Key provided
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-01
- Publication Date
- 2026-08-14
Smart Images

Figure 2026527635000001_ABST
Abstract
Description
[Technical Field]
[0001] The following disclosure relates to communication technologies, particularly communication networks, and more specifically, wireless communication networks. This disclosure relates to the provision of keys in wireless communication networks, and in particular to the provision of keys used for communication between user equipment and secondary nodes. [Overview of the project]
[0002] In modern communication technologies, user equipment (UEs) need to access network nodes multiple times. For any subsequent access and / or communication session, encryption and integrity protection of transmitted and / or received messages are used to protect communications from third parties. Such encryption and integrity protection requires coordination between the network node and the UE, which enables the decryption of encrypted messages and the verification of the integrity of messages received from each other entity. In particular, both sides (UE and network node) need information about at least one pair of (encryption) keys to perform the decryption and integrity verification of messages received from each other entity. [Modes for carrying out the invention]
[0003] Modern wireless communication networks can be structured with master nodes (MNs) and secondary nodes (SNs). User equipment (UEs) can communicate with only the MN (so-called single connectivity) and can also communicate with at least one (e.g., serving) SN (so-called dual connectivity) (e.g., simultaneously). Dual connectivity may relate in particular to multi-RAT dual connectivity (MR-DC), e.g., EN-DC (E-UTRA-NR dual connectivity), NR-DC (New Radio Dual Connectivity), NGEN-DC (NG-RAN-E-UTRA dual connectivity), and NE-DC (NR-E-UTRA dual connectivity). The following disclosures relate in particular to, but are not limited to, the UE's access to the SN (especially during the UE's handover to the SN and / or the selective activation of the SN). When a UE's access to an SN is disclosed, a UE handover to an SN, in particular, the selective activation of the SN to which the UE handover occurs, is also disclosed.
[0004] Each node may provide at least one or more cells. For example, MN may provide at least one primary cell (PCell). For example, SN may provide at least one PSCell and / or at least one SCell. At least some or (e.g., all) cells involved in the following disclosure (e.g., in a given time instance) may be part of the same cell group (e.g., a master cell group (MSG) and / or a secondary cell group (SCG)).
[0005] A first solution for providing keys to UEs and network nodes (e.g., MNs or SNs) is that for a given communication session and / or the UE's next access to the network node, a key (e.g., a single key) and / or fragments of information from which the key can be derived may be provided to the network node and / or UE (e.g., as part of the configuration). The key may be specific to the network node (specific to the network node from the UE's perspective, and specific to the UE from the network node's perspective) and may remain constant for a predetermined period or until a predetermined event occurs. In this case, it is recognized that the key may be reused. This can happen, for example, when the connection between the UE and the network node is disconnected (e.g., disconnected from a cell provided by the network node) and then reconnected to the same network node (e.g., reconnected to the same or a different cell provided by the network node). Reusing keys is a security risk.
[0006] Another solution might be to provide a list of keys to be used to multiple SNs (e.g., some or all of the SNs in a given cell group). For any access by the UE, the SN selects the next key from the list. Using a list avoids the reuse of the same key. However, if all SNs obtain the same list of keys, a security breach at one SN could compromise the communication security of all SNs configured to use the same list of keys. Also, when using a list from which a key is drawn for each new access by the UE, the SN needs to know about any access by the UE to any SN using the same list in order to select the correct key. As a result, a security vulnerability remains, while signaling and bookkeeping overhead increases.
[0007] Therefore, one of the purposes of this disclosure is to enable particularly secure delivery of keys to (e.g., secondary) network nodes while keeping bookkeeping and signaling overhead low.
[0008] According to the first exemplary embodiment, - A step of obtaining at least one secondary node counter list (e.g., by RRC, e.g., in an RRCReconfig message) from the master node MN, wherein the secondary node counter list corresponds to (e.g., associated with) (e.g., each) a group of secondary nodes that are different from each other (e.g., each) (e.g., the UE intends to request access to and / or belong to the same cell group as the MN and / or belong to the same cell group as each other), -The steps include obtaining instructions for a secondary node (e.g., one of at least one secondary node to which the secondary node counter list corresponds) from the master node MN (e.g., via RRC, e.g., the same RRCReconfig message), - A step of generating a secondary node key based at least in part on at least one acquired secondary node counter list and (for example) the instructions of the secondary node (which may include, for example, a step of selecting unused counters from the list), A method is disclosed that includes the step of using the generated secondary node key to access the secondary node (e.g., by performing a random access procedure, such as by giving instructions to the secondary node).
[0009] This method may be executed and / or controlled, for example, by a device, such as a server. Alternatively, this method may be executed and / or controlled by a server cloud comprising multiple devices, such as at least two servers. Alternatively, the method may be executed and / or controlled, for example, by an electronic device, such as a node in a communication system, and / or by a user device (UE). For example, the method may be executed and / or controlled by using at least one processor of an electronic device.
[0010] In a further exemplary embodiment, a computer program is disclosed which, when executed by a processor, causes a device, such as a server, a network node, or an UE, to perform and / or control the operation of the method according to the first exemplary embodiment.
[0011] Computer programs can be stored on computer-readable storage media, particularly tangible and / or non-temporary media. Computer-readable storage media may include, for example, disks or memory. Computer programs can be stored on computer-readable storage media in the form of encoded instructions. Computer-readable storage media may be intended to be involved in the operation of a device, such as internal or external memory, for example, computer read (e.g., dedicated) memory (ROM) or hard disks, or optical discs intended for program distribution.
[0012] In further exemplary embodiments, an apparatus is disclosed comprising means configured to perform and / or control the method according to the first exemplary embodiment, or the respective means for performing and / or controlling it.
[0013] The means of the apparatus may be implemented in hardware and / or software. They may include, for example, at least one processor for executing computer program code to perform the required function, at least one memory for storing the program code, or both. Alternatively, they may include, for example, circuitry designed to implement the required function, such as a chipset or circuitry implemented on a chip, such as an integrated circuit. In general, the means may include, for example, one or more processing means or processors.
[0014] The apparatus disclosed above in any embodiment may be a module or component for a device, such as a chip. Alternatively, the apparatus disclosed in any embodiment may be a device, such as a server or a server cloud. The apparatus disclosed in any embodiment may comprise the disclosed components, such as means, a processor, and memory (only), or may further comprise one or more additional components.
[0015] User equipment (UE) can include mobile devices such as mobile phones, tablets, smartwatches, laptops, personal digital assistants (PDAs), wearables, Internet of Things (IoT) devices, Industrial IoT (IoT) devices, vehicles, and / or combinations thereof. Such user equipment is sometimes referred to as user devices.
[0016] Network nodes can correspond to components of a communication network, such as base stations (BTS), node B, evolved node B (eNB), next-generation node B (gNB), distributed units (DU), central units (CU), and / or combinations thereof. Network nodes are sometimes simply called nodes.
[0017] Therefore, this method may be performed and / or controlled by a device, the device in particular may be a UE. This method may be performed within an existing communication session. A communication session may be established between a device (e.g., a UE) and at least one network node (e.g., a master network node). The communication session may include secondary nodes in addition to the master node. This method may have the effect of adjusting an existing communication session, in particular by adding, removing, and / or modifying secondary nodes, to achieve and / or maintain, for example, dual connectivity (e.g., a communication session including a master node and secondary nodes). This method may relate to selectively activating a given SN for communication with the UE (e.g., in addition to an MN).
[0018] Here and hereinafter, a communication session between a UE and a network node (either a secondary node or a master node) includes a network node for providing a cell (e.g., a spatial coverage area where the UE can be located while receiving a radio signal from the network node and / or transmitting a radio signal to the network node and / or maintaining a communication session with the network node).
[0019] This method includes the step of obtaining at least one secondary node counter list (SN counter list). The secondary node counter list can be obtained from a master node (MN), e.g., the MN to which the UE is currently connected in the communication session. The obtaining can be performed by radio resource control (RRC), e.g., by an RRCReconfig message obtained by the device from the MN.
[0020] The obtaining can, here and hereinafter, for example, indicate that each piece of information (itself) (here, the secondary node counter list) is received via a radio communication link. The step of obtaining can, in particular, mean receiving as part of a radio resource control (RRC) message. The step of obtaining information can also mean that only an indication of each piece of information (e.g., an index, a reference, and / or a combination thereof) is received. The indication can enable the obtaining entity (here, the device, e.g., the UE) to derive the information (here, the secondary node counter list).
[0021] The SN counter list corresponds to different secondary nodes among a plurality of secondary nodes, respectively. When the SN counter list corresponds to each SN, for example, the SN counter list may be unique to that SN, associated with the SN, usable only by each SN (only), and / or specifically configured (e.g., by the MN) for the SN. The plurality of SNs may include at least one SN that the UE intends to access (e.g., based on a trigger signal from the MN or based on a (e.g., signal quality) measurement) (e.g., requests access and / or executes a random access procedure).
[0022] Furthermore or alternatively, the plurality of SNs may be, for example, part of the same cell group among each other and / or with the MN. If two or more network nodes (e.g., SNs and / or MNs) are part of the same cell group, this may mean, for example, that the network nodes each provide at least one cell that is part of the same cell group. The cell group may correspond to, for example, a master cell group (MCG) or a secondary cell group (SCG). For example, the plurality of secondary nodes may be part of the same or different SCGs. For example, the SN counter list (e.g., all SN counter lists) may be unique to one cell group (e.g., SCG) to which the SN belongs (e.g., to which the SN counter list is provided).
[0023] A given SN counter list may contain at least two SN counter values sorted in a predetermined order. For example, there may be a first SN counter value, a second SN counter value, and so on. The SN counter list may contain, for example, at least 3, 4, 5, 6, 7, 8, 9, 10, 15, 16, 20, 30, 32, 40, 50, 60, 64, 70, 80, 90, 100, 128 or more SN counter values. The number of SN counter values in the list may correspond to the number of accesses the device can perform on each SN before a new SN counter list is needed. A given SN counter value may take discrete values from a potential SN counter value. An SN counter value may take powers of 2. For example, the SN counter value can take values between 0 and a given maximum value, for example, 1, 3, 7, 15, 31, 63, 127, 255, 511, 1023, 2047, 4095, 2 13 , 2 14 , 2 15 , 2 16 , 2 24 , 2 32 It can be one of the following, or a higher power of 2. The maximum value may be given by the number of bits used to encode and / or provide and / or obtain each SN counter value (also called the SN counter length). The SN counter list may be represented as a list of SN counter values, but the SN counter list may also be represented or stored, for example, in addition or alternatively, as an array, graph, generating function, and / or a combination thereof.
[0024] The method further comprises the step of obtaining an indication of a secondary node among multiple secondary nodes. For example, the secondary node indicated by the indication of a secondary node may correspond to the secondary node in one of the obtained SN counter lists. For example, such an indication may comprise and / or correspond to a secondary node identifier, such as a secondary node group ID (SN group ID). The SN group ID may be an identifier associated with a given SN. The SN may be associated with a cell group, e.g., an SCG. The SN group ID may be assigned by a master node, e.g., a master node that provides the SN counter list and / or the indication of the SN. The indication of the SN may enable an apparatus performing the method according to the first exemplary embodiment to identify a particular SN and / or select an SN counter list corresponding to the SN indicated by the indication of the SN. If multiple SNs contain only a single SN (e.g., only one SN counter list is obtained), the indication of a secondary node may be implicit by the step of obtaining a message that does not contain an indication of an SN (e.g., an explicit indication of the SN, e.g., a secondary node group ID) (e.g., a message that may contain an indication of the SN in at least some cases).
[0025] The SN directive may be obtained from the main node (e.g., a main node from which at least one SN counter list has been previously acquired). The SN directive may be obtained separately (e.g., by separate signaling) from at least one secondary counter list. The SN directive may be obtained by the RRC, for example, in an RRCReconfig message. The RRCReconfig message may be identical or different from the RRCReconfig message from which at least one secondary node counter list is obtained. In other words, at least one SN counter list and the SN directive may be obtained in the same message or different messages, the message may be, for example, an RRC signaling from the MN to the UE (a device performing the method according to the first exemplary embodiment).
[0026] The method further includes the step of generating a secondary key. The generation step is at least in part based on one of the at least one SN counter lists obtained and an instruction for a secondary node. For example, the generation step may involve selecting an SN counter list corresponding to an SN indicated by an instruction for an SN. Thus, an SN counter list may be identifiable by an instruction for an SN and / or be associated with an instruction for an SN. The generation step may further include the step of selecting an SN counter value (e.g., an unused one) from the (e.g., selected) SN counter list. An unused SN counter value may be an SN counter value (e.g., from the SN counter list) that has not been previously used to access a secondary node. For example, the method may include the step of selecting the next SN counter value from the SN counter list. For example, the method may include the step of tracking the last selected SN counter value and selecting the next SN counter value. Based on a previously (e.g., last) selected SN counter value, the next SN counter value may be defined by a predetermined order in which SN counter values are stored and / or ordered in the SN counter list. In addition or alternatively, the used value may be discarded, and as a result, the method comprises the step of selecting a remaining first SN counter value (in accordance with the order of the SN counters in the list). If a previously selected SN counter value is not remembered and / or unknown, the method may include the step of selecting a first SN counter value from the SN counter list.
[0027] The step of generating a secondary node key may include providing input to a generation function (sometimes called a key generator) and obtaining an output from the generation function in response to the provided input. The generation step may be based on a selected SN counter value, and further on a further value such as the key associated with the master node (MN key). Alternatively, the generation step may be based at least in part on the SN counter length.
[0028] The step of generating SN keys based on an SN counter list allows for the generation of SN-specific SN keys for any new access to an SN. Note that SN keys corresponding to SN counter values in the SN counter list may be pre-generated and stored. In addition or alternatively, SN keys may be generated one at a time as needed for subsequent access to an SN (e.g., addition or modification). Since each SN counter list corresponds to an individual SN, an SN does not need to track a given UE's access to itself (e.g., to a single SN) and not to track the UE's access to multiple SNs. Because the method includes a step of using SN indications when generating SN keys, the UE is enabled to associate its SN access with a specific SN, for example, to count access to any given SN separately from access to other SNs. From the SN keys, keys for specific protection of RRC messages (e.g., Krrc enc, Krrc int) and / or keys for user-plane messages (Kupenc, Kupint) may be derived.
[0029] This method further includes a step of accessing the secondary node (e.g., the SN indicated by the instruction) as instructed by the secondary node using the generated secondary node key. The access step may include performing a random access procedure to the secondary node. In addition or alternatively, the access step may include the direct initiation of uplink (UL) and / or downlink (DL) traffic without a random access procedure, sometimes called a RACH-less handover (for example, in this case the UE may still use the generated SN key to secure the message).
[0030] The step of using an SN key to access an SN may include the step of using the SN key to encrypt or decrypt or integrity protect at least one message, which is sent to and / or received from the SN (for example, as part of a random access procedure).
[0031] According to an embodiment of the first exemplary aspect, - At least one secondary node counter list contains at least two secondary counter lists.
[0032] At least one SN counter list may include (for example, at least) 2, 3, 4, 5, 6, 7, 8, 9, 10, 16, 20, 30, 32, 40, 50, 64, 70, 80, 90, 100, 110, 120, 128 or more SN counter lists. When two or more SN counter lists are provided, the retrieved SN indication may include (for example, explicit) indications of the SN, such as an SN group ID.
[0033] The step of obtaining at least two SN counter lists allows for the use of SN-specific SN counter values. A first SN associated with a first SN counter list may not be able to decrypt a message sent to another second SN whose key is generated using another second SN counter list. This enhances security.
[0034] According to an embodiment of the first exemplary aspect, the method further, - The steps to count the number of accesses to each secondary node (e.g., by the device performing the method) and generate a secondary key are further based on the counted number of accesses (e.g., by the device) (e.g., by using the number as an index to a list).
[0035] The number of accesses to each secondary node can be counted. The counting step may be implemented, for example, by storing the last SN counter drawn from each SN counter list corresponding to the SN. The counting step may also include, or alternatively, incrementing the number by a (e.g., fixed) value for each given access to the SN. This number may be used, for example, as an index to the SN counter list. Counting can also be implemented by discarding (e.g., deleting, removing) entries in the SN counter list corresponding to each SN (e.g., the currently used SN counter value).
[0036] According to an embodiment of the first exemplary aspect, - The secondary node counter list contains (for example) a non-monotonical sequence of secondary node counter values, or - The secondary node counter lists (e.g., multiple lists) are distinct from each other (e.g., each contains a different sequence of secondary node counters).
[0037] A non-monotonically occurring sequence of SN counters can refer to a sequence of values that neither descends nor ascends completely. In other words, traversing SN counter values in a given order of SN counters results in at least one increase from a given SN counter value to the next (e.g., immediately following) SN counter value, and at least one decrease from a given SN counter value to the next (e.g., immediately following) SN counter value. An SN counter value in a given SN counter list can be unique within the list, for example, there may be no repetitions of counter values in the SN counter list. Alternatively, there may be at least one repetition of a given SN counter value in the SN counter list. In addition or alternatively, any two consecutive SN counter values in a given SN counter list can be different from each other, or at least one pair of consecutive SN counter values may be identical.
[0038] The SN counter lists of different SNs (e.g., multiple SNs) may be different from one another. At least one SN counter value may differ between SN counter lists (e.g., at a given (e.g., the same) position within each counter list). In particular, for a given index (e.g., any) in the SN counter list (e.g., a position within it), each SN counter value drawn from each SN counter list may be different for an SN counter list (e.g., an unmodified SN counter list as provided to the UE by the MN) (e.g., by taking the Nth SN counter from each SN counter list according to a predetermined order of SN counter values within each SN counter list). In addition or alternatively, at least two SN counter lists may differ in the number of their SN counter values and / or their respective maximum (e.g., possible) counter values (e.g., SN counter length). Since the SN counter lists differ between SNs (e.g., within the same cell group), a breach of one first SN does not enable the UE (performing the method) to decrypt communications between another SN different from the first SN.
[0039] According to a second exemplary embodiment, - A step of generating at least one secondary node counter list, wherein the secondary node counter list corresponds to different secondary nodes (for example, each) among a plurality of secondary nodes, - A step of providing a directive for at least one secondary node key to a secondary node among a plurality of secondary nodes (e.g., those belonging to the same cell group as MN and / or belonging to each other in the same cell group), wherein at least one secondary node key of the directive for at least one secondary node key corresponds to a secondary node counter value included in the generated secondary node counter list corresponding to the secondary node among the plurality of secondary nodes (e.g., simultaneously providing the following two items to the UE, or as at least one logical action), - The step of providing at least one of the generated secondary node counter lists to a user device (e.g., serviced by the device), A method is disclosed that includes the step of providing instructions for a secondary node among a plurality of secondary nodes to a user device (for example, by RRC, for example, in the same message having two generated SN counter lists).
[0040] This method may be executed and / or controlled, for example, by a device, such as a server. Alternatively, this method may be executed and / or controlled by a server cloud comprising multiple devices, such as at least two servers. Alternatively, the method may be executed and / or controlled by an electronic device, such as a network node in a communication system, and / or by a user device (UE). For example, the method may be executed and / or controlled by using at least one processor of an electronic device.
[0041] In a further exemplary embodiment, a computer program is disclosed which, when executed by a processor, causes a device, such as a server, a network node, or an UE, to perform and / or control the operation of the method according to a second exemplary embodiment.
[0042] Computer programs can be stored on computer-readable storage media, particularly tangible and / or non-temporary media. Computer-readable storage media may include, for example, disks or memory. Computer programs can be stored on computer-readable storage media in the form of encoded instructions. Computer-readable storage media may be intended to be involved in the operation of a device, such as internal or external memory, for example, computer read (e.g., dedicated) memory (ROM) or hard disks, or optical discs intended for program distribution.
[0043] In further exemplary embodiments, an apparatus is disclosed comprising means configured to perform and / or control the method according to the second exemplary embodiment, or the respective means for performing and / or controlling it.
[0044] The means of the apparatus may be implemented in hardware and / or software. They may include, for example, at least one processor for executing computer program code to perform the required function, at least one memory for storing the program code, or both. Alternatively, they may include, for example, circuitry designed to implement the required function, such as a chipset or circuitry implemented on a chip, such as an integrated circuit. In general, the means may include, for example, one or more processing means or processors.
[0045] The apparatus disclosed above in any embodiment may be a module or component for a device, such as a chip. Alternatively, the apparatus disclosed in any embodiment may be a device, such as a server or a server cloud. The apparatus disclosed in any embodiment may comprise the disclosed components, such as means, a processor, and memory (only), or may further comprise one or more additional components.
[0046] Therefore, the method may be performed and / or controlled by a device, which may be a network node in particular, and especially a master node. The method may be performed within an existing communication session. The communication session may be established between a device (e.g., a master node MN) and at least one UE (e.g., the UE performs the method according to the first exemplary embodiment). The communication session may include secondary nodes in addition to the master node. The method may have the effect of adjusting an existing communication session, in particular by adding, removing, and / or modifying secondary nodes, to achieve, for example, dual connectivity (e.g., a communication session including a master node and secondary nodes).
[0047] This method includes the step of generating at least one secondary node counter list. The secondary node counter list corresponds to each of several different secondary nodes. The generation step may include the step of selecting the SN counter length, the number of SN counters in the SN counter list, the SN counter values, and / or the order of the SN counter values. At least one of these embodiments, in particular the SN counter values, may be selected using (e.g., a pseudo) random process or (e.g., a deterministic) rule. Multiple SN counter lists for different SNs may be generated in a cooperative manner to ensure that they are different from one another.
[0048] The method further includes the step of providing an instruction for at least one secondary node key (SN key) to a secondary node among a plurality of secondary nodes. The at least one secondary node key provided by the instruction for at least one secondary node key corresponds to a secondary node counter value included in a generated secondary node counter list corresponding to the secondary node among the plurality of secondary nodes. If the SN counter value corresponds to an SN key, this may include the possibility of deriving the SN key at least in part on the SN counter value (for example, with respect to an apparatus performing the method according to the first exemplary embodiment). That is, the SN counter value included in the generated SN counter list corresponds to the SN key indicated by the provided SN key instruction. As disclosed with respect to the first exemplary embodiment, a key generator may be used, for example, to convert the SN counter value to an SN key. The method according to the second exemplary embodiment may obtain an SN key corresponding to an SN counter value included in an SN counter list corresponding to an SN for which an instruction for at least one SN key is provided, using a similar or essentially identical key generator (as used in the method according to the first exemplary embodiment).
[0049] The step of providing (information instructions) here and below may indicate, for example, that each piece of information (in itself) (here, at least one SN key) is transmitted, for example, by a wireless communication link. The step of providing may, in particular, mean a step of transmitting as part of a Radio Resource Control (RRC) message. The step of providing information instructions may also mean that only the instructions for each piece of information (e.g., index, reference and / or combination thereof) are received. The instructions may enable an retrieving entity (here, the device is, for example, a secondary network node) to derive the information (here, at least one SN key).
[0050] The method further includes the step of providing a user device (UE) with at least one of the generated secondary node counter lists. The UE may be configured to perform and / or control the method according to the first exemplary embodiment. The device performing the method according to the second device may act as a (serving) master node to the UE.
[0051] The method further includes the step of providing the user equipment with instructions for a secondary node among several secondary nodes. The instructions for a secondary node indicate the secondary node corresponding to one of the generated SN counter lists.
[0052] At least one of the steps of providing an instruction for at least one secondary node key, providing at least one of the generated secondary SN counter lists, or providing an instruction for a secondary node, may be performed as a single logical operation and / or simultaneously (e.g., essentially, within a period of less than 100 μs, 1 ms, 10 ms, or 100 ms), or alternatively, as at least two distinct logical operations and / or at different times.
[0053] According to an embodiment of a second exemplary aspect, - At least one secondary node counter list contains at least two secondary counter lists.
[0054] According to an embodiment of a second exemplary aspect, the method further: -The process includes a step of providing instructions for at least one secondary node key (e.g., by an SN change request, SN add request, SN release request / procedure, or via Class 2 signaling) (e.g., the providing step is performed) before receiving instructions for imminent access to a secondary node by a user device (e.g., by an RRCReconfigurationComplete message) using a secondary node key indicated by instructions for at least one secondary node key (e.g., from a user device).
[0055] An instruction for imminent access by a UE (e.g., a UE provided with at least one SN counter list and an instruction for an SN) to a secondary node (e.g., a secondary node provided with an instruction for at least one SN key) may be, for example, RRC signaling, and / or may correspond to an RRCReconfigurationComplete message obtained from the UE by an MN performing a method according to a second exemplary embodiment. The RRCReconfigurationComplete message may include further RRCReconfigurationComplete messages directed to an SN. The RRCReconfigurationComplete message may indicate that a condition (e.g., a CPAC PSCell condition) is met on the UE side in order to initiate access to each SN. An instruction for imminent access by a UE to a secondary node may be received from the UE.
[0056] In this embodiment, the SN key does not have to be used immediately (for example, in a signaling action immediately following the SN), but may be used for the UE's future and / or future access to the SN (for example, adding or modifying the SN).
[0057] The steps provided may, in this case, respond to and / or be performed as part of a secondary node change request, a secondary node addition request, or a secondary node release request (e.g., release of a communication session using a different SN key than the SN key indicated by the instruction of at least one SN key provided). The steps provided may (for example, in this case) be performed in addition or alternatively by Class 2 and / or Xn signaling.
[0058] According to an embodiment of a second exemplary aspect, - The instruction for at least one secondary node key corresponds to a secondary node key list (which may be generated by MN, for example) corresponding to a generated secondary node counter list corresponding to a secondary network node. -The method is further, - Secondary node change request, or - A secondary node addition request, including a step provided (e.g., by RRC) as part of at least one of them (e.g., the step provided is performed).
[0059] An instruction for at least one SN key may correspond to a secondary node key list. The SN key list may contain a list of SN keys in a predetermined order. The SN key list may correspond to a generated SN counter list. In particular, the SN keys in the SN key list may correspond (e.g., one by one) to the SN counter values in the generated SN counter list. For example, an SN key list can be obtained by iterating over an SN counter list (e.g., selecting SN counter values in a predetermined order), generating SN keys based on the selected SN counter values (e.g., any SN counter value) (and potentially other factors and / or variables such as SN keys and / or SN counter lengths), and storing them sequentially as a sequence in the order in which they are generated based on the SN counter values. The SN key list may have SN keys corresponding to (e.g., all) SN counter values contained in the SN counter list, or alternatively, to (only) a subset of the SN counter values contained in the SN counter list.
[0060] In this case, the provision may be made by RRC signaling. The provision may also be made as an addition or alternative to an SN change request and / or SN addition request.
[0061] Providing the SN key list to the SN has the advantage of extremely fast access because it eliminates the need to provide the SN with a separate key for new access to the UE.
[0062] According to an embodiment of a second exemplary aspect, - Instructions for at least one secondary node key correspond to a secondary node key (e.g., a single key) for user equipment to access a secondary network node. -The method is further, - A request to add a secondary node (for example, the SN to which the counter / key corresponds), or -Includes a step provided (e.g., by RRC) as part of at least one of the secondary node release requests (for example, of a session established in a random access procedure using different SN keys and / or different SNs).
[0063] The instruction for at least one secondary node key may correspond to the SN key itself (e.g., a single SN key). For example, the SN key may be sent to the SN by the MN. The SN key may enable and / or be used to allow the UE to access the SN.
[0064] This provision can be made here by RRC. In addition or alternatively, the providing step may be made as part of an SN addition request, e.g., a request for an SN counter list and / or SN key to add the corresponding SN. In addition or alternatively, the providing step may be made as part of an SN release request, e.g., a request for the release of a communication session established (e.g., with the same UE) using a different SN key (e.g., a previous and / or to be released).
[0065] In this case, the SN key may be provided for future access to the SN by the UE. Sharing a single key early on provides strong security. The SN may be called a candidate SN because, in this case, it is prepared (by providing the SN key) for the next access by the UE (e.g., a UE previously connected to the SN) while the access procedure (e.g., SN modification and / or addition by the MN) has not yet begun. In other words, in this embodiment, the SN key is provided to an SN that the MN has not yet begun preparing for access by the UE (and / or has not initiated the CPAC procedure), but which can instead initiate such access in the future.
[0066] According to an embodiment of a second exemplary aspect, the method further: - After receiving an instruction for imminent access to the secondary node by the user device using a secondary node key instructed by at least one secondary node key (for example, by an SN reconfiguration complete message), the step of providing instructions for at least one secondary node key (for example, the step of providing instructions is performed), or - The process includes the step of providing instructions for at least one secondary node key (for example, the providing step is performed) before receiving instructions for imminent access to the secondary node by user equipment using a secondary node key provided by instructions for at least one secondary node key, - The instruction for at least one secondary node key includes a secondary node key for user equipment to access a secondary network node, or -Includes at least one of the following: providing it as part of a secondary node reconfiguration completion message (for example, from MN to SN).
[0067] This embodiment covers the case where the SN key is provided for the upcoming (e.g., immediate) access to the SN by the UE. The SN key may be provided as part of an SN reconfiguration completion message (e.g., an RRC message). In this embodiment, it may already be certain that the UE will connect to the SN (e.g., immediately), and the SN is not referred to as a candidate SN. In other words, here the SN key is provided to the SN after the MN has already begun preparing for the UE's access to the SN (e.g., SN modification and / or SN addition) and / or initiated the CPAC procedure.
[0068] According to an embodiment of a second exemplary aspect, the method further: - A step of counting the number of accesses to each secondary node by each user device, wherein the instruction of at least one secondary key is at least partially based on the counted number of accesses.
[0069] An MN can track access to each SN by at least one or more UEs. This is especially true if the MN provides each (candidate) SN with an SN key (e.g., a single one). In order to select the correct entry from either the SN counter list and / or the SN key list, and / or generate the correct SN key, the MN needs to be informed of the SN counters that the UE selects from its own SN counter list. By counting the number of accesses, the MN can provide the SN with the correct SN key. In embodiments where the SN is provided with an SN key list, the SN can track the number of accesses, and the MN is relieved of the burden of monitoring accesses by the UE. Tracking the number of accesses can be done by discarding (e.g., used) SN counter values from the SN counter list and / or discarding (e.g., used) SN keys from the SN key list.
[0070] According to an embodiment of a second exemplary aspect, - Each secondary node counter list must contain a non-monotonic sequence of secondary node counters, or - This includes the fact that the secondary node counter lists are different from each other.
[0071] As a result, the SN key lists that may be provided to (for example, different) SNs may be different from each other.
[0072] The disclosures presented in relation to the first exemplary embodiment are also disclosed in relation to the second exemplary embodiment, where applicable.
[0073] According to a third exemplary embodiment, - A step of obtaining instructions for at least one secondary node key from a master node (in the same cell group as the device that performs and / or controls the method according to a third exemplary embodiment), wherein the at least one secondary node key corresponds to a counter included in a generated secondary node counter list (corresponding to the device that performs and / or controls the method according to a third exemplary embodiment), A method is disclosed that includes the step of using one of the at least one secondary node keys indicated by the instructions of the at least one secondary node key obtained to perform a random access procedure (e.g., initiated by the user device) with the user device (e.g., by accepting the random access procedure).
[0074] This method may be executed and / or controlled, for example, by a device, such as a server. Alternatively, this method may be executed and / or controlled by a server cloud comprising multiple devices, such as at least two servers. Alternatively, the method may be executed and / or controlled by an electronic device, such as a network node in a communication system, and / or by a user device (UE). For example, the method may be executed and / or controlled by using at least one processor of an electronic device.
[0075] In a further exemplary embodiment, a computer program is disclosed which, when executed by a processor, causes a device, such as a server, a network node, or an UE, to perform and / or control the operation of the method according to a third exemplary embodiment.
[0076] Computer programs can be stored on computer-readable storage media, particularly tangible and / or non-temporary media. Computer-readable storage media may include, for example, disks or memory. Computer programs can be stored on computer-readable storage media in the form of encoded instructions. Computer-readable storage media may be intended to be involved in the operation of a device, such as internal or external memory, for example, computer read (e.g., dedicated) memory (ROM) or hard disks, or optical discs intended for program distribution.
[0077] In further exemplary embodiments, an apparatus is disclosed comprising means configured to perform and / or control the method according to the third exemplary embodiment, or the respective means for performing and / or controlling it.
[0078] The means of the apparatus may be implemented in hardware and / or software. They may include, for example, at least one processor for executing computer program code to perform the required function, at least one memory for storing the program code, or both. Alternatively, they may include, for example, circuitry designed to implement the required function, such as a chipset or circuitry implemented on a chip, such as an integrated circuit. In general, the means may include, for example, one or more processing means or processors.
[0079] The apparatus disclosed above in any embodiment may be a module or component for a device, such as a chip. Alternatively, the apparatus disclosed in any embodiment may be a device, such as a server or a server cloud. The apparatus disclosed in any embodiment may comprise the disclosed components, such as means, a processor, and memory (only), or may further comprise one or more additional components.
[0080] Therefore, the method may be performed and / or controlled by a device, which may be a network node in particular, and especially a secondary node. The method may be performed at least partially within an existing communication session. A communication session may be established between a device (e.g., a secondary node SN) and at least one UE (e.g., a UE performing the method according to the first exemplary embodiment). The method may have the effect of coordinating an existing communication session, in particular adding and / or releasing a secondary node, to achieve, for example, dual connectivity (e.g., a communication session including a master node and a secondary node).
[0081] An instruction for at least one SN key may be obtained from the master node, which belongs to the same cell group as the device (e.g., a secondary node) performing the method according to a third exemplary embodiment.
[0082] At least one secondary node key corresponds to a counter included in the generated SN counter list corresponding to the apparatus performing the method according to the third exemplary embodiment. Thus, at least one SN key corresponds to an SN counter list specific to the apparatus performing the method. At least one SN key may, in particular, be different from (e.g., any) SN key received by another SN (e.g., within the same cell group).
[0083] An instruction for at least one SN key may be associated with and / or correspond to a UE. The method may comprise associating the instruction for at least one SN key and / or at least one SN key of the instruction with each UE, for example, with a conditional PSCell Addition and Change (CPAC) context which may be specific to the UE. The method may comprise storing multiple instructions for at least one SN key and / or multiple at least one SN keys of instructions, each for a different UE.
[0084] This method includes performing access by user equipment. For example, this may include accepting (random) access requests from the UE. Access may be initiated by the UE. The device (and / or UE) may be configured to perform access processing using one of at least one secondary node keys indicated by an acquired instruction for at least one secondary node key. Thus, by receiving an instruction for at least one secondary node key, the method enables a device performing the method according to a third exemplary embodiment to perform access with a UE performing the method according to a first exemplary embodiment, and / or to cooperate with a master node performing the method according to a second exemplary embodiment. This enables particularly secure but fast access by the UE to a device performing the method according to a third exemplary embodiment (e.g., a secondary node).
[0085] According to an embodiment of a third exemplary aspect, the method further, - A step to obtain instructions for at least one secondary node key as part of a secondary node change request (e.g., the device is currently serving the UE) or a secondary node addition request (e.g., from the MN to the device), - A step of obtaining an instruction for at least one secondary node key as part of a secondary node change request or a secondary node addition request (for example, the step of obtaining is performed), wherein the instruction for at least one secondary node key corresponds to a secondary node key list (for example, which may be generated by MN) corresponding to a generated secondary node counter list corresponding to a device.
[0086] A secondary node change request may be received in a communication session in which a device performing the method according to the third exemplary embodiment is currently servicing the UE. A secondary node addition request may be received by a device performing the method according to the third exemplary embodiment while disconnected from the UE, for example, while not servicing the UE. SN change requests and / or SN addition requests may be received from the master node.
[0087] An instruction for at least one secondary node key may correspond to a secondary node key list. The secondary node key list may be generated by the master node and correspond to a generated secondary node counter list corresponding to an apparatus (e.g., a secondary node) performing the method according to a third exemplary embodiment.
[0088] According to an embodiment of a third exemplary aspect, - After a request to add a secondary node, or as part of a message indicating that the secondary node has been reconfigured (for example, from the MN to the device), the step of obtaining instructions for at least one secondary node key (for example, the step of obtaining the key is performed), - Disclosed is a method that includes the step of obtaining an instruction for at least one secondary node key as part of a secondary node reconfiguration completion message (e.g., the step of obtaining is performed), wherein the instruction for at least one secondary node key corresponds to a secondary node key (e.g., a single key) for access to the device by a user device (e.g., immediately following).
[0089] In this embodiment, the (e.g., single) SN key may be acquired (e.g., immediately) before it is required by the apparatus performing the method according to the third exemplary embodiment. For example, the MN may have already begun preparing for the UE's access to the SN before the instruction for the (e.g., single) SN key is acquired by the SN. For example, the SN key may be acquired after the CPAC procedure (e.g., to the SN) has been initiated (e.g., by the MN).
[0090] According to an embodiment of a third exemplary aspect, - A step of obtaining instructions for at least one secondary node key as part of a request to add a secondary node (for example, to a device) or a request to release a secondary node (for example, at the end of a communication session initiated with another SN key from the MN) (for example, the step of obtaining is performed), - Disclosed is a method that includes the step of obtaining an instruction for at least one secondary node key as part of a request to add a secondary node or a request to release a secondary node (e.g., the step of obtaining is performed), wherein the instruction for at least one secondary node key corresponds to a secondary node key (e.g., a single key) for (e.g., future potential) access to the device by a user device.
[0091] In this embodiment, the (e.g., single) SN key may be acquired (e.g., well in advance) before it is required by the apparatus performing the method according to the third exemplary embodiment. For example, the MN may not have yet begun preparing for the UE's access to the SN before the instruction for the (e.g., single) SN key is acquired by the SN. The SN key may be acquired by the SN before the CPAC procedure (e.g., to the SN) (by the MN) can be initiated. Alternatively, such preparation may be performed later. In this embodiment, the apparatus performing the method according to the third exemplary embodiment may be referred to as the candidate SN.
[0092] At least one SN key instruction may be obtained as part of a secondary node addition request. At this stage, it is not yet known exactly when the UE will attempt to access the device performing the method according to the third exemplary embodiment. Additionally or alternatively, at least one SN key instruction may be obtained as part of an SN release request. An SN release request may be obtained at the end of a communication session with the UE, using an SN key different from the one indicated by the SN key instruction obtained as part of the SN release request. By providing the UE with a communication session in advance, the network (e.g., MN) can consider the device performing the method according to the third exemplary embodiment as a candidate SN for future access by the UE.
[0093] According to an embodiment of a third exemplary aspect, the method further, - A step of counting the number of accesses by each user device (for example, to the device that executes and / or controls this method), - Includes the step of selecting a secondary node key (for example, one used for access by the UE) from a list of secondary node keys based on the counted number of accesses.
[0094] If the instruction for at least one SN key includes an SN key list, a device performing the method according to a third exemplary embodiment may need to track access by each UE in order to select the correct SN key from the SN key list.
[0095] According to an embodiment of a third exemplary aspect, - The secondary node counter list contains a non-monotonical sequence of secondary node counters, or - The secondary node counter lists are different from each other.
[0096] As a result, the SN key list may be specific to the apparatus performing the method according to the third exemplary embodiment.
[0097] Any disclosure presented in relation to a first or second exemplary embodiment will also be disclosed in relation to a third exemplary embodiment, where applicable.
[0098] A fourth exemplary embodiment is disclosed, comprising at least one UE performing and / or controlling the method according to the first exemplary embodiment, at least one MN performing and / or controlling the method according to the second exemplary embodiment, and at least one secondary node performing and / or controlling the method according to the first exemplary embodiment.
[0099] For example, the system comprises a user device UE, a master node MN, and a secondary node SN. -UE is -A step of obtaining at least one secondary node counter list (e.g., in an RRCReconfig message, etc., by RRC, from the main node MN), wherein the secondary node counter list corresponds to (e.g., associated with) different secondary nodes among a plurality of secondary nodes, each containing a secondary node (e.g., UE intends to request access and / or belongs to the same cell group as MN and / or belongs to the same cell group as each other), -The steps include obtaining instructions (e.g., via RRC, the same RRCReconfig message, etc.) for a secondary node among several secondary nodes (e.g., one of the at least one secondary node to which the secondary node counter list corresponds) (for example, from the main node MN), - A step of generating a secondary node key based at least partially on one of the acquired secondary node counter lists and the secondary node instructions (for example, this may include a step of selecting unused counters from the list), -The system is configured to perform the steps of accessing the secondary node according to the instructions of the secondary node (e.g., the steps of performing a random access procedure) using the generated secondary node key, -MN is, - A step of generating at least one secondary node counter list, wherein the secondary node counter list corresponds to different secondary nodes among a plurality of secondary nodes, each containing the secondary node; - A step of providing a directive for at least one secondary node key to a secondary node among multiple secondary nodes (e.g., belonging to the same cell group as the MN and / or belonging to the same cell group as each other), wherein at least one secondary node key of the directive for at least one secondary node key corresponds to a secondary node counter value included in the generated secondary node counter list corresponding to the secondary node among multiple secondary nodes (e.g., by the UE) (while providing the following two items to the UE, or as at least one logical action), - The step of providing at least one of the generated secondary node counter lists to a user device (e.g., serviced by the MN), -The system is configured to perform the steps of providing instructions to the user equipment for a secondary node among several secondary nodes (for example, in the same message with two generated SN counter lists by RRC), -SN is, -A step of obtaining instructions for at least one secondary node key from a master node (for example, in the same cell group as SN), wherein at least one secondary node key corresponds to a counter included in the generated secondary node counter list corresponding to SN, -The system is configured to perform the steps of: - Using at least one secondary node key of the acquired instructions for at least one secondary node key, perform access to the user equipment (e.g., initiated by the user equipment) (e.g., a random access procedure with the user equipment) (e.g., by accepting a random access procedure).
[0100] Any disclosure presented in relation to the first, second, or third exemplary embodiments shall also be disclosed in relation to the fourth exemplary embodiment, where applicable. [Brief explanation of the drawing]
[0101] The following is shown in the diagram: [Figure 1a] This figure shows two exemplary embodiments of a user device that switches secondary cells, in all exemplary aspects. [Figure 1b] This figure shows two exemplary embodiments of a user device that switches secondary cells, in all exemplary aspects. [Figure 2] This figure shows exemplary embodiments of key generation according to all exemplary aspects. [Figure 3] This figure shows exemplary embodiments of key generation according to all exemplary aspects. [Figure 4a] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 4b] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 4c] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 4d] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 5a] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 5b] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 5c] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 6a] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 6b] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 6c]These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 6d] These are signaling diagrams of exemplary embodiments according to all exemplary aspects. [Figure 7] This is a flowchart of the method according to an embodiment of the first exemplary aspect. [Figure 8] This is a flowchart of the method according to a second exemplary embodiment. [Figure 9] This is a flowchart of the method according to a third exemplary embodiment. [Figure 10] This is a block diagram showing an embodiment according to a first exemplary aspect. [Figure 11] This is a block diagram showing an embodiment according to a second exemplary aspect. [Figure 12] This is a block diagram showing an embodiment according to a third exemplary aspect. [Figure 13] This is an example of a storage medium.
[0102] Figure 1a illustrates a dual connectivity scenario in which UE100 moves away from cell PSCell 1a provided by network node 200 (SN1) to another cell PSCell 2a provided by network node 200a (SN2). A PSCell is a primary cell within a secondary cell group (SCG). It can be combined with secondary cells (SCells) within the SCG, which are associated with carrier aggregation (CA). Initial access to the PSCell may be performed.
[0103] In the next step, UE100 moves away from cell PSCell 2a again and returns to cell PSCell 1a. In such a scenario, according to prior art, UE100 may not receive any configuration for cell PSCell 1a during the process. That is, UE100 may use the same configuration previously obtained to access cell PSCell 1a, which includes the respective keys used to access cell PSCell 1a (i.e., node 200 (SN1) providing cell PSCell 1a). UE100 may add cell PSCell 1a during the selective activation phase. In addition to cell PSCell 1a and / or cell PSCell 2a, UE100 may be connected to a master node (not shown) to achieve dual connectivity with a master node and secondary nodes (network nodes 200 (SN1), 200a (SN2)).
[0104] Figure 1b presents a similar scenario in which UE100 first moves from cell PSCell 1a, provided by the first network node 200 (SN1), to another cell PSCell 2a, provided by the second network node 200a (SN2). The UE then moves back to the cell provided by network node 200 (SN1), the only difference being that it is now connected to network node 200 (SN1) in a different cell PSCell 1b, also provided by network node 200 (SN1). Here again, according to prior art, UE100 may perform selective activation, reusing a configuration previously acquired for network node 200 (SN1). In this case, the key to access network node 200 (SN1) can also be reused.
[0105] Both scenarios shown in Figures 1a and 1b present a security problem in conventional technology because the same key (SN key) is used to access secondary nodes 200 and 200a. gNBas shown) can be derived from the sk counter in the conditional reconfiguration to be executed. The same S-K is used until a new configuration is obtained. gNB is used. The proposed solution provides the UE100 with a plurality of SN counter values (as an SN counter list) for at least one or more secondary nodes (200, 200a). As shown in FIGS. 1a and 1b, when accessing the secondary node (200, 200a) for the second (or third, fourth, or more) time, an unused SN counter value is used to access the secondary network node (here, network node 200 (SN1), but the same applies to 200a (SN2)). The UE can change the SN counter value at any time of SN change.
[0106] To illustrate SN key generation, FIG. 2 shows a key generator 110 that may exist within, for example, a UE (executing a method according to a first exemplary aspect) or a master node (executing a method according to a second exemplary aspect), and may exist as a functional unit, such as a functional block within computer code stored in a memory that executes the functions described herein when executed by a processor. The key generator 110 can receive a key K specific to a network node, particularly a master node. gNB can also receive an SN counter value. The SN counter value can be derived, for example, from a previously obtained SN counter list (in the case of a UE) from a master node (e.g., in conjunction with the master node key K). Optionally, the key generator 110 can obtain an SN counter length that may indicate, for example, the range of possible values that the SN counter value can take. Based on at least the MN key K gNB and the SN counter value and optionally the SN counter length, the key generator outputs a secondary node key K gNB SN . The key generator 110 can execute a mathematically defined operation to generate a key suitable for the end-to-end encryption method used between the UE and the SN for this purpose. SN
[0107] In other words, when a UE is setting up dual connectivity, the UE secures the connection with the serving SN and uses the SN key K to encrypt it. SN This requires. In the current MR-DC scenario, the SN key is provided by the MN (e.g., as part of the SN counter list), the length of the SN counter (optionally), and the MN key K, as shown in Figure 2. gNB The Serving SN is generated by the UE using the SN. The Serving SN should also know the SN key that the UE will use to have end-to-end encryption. The MN can determine the SN counter value for the UE, so the MN may already know the key generated by the UE using the counter, and then the MN can compute the SN key using the appropriate counter value (e.g., by using a key generator 110 similar to and / or identical to the one shown in Figure 2) and inform the SN of the SN key to be used before it becomes the Serving SN (in either SN addition or SN modification). For example, in SN addition or SN modification, the MN may share the candidate SN and KSN during preparation. Such provision may be made, for example, by the RRC as part of an S-NODE ADDITION REQUEST message or other messages as detailed below.
[0108] Figure 3 illustrates one of the concepts of this disclosure. On the left is a table showing multiple SN counter lists (i.e., at least secondary node counter lists in the language of the claims). Each column can be considered a single SN counter list specific to a secondary node SN1, SN2, or SN3. Given an SN counter value (e.g., counter 1.1), each SN key (e.g., K SN 1.1) can be associated. The SN key can be derived (and / or derivable) from the associated SN counter value using the key generator shown in Figure 2. In addition, the MN key K gNBand / or the SN counter length may be used. At least one SN counter list (one of the columns shown in Figure 3) may be generated by the MN, provided to the UE (e.g., by the MN), and / or retrieved by the UE.
[0109] In this and any other embodiment, the UE may obtain the SN counter length and / or master node key from, for example, the master node. The master node may provide the SN counter length and / or master node key to the UE.
[0110] The secondary node needs to know the SN key that the UE will use for subsequent access to the SN (e.g., subsequent CPAC). The SN key may be provided to the secondary node, for example, as an instruction for at least one SN key. For example, at least one entry or left column of SN keys (e.g., the whole) (a so-called SN key list) may be provided to the secondary node SN1. The SN can then decrypt messages sent by the UE based on one of the SN keys in the SN key list.
[0111] Figure 4 shows an exemplary embodiment as a signaling diagram. It shows signals exchanged between a UE (e.g., including performing the method according to the first exemplary embodiment), a master node (MN) (e.g., performing the method according to the second exemplary embodiment), a first secondary node (SN1), and a second secondary node (SN2) (e.g., SN1 and / or SN2 each performing the method according to the third exemplary embodiment). In the illustrated embodiment, an SN key list (instead of a single SN key) is shared with the secondary nodes SN1 and SN2.
[0112] Signaling 401:UE is connected to the master node MN and the first secondary node SN1 PSCell1. In this step, UE sends the SN key K for SN1 on the PSCell-1 link. SN I am using version 1.0.
[0113] Signaling 402: The MN generates a list of SN counters (SN counter list) for SN1 (i.e., the SN counter list may be specific to the first secondary node SN1). In this embodiment, the MN also generates an SN1 key corresponding to the generated list of SN1 counters. The generation of such a key may be conditional on SN1, i.e., on SN1 being considered for selective activation, i.e., to "return" the UE to SN1 at a later stage (see Figures 1a and 1b).
[0114] Signaling 403:MN transmits SN1 and SN1's K via an SN change procedure (e.g., as part of an SN change request). SN Share a list (SN key list) (for example, for selective activation).
[0115] Signaling 404: When SN1 receives an SN1 key, it does not need to update the key for any ongoing transmissions (communication sessions) between SN1 and the UE. Such updates may occur in legacy behavior. Here, updating the key for the current communication session may be omitted because the acquired / provided SN key is intended to be used by SN1 for UE return, for example, as part of selective activation, i.e., when the UE hands over to another SN and then hands over back to SN1. SN1 maintains a list of SN keys along with the UE context (e.g., associating the SN key list with the UE).
[0116] Signaling 405:SN1 acknowledges the SN change request.
[0117] Signaling 406: MN generates a list of SN counters for SN2. MN also generates an SN2 key corresponding to the list of SN2 counters.
[0118] Signaling 407: MN shares the list of SN2 keys (SN key list) with SN2 via the SN addition procedure.
[0119] Signaling 408:SN2 holds all SN2 keys shared by the MN and uses them one by one when the UE hands over to SN2 in a subsequent manner, for example, in the order of the SN2 key list.
[0120] Signaling 409:SN2 affirms the SN addition request.
[0121] Signaling 410: MN constitutes the UE with respect to the SCPAC preparation of SN1 and SN2. MN provides the UE with a list of SN1 and SN2 counters generated in the previous step. These counter values are provided as a list of SN counters (SN counter list) along with the SN-Key-Group-ID (indicating the SN).
[0122] Here, and in any other embodiment, the MN may assign a unique SN key group ID to each SN (e.g., one involved in selective activation).
[0123] The MN includes an "SN-Key-Group-ID" (as an indication for the SN) in each candidate configuration. If the UE switches from the current serving cell (e.g., SN1) to a new (serving) cell (e.g., SN2) as part of selective activation, and / or if there is a change in the SN-Group-ID, the UE will specify the SK that should be used in the target cell. eNB and / or SK gNB To generate a new SN, for example, to access a target SN (e.g., SN2), apply an "unused" SN counter value from the retrieved SN counter list that corresponds to a new SN-Key-Group-ID (indicating / identifying the SN to be handed over).
[0124] Signaling 411:UE sends RRCReconfigurationComplete when it completes the RRCReconfiguration received from MN.
[0125] Signaling 412: The UE can evaluate that PScell-2 satisfies the CPAC condition. The UE can then compare the SN group ID (e.g., one from a given SN counter list) with the CPAC ID and decide to use a new SN key after the CPAC is performed on PSCell-2, since PSCell-2 is under a different SN (SN2) than the previous serving SN (SN1). The UE can retrieve the SN counters and / or related SN counter list for the associated SN group corresponding to the correct SN and generate an SN key accordingly.
[0126] Signaling 413-414:UE sends RRCReconfigurationComplete to the MN, which contains the SN's RRCReconfigurationComplete. The MN forwards the SN's RRC reconfiguration completion to the target SN, i.e., SN2.
[0127] Signaling 415: The UE initiates a Random Access Procedure (RACH) toward SN2, and the UE will use the next SN key K-SN1.1, which is generated by using the next SN1 counter.
[0128] Signaling 416: SN2 will identify that the UE is accessing this SN2 for the first time, and therefore SN2 will retrieve the next K-SN, K-SN2.1, from the list of SN2 keys provided by MN. SN2 will discard this key in a future CPAC procedure because the same key will not be used twice.
[0129] Signaling 417: A change from SN1 to SN2 is followed by a change from SN2 to SN1, i.e., the PSCell-1 condition is met. The UE identifies that it needs to decrement the next SN1 counter and generate a new SN1 key for this access (the same procedure as described in Signaling 412). The UE discards this counter for future use and retains other SN1 counters.
[0130] Signaling 418-420: Same as signaling 413-415.
[0131] Signaling 421: Similar to signaling 416, SN1 identifies that the UE is accessing SN1 from another SN, and therefore SN1 receives the next K from the list of SN1 keys provided by the MN. SN This will lead to the extraction of K-SN1.1. Since SN1 is not used twice, this key will either be discarded or marked as to be used for future CPAC procedures.
[0132] Signaling 422-426: The same procedure as described in Signaling 412-416. It is included here to show how SN2 and UE use different keys in those steps (different from Signaling 12-16).
[0133] Figure 5 shows a signaling diagram of a solution in another embodiment in which the SN key is provided on demand, i.e., immediately before it is needed. The entities involved and their relationships to the embodiments are the same as those described with respect to Figure 4. Several signalings different from those in Figure 4 are described below, although some may be identical.
[0134] In signaling 6, the MN does not share candidate SNs and the next SN key until necessary. The MN also does not provide a (complete) list of SN keys.
[0135] When the UE performs an inter-SN (i.e., secondary node change) CPC (conditional PSCell change) (signaling 10, 11), the MN retrieves the SN2 key (generated in signaling 5), and the UE uses the SN2 key. The MN shares the SN2 key with SN2. The key is provided, for example, as part of the SN reconfiguration completion message.
[0136] This process is repeated in subsequent SN changes, with the MN sharing the SN key with the new SN to which the UE is handing over. For example, when the UE performs another inter-SN CPC (signaling 15, 16), the MN retrieves the SN1 key (generated in signaling 2) that the UE will use and shares it with SN1.
[0137] Figure 6 shows a signaling diagram of a solution in another embodiment. The entities involved and their relationships to the embodiments are the same as those described with respect to Figures 4 and 5. Several signalings different from those in Figures 4 and 5 are described below, although some may be identical.
[0138] In signaling 2 and 5, the MN generates SN1 and SN2 keys along with the SN1 and SN2 counters. The MN retrieves the first SN2 key from the list of SN2 keys shared with SN2. The MN shares this retrieved key with SN2. Therefore, SN2 will know the next key (and only the next one) that the UE will use.
[0139] When a UE hands over from SN1 to SN2 and then back to SN1, it becomes a candidate for CPAC (the UE can then hand over back to SN1). Therefore, in signaling 15, the MN notifies SN1 of the next SN1 key to be used when the UE hands over back to SN1. SN1 is a candidate SN in this case. Whether the UE actually hands over back to SN1 is uncertain.
[0140] The MN can notify SN1 of the next SN1 key via the SN release procedure (at the end of the previous communication session between the UE and SN1), or via Class 2 signaling, which is, for example, one-way signaling without an acknowledgment message.
[0141] Alternatively, the following SN1 key should be used for the first CPAC KS eNB and / or KS gNBIn addition, it may be provided from MN to SN1 in SN-Addition-Request. MN may provide only the following key for subsequent returns. This next key may be for future use by UE in access procedures to SN1 at an unknown time. This next key is provided again with the following value from the list when SGNB-Reconfiguration-complete is sent for the first cell change.
[0142] Figure 7 is a flowchart illustrating the method according to a first exemplary embodiment. This method can be performed, for example, by a UE in an existing communication session with a master node. In the first action M100, at least one secondary node counter list is obtained from an MN performing, for example, the method according to a second exemplary embodiment. For example, multiple NS counter lists may be obtained, and the SN counter list is associated with each individual SN. The method further includes the step of obtaining an SN instruction in operation M102. For example, the step of obtaining such an SN instruction may enable the UE to identify the SN counter list to be used to generate an SN key for accessing the SN indicated by the SN instruction. In operation M104, a secondary node key is generated. For example, the generation step may include the step of selecting an SN counter list based on the obtained instruction, and further the step of selecting an SN counter value from the selected SN counter list. The SN counter value can be input to a key generator, for example, implemented as code in the memory of the device performing the method (e.g., along with the SN counter length and / or MN key). In operation M106, the method further includes the step of using the generated key to access the secondary node indicated by the instructions of the secondary node. The secondary node may perform the method according to a third exemplary embodiment. The SN to be accessed is also provided with the correct SN key, for example, by one of the procedures outlined in Figures 4 to 6.
[0143] Figure 8 is a flowchart illustrating the method according to a second exemplary embodiment. This method may be performed by a master node. In operation M200, the method includes the step of generating at least one secondary node counter list. The SN counter list may be generated for a particular SN (e.g., performing the method according to a third exemplary embodiment) and may differ from an SN counter list generated for another SN (e.g., in the same cell group). In action M202, an instruction for at least one SN key is provided to the SN. The SN key may correspond to an SN counter value contained in the generated SN counter list. In operation M204, at least one of the generated secondary node counter lists is provided to a UE (e.g., performing the method according to a first exemplary embodiment), for example in RRC signaling. This allows the UE to access the SN to which any of the SN counter lists corresponds. In operation M206, an instruction for a secondary node (e.g., a secondary node) is provided to the user device, i.e., the UE, to which at least one generated SN counter list was provided in operation M204.
[0144] Figure 9 shows a flowchart of a third exemplary embodiment of the method, which may be performed, for example, by a secondary node. In action M300, instruction for at least one SN key may be obtained, for example, from an MN (e.g., performing the second exemplary embodiment of the method). Instruction for at least one SN key may include, for example, one (e.g., a single) SN key or multiple SN keys, e.g., an SN key list. The method further includes, in operation M302, performing access by a user device (e.g., performing the first exemplary embodiment of the method). In other words, an SN performing the described method may, for example, as part of a random access procedure, accept and / or respond to an access request from a UE. The UE and / or SN may, in action M300, use one of the SN keys provided to the SN by the MN for access and / or subsequent communication.
[0145] Figure 10 shows an exemplary block diagram of UE100. The UE may perform the method according to the first exemplary embodiment. The UE comprises a user interface A160, program memory A110, main memory A120, and data memory A140. It further includes a processor A130. The device 100 may further comprise functional units A131 to A134, each corresponding to the operations shown in the flowchart of Figure 7. The SN counter list acquisition unit A131 may acquire at least one SN counter list from, for example, an MN (for example, performing the method according to the second exemplary embodiment). Functional units A131 to A134 may be connected to and / or controlled by a communication interface A150 to acquire their respective information and / or perform access to the SN (accessor A134).
[0146] Figure 11 shows an exemplary block diagram of a master network node (MN). The MN can perform a method according to a second exemplary embodiment. The MN may include a user interface A260, program memory A210, main memory A220, and data memory A240. It may also include a processor A230. The network node 200 may further include functional units A231 to A234, each corresponding to an action shown in the flowchart of Figure 8. Functional units A232 to A234 can operate together, for example, with a communication interface A250.
[0147] Figure 12 shows an exemplary block diagram of a secondary network node (SN). The SN may perform a method according to a third exemplary embodiment. The SN may comprise a user interface A360, program memory A310, main memory A320, and data memory A340. It may also include a processor A330. The network node 200 may further comprise functional units A331 and A332, which correspond to the actions shown in the flowchart of Figure 9, respectively. Functional units A331 and A332 can operate together, for example, with a communication interface A350.
[0148] Figure 13 is a schematic diagram of an example of a tangible, non-temporary, computer-readable storage medium according to the present invention, which may be used to implement, for example, the programs and / or main memories A110, A120, A140, A210, A220, A240, A310, A320, A340 of the UE100, SN200, or MN in Figures 7 to 9. Figure 13 shows, for example, a flash memory 1300 which may be soldered or bonded to a printed circuit board, a solid-state drive 1301 having a plurality of memory chips (e.g., flash memory chips), a magnetic hard drive 1302, a secure digital (SD) card 1303, a universal serial bus (USB) memory stick 1304, an optical storage medium 1305 (e.g., a CD-ROM or DVD, etc.), and a magnetic storage medium 1306.
[0149] Some embodiments include the following:
[0150] (Embodiment 1) For example, a method according to the first exemplary embodiment, A step of obtaining at least one secondary node counter list, which corresponds to different secondary nodes among multiple secondary nodes, Steps include obtaining instructions for one of several secondary nodes, A step of generating a secondary node key based at least partially on at least one acquired secondary node counter list and secondary node instructions, A method including the steps of accessing a secondary node using the generated secondary node key.
[0151] (Embodiment 2) The method of Embodiment 1, wherein at least one secondary node counter list includes at least two secondary counter lists.
[0152] (Embodiment 3) The method of Embodiment 1 or 2 includes the steps of counting the number of accesses to each secondary node (for example, by a device that performs and / or controls the Method), generating a secondary key, and further, a step based on the counted number of accesses.
[0153] (Embodiment 4) The secondary node counter list contains a non-monotonic sequence of secondary node counter values, or One of the methods of Embodiments 1 to 3, wherein at least one of the secondary node counter lists is different from one another.
[0154] (Embodiment 5) For example, a method according to a second exemplary embodiment, A step of generating at least one secondary node counter list, wherein the secondary node counter list corresponds to different secondary nodes among a group of secondary nodes, A step of providing instructions for at least one secondary node key to one of a plurality of secondary nodes, wherein at least one secondary node key of the instructions for at least one secondary node key corresponds to a secondary node counter value included in the generated secondary node counter list corresponding to the secondary node among the plurality of secondary nodes; The steps include providing at least one of the generated secondary node counter lists to the user's equipment, A method comprising the steps of providing instructions to a user device for one of several secondary nodes.
[0155] (Embodiment 6) The method of Embodiment 5, wherein at least one secondary node counter list includes at least two secondary counter lists.
[0156] (Embodiment 7) The method of Embodiment 5 or 6 further includes at least one of the steps of providing instructions for at least one secondary node key before receiving instructions for imminent access to a secondary node by a user device using a secondary node key indicated by instructions for at least one secondary node key.
[0157] (Embodiment 8) The instruction for at least one secondary node key corresponds to the secondary node key list corresponding to the generated secondary node counter list corresponding to the secondary network node, The method is further, Secondary node change request, or A method of any of Embodiments 5 to 7, which includes providing a secondary node addition request as part of at least one of the following.
[0158] (Embodiment 9) The instruction for at least one secondary node key corresponds to the secondary node key for access to the secondary network node by the user equipment. The method is further, Request to add a secondary node, or A method of any of embodiments 5 to 8, which includes providing as part of at least one of the Kandari node release requests.
[0159] (Embodiment 10) The method is further, A step of providing instructions for at least one secondary node key after receiving instructions for imminent access to a secondary node by a user device, using a secondary node key provided by instructions for at least one secondary node key, or The process includes at least one step of providing instructions for at least one secondary node key using a secondary node key provided by at least one secondary node key, before the user device receives instructions for imminent access to the secondary node, The instruction for at least one secondary node key includes a secondary node key for user equipment to access a secondary network node, or Any method of Embodiments 5 to 9, which includes at least one of providing it as part of a secondary node reconfiguration completion message.
[0160] (Embodiment 11) The method is further, A method according to any of embodiments 5 to 10, comprising the step of counting the number of accesses to each secondary node by each user device, wherein the instruction for at least one secondary key is at least partially based on the number of counted accesses.
[0161] (Embodiment 12) Each secondary node counter list contains a non-monotonic sequence of secondary node counter values, or The secondary node counter lists are at least one of the following, according to any of embodiments 5 to 11.
[0162] (Embodiment 13) For example, a method according to a third exemplary embodiment, A step of obtaining instructions for at least one secondary node key from a master node, wherein at least one secondary node key corresponds to a secondary node counter value included in a generated secondary node counter list (for example, corresponding to a device that performs and / or controls the method), A method comprising the steps of performing access to a user device using at least one secondary node key of instructions for at least one secondary node key obtained.
[0163] (Embodiment 14) The method is further, A step of obtaining instructions for at least one secondary node key as part of a secondary node change request or a secondary node addition request, The method of Embodiment 13, which includes at least one of the following steps: obtaining an instruction for at least one secondary node key as part of a secondary node change request or a secondary node add request, wherein the instruction for at least one secondary node key corresponds to a secondary node key list corresponding to a generated secondary node counter list (for example, corresponding to a device that performs and / or controls the method).
[0164] (Embodiment 15) The method is further, The steps include obtaining instructions for at least one secondary node key after a secondary node addition request, or as part of a secondary node reconfiguration completion message, or The method of Embodiment 13 or 14, comprising at least one of the following steps: obtaining instructions for at least one secondary node key as part of a secondary node reconfiguration completion message, wherein the instructions for at least one secondary node key correspond to a secondary node key for access by user equipment (e.g., to equipment that performs and / or controls the method).
[0165] (Embodiment 16) The method is further, A step of obtaining instructions for at least one secondary node key as part of a secondary node addition request or a secondary node release request, A method of any embodiment 13 to 15, comprising at least one of the steps of obtaining instruction for at least one secondary node key as part of a request to add a secondary node or a request to release a secondary node, wherein the instruction for at least one secondary node key corresponds to a secondary node key for access by user equipment (e.g., to equipment that performs and / or controls the method).
[0166] (Embodiment 17) The means are further, A step of counting the number of accesses by each user device (for example, to the device that performs and / or controls the method), A method configured to perform the steps of selecting a secondary node key from a list of secondary node keys based on the number of accesses counted, and any of embodiments 13 to 16.
[0167] (Embodiment 18) The method is further, Each secondary node counter list contains a non-monotonic sequence of secondary node counter values, or The secondary node counter lists are at least one of the following, according to any of embodiments 13 to 17.
[0168] (Embodiment 19) For example, a first apparatus (e.g., UE) including means for performing any of the methods of Embodiments 1 to 4.
[0169] (Embodiment 20) A first device (e.g., UE) comprising at least one processor and at least one memory for storing instructions, wherein, once an instruction is executed by at least one processor, the first device causes the device to execute and / or control a method according to at least one of embodiments 1 to 4.
[0170] (Embodiment 21) For example, a second device (e.g., a master network node) comprising means for performing any of the methods of Embodiments 5 to 12.
[0171] (Embodiment 22) A second device (e.g., a master network node) comprising at least one processor and at least one memory for storing instructions, wherein, once an instruction is executed by at least one processor, the second device causes the device to execute and / or control a method according to at least one of embodiments 5 to 12.
[0172] (Embodiment 23) For example, a third device (e.g., a secondary network node) comprising means for performing any of the methods of Embodiments 13 to 18.
[0173] (Embodiment 24) A third device (e.g., a secondary network node) comprising at least one processor and at least one memory for storing instructions, wherein when an instruction is executed by at least one processor, the third device causes the device to perform and / or control at least one of the methods according to any of embodiments 13 to 18.
[0174] (Embodiment 25) A computer program, when executed by a processor, causes a device (e.g., the device of Embodiment 19 or 20) to perform and / or control actions and / or steps of any of Embodiments 1 to 4.
[0175] (Embodiment 26) A computer program product including the computer program of Embodiment 25.
[0176] (Embodiment 25) A computer program, when executed by a processor, causes a device (e.g., the device of Embodiment 21 or 22) to perform and / or control actions and / or steps of any of Embodiments 5 to 12.
[0177] (Embodiment 26) A computer program product including the computer program of Embodiment 25.
[0178] (Embodiment 27) A computer program, when executed by a processor, causes a device (e.g., the device of Embodiment 23 or 24) to perform and / or control actions and / or steps of any of the methods of Embodiments 13 to 18.
[0179] (Embodiment 28) A computer program product including the computer program of Embodiment 27.
[0180] (Embodiment 29) A first apparatus according to either Embodiment 19 or 20, A second device according to either embodiment 21 or 22, A third device according to either embodiment 23 or 24, A system equipped with these features.
[0181] In this specification, any presented connections in the embodiments described should be understood as being in a manner in which the relevant components are operably coupled. Thus, connections may be direct or indirect using any number or combination of intervening elements, and merely functional relationships may exist between the components.
[0182] Furthermore, any of the methods, processes, and actions described or illustrated herein may be implemented using executable instructions within a general-purpose or dedicated processor and stored on a computer-readable storage medium (e.g., disk, memory, etc.) to be executed by such a processor. The reference to “computer-readable storage medium” should be understood to include dedicated circuits such as FPGAs, ASICs, signal processing devices, and other devices.
[0183] The expression "A and / or B" is considered to include one of three scenarios: (i) A, (ii) B, or (iii) A and B. The expression "at least one of A or B," which has the same meaning as "A and / or B," may be used herein. Furthermore, the article "a" should not be understood as "one," that is, the use of the expression "an element" does not exclude the existence of further elements. The term "comprising" should be understood in an open sense, that is, an object "containing element A" may contain further elements in addition to element A.
[0184] All presented embodiments are (merely) examples, and it will be understood that any feature presented for a particular exemplary embodiment may be used in any manner, either by itself or in combination with any feature presented for the same or another particular exemplary embodiment, and / or in combination with any other feature not mentioned. In particular, the exemplary embodiments presented herein should also be understood as being technically valid and disclosed in all possible combinations with each other, unless the exemplary embodiments are substitutes for each other. Furthermore, it will be understood that any feature presented for an exemplary embodiment in a particular category (method / apparatus / computer program / system) may be used in a corresponding manner in an exemplary embodiment of any other category. It will also be understood that the presence of a feature in a presented exemplary embodiment does not necessarily mean that the feature constitutes an essential feature that cannot be omitted or substituted.
[0185] A description of a feature containing at least one of the features listed later is not required to ensure that the feature contains at least one of the features listed later, or at least one of the features listed later. It is also possible to select any combination of the listed features, or to select just one of the listed features (e.g., only one). Any specific combination of all the features listed later may also be considered. Furthermore, it may be possible to select multiple of the listed features (e.g., only one).
[0186] All method operation sequences presented above are not mandatory, and alternative sequences may be possible. Nevertheless, any specific sequence of method operation illustrated in the drawings shall be considered one possible sequence of method operation for each embodiment described by each drawing.
[0187] The subject matter has been described above using exemplary embodiments. It should be noted that alternative methods and modifications exist that will be obvious to those skilled in the art and can be implemented without departing from the scope of the appended claims.
[0188] List of Abbreviations ACK: Affirmative response RRC: Wireless Resource Control UE: User Equipment MN: Master Node SN: Secondary node MR-DC: Multi-RAT Dual Connectivity PCell: Primary Cell PSCell: Primary and Secondary Cells SCell: Secondary Cell SCG: Secondary Cell Group MCG: Mastercell Group CPAC: Conditional PSCell additions and modifications
Claims
1. At least one processor, A device comprising at least one memory for storing instructions, wherein when an instruction is executed by the at least one processor, the device has at least one A step of obtaining at least one secondary node counter list, wherein the secondary node counter list corresponds to different secondary nodes among a plurality of secondary nodes, The steps include obtaining instructions for one of the multiple secondary nodes, The steps include generating a secondary node key based at least partially on the at least one acquired secondary node counter list and the instructions for the secondary node, A device characterized by causing the user to perform the step of accessing the secondary node using the generated secondary node key.
2. The apparatus according to claim 1, characterized in that the at least one secondary node counter list includes at least two secondary counter lists.
3. The aforementioned device further, The apparatus according to claim 1, wherein the step of counting the number of accesses of the apparatus to each secondary node, and the step of generating the secondary key further involves performing a step based on the counted number of accesses.
4. The secondary node counter list includes a non-monotonic sequence of secondary node counter values, or The apparatus according to claim 1, characterized in that at least one of the following is that the secondary node counter lists are different from each other.
5. At least one processor, A device comprising at least one memory for storing instructions, wherein when an instruction is executed by the at least one processor, the device has at least A step of generating at least one secondary node counter list, wherein the secondary node counter list corresponds to different secondary nodes among a plurality of secondary nodes, A step of providing an instruction for at least one secondary node key to one of the plurality of secondary nodes, wherein the at least one secondary node key of the instruction for at least one secondary node key corresponds to a secondary node counter value included in the generated secondary node counter list corresponding to the secondary node among the plurality of secondary nodes; The steps include providing at least one of the generated secondary node counter lists to the user device, An apparatus characterized by performing the steps of providing instructions to the user equipment for one of the plurality of secondary nodes.
6. The apparatus according to claim 5, characterized in that the at least one secondary node counter list includes at least two secondary counter lists.
7. The aforementioned device further, The apparatus according to claim 5, characterized in that it performs at least one of the steps of providing instructions for the at least one secondary node key before receiving instructions for imminent access to the secondary node by a user device using the secondary node key indicated by the instructions for the at least one secondary node key.
8. The instruction for at least one secondary node key corresponds to the secondary node key list corresponding to the generated secondary node counter list corresponding to the secondary network node, The aforementioned device further, Secondary node change request, or The apparatus according to claim 5, characterized in that it performs the step provided as part of at least one of the requests to add a secondary node.
9. The instruction for at least one secondary node key corresponds to the secondary node key for accessing the secondary network node by the user device, The aforementioned device further, Request to add a secondary node, or The apparatus according to claim 5, characterized in that it performs the step provided as part of at least one of the secondary node release requests.
10. The aforementioned device further, After receiving an instruction from the user device for imminent access to the secondary node using the secondary node key instructed by the at least one secondary node key, the step of providing the instruction for the at least one secondary node key, or Before receiving an instruction from the user device for imminent access to the secondary node using the secondary node key instructed by the at least one secondary node key, perform at least one of the steps of providing instructions for the at least one secondary node key: The instruction for at least one secondary node key includes the secondary node key for the user device to access the secondary network node, or The apparatus according to claim 5, characterized by at least one of the following: providing as part of a secondary node reconfiguration completion message.
11. The aforementioned device further, The apparatus according to claim 5, wherein the step of counting the number of accesses to each secondary node by each user device is further configured to perform the step of at least one secondary key instruction based at least in part on the counted number of accesses.
12. Each of the aforementioned secondary node counter lists contains a non-monotonic sequence of secondary node counter values, or The apparatus according to claim 5, characterized in that at least one of the following is that the plurality of secondary node counter lists are different from one another.
13. At least one processor, A device comprising at least one memory for storing instructions, wherein when an instruction is executed by the at least one processor, the device has at least one A step of obtaining instructions for at least one secondary node key from a master node, wherein the at least one secondary node key corresponds to a secondary node counter value included in a generated secondary node counter list corresponding to the device; An apparatus characterized by causing the device to perform the steps of: using one of the at least one secondary node keys obtained to access user equipment.
14. The aforementioned device further, A step of obtaining instructions for at least one secondary node key as part of a secondary node change request or a secondary node addition request, The apparatus according to 13, characterized in that it performs at least one of the following steps: obtaining an instruction for the at least one secondary node key as part of a secondary node change request or a secondary node addition request, wherein the instruction for the at least one secondary node key corresponds to a secondary node key list corresponding to the generated secondary node counter list corresponding to the apparatus.
15. The aforementioned device further, The steps include obtaining instructions for at least one secondary node key after a request to add a secondary node, or as part of a message indicating that the secondary node has been reconfigured, The apparatus according to 13, characterized in that it performs at least one of the following steps as part of a secondary node reconfiguration completion message: obtaining an instruction for the at least one secondary node key, wherein the instruction for the at least one secondary node key corresponds to a secondary node key for access to the apparatus by the user equipment.
16. The aforementioned device further, A step of obtaining instructions for at least one secondary node key as part of a request to add a secondary node or a request to release a secondary node, The apparatus according to 13, characterized in that it performs at least one of the following steps: obtaining instruction for at least one secondary node key as part of a request to add a secondary node or a request to release a secondary node, wherein the instruction for at least one secondary node key corresponds to a secondary node key for access to the apparatus by the user equipment.
17. The aforementioned device further, A step of counting the number of times each user device accesses the device, The apparatus according to claim 13, characterized in that it is configured to perform the step of selecting the secondary node key from the secondary node key list based on the counted number of accesses.
18. Each of the aforementioned secondary node counter lists contains a non-monotonic sequence of secondary node counter values, or The apparatus according to claim 13, characterized in that at least one of the following is that the plurality of secondary node counter lists are different from each other.