integrity checks in communications. Furthermore, the exemplary UE security handling component 198 may be configured to send a first TAU request iteration to a first network entity, wherein the first TAU request iteration is integrity protected using a second uplink count different from the first uplink count. The exemplary UE security handling component 198 may also be configured to derive a second integrity key based on a first security context, a second uplink count, and a second mapped security context. Furthermore, the exemplary UE security handling component 198 may be configured to receive a downlink transmission from the first network entity. The exemplary UE security handling component 198 may also be configured to perform an integrity check on the downlink transmission using at least one of the first and second integrity keys. The integrity check is performed using the integrity keys to verify the integrity of the downlink transmission.Furthermore, an exemplary UE security handling component 198 may be configured to set a master security key for the UE when an integrity check in a downlink transmission is successful, using a derived integrity key, wherein the master security key is set based on a first or second mapped security context used to derive the derived integrity key. The master security key may be a key used to derive other security keys.
[0051] In some embodiments, the UE security handling component 198 may be configured to send a first TAU request to a first network entity. The first TAU request may be encoded using a first security context associated with a first RAT. The first TAU request may be integrity-protected using a first uplink count based on the first security context, and the first TAU request may include a first set of information containing identifiers mapped to a second RAT associated with the first network entity. An exemplary UE security handling component 198 may also be configured to derive a first mapped security context based on the first security context and a first uplink count. An exemplary UE security handling component 198 may also be configured to send a second TAU request to a first network entity. The second TAU request may be encoded using the first security context, and the second TAU request may be integrity-protected using a second uplink count different from the first uplink count, and the second TAU request may include a first set of information. The exemplary UE security handling component 198 may also be configured to derive a second mapped security context based on a first security context and a second uplink count. The exemplary UE security handling component 198 may also be configured to communicate with the first network entity based on the second mapped security context.
[0052] In another embodiment, the UE security handling component 198 may be configured to send a first TAU request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first RAT. The first network entity may be associated with a second RAT. The first TAU request may be encoded using a first security context associated with the first RAT, the first TAU request may be integrity protected using a first uplink count based on the first security context, and the first TAU request may include a first set of information containing identifiers mapped to a second RAT associated with the first network entity.
[0053] The exemplary UE security handling component 198 may also be configured to send a series of first TAU requests to a first network entity. The series of first TAU requests may include a first set of information, and the series of first TAU requests may be integrity protected using a first uplink count. The exemplary UE security handling component 198 may also be configured to derive a mapped security context based on a first security context and a first uplink count. Furthermore, the exemplary UE security handling component 198 may be configured to communicate with the first network entity based on the mapped security context.
[0054] In another embodiment, the UE security handling component 198 may be configured to send a first TAU request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT, which is different from the first RAT. The first network entity may be associated with a second RAT. The first TAU request may be encoded using a first security context associated with the first RAT, and the first TAU request may be integrity-protected using a first uplink count based on the first security context. The exemplary UE security handling component 198 may also be configured to derive a first integrity key based on the first security context, a first uplink count, and a first mapped security context. The exemplary UE security handling component 198 may also be configured to send iterations of the first TAU request to a first network entity. Iterations of the first TAU request may be integrity-protected using a second uplink count, which is different from the first uplink count. Furthermore, the exemplary UE security handling component 198 may also be configured to derive a second integrity key based on a first security context, a second uplink count, and a second mapped security context. The exemplary UE security handling component 198 may also be configured to receive downlink transmissions from a first network entity. The exemplary UE security handling component 198 may also be configured to perform an integrity check on the downlink transmission using at least one of the first and second integrity keys. The exemplary UE security handling component 198 may also be configured to set the UE's master security key using the derived integrity key when the integrity check on the downlink transmission is successful. The master security key is set based on the respective integrity keys.
[0055] In an alternative configuration, the network entity may be configured to manage one or more aspects of wireless communication by facilitating security handling of the re-selection of EPC from 5GS in the case of RLF and the retransmission of EPS TAU requests to facilitate improved mobility support. For example, the network entity may include a network security handling component 199. Aspects of the network security handling component 199 may be implemented by the MME, AMF (e.g., AMF 161), and / or base station (e.g., base station 102).
[0056] The network security handling component 199 may be configured to receive a first TAU request generated by the UE, wherein the first TAU request is encoded using a first security context associated with a first RAT, the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with a first network entity. Furthermore, the network security handling component 199 may be configured to output a first context request for a second network entity based on the first TAU request, wherein the second network entity is associated with the first RAT. The network security handling component 199 may also be configured to receive a first mapped security context based on the first context request, wherein the first mapped security context is derived from the first security context and the first uplink count. Furthermore, the network security handling component 199 may be configured to receive a second TAU request, wherein the second TAU request is encoded using the first security context, the second TAU request is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information. The network security handling component 199 may also be configured to output a second context request for a second network entity based on the second TAU request. Furthermore, the network security handling component 199 may be configured to receive a second mapped security context based on the second context request, wherein the second mapped security context is derived from the first security context and the second uplink count.The network security handling component 199 may also be configured to send downlink messages based on a second mapped security context.
[0057] In another embodiment, the network security handling component 199 may be configured to receive a first context request, the first context request comprising at least a first TAU request generated by the UE, the first TAU request being integrity protected using a first uplink count, the first TAU request being encoded using a first security context associated with a first RAT, the first RAT being different from a second RAT associated with a first network entity. Furthermore, the network security handling component 199 may be configured to derive a first mapped security context when a first integrity check in the first TAU request is successful. The network security handling component 199 may also be configured to output a first mapped security context for a first network entity. Furthermore, the network security handling component 199 may be configured to receive a second context request, the second context request including at least a second TAU request generated by the UE, the second TAU request being integrity protected using a second uplink count different from the first uplink count. The network security handling component 199 may also be configured to derive a second mapped security context when a second integrity check in the second TAU request is successful. Furthermore, the network security handling component 199 may be configured to output a second mapped security context for the first network entity.
[0058] In some embodiments, the network security handling component 199 may be configured to receive a first TAU request from the UE. The first TAU request may be encoded using a first security context associated with a first RAT, the first TAU request may be integrity protected using a first uplink count based on the first security context, and the first TAU request may include a first set of information including an identifier mapped to a second RAT associated with a first network entity. The exemplary network security handling component 199 may also be configured to send a first context request to a second network entity based on the first TAU request. The second network entity may be associated with the first RAT. The exemplary network security handling component 199 may also be configured to receive a first mapped security context from the second network entity based on the first context request. The first mapped security context may be derived from the first security context and a first uplink count. Furthermore, the exemplary network security handling component 199 may be configured to receive a second TAU request from the UE. The second TAU request may be encoded using the first security context, may be integrity protected using a second uplink count different from the first uplink count, and may contain a first set of information. The exemplary network security handling component 199 may also be configured to send a second context request to a second network entity based on the second TAU request. Furthermore, the exemplary network security handling component 199 may be configured to receive a second mapped security context from the second network entity based on the second context request. The second mapped security context may be derived from the first security context and the second uplink count.The exemplary network security handling component 199 may also be configured to send downlink messages to the UE based on a second mapped security context.
[0059] In another embodiment, the network security handling component 199 may be configured to receive a first context request from a first network entity, wherein the first context request includes at least a first TAU request generated by the UE. The first TAU request may be integrity protected using a first uplink count, and the first TAU request may be encoded using a first security context associated with a first RAT, the first RAT may be different from a second RAT associated with the first network entity. The exemplary network security handling component 199 may also be configured to derive a first mapped security context when the integrity check in the first TAU request is successful. The exemplary network security handling component 199 may also be configured to send a first mapped security context to the first network entity. Furthermore, the exemplary network security handling component 199 may be configured to receive a second context request from the first network entity. The second context request may include at least a second TAU request generated by the UE, the second TAU request being integrity-protected using a second uplink count different from the first uplink count. The exemplary network security handling component 199 may also be configured to derive a second mapped security context when the integrity check in the second TAU request is successful. The exemplary network security handling component 199 may also be configured to send the second mapped security context to the first network entity.
[0060] The embodiments presented herein may enable devices in a wireless communication system to facilitate security handling of the re-selection of EPC from 5GS in the case of RLF and the retransmission of EPS TAU requests to facilitate improved mobility support.
[0061] The following description provides an example relating to 5G NR (and, more specifically, EPC re-selection from 5G), but the concepts described herein may be applicable to other similar areas such as LTE, LTE-A, CDMA, GSM, and / or other wireless technologies, where a UE may perform re-selection from a cell associated with a first RAT to a second cell associated with a second RAT.
[0062] Figure 2A is Figure 200, which shows an example of a first subframe in a 5G NR frame structure. Figure 2B is Figure 230, which shows an example of a DL channel in a 5G NR subframe. Figure 2C is Figure 250, which shows an example of a second subframe in a 5G NR frame structure. Figure 2D is Figure 280, which shows an example of a UL channel in a 5G NR subframe. The 5G NR frame structure may be frequency division duplex (FDD) where, for a given set of subcarriers (carrier system bandwidth), the subframes within the set of subcarriers are dedicated to either DL or UL, or it may be time division duplex (TDD) where, for a given set of subcarriers (carrier system bandwidth), the subframes within the set of subcarriers are dedicated to both DL and UL. In the example provided by Figures 2A and 2C, it is assumed that the 5G NR frame structure is TDD, subframe 4 is composed of slot format 28 (mostly DL), where D is DL, U is UL, and F is flexible for use between DL / UL, and subframe 3 is composed of slot format 1 (all UL). Subframes 3 and 4 are shown in slot formats 1 and 28, respectively, but any particular subframe may be composed of any of the various available slot formats 0 to 61. Slot formats 0 and 1 are all DL and UL, respectively. The other slot formats 2 to 61 include a mixture of DL, UL, and flexible symbols. The UE is composed of slot formats (dynamically via DL Control Information (DCI) or semi-statically / statically via Radio Resource Control (RRC) signaling) through the received Slot Format Indicator (SFI). Note that the following description also applies to the 5G NR frame structure which is TDD.
[0063] Figures 2A to 2D show a frame structure, and aspects of this disclosure may be applicable to other wireless communication technologies that may have different frame structures and / or different channels. A frame (10 ms) may be divided into 10 subframes (1 ms) of equal size. Each subframe may contain one or more time slots. Subframes may also contain minislots that may contain 7, 4, or 2 symbols. Each slot may contain 14 or 12 symbols, depending on whether the cyclic prefix (CP) is normal or extended. In the case of a normal CP, each slot may contain 14 symbols, and in the case of an extended CP, each slot may contain 12 symbols. Symbols on the DL may be CP orthogonal frequency division multiplexing (OFDM) (CP-OFDM) symbols. The symbols on the UL may be CP-OFDM symbols (for high-throughput scenarios) or Discrete Fourier Transform (DFT) Spread OFDM (DFT-s-OFDM) symbols (also known as Single Carrier Frequency Division Multiple Access (SC-FDMA) symbols) (for power-limited scenarios and limited to single-stream transmissions). The number of slots within a subframe is based on CP and numerology. Numerology defines the subcarrier spacing (SCS), which effectively defines a symbol length / duration equal to 1 / SCS.
[0064] [Table 1]
[0065] For normal CP (14 symbols / slot), different numerologies μ0-4 allow 1, 2, 4, 8, and 16 slots per subframe, respectively. For extended CP, numerology 2 allows 4 slots per subframe. Therefore, for normal CP and numerology μ, there are 14 symbols / slot and 2 μ slots / subframe. As shown in Table 1, the subcarrier spacing is 2 μ*May be equal to 15 kHz, where μ is numerology 0 to 4. Thus, numerology μ=0 has a subcarrier interval of 15 kHz, and numerology μ=4 has a subcarrier interval of 240 kHz. Symbol length / duration is inversely related to subcarrier interval. Figures 2A to 2D provide examples of a normal CP with 14 symbols per slot and a numerology μ=2 with 4 slots per subframe. The slot duration is 0.25 ms, the subcarrier interval is 60 kHz, and the symbol duration is approximately 16.67 μs. Within a set of frames, there may be one or more different bandwidth parts (BWPs) (see Figure 2B) that are frequency-division multiplexed. Each BWP may have a specific numerology and CP (normal or extended).
[0066] A resource grid can be used to represent a frame structure. Each time slot contains a resource block (RB) (also called a physical RB (PRB)) spanning 12 consecutive subcarriers. The resource grid is divided into multiple resource elements (REs). The number of bits carried by each RE depends on the modulation scheme.
[0067] As shown in Figure 2A, some of the REs carry reference (pilot) signals (RS) for the UE. RS may include demodulated RS (DM-RS) (shown as R for one particular configuration, but other DM-RS configurations are possible) and channel state information reference signals (CSI-RS) for channel estimation in the UE. RS may also include beam measurement RS (BRS), beam improvement RS (BRRS), and phase tracking RS (PT-RS).
[0068] Figure 2B shows an example of various DL channels within a subframe of a frame. A physical downlink control channel (PDCCH) carries DCI within one or more control channel elements (CCEs) (e.g., 1, 2, 4, 8, or 16 CCEs), each CCE containing 6 RE groups (REGs), and each REG containing 12 consecutive REs within the OFDM symbol of the RB. A PDCCH within a single BWP may be called a control resource set (CORESET). The UE is configured to monitor PDCCH candidates in a PDCCH search space (e.g., common search space, UE-specific search space) during PDCCH monitoring opportunities on the CORESET, where PDCCH candidates have different DCI formats and different aggregation levels. Additional BWPs may be located at higher and / or lower frequencies across the channel bandwidth. A primary synchronization signal (PSS) may be within symbol 2 of a particular subframe of the frame. The PSS is used by the UE104 to determine subframe / symbol timing and physical layer identification information. The secondary synchronization signal (SSS) may be within symbol 4 of a particular subframe of a frame. The SSS is used by the UE to determine the physical layer cell identification information group number and radio frame timing. Based on the physical layer identification information and physical layer cell identification information group number, the UE can determine the physical cell identifier (PCI). Based on the PCI, the UE can determine the location of the DM-RS. The physical broadcast channel (PBCH) carrying the master information block (MIB) may be logically grouped with the PSS and SSS to form a synchronization signal (SS) / PBCH block (also called an SS block (SSB)). The MIB provides the number of RBs and the system frame number (SFN) within the system bandwidth. The physical downlink shared channel (PDSCH) carries user data, broadcast system information not transmitted through the PBCH such as the system information block (SIB), and paging messages.
[0069] As shown in Figure 2C, for channel estimation at the base station, some of the REs carry DM-RS (shown as R for one particular configuration, but other DM-RS configurations are possible). The UE may transmit DM-RS for the physical uplink control channel (PUCCH) and DM-RS for the physical uplink shared channel (PUSCH). The PUSCH DM-RS may be transmitted within the first one or two symbols of the PUSCH. The PUCCH DM-RS may be transmitted in different configurations depending on whether a short or long PUCCH is transmitted and depending on the specific PUCCH format used. The UE may transmit a sounding reference signal (SRS). The SRS may be transmitted within the last symbol of a subframe. The SRS may have a comb structure, and the UE may transmit the SRS in one of the combs. The SRS may be used by the base station for channel quality estimation to enable frequency-dependent scheduling on the UL.
[0070] Figure 2D shows an example of various UL channels within a frame subframe. In one configuration, the PUCCH may be located as shown. The PUCCH carries uplink control information (UCI), such as scheduling requests, channel quality indicators (CQI), precoding matrix indicators (PMI), rank indicators (RI), and hybrid automatic retransmission request (HARQ) acknowledgment (ACK) (HARQ-ACK) feedback (i.e., one or more HARQ ACK bits indicating one or more ACKs and / or negative ACKs (NACKs)). The PUCCH carries data and may additionally carry buffer status reports (BSR), power headroom reports (PHR), and / or UCI.
[0071] Figure 3 is a block diagram illustrating an example of a first wireless device configured to exchange wireless communications with a second wireless device. In the illustrated example of Figure 3, the first wireless device may include a base station 310, the second wireless device may include a UE 350, and the base station 310 may communicate with the UE 350 in an access network. As shown in Figure 3, the base station 310 includes a transmit processor (TX processor 316), a transmitter 318Tx, a receiver 318Rx, an antenna 320, a receive processor (RX processor 370), a channel estimator 374, a controller / processor 375, and a memory 376. The exemplary UE 350 includes an antenna 352, a transmitter 354Tx, a receiver 354Rx, an RX processor 356, a channel estimator 358, a controller / processor 359, a memory 360, and a TX processor 368. In other examples, the base station 310 and / or UE350 may include additional or alternative components.
[0072] In the DL, Internet Protocol (IP) packets can be provided to the controller / processor 375. The controller / processor 375 implements Layer 3 and Layer 2 functions. Layer 3 includes the Radio Resource Control (RRC) layer, and Layer 2 includes the Service Data Adaptive Protocol (SDAP) layer, the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Medium Access Control (MAC) layer. The controller / processor 375 provides RRC layer functions associated with broadcasting system information (e.g., MIB, SIB), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection correction, and RRC connection release), inter-radio access technology (RAT) mobility, and measurement configuration for UE measurement reporting; PDCP layer functions associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functions associated with forwarding upper layer packet data units (PDUs), error correction via ARQ, concatenation, segmentation, and reassembly of RLC service data units (SDUs), re-segmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, multiplexing MAC SDUs onto transport blocks (TBs), demultiplexing MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority processing, and logical channel prioritization.
[0073] The TX processor 316 and RX processor 370 implement Layer 1 functions associated with various signal processing functions. Layer 1, including the physical (PHY) layer, may include error detection on the transport channel, forward error correction (FEC) coding / decoding of the transport channel, interleaving, rate matching, mapping onto the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. The TX processor 316 handles mapping to signal constellations based on various modulation schemes (e.g., 2-phase shift keying (BPSK), 4-phase shift keying (QPSK), M-phase shift keying (M-PSK), M-quadrature amplitude modulation (M-QAM)). Coded and modulated symbols may then be divided into parallel streams. Each stream may then be mapped to an OFDM subcarrier to generate a physical channel that carries a time-domain OFDM symbol stream, multiplexed with a reference signal (e.g., a pilot) in the time-domain and / or frequency-domain, and then synthesized together using an inverse fast Fourier transform (IFFT). The OFDM stream is spatially precoded to generate multiple spatial streams. Channel estimates from channel estimator 374 can be used to determine the coding and modulation scheme, as well as for spatial processing. Channel estimates can be derived from a reference signal and / or channel state feedback transmitted by UE350. Each spatial stream can then be provided to a different antenna of antenna 320 via a separate transmitter (e.g., transmitter 318Tx). Each transmitter 318Tx can modulate a radio frequency (RF) carrier over its respective spatial stream for transmission.
[0074] In UE350, each receiver 354Rx receives signals through its respective antenna of antenna 352. Each receiver 354Rx reconstructs the information modulated on the RF carrier and provides this information to the RX processor 356. The TX processor 368 and RX processor 356 implement Layer 1 functionality associated with various signal processing functions. The RX processor 356 may perform spatial processing on the information to reconstruct any spatial stream directed to UE350. If multiple spatial streams are directed to UE350, two or more of the multiple spatial streams may be synthesized by the RX processor 356 into a single OFDM symbol stream. The RX processor 356 then uses a Fast Fourier Transform (FFT) to convert the OFDM symbol stream from the time domain to the frequency domain. The frequency domain signal contains a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, and the reference signal, are reconstructed and demodulated by determining the most likely signal constellation point transmitted by base station 310. These soft decisions may be based on channel estimates calculated by the channel estimator 358. The soft decisions are then decoded and deinterleaved to reconstruct the data and control signals initially transmitted by the base station 310 on the physical channel. The data and control signals are then provided to the controller / processor 359, which implements Layer 3 and Layer 2 functions.
[0075] The controller / processor 359 may be associated with memory 360, which stores program code and data. Memory 360 is sometimes referred to as computer-readable media. In UL, the controller / processor 359 provides demultiplexing between transport and logical channels, packet reassembly, decoding, header decompression, and control signal processing to reconstruct IP packets. The controller / processor 359 is also responsible for error detection using the ACK protocol and / or NACK protocol to support HARQ operation.
[0076] Similar to the functions described for DL transmission by base station 310, the controller / processor 359 provides RRC layer functions associated with system information (e.g., MIB, SIB) collection, RRC connection, and measurement reporting; PDCP layer functions associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functions associated with the transfer of upper layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and sorting of RLC data PDUs; and MAC layer functions associated with mapping between logical channels and transport channels, multiplexing MAC SDUs onto TB, demultiplexing MAC SDUs from TB, scheduling information reporting, error correction via HARQ, priority processing, and logical channel prioritization.
[0077] The channel estimate derived by the channel estimator 358 from a reference signal or feedback transmitted by the base station 310 may be used by the TX processor 368 to select an appropriate coding and modulation scheme and to facilitate spatial processing. The spatial stream generated by the TX processor 368 may be provided to different antennas of the antenna 352 via a separate transmitter (e.g., transmitter 354Tx). Each transmitter 354Tx may modulate the RF carrier in its respective spatial stream for transmission.
[0078] UL transmission is processed at base station 310 in a manner similar to that described for receiver functions in UE350. Each receiver 318Rx receives the signal through its respective antenna of antenna 320. Each receiver 318Rx reconstructs the information modulated on the RF carrier and provides this information to RX processor 370.
[0079] The controller / processor 375 may be associated with memory 376 that stores program code and data. Memory 376 is sometimes referred to as computer-readable media. In UL, the controller / processor 375 performs demultiplexing between transport and logical channels, packet reassembly, decoding, header decompression, and control signal processing to reconstruct IP packets. The controller / processor 375 is also responsible for error detection using the ACK protocol and / or NACK protocol to support HARQ operation.
[0080] At least one of the TX processor 368, RX processor 356, and controller / processor 359 may be configured to perform an embodiment related to the UE security handling component 198 in Figure 1.
[0081] At least one of the TX processor 316, RX processor 370, and controller / processor 375 may be configured to perform an embodiment related to the network security handling component 199 in Figure 1.
[0082] Figure 4 is Figure 400, which shows an example of a wireless communication system and access network, including a first network node 402a, a second network node 402b, a UE 404, an advanced packet core (e.g., EPC 410), and a core network 430 (e.g., a 5G core (5GC)), as presented herein. Embodiments of the first network node 402a and / or the second network node 402b, sometimes collectively referred to herein as "network nodes 402a / 402b," can be implemented by the base station 102 in Figure 1, and / or components of the base station 102, such as the CU 110, DU 130, and / or RU 140. Embodiments of the UE 404 can be implemented by the UE 104 in Figure 1.
[0083] In the example shown in Figure 4, the first network node 402a may be configured for 4G LTE (collectively referred to as Advanced Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN)) and may interface with EPC 410 through the first backhaul link 452 (e.g., S1 interface). The second network node 402b may be configured for 5G NR (collectively referred to as Next Generation RAN (NG-RAN)) and may interface with the core network 430 through the second backhaul link 454. In addition to other functions, network nodes 402a / 402b may perform one or more of the following functions: transfer of user data, encryption and decryption of radio channels, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection setup and release, load balancing, delivery for non-access layer (NAS) messages, NAS node selection, synchronization, radio access network (RAN) sharing, multimedia broadcast multicast service (MBMS), subscriber and equipment tracking, RAN information management (RIM), paging, positioning, and delivery of alert messages. Network nodes 402a / 402b may communicate with each other directly or indirectly (e.g., through EPC 410 or core network 430) via a third backhaul link 456 (e.g., X2 interface). The first backhaul link 452, the second backhaul link 454, and the third backhaul link 456 may be wired or wireless.
[0084] Network nodes 402a / 402b can communicate wirelessly with UE404. Each of network nodes 402a / 402b can provide communication coverage to its respective geographical coverage area 406. There may be overlapping geographical coverage areas. In the example in Figure 4, the communication link 408 between network nodes 402a / 402b and UE404 may include uplink (UL) (also called reverse link) transmissions from UE404 to each network node, and / or downlink (DL) (also called forward link) transmissions from each network node to UE404. The communication link 408 may use MIMO antenna technology, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be through one or more carriers.
[0085] EPC410 may include a mobility management entity (e.g., MME412), another MME414, a serving gateway 416, a multimedia broadcast multicast service (MBMS) gateway (e.g., MBMS GW418), a broadcast multicast service center (e.g., BM-SC420), and a packet data network (PDN) gateway (e.g., PDN gateway 422). MME412 may communicate with a home subscriber server (e.g., HSS424). MME412 is the control node that handles signaling between UE404 and EPC410. Generally, MME412 provides bearer and connectivity management. All user Internet Protocol (IP) packets are forwarded through the serving gateway 416, which itself connects to the PDN gateway 422. The PDN gateway 422 provides UE IP address allocation and other functions. The PDN gateway 422 and BM-SC420 connect to IP service 426. IP service 426 may include the Internet, intranet, IP multimedia subsystem (IMS), PS streaming service, and / or other IP services. BM-SC420 may provide functionality for MBMS user service provisioning and delivery. BM-SC420 may act as an entry point for content provider MBMS transmissions, may be used to authorize and initiate MBMS bearer services within a Public Land Mobile Network (PLMN), and may be used to schedule MBMS transmissions. MBMS GW418 may be used to deliver MBMS traffic to network nodes 402a / 402b belonging to a multicast broadcast single frequency network (MBSFN) area broadcasting specific services, and may be responsible for session management (start / stop) and collecting eMBMS-related billing information.
[0086] The core network 430 may include access and mobility management functions (e.g., AMF432), other AMF434 functions, session management functions (e.g., SMF436), and user plane functions (e.g., UPF438). AMF432 may communicate with integrated data management (e.g., UDM440). AMF432 is a control node that handles signaling between the UE404 and the core network 430. Generally, AMF432 provides QoS flow and session management. All user IP packets are forwarded through UPF438. UPF438 provides IP address allocation for the UE and other functions. UPF438 connects to IP services 442. IP services 442 may include the Internet, intranet, IP multimedia subsystem (IMS), packet-switched (PS) streaming (PSS) services, and / or other IP services.
[0087] In the example in Figure 4, the MME412 and / or AMF432 may be configured to manage one or more aspects of wireless communication by facilitating security handling of re-selection from 5GS to EPC in the case of RLF and retransmission of EPS TAU requests to facilitate improved mobility support. For example, the MME412 and / or AMF432 may be configured to facilitate handover from a 5G network associated with a second network node 402b to an EPS network associated with a first network node 402a. The MME412 and / or AMF432 may include a network security handling component 497. An aspect of the network security handling component 497 may be similar to the network security handling component 199 in Figures 1 and / or 3.
[0088] The Non-Access Layer (NAS) forms the highest layer of the control plane between the UE and MME in the wireless interface. Protocols that are part of the NAS provide support for UE mobility. NAS security is an additional function of the NAS that provides services to the NAS protocol. For example, NAS security may provide integrity protection and encryption for NAS signaling messages.
[0089] Security parameters for authentication, integrity protection, and encryption may be referred to as a security context and may be identified by a key set identifier (KSI). Information representing a security context may be stored in the UE and the network serving the UE (e.g., the serving network). With respect to communicating NAS signaling messages, the security context may be referred to as a “NAS security context” and may include a key, the key set identifier associated with the key, the UE security capabilities (e.g., a set of identifiers corresponding to the encryption and integrity algorithms implemented by the UE), an uplink NAS count, and a downlink NAS count. When a security context is activated, the uplink NAS count and downlink NAS count may each be set to 0 and may be sequentially incremented as each NAS message is communicated. Thus, the uplink NAS count value may indicate the amount of uplink NAS messages communicated, and the downlink NAS count value may indicate the amount of downlink NAS messages communicated associated with the active security context.
[0090] When a UE connects to a 5G network, the 5G security context is identified by the 5G Key Set Identifier (ngKSI) and the 5G NAS Master Security Key (K AMF) may include. The 5G NAS master security key may also be referred to herein as the “5G NAS key” or “5G master security key”. When the UE connects to the EPS network, the EPS security context is identified by the EPS NAS master security key (K) identified by the Key Set Identifier for EPS (eKSI). ASME ) may include. The EPS NAS master security key may also be referred to as the "EPS NAS key" or "EPS master security key" in this specification.
[0091] Figure 5 illustrates an example of different security contexts, as presented herein. For example, Figure 5 includes a first security context 500, a second security context 520 associated with a 5G network, and a third security context 540 associated with an EPS network. A security context includes data that can be used to protect the integrity of NAS signaling, for example, when sending and / or receiving NAS messages. Security context data can be associated with protecting the integrity of NAS signaling associated with each RAN. For example, the second security context 520 may include 5G security context data used to send and / or validate 5G NAS messages. The third security context 540 may include EPS security context data used to send and / or validate EPS NAS messages.
[0092] In the example in Figure 5, the first security context 500 includes a master security key 502 and a KSI 504 associated with the master security key 502. For example, the KSI 504 may represent the master security key 502. The first security context 500 also includes a UE security capability 506, which may include a set of identifiers corresponding to the encryption and integrity algorithms implemented by the UE. For example, the UE security capability 506 may include an integrity key and an encryption key, as well as associated identifiers for the selected integrity and encryption algorithms. The first security context 500 also includes a NAS count pair, which includes an uplink NAS count 508 and a downlink NAS count 510. The uplink NAS count 508 indicates the amount of uplink NAS messages communicated, and the downlink NAS count 510 indicates the amount of downlink NAS messages communicated associated with the active security context. When the security context is activated, the uplink NAS count 508 and the downlink NAS count 510 may be set to an initial value (for example, they may be set to 0). After the NAS count value is set to its starting value, the NAS count value can be incremented each time a NAS message is communicated.
[0093] As explained above, the second security context 520 includes 5G security context data to facilitate the integrity protection of 5G NAS messages. For example, the second security context 520 includes 5G key 522(K AMF ) includes 5G KSI 524 (ngKSI), 5G UE security capability 526, 5G uplink NAS count 528, and 5G downlink NAS count 530. The 5G security context data of the second security context 520 may be similar to the security context data of the first security context 500, but may be configured for a 5G network.
[0094] The third security context 540 includes EPS security context data to facilitate integrity protection of EPS NAS messages. For example, the third security context 540 includes EPS key 542(K ASME This includes EPS KSI 544 (eKSI), EPS UE security capability 546, EPS uplink NAS count 548, and EPS downlink NAS count 550. The EPS security context data of the third security context 540 may be similar to the security context data of the first security context 500, but may be configured for the EPS network.
[0095] A security context can be associated with a state, such as a "current" state or a "non-current" state. A current security context is the security context being activated. A non-current security context is a security context that is not current (for example, a security context that is not being activated). A security context can be associated with a type, such as a "native" type or a "mapped" type. Native security contexts include "fully native" security contexts or "partially native" security contexts. A security context can be one type and one state at a time; however, the type of a particular security context can change over time. For example, a partially native security context can be converted to a fully native security context.
[0096] The native security context is created by the primary authentication procedure and identified by a native key set identifier (e.g., native eKSI or native ngKSI) and key (e.g., EPS key K ASME or 5G key K AMFA security context is a security context that has the following characteristics. For example, a primary authentication procedure may enable mutual authentication between the UE and the network and provide keying material that can be used between the UE and the network in subsequent security procedures. When a UE registers with the network, the UE and the network may perform a primary authentication procedure, and if the primary authentication procedure is successful, a native security context may be generated. The UE may store a copy of the native security context, and the network may store a copy of the native security context associated with the UE in network entities such as the MME and / or AMF.
[0097] The native security context may include a native KSI that identifies the native key. The native KSI may be derived during the primary authentication procedure, allowing the UE and network to identify the native security context without calling the authentication procedure. Therefore, the native KSI may allow for the reuse of the native security context during subsequent connection setup between the UE and the network, without requiring the execution of an authentication procedure.
[0098] The native security context can be a partial native security context or a full native security context. A partial native security context is a security context that includes a key (e.g., 5G key 522 or EPS key 542), along with an associated key set identifier (e.g., 5G KSI524 or EPS KSI544), UE security capabilities, and NAS count pair (e.g., uplink NAS count value and downlink NAS count value). A partial native security context can be created by primary authentication and is in a "non-current" state. A full native security context is a security context that includes the security context data of the partial native security context, and also includes the NAS integrity key and cipher key, and the associated key set identifier of the selected NAS integrity and encryption algorithms. A full native security context can be in a "current" state or a "non-current" state.
[0099] A mapped security context is a security context for which the key is derived from keys associated with different RANs. For example, a mapped 5G security context includes a mapped 5G key (K AMF ) derived from an EPS key (e.g., EPS key 542). A mapped EPS security context includes a mapped EPS key (K ASME ) derived from a 5G key (e.g., 5G key 522).
[0100] A mapped security context may include a mapped KSI of the first network, associated with the mapped key, which is derived from the native key of the second network. For example, a mapped 5G security context may include a mapped 5G KSI, associated with the mapped 5G key, which is derived from the EPS key of the EPS network. The mapped KSI can be generated in the UE and network when the mapped key is derived. Therefore, the mapped KSI can indicate the use of the mapped key.
[0101] In some aspects, security context mismatches may occur between the UE and the first network, for example, during re-selection from a second network to a first network (e.g., re-selection from 5GS to EPS). The number of 5GS to EPS re-selection procedures performed in a deployment may be large, for example, due to the non-ubiquitous coverage of 5G in the deployment scenario. Furthermore, 5G networks may not initially support IP Multimedia Subsystem (IMS) voice calls. In such scenarios, a UE camped on to a cell associated with a 5G network may be redirected to a cell associated with an EPS network, for example, to attempt to establish a voice call.
[0102] Figure 6 shows an exemplary communication flow 600 between a network node 602, a UE 604, an MME 606, and an AMF 608, as presented herein. In the illustrated example, the communication flow 600 facilitates idle-mode mobility from 5GS to EPS. For example, UE 604 may be connected to and / or camp-on to a first cell associated with a first RAT (e.g., a 5G network) and redirected to a second cell associated with a second RAT (e.g., an EPS network or an LTE network). In the example in Figure 6, MME 606 may be associated with the EPS network 607, and AMF 608 may be associated with the 5G network 609. The exemplary communication flow 600 may be associated with performing a Tracking Area Update (TAU) request procedure after being redirected to the second cell (e.g., the EPS network 607), or an initial attachment procedure with the second cell.
[0103] An embodiment of network node 602 can be implemented by base station 102 in Figure 1, and / or components of base station 102 such as CU, DU, and / or RU. An embodiment of UE 604 can be implemented by UE 104 in Figure 1. An embodiment of MME 606 can be implemented by MME 412 in Figure 4. An embodiment of AMF 608 can be implemented by AMF 161 in Figure 1, AMF 432 and / or other AMF 434 in Figure 4. In the example of Figure 6, UE 604 communicates with MME 606 via network node 602. For example, UE 604 may send an uplink message that is received by network node 602, which then forwards the uplink message to MME 606. In the downlink direction, MME 606 may send a message that is received by network node 602 and then forwarded by network node 602 to UE 604.
[0104] In the example in Figure 6, UE604 is performing a reselection from the 5G network 609 to the EPS network 607. Therefore, UE604 is configured with a 5G security context 690, such as the second security context 520 in Figure 5, which is the current (or active) 5G security context. UE604 may derive a mapped EPS security context based on the 5G security context data of the current 5G security context to facilitate communication with MME606 and the EPS network 607.
[0105] As shown in Figure 6, UE604 sends a first TAU request message 610, which is received by MME606. UE604 may send the first TAU request message 610 to update the registration of UE604's actual tracking area in the EPS network 607. UE604 may send the first TAU request message 610 via an EPS NAS message. Therefore, the first TAU request message 610 may include parameters associated with the EPS network 607.
[0106] For example, the first TAU request message 610 includes a mapped EPS globally unique temporary UE identity (e.g., a mapped EPS GUTI 612) and the EPS security capabilities of UE 604, such as the EPS UE security capability 546 in Figure 5. The mapped EPS GUTI 612 may be derived from a 5G GUTI. When UE 604 registers with the 5G network 609, it may consist of a 5G GUTI. The 5G GUTI may point to an AMF where the 5G key associated with UE 604 is stored. Thus, the mapped EPS GUTI 612 may include information about the AMF with the most recent security context of UE 604 in the 5G network 609, and an identifier for the UE within the AMF. For example, the mapped EPS GUTI612 may include the address associated with AMF608 and the Temporary Mobile Subscription Identifier (e.g., TMSI613) associated with UE604.
[0107] UE604 may integrity-protect the first TAU request message 610 using the 5G security context 690 identified by the 5G GUTI used to derive the mapped EPS GUTI 612. For example, UE604 may calculate a NAS message authentication code (e.g., NAS-MAC 614) for the first TAU request message 610. UE604 may calculate NAS-MAC 614 similarly to the calculation of NAS-MAC for 5G NAS messages. The uplink NAS count for integrity-protecting the first TAU request message 610 may be the same value as the 5G uplink NAS count (e.g., the same value as 5G uplink NAS count 528 in Figure 5). As a result, the uplink NAS count value across the communication system is incremented. The first TAU request message 610 may include eKSI parameters 616, and UE604 may include a 5G KSI (ngKSI) corresponding to the 5G security context 690 in the eKSI parameters 616.
[0108] In the example in Figure 6, after sending the first TAU request message 610, UE604 may increment the 5G uplink NAS count of the 5G security context 690 by 1 in 618.
[0109] In 620, MME606 may obtain the AMF address of the AMF that stores the 5G security context associated with UE604. For example, MME606 may obtain the AMF address of AMF608 using the mapped EPS GUTI612 of the first TAU request message 610.
[0110] As shown in Figure 6, MME606 may send a context request message 622, which is received by AMF608. The context request message 622 may contain all or part of the information from the first TAU request message 610. For example, the context request message 622 may contain the NAS-MAC 614 and eKSI parameters 616. The context request message 622 may also contain the mapped EPS GUTI 612.
[0111] In 630, the AMF608 may, for example, identify the 5G NAS security context 692 associated with the UE604 based on the context request message 622. The AMF608 may identify the 5G NAS security context 692 associated with the UE604 using the 5G KSI included in the eKSI parameter 616 of the context request message 622.
[0112] In step 632, AMF608 may verify the first TAU request message 610 using the 5G NAS security context 692. AMF608 may verify the first TAU request message 610 as if it were a 5G NAS message. If AMF608 successfully verifies the first TAU request message 610, AMF608 may generate a mapped EPS security context 636 in step 634. For example, AMF608 may derive the mapped EPS security context 636 using the 5G NAS security context 692. AMF608 may, for example, use the 5G uplink NAS count derived from the first TAU request message 610 to obtain the 5G key (K AMF ) from the mapped EPS key (K ASMEThe mapped EPS security context 636 can be derived by deriving '). For example, UE604 may use the 5G uplink NAS count to ensure the integrity of the first TAU request message 610. Once AMF608 identifies the UE604's 5G NAS security context 692 and verifies the first TAU request message 610, AMF608 may have the ability to determine the 5G uplink NAS count.
[0113] AMF608 maps the EPS key (K) based on the value taken from the 5G KSI (ngKSI) in context request message 622. ASME The mapped EPS KSI (eKSI) for ') can be determined. The EPS uplink and downlink NAS count values in the mapped EPS security context 636 can be set to the uplink and downlink NAS count values of the 5G NAS security context 692, respectively. The AMF 608 can set the EPS NAS algorithm to the one previously shown to the UE 604 (for example, during the connection establishment procedure or connection re-establishment procedure).
[0114] As shown in Figure 6, the AMF608 may output a context response message 638 that is received by the MME606. The context response message 638 may contain the mapped EPS security context 636. In some examples, after sending the context response message 638, the AMF608 may discard (or erase) the 5G NAS security context 692 that was used to derive the mapped EPS security context 636. In some examples, after sending the context response message 638, the AMF608 may start a timer, and after the timer expires, discard the 5G NAS security context 692.
[0115] In the illustrated example in Figure 6, UE604 may generate a UE-mapped EPS security context 642 at 640. For example, UE604 may derive the UE-mapped EPS security context 642 in a similar manner to how AMF608 derives the mapped EPS security context 636. UE604 may set the EPS NAS algorithm to one previously received from AMF608 (for example, during a connection establishment procedure or a connection re-establishment procedure). UE604 may activate the UE-mapped EPS security context 642 for use in processing EPS NAS messages received from MME606.
[0116] In 650, MME606 may compare the UE security algorithm with security algorithm information 694. MME606 may configure security algorithm information 694 via network management. Security algorithm information 694 may contain a list of algorithms made available for use. The algorithms in security algorithm information 694 may be ordered according to priority. MME606 may compare the EPS NAS algorithm contained in the mapped EPS security context 636 of the context response message 638 with security algorithm information 694. In 650, MME606 may compare the security algorithms and decide whether to select a different EPS NAS algorithm. If MME606 decides to perform an algorithm change, MME606 may select an EPS NAS algorithm from security algorithm information 694 that has the highest priority and is also available to UE604. For example, MME606 may use the UE's UE security capabilities, such as the EPS UE security capability 546 in Figure 5, to determine which EPS NAS algorithm to select from the security algorithm information 694.
[0117] If MME606 decides to select a different EPS NAS algorithm, UE604 and MME606 may execute a NAS security mode command (SMC) procedure (for example, NAS SMC procedure 660) to derive a new NAS key using the selected EPS NAS algorithm. If MME606 decides not to perform the algorithm change, or after MME606 and UE604 have executed NAS SMC procedure 660, MME606 may output a TAU acknowledgment message 662 to be received by UE604. MME606 may output (for example, send or communicate) the TAU acknowledgment message 662 via an EPS NAS message.
[0118] In 664, UE604 may perform integrity verification of the TAU received message 662. For example, UE604 may perform integrity verification of the mapped EPS key (K) of the UE-mapped EPS security context 642. ASME The integrity verification of the TAU reception message 662 can be performed using '). If the integrity verification is successful, UE604 may send the TAU completion message 666, which is received by MME606. If the integrity verification fails, UE604 may discard the TAU completion message 666.
[0119] As described above, UE604 may initiate the procedure shown in Figure 6 based on a re-selection from a first cell associated with the 5G network 609 to a second cell associated with the EPS network 607. However, there may be cases where the security contexts in UE604 and MME606 do not match.
[0120] For example, after establishing a connection with a second cell associated with EPS network 607 and sending the first TAU request message 610, UE604 may experience a radio link failure (RLF). In such an example, UE604 may resend the first TAU request message 610, for example, after establishing a new RRC connection with another cell associated with EPS network 607, or after re-establishing the RRC connection with the second cell. For example, UE604 may send a second TAU request message 670, which is received by MME606. The second TAU request message 670 may contain the same information as the first TAU request (for example, the first TAU request message 610).
[0121] However, when sending the second TAU request message 670, UE604 may use an updated 5G NAS uplink count value to ensure the integrity of the second TAU request message 670. For example, the 5G NAS uplink count value used to ensure the integrity of the first TAU request message 610 may be 5, and the 5G NAS uplink count value used to ensure the integrity of the second TAU request message 670 may be 6.
[0122] In some examples, when MME606 receives a second TAU request message 670, MME606 may be configured in 672 to compare the contents of the first TAU request message 610 and the second TAU request message 670. In some examples, if the contents (e.g., information elements) of the first TAU request message 610 and the second TAU request message 670 are the same, MME606 may discard the second TAU request message 670 and continue executing the TAU request procedure in Figure 6 based on the first TAU request message 610. In such examples, MME606 may refrain from sending another context request message to AMF608 based on the second TAU request message 670.
[0123] It will be understood that refraining from sending another context request message may be sufficient in inter-MME scenarios because there is no security context mapping that may occur. Furthermore, refraining from sending another context request message may be sufficient when performing reselection from UMTS to EPS, because freshness corresponding to NONCE_UE may be used for context mapping. As used herein, "NONCE_UE" refers to a 32-bit pseudorandom number generated by the UE to facilitate the freshness of the security mapping from UMTS to EPS. NONCE_UE is the mapped EPS key (K ASME It can be used as input along with an existing security key, such as a 3G security key, to calculate ').
[0124] However, as illustrated in the example in Figure 6, when performing a reselection from 5G to EPS (for example, when performing a reselection from 5G network 609 to EPS network 607), AMF608 may generate a mapped EPS security context 636 (for example, in 634) using the 5G NAS uplink count associated with the TAU request message. For example, AMF608 may generate a mapped EPS security context 636 that AMF608 provides to MME606 through context response message 638, using the value 5 of the 5G NAS uplink count associated with the first TAU request message 610. The mapped EPS security context 636 is based on the MME EPS key (K ASME It may include '_MME). Therefore, MME606 is an MME EPS key (K) based on the 5G NAS uplink count value of 5. ASME It can be composed of '_MME).
[0125] Similarly, UE604 may generate a UE-mapped EPS security context 642 (for example, in 640) using the same 5G NAS uplink count associated with the TAU request message. For example, with respect to the first TAU request message 610, UE604 may generate a first UE EPS key (K) in 640. ASME It may be possible to generate a UE-mapped EPS security context 642 that includes '_UE'.
[0126] However, after sending the second TAU request message 670, UE 604 may generate a new UE-mapped EPS security context 682 in 680. The new UE-mapped EPS security context 682 may be based at least partially on the 5G NAS uplink count value associated with the second TAU request message 670. For example, the new UE-mapped EPS security context 682 may be based on the 5G NAS uplink count value of 6 associated with the second TAU request message 670. In such an example, the new UE-mapped EPS security context 682 may be based on the second UE EPS key (K ASME '_UE2) may include. The mapped EPS security context 636 and the new UE mapped EPS security context 682 can be derived in AMF608 and UE604 respectively using different 5G NAS uplink count values, so the MME EPS key (K ASME '_MME) and the second UE EPS key (K ASME It should be understood that '_UE2)' can also be different. As a result, the mapped EPS key K ASME '_MME, K ASMEBecause '_UE2 is different, UE604 may drop EPS NAS messages received from MME606. That is, because UE604 and MME606 are using mismatched mapped EPS security contexts and mapped EPS keys, UE604 may drop or reject EPS NAS messages from MME606 (e.g., TAU reception message 662 and / or messages associated with NAS SMC procedure 660) due to a mismatch in integrity calculation. Such a scenario may result in service interruption and / or call interruption.
[0127] The examples disclosed herein provide techniques for eliminating inconsistencies in the handling of TAU request message repetitions as described above. In a first aspect, the disclosed techniques can eliminate inconsistencies by modifying how MME606 handles TAU request message repetitions. In a second aspect, the disclosed techniques can eliminate inconsistencies by modifying how UE604 performs integrity protection of TAU request messages. In a third aspect, the disclosed techniques can eliminate inconsistencies by modifying how UE604 performs integrity verification of EPS NAS messages.
[0128] As described above, when MME606 receives a second TAU request message 670, if the content (e.g., information elements) of the first TAU request message 610 and the second TAU request message 670 are the same, MME606 may discard the second TAU request message 670 and refrain from sending another context request message to AMF608. In the first exemplary embodiment, the disclosed technique can eliminate the inconsistency described above by modifying how MME handles iterations of TAU request messages.
[0129] For example, MME606 may be configured to decide whether or not to send a context request message to AMF608 when MME606 can obtain an AMF address from a TAU request. That is, rather than refraining from sending a second context request message on the basis that the first TAU request message 610 and the second TAU request message 670 contain the same content (e.g., the same information elements), as described in 672, MME606 may decide whether or not to send a second context request message 674 on the basis that MME606 can obtain an AMF address. Thus, if the second TAU request message 670 contains a mapped EPS GUTI that includes an AMF address, such as a mapped EPS GUTI 612, MME606 may decide to send a second context request message 674 to AMF608 requesting a new mapped EPS security context.
[0130] In such an example, AMF608 may generate a mapped EPS security context 636 based on the 5G NAS uplink count (e.g., value 6) associated with the second TAU request message 670, which is included in the second context request message 674. As a result, the mapped EPS security context 636 and the new UE mapped EPS security context 682 may be derived based on the same 5G NAS uplink count (e.g., value 6), thereby their respective mapped EPS key K ASME '_MME, K ASME '_UE2 can also yield the same result. In some examples, UE604 may update the security context of UE604 from the UE-mapped EPS security context 642 to the new UE-mapped EPS security context 682, based on the derivation of the new UE-mapped EPS security context 682 in 684 (for example in 680).
[0131] In some cases, when the MME606 receives a mapped EPS security context from the AMF608, the MME606 may be configured to update that mapped security context. For example, in some scenarios, the MME606 may generate EPS NAS messages to send to the UE604, and while one or more of the generated EPS NAS messages are pending transmission, it may receive a new mapped EPS security context. In such cases, the MME606 may be configured to discard pending EPS NAS messages that are integrity protected using the older mapped EPS security context.
[0132] It will be understood that MME606 can send a context request message requesting a mapped EPS security context, as long as MME606 can obtain an address to send the second context request message 674. Thus, in some examples, an address included in the mapped EPS GUTI may correspond to an AMF (e.g., AMF608). In other examples, an address included in the mapped EPS GUTI of the first TAU request message 610 and the second TAU request message 670 may map to an MME.
[0133] In some examples, MME606 may receive a second TAU request message 670 with the same information elements before sending TAU acceptance message 662 to UE604. In some such examples, MME606 may forward the second TAU request message 670 to AMF608 (for example, via a second context request message 674) as described above. In other examples, MME606 may activate a new native EPS security context which will be used to perform authentication and protect subsequent NAS messages to UE604. For example, MME606 may use the same EPS key (K) for MME606 and UE604 to perform integrity verification of EPS NAS messages. ASMEYou may decide to run NAS SMC procedure 660 with UE604, as if you were using ).
[0134] In some examples, after sending a TAU acceptance message 662 to the UE604, the MME606 may receive a second TAU request message 670 with the same information elements. In some such examples, the MME606 may decide to activate a new native EPS security context which will be used to perform authentication and protect subsequent NAS messages to the UE604. For example, the MME606 may use the same EPS key (K) to perform integrity verification of EPS NAS messages. ASME You may decide to run NAS SMC procedure 660 with UE604, as if you were using ).
[0135] In some examples, MME606 may receive a second TAU request message 670 with the same information elements after sending the TAU acknowledgment message 662 and before receiving the TAU completion message 666 from UE604. In aspects other than system-to-system change from N1 mode to S1 mode in IDLE mode with UE604 operating in single registration mode, MME606 may resend the TAU acknowledgment message 662. In some such examples, MME606 may restart a timer (e.g., a T3450 timer) if the TAU completion message 666 is expected. In aspects of system-to-system change from N1 mode to S1 mode in IDLE mode with UE604 operating in single registration mode, MME606 may initiate an authentication procedure with UE604, followed by executing a security mode control procedure (e.g., NAS SMC procedure 660) in an attempt to bring the new partial native EPS security context into use. If the integration of the new partial native EPS security context is successful, MME606 may set the new partial native EPS security context as the full native EPS security context. MME606 may also retransmit the TAU reception message 662 and use the (new) full native EPS security context to ensure the integrity of the retransmission of the TAU reception message 662. In some examples, MME606 may also restart the T3450 timer. In such examples, the retransmission counter for the T3450 timer may not be incremented.
[0136] In some cases, MME606 may receive a first TAU request message 610 and a second TAU request message 670, but may not yet send a TAU acceptance message 662 or a TAU rejection message. If one or more information elements in the first TAU request message 610 and the second TAU request message 670 are different, the TAU procedure initiated based on the first TAU request message 610 may be aborted, and a new TAU procedure initiated based on the second TAU request message 670 may proceed (for example, proceed).
[0137] If the information elements in the first TAU request message 610 and the second TAU request message 670 are the same (e.g., not different), then, in any manner other than a system-to-system change from N1 mode to S1 mode in IDLE mode with a UE 604 operating in single registration mode, the MME 606 may continue the previously started TAU procedure (e.g., based on the first TAU request message 610) and discard the second TAU request message 670. That is, the MME 606 may refrain from sending a second context request message 674 to the AMF 608 requesting a new mapped EPS security context based on the second TAU request message 670.
[0138] In an instance of a system-to-system change from N1 mode to S1 mode in IDLE mode, with UE604 operating in single registration mode, MME606 may forward a new TAU request message to AMF608 (e.g., through another context request message) to perform an integrity check, obtain the latest mapped EPS security context, and continue the previous TAU procedure. For example, MME606 may forward a second TAU request message 670 to AMF608 (e.g., through a second context request message 674). As an example, the integrity check may be based on the integrity key, uplink count, transmission direction (e.g., a 1-bit indicator indicating the downlink direction for a downlink transmission), and the payload of the downlink transmission. AMF608 may verify the second TAU request message 670 (e.g., in 632). AMF608 may then generate a new mapped EPS security context based on the second TAU request message 670. For example, the new mapped EPS security context may be at least partially based on the 5G NAS uplink count (e.g., value 6) associated with the second TAU request message 670. As a result, the new MME EPS key (e.g., K ASME The mapped EPS security context 636 provided to MME606, including '_MME', is used to obtain the new UE EPS key (K ASME '_UE2)' may be the same as the new UE-mapped EPS security context 682. As a result, MME606 may be the same as the new MME EPS key (e.g., K ASMEWhen using '_MME) to ensure the integrity of a subsequent NAS message (e.g., TAU reception message 662), UE604 may succeed in performing integrity verification on the later received NAS message (e.g., TAU reception message 662) in 664. In some examples, UE604 may update the security context of UE604 from the mapped EPS security context 642 to the new UE-mapped EPS security context 682 in 684, based on the derivation of the new UE-mapped EPS security context 682 (e.g., in 680).
[0139] In some cases, instead of forwarding a second TAU request message 670 containing the same information elements as the first TAU request message 610 to the AMF608, the MME606 may decide to initiate an authentication procedure and a subsequent security mode control procedure to bring the new partial native EPS security context into use. If bringing the new partial native EPS security context into use is successful (for example, if the NAS SMC procedure 660 succeeds), the MME606 may set the new partial native EPS security context to a full native EPS security context, which can then be used to protect any future NAS messages sent to the UE604, such as the TAU acceptance message 662.
[0140] As described above, when UE604 sends the first TAU request message 610 and the second TAU request message 670, UE604 uses the respective 5G NAS uplink count to ensure the integrity of each TAU request message. In a second exemplary embodiment, the techniques disclosed may eliminate inconsistencies by modifying how UE604 performs integrity protection of TAU request messages. For example, UE604 may be configured to use the same 5G NAS uplink count value when sending two consecutive TAU request messages, such as the first TAU request message 610 and a repetition of the first TAU request message (e.g., the second TAU request message 670). For example, UE604 may skip incrementing the 5G uplink NAS count of the 5G security context 690 by 1 in 618.
[0141] By sending the first TAU request message 610 and the second TAU request message 670 without incrementing the 5G NAS uplink count, the first TAU request message 610 and the second TAU request message 670 can be integrity-protected using the same 5G NAS uplink COUNT value. As a result, the mapped EPS security context 636 generated by AMF 608 (e.g., in 634) and the new UE mapped EPS security context 682 generated by UE 604 (e.g., in 680) can be the same. Therefore, integrity verification performed on subsequent NAS messages received in UE 604 (e.g., in 664) may succeed, and communication between UE 604 and the cell associated with the EPS network 607 may continue successfully. In some examples, UE604 may update the security context of UE604 from the UE-mapped EPS security context 642 to the new UE-mapped EPS security context 682, based on the derivation of the new UE-mapped EPS security context 682 in 684 (for example, in 680).
[0142] In other words, since the 5G NAS uplink count value is the same for the first TAU request message 610 and the second TAU request message 670, each TAU request message contains the same content (e.g., the same information elements) and is each protected for integrity using the same 5G NAS uplink COUNT value. In some examples, if MME 606 receives the first TAU request message 610 and the second TAU request message 670, MME 606 may discard the second TAU request message 670 and continue the TAU procedure based on the first TAU request message 610. If MME606 does not receive the first TAU request message 610 (for example, if a radio link failure occurs and network node 602 misses one or more RLC packets containing RRC connection setup completion information), but MME606 receives the second TAU request message 670, in another example, MME606 may use the second TAU request message 670 to execute the TAU procedure in Figure 6 (for example, to request a mapped EPS security context for AMF608). In either scenario, the mapped EPS key (K ASME '_MME, K ASME '_UE2) is the same, and therefore, continued communication between UE604 and the cell associated with EPS network 607 can be successful.
[0143] In a third exemplary embodiment, the disclosed technique may eliminate inconsistencies in handling iterations of TAU request messages by modifying how UE604 performs integrity verification of EPS NAS messages. For example, UE604 may attempt to perform integrity verification based on different EPS keys (e.g., in 664).
[0144] For example, UE604 has a 5G key (K AMFBased on the 5G NAS uplink count associated with the first TAU request message 610 (for example, value 5), the first EPS key (K) of the UE-mapped EPS security context 642 is determined. ASME '1) can be derived. Then, UE604 can determine the first EPS key (K ASME From '1), the first NAS integrity key (NAS_IK1) can be derived.
[0145] UE604 also supports 5G keys (K AMF Based on the 5G NAS uplink count associated with the second TAU request message 670 (for example, value 6), the second EPS key (K) of the new UE-mapped EPS security context 682 is determined. ASME '2) can be derived. Then, UE604 can obtain the second EPS key (K ASME From '2), the second NAS integrity key (NAS_IK2) can be derived.
[0146] When UE604 receives an EPS NAS integrity protected message from MME606 (e.g., TAU reception message 662), UE604 may attempt to perform integrity verification (e.g., in 664) using the NAS integrity keys (e.g., NAS_IK1 and NAS_IK2). If one of the NAS integrity keys allows the integrity verification to pass, UE604 selects the respective NAS integrity key and proceeds to communicate with the cell associated with the EPS network 607 based on the respective NAS integrity key. For example, if the integrity verification is successful using the first NAS integrity key (NAS_IK1), UE604 will then attempt to communicate with the first EPS key (K ASME '1) to the EPS key (K ASME ) can be set as. UE604 also has a second EPS key (K ASME '2), and the second EPS key (K ASME '2) Any other keys derived from this may be erased. Similarly, if integrity verification is successful using the second NAS integrity key (NAS_IK2), UE604 will erase the second EPS key (K ASME '2) to the EPS key (KASME ) can be set as. UE604 also has a first EPS key (K ASME '1), and the first EPS key (K ASME Any other keys derived from '1) may be deleted. If integrity verification fails using both NAS integrity keys (NAS_IK1, NAS_IK2) (for example, neither NAS integrity key successfully performs integrity verification), UE604 may drop the EPS NAS message.
[0147] The above explanation provides an example containing two TAU request messages, but it should be understood that other examples may contain any suitable number of TAU request messages. For example, there may be z possible NAS uplink COUNT values (e.g., x, x+1, x+2, ..., z). Integrity verification uses y EPS key (K) with 5G NAS uplink COUNT y. ASME Using the NAS integrity key (NAS_IK_y) derived from 'y', the process is completed successfully, provided that y is one of the z possible NAS uplink COUNT values (e.g., x, x+1, x+2, ..., z), then UE604 will use the y EPS key (K ASME 'y) to EPS key (K ASME Set as ) and all other EPS keys (K ASME ') and the keys derived from each of them can be erased.
[0148] Figure 7 is a flowchart 700 of a wireless communication method. The method can be performed by a UE (e.g., UE104, UE350, UE404, and / or device 1104 in Figure 11). The method can facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0149] In 702, the UE sends a first TAU request to the first network entity, as described with respect to the first TAU request message 610 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context, such as the 5G uplink NAS count 528 in Figure 5. The first TAU request may include a first set of information containing identifiers mapped to a second RAT associated with the first network entity, such as the mapped EPS GUTI 612 in Figure 6. In 702, the transmission of the first TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0150] In some examples, a UE may send a first TAU request when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT. For example, a UE may send a first TAU request when performing a reselection from 5GS to EPS. As described with respect to the MME 606, EPS network 607, and 5G network 609 in Figure 6, the second RAT may differ from the first RAT, and the first network entity may be associated with the second RAT.
[0151] In 704, the UE sends a second TAU request to the first network entity, as described with respect to the second TAU request message 670 in Figure 6. The second TAU request may include a first set of information, as described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameters 616 in Figure 6. The second TAU request may be integrity protected using a second uplink count. In 704, the transmission of the second TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0152] In 706, the UE derives a mapped security context based on a first security context and at least one of a first uplink count or a second uplink count, as described with respect to the UE-mapped EPS security context 642 and / or the new UE-mapped EPS security context 682 in Figure 6. In 706, the derivation of the mapped security context may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0153] In 708, the UE communicates with the first network entity based on the mapped security context, as described with respect to the TAU completion message 666 in Figure 6. In 714, the communication based on the mapped security context may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0154] Figure 8 is a flowchart of a wireless communication method 800. The method can be performed by a UE (e.g., UE104, UE350, UE404, and / or device 1104 in Figure 11). The method can facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0155] In 802, the UE sends a first TAU request to the first network entity, as described with respect to the first TAU request message 610 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context, such as the 5G uplink NAS count 528 in Figure 5. The first TAU request may include a first set of information containing identifiers mapped to a second RAT associated with the first network entity, such as the mapped EPS GUTI 612 in Figure 6. In 802, the transmission of the first TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0156] In some examples, a UE may send a first TAU request when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT. For example, a UE may send a first TAU request when performing a reselection from 5GS to EPS. As described with respect to the MME 606, EPS network 607, and 5G network 609 in Figure 6, the second RAT may differ from the first RAT, and the first network entity may be associated with the second RAT.
[0157] In 804, the UE sends a second TAU request to the first network entity, as described with respect to the second TAU request message 670 in Figure 6. The second TAU request may include a first set of information, as described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameters 616 in Figure 6. The second TAU request may be integrity protected using a second uplink count. In 804, the transmission of the second TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0158] In 806, the UE derives a mapped security context based on a first security context and at least one of a first uplink count or a second uplink count, as described with respect to the UE-mapped EPS security context 642 and / or the new UE-mapped EPS security context 682 in Figure 6. The derivation of the mapped security context in 806 may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0159] In 814, the UE communicates with the first network entity based on the mapped security context, as described with respect to the TAU completion message 666 in Figure 6. In 814, the communication based on the mapped security context may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0160] In some examples, the UE604 eliminates inconsistencies in iterations of TAU requests by modifying how the UE604 performs integrity protection of TAU request messages, as described with respect to the second aspect of Figure 6, where a second TAU request may include an iteration of the first TAU request in 804, and the second uplink count may be the same value as the first uplink count. In some examples, the UE may send a second TAU request based on the occurrence of a radio link failure. In some examples, a mapped security context may be associated with a second RAT. For example, a mapped security context may be associated with the UE-mapped EPS security context 642 in Figure 6, or a new UE-mapped EPS security context 682.
[0161] In some examples, as described with respect to the UE-mapped EPS security context 642 in Figure 6, the second TAU request may include an iteration of the first TAU request, the second uplink count may differ from the first uplink count in 804, and the mapped security context may be the first mapped security context.
[0162] In some such examples, the UE may derive a second mapped security context based on a first security context and a first uplink count, as described in 808 with respect to the new UE-mapped EPS security context 682 in Figure 6. The UE may use the first security context to encode a second TAU request, and the second TAU request may be integrity-protected using a second uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. In 808, the derivation of the second mapped security context may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0163] In 810, the UE may update its security context from a second mapped security context to a first mapped security context based on the derivation of a first mapped security context, as described with respect to 684 in Figure 6. In 810, the update of the UE's security context may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0164] In 812, the UE may, after updating the UE's security context, discard pending transmissions that are integrity-protected using a second mapped security context. In 812, the discarding of pending transmissions may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0165] Figure 9 is a flowchart 900 of a wireless communication method. The method can be performed by a UE (e.g., UE104, UE350, UE404, and / or device 1104 in Figure 11). The method can facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0166] In 902, the UE sends a first TAU request to the first network entity when it performs a change from the first cell associated with the first RAT to connect to a second cell associated with a second RAT that is different from the first RAT, as described with respect to the first TAU request message 610 in Figure 6. The first network entity may be associated with the second RAT, as described with respect to the MME 606 and EPS network 607 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context. In 902, the transmission of the first TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0167] In 904, the UE derives a first integrity key based on the first security context, the first uplink count, and the first mapped security context, as described for the first NAS integrity key (NAS_IK1). For example, the UE derives a 5G key (K AMFBased on the 5G NAS uplink count associated with the first TAU request message 610 (for example, value 5), the first EPS key (K) of the UE-mapped EPS security context 642 is determined. ASME '1) can be derived. Next, UE can obtain the first EPS key (K ASME '1) From which the first NAS integrity key (NAS_IK1) can be derived. In 904, the derivation of the first integrity key can be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0168] In 906, the UE sends a repetition of the first TAU request to the first network entity, as described with respect to the second TAU request message 670 in Figure 6. The repetition of the first TAU request may be integrity-protected using a second uplink count different from the first uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. In 906, the transmission of the repetition of the first TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0169] In 908, UE uses the second EPS key (K ASME As explained with respect to the second NAS integrity key (NAS_IK2) from '2), the second integrity key is derived based on the first security context, the second uplink count, and the second mapped security context. For example, the UE derives the 5G key (K AMF Based on the 5G NAS uplink COUNT value (e.g., 6) associated with the second TAU request message 670, the second EPS key (K) of the new UE-mapped EPS security context 682 is determined. ASME '2) can be derived. Next, UE can obtain the second EPS key (K ASME'2) From which the second NAS integrity key (NAS_IK2) can be derived. In 908, the derivation of the second integrity key can be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0170] In 910, the UE receives a downlink transmission from the first network entity, as described with respect to the TAU reception message 662 in Figure 6. In 910, the reception of the downlink transmission may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0171] In 912, the UE performs an integrity check in the downlink transmission using at least one of the first and second integrity keys, as described with respect to 664 in Figure 6. In 912, the performance of the integrity check may be carried out by the UE security handling component 198 of the device 1104 in Figure 11.
[0172] In 914, the UE sets its master security key using the derived integrity key when the integrity check in the downlink transmission is successful. The master security key may be set based on each integrity key used to successfully perform the integrity check. In 914, the setting of the master security key may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0173] Figure 10 is a flowchart 1000 of a wireless communication method. The method can be performed by a UE (e.g., UE104, UE350, UE404, and / or device 1104 in Figure 11). The method can facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0174] In 1002, the UE sends a first TAU request to the first network entity when it performs a change from the first cell associated with the first RAT to connect to a second cell associated with a second RAT that is different from the first RAT, as described with respect to the first TAU request message 610 in Figure 6. The first network entity may be associated with the second RAT, as described with respect to the MME 606 and EPS network 607 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context. In 1002, the transmission of the first TAU request may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0175] In some examples, the UE may derive a first mapped security context based on a first security context and a first uplink count, as described with respect to the UE-mapped EPS security context 642 in Figure 6, in 1004. The derivation of the first mapped security context in 1004 may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0176] In 1006, the UE derives a first integrity key based on the first security context, the first uplink count, and the first mapped security context, as described with respect to the first NAS integrity key (NAS_IK1). For example, the UE derives a 5G key (K AMF Based on the 5G NAS uplink count associated with the first TAU request message 610 (for example, value 5), the first EPS key (K) of the UE-mapped EPS security context 642 is determined. ASME '1) can be derived. Next, UE can obtain the first EPS key (K ASME'1) From which the first NAS integrity key (NAS_IK1) can be derived. In 1006, the derivation of the first integrity key can be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0177] In 1008, the UE sends a repetition of the first TAU request to the first network entity, as described with respect to the second TAU request message 670 in Figure 6. The repetition of the first TAU request may be integrity-protected using a second uplink count different from the first uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. The transmission of the repetition of the first TAU request in 1008 may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0178] In 1010, UE uses the second EPS key (K ASME As explained with respect to the second NAS integrity key (NAS_IK2) from '2), the second integrity key is derived based on the first security context, the second uplink count, and the second mapped security context. For example, the UE derives the 5G key (K AMF Based on the 5G NAS uplink COUNT value (e.g., 6) associated with the second TAU request message 670, the second EPS key (K) of the new UE-mapped EPS security context 682 is determined. ASME '2) can be derived. Next, UE can obtain the second EPS key (K ASME '2) From which a second NAS integrity key (NAS_IK2) can be derived. In 1010, the derivation of the second integrity key can be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0179] In 1012, the UE receives a downlink transmission from the first network entity, as described with respect to the TAU reception message 662 in Figure 6. In 1012, the reception of the downlink transmission may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0180] In 1014, the UE performs an integrity check in the downlink transmission using at least one of the first integrity key and the second integrity key, as described with respect to 664 in Figure 6. In 1014, the performance of the integrity check may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0181] In 1016, the UE sets its master security key using the derived integrity key when the integrity check in the downlink transmission is successful. The master security key may be set based on each integrity key used to successfully perform the integrity check. In 1016, the setting of the master security key may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0182] In some examples, the UE may then discard information related to other derived integrity keys after setting the master security key. For example, the UE may set the master security key in the first mapped security context at 1016. In such an example, the UE may, at 1018, erase the second mapped security context and any keys derived using the second mapped security context when the integrity check in the downlink transmission is successful using the first integrity key. The erasure of the second mapped security context at 1018 may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0183] In another example, the UE may, at 1016, set the master security key in a second mapped security context. In such an example, the UE may, at 1020, erase the first mapped security context and any keys derived using the first mapped security context when the integrity check in the downlink transmission is successful using the second integrity key. The erasure of the first mapped security context at 1020 may be performed by the UE security handling component 198 of the device 1104 in Figure 11.
[0184] Figure 11 is Figure 1100, which shows an example of a hardware implementation for device 1104. Device 1104 may be a UE, a component of a UE, or implement UE functionality. In some embodiments, device 1104 may include a cellular baseband processor 1124 (also called a modem) coupled to one or more transceivers (e.g., a cellular RF transceiver 1122). The cellular baseband processor 1124 may include on-chip memory 1124'. In some embodiments, device 1104 may further include one or more subscriber identification module (SIM) cards 1120 and an application processor 1106 coupled to a secure digital (SD) card 1108 and a screen 1110. The application processor 1106 may include on-chip memory 1106'. In some embodiments, the device 1104 may further include a Bluetooth module 1112, a WLAN module 1114, an SPS module 1116 (e.g., a GNSS module), one or more sensor modules 1118 (e.g., motion sensors such as a barometric pressure sensor / altimeter, an inertial management unit (IMU), a gyroscope, and / or an accelerometer, light detection and ranging (LIDAR), radio-assisted detection and ranging (RADAR), sound navigation and ranging (SONAR), a magnetometer, audio and / or other technologies used for positioning), an additional memory module 1126, a power supply 1130, and / or a camera 1132. The Bluetooth module 1112, the WLAN module 1114, and the SPS module 1116 may include an on-chip transceiver (TRX) (or, in some cases, simply a receiver (RX)). The Bluetooth module 1112, the WLAN module 1114, and the SPS module 1116 may include their own dedicated antennas and / or may utilize one or more antennas 1180 for communication.The cellular baseband processor 1124 communicates with the UE 104 and / or the RU associated with the network entity 1102 via one or more antennas 1180 through a transceiver (e.g., a cellular RF transceiver 1122). The cellular baseband processor 1124 and the application processor 1106 may each include computer-readable media / memory, such as on-chip memory 1124' and on-chip memory 1106', respectively. An additional memory module 1126 may also be considered computer-readable media / memory. Each computer-readable media / memory (e.g., on-chip memory 1124', on-chip memory 1106', and / or additional memory module 1126) may be non-transient. The cellular baseband processor 1124 and the application processor 1106 are each responsible for general processing, including the execution of software stored on the computer-readable media / memory. When the software is executed by the cellular baseband processor 1124 / application processor 1106, it causes the cellular baseband processor 1124 / application processor 1106 to perform the various functions described above. Computer-readable media / memory may also be used to store data manipulated by the cellular baseband processor 1124 / application processor 1106 when the software is executed. The cellular baseband processor 1124 / application processor 1106 may be a component of the UE350 and may include memory 360 and / or at least one of the TX processor 368, RX processor 356, and controller / processor 359. In one configuration, the device 1104 may be a processor chip (modem and / or application) and may include only the cellular baseband processor 1124 and / or application processor 1106, while in another configuration, the device 1104 may be the entire UE (see, for example, the UE350 in Figure 3) and may include additional modules of the device 1104.
[0185] As described above, the UE security handling component 198 is configured to send a first tracking area update (TAU) request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; send a second TAU request to the first network entity, wherein the second TAU request includes a first set of information, and the second TAU request is integrity-protected using a second uplink count; derive a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count; and communicate with the first network entity based on the mapped security context.
[0186] In another embodiment, the UE security handling component 198 transmits a first tracking area update (TAU) request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from the first radio access technology (RAT), wherein the first network entity is associated with the second RAT, the first TAU request is encoded using a first security context associated with the first RAT, the first TAU request is integrity protected using a first uplink count based on the first security context, a first integrity key is derived based on the first security context, the first uplink count, and the first mapped security context, and transmits iterations of the first TAU request to the first network entity. The configuration may include: an iteration of a first TAU request being integrity protected using a second uplink count different from a first uplink count; deriving a second integrity key based on a first security context, a second uplink count, and a second mapped security context; receiving a downlink transmission from a first network entity; performing an integrity check on the downlink transmission using at least one of the first and second integrity keys; and setting the UE's master security key using the derived integrity key when the integrity check on the downlink transmission is successful, wherein the master security key is set based on the first or second mapped security context used to derive the derived integrity key.
[0187] The UE security handling component 198 may reside within the cellular baseband processor 1124, the application processor 1106, or both the cellular baseband processor 1124 and the application processor 1106. The UE security handling component may be one or more hardware components specifically configured to perform the described process / algorithm, implemented by one or more processors configured to perform the described process / algorithm, stored in a computer-readable medium for implementation by one or more processors, or any combination thereof.
[0188] As shown, the device 1104 may include various components configured for various functions. For example, the UE security handling component may include one or more hardware components that perform each of the algorithm blocks in the flowcharts of Figures 7, 8, 9, and / or 10.
[0189] In one configuration, the device 1104, and more specifically, the cellular baseband processor 1124 and / or application processor 1106, are means for sending a first tracking area update (TAU) request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request is mapped to a second RAT associated with the first network entity. The system includes means comprising a first set of information including an identifier; means for sending a second TAU request to a first network entity, wherein the second TAU request comprises a first set of information and the second TAU request is integrity protected using a second uplink count; means for deriving a mapped security context based on a first security context and at least one of the first uplink count or the second uplink count; and means for communicating with the first network entity based on the mapped security context.
[0190] In an alternative configuration, the exemplary device 1104 also includes means for sending a first TAU request when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT, wherein the second RAT is different from the first RAT and the first network entity is associated with the second RAT.
[0191] In an alternative configuration, the second TAU request consists of an iteration of the first TAU request, and the second uplink count is the same value as the first uplink count.
[0192] In another configuration, the exemplary device 1104 also includes means for transmitting a second TAU request based on the occurrence of a radio link failure.
[0193] In another configuration, the mapped security context is associated with a second RAT.
[0194] In another configuration, the second uplink count is different from the first uplink count, and the mapped security context is the first mapped security context. Exemplary device 1104 also includes means for deriving the second mapped security context based on the first security context and the first uplink count, wherein the second TAU request is encoded using the first security context and integrity protected using the second uplink count, and the first mapped security context is derived based on the first security context and the second uplink count.
[0195] In an alternative configuration, the exemplary device 1104 also includes means for updating the security context of the UE from a second mapped security context to the first mapped security context based on the derivation of a first mapped security context, and means for discarding pending transmissions that would otherwise be integrity protected using the second mapped security context after updating the security context of the UE.
[0196] In another configuration, the second TAU request includes an iteration of the first TAU request.
[0197] In one configuration, when the device 1104, and more specifically the cellular baseband processor 1124 and / or application processor 1106, performs a change from the first cell associated with the first RAT to connect to a second cell associated with a second RAT different from the first radio access technology (RAT), means for sending a first tracking area update (TAU) request to a first network entity, wherein the first network entity is associated with the second RAT, the first TAU request is encoded using a first security context associated with the first RAT, and the first TAU request is integrity protected using a first uplink count based on the first security context, means for deriving a first integrity key based on the first security context, the first uplink count, and the first mapped security context, and means for sending a first tracking area update (TAU) request to the first network entity Means for transmitting a first TAU request iteration, wherein the first TAU request iteration is integrity protected using a second uplink count different from a first uplink count; means for deriving a second integrity key based on a first security context, a second uplink count, and a second mapped security context; means for receiving a downlink transmission from a first network entity; means for performing an integrity check on the downlink transmission using at least one of the first integrity key and the second integrity key; and means for setting a master security key for the UE when the integrity check on the downlink transmission is successful, using the derived integrity key, wherein the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.
[0198] In an alternative configuration, exemplary device 1104 also includes means for erasing a second mapped security context and any keys derived using the second mapped security context when an integrity check in a downlink transmission is successful using a first integrity key, wherein the master security key includes the first mapped security context.
[0199] In another configuration, exemplary device 1104 also includes means for erasing the first mapped security context and any keys derived using the first mapped security context when an integrity check in a downlink transmission is successful using a second integrity key, wherein the master security key includes the second mapped security context.
[0200] In another configuration, the exemplary device 1104 also includes means for deriving a first mapped security context based on a first security context and a first uplink count.
[0201] The means may be a UE security handling component 198 of the device 1104, configured to perform the functions enumerated by the means. As described above, the device 1104 may include a TX processor 368, an RX processor 356, and a controller / processor 359. Thus, in one configuration, the means may be a TX processor 368, an RX processor 356, and / or a controller / processor 359, configured to perform the functions enumerated by the means.
[0202] Figure 12 is a flowchart 1200 of a wireless communication method. The method can be performed by a first network entity (for example, base station 102, or components of base station 102, MME 412, AMF 432, network entity 1602 in Figure 16, and / or network entity 1760 in Figure 17). The method can facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0203] The first network entity may communicate with the UE and the second network entity. In some examples, the first network entity may include an MME such as MME606 in Figure 6, and the second network entity may include an AMF such as AMF608 in Figure 6.
[0204] In 1202, the first network entity obtains a first TAU request generated by the UE, as described with respect to the first TAU request message 610 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU request message 610. The first TAU request may include a first set of information containing identifiers mapped to a second RAT associated with the first network entity, as described with respect to the mapped EPS GUTI 612 in Figure 6. In 1202, the acquisition of the first TAU request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0205] In 1204, the first network entity outputs a first context request for the second network entity based on the first TAU request, as described with respect to the context request message 622 and AMF608 in Figure 6. The second network entity may be associated with the first RAT, such as AMF608 associated with the 5G network 609. In some examples, the first context request may include an identifier mapped to the second RAT, such as the mapped EPS GUTI612 in the first TAU request message 610 in Figure 6. In some examples, the first TAU request may be integrity protected using the first uplink count. In 1204, the output of the first context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0206] In 1206, the first network entity obtains a first mapped security context based on a first context request, as described with respect to the mapped EPS security context 636 in Figure 6. The first mapped security context may be derived from the first security context and the first uplink count. In 1206, obtaining the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0207] In 1208, the first network entity receives a second TAU request, as described with respect to the second TAU request message 670 in Figure 6. The second TAU request may be encoded using the first security context. The second TAU request may be integrity-protected using a second uplink count different from the first uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. As described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameter 616 in Figure 6, the second TAU request may contain a first set of information. In some examples, the second TAU request may contain an iteration of the first TAU request. In 1208, the acquisition of the second TAU request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0208] In 1210, the first network entity outputs a second context request for the second network entity based on the second TAU request, as described with respect to the second context request message 674 in Figure 6. In 1210, the output of the second context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0209] In 1212, the first network entity obtains a second mapped security context based on a second context request, wherein the second mapped security context is derived from the first security context and the second uplink count. The manner in which the second mapped security context is obtained may be similar to that of obtaining the first mapped security context, as described with respect to the mapped EPS security context 636 in Figure 6. The acquisition of the second mapped security context in 1212 may be performed by the network security handling component 199 of the network entity 1602 in Figure 16, and / or the network security handling component 497 of the network entity 1760 in Figure 17.
[0210] In 1214, the first network entity outputs a downlink message based on the second mapped security context, as described with respect to the TAU reception message 662 in Figure 6. In 1214, the output of the downlink message may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0211] Figure 13 is a flowchart 1300 of a wireless communication method. The method can be performed by a first network entity (for example, base station 102, or components of base station 102, MME 412, AMF 432, network entity 1602 in Figure 16, and / or network entity 1760 in Figure 17). The method can facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0212] The first network entity may communicate with the UE and the second network entity. In some examples, the first network entity may include an MME such as MME606 in Figure 6, and the second network entity may include an AMF such as AMF608 in Figure 6.
[0213] In 1302, the first network entity obtains a first TAU request generated by the UE, as described with respect to the first TAU request message 610 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU request message 610. The first TAU request may include a first set of information containing identifiers mapped to a second RAT associated with the first network entity, as described with respect to the mapped EPS GUTI 612 in Figure 6. In 1302, the acquisition of the first TAU request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0214] In some examples, the first network entity may derive the address of the second network entity based on an identifier mapped to the second RAT, as described with respect to 620 in Figure 6, in 1304. The derivation of the address of the second network entity in 1304 may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0215] In 1306, the first network entity outputs a first context request for the second network entity based on the first TAU request, as described with respect to the context request message 622 and AMF608 in Figure 6. The second network entity may be associated with the first RAT, such as AMF608 associated with the 5G network 609. In some examples, the first context request may include an identifier mapped to the second RAT, such as the mapped EPS GUTI612 in the first TAU request message 610 in Figure 6. In some examples, the first TAU request may be integrity protected using the first uplink count. In 1306, the output of the first context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0216] In 1308, the first network entity obtains a first mapped security context based on a first context request, as described with respect to the mapped EPS security context 636 in Figure 6. The first mapped security context may be derived from the first security context and the first uplink count. In 1308, the acquisition of the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0217] In 1310, the first network entity receives a second TAU request, as described with respect to the second TAU request message 670 in Figure 6. The second TAU request may be encoded using the first security context. The second TAU request may be integrity-protected using a second uplink count different from the first uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. As described with respect to the mapped EPS GUTI 612, NAS-MAC 614, and eKSI parameter 616 in Figure 6, the second TAU request may contain a first set of information. In some examples, the second TAU request may contain an iteration of the first TAU request. In 1310, the acquisition of the second TAU request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0218] In 1312, the first network entity outputs a second context request for the second network entity based on the second TAU request, as described with respect to the second context request message 674 in Figure 6. In 1312, the output of the second context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0219] In 1314, the first network entity obtains a second mapped security context based on a second context request, wherein the second mapped security context is derived from the first security context and the second uplink count. The manner in which the second mapped security context is obtained may be similar to that of obtaining the first mapped security context, as described with respect to the mapped EPS security context 636 in Figure 6. The acquisition of the second mapped security context in 1314 may be performed by the network security handling component 199 of the network entity 1602 in Figure 16, and / or the network security handling component 497 of the network entity 1760 in Figure 17.
[0220] In 1316, the first network entity outputs a downlink message based on the second mapped security context, as described with respect to the TAU reception message 662 in Figure 6. In 1316, the output of the downlink message may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0221] In some examples, in 1318, the first network entity may update its security context from the first mapped security context to the second mapped security context based on obtaining the second mapped security context. The update of the security context of the first network entity in 1318 may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0222] Furthermore, in 1320, the first network entity may, after updating the security context of the first network entity, discard any pending downlink transmissions that are integrity protected using the first mapped security context. In 1320, the discarding of pending downlink transmissions may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0223] In some examples, the first network entity may receive a second TAU request message with the same information elements at 1310 after outputting a downlink message at 1316 and before receiving an uplink message in response to the downlink message. For example, the first network entity may receive a second TAU request message after outputting a TAU accepted message 662 and before receiving a TAU completed message 666.
[0224] In some examples, the UE is configured to operate in single registration mode, and the downlink message includes a TAU acceptance message, and the first network entity may retransmit the downlink message. In some examples, the first network entity may restart the T3450 timer when a TAU completion message is expected from the UE, such as the TAU completion message 666 in Figure 6. The first network entity may also skip incrementing the retransmission counter for the T3450 timer.
[0225] In some examples, the first network entity obtains a first TAU request in 1302 based on an inter-system change from N1 mode to S1 mode. The UE is configured to operate in single registration mode, and the downlink message includes a TAU acceptance message, and the first network entity may initiate an authentication procedure with the UE. The first network entity may also execute a security mode control procedure to transition a new partial native EPS security context to the current full native EPS security context. For example, the first network entity may execute NAS SMC procedure 660 with the UE to transition a partial native EPS security context to a full native EPS security context in order to facilitate communication between the UE and EPS NAS messages.
[0226] In some examples where the security mode control procedure succeeds, the first network entity may output a downlink message repetition, which is then integrity-protected using the current full native EPS security context. The first network entity may also restart the T3450 timer when a TAU completion message is expected from the UE, such as TAU completion message 666 in Figure 6. The first network entity may also skip incrementing the retransmission counter for the T3450 timer.
[0227] In some examples, where the first network entity receives a first TAU request in 1302 based on a non-system-to-system change from N1 mode to S1 mode, and the UE is configured to operate in single registration mode, the first network entity may skip the initiation of the TAU procedure based on a second TAU request. The first network entity may also protect the integrity of downlink messages based on a first mapped security context.
[0228] In some examples, where the first network entity receives a first TAU request at 1302 based on an inter-system change from N1 mode to S1 mode, and the UE is configured to operate in single registration mode, the first network entity may decide to initiate a second TAU procedure. For example, the first network entity may output a second context request to the second network entity at 1312. The first network entity may also integrity protect downlink messages based on the second mapped security context.
[0229] In some cases, the first network entity may receive a TAU request message but has not yet sent a TAU accepted or rejected message. If one or more informational elements in the TAU request message are different, a TAU procedure initiated based on the first TAU request message may be aborted, while a TAU procedure initiated based on the second TAU request message may proceed (for example, proceed).
[0230] If the information elements in the TAU request message are the same (e.g., not different), then in any manner other than a system-to-system change from N1 mode to S1 mode in IDLE mode with a UE operating in single registration mode, the first network entity may continue the previously initiated TAU procedure (e.g., based on the first TAU request message) and discard the second TAU request message. That is, the first network entity may refrain from sending a second context request message to the second network entity requesting a new mapped EPS security context based on the second TAU request message.
[0231] In an inter-system change from N1 mode to S1 mode in IDLE mode with a UE operating in single registration mode, the first network entity may forward a new TAU request message to the second network entity (e.g., through another context request message) in order to perform an integrity check, obtain the latest mapped EPS security context, and continue the previous TAU procedure. For example, the first network entity may forward a second TAU request message to the second network entity (e.g., through a second context request message). The second network entity may verify the second TAU request message. The second network entity may then generate a new mapped EPS security context based on the second TAU request message. For example, the new mapped EPS security context may be at least partially based on the 5G NAS uplink COUNT value (e.g., 6) associated with the second TAU request message. As a result, a new MME EPS key (e.g., K ASME The mapped EPS security context provided to the first network entity, including '_MME', is used to create a new UE EPS key (K ASME The new mapped security context containing '_UE2' may be the same. As a result, the first network entity may have a new MME EPS key (e.g., K ASME When using '_MME)' to ensure the integrity of subsequent NAS messages (e.g., TAU reception messages), the UE may succeed in performing integrity verification on the later received NAS messages (e.g., TAU reception messages). In some examples, the UE may update its security context from the mapped EPS security context to the new mapped EPS security context based on the derivation of the new mapped EPS security context.
[0232] Figure 14 is a flowchart 1400 of a wireless communication method. The method may be performed by a second network entity (for example, base station 102, or components of base station 102, MME 412, AMF 432, network entity 1602 in Figure 16, and / or network entity 1760 in Figure 17). The method may facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0233] A second network entity may communicate with a first network entity. In some examples, the first network entity may include an MME such as MME606 in Figure 6, and the second network entity may include an AMF such as AMF608 in Figure 6.
[0234] In step 1402, the second network entity obtains a first context request, the first context request including at least a first TAU request generated by the UE, as described with respect to the context request message 622 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU request message 610. The first RAT may be different from a second RAT associated with the first network entity. For example, the first RAT may correspond to the 5G network 609, and the second RAT associated with the first network entity may correspond to the EPS network 607 associated with the MME 606 in Figure 6. In 1402, the acquisition of the first context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0235] In 1404, the second network entity derives a first mapped security context when the first integrity check in the first TAU request is successful, as described with respect to 632, 634 in Figure 6 and the mapped EPS security context 636. In 1404, the derivation of the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16 and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0236] In 1406, the second network entity outputs a first mapped security context for the first network entity, as described with respect to the mapped EPS security context 636 and context response message 638 in Figure 6. In 1406, the output of the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0237] In 1408, the second network entity obtains a second context request, the second context request includes at least a second TAU request generated by the UE, as described with respect to the second context request message 674 which includes a TAU request in Figure 6. The second TAU request may be integrity-protected using a second uplink count different from the first uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. In 1408, obtaining the second context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0238] In 1410, the second network entity derives a second mapped security context when the second integrity check in the second TAU request is successful. The manner in which the second mapped security context is derived may be similar to that of deriving the first mapped security context, as described with respect to 632, 634 and the mapped EPS security context 636 in Figure 6. In 1410, the derivation of the second mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0239] In 1412, the second network entity outputs a second mapped security context for the first network entity. The manner in which the second mapped security context is output may be similar to that which outputs the first mapped security context, as described with respect to the mapped EPS security context 636 and context response message 638 in Figure 6. In 1412, the output of the second mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0240] Figure 15 is a flowchart 1500 of a wireless communication method. The method may be performed by a second network entity (for example, base station 102, or components of base station 102, MME 412, AMF 432, network entity 1602 in Figure 16, and / or network entity 1760 in Figure 17). The method may facilitate improved communication performance by improving security handling of re-selection from a first cell to a second cell, in an example that includes retransmission of RLF and TAU request messages.
[0241] A second network entity may communicate with a first network entity. In some examples, the first network entity may include an MME such as MME606 in Figure 6, and the second network entity may include an AMF such as AMF608 in Figure 6.
[0242] In step 1502, the second network entity obtains a first context request, the first context request includes at least a first TAU request generated by the UE, as described with respect to the context request message 622 in Figure 6. The first TAU request may be encoded using a first security context associated with the first RAT, such as the 5G security context 690 in Figure 6. The first TAU request may be integrity protected using a first uplink count based on the first security context, such as the 5G NAS uplink count associated with the first TAU request message 610. The first RAT may be different from a second RAT associated with the first network entity. For example, the first RAT may correspond to the 5G network 609, and the second RAT associated with the first network entity may correspond to the EPS network 607 associated with the MME 606 in Figure 6. In 1502, the acquisition of the first context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0243] In some examples, the first context request may further include identifiers mapped to the second RAT, such as the illustrated mapped EPS GUTI612 in Figure 6.
[0244] In 1504, the second network entity derives a first mapped security context when the first integrity check in the first TAU request is successful, as described with respect to 632, 634 in Figure 6 and the mapped EPS security context 636. In 1504, the derivation of the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16 and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0245] In some examples, a second network entity may perform a first integrity check in a first TAU request based on the first security context, as described with respect to 632 in Figure 6 and 5G NAS security context 692.
[0246] In 1506, the second network entity outputs a first mapped security context for the first network entity, as described with respect to the mapped EPS security context 636 and context response message 638 in Figure 6. In 1506, the output of the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0247] In some examples, at 1508, the second network entity may start a timer after outputting the first mapped security context. At 1508, the timer may be started by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0248] In some examples, in 1510, the second network entity may clear the first mapped security context after the timer expires. In 1510, the clearing of the first mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0249] In 1512, the second network entity obtains a second context request, the second context request includes at least a second TAU request generated by the UE, as described with respect to the second context request message 674 which includes the TAU request in Figure 6. The second TAU request may be integrity-protected using a second uplink count different from the first uplink count. For example, the first TAU request may be integrity-protected using an uplink NAS count value of 5, and the second TAU request may be integrity-protected using an uplink NAS count value of 6. In 1512, obtaining the second context request may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0250] In some examples, the second TAU request may include an iteration of the first TAU request.
[0251] In 1514, the second network entity derives a second mapped security context when the second integrity check in the second TAU request is successful. The manner in which the second mapped security context is derived may be similar to that of deriving the first mapped security context, as described with respect to 632, 634 and the mapped EPS security context 636 in Figure 6. In 1514, the derivation of the second mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0252] In 1516, the second network entity outputs a second mapped security context for the first network entity. The manner in which the second mapped security context is output may be similar to that which outputs the first mapped security context, as described with respect to the mapped EPS security context 636 and context response message 638 in Figure 6. In 1516, the output of the second mapped security context may be performed by the network security handling component 199 of network entity 1602 in Figure 16, and / or the network security handling component 497 of network entity 1760 in Figure 17.
[0253] Figure 16 is Figure 1600, which shows an example of a hardware implementation for network entity 1602. Network entity 1602 may be a BS, a component of a BS, or implement BS functionality. Network entity 1602 may include at least one of CU1610, DU1630, or RU1640. For example, depending on the layer functionality handled by the network security handling component 199, network entity 1602 may include CU1610, both CU1610 and DU1630, each of CU1610, DU1630, and RU1640, DU1630, both DU1630 and RU1640, or RU1640. CU1610 may include a CU processor 1612. CU processor 1612 may include on-chip memory 1612'. In some embodiments, CU1610 may further include an additional memory module 1614 and a communication interface 1618. CU1610 communicates with DU1630 through a midhaul link such as an F1 interface. DU1630 may include a DU processor 1632. DU processor 1632 may include on-chip memory 1632'. In some embodiments, DU1630 may further include an additional memory module 1634 and a communication interface 1638. DU1630 communicates with RU1640 through a fronthaul link. RU1640 may include an RU processor 1642. RU processor 1642 may include on-chip memory 1642'. In some embodiments, RU1640 may further include an additional memory module 1644, one or more transceivers 1646, an antenna 1680, and a communication interface 1648. RU1640 communicates with UE104. On-chip memory (e.g., on-chip memory 1612', on-chip memory 1632', and / or on-chip memory 1642'), and / or additional memory modules (e.g., additional memory module 1614, additional memory module 1634, and / or additional memory module 1644) may each be considered a computer-readable medium / memory. Each computer-readable medium / memory may be non-transient.Each of the CU processor 1612, DU processor 1632, and RU processor 1642 is responsible for general processing, including the execution of software stored on computer-readable media / memory. When the software is executed by the corresponding processor, it causes the processor to perform the various functions described above. Computer-readable media / memory may also be used to store data manipulated by the processor when the software is executed.
[0254] As described above, the network security handling component 199 receives a first tracking area update (TAU) request generated by a user device (UE), wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with a first network entity; based on the first TAU request, outputs a first context request for a second network entity, wherein the second network entity is associated with the first RAT; and based on the first context request, receives a first mapped security context, which is the first mapped The system is configured to: derive a security context from a first security context and a first uplink count; receive a second TAU request, the second TAU request being encoded using the first security context and integrity protected using a second uplink count different from the first uplink count, and the second TAU request containing a first set of information; output a second context request for a second network entity based on the second TAU request; receive a second mapped security context based on the second context request, the second mapped security context being derived from a first security context and a second uplink count; and send a downlink message based on the second mapped security context.
[0255] In another embodiment, the network security handling component 199 receives a first context request, the first context request includes at least a first tracking area update (TAU) request generated by a user device (UE), the first TAU request is integrity protected using a first uplink count, the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first RAT is different from a second RAT associated with a first network entity, and when the first integrity check in the first TAU request is successful, the first mapped security context The system may be configured to derive text, output a first mapped security context for a first network entity, receive a second context request, the second context request includes at least a second TAU request generated by the UE, the second TAU request is integrity protected using a second uplink count different from the first uplink count, derive a second mapped security context when a second integrity check in the second TAU request is successful, and output the second mapped security context for the first network entity.
[0256] The network security handling component 199 may be located within one or more processors of CU1610, DU1630, and RU1640. The network security handling component 199 may be one or more hardware components specifically configured to execute the described process / algorithm, implemented by one or more processors configured to execute the described process / algorithm, stored in a computer-readable medium for implementation by one or more processors, or any combination thereof.
[0257] In one configuration, network entity 1602 may be a first network entity, and means for obtaining a first tracking area update (TAU) request generated by a user device (UE), wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; means for outputting a first context request for a second network entity based on the first TAU request, wherein the second network entity is associated with the first RAT; and means for obtaining a first mapped security context based on the first context request, The system includes means for deriving a mapped security context from a first security context and a first uplink count; means for obtaining a second TAU request, wherein the second TAU request is encoded using the first security context, the second TAU request is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information; means for outputting a second context request for a second network entity based on the second TAU request; means for obtaining a second mapped security context based on the second context request, wherein the second mapped security context is derived from the first security context and a second uplink count; and means for outputting a downlink message based on the second mapped security context.
[0258] In an alternative configuration, the first context request includes an identifier mapped to the second RAT, and the first TAU request is integrity-protected using the first uplink count.
[0259] In another configuration, the exemplary network entity 1602 also includes means for deriving the address of a second network entity based on an identifier mapped to a second RAT.
[0260] In another configuration, the exemplary network entity 1602 also includes means for updating the security context of a first network entity from a first mapped security context to a second mapped security context based on obtaining a second mapped security context, and means for discarding a pending downlink transmission protected for integrity using the first mapped security context after updating the security context of the first network entity.
[0261] In another configuration, a second TAU request includes a repetition of a first TAU request.
[0262] In another configuration, a first TAU request is obtained based on a non-inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU acceptance message, and the exemplary network entity 1602 also includes means for retransmitting the downlink message.
[0263] In another configuration, the exemplary network entity 1602 also includes means for restarting a T3450 timer and means for skipping incrementing a retransmission counter associated with the T3450 timer when a TAU completion message is expected from the UE.
[0264] In an alternative configuration, the first TAU request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, the downlink message includes a TAU acceptance message, and the exemplary network entity 1602 also includes means for initiating an authentication procedure and means for executing a security mode control procedure to transition a new partially native evolved packet system (EPS) security context to the current fully native EPS security context.
[0265] In an alternative configuration, the exemplary network entity 1602 also includes means for outputting a downlink message repetition when the security mode control procedure is successful, such that the downlink message repetition is integrity protected using the current full native EPS security context; means for restarting the T3450 timer when a TAU completion message is expected from the UE; and means for skipping incrementing the retransmission counter with respect to the T3450 timer.
[0266] In an alternative configuration, a first TAU request is obtained based on a non-system-to-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, and the exemplary network entity 1602 also includes means for skipping the initiation of a TAU procedure based on a second TAU request, and means for protecting the integrity of downlink messages based on a first mapped security context.
[0267] In an alternative configuration, a first TAU request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, and the exemplary network entity 1602 also includes means for deciding to initiate a second TAU procedure, which includes outputting a second context request to the second network entity and, based on the second mapped security context, ensuring the integrity of the downlink message.
[0268] In an alternative configuration, the first network entity includes a Mobility Management Entity (MME), and the second network entity includes an Access and Mobility Management Function (AMF).
[0269] In one configuration, network entity 1602 may be a second network entity, and means for obtaining a first context request, wherein the first context request includes at least a first tracking area update (TAU) request generated by a user device (UE), the first TAU request is integrity protected using a first uplink count, the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), and the first RAT is different from a second RAT associated with the first network entity, and when the first integrity check in the first TAU request is successful, the first mapped security The system includes means for deriving a context; means for outputting a first mapped security context for a first network entity; means for obtaining a second context request, wherein the second context request includes at least a second TAU request generated by the UE, and the second TAU request is integrity protected using a second uplink count different from the first uplink count; and means for deriving a second mapped security context when a second integrity check in the second TAU request is successful; and means for outputting a second mapped security context for the first network entity.
[0270] In another configuration, the first context request further includes an identifier mapped to the second RAT.
[0271] In another configuration, the second TAU request includes an iteration of the first TAU request.
[0272] In another configuration, the exemplary network entity 1602 also includes means for starting a timer after outputting a first mapped security context, and means for clearing the first mapped security context after the timer has expired.
[0273] In an alternative configuration, the exemplary network entity 1602 also includes means for performing a first integrity check in a first TAU request based on a first security context.
[0274] In an alternative configuration, the first network entity includes a Mobility Management Entity (MME), and the second network entity includes an Access and Mobility Management Function (AMF).
[0275] The means may be a network security handling component 199 of the network entity 1602, configured to perform the functions enumerated by the means. As described above, the network entity 1602 may include a TX processor 316, an RX processor 370, and a controller / processor 375. Thus, in one configuration, the means may be the TX processor 316, the RX processor 370, and / or the controller / processor 375, configured to perform the functions enumerated by the means.
[0276] Figure 17 is Figure 1700, which shows an example of a hardware implementation for network entity 1760. In one example, network entity 1760 may be within core network 120. Network entity 1760 may include network processor 1712. Network processor 1712 may include on-chip memory 1712'. In some embodiments, network entity 1760 may further include an additional memory module 1714. Network entity 1760 communicates with CU 1702 directly (e.g., via a backhaul link) or indirectly (e.g., via RIC) via network interface 1780. On-chip memory 1712' and additional memory module 1714 can be considered as computer-readable media / memory, respectively. Each computer-readable media / memory may be non-transient. Network processor 1712 is responsible for general processing, including the execution of software stored on the computer-readable media / memory. When the software is executed by the corresponding processor, it causes the processor to perform the various functions described above. Computer-readable media / memory can also be used to store data that is manipulated by the processor when software is running.
[0277] As described above, the network security handling component 497 receives a first tracking area update (TAU) request generated by a user device (UE), wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with a first network entity; based on the first TAU request, outputs a first context request for a second network entity, wherein the second network entity is associated with the first RAT; and based on the first context request, receives a first mapped security context, which is the first mapped The system is configured to: derive a security context from a first security context and a first uplink count; receive a second TAU request, the second TAU request being encoded using the first security context and integrity protected using a second uplink count different from the first uplink count, and the second TAU request containing a first set of information; output a second context request for a second network entity based on the second TAU request; receive a second mapped security context based on the second context request, the second mapped security context being derived from a first security context and a second uplink count; and send a downlink message based on the second mapped security context.
[0278] In another embodiment, the network security handling component 497 receives a first context request, the first context request includes at least a first tracking area update (TAU) request generated by a user device (UE), the first TAU request is integrity protected using a first uplink count, the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first RAT is different from a second RAT associated with a first network entity, and when the first integrity check in the first TAU request is successful, the first mapped security context The system may be configured to derive text, output a first mapped security context for a first network entity, receive a second context request, the second context request includes at least a second TAU request generated by the UE, the second TAU request is integrity protected using a second uplink count different from the first uplink count, derive a second mapped security context when a second integrity check in the second TAU request is successful, and output the second mapped security context for the first network entity.
[0279] The network security handling component 497 may be located within the network processor 1712. The network security handling component 497 may be one or more hardware components specifically configured to execute the described process / algorithm, implemented by one or more processors configured to execute the described process / algorithm, stored in a computer-readable medium for implementation by one or more processors, or any combination thereof. The network entity 1760 may include various components configured for various functions.
[0280] In one configuration, network entity 1760 may be a first network entity, and means for obtaining a first tracking area update (TAU) request generated by a user device (UE), wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; means for outputting a first context request for a second network entity based on the first TAU request, wherein the second network entity is associated with the first RAT; and means for obtaining a first mapped security context based on the first context request, The system includes means for deriving a mapped security context from a first security context and a first uplink count; means for obtaining a second TAU request, wherein the second TAU request is encoded using the first security context, the second TAU request is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information; means for outputting a second context request for a second network entity based on the second TAU request; means for obtaining a second mapped security context based on the second context request, wherein the second mapped security context is derived from the first security context and a second uplink count; and means for outputting a downlink message based on the second mapped security context.
[0281] In an alternative configuration, the first context request includes an identifier mapped to the second RAT, and the first TAU request is integrity-protected using the first uplink count.
[0282] In another configuration, the exemplary network entity 1760 also includes means for deriving the address of a second network entity based on an identifier mapped to a second RAT.
[0283] In another configuration, the exemplary network entity 1760 also includes means for updating the security context of a first network entity from a first mapped security context to a second mapped security context based on obtaining a second mapped security context, and means for discarding a pending downlink transmission protected for integrity using the first mapped security context after updating the security context of the first network entity.
[0284] In another configuration, a second TAU request includes an iteration of a first TAU request.
[0285] In another configuration, a first TAU request is obtained based on a non-inter-system change from N1 mode to S1 mode, the UE is configured to operate in a single registration mode, the downlink message includes a TAU acceptance message, and the exemplary network entity 1760 also includes means for retransmitting the downlink message.
[0286] In another configuration, the exemplary network entity 1760 also includes means for restarting a T3450 timer and means for skipping incrementing a retransmission counter for the T3450 timer when a TAU completion message is expected from the UE.
[0287] In an alternative configuration, the first TAU request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, the downlink message includes a TAU acceptance message, and the exemplary network entity 1760 also includes means for initiating an authentication procedure and means for executing a security mode control procedure to transition a new partially native evolved packet system (EPS) security context to the current fully native EPS security context.
[0288] In an alternative configuration, the exemplary network entity 1760 also includes means for outputting a downlink message repetition when the security mode control procedure is successful, such that the downlink message repetition is integrity protected using the current full native EPS security context; means for restarting the T3450 timer when a TAU completion message is expected from the UE; and means for skipping incrementing the retransmission counter with respect to the T3450 timer.
[0289] In an alternative configuration, a first TAU request is obtained based on a non-system-to-system change from N1 mode to S1 mode, and the UE is configured to operate in single registration mode. The exemplary network entity 1760 also includes means for skipping the initiation of a TAU procedure based on a second TAU request, and means for protecting the integrity of downlink messages based on a first mapped security context.
[0290] In an alternative configuration, a first TAU request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, and the exemplary network entity 1760 also includes means for deciding to initiate a second TAU procedure, which includes outputting a second context request to the second network entity and, based on the second mapped security context, ensuring the integrity of the downlink message.
[0291] In an alternative configuration, the first network entity includes a Mobility Management Entity (MME), and the second network entity includes an Access and Mobility Management Function (AMF).
[0292] In one configuration, network entity 1760 may be a second network entity, and means for obtaining a first context request, wherein the first context request includes at least a first tracking area update (TAU) request generated by a user device (UE), the first TAU request is integrity protected using a first uplink count, the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), and the first RAT is different from a second RAT associated with the first network entity, and when the first integrity check in the first TAU request is successful, the first mapped security The system includes means for deriving a context; means for outputting a first mapped security context for a first network entity; means for obtaining a second context request, wherein the second context request includes at least a second TAU request generated by the UE, and the second TAU request is integrity protected using a second uplink count different from the first uplink count; and means for deriving a second mapped security context when a second integrity check in the second TAU request is successful; and means for outputting a second mapped security context for the first network entity.
[0293] In another configuration, the first context request further includes an identifier mapped to the second RAT.
[0294] In another configuration, the second TAU request includes an iteration of the first TAU request.
[0295] In another configuration, the exemplary network entity 1760 also includes means for starting a timer after outputting a first mapped security context, and means for clearing the first mapped security context after the timer has expired.
[0296] In an alternative configuration, the exemplary network entity 1760 also includes means for performing a first integrity check in a first TAU request based on a first security context.
[0297] In an alternative configuration, the first network entity includes a Mobility Management Entity (MME), and the second network entity includes an Access and Mobility Management Function (AMF).
[0298] The means may be a network security handling component 497 of the network entity 1760, configured to perform the functions enumerated by the means. As described above, the network entity 1760 may include a network processor 1712. Thus, in one configuration, the means may be a network processor 1712 configured to perform the functions enumerated by the means.
[0299] The examples disclosed herein provide techniques for eliminating inconsistencies in the handling of TAU request message repetitions as described above. For example, the disclosed techniques may eliminate inconsistencies by modifying how the network handles TAU request message repetitions. The disclosed techniques may, additionally or alternatively, eliminate inconsistencies by modifying how the UE protects the integrity of TAU request messages. Furthermore, the disclosed techniques may eliminate inconsistencies by modifying how the UE performs message integrity verification.
[0300] It should be understood that the specific order or hierarchy of blocks in the disclosed process / flowchart is illustrative of an exemplary technique. It should also be understood that the specific order or hierarchy of blocks in the process / flowchart may be rearranged based on design preferences. Furthermore, some blocks may be combined or omitted. The attached method claims present various block elements in an exemplary order, and are not limited to the specific order or hierarchy presented.
[0301] The above description is provided to enable any person skilled in the art to practice the various embodiments described herein. Various modifications to these embodiments will be readily apparent to a person skilled in the art, and the general principles defined herein may apply to other embodiments. Accordingly, the claims should not be limited to the embodiments described herein, but should be given the entire scope consistent with the claim language. References to elements in the singular form mean "one or more," not "unique," unless otherwise explicitly stated. Terms such as "if," "when," and "while" do not imply an immediate temporal relationship or response. That is, these phrases, for example, "when," do not imply an immediate action in response to or during the occurrence of an action, but merely imply that an action will occur if the conditions are met, but without requiring any specific or immediate temporal constraints for the action to occur. The word "exemplary" is used herein to mean "to serve as an example, case, or illustration." Any embodiment described herein as "exemplary" should not necessarily be construed as being preferable or advantageous to any other embodiment. Unless otherwise specified, the term “several” refers to one or more. Combinations such as “at least one of A, B, or C,” “one or more of A, B, or C,” “at least one of A, B, and C,” “one or more of A, B, and C,” and “A, B, C, or any combination thereof” include any combination of A, B, and / or C, and may include multiple A, multiple B, or multiple C. Specifically, combinations such as “at least one of A, B, or C,” “one or more of A, B, or C,” “at least one of A, B, and C,” “one or more of A, B, and C,” and “A, B, C, or any combination thereof” may be A only, B only, C only, A and B, A and C, B and C, or A and B and C, and any such combination may include one or more members of A, B, or C.A set should be interpreted as a set of elements, where an element consists of one or more. Therefore, in the case of a set of X, X will contain one or more elements. When the first device receives data from or transmits data to the second device, the data may be received / transmitted directly between the first and second devices, or indirectly between the first and second devices through a set of devices. All structural and functional equivalents of the various aspects of the elements described throughout this disclosure, known to those skilled in the art or to be known later, are expressly incorporated herein by reference and are encompassed by the claims. Furthermore, nothing disclosed herein is made public, whether such disclosure is expressly enumerated in the claims. The terms “module,” “mechanism,” “element,” and “device” may not be substitutes for the term “means.” Therefore, no claimed element should be interpreted as means plus function unless it is expressly enumerated using the phrase “means for.”
[0302] As used herein, the phrase “based on” should not be interpreted as referring to a closed set such as information, one or more conditions, or one or more factors. In other words, the phrase “based on A” (where “A” may be information, a condition, a factor, etc.) should be interpreted as “at least on A” unless otherwise specified.
[0303] The following embodiments are illustrative and not limiting, but may be combined with other embodiments or teachings described herein.
[0304] Embodiment 1 is a method for wireless communication in a UE, comprising the steps of: transmitting a first tracking area update (TAU) request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity; transmitting a second TAU request to the first network entity, wherein the second TAU request includes a first set of information, and the second TAU request is integrity-protected using a second uplink count; deriving a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count; and communicating with the first network entity based on the mapped security context.
[0305] Embodiment 2 is the method of Embodiment 1, further comprising the step of sending a first TAU request when performing a change from a first cell associated with a first RAT in order to connect to a second cell associated with a second RAT, wherein the second RAT is different from the first RAT and the first network entity is associated with the second RAT.
[0306] Embodiment 3 is any of the methods of Embodiments 1 and 2, further comprising the second TAU request comprising an iteration of the first TAU request, and the second uplink count being the same value as the first uplink count.
[0307] Embodiment 4 is any of embodiments 1 to 3, further comprising the step of sending a second TAU request based on the occurrence of a wireless link failure.
[0308] Embodiment 5 is any method of Embodiments 1 and 2, further comprising associating the mapped security context with a second RAT.
[0309] Embodiment 6 is a method of either Embodiment 1 or 2, further comprising the steps of deriving a second mapped security context based on a first security context and a first uplink count, wherein a second TAU request is encoded using the first security context and integrity protected using the second uplink count, and the first mapped security context is derived based on the first security context and the second uplink count.
[0310] Embodiment 7 is any of embodiments 1 and 6, further comprising the steps of updating the UE's security context from a second mapped security context to the first mapped security context based on the derivation of a first mapped security context, and, after updating the UE's security context, discarding any pending transmissions that would otherwise be integrity protected using the second mapped security context.
[0311] Embodiment 8 is any of embodiments 1, 6, and 7, further comprising the second TAU request including an iteration of the first TAU request.
[0312] Embodiment 9 is a device for wireless communication in a UE, comprising at least one processor coupled to memory and configured to implement any of embodiments 1 to 8.
[0313] In embodiment 10, the apparatus of embodiment 9 further includes at least one antenna coupled to at least one processor.
[0314] In embodiment 11, the apparatus of embodiment 9 or 10 further includes a transceiver coupled to at least one processor.
[0315] Embodiment 12 is a device for wireless communication, which includes means for implementing any of Embodiments 1 to 8.
[0316] In embodiment 13, the apparatus of embodiment 12 further includes at least one antenna coupled to means for performing any of the methods of embodiments 1 to 8.
[0317] In embodiment 14, the apparatus of embodiment 12 or 13 further includes a transceiver coupled to means for performing any of the methods of embodiments 1 to 8.
[0318] Embodiment 15 is a non-temporary computer-readable storage medium for storing computer executable code, wherein, when the code is executed, it causes a processor to implement any of embodiments 1 to 8.
[0319] Embodiment 16 is a method for wireless communication in a UE, the step of sending a first tracking area update (TAU) request to a first network entity when performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from a first radio access technology (RAT), the step of the first network entity being associated with the second RAT, the first TAU request being encoded using a first security context associated with the first RAT, and the first TAU request being integrity protected using a first uplink count based on the first security context, the step of deriving a first integrity key based on the first security context, the first uplink count, and the first mapped security context, and the step of sending iterations of the first TAU request to the first network entity. A method comprising the steps of: ensuring the integrity of an iteration of a first TAU request is protected using a second uplink count different from a first uplink count; deriving a second integrity key based on a first security context, a second uplink count, and a second mapped security context; receiving a downlink transmission from a first network entity; performing an integrity check on the downlink transmission using at least one of the first and second integrity keys; and setting a master security key for the UE when the integrity check on the downlink transmission is successful, using the derived integrity key, wherein the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key.
[0320] Embodiment 17 is the method of Embodiment 16, further comprising the step of erasing a second mapped security context and any keys derived using the second mapped security context when an integrity check in a downlink transmission is successful using a first integrity key, wherein the master security key includes the first mapped security context.
[0321] Embodiment 18 is the method of Embodiment 16, further comprising the step of erasing the first mapped security context and any keys derived using the first mapped security context when the integrity check in the downlink transmission is successful using a second integrity key, wherein the master security key includes the second mapped security context.
[0322] Embodiment 19 is any of the methods of embodiments 16 to 18, further comprising the step of deriving a first mapped security context based on a first security context and a first uplink count.
[0323] Embodiment 20 is a device for wireless communications in a UE, comprising at least one processor coupled to memory and configured to implement any of embodiments 16 to 19.
[0324] In embodiment 21, the apparatus of embodiment 20 further includes at least one antenna coupled to at least one processor.
[0325] In embodiment 22, the apparatus of embodiment 20 or 21 further includes a transceiver coupled to at least one processor.
[0326] Embodiment 23 is a device for wireless communication, which includes means for implementing any of embodiments 16 to 19.
[0327] In embodiment 24, the apparatus of embodiment 23 further includes at least one antenna coupled to means for performing any of the methods of embodiments 16 to 19.
[0328] In embodiment 25, the apparatus of embodiment 23 or 24 further includes a transceiver coupled to means for performing any of the methods of embodiments 16 to 19.
[0329] Embodiment 26 is a non-temporary computer-readable storage medium for storing computer executable code, wherein, when the code is executed, it causes a processor to implement any of embodiments 16 to 19.
[0330] Embodiment 27 is a method for wireless communication in a first network entity, comprising the steps of: obtaining a first tracking area update (TAU) request generated by a user device (UE), wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity protected using a first uplink count based on the first security context, and the first TAU request comprises a first set of information including an identifier mapped to a second RAT associated with a first network entity; outputting a first context request for a second network entity based on the first TAU request, wherein the second network entity is associated with the first RAT; and obtaining a first mapped security context based on the first context request, wherein the first mapping A method comprising the steps of: deriving a configured security context from a first security context and a first uplink count; obtaining a second TAU request, wherein the second TAU request is encoded using the first security context, the second TAU request is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of information; outputting a second context request for a second network entity based on the second TAU request; obtaining a second mapped security context based on the second context request, wherein the second mapped security context is derived from a first security context and a second uplink count; and outputting a downlink message based on the second mapped security context.
[0331] Embodiment 28 is the method of Embodiment 27, further comprising the first context request including an identifier mapped to a second RAT, and the first TAU request being integrity protected using a first uplink count.
[0332] Embodiment 29 is any of the methods of embodiments 27 and 28, further comprising the step of deriving the address of a second network entity based on an identifier mapped to a second RAT.
[0333] Embodiment 30 is any of embodiments 27 to 29, further comprising the steps of updating the security context of a first network entity from a first mapped security context to a second mapped security context based on obtaining a second mapped security context, and, after updating the security context of the first network entity, discarding any pending downlink transmissions that would otherwise be integrity protected using the first mapped security context.
[0334] Embodiment 31 is any of the methods of Embodiments 27 to 30, further comprising the second TAU request including an iteration of the first TAU request.
[0335] Embodiment 32 is any of the methods of Embodiments 27 to 31, further comprising the first TAU request being obtained based on a non-system-to-system change from N1 mode to S1 mode, the UE being configured to operate in single registration mode, and the downlink message comprising a TAU acceptance message, the method further comprising the step of retransmitting the downlink message.
[0336] Embodiment 33 is any of embodiments 27 to 32, further comprising the steps of restarting the T3450 timer when a TAU completion message is expected from the UE, and skipping the step of incrementing the retransmission counter for the T3450 timer.
[0337] Embodiment 34 is any method of Embodiments 27 to 31, further comprising the steps of: a first TAU request being obtained based on an inter-system change from N1 mode to S1 mode; the UE being configured to operate in single registration mode; and a downlink message containing a TAU acceptance message, wherein the method further comprises the steps of: initiating an authentication procedure; and executing a security mode control procedure to transition a new partially native evolved packet system (EPS) security context to the current fully native EPS security context.
[0338] Embodiment 35 is any method of embodiments 27 and 34, further comprising the steps of: outputting a downlink message repetition when the security mode control procedure is successful, wherein the downlink message repetition is integrity protected using the current full native EPS security context; restarting the T3450 timer when a TAU completion message is expected from the UE; and skipping incrementing the retransmission counter for the T3450 timer.
[0339] Embodiment 36 is any method of embodiments 27 to 31, further comprising the steps of: a first TAU request being obtained based on a non-system-to-system change from N1 mode to S1 mode, and the UE being configured to operate in single registration mode, wherein the method further comprises the steps of: skipping the initiation of a TAU procedure based on a second TAU request; and integrity protecting a downlink message based on a first mapped security context.
[0340] Embodiment 37 is any method of Embodiments 27 to 31, further comprising the first TAU request being obtained based on an inter-system change from N1 mode to S1 mode, and the UE being configured to operate in single registration mode, the method further comprising the step of deciding to initiate a second TAU procedure, which includes outputting a second context request to a second network entity, and integrity-protecting a downlink message based on a second mapped security context.
[0341] Embodiment 38 is any of embodiments 27 to 37, further comprising a first network entity including a mobility management entity (MME) and a second network entity including an access and mobility management function (AMF).
[0342] Embodiment 39 is a device for wireless communications in a UE, comprising at least one processor coupled to memory and configured to implement any of embodiments 27 to 38.
[0343] In embodiment 40, the apparatus of embodiment 39 further includes at least one antenna coupled to at least one processor.
[0344] In embodiment 41, the apparatus of embodiment 39 or 40 further includes a transceiver coupled to at least one processor.
[0345] Embodiment 42 is a device for wireless communication, which includes means for implementing any of embodiments 27 to 38.
[0346] In embodiment 43, the apparatus of embodiment 42 further includes at least one antenna coupled to means for performing any of the methods of embodiments 27 to 38.
[0347] In embodiment 44, the apparatus of embodiment 42 or 43 further includes a transceiver coupled to means for performing any of the methods of embodiments 27 to 38.
[0348] Embodiment 45 is a non-temporary computer-readable storage medium for storing computer executable code, wherein, when the code is executed, it causes a processor to implement any of embodiments 27 to 38.
[0349] Embodiment 46 is a method for wireless communication in a second network entity, comprising the steps of obtaining a first context request, wherein the first context request includes at least a first tracking area update (TAU) request generated by a user device (UE), the first TAU request is integrity protected using a first uplink count, the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first RAT is different from a second RAT associated with a first network entity, and when a first integrity check in the first TAU request is successful, a first mapped security context A method comprising the steps of: deriving text; outputting a first mapped security context for a first network entity; obtaining a second context request, wherein the second context request includes at least a second TAU request generated by the UE, and the second TAU request is integrity protected using a second uplink count different from the first uplink count; and, when a second integrity check in the second TAU request is successful, deriving a second mapped security context; and outputting a second mapped security context for the first network entity.
[0350] Embodiment 47 is the method of Embodiment 46, further comprising the first context request further including an identifier mapped to a second RAT.
[0351] Embodiment 48 is any of embodiments 46 and 47, further comprising the second TAU request including an iteration of the first TAU request.
[0352] Embodiment 49 is any of embodiments 46 to 48, further comprising the steps of: outputting a first mapped security context, then starting a timer; and, after the timer has expired, clearing the first mapped security context.
[0353] Embodiment 50 is any of the methods of embodiments 46 to 49, further comprising the step of performing a first integrity check in a first TAU request based on a first security context.
[0354] Embodiment 51 is any of embodiments 46 to 50, further comprising a first network entity including a mobility management entity (MME) and a second network entity including an access and mobility management function (AMF).
[0355] Embodiment 52 is a device for wireless communication in a UE, comprising at least one processor coupled to memory and configured to implement any of embodiments 46 to 51.
[0356] In embodiment 53, the apparatus of embodiment 52 further includes at least one antenna coupled to at least one processor.
[0357] In embodiment 54, the apparatus of embodiment 52 or 53 further includes a transceiver coupled to at least one processor.
[0358] Embodiment 55 is a device for wireless communication, which includes means for implementing any of embodiments 46 to 51.
[0359] In embodiment 56, the apparatus of embodiment 55 further includes at least one antenna coupled to means for performing any of the methods of embodiments 46 to 51.
[0360] In embodiment 57, the apparatus of embodiment 55 or 56 further includes a transceiver coupled to means for performing any of the methods of embodiments 46 to 51.
[0361] Embodiment 58 is a non-temporary computer-readable storage medium for storing computer executable code, wherein, when the code is executed, it causes a processor to implement any of embodiments 46 to 51. [Explanation of Symbols]
[0362] 102, 310 base station 104, 350, 404, 604 UE 105 SMO Framework 110, 1610, 1702 CU 111 Open eNB (O-eNB) 115 Non-Real-Time (Non-RT) RIC, Non-RT RIC 120, 430 core network 125 Near-RT RIC 130, 1630 DU 140, 1640 RU 150 Wi-Fi AP 154 Communication Links 158 D2D communication link 161, 432, 608 AMF 162,436 SMF 163,438 UPF 164,440 UDM 165 GMLC 166 LMF 168 Location Server 170 Satellite Positioning System (SPS) 182, 184 Beamformed signals 190 Open Cloud (O-Cloud) 198 UE Security Handling Components 199, 497 Network Security Handling Components 316, 368 TX processors 318Tx, 354Tx Transmitters 318Rx, 354Rx receivers 320, 352, 1180, 1680 antennas 356, 370 RX processors 358, 374 channel estimator 359, 375 Controllers / Processors 360, 376 memory 402a First network node, network node 402b Second network node, network node 406 Geographic Coverage Areas 408 Communication Link 410 EPC 412, 606 MME 414 Other MMEs 416 Serving Gateway 418 MBMS GW 420 BM-SC 422 PDN Gateway 424 HSS 426, 442 IP services 434 Other AMF 452 First backhaul link 454 Second backhaul link 456 Third backhaul link 500 First Security Context 502 Master Security Key 504 KSI 506 UE Security Capabilities 508 Uplink NAS Count 510 Downlink NAS Count 520 Second Security Context 522 5G key 524 5G KSI 526 5G UE Security Capabilities 528 5G uplink NAS count 530 5G Downlink NAS Count 540 The Third Security Context 542 EPS key 544 EPS KSI 546 EPS UE security capabilities 548 EPS uplink NAS count 550 EPS downlink NAS count 602 Network Nodes 607 EPS Network 609 5G network 610 First TAU request message 612 mapped EPS GUTI 613 TMSI 614 NAS-MAC 616 eKSI parameters 622 Context Request Message 636 Mapped EPS Security Contexts 638 Contextual response message 642 UE-mapped EPS security context, mapped EPS security context 660 NAS SMC Procedure 662 TAU Reception Message 666 TAU Completion Message 670 Second TAU request message 674 Second context request message 682 New UE-mapped EPS security context 690 5G Security Context 692 5G NAS Security Context 694 Security Algorithm Information 1102, 1602, 1760 Network Entities 1104 Equipment 1106 Application Processors 1106', 1124', 1612', 1632', 1642', 1712' On-chip memory 1108 Secure Digital (SD) Card 1110 screen 1112 Bluetooth module 1114 WLAN module 1116 SPS module 1118 Sensor Module 1120 Subscriber Identification Module (SIM) Card 1122 Cellular RF Transceiver 1124 Cellular Baseband Processor 1126, 1614, 1634, 1644, 1714 Additional memory modules 1130 Power supply 1132 Camera 1612 CU processor 1618, 1638, 1648 communication interfaces 1632 DU processor 1642 RU processor 1646 Transceiver 1712 Network Processors 1780 Network Interface
Claims
1. A device for wireless communication in user equipment (UE), Memory and At least one processor coupled to the memory and The at least one processor coupled to the memory is Sending a first Tracking Area Update (TAU) request to a first network entity, wherein the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. Sending a second TAU request to the first network entity, wherein the second TAU request includes a first set of the information, and the second TAU request is integrity protected using a second uplink count. Deriving a mapped security context based on the first security context and at least one of the first uplink count or the second uplink count, and Based on the mapped security context, communicate with the first network entity. A device configured to perform the following actions.
2. The aforementioned device The apparatus according to claim 1, further comprising at least one antenna coupled to the at least one processor, wherein the at least one processor coupled to the memory transmits the first TAU request when it performs a change from the first cell associated with the first RAT to connect to the second cell associated with the second RAT, wherein the second RAT is different from the first RAT and the first network entity is associated with the second RAT.
3. The apparatus according to claim 2, wherein the second TAU request comprises an iteration of the first TAU request, and the second uplink count is the same value as the first uplink count.
4. The apparatus according to claim 3, wherein the at least one processor coupled to the memory is configured to transmit the second TAU request based on the occurrence of a wireless link failure.
5. The apparatus according to claim 2, wherein the mapped security context is associated with the second RAT.
6. The second uplink count differs from the first uplink count, the mapped security context is the first mapped security context, and the at least one processor coupled to the memory is Deriving a second mapped security context based on the first security context and the first uplink count, wherein the second TAU request is encoded using the first security context and integrity protected using the second uplink count, and the first mapped security context is derived based on the first security context and the second uplink count. The apparatus according to claim 1, further configured to perform the following:
7. The at least one processor coupled to the memory, Based on the derivation of the first mapped security context, update the security context of the UE from the second mapped security context to the first mapped security context, and After updating the security context of the UE, discard any pending transmissions that are integrity protected using the second mapped security context. The apparatus according to claim 6, further configured to perform the following:
8. The apparatus according to claim 6, wherein the second TAU request includes an iteration of the first TAU request.
9. A device for wireless communication in user equipment (UE), Memory and At least one processor coupled to the memory and The at least one processor coupled to the memory is When performing a change from a first cell associated with a first RAT to connect to a second cell associated with a second RAT different from a first radio access technology (RAT), a first tracking area update (TAU) request is sent to a first network entity, wherein the first network entity is associated with the second RAT, the first TAU request is encoded using a first security context associated with the first RAT, and the first TAU request is integrity protected using a first uplink count based on the first security context. Deriving a first integrity key based on the first security context, the first uplink count, and the first mapped security context, Sending iterations of the first TAU request to the first network entity, wherein the iterations of the first TAU request are integrity-protected using a second uplink count different from the first uplink count. Deriving a second integrity key based on the first security context, the second uplink count, and the second mapped security context, Receiving a downlink transmission from the aforementioned first network entity, Using at least one of the first integrity key and the second integrity key, perform integrity checks in the downlink transmission, and Setting the master security key of the UE when the integrity check in the downlink transmission is successful using the derived integrity key, wherein the master security key is set based on the first mapped security context or the second mapped security context used to derive the derived integrity key. A device configured to perform the following actions.
10. The aforementioned device At least one antenna coupled to the at least one processor The memory further comprises the at least one processor coupled to the memory, If the integrity check in the downlink transmission is successful using the first integrity key, the second mapped security context and any keys derived using the second mapped security context are to be erased. It is further configured to do the following: The apparatus according to claim 9, wherein the master security key includes the first mapped security context.
11. The at least one processor coupled to the memory, When the integrity check in the downlink transmission is successful using the second integrity key, the first mapped security context and any keys derived using the first mapped security context are erased. It is further configured to do the following: The apparatus according to claim 9, wherein the master security key includes the second mapped security context.
12. The at least one processor coupled to the memory, Deriving the first mapped security context based on the first security context and the first uplink count. The apparatus according to claim 9, further configured to perform the following:
13. A device for wireless communication in a first network entity, Memory and At least one processor coupled to the memory and The at least one processor coupled to the memory is Obtaining a first Tracking Area Update (TAU) request generated by a User Equipment (UE), wherein the first TAU request is encoded using a first security context associated with a first Radio Access Technology (RAT), the first TAU request is integrity-protected using a first uplink count based on the first security context, and the first TAU request includes a first set of information including an identifier mapped to a second RAT associated with the first network entity. Based on the first TAU request, output a first context request for a second network entity, wherein the second network entity is associated with the first RAT. Obtaining a first mapped security context based on the first context request, wherein the first mapped security context is derived from the first security context and the first uplink count. Obtaining a second TAU request, wherein the second TAU request is encoded using the first security context, the second TAU request is integrity protected using a second uplink count different from the first uplink count, and the second TAU request includes a first set of the information. Based on the second TAU request, output a second context request for the second network entity. Obtaining a second mapped security context based on the second context request, wherein the second mapped security context is derived from the first security context and the second uplink count, and Output a downlink message based on the second mapped security context described above. A device configured to perform the following actions.
14. The apparatus according to claim 13, wherein the first context request includes the identifier mapped to the second RAT, and the first TAU request is integrity protected using the first uplink count.
15. The aforementioned device At least one antenna coupled to the at least one processor The memory further comprises the at least one processor coupled to the memory, The address of the second network entity is derived based on the identifier mapped to the second RAT. The apparatus according to claim 13, further configured to perform the following:
16. The at least one processor coupled to the memory, Based on obtaining the second mapped security context, the security context of the first network entity is updated from the first mapped security context to the second mapped security context, and After updating the security context of the first network entity, discard any pending downlink transmissions that would otherwise be integrity protected using the first mapped security context. The apparatus according to claim 13, further configured to perform the following:
17. The apparatus according to claim 13, wherein the second TAU request includes an iteration of the first TAU request.
18. The first TAU request is obtained based on a non-system-to-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, the downlink message includes a TAU acceptance message, and the at least one processor coupled to the memory is Resend the aforementioned downlink message. The apparatus according to claim 13, further configured to perform the following:
19. The at least one processor coupled to the memory, When a TAU completion message is expected from the UE, restart the T3450 timer, and Skip incrementing the retransmission counter for the T3450 timer. The apparatus according to claim 18, further configured to perform the following:
20. The first TAU request is obtained based on an inter-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, the downlink message includes a TAU acceptance message, and the at least one processor coupled to the memory, Initiating the authentication procedure, and To transition the new partially native Evolutionary Packet System (EPS) security context to the current fully native EPS security context, execute the security mode control procedure. The apparatus according to claim 13, further configured to perform the following:
21. The at least one processor coupled to the memory, When the security mode control procedure is successful, a downlink message repetition is output, wherein the downlink message repetition is integrity protected using the current full native EPS security context. When a TAU completion message is expected from the UE, restart the T3450 timer, and Skip incrementing the retransmission counter for the T3450 timer. The apparatus according to claim 20, further configured to perform the following:
22. The first TAU request is obtained based on a non-system-to-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, and the at least one processor coupled to the memory is Based on the second TAU request, the start of the TAU procedure is skipped, and Based on the first mapped security context, the downlink message is to be protected for integrity. The apparatus according to claim 13, further configured to perform the following:
23. The first TAU request is obtained based on a system-to-system change from N1 mode to S1 mode, the UE is configured to operate in single registration mode, and the at least one processor coupled to the memory is The decision is to initiate a second TAU procedure, Outputting the second context request to the second network entity, and Based on the second mapped security context, the downlink message is to be protected for integrity. including The apparatus according to claim 13, further configured to perform the following:
24. The apparatus according to claim 13, wherein the first network entity includes a mobility management entity (MME), and the second network entity includes an access and mobility management function (AMF).
25. A device for wireless communication in a second network entity, Memory and At least one processor coupled to the memory and The at least one processor coupled to the memory is Obtaining a first context request, wherein the first context request includes at least a first tracking area update (TAU) request generated by a user device (UE), the first TAU request is integrity protected using a first uplink count, the first TAU request is encoded using a first security context associated with a first radio access technology (RAT), and the first RAT is different from a second RAT associated with a first network entity. When the first integrity check in the first TAU request is successful, derive the first mapped security context. Outputting the first mapped security context for the first network entity, Obtaining a second context request, wherein the second context request includes at least a second TAU request generated by the UE, and the second TAU request is integrity protected using a second uplink count different from the first uplink count. When the second integrity check in the second TAU request is successful, a second mapped security context is derived, and Outputting the second mapped security context for the first network entity. A device configured to perform the following actions.
26. The apparatus according to claim 25, wherein the first context request further includes an identifier mapped to the second RAT.
27. The apparatus according to claim 25, wherein the second TAU request includes an iteration of the first TAU request.
28. The aforementioned device At least one antenna coupled to the at least one processor The memory further comprises the at least one processor coupled to the memory, After outputting the first mapped security context, start the timer, and After the timer expires, the first mapped security context is deleted. The apparatus according to claim 25, further configured to perform the following:
29. The apparatus according to claim 25, wherein the at least one processor is configured to perform the first integrity check in the first TAU request based on the first security context.
30. The apparatus according to claim 25, wherein the first network entity includes a mobility management entity (MME), and the second network entity includes an access and mobility management function (AMF).