Security updates for subsequent LTMs

The solution addresses security update challenges in L1/L2 triggered mobility by determining and transmitting security keys and NCCs to UEs, ensuring secure and efficient key synchronization during inter-CU mobility, reducing latency and overhead.

JP2026528819APending Publication Date: 2026-08-25LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2026507772
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-08-08
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in managing security updates during Layer 1/Layer 2 (L1/L2) triggered mobility (LTM), particularly in scenarios involving subsequent central unit (CU) inter-mobility, where there is no Radio Resource Control (RRC) reconfiguration message, leading to unclear key synchronization and security update requirements.

Method used

A base station processor determines a security key and next-hop chaining counter (NCC) for UE-to-target base station communication, transmitting these via a transceiver to facilitate security updates, and includes indicators for DU notification, using AMF-provided parameters for key derivation and synchronization.

Benefits of technology

Ensures secure and efficient security key updates during LTM, reducing latency and overhead by enabling seamless key synchronization between UEs and target base stations, particularly in inter-CU scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026528819000001_ABST
    Figure 2026528819000001_ABST
Patent Text Reader

Abstract

Various aspects of this disclosure relate to user equipment, processors, and methods for security updates for successor central unit (CU) interlayer 1 / layer 2 (L1 / L2) triggered mobility (LTM). In one aspect, a base station, which is a first target base station for the LTM, determines a first security key to be used between the user equipment (UE) and a second target base station for the LTM, and a next-hop (NH) chaining counter (NCC) to be used by the UE for key derivation for cell switching. The base station transmits the NCC to the UE via a transceiver. In this way, the key for cell switching derived by the UE is synchronized with the first security key.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure relates to wireless communications, and more particularly to security updates for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), such as base stations, user equipment, processors, and methods for security updates for subsequent central unit (CU) inter-LTM. [Background technology]

[0002] A wireless communication system may include one or more network communication devices, such as base stations, which may also be known as eNodeB (eNB), next-generation NodeB (gNB), or other appropriate terms. Each network communication device, such as a base station, may support wireless communication to one or more user communication devices, which may also be known as user equipment (UE), or other appropriate terms. A wireless communication system may support wireless communication with one or more user communication devices by using the resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)). Furthermore, a wireless communication system may support wireless communication across a variety of radio access technologies, including 3G radio access technologies, 4G radio access technologies, and 5G radio access technologies, in particular, among other appropriate radio access technologies beyond 5G (e.g., 6G).

[0003] When a UE moves to a new cell with a change of Packet Data Convergence Protocol (PDCP) anchor, the UE and the network must obtain a new security key for security update. For LTM within the CU (including LTM within the DU in the CU and LTM between the DUs in the CU), security update is not required thanks to the invariant PDCP anchor, but for LTM between the CUs, since PDCP anchor relocation occurs, security update should be performed. However, for subsequent LTM between the CUs, there is no Radio Resource Control (RRC) reconfiguration message between the UE and the candidate CU. Therefore, there are still some open issues in the LTM schemes to be considered.

Summary of the Invention

Problems to be Solved by the Invention

[0004] The present disclosure relates to a base station, a user equipment, a method and a processor that support security update for subsequent LTM between the CUs.

Means for Solving the Problems

[0005] In a first aspect of the solution, a base station may comprise a processor and a transceiver coupled to the processor, the base station being a first target base station for layer 1 / layer 2 (L1 / L2) trigger-based mobility (LTM), the processor being configured to determine a first security key to be used between a user equipment (UE) and a second target base station for LTM, and a next hop (NH) chaining counter (NCC) to be used for key derivation for cell switch by the UE, and to transmit the NCC to the UE via the transceiver.

[0006] In some implementations of the methods and apparatuses described herein, the processor may be further configured to transmit the first security key and the NCC to the second target base station via the transceiver.

[0007] In some implementations of the methods and apparatus described herein, the first target base station may include a first target central unit (CU) and one or more distributed units (DUs), the one or more DUs including a first target DU that serves a UE.

[0008] In some implementations of the methods and apparatus described herein, the processor may include a first processor of a first target CU, the first processor may be configured to receive a cell switch decision message from a first target DU instructing a cell switch to a target cell, determine whether a security update is required based on the received cell switch decision message, perform a first security key derivation to determine a first security key and NCC in response to determining that a security update is required, and transmit an NCC to the first target DU via a transceiver so that the NCC is transmitted to the UE via the first target DU.

[0009] In some implementations of the methods and apparatus described herein, the first processor may be further configured to transmit the first security key and NCC to a second target base station via a transceiver.

[0010] In some implementations of the methods and apparatus described herein, the first security key derivation may include, if the first target CU has an unused {NH,NCC} pair, calculating a first security key from NH and setting the value of NCC to be equal to the value of NCC in the unused {NH,NCC} pair, or, if the first target CU does not have an unused {NH,NCC} pair, calculating a first security key from the current security key used by the first target base station and UE and setting the value of NCC to be equal to the current NCC value associated with the current security key.

[0011] In some implementations of the methods and apparatus described herein, the first processor may be configured to determine that a security update is required when the target cell is managed by a second target base station, and to determine that a security update is not required when the target cell is managed by the first target base station.

[0012] In some implementations of the methods and apparatus described herein, the processor may further include a second processor of the first target DU, the second processor may be configured to transmit the NCC received from the first target CU to the UE via a transceiver, thereby the NCC is used by the UE to perform a second security key derivation to determine a second security key to be used between the UE and the second target base station.

[0013] In some implementations of the methods and apparatus described herein, the first processor may be further configured to transmit a first indicator via a transceiver to the first target DU indicating whether the first target DU should notify the UE that a security update is required during cell switching to a target cell.

[0014] In some implementations of the methods and apparatus described herein, the first indicator may include one of the following: a security update indicator indicating whether a security update is required; a CU indicator indicating that the CU of a target cell is different from a first target CU; an inter-CU LTM indicator indicating that a cell switch is associated with an inter-CU LTM; or a CU node identifier (ID) indicating the ID of the CU of a target cell.

[0015] In some implementations of the methods and apparatus described herein, the second processor may be further configured to transmit a second indicator via a transceiver to the UE indicating whether a security update is required during cell switching to a target cell, the second indicator being determined by a first target DU based on the first indicator.

[0016] In some implementations of the methods and apparatus described herein, the second indicator may include one of the following: a security update indicator indicating whether a security update is required; a CU indicator indicating that the CU of a target cell is different from a first target CU; an inter-CU LTM indicator indicating that a cell switch is associated with an inter-CU LTM; and a CU node identifier (ID) indicating the ID of the CU of a target cell.

[0017] In some implementations of the methods and apparatus described herein, the NCC may be transmitted from a first target base station to a UE by a media access control (MAC) control element (CE).

[0018] In some implementations of the methods and apparatus described herein, MAC CE may be an LTM cell switch command.

[0019] In some implementations of the methods and apparatus described herein, the second processor may be further configured to receive a first security update failure message indicating a security update failure via a transceiver and from the UE.

[0020] In some implementations of the methods and apparatus described herein, the processor may be further configured to obtain information about security update parameters from an access and mobility management function (AMF) and to transmit the obtained information about security update parameters to the UE via a transceiver, the information about security update parameters being used by the UE to update the NH parameters associated with the first security key.

[0021] In some implementations of the methods and apparatus described herein, information about security update parameters may indicate that a NAS security context different from the currently active non-accessible layer (NAS) security context is activated by AMF.

[0022] In some implementations of the methods and apparatus described herein, the security update parameter may include an NH indicator indicating that a NAS security context different from the currently active NAS security context is activated by the AMF, an ngKSI indicating the NAS security context used to derive the updated NH parameter, or a downlink NAS COUNT including a NAS SQN and a NAS OVERFLOW, where the NAS SQN is a sequence number used for a security key used between the UE and the first target base station, and the NAS OVERFLOW is a value that is incremented each time the NAS SQN is incremented from its maximum value.

[0023] In some implementations of the methods and apparatus described herein, information about security update parameters may be transmitted to the UE by a media access control (MAC) control element (CE) for LTM cell switch commands or by a MAC CE for security updates.

[0024] In some implementations of the methods and apparatus described herein, the processor may be further configured to receive a second security update failure message indicating a failure to update the NH parameters via a transceiver and from the UE.

[0025] In some implementations of the methods and apparatus described herein, the second security update failure message may be received by a media access control (MAC) control element (CE).

[0026] In a second embodiment of the solution, the base station comprises a processor and a transceiver coupled to the processor, the base station being a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), the processor being configured to determine whether a security update is required for the LTM and, based on the result of the determination, to transmit security update information to the user equipment (UE) via the transceiver, the security update information being associated with a first security key to be used between the UE and a second target base station for the LTM.

[0027] In some implementations of the methods and apparatus described herein, the first target base station may include a first target central unit (CU) and one or more distributed units (DUs), the one or more DUs including a first target DU serving a UE, and the processor including a first processor of the first target CU, the first processor configured to receive a cell switch decision message from the first target DU instructing a cell switch to a target cell, and to determine whether a security update is required based on the received cell switch decision message.

[0028] In some implementations of the methods and apparatus described herein, security update information may include a next-hop (NH) chaining counter (NCC) to be used for key derivation for cell switching by the UE, and the first processor is configured to perform a first security key derivation to determine a first security key and an NCC in response to determining that a security update is required, and to transmit the NCC to the first target DU via a transceiver so that the NCC is transmitted to the UE via the first target DU.

[0029] In some implementations of the methods and apparatus described herein, the first processor may be further configured to transmit a first security key and NCC to a second target base station via a transceiver.

[0030] In some implementations of the methods and apparatus described herein, the first processor may be further configured to send a first indicator to the first target DU indicating whether the first target DU should notify the UE that a security update is required during cell switching to the target cell.

[0031] In some implementations of the methods and apparatus described herein, the processor may further include a second processor of the first target DU, the second processor configured to transmit a second indicator via a transceiver to the UE indicating whether a security update is required during cell switching to a target cell, the second indicator being determined by the first target DU based on the first indicator.

[0032] In some implementations of the methods and apparatus described herein, the processor may be configured to determine that a security update is required in response to receiving information about security update parameters from an access and mobility management function (AMF), the information about security update parameters being used by the UE to update the next-hop (NH) parameter associated with the first security key, and the security update information including the received information about security update parameters.

[0033] In a third embodiment of the solution, a processor for wireless communication comprises at least one memory and a controller coupled to at least one memory, the controller configured to cause the processor to determine a first security key to be used between user equipment (UE) and a second target base station for LTM at a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), and a next-hop (NH) chaining counter (NCC) to be used for key derivation for cell switching by the UE, and to transmit the NCC to the UE via a transceiver.

[0034] A fourth embodiment of the solution is a method implemented by a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), the method comprising the steps of determining a first security key to be used between user equipment (UE) and a second target base station for LTM, and a next-hop (NH) chaining counter (NCC) to be used by the UE for key derivation for cell switching, and transmitting the NCC to the UE.

[0035] In a fifth embodiment of the solution, a processor for wireless communication comprises at least one memory and a controller coupled to at least one memory, the controller configured to cause the processor to determine whether a security update for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM) is required at a first target base station for LTM, and, based on the result of the determination, transmit security update information to the user equipment (UE) via a transceiver, the security update information being associated with a first security key to be used between the UE and a second target base station for LTM.

[0036] A sixth embodiment of the solution is a method implemented by a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), the method comprising the steps of determining whether a security update is required for the LTM, and, based on the result of the determination, transmitting security update information to a user equipment (UE), the security update information being associated with a first security key to be used between the UE and a second target base station for the LTM.

[0037] In a seventh embodiment of the solution, the user equipment (UE) comprises a processor and a transceiver coupled to the processor, the processor configured to receive, via the transceiver and from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM) a next-hop (NH) chaining counter (NCC) to be used by the UE for key derivation for cell switching, and to perform key derivation using the NCC to determine a first security key to be used between the UE and a second target base station for LTM.

[0038] In some implementations of the methods and apparatus described herein, key derivation may include calculating a security key from the current security key if the value of the NCC is equal to the value of the current NCC associated with the current security key used by the first target base station and UE, or if the value of the NCC is different from the value of the current NCC, iteratively synchronizing locally stored NH parameters to increment the value of the current NCC, and calculating a security key from the synchronized NH parameters if the value of the current NCC matches the value of the NCC received from the first target base station.

[0039] In some implementations of the methods and apparatus described herein, the processor may be further configured to receive an indicator via a transceiver and from a first target base station indicating whether a security update is required during cell switching to a target cell, and to perform key derivation if the indicator indicates that a security update is required.

[0040] In some implementations of the methods and apparatus described herein, the indicator may include one of the following: a security update indicator indicating whether a security update is required; a CU indicator indicating that the CU of a target cell is different from a first target CU; an inter-CU LTM indicator indicating that a cell switch is associated with an inter-CU LTM; and a CU node identifier (ID) indicating the ID of the CU of a target cell.

[0041] In some implementations of the methods and apparatus described herein, the NCC may be received by the UE from a first target base station via a media access control (MAC) control element (CE).

[0042] In some implementations of the methods and apparatus described herein, MAC CE may be an LTM cell switch command.

[0043] In some implementations of the methods and apparatus described herein, the processor may be further configured to transmit a first security update failure message indicating a security update failure via a transceiver to a first target base station.

[0044] In some implementations of the methods and apparatus described herein, the processor may be further configured to receive information about security update parameters issued by the Access and Mobility Management Function (AMF) via a transceiver and from a first target base station, and to update the NH parameter associated with the first security key based on the information about the security update parameters.

[0045] In some implementations of the methods and apparatus described herein, information about security update parameters may indicate that a NAS security context different from the currently active non-accessible layer (NAS) security context is activated by AMF.

[0046] In some implementations of the methods and apparatus described herein, the security update parameter may include an NH indicator indicating that a NAS security context different from the currently active NAS security context is activated by the AMF, an ngKSI indicating the NAS security context used to derive the updated NH parameter, or a downlink NAS COUNT including a NAS SQN and a NAS OVERFLOW, where the NAS SQN is a sequence number used for a security key used between the UE and the first target base station, and the NAS OVERFLOW is a value that is incremented each time the NAS SQN is incremented from its maximum value.

[0047] In some implementations of the methods and apparatus described herein, information about security update parameters may be received by the UE via a media access control (MAC) control element (CE) for LTM cell switch commands or a MAC CE for security updates.

[0048] In some implementations of the methods and apparatus described herein, the processor may be further configured to transmit a second security update failure message indicating the failure of the NH parameter update to a first target base station via a transceiver.

[0049] In some implementations of the methods and apparatus described herein, the second security update failure message may be transmitted by a media access control (MAC) control element (CE).

[0050] In an eighth embodiment of the solution, the user equipment (UE) comprises a processor and a transceiver coupled to the processor, the processor configured to receive security update information via the transceiver and from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), and to perform operations related to security updates for LTM based on the security update information, the security update information being associated with a first security key to be used between the UE and a second target base station for LTM.

[0051] In some implementations of the methods and apparatus described herein, security update information may include a next-hop (NH) chaining counter (NCC) to be used for key derivation for cell switching by the UE, and the operation associated with the security update includes a key derivation operation for determining a first security key by using the NCC.

[0052] In some implementations of the methods and apparatus described herein, security update information may further include an indicator indicating whether a security update is required during cell switching to a target cell.

[0053] In some implementations of the methods and apparatus described herein, security update information may include information about security update parameters used by the UE to update the next-hop (NH) parameter associated with a first security key, and the operation related to security update includes updating the NH parameter by using the information about the security update parameters.

[0054] In a ninth embodiment of the solution, a processor for wireless communication comprises at least one memory and a controller coupled to at least one memory, the controller configured to cause the processor to receive, via a transceiver and from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), a next-hop (NH) chaining counter (NCC) to be used for key derivation for cell switching by the UE, and to perform key derivation using the NCC to determine a first security key to be used between the UE and a second target base station for LTM.

[0055] A tenth embodiment of the solution is a method implemented by a user device (UE), the method comprising: receiving a next-hop (NH) chaining counter (NCC) from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM) to be used by the UE for key derivation for cell switching; and performing key derivation using the NCC to determine a first security key to be used between the UE and a second target base station for the LTM.

[0056] In an eleventh embodiment of the solution, a processor for wireless communications comprising at least one memory and a controller coupled to at least one memory, the controller configured to cause the processor to receive security update information via a transceiver and from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), and to perform operations related to security updates for LTM based on the security update information, the security update information being associated with a first security key to be used between the UE and a second target base station for LTM.

[0057] In a twelfth embodiment of the solution, a method implemented by a user device (UE) comprises the steps of receiving security update information from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), and performing an operation related to a security update for the LTM based on the security update information, wherein the security update information is associated with a first security key to be used between the UE and a second target base station for the LTM.

[0058] Please understand that this abstract is not intended to identify any key or essential features of the embodiments of the Disclosure, nor is it intended to be used to limit the scope of the Disclosure. Other features of the Disclosure will be readily apparent from the following description. [Brief explanation of the drawing]

[0059] [Figure 1] This figure shows an example of a wireless communication system that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 2] This figure shows illustrative concepts of LTMs and subsequent LTMs associated with aspects of this disclosure. [Figure 3A] This figure shows exemplary scenarios of LTM associated with aspects of this disclosure. [Figure 3B] This figure shows exemplary scenarios of LTM associated with aspects of this disclosure. [Figure 3C] This figure shows exemplary scenarios of LTM associated with aspects of this disclosure. [Figure 4] This figure shows an exemplary key derivation associated with an aspect of this disclosure. [Figure 5] This figure shows a signaling procedure for supporting security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 6] This figure shows a first example of a signaling procedure for supporting security updates for subsequent LTMs, according to the aspects of this disclosure. [Figure 7] This figure shows a second example of a signaling procedure for supporting security updates for subsequent LTMs, according to the aspects of this disclosure. [Figure 8] This figure shows a third example of a signaling procedure for supporting security updates for subsequent LTMs, according to the aspects of this disclosure. [Figure 9] This figure shows a fourth example of a signaling procedure for supporting security updates for subsequent LTMs, according to the aspects of this disclosure. [Figure 10] This figure shows an example of a device that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 11] This figure shows an example of a device that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 12] This figure shows an example of a device that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 13] This figure shows an example of a device that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 14] This figure shows an example of a processor that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 15]This figure shows an example of a processor that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 16] This figure shows an example of a processor that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 17] This figure shows an example of a processor that supports security updates for subsequent LTMs according to the aspects of this disclosure. [Figure 18] This is a flowchart illustrating a method for supporting security updates for subsequent LTMs in the manner of this disclosure. [Figure 19] This is a flowchart illustrating a method for supporting security updates for subsequent LTMs in the manner of this disclosure. [Figure 20] This is a flowchart illustrating a method for supporting security updates for subsequent LTMs in the manner of this disclosure. [Figure 21] This is a flowchart illustrating a method for supporting security updates for subsequent LTMs in the manner of this disclosure. [Modes for carrying out the invention]

[0060] The principles of this disclosure are described here with reference to several embodiments. These embodiments are described for illustrative purposes only and should be understood as helping those skilled in the art to understand and implement this disclosure, without implying any limitation on the scope of this disclosure. The disclosures described herein may be implemented in various ways other than those described below.

[0061] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meanings as those generally understood by those skilled in the art of the field to which this disclosure belongs.

[0062] References in this disclosure to “one embodiment,” “exemplary embodiment,” “embodiment,” and “some embodiments” indicate that the embodiments described may include certain features, structures, or characteristics, but not all embodiments are required to include such features, structures, or characteristics. Furthermore, such phrases do not necessarily refer to the same embodiment. Moreover, when certain features, structures, or characteristics are described in relation to a particular embodiment, it is stated that this is within the scope of what a person skilled in the art would know to affect such features, structures, or characteristics in relation to other embodiments, whether explicitly stated or not.

[0063] Terms such as "first" and "second" may be used herein to describe various elements, but it should be understood that these elements should not be limited by these terms. These terms are used merely to distinguish one element from another. For example, without departing from the scope of the embodiment, the first element may be called the second element, and similarly, the second element may be called the first element. The term "and / or" as used herein includes any combination of one or more of the listed terms.

[0064] The terms used herein are for the purpose of describing specific embodiments only and are not intended to limit the exemplary embodiments. The singular forms “a,” “an,” and “the” as used herein also include the plural form unless the context otherwise explicitly indicates. It should be further understood that, as used herein, the terms “comprises,” “comprising,” “has,” “having,” “includes,” and / or “including” specify the existence of the described function, element, and / or component, but do not exclude the existence or addition of one or more other functions, elements, components, and / or combinations thereof.

[0065] As used herein, the term “communication network” refers to any network conforming to any appropriate communication standard, such as 5G New Radio (NR), Long-Term Evolution (LTE), LTE Advanced (LTE-A), Broadband Code Division Multiple Access (WCDMA®), High-Speed ​​Packet Access (HSPA), and Narrowband Internet of Things (NB-IoT). Furthermore, communication between terminal devices and network devices within a communication network may be carried out according to any appropriate generation communication protocol, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G) communication protocols, and / or any other protocols currently known or to be developed in the future. Embodiments of this disclosure may be applied to various communication systems. Given the rapid development in communications, there may be future communication technologies and systems to which this disclosure may be embodied. It should not be considered that the scope of this disclosure is limited to the systems described above.

[0066] As used herein, the term “network device” generally refers to a node in a communication network from which a terminal device can access the communication network and receive services. Depending on the terminology and technology applied, a network device may refer to a base station (BS) or access point (AP), such as a Node B (NodeB or NB), a Radio Access Network (RAN) node, an Advanced Node B (eNodeB or eNB), an NR NB (also known as a gNB), a Remote Radio Unit (RRU), a Radio Header (RH), an Infrastructure Device for V2X (vehicle-to-vehicle-to-infrastructure) communication, a Transmit Receive Point (TRP), a Receive Point (RP), a Remote Radio Head (RRH), a repeater, an Access Backhaul Integration (IAB) node, a low-power node such as a femtoBS or picoBS, and so on.

[0067] As used herein, the term “terminal device” generally refers to any terminal device that may be capable of wireless communication. For the purposes of this document, terminal devices may also be called communication devices, user equipment (UE), end-user devices, subscriber stations (SS), unmanned aerial vehicles (UAVs), portable subscriber stations, mobile stations (MS), or access terminals (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop embedded devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices (e.g., remote surgery devices), industrial devices (e.g., robots and / or other wireless devices operating in an industrial and / or automated processing chain context), consumer electronic devices, and devices operating in commercial and / or industrial wireless networks. In the following description, the terms “terminal device,” “communication device,” “terminal,” “user equipment,” and “UE” may be used interchangeably.

[0068] As mentioned above, when a UE moves from one cell to another, a serving cell change must be performed at some point. In legacy systems, serving cell changes are performed by explicit RRC reconfiguration signaling to trigger synchronization of the target cell based on an L3 measurement report. This results in longer latency, greater overhead, and longer interrupt times than beam-level mobility.

[0069] The 3rd Generation Partnership Project (3GPP®) has approved a new work item for further enhancing New Radio (NR) mobility, named Layer 1 / Layer 2 (L1 / L2) Triggered Mobility (LTM), to modify serving cells via L1 / L2 signaling in order to reduce latency, overhead, and interrupt time during cell switching.

[0070] There are two definitions related to LTM: LTM and Successive LTM. LTM refers to a PCell (primary cell of a master cell group) or PSCell (primary cell of a secondary cell group) cell switch procedure triggered by a Media Access Control (MAC) control element (CE) based on L1 measurements. Successive LTM refers to a successive LTM cell switch procedure between candidate cells where the UE does not need to be reconfigured by the network.

[0071] Figure 2 illustrates illustrative concepts of LTMs and subsequent LTMs associated with aspects of this disclosure.

[0072] In LTM, when a UE connects to a source DU, the source CU corresponding to the source DU prepares all candidate cell configurations within several candidate DUs (e.g., eight candidate DUs) and provides them to the UE through RRC signaling. As shown in Figure 2, for example, LTM refers to mobility from source DU to candidate DU1, and subsequent LTMs refer to mobility from candidate DU1 to candidate DU2, or mobility from candidate DU1 back to source DU without further RRC signaling (e.g., RRCReconfiguration).

[0073] Possible applicable scenarios for LTM include intra-CU intra-DU LTM, intra-CU inter-DU LTM, and inter-CU LTM.

[0074] Figures 3A to 3C show exemplary scenarios of LTM associated with aspects of the present disclosure. Figure 3A shows a scenario for LTM within a DU within a CU, Figure 3B shows a scenario for LTM between DUs within a CU, and Figure 3C shows a scenario for LTM between DUs between CUs.

[0075] As shown in Figure 3A, in the scenario for LTM within a DU within a CU, the UE moves between different cells within the same DU. As shown in Figure 3B, in the scenario for LTM between DUs within a CU, the UE moves between different cells that belong to different DUs but are within the same CU. As shown in Figure 3C, in the scenario for LTM between CUs, the UE moves between different cells that belong to different DUs, where the different DUs belong to different CUs.

[0076] Figure 4 shows exemplary key derivation associated with aspects of the present disclosure.

[0077] Referring to Figure 4, the keys used in the above security-related functions are organized and derived as follows. · Keys for the Access and Mobility Management Function (AMF): · K AMF is a key derived by the Mobile Equipment (ME) and the Security Anchor Function (SEAF) from K SEAF . · Keys for NAS signaling: · K NASint is a key derived by the ME and the AMF from K AMF and is used only for the protection of NAS signaling with a specific integrity algorithm. · K NASenc is a key derived by the ME and the AMF from K AMF and is used only for the protection of NAS signaling with a specific encryption algorithm. Keys for gNB: · K gNB is a key derived by the ME and the AMF from K AMF . K gNBThis is further derived by ME and source gNB when performing horizontal or vertical key derivation. Key for UP traffic: ·K UPenc is, K gNB The key is derived from ME and gNB and is to be used solely for protecting UP traffic between ME and gNB using a specific cryptographic algorithm. ·K UPint is, K gNB The key is derived from ME and gNB and is to be used solely for the protection of UP traffic between ME and gNB using a specific integrity algorithm. Keys for RRC signaling: ·K RRCint is, K gNB The key is derived from ME and gNB and is to be used solely for the protection of RRC signaling in a specific integrity algorithm. ·K RRCenc is, K gNB The key is derived from ME and gNB and is used solely for the protection of RRC signaling in a specific cryptographic algorithm. Intermediate key: NH is a key derived by ME and AMF to provide forward security. ·K gNB * is the key derived by ME and gNB when performing horizontal or vertical key derivation.

[0078] As mentioned above, primary authentication enables mutual authentication between the UE and the network, K SEAF It provides an anchor key called K. SEAF For example, during primary authentication or NAS key re-key generation and key refresh events, K AMF K is created. AMF Based on K NASint and K NASenc This is then derived when a successful NAS security mode command (SMC) procedure is in operation.

[0079] Whenever an initial AS security context needs to be established between the UE and the gNB, the AMF and the UE, K gNB And derive the next-hop (NH) parameter. K gNB And NH is K AMF It is derived from the following: The NH Chaining Counter (NCC) is calculated for each K gNB and associated with the NH parameter. Any K gNB However, it is associated with the NCC corresponding to the NH value from which it was derived. In the initial setup, K gNB is, K AMF It is directly derived from and then assumed to be associated with a virtual NH parameter whose NCC value is equal to zero. In the initial setup, the derived NH value is associated with an NCC value of 1. In the handover, K gNB *K is used between the UE and the target gNB. gNB The basis for this is the currently active K gNB It is derived either from or from the NH parameters. gNB *But the currently active K gNB When derived from, this is called a horizontal key derivation and is shown for UE along with the non-increasing NCC. gNB If * is derived from the NH parameter, this derivation is called a vertical key derivation and is shown for UE as NCC increases. Finally, K RRCint , K RRCenc , K UPint and K UPenc This is a new K gNB After K is derived, gNB It is derived based on this.

[0080] Using such a key derivation, the K shared with the UE is gNB gNBs that know which previous K was used between the same UE and the previous gNB. gNB It cannot be calculated, and therefore provides backward security. Similarly, K is shared with the UE. gNBA gNB that knows which future K will be used between the same UE and another gNB after n or more handovers gNB It is also impossible to predict (because the NH parameters can only be calculated by UE and AMF).

[0081] The AS SMC procedure is for RRC and user plane (UP) security algorithm negotiation and RRC security activation. When an AS security context should be established in the gNB, the AMF sends the full UE 5G security capability to the gNB (i.e., all bits for any capability defined in TS24.501 and received in NAS signaling). During handover (or UE context retrieval), the full UE 5G security capability is also sent by the source gNB to the target gNB (or, respectively, by the final serving gNB to the receiving gNB). The gNB selects a ciphering algorithm from its configured list that has the highest priority and is also a UE 5G security capability. The gNB also selects an integrity algorithm from its configured list that has the highest priority and is also a UE 5G security capability. The selected algorithm is indicated to the UE in the AS SMC message, and this message is integrity protected. RRC downlink ciphering (encryption) in the gNB begins after the AS SMC message is sent. RRC uplink deciphering in the gNB begins after the UE receives a successful verification of the integrity-protected AS security mode completion message. The UE verifies the validity of the AS SMC message from the gNB by verifying the integrity of the received message. RRC uplink deciphering in the UE begins after the AS security mode completion message is sent. RRC downlink deciphering in the UE shall begin after the UE receives a successful verification of the AS SMC message. The RRC connection reconfiguration procedure used to add a data radio bearer (DRB) shall only be performed after RRC security has been activated as part of the AS SMC procedure.

[0082] A UE connected to 5GC shall support integrity-protected DRB at the highest data rate and any lower data rate supported by the UE for both uplink (UL) and downlink (DL). In the event of an integrity check failure (i.e., an incomplete or missing MAC-I), the PDU shall be discarded by the receiving PDCP entity.

[0083] PDCP COUNT is the same radio bearer identity and the same K gNB When it is likely to be reused together, key refresh, K gNB , K RRCenc , K RRCint , K UPenc , and K UPint This is possible and can be initiated by gNB. Key re-key generation is also possible, K gNB , K RRCenc , K RRCint , K UPenc , and K UPint This is possible, and when a different 5G AS security context than the currently active one must be activated, it can be initiated by AMF.

[0084] When a UE changes its PDCP anchor and moves to a new cell, the UE and network shall acquire a new key for security updates. Within a CU (including within a CU and between DUs), security updates are not required because the PDCP anchor has not been changed. However, security updates are required for inter-CU LTMs because a PDCP anchor relocation occurs.

[0085] When considering security updates for LTM, several issues need to be considered, as follows: The first issue is that for subsequent CU-to-LTM (for example, when a UE moves from candidate CU1 to another candidate CU2, or when a UE returns from candidate CU1 to the source CU), there is no RRCReconfiguration message between the UE and the candidate CU. It is unclear how keys are synchronized between the UE and candidate CU2 or the source CU.

[0086] The second issue is that security updates are not required for intra-CU LTMs, but are mandatory for inter-CU LTMs. It is unclear how subsequent LTMs will be supported in the case of hybrid inter-CU LTMs and intra-CU LTMs. The third issue is that when the AMF has a new NAS security context, it must derive a new NH parameter with a new NCC value equal to zero. It is unclear how the UE will support the activation of the new NH for subsequent inter-CU LTMs. Therefore, a solution is needed to resolve the above issues in order to support subsequent LTMs.

[0087] This disclosure proposes a solution to support security updates for subsequent LTMs, for example, for subsequent inter-CU LTMs. In this solution, security update information associated with a security key to be used between the UE and the target base station (e.g., candidate CU2 or source CU as mentioned above) for subsequent LTMs is introduced to facilitate security updates on both the UE and target base station sides. Security updates for subsequent LTMs can be achieved by implementing exemplary embodiments of this disclosure.

[0088] The aspects of this disclosure are described in the context of wireless communication systems.

[0089] Figure 1 shows an example of a wireless communication system supporting security updates for subsequent LTMs according to an aspect of this disclosure. The wireless communication system 100 may include one or more network entities 102 (also called network equipment (NEs)), one or more UEs 104, a core network 106, and a packet data network 108. The wireless communication system 100 may support various radio access technologies. In some implementations, the wireless communication system 100 may be a 4G network, such as an LTE network or an LTE Advanced (LTE-A) network. In some other implementations, the wireless communication system 100 may be a 5G network, such as an NR network. In other implementations, the wireless communication system 100 may be a combination of 4G and 5G networks, or other suitable radio access technologies, including IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20. The wireless communication system 100 may support radio access technologies beyond 5G. Furthermore, the wireless communication system 100 may support technologies such as time-division multiple access (TDMA), frequency-division multiple access (FDMA), or code-division multiple access (CDMA).

[0090] One or more network entities 102 may be distributed across a geographical area to form a wireless communication system 100. One or more of the network entities 102 described herein may be a network node, base station, network element, radio access network (RAN), transceiver base station, access point, NodeB, eNodeB (eNB), next-generation NodeB (gNB), or other appropriate terms, or may include them, or may be referred to as such. The network entities 102 and UE 104 may communicate via a communication link 110, which may be wireless or wired. For example, the network entities 102 and UE 104 may perform wireless communication via a Uu interface (e.g., receiving and transmitting signaling).

[0091] Network entity 102 may provide a geographic coverage area 112 that network entity 102 can support for services (e.g., voice, video, packet data, messaging, broadcast, etc.) for one or more UEs 104 within that geographic coverage area 112. For example, network entity 102 and UE 104 may support wireless communication of signals associated with services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or more radio access technologies. In some implementations, network entity 102 may be mobile and, for example, a satellite associated with a non-terrestrial network. In some implementations, different geographic coverage areas 112 associated with the same or different radio access technologies may overlap, or different geographic coverage areas 112 may be associated with different network entities 102. The information and signals described herein may be represented using any of a wide variety of technologies and techniques. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be mentioned throughout the description may be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or optical particles, or any combination thereof.

[0092] One or more UEs 104 may be distributed across the geographical area of ​​the wireless communication system 100. The UEs 104 may include, or be referred to as, mobile devices, wireless devices, remote devices, remote units, handheld devices, or subscriber devices, or any other appropriate term. In some implementations, the UEs 104 may be referred to as units, stations, terminals, or clients, among other examples. Additionally or alternatively, the UEs 104 may be referred to as Internet of Things (IoT) devices, any Internet of Things (IoE) devices, or machine-type communications (MTC) devices, among other examples. In some implementations, the UEs 104 may be stationary within the wireless communication system 100. In some implementations, the UEs 104 may be mobile within the wireless communication system 100.

[0093] One or more UE104s may be devices of different forms or with different capabilities. Several examples of UE104s are shown in Figure 1. UE104s may be capable of communicating with various types of devices, such as network entities 102, other UE104s, or network equipment (e.g., core network 106, packet data network 108, relay devices, integrated access and backhaul (IAB) nodes, or other network equipment), as shown in Figure 1. Additionally or alternatively, UE104s may support communication with other network entities 102 or UE104s, which may act as relays in the wireless communication system 100.

[0094] UE104 may also support direct wireless communication with other UE104s via communication link 114. For example, UE104 may support direct wireless communication with another UE104 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-infrastructure (V2X) deployments, or cellular V2X deployments, communication link 114 may be called a side link. For example, UE104 may support direct wireless communication with another UE104 via the PC5 interface.

[0095] A network entity 102 may support communication with the core network 106, or with another network entity 102, or both. For example, a network entity 102 may interface with the core network 106 through one or more backhaul links 116 (e.g., via S1, N2, or another network interface). Network entities 102 may communicate with each other through the backhaul links 116 (e.g., via X2, Xn, or another network interface). In some implementations, network entities 102 may communicate with each other directly (e.g., between network entities 102). In some other implementations, network entities 102 may communicate with each other or indirectly (e.g., via the core network 106). In some implementations, one or more network entities 102 may include sub-components such as access network entities, which may be examples of access node controllers (ANCs). An ANC may communicate with one or more UEs 104 through one or more other access network transmitting entities, which may be called radio heads, smart radio heads, or transmit / receive points (TRPs).

[0096] In some implementations, the network entity 102 may consist of a decoupled architecture, which may be configured to use a physically or logically distributed protocol stack between two or more network entities 102, such as an Access Backhaul Integration (IAB) network, an Open Radio Access Network (O-RAN) (e.g., a network configuration sponsored by the O-RAN Alliance), or a Virtualized RAN (vRAN) (e.g., a Cloud RAN (C-RAN)). For example, the network entity 102 may include one or more of the following, or any combination thereof: CUs, DUs, Radio Units (RUs), RAN Intelligent Controllers (RICs) (e.g., Near Real-Time RICs (Near RT RICs), Non-Real-Time RICs (Non-RT RICs)), Service Management and Orchestration (SMO) systems.

[0097] RU may also be called a radio head, smart radio head, remote radio head (RRH), remote radio unit (RRU), or transmit / receive point (TRP). One or more components of network entity 102 in a separated RAN architecture may be co-located, or one or more components of network entity 102 may be located in distributed locations (e.g., separate physical locations). In some implementations, one or more network entities 102 in a separated RAN architecture may be implemented as virtual units (e.g., virtual CU (VCU), virtual DU (VDU), virtual RU (VRU)).

[0098] The functional division between CUs, DUs, and RUs may be flexible and may support different functionalities depending on which functions (e.g., network layer functions, protocol layer functions, baseband functions, radio frequency functions, and any combination thereof) are performed in the CU, DU, or RU. For example, a functional division of the protocol stack may be used between the CU and DU so that the CU may support one or more layers of the protocol stack and the DU may support one or more different layers of the protocol stack. In some implementations, the CU may host higher protocol layer (e.g., Layer 3 (L3), Layer 2 (L2)) functionalities and signaling (e.g., Radio Resource Control (RRC), Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP)). The CU may be connected to one or more DUs or RUs, each of which may host lower protocol layers such as Layer 1 (L1) (e.g., physical (PHY) layer) or L2 (e.g., radio link control (RLC) layer, medium access control (MAC) layer) functionality and signaling, each of which may be at least partially controlled by the CU160.

[0099] As an addition or alternative, a functional decomposition of the protocol stack may be used between the DU and RU so that the DU can support one or more layers of the protocol stack and the RU can support one or more different layers of the protocol stack. The DU may support one or more different cells (for example, through one or more RUs). In some implementations, the functional decomposition between the CU and the DU, or between the DU and the RU, may be within the protocol layer (for example, some functions for the protocol layer may be performed by one of the CU, DU, or RU, and other functions of the protocol layer may be performed by one of the different CU, DU, or RU).

[0100] A CU may be further functionally divided into CU control plane (CU-CP) and CU user plane (CU-UP) functions. A CU may be connected to one or more DUs via midhaul communication links (e.g., F1, F1-c, F1-u), and a DU may be connected to one or more RUs via fronthaul communication links (e.g., open fronthaul (FH) interfaces). In some implementations, the midhaul or fronthaul communication links may be implemented according to interfaces (e.g., channels) between layers of protocol stacks supported by each network entity 102 communicating via such communication links.

[0101] The core network 106 can support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The core network 106 may be an advanced packet core (EPC) or a 5G core (5GC), which may include control plane entities that manage access and mobility (e.g., a mobility management entity (MME), an access and mobility management function (AMF)), as well as user plane entities that route packets or interconnect to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entities may manage non-access layer (NAS) functions such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for one or more UEs 104 served by one or more network entities 102 associated with the core network 106.

[0102] The core network 106 may communicate with the packet data network 108 via one or more backhaul links 116 (for example, via S1, N2, or another network interface). The packet data network 108 may include an application server 118. In some implementations, one or more UEs 104 may communicate with the application server 118. The UEs 104 may establish a session with the core network 106 (for example, a protocol data unit (PDU) session) via a network entity 102. The core network 106 may use the established session (for example, an established PDU session) to route traffic (for example, control information, data, etc.) between the UEs 104 and the application server 118. The PDU session may be an example of a logical connection between the UEs 104 and the core network 106 (for example, one or more network functions of the core network 106).

[0103] In the wireless communication system 100, the network entities 102 and UE104 can use the resources of the wireless communication system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some implementations, the network entities 102 and UE104 may support different resource structures. For example, the network entities 102 and UE104 may support different frame structures. In some implementations, for example in 4G, the network entities 102 and UE104 may support a single frame structure. In some other implementations, for example in 5G, and in other suitable radio access technologies, the network entities 102 and UE104 may support various frame structures (i.e., multiple frame structures). The network entities 102 and UE104 may support various frame structures based on one or more numerologies.

[0104] One or more numerologies may be supported in the wireless communication system 100, and the numerologies may include subcarrier intervals and cyclic prefixes. A first numerology (e.g., μ=0) may be associated with a first subcarrier interval (e.g., 15 kHz) and a typical cyclic prefix. In some implementations, the first numerology (e.g., μ=0) associated with the first subcarrier interval (e.g., 15 kHz) may use one slot per subframe. A second numerology (e.g., μ=1) may be associated with a second subcarrier interval (e.g., 30 kHz) and a typical cyclic prefix. A third numerology (e.g., μ=2) may be associated with a third subcarrier interval (e.g., 60 kHz) and a typical cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., μ=3) may be associated with a fourth subcarrier interval (e.g., 120 kHz) and a typical cyclic prefix. A fifth numerology (e.g., μ=4) may be associated with a fifth subcarrier interval (e.g., 240 kHz) and a typical cyclic prefix.

[0105] The time intervals of resources (e.g., communication resources) may be organized according to frames (also called wireless frames). Each frame may have a duration, for example, 10 milliseconds (ms). In some implementations, each frame may contain multiple subframes. For example, each frame may contain 10 subframes, each subframe may have a duration, for example, 1 ms. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0106] As an addition or alternative, the time intervals of resources (e.g., communication resources) may be organized according to slots. For example, a subframe may contain a certain number (e.g., a quantity) of slots. The number of slots in each subframe may depend on one or more numerologies supported in the wireless communication system 100. For example, the first, second, third, fourth, and fifth numerologies (i.e., μ=0, μ=1, μ=2, μ=3, μ=4) associated with the respective subcarrier intervals of 15kHz, 30kHz, 60kHz, 120kHz, and 240kHz may use one slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and sixteen slots per subframe, respectively. Each slot may contain a certain number (e.g., a quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., a quantity) of slots for a subframe may depend on the numerology. For a standard cyclic prefix, a slot may contain 14 symbols. For an extended cyclic prefix (e.g., applicable to a 60 kHz subcarrier interval), a slot may contain 12 symbols. The relationships between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for standard and extended cyclic prefixes may depend on the numerology. It should be understood that references to a first numerology (e.g., μ=0) associated with a first subcarrier interval (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0107] In the wireless communication system 100, the electromagnetic (EM) spectrum can be divided into various classes, frequency bands, frequency channels, etc., based on frequency or wavelength. For example, the wireless communication system 100 may support one or more operating frequency bands, such as frequency range designations FR1 (410 MHz to 7.125 GHz), FR2 (24.25 GHz to 52.6 GHz), FR3 (7.125 GHz to 24.25 GHz), FR4 (52.6 GHz to 114.25 GHz), FR4a or FR4-1 (52.6 GHz to 71 GHz), and FR5 (114.25 GHz to 300 GHz). In some implementations, network entities 102 and UE 104 may conduct wireless communication over one or more of these operating frequency bands. In some implementations, FR1 may be used by network entities 102 and UE 104, in particular, among other equipment or devices for cellular communication traffic (e.g., control information, data). In some implementations, FR2 can be used by network entities 102 and UE104, in particular, among other equipment or devices for short-range, high-data-rate capabilities.

[0108] FR1 may be associated with one or more numerologies (e.g., at least three). For example, FR1 may be associated with a first numerology including a 15 kHz subcarrier interval (e.g., μ=0), a second numerology including a 30 kHz subcarrier interval (e.g., μ=1), and a third numerology including a 60 kHz subcarrier interval (e.g., μ=2). FR2 may be associated with one or more numerologies (e.g., at least two). For example, FR2 may be associated with a third numerology including a 60 kHz subcarrier interval (e.g., μ=2), and a fourth numerology including a 120 kHz subcarrier interval (e.g., μ=3).

[0109] Figure 5 shows an exemplary signaling procedure 500 for security updates for subsequent LTMs according to an aspect of the present disclosure. As shown in Figure 5, the first target base station 102-1 determines in step 502 whether a security update for an LTM is required. In some exemplary embodiments, the first target base station 102-1 may be a base station for (i.e., supporting) an LTM, such as a gNB, or another type of base station applicable for an LTM. In the present disclosure, the first target base station may be different from the source base station from which the UE receives RRC messages for an LTM (e.g., RRCReconfiguration).

[0110] In some exemplary embodiments, the first target base station 102-1 may include a first target CU (also referred to as candidate CU1 as described above) and one or more DUs, one or more of which include a first target DU (also referred to as candidate DU1 as described above) serving the UE 104. In some exemplary embodiments, the first target CU may receive a cell switch decision message from the first target DU instructing a cell switch to a target cell, and then determine whether a security update is required based on the received cell switch decision message. In some exemplary embodiments, the first target CU may determine that a security update is required in response to obtaining information about security update parameters from an access and mobility management function (AMF) located in the core network 106.

[0111] In step 504, the first target base station 102-1 may send security update information to the UE 104 based on the result of the decision in step 502. For example, the first target base station 102-1 may send security update information to the UE 104 in response to determining that a security update is required. In step 506, the UE 104 receives the security update information and, in step 508, may perform actions related to the security update for LTM based on the security update information.

[0112] In some exemplary embodiments, security update information may be associated with a first security key to be used between the UE and a second target base station. In this disclosure, the second target base station may also be a base station for (i.e., supporting) the LTM, and may be, for example, a gNB, or other types of base stations applicable for the LTM. In some exemplary embodiments, the second target base station may also be a source base station from which the UE receives RRC messages for the LTM (e.g., RRCReconfiguration).

[0113] In some exemplary embodiments, security update information may include, for example, an NCC to be used by the UE for key derivation for cell switching, and the NCC may be determined by a first key derivation by a first target CU in response to the determination that a security update is needed. In such a case, the NCC is first sent to a first target DU and then forwarded to the UE via the first target DU, and the security update-related operation performed by the UE 104 may include a key derivation operation to determine a first security key using the NCC. A detailed explanation of this case is given below with reference to Figures 6-8.

[0114] In some exemplary embodiments, security update information may include information about security update parameters obtained from the AMF, which can be used by the UE to update the NH parameter associated with the first security key. In such cases, the operation related to security updates may include updating the NH parameter by using the information about the security update parameters. A detailed explanation of this case is provided below with reference to Figure 9.

[0115] Further details regarding security updates for subsequent LTMs are shown in Figures 6 to 9. Figure 6 shows a first example of a signaling procedure 600 for supporting security updates for subsequent LTMs according to the embodiments of this disclosure. In this disclosure, Figure 6 represents security updates for subsequent LTMs without a new NAS security context.

[0116] As shown in Figure 6, the first target base station 102-1 may, in step 602, determine a first security key to be used between UE 104 and the second target base station, and an NCC to be used for key derivation for cell switching by UE 104. Here, both the first target base station 102-1 and the second target base station may be base stations for (i.e., supporting LTM), and may be, for example, a gNB, or other types of base stations applicable for LTM.

[0117] In step 604, the first target base station 102-1 may transmit an NCC to the UE 104. In step 606, the UE 104 receives the NCC from the first target base station 102-1, and in step 608, uses the NCC to perform key derivation to determine the first security key to be used between the UE 104 and the second target base station.

[0118] Hereafter, a detailed explanation of steps 602-608 in procedure 600 is provided with reference to Figures 7 and 8. Figure 7 shows a second example of the signaling procedure 700 for security updates for subsequent LTMs according to the embodiments of this disclosure. Figure 7 shows security updates for subsequent LTMs without a new NAS security context.

[0119] As shown in Figure 7, the signaling procedure 700 involves UE 104, a first target base station 102-1, and a second target base station 102-2, where both the first target base station 102-1 and the second target base station 102-2 may be base stations for (i.e., supporting LTM), and may be, for example, gNBs, or other types of base stations applicable for LTM.

[0120] In some exemplary embodiments, the first target base station 102-1 may include a first target CU 102-10 and one or more DUs, one or more of which include a first target DU (also called candidate DU1, as described above) 102-11 that serves the UE 104. The second target base station 102-2 may include a second target CU 102-20.

[0121] In some exemplary embodiments, in step 702, the first target DU102-11 may decide to perform a cell switch to a target cell, i.e., make an LTM cell switch decision, based, for example, on an L1 measurement report of a candidate cell received from UE104. Then, in step 704, the first target DU102-11 may signal the LTM cell switch decision to the first target CU102-10 by sending a cell switch decision message that instructs a cell switch to a target cell, for example, a message indicating that a UE context correction is needed including the target cell, an LTM cell change notification message, or any other message that may instruct a cell switch.

[0122] In step 706, the first target CU102-10 receives a cell switch decision message from the first target DU102-11 and may determine whether a security update is required based on the received cell switch decision message.

[0123] In some exemplary embodiments, the first target CU102-10 may determine that a security update is not required when the target cell is managed by the first target base station, and in such cases, the first target CU102-10 does not perform the first key derivation. In some exemplary embodiments, the first target CU102-10 may determine that a security update is required when the target cell is managed by the second target base station, and in such cases, the first target CU102-10 performs the first security key derivation.

[0124] In response to determining that a security update is needed, the first target CU102-10, in step 708, obtains the first security key (i.e., K gNB2 *) and a first security key derivation may be performed to determine the NCC for the LTM cell switch. In this disclosure, step 708 corresponds to step 602 in Figure 6.

[0125] In some exemplary embodiments, for the derivation of the first security key, if the first target CU102-10 has an unused {NH,NCC} pair, then the first target CU102-10 derives the first security key (i.e., K) from NH. gNB2 *) should be calculated and the value of NCC should be set to be equal to the value of NCC in an unused {NH,NCC} pair. Otherwise, if the first target CU does not have an unused {NH,NCC} pair, the first target CU102-10 should use the current security key (i.e., K) used by the first target base station and UE. gNB1 ) from the first security key (i.e., K gNB2Calculate the NCC value and the current security key (i.e., K gNB1 You should set it to be equal to the current NCC value associated with it.

[0126] Subsequently, in step 710, the first target CU102-10 may send the NCC to the first target DU102-11 so that the NCC can be sent to the UE104 via the first target DU102-11. In step 724, the first target CU102-10 may further send the first security key and the NCC to the second target CU102-20, and therefore, in step 726, the NCC is received by the second target CU102-20. The order of steps 710 and 724 may differ from that shown in Figure 7. For example, step 710 may be performed before step 724, or steps 710 and 724 may be performed simultaneously.

[0127] In some exemplary embodiments, the first target CU102-10 may signal an NCC to the first target DU102-11 by sending a UE context correction confirmation message, as shown in Figure 7. However, the first target CU102-10 may also send an NCC to the first target DU102-11 by other messages, such as a UE context correction request message. In some exemplary embodiments, the first target CU102-10 signals a first security key and an NCC, i.e., {K gNB2 The *,NCC} pair may be sent to the second target CU102-20 via UE-related signaling, for example, the security information notification message shown in Figure 7.

[0128] In step 712, the first target DU102-11 may receive an NCC from the first target CU102-10, and in step 714, it may transmit the NCC received from the first target CU102-10 to the UE104, thereby allowing the UE104 to perform a second security key derivation to determine a second security key to be used between the UE and the second target base station.

[0129] In some exemplary embodiments, the NCC is transmitted by MAC CE from the first target base station 102-1 (in particular, the first target DU102-11) to the UE104, where MAC CE may be an LTM cell switch command, i.e., the NCC may be included within the LTM cell switch command. However, it will be understood by those skilled in the art that the NCC may also be transmitted to the UE104 by a message other than an LTM cell switch command. In step 716, the UE104 may receive the NCC from the first target DU102-11 (for example, by MAC CE), and in step 718, perform a second security key derivation using the received NCC.

[0130] In some exemplary embodiments, for the second key derivation, the value of NCC is the current security key (i.e., K) used by the first target base station 102-1 and UE104. gNB1 If it is equal to the current NCC value associated with ), UE104 will determine the current security key (i.e., K gNB1 ) from the first security key (i.e., K gNB2 *) can be calculated, or if the NCC value is different from the current NCC value, UE104 repeatedly synchronizes the locally stored NH parameters and increments the current NCC value, and if the current NCC value matches the NCC value received from the first target base station, the first security key (i.e., K) is obtained from the synchronized NH parameters. gNB2 You just need to calculate *).

[0131] However, if UE104 does not receive the NCC, for example, if the NCC is not included in the MAC CE, UE104 will not perform a second key derivation, meaning that when UE104 connects to the target cell, it will not use the current security key (i.e., K gNB1 ) is used. If the security update fails and, for example, the security key derived by UE104 in step 718 is different from the first security key sent to the second target CU102-20 in step 724, UE104 may, in step 720, send a first security update failure message indicating the failure of the security update to the first target DU102-11, for example, by MAC CE. By doing so, the first target DU102-11 receives the first security update failure message indicating the failure of the security update from UE104 in step 722. In some exemplary embodiments, the first target DU102-11 may send a third security update failure message indicating the failure of the security update to the first target CU102-10, which is not shown in Figure 7. In some exemplary embodiments, the first target DU102-11 may forward a first security update failure message indicating a security update failure to the first target CU102-10, which is not shown in Figure 7.

[0132] Figure 8 shows an example of a signaling procedure 800 for security updates for subsequent LTMs according to an aspect of this disclosure. Figure 8 also shows security updates for subsequent LTMs without a new NAS security context. As shown in Figure 8, some steps in Figure 8 are the same as those in Figure 7, for example, steps 802-808 and 818-826 correspond to steps 702-708 and 718-726, respectively. Therefore, for the sake of brevity, descriptions of these steps are omitted, and only the steps that differ from those in Figure 7 are described in detail below.

[0133] Referring to Figure 8, if the first target CU102-10 determines in step 806 that a security update is required and performs the first security key derivation in step 808, then in step 810, it should send a first indicator to the first target DU102-11 indicating whether the first target DU102-11 should notify the UE104 that a security update is required during cell switching to the target cell.

[0134] In some exemplary embodiments, the first indicator may be sent to the first target DU102-11 together with the NCC in step 810, as shown in Figure 8. For example, the first target CU102-10 may send the NCC to the first target DU102-11 together with the first indicator in a UE context correction confirmation message, as shown in Figure 8. However, the first target CU102-10 may also send the NCC to the first target DU102-11 together with the first indicator in another message, for example, a UE context correction request message. As another example, the first target CU102-10 may send the first indicator to the first target DU102-11 separately from the NCC, for example, in a message different from the message containing the NCC.

[0135] In some exemplary embodiments, the first indicator may include a security update indicator, a CU indicator, an inter-CU LTM indicator, or a CU node identifier (ID). For example, a security update indicator may indicate whether a security update is required; for example, if the security update indicator is set to TRUE or 1, the first target DU102-11 should notify UE104 that a security update is required during the LTM cell switch. A CU indicator may indicate that the CU of a target cell is different from the first target CU; for example, if the CU indicator is set to TRUE or 1, the first target DU102-11 should notify UE104 that a security update is required during the LTM cell switch.

[0136] Furthermore, the CU-to-LTM indicator may indicate that a cell switch is associated with CU-to-LTM. For example, if the CU-to-LTM indicator is set to TRUE or 1, the first target DU102-11 should notify UE104 that a security update is required during the LTM cell switch. Additionally, the CU node identifier (ID) may indicate the ID of the CU of the target cell. For example, if the CU node ID is different from the current CU node ID, the first target DU102-11 should notify UE104 that a security update is required during the LTM cell switch.

[0137] After receiving the first indicator in step 812, the first target DU102-11 may determine a second indicator indicating whether a security update is required during cell switching to the target cell, and in step 814, may send the second indicator to UE104.

[0138] In some exemplary embodiments, the second indicator may be determined by the first target DU102-11 based on the first indicator. In some exemplary embodiments, the second indicator may be sent to UE104 together with the NCC in step 814, as shown in Figure 8. For example, the first target DU102-11 may send the NCC together with the second indicator to UE104 by MAC CE used for the LTM cell switch command, as shown in Figure 8, i.e., the NCC and the second indicator may be included in the LTM cell switch command. However, the first target DU102-11 may send the NCC together with the second indicator to the first target DU102-11 in a different message. As another example, the first target CU102-10 may send the first indicator separately from the NCC to the first target DU102-11, for example, in a message different from the message containing the NCC.

[0139] In some exemplary embodiments, the second indicator may include a security update indicator, a CU indicator, an inter-CU LTM indicator, or a CU node identifier (ID). For example, a security update indicator may indicate whether a security update is required; for example, if the security update indicator is set to 1, it means that a security update is required, and UE104 will perform the security update during the LTM cell switch. A CU indicator may indicate that the CU of a target cell is different from the first target CU; for example, if the CU indicator is set to 1, it means that a security update is required, and UE104 will perform the security update during the LTM cell switch.

[0140] Furthermore, the CU-to-LTM indicator may indicate that a cell switch is associated with CU-to-LTM. For example, if the CU-to-LTM indicator is set to 1, it means that a security update is required, and UE104 will perform the security update during the LTM cell switch. Additionally, the CU node identifier (ID) may indicate the ID of the CU of the target cell. For example, if the CU node ID is different from the current CU node ID, it means that a security update is required, and UE104 will perform the security update during the LTM cell switch.

[0141] In some exemplary embodiments, the second indicator may be the same as the first indicator. For example, both the second and first indicators are security update indicators set to 1. In some exemplary embodiments, the second indicator may be different from the first indicator. For example, the first indicator is a CU node ID different from the current CU node ID (i.e., the CU node ID for the first target CU102-10), and the second indicator is a security update indicator set to 1 indicating that a security update is required.

[0142] In step 816, UE104 receives a second indicator from the first target DU102-11 and may then determine, based on the second indicator, whether a security update is required. If the second indicator indicates that a security update is not required, the UE does not perform a second key derivation. In other words, when the UE connects to the target cell, it does not use the current security key (i.e., K gNB1 ) is used. However, if the second indicator indicates that a security update is required, UE104 performs a second key derivation as described with reference to Figure 7.

[0143] The above description states that when an NCC is sent, the first and second indicators are sent; however, the first and second indicators may also be sent when an NCC is not sent. For example, if the first target CU102-10 determines that no security update is required and therefore the first key derivation is not performed, an NCC is not generated. In such a case, the first target CU102-10 only needs to send the first indicator to the first target DU102-11 indicating that the first target DU102-11 should notify the UE104 that no security update is required during the cell switch to the target cell, and therefore the first target DU102-11 only needs to send the second indicator to the UE104 indicating that no security update is required during the cell switch to the target cell.

[0144] In some exemplary embodiments, a second indicator shows that no security update is required and the current security key used by UE104 (i.e., K) gNB1 If the security key used is different from the security key used in the second target CU102-2, UE104 may, in step 820, send a first security update failure message to the first target DU102-11 indicating that the security update has failed, as in step 720.

[0145] Figure 9 shows an example of a signaling procedure 900 for supporting security updates for subsequent LTMs, according to the embodiments of this disclosure. The signaling procedure 900 is intended for situations where there is a new NAS security context.

[0146] As shown in Figure 9, if AMF103 activates a new NAS security context different from the currently active NAS security context, in step 902, it sends a message to the first target CU102-10. The message may carry information about security update parameters, which may indicate that AMF103 is activating a NAS security context different from the currently active NAS security context, and which may be used by UE104 to update the NH parameters associated with the first security key. For example, the message may include security update parameters such as an NH indicator, ngKSI, and / or downlink NAS COUNT. The NH indicator may indicate that AMF is activating a new NAS security context, and ngKSI may indicate the new NAS security context used to derive the updated NH parameters (i.e., new NH parameters). Furthermore, the downlink NAS COUNT may include the NAS SQN and NAS OVERFLOW, where the NAS SQN is a sequence number used for the security key used between the UE and the first target base station, and the NAS OVERFLOW is a value that is incremented each time the NAS SQN is incremented from its maximum value.

[0147] In some exemplary embodiments, the message may be, for example, a route switch request confirmation message or a handover request message. However, other messages are applicable if they can perform the same function.

[0148] In step 904, the first target CU102-10 may obtain information about security update parameters (including NH indicator, ngKSI, and downlink NAS COUNT) from AMF103 and transmit it to the first target DU102-11 in step 906.

[0149] In some exemplary embodiments, the first target CU102-10 may send information about security update parameters (i.e., received NH indicators, ngKSI, and / or downlink NAS COUNT) to the first target DU102-11, for example, by a UE context correction request message or other message. The first target DU102-11 receives the information about security update parameters in step 908 and may then respond in step 910 with a response message, such as a UE context correction response message. In step 912, the first target CU102-10 receives the response message.

[0150] In step 914, the first target DU102-11 may send information about security update parameters (i.e., the received NH indicator, ngKSI, and / or downlink NAS COUNT) to UE104, for example, by MAC CE. In one example, MAC CE may be MAC CE used for LTM cell switch commands, i.e., the NH indicator, ngKSI, and / or downlink NAS COUNT may be included in the LTM cell switch commands. In another example, MAC CE may be MAC CE used for security updates, i.e., MAC CE includes ngKSI and downlink NAS COUNT.

[0151] In step 916, UE104 receives information about security update parameters (i.e., NH indicator, ngKSI, and downlink NAS COUNT), and in step 918, performs an NH update using the NAS security context identified by ngKSI and downlink NAS COUNT to obtain a new (i.e., updated) NH. The NH parameters are associated with the first security key.

[0152] In some exemplary embodiments, if an NH update fails (for example, UE104 is unable to perform the NH update for some reason), UE104 may, in step 920, send a second security update failure message (or a second security update failure message indicating a security update failure) to the first target DU102-11 indicating a failure to update the NH parameters, and the first target DU102-11 may then receive the second security update failure message in step 922. In some exemplary embodiments, the first target DU102-11 may send a fourth security update failure message indicating a security update failure to the first target CU102-10, which is not shown in Figure 9. In some exemplary embodiments, the first target DU102-11 may forward a second security update failure message indicating a security update failure to the first target CU102-10, which is not shown in Figure 9.

[0153] In some exemplary embodiments, the second security update failure message may be sent by MAC CE.

[0154] Figures 10 to 13 show examples of devices that support security updates for subsequent LTMs according to aspects of this disclosure.

[0155] Figure 10 shows an example of a device 1000 supporting security updates for subsequent LTMs according to aspects of this disclosure. Device 1000 may be an example of the first target base station 102-1 described herein. Device 1000 may support wireless communication with one or more network entities 102 (e.g., the second target base station 102-2 or AMF 103 described above) or any combination thereof. Device 1000 may include components for bidirectional communication, including components for transmitting and receiving communications, such as a processor 1002 (including the first processor of the first target CU 102-10 and the second processor of the first target DU 102-11), memory 1004, transceiver 1006, and optionally an I / O controller 1008. These components may communicate electronically via one or more interfaces (e.g., buses) or otherwise coupled (e.g., operably, communicatively, functionally, electronically, electrically).

[0156] The processor 1002, memory 1004, transceiver 1006, or various combinations thereof or various components thereof may be examples of means for carrying out various aspects of the disclosure described herein. For example, the processor 1002, memory 1004, transceiver 1006, or various combinations thereof or components thereof may support a method for carrying out one or more of the operations described herein.

[0157] In some implementations, the processor 1002, memory 1004, transceiver 1006, or various combinations or components thereof, may be implemented in hardware (for example, in a communication management circuit configuration). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which may be configured as means for performing the functions described herein or otherwise supporting such means. In some implementations, the processor 1002 and the memory 1004 coupled with the processor 1002 may be configured to perform one or more of the functions described herein (for example, the processor 1002 executes instructions stored in the memory 1004).

[0158] For example, the processor 1002 may support wireless communication in device 1000 according to the examples disclosed herein. The processor 1002 may be configured to operate to support means for determining a first security key to be used between the UE and a second target base station for LTM, and an NCC to be used by the UE for key derivation for cell switching, and means for transmitting the NCC to the UE.

[0159] The processor 1002 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some implementations, the processor 1002 may be configured to operate a memory array using a memory controller. In some implementations, the memory controller may be integrated into the processor 1002. The processor 1002 may be configured to execute computer-readable instructions stored in memory (e.g., memory 1004) to cause device 1000 to perform various functions of this disclosure.

[0160] Memory 1004 may include random access memory (RAM) and read-only memory (ROM). Memory 1004 may store computer-readable computer-executable code, which, when executed by processor 1002, causes device 1000 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. In some implementations, the code may not be directly executable by processor 1002, but (for example, when compiled and executed) can cause the computer to perform the functions described herein. In some implementations, memory 1004 may include a basic input / output system (BIOS) that may control basic hardware or software operations, in particular, interactions with peripheral components or peripheral devices.

[0161] The I / O controller 1008 can manage input and output signals for device 1000. The I / O controller 1008 can also manage peripheral devices not integrated into device 1000. In some implementations, the I / O controller 1008 may represent physical connections or ports to external peripheral devices. In some implementations, the I / O controller 1008 may use an operating system such as iOS®, ANDROID®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. In some implementations, the I / O controller 1008 may be implemented as part of a processor, such as processor 1006. In some implementations, a user may interact with device 1000 via the I / O controller 1008 or via hardware components controlled by the I / O controller 1008.

[0162] In some implementations, device 1000 may include a single antenna 1010. However, in other implementations, device 1000 may have two or more antennas 1010 (e.g., multiple antennas), including multiple antenna panels or antenna arrays, and these antennas may be capable of simultaneously transmitting or receiving multiple wireless transmissions. Transceiver 1006 may communicate bidirectionally with one or more antennas 1010, wired or wireless links, as described herein. For example, transceiver 1006 may represent a wireless transceiver and communicate bidirectionally with another wireless transceiver. Transceiver 1006 may include a modem for modulating packets, feeding the modulated packets to one or more antennas 1010 for transmission, and demodulating packets received from one or more antennas 1010. Transceiver 1006 may include one or more transmit chains, one or more receive chains, or a combination thereof.

[0163] The transmit chain may be configured to generate and transmit signals (e.g., control information, data, packets). The transmit chain may include at least one modulator for modulating data into a carrier signal and preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmit chain may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. The transmit chain may also include one or more antennas 1010 for transmitting the amplified signal to the air or a wireless medium.

[0164] A receiving chain may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, a receiving chain may include one or more antennas 1010 for receiving signals over air or a wireless medium. A receiving chain may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. A receiving chain may include at least one demodulator configured to demodulate the received signal and to obtain transmitted data by inverting the modulation technique applied during the transmission of the signal. A receiving chain may include at least one decoder for decoding the demodulated signal to receive transmitted data.

[0165] Figure 11 shows an example of a device 1100 supporting security updates for subsequent LTMs according to aspects of this disclosure. Device 1100 may be an example of a first target base station 102-1 as described herein. Device 1100 may support wireless communication with one or more network entities 102 (e.g., the second target base station 102-2 or AMF 103 described above) or any combination thereof. Device 1100 may include components for bidirectional communication, including components for transmitting and receiving communications, such as a processor 1102 (including a first processor in the first target CU 102-10 and a second processor in the first target DU 102-11), memory 1104, transceiver 1106, and optionally an I / O controller 1108. These components may communicate electronically via one or more interfaces (e.g., buses) or otherwise coupled (e.g., operably, communicatively, functionally, electronically, electrically).

[0166] The processor 1102, memory 1104, transceiver 1106, or various combinations thereof or various components thereof may be examples of means for carrying out various aspects of the disclosure described herein. For example, the processor 1102, memory 1104, transceiver 1106, or various combinations thereof or components thereof may support a method for carrying out one or more of the operations described herein.

[0167] In some implementations, the processor 1102, memory 1104, transceiver 1106, or various combinations or components thereof, may be implemented in hardware (for example, in a communication management circuit configuration). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which may be configured as means for performing the functions described herein or otherwise supporting such means. In some implementations, the processor 1102 and the memory 1104 coupled with the processor 1102 may be configured to perform one or more of the functions described herein (for example, the processor 1102 executes instructions stored in the memory 1104).

[0168] For example, the processor 1102 may support wireless communication in device 1100 according to the examples disclosed herein. The processor 1102 may be configured to operate to support means for determining whether a security update is required for the LTM and means for transmitting security update information to the user equipment (UE) based on the result of the determination, the security update information being associated with a first security key to be used between the UE and a second target base station for the LTM.

[0169] The processor 1102 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some implementations, the processor 1102 may be configured to operate a memory array using a memory controller. In some implementations, the memory controller may be integrated into the processor 1102. The processor 1102 may be configured to execute computer-readable instructions stored in memory (e.g., memory 1104) to cause device 1100 to perform various functions of this disclosure.

[0170] Memory 1104 may include random access memory (RAM) and read-only memory (ROM). Memory 1104 may store computer-readable computer-executable code, which, when executed by processor 1102, causes device 1100 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. In some implementations, the code may not be directly executable by processor 1102, but (for example, when compiled and executed) can cause the computer to perform the functions described herein. In some implementations, memory 1104 may include a basic input / output system (BIOS) that can control basic hardware or software operations, in particular, interactions with peripheral components or peripheral devices.

[0171] The I / O controller 1108 can manage input and output signals for device 1100. The I / O controller 1108 can also manage peripheral devices not integrated into device 1100. In some implementations, the I / O controller 1108 may represent physical connections or ports to external peripheral devices. In some implementations, the I / O controller 1108 may use an operating system such as iOS®, ANDROID®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. In some implementations, the I / O controller 1108 may be implemented as part of a processor, such as processor 1102. In some implementations, a user may interact with device 1100 via the I / O controller 1108 or via hardware components controlled by the I / O controller 1108.

[0172] In some implementations, device 1100 may include a single antenna 1110. However, in other implementations, device 1100 may have two or more antennas 1110 (e.g., multiple antennas), including multiple antenna panels or antenna arrays, and these antennas may be capable of simultaneously transmitting or receiving multiple wireless transmissions. Transceiver 1106 may communicate bidirectionally with one or more antennas 1110, wired or wireless links, as described herein. For example, transceiver 1106 may represent a wireless transceiver and communicate bidirectionally with another wireless transceiver. Transceiver 1106 may also include a modem for modulating packets and providing the modulated packets to one or more antennas 1110 for transmission, and for demodulating packets received from one or more antennas 1110. Transceiver 1106 may include one or more transmit chains, one or more receive chains, or a combination thereof.

[0173] The transmit chain may be configured to generate and transmit signals (e.g., control information, data, packets). The transmit chain may include at least one modulator for modulating data into a carrier signal and preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmit chain may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. The transmit chain may also include one or more antennas 1110 for transmitting the amplified signal to air or a wireless medium.

[0174] A receiving chain may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, a receiving chain may include one or more antennas 1110 for receiving signals over air or a wireless medium. A receiving chain may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. A receiving chain may include at least one demodulator configured to demodulate the received signal and to obtain transmitted data by inverting the modulation technique applied during the transmission of the signal. A receiving chain may include at least one decoder for decoding the demodulated signal to receive transmitted data.

[0175] Figure 12 shows an example of a device 1200 supporting security updates for subsequent LTMs according to aspects of this disclosure. Device 1200 may be an example of a UE 104 as described herein. Device 1200 may support wireless communication with one or more network entities 102 (e.g., the first target base station 102-1 described above) or any combination thereof. Device 600 may include components for bidirectional communication, including components for transmitting and receiving communications, such as a processor 1202, memory 1204, transceiver 1206, and optionally an I / O controller 1208. These components may communicate electronically via one or more interfaces (e.g., buses) or otherwise be coupled (e.g., operably, communicatively, functionally, electronically, electrically).

[0176] The processor 1202, memory 1204, transceiver 1206, or various combinations thereof or various components thereof may be examples of means for carrying out various aspects of the disclosure described herein. For example, the processor 1202, memory 1204, transceiver 1206, or various combinations thereof or components thereof may support a method for carrying out one or more of the operations described herein.

[0177] In some implementations, the processor 1202, memory 1204, transceiver 1206, or various combinations or components thereof, may be implemented in hardware (for example, in a communication management circuit configuration). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which may be configured as means for performing the functions described herein or otherwise supporting such means. In some implementations, the processor 1202 and the memory 1204 coupled with the processor 1202 may be configured to perform one or more of the functions described herein (for example, the processor 1202 executes instructions stored in memory 604).

[0178] For example, the processor 1202 may support wireless communication in the device 1200 according to the examples disclosed herein. The processor 1202 may be configured to support means for receiving an NCC from a first target base station for the LTM to be used by the UE for key derivation for cell switching, and means for performing key derivation using the NCC to determine a first security key to be used between the UE and a second target base station for the LTM.

[0179] The processor 1202 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some implementations, the processor 1202 may be configured to operate a memory array using a memory controller. In some implementations, the memory controller may be integrated into the processor 1202. The processor 1202 may be configured to execute computer-readable instructions stored in memory (e.g., memory 1204) to cause device 1200 to perform various functions of this disclosure.

[0180] Memory 1204 may include random access memory (RAM) and read-only memory (ROM). Memory 1204 may store computer-readable computer-executable code, which, when executed by processor 1202, causes device 1200 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. In some implementations, the code may not be directly executable by processor 1202, but (for example, when compiled and executed) may cause the computer to perform the functions described herein. In some implementations, memory 1204 may include a basic input / output system (BIOS) that may control basic hardware or software operations, in particular, interactions with peripheral components or peripheral devices.

[0181] The I / O controller 1208 can manage input and output signals for device 1200. The I / O controller 1208 can also manage peripherals not integrated into device 1200. In some implementations, the I / O controller 1208 may represent physical connections or ports to external peripherals. In some implementations, the I / O controller 1208 may use an operating system such as iOS®, ANDROID®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. In some implementations, the I / O controller 1208 may be implemented as part of a processor, such as processor 1206. In some implementations, a user may interact with device 1200 via the I / O controller 1208 or via hardware components controlled by the I / O controller 1208.

[0182] In some implementations, device 1200 may include a single antenna 1210. However, in other implementations, device 1200 may have two or more antennas 1210 (e.g., multiple antennas) including multiple antenna panels or antenna arrays, and these antennas may be capable of simultaneously transmitting or receiving multiple wireless transmissions. Transceiver 1206 may communicate bidirectionally with one or more antennas 1210, wired or wireless links, as described herein. For example, transceiver 1206 may represent a wireless transceiver and communicate bidirectionally with another wireless transceiver. Transceiver 1206 may include a modem for modulating packets, feeding the modulated packets to one or more antennas 1210 for transmission, and demodulating packets received from one or more antennas 1210. Transceiver 1206 may include one or more transmit chains, one or more receive chains, or a combination thereof.

[0183] The transmit chain may be configured to generate and transmit signals (e.g., control information, data, packets). The transmit chain may include at least one modulator for modulating data into a carrier signal and preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmit chain may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. The transmit chain may also include one or more antennas 1210 for transmitting the amplified signal to air or a wireless medium.

[0184] A receiving chain may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, a receiving chain may include one or more antennas 1210 for receiving signals over air or a wireless medium. A receiving chain may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. A receiving chain may include at least one demodulator configured to demodulate the received signal and to obtain transmitted data by inverting the modulation technique applied during the transmission of the signal. A receiving chain may include at least one decoder for decoding the demodulated signal to receive transmitted data.

[0185] Figure 13 shows an example of a device 1300 supporting security updates for subsequent LTMs according to aspects of this disclosure. Device 1300 may be an example of a UE 104 as described herein. Device 1300 may support wireless communication with one or more network entities 102 (e.g., the first target base station 102-1 described above), a UE 104, or any combination thereof. Device 1300 may include components for bidirectional communication, including components for transmitting and receiving communications, such as a processor 1302, memory 1304, transceiver 1306, and optionally an I / O controller 1308. These components may communicate electronically via one or more interfaces (e.g., buses) or otherwise be coupled (e.g., operably, communicatively, functionally, electronically, electrically).

[0186] The processor 1302, memory 1304, transceiver 1306, or various combinations thereof or various components thereof may be examples of means for carrying out various aspects of the disclosure described herein. For example, the processor 1302, memory 1304, transceiver 1306, or various combinations thereof or components thereof may support a method for carrying out one or more of the operations described herein.

[0187] In some implementations, the processor 1302, memory 1304, transceiver 1306, or various combinations or components thereof, may be implemented in hardware (for example, in a communication management circuit). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, which may be configured as means for performing the functions described herein or otherwise supporting such means. In some implementations, the processor 1302 and the memory 1304 coupled with the processor 1302 may be configured to perform one or more of the functions described herein (for example, the processor 1302 executes instructions stored in the memory 1304).

[0188] For example, the processor 1302 may support wireless communication in the device 1300 according to the examples disclosed herein. The processor 1302 may be configured to operate to support means for receiving security update information from a first target base station for the LTM, and means for performing operations related to security updates for the LTM based on the security update information, wherein the security update information is associated with a first security key to be used between the UE and a second target base station for the LTM.

[0189] The processor 1302 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, microcontrollers, ASICs, FPGAs, programmable logic devices, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some implementations, the processor 1302 may be configured to operate a memory array using a memory controller. In some implementations, the memory controller may be integrated into the processor 1302. The processor 1302 may be configured to execute computer-readable instructions stored in memory (e.g., memory 1304) to cause device 1300 to perform various functions of this disclosure.

[0190] Memory 1304 may include random access memory (RAM) and read-only memory (ROM). Memory 1304 may store computer-readable computer-executable code, which, when executed by processor 1302, causes device 1300 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. In some implementations, the code may not be directly executable by processor 1302, but (for example, when compiled and executed) can cause the computer to perform the functions described herein. In some implementations, memory 1304 may include a basic input / output system (BIOS) that can control basic hardware or software operations, in particular, interactions with peripheral components or peripheral devices.

[0191] The I / O controller 1308 can manage input and output signals for device 1300. The I / O controller 1308 can also manage peripheral devices not integrated into device 1300. In some implementations, the I / O controller 1308 may represent physical connections or ports to external peripheral devices. In some implementations, the I / O controller 1308 may use an operating system such as iOS®, ANDROID®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. In some implementations, the I / O controller 1308 may be implemented as part of a processor, such as processor 1302. In some implementations, a user may interact with device 1300 via the I / O controller 1308 or via hardware components controlled by the I / O controller 1308.

[0192] In some implementations, device 1300 may include a single antenna 1310. However, in other implementations, device 1300 may have two or more antennas 1310 (e.g., multiple antennas), including multiple antenna panels or antenna arrays, and these antennas may be capable of simultaneously transmitting or receiving multiple wireless transmissions. Transceiver 1306 may communicate bidirectionally with one or more antennas 1310, wired or wireless links, as described herein. For example, transceiver 1306 may represent a wireless transceiver and communicate bidirectionally with another wireless transceiver. Transceiver 1306 may include a modem for modulating packets and providing the modulated packets to one or more antennas 1310 for transmission, and for demodulating packets received from one or more antennas 1310. Transceiver 1306 may include one or more transmit chains, one or more receive chains, or a combination thereof.

[0193] The transmit chain may be configured to generate and transmit signals (e.g., control information, data, packets). The transmit chain may include at least one modulator for modulating data into a carrier signal and preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmit chain may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. The transmit chain may also include one or more antennas 1310 for transmitting the amplified signal to air or a wireless medium.

[0194] The receiving chain may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiving chain may include one or more antennas 1310 for receiving signals over air or a wireless medium. The receiving chain may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiving chain may include at least one demodulator configured to demodulate the received signal and to obtain transmitted data by inverting the modulation technique applied during the transmission of the signal. The receiving chain may include at least one decoder for decoding the demodulated signal to receive transmitted data.

[0195] Figure 14 shows an example of a processor 1400 supporting security updates for subsequent LTMs according to aspects of this disclosure. The processor 1400 (including a first processor in the first target CU102-10 and a second processor in the first target DU102-11) may be an example of a processor configured to perform various operations according to the examples described herein. The processor 1400 may include a controller 1402 configured to perform various operations according to the examples described herein. The processor 1400 may optionally include at least one memory 1404, such as an L1 / L2 / L3 cache. Additionally or alternatively, the processor 1400 may optionally include one or more arithmetic logic units (ALUs) 1406. One or more of these components may communicate electronically via one or more interfaces (e.g., buses) or otherwise be coupled (e.g., operationally, communicatively, functionally, electronically, electrically).

[0196] The processor 1400 may be a processor chipset, which may include a protocol stack (e.g., a software stack) that is executed by the processor chipset to perform various operations as described herein (e.g., receive, acquire, retrieve, transmit, output, forward, store, decide, identify, access, write, read). The processor chipset may include one or more cores, one or more caches (e.g., the processor chipset (e.g., processor 1400) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc.)).

[0197] The controller 1402 may be configured to manage and coordinate various operations of the processor 1400 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, deciding, identifying, accessing, writing, and reading) so that the processor 1400 supports various base station operations as described herein. For example, the controller 1402 may act as a control unit for the processor 1400, generating control signals that manage the operation of various components of the processor 1400. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating the timing of operations.

[0198] The controller 1402 may be configured to fetch instructions from memory 1404 (e.g., acquire, retrieve, receive) and to determine subsequent instructions to be executed so that the processor 1400 can support various operations as illustrated herein. The controller 1402 may be configured to track the memory addresses of instructions associated with memory 1404. The controller 1402 may be configured to decode instructions to determine the operations to be performed and the operands involved. For example, the controller 1402 may be configured to translate instructions and to determine control signals to be output to other components of the processor 1400 so that the processor 1400 can support various operations as illustrated herein. Additionally or alternatively, the controller 1402 may be configured to manage the flow of data within the processor 1400. The controller 1402 may be configured to control the transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 1400.

[0199] Memory 1404 may include one or more caches (for example, memory local to or contained within the processor 1400), or other memory such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, or flash memory. In some implementations, memory 1404 may be located within or on the processor chipset (for example, locally to the processor 1400). In some other implementations, memory 1404 may be located outside the processor chipset (for example, remotely to the processor 1400).

[0200] Memory 1404 may store computer-readable computer-executable code, which, when executed by processor 1400, causes processor 1400 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. Controller 1402 and / or processor 1400 may be configured to execute computer-readable instructions stored in memory 1404 for causing processor 1400 to perform various functions. For example, processor 1400 and / or controller 1402 may be coupled to or with memory 1404, and processor 1400, controller 1402, and memory 1404 may be configured to perform various functions described herein. In some examples, processor 1400 may include multiple processors, and memory 1404 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, and they may be configured individually or collectively to perform various functions described herein.

[0201] One or more ALU1406s may be configured to support various operations as illustrated in the examples described herein. In some implementations, one or more ALU1406s may be located within or on a processor chipset (e.g., processor 1400). In some other implementations, one or more ALU1406s may be located outside the processor chipset (e.g., processor 1400). One or more ALU1406s may perform one or more operations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU1406s may receive input operands and operation codes, which determine the operation to be performed. One or more ALU1406s may consist of various logic and arithmetic circuits, including adders, subtractors, shifters, and logic gates, for processing and handling data according to the operations. As an addition or alternative, one or more ALU1406s may support logical operations such as AND, OR, exclusive OR (XOR), not-OR (NOR), and not-AND (NAND), enabling one or more ALU1406s to handle conditional operations, comparisons, and bitwise operations.

[0202] The processor 1400 may support wireless communication as illustrated herein. The processor 1400 may be configured to support, or be operable to support, means for determining a first security key to be used between the UE and a second target base station for the LTM, and a NCC to be used by the UE for key derivation for cell switching, and means for transmitting the NCC to the UE.

[0203] Figure 15 shows an example of a processor 1500 supporting security updates for subsequent LTMs according to aspects of this disclosure. The processor 1500 (including a first processor in the first target CU102-10 and a second processor in the first target DU102-11) may be an example of a processor configured to perform various operations according to the examples described herein. The processor 1500 may include a controller 1502 configured to perform various operations according to the examples described herein. The processor 1500 may optionally include at least one memory 1504, such as an L1 / L2 / L3 cache. Additionally or alternatively, the processor 1500 may optionally include one or more arithmetic logic units (ALUs) 1506. One or more of these components may communicate electronically via one or more interfaces (e.g., buses) or otherwise be coupled (e.g., operationally, communicatively, functionally, electronically, electrically).

[0204] The processor 1500 may be a processor chipset, which may include a protocol stack (e.g., a software stack) that is executed by the processor chipset to perform various operations as described herein (e.g., receive, acquire, retrieve, transmit, output, forward, store, decide, identify, access, write, read). The processor chipset may include one or more cores, one or more caches (e.g., the processor chipset (e.g., processor 1500) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc., which are local to or contained therein).

[0205] The controller 1502 may be configured to manage and coordinate various operations of the processor 1500 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, deciding, identifying, accessing, writing, and reading) so that the processor 1500 supports various base station operations as described herein. For example, the controller 1502 may act as a control unit for the processor 1500, generating control signals that manage the operation of various components of the processor 1500. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating the timing of operations.

[0206] The controller 1502 may be configured to fetch instructions from memory 1504 (e.g., acquire, retrieve, receive) and to determine subsequent instructions to be executed so that the processor 1500 can support various operations as illustrated herein. The controller 1502 may be configured to track the memory address of the instruction associated with memory 1504. The controller 1502 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1502 may be configured to translate instructions and to determine control signals to be output to other components of the processor 1500 so that the processor 1500 can support various operations as illustrated herein. Additionally or alternatively, the controller 1502 may be configured to manage the flow of data within the processor 1500. The controller 1502 may be configured to control the transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 1500.

[0207] Memory 1504 may include one or more caches (for example, memory local to or contained within the processor 1500), or other memory such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, or flash memory. In some implementations, memory 1504 may be located within or on the processor chipset (for example, locally to the processor 1500). In some other implementations, memory 1504 may be located outside the processor chipset (for example, remotely to the processor 1500).

[0208] Memory 1504 may store computer-readable computer-executable code, which, when executed by processor 1500, causes processor 1500 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. Controller 1502 and / or processor 1500 may be configured to execute computer-readable instructions stored in memory 1504 to cause processor 1500 to perform various functions. For example, processor 1500 and / or controller 1502 may be coupled to or with memory 1504, and processor 1500, controller 1502, and memory 1504 may be configured to perform various functions described herein. In some examples, processor 1500 may include multiple processors, and memory 1504 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, and they may be configured individually or collectively to perform various functions described herein.

[0209] One or more ALU1506 may be configured to support various operations as illustrated in the examples described herein. In some implementations, one or more ALU1506 may be located within or on a processor chipset (e.g., processor 1500). In some other implementations, one or more ALU1506 may be located outside the processor chipset (e.g., processor 1500). One or more ALU1506 may perform one or more operations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU1506 may receive input operands and operation codes, which determine the operation to be performed. One or more ALU1506 may consist of various logic and arithmetic circuits, including adders, subtractors, shifters, and logic gates, for processing and handling data according to the operations. As an addition or alternative, one or more ALU1506s may support logical operations such as AND, OR, exclusive OR (XOR), not-OR (NOR), and not-AND (NAND), enabling one or more ALU1506s to handle conditional operations, comparisons, and bitwise operations.

[0210] The processor 1500 may support wireless communication as illustrated herein. The processor 1500 may be configured or operable to support means for determining whether a security update is required for the LTM, and means for sending security update information to the UE based on the result of the determination, the security update information being associated with a first security key to be used between the UE and a second target base station for the LTM.

[0211] Figure 16 shows an example of a processor 1600 supporting security updates for subsequent LTMs according to aspects of this disclosure. The processor 1600 may be an example of a processor configured to perform various operations according to the examples described herein. The processor 1600 may include a controller 1602 configured to perform various operations according to the examples described herein. The processor 1600 may optionally include at least one memory 1604, such as an L1 / L2 / L3 cache. Additionally or alternatively, the processor 1600 may optionally include one or more arithmetic logic units (ALUs) 1606. One or more of these components may communicate electronically via one or more interfaces (e.g., buses) or otherwise be coupled (e.g., operationally, communicatively, functionally, electronically, electrically).

[0212] The processor 1600 may be a processor chipset, which may include a protocol stack (e.g., a software stack) that is executed by the processor chipset to perform various operations as described herein (e.g., receive, acquire, retrieve, transmit, output, forward, store, decide, identify, access, write, read). The processor chipset may include one or more cores, one or more caches (e.g., the processor chipset (e.g., processor 1600) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc., which are local to or contained therein).

[0213] The controller 1602 may be configured to manage and coordinate various operations of the processor 1600 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, deciding, identifying, accessing, writing, and reading) so that the processor 1600 supports various base station operations as described herein. For example, the controller 1602 may act as a control unit for the processor 1600 and generate control signals that manage the operation of various components of the processor 1600. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating the timing of operations.

[0214] The controller 1602 may be configured to fetch instructions from memory 1604 (e.g., acquire, retrieve, receive) and to determine subsequent instructions to be executed so that the processor 1600 can support various operations as illustrated herein. The controller 1602 may be configured to track the memory addresses of instructions associated with memory 1604. The controller 1602 may be configured to decode instructions to determine the operations to be performed and the operands involved. For example, the controller 1602 may be configured to translate instructions and to determine control signals to be output to other components of the processor 1600 so that the processor 1600 can support various operations as illustrated herein. Additionally or alternatively, the controller 1602 may be configured to manage the flow of data within the processor 1600. The controller 1602 may be configured to control the transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 1600.

[0215] Memory 1604 may include one or more caches (for example, memory local to or contained within the processor 1600), or other memory such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, or flash memory. In some implementations, memory 1604 may be located within or on the processor chipset (for example, locally to the processor 1600). In some other implementations, memory 1604 may be located outside the processor chipset (for example, remotely to the processor 1600).

[0216] Memory 1604 may store computer-readable computer-executable code, which, when executed by processor 1600, causes processor 1600 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. Controller 1602 and / or processor 1600 may be configured to execute computer-readable instructions stored in memory 1604 for causing processor 1600 to perform various functions. For example, processor 1600 and / or controller 1602 may be coupled to or with memory 1604, and processor 1600, controller 1602, and memory 1604 may be configured to perform various functions described herein. In some examples, processor 1600 may include multiple processors, and memory 1604 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, and they may be configured individually or collectively to perform various functions described herein.

[0217] One or more ALU1606s may be configured to support various operations as illustrated in the examples described herein. In some implementations, one or more ALU1606s may be located within or on a processor chipset (e.g., processor 1600). In some other implementations, one or more ALU1606s may be located outside the processor chipset (e.g., processor 1600). One or more ALU1606s may perform one or more operations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU1606s may receive input operands and operation codes, which determine the operation to be performed. One or more ALU1606s may consist of various logic and arithmetic circuits, including adders, subtractors, shifters, and logic gates, for processing and handling data according to the operations. As an addition or alternative, one or more ALU1606s may support logical operations such as AND, OR, exclusive OR (XOR), not-OR (NOR), and not-AND (NAND), enabling one or more ALU1606s to handle conditional operations, comparisons, and bitwise operations.

[0218] The processor 1600 may support wireless communication as illustrated herein. The processor 1600 may be configured or operable to support means for receiving an NCC from a first target base station for the LTM to be used by the UE for key derivation for cell switching, and means for performing key derivation using the NCC to determine a first security key to be used between the UE and a second target base station for the LTM.

[0219] Figure 17 shows an example of a processor 1700 supporting security updates for subsequent LTMs according to aspects of this disclosure. The processor 1700 may be an example of a processor configured to perform various operations according to the examples described herein. The processor 1700 may include a controller 1702 configured to perform various operations according to the examples described herein. The processor 1700 may optionally include at least one memory 1704, such as an L1 / L2 / L3 cache. Additionally or alternatively, the processor 1700 may optionally include one or more arithmetic logic units (ALUs) 1706. One or more of these components may communicate electronically via one or more interfaces (e.g., buses) or otherwise be coupled (e.g., operationally, communicatively, functionally, electronically, electrically).

[0220] The processor 1700 may be a processor chipset, which may include a protocol stack (e.g., a software stack) that is executed by the processor chipset to perform various operations as described herein (e.g., receive, acquire, retrieve, transmit, output, forward, store, decide, identify, access, write, read). The processor chipset may include one or more cores, one or more caches (e.g., the processor chipset (e.g., processor 1700) or other memory (e.g., memory that is local to or contained in random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc.).

[0221] The controller 1702 may be configured to manage and coordinate various operations of the processor 1700 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, deciding, identifying, accessing, writing, and reading) so that the processor 1700 supports various base station operations as described herein. For example, the controller 1702 may act as a control unit for the processor 1700, generating control signals that manage the operation of various components of the processor 1700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating the timing of operations.

[0222] The controller 1702 may be configured to fetch instructions from memory 1704 (e.g., acquire, retrieve, receive) and to determine subsequent instructions to be executed so that the processor 1700 can support various operations as illustrated herein. The controller 1702 may be configured to track the memory addresses of instructions associated with memory 1704. The controller 1702 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1702 may be configured to translate instructions and to determine control signals to be output to other components of the processor 1700 so that the processor 1700 can support various operations as illustrated herein. Additionally or alternatively, the controller 1702 may be configured to manage the flow of data within the processor 1700. The controller 1702 may be configured to control the transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 1700.

[0223] Memory 1704 may include one or more caches (for example, memory local to or contained within the processor 1700), or other memory such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, or flash memory. In some implementations, memory 1704 may be located within or on the processor chipset (for example, locally to the processor 1700). In some other implementations, memory 1704 may be located outside the processor chipset (for example, remotely to the processor 1700).

[0224] Memory 1704 may store computer-readable computer-executable code, which, when executed by processor 1700, causes processor 1700 to perform various functions described herein. The code may be stored in a non-temporary computer-readable medium, such as system memory or another type of memory. Controller 1702 and / or processor 1700 may be configured to execute computer-readable instructions stored in memory 1704 to cause processor 1700 to perform various functions. For example, processor 1700 and / or controller 1702 may be coupled to or with memory 1704, and processor 1700, controller 1702, and memory 1704 may be configured to perform various functions described herein. In some examples, processor 1700 may include multiple processors, and memory 1704 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, and they may be configured individually or collectively to perform various functions described herein.

[0225] One or more ALU1706 may be configured to support various operations as illustrated in the examples described herein. In some implementations, one or more ALU1706 may be located within or on a processor chipset (e.g., processor 1700). In some other implementations, one or more ALU1706 may be located outside the processor chipset (e.g., processor 1700). One or more ALU1706 may perform one or more operations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU1706 may receive input operands and operation codes, which determine the operation to be performed. One or more ALU1706 may consist of various logic and arithmetic circuits, including adders, subtractors, shifters, and logic gates, for processing and handling data according to the operations. As an addition or alternative, one or more ALU1706s may support logical operations such as AND, OR, exclusive OR (XOR), not-OR (NOR), and not-AND (NAND), enabling one or more ALU1706s to handle conditional operations, comparisons, and bitwise operations.

[0226] The processor 1700 may support wireless communication as illustrated herein. The processor 1700 may be configured or operable to support means for receiving security update information from a first target base station for the LTM and means for performing operations related to security updates for the LTM based on the security update information, the security update information being associated with a first security key to be used between the UE and a second target base station for the LTM.

[0227] Figure 18 shows a flowchart of method 1800 supporting security updates for subsequent LTMs according to an aspect of this disclosure. The operation of method 1800 may be carried out by a device or its components, as described herein. For example, the operation of method 1800 may be carried out by a first target base station 102-1, as described herein. In some implementations, the device may execute a set of instructions for controlling the functional elements of the device to perform the functions described. In addition or alternatively, the device may use dedicated hardware to perform aspects of the functions described.

[0228] In 1805, the method may include the step of determining a first security key to be used between UE104 and the second target base station 102-2 for LTM, and an NCC to be used for key derivation for cell switching by UE104. The operation of 1805 may be carried out according to the examples described herein. In some implementations, the mode of operation of 2005 may be carried out by the device described with reference to Figure 1.

[0229] In 1810, the method may include the step of sending the NCC to UE104. The operation of 1810 may be carried out according to the examples described herein. In some implementations, the operation of 2010 may be carried out by the device described with reference to Figure 1.

[0230] Figure 19 shows a flowchart of Method 1900 supporting security updates for subsequent LTMs according to an aspect of this disclosure. The operation of Method 1900 may be carried out by a device or its components, as described herein. For example, the operation of Method 1900 may be carried out by a first target base station 102-1, as described herein. In some implementations, the device may execute a set of instructions for controlling the functional elements of the device to perform the functions described. In addition or alternatively, the device may use dedicated hardware to perform aspects of the functions described.

[0231] In 1905, the method may include a step of determining whether a security update for LTM is required. The operation of 1905 may be carried out according to the examples described herein. In some implementations, the operation of 1905 may be carried out by the device described with reference to Figure 1.

[0232] In 1910, the method may include the step of sending security update information to UE104 based on the result of the determination, the security update information being associated with a first security key to be used between UE104 and the second target base station 102-2 for LTM. The operation of 1910 may be carried out according to the examples described herein. In some implementations, the operation of 1910 may be carried out by the device described with reference to Figure 1.

[0233] Figure 20 shows a flowchart of Method 2000 supporting security updates for subsequent LTMs according to an aspect of this disclosure. The operation of Method 2000 may be carried out by a device or its components, as described herein. For example, the operation of Method 2000 may be carried out by UE104, as described herein. In some implementations, the device may execute a set of instructions for controlling the functional elements of the device to perform the described functions. Additionally or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0234] In 2005, the method may include the step of receiving an NCC from a first target base station 102-1 for LTM to be used for key derivation for cell switching by UE 104. The operation of 2205 may be carried out according to the examples described herein. In some implementations, the operation of 2205 may be carried out by the device described with reference to Figure 1.

[0235] In 2010, the method may include the step of performing key derivation by using NCC to determine a first security key to be used between UE104 and the second target base station 102-2 for LTM. The operation of 2010 may be carried out according to the examples described herein. In some implementations, the mode of operation of 2010 may be carried out by the device described with reference to Figure 1.

[0236] Figure 21 shows a flowchart of method 2100 supporting security updates for subsequent LTMs according to an aspect of this disclosure. The operation of method 2100 may be carried out by a device or its components, as described herein. For example, the operation of method 2100 may be carried out by UE104, as described herein. In some implementations, the device may execute a set of instructions to control the functional elements of the device to perform the described functions. Additionally or alternatively, the device may use dedicated hardware to perform aspects of the described functions.

[0237] In 2105, the method may include the step of receiving security update information from a first target base station 102-1 for LTM. The operation of 2105 may be carried out according to the examples described herein. In some implementations, the operation of 2105 may be carried out by the device described with reference to Figure 1.

[0238] In 2110, the method may include the step of performing an action related to a security update for the LTM based on security update information, wherein the security update information is associated with a first security key to be used between UE 104 and a second target base station 102-2 for the LTM. The operation of 2110 may be performed according to the examples described herein. In some implementations, the actions of 2110 may be performed by the device described with reference to Figure 1.

[0239] It should be noted that the methods described herein represent possible implementations, that the operations and steps may be rearranged or possibly modified, and that other implementations are possible. Furthermore, two or more embodiments of these methods may be combined.

[0240] The various exemplary blocks and components described in this disclosure may be implemented or carried out using general-purpose processors, DSPs, ASICs, CPUs, FPGAs or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but alternatively, the processor may be any processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors working with a DSP core, or any other such configuration).

[0241] The functions described herein may be implemented in hardware, software executed by a processor, firmware, or a combination thereof. When implemented in software executed by a processor, the functions may be stored in or transmitted through a computer-readable medium as one or more instructions or codes. Other examples and implementations fall within the scope of this disclosure and the accompanying claims. For example, due to the nature of the software, the functions described herein may be implemented using software executed by a processor, hardware, firmware, hardwiring, or a combination thereof. The features implementing the functions may also be physically located in various locations, including the distribution of parts of the functions so that they are implemented in various physical locations.

[0242] Computer-readable media include both non-temporary computer storage media and communication media, including any media that facilitate the transfer of computer programs from one location to another. Non-temporary storage media can be any available media that can be accessed by a general-purpose or dedicated computer. For example, non-temporary computer-readable media may include RAM, ROM, electrically erasable programmable ROM (EEPROM), flash memory, compact disk (CD) ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other non-temporary media that can be used to carry or store desired program code means in the form of instructions or data structures, and can be accessed by a general-purpose or dedicated computer or a general-purpose or dedicated processor.

[0243] As used herein, including in the claims, the article “a” preceding an element is unrestricted and is understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” used in a list of items (for example, a list of items ending with a phrase such as “at least one of,” “one or more of,” or “one or both of”) indicates an inclusive list, for example, such that a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” should not be interpreted as a reference to a closed set of conditions. For example, an exemplary step described as “based on condition A” may be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase “based on” should be construed in the same way as the phrase “at least partially based on.” Furthermore, as used herein, including in the claims, “set” may include one or more elements.

[0244] The descriptions herein are provided to enable those skilled in the art to create or use this disclosure. Various modifications of this disclosure will become apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of this disclosure. Accordingly, this disclosure should be given the broadest scope that is consistent with the principles and novel features disclosed herein, and is not limited to the examples and designs described herein. [Explanation of Symbols]

[0245] 100 Wireless Communication Systems 102 Network Entities 102-1 First Target Base Station 102-10 First Target CU 102-11 First Target DU 102-2 Second Target Base Station 102-20 Second Target CU 103 AMF 104 UE 106 Core Network 108 Packet Data Network 110 Communication Link 112 Geographic Coverage Area 114 Communication Link 116 Backhaul Link 118 Application Server 160 CU 1000 Device 1002 Processor 1004 Memory 1006 Transceiver 1008 I / O Controller 1010 Antenna 1100 Device 1102 Processor 1104 Memory 1106 Transceiver 1108 I / O Controller 1110 Antenna 1200 Device 1202 Processor 1204 Memory 1206 Transceiver 1208 I / O Controller 1210 Antenna 1300 Device 1302 Processor 1304 Memory 1306 Transceiver 1308 I / O Controller 1310 Antenna 1400 Processor 1402 Controller 1404 Memory 1402 Controller 1404 Memory 1406 Arithmetic Logic Unit (ALU) 1500 processors 1502 Controller 1504 memory 1506 Arithmetic Logic Unit (ALU) 1600 processor 1602 Controller 1604 memory 1606 Arithmetic Logic Unit (ALU) 1700 Processor 1702 Controller 1704 memory

Claims

1. Processor and A transceiver coupled to the aforementioned processor and A base station equipped with, The aforementioned base station is a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), and the processor is Determining a first security key to be used between the user equipment (UE) and the second target base station for the LTM, and a next-hop (NH) chaining counter (NCC) to be used by the UE for key derivation for cell switching, To transmit the NCC to the UE via the transceiver. A base station configured to perform the following actions.

2. The aforementioned processor, The base station according to claim 1, further configured to transmit the first security key and the NCC to the second target base station via the transceiver.

3. The base station according to claim 2, wherein the first target base station includes a first target central unit (CU) and one or more distributed units (DUs), the one or more DUs including a first target DU that serves the UE.

4. The processor further includes a second processor of the first target DU, the second processor is The base station according to claim 3, configured to transmit the NCC received from the first target CU to the UE via the transceiver, thereby the NCC being used by the UE to perform a second security key derivation to determine a second security key to be used between the UE and the second target base station.

5. The aforementioned second processor is The base station according to claim 4, further configured to transmit a second indicator to the UE via the transceiver indicating whether a security update is required during the cell switch to the target cell, the second indicator being determined by the first target DU based on the first indicator.

6. The second indicator is, A security update indicator that shows whether a security update is required. A CU indicator that shows that the CU of the target cell is different from the first target CU, A CU-to-CU LTM indicator that indicates the cell switch is associated with CU-to-CU LTM, and CU node identifier (ID) indicating the ID of the target cell's CU, The base station according to claim 5, comprising one of the following.

7. The base station according to claim 1, wherein the NCC is transmitted from the first target base station to the UE by a media access control (MAC) control element (CE).

8. The base station according to claim 7, wherein the MAC CE is an LTM cell switch command.

9. The aforementioned second processor is The base station according to claim 4, further configured to receive a first security update failure message indicating a security update failure via the transceiver and from the UE.

10. A method implemented by a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM), The steps include determining a first security key to be used between the user equipment (UE) and a second target base station for the LTM, and a next-hop (NH) chaining counter (NCC) to be used by the UE for key derivation for cell switching, The steps include sending the aforementioned NCC to the aforementioned UE and Methods that include...

11. Processor and A transceiver coupled to the aforementioned processor and User equipment (UE) equipped with, The aforementioned processor, The UE receives a next-hop (NH) chaining counter (NCC) via the transceiver and from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM) to be used for key derivation for cell switching, By using the aforementioned NCC, key derivation is performed to determine the first security key to be used between the UE and the second target base station for the LTM. A UE configured to perform the following actions.

12. The aforementioned key derivation is, If the value of the NCC is equal to the value of the current NCC associated with the current security key used by the first target base station and the UE, calculate the security key from the current security key, or If the value of the NCC differs from the current value of the NCC, the locally stored NH parameters are repeatedly synchronized and the current value of the NCC is incremented, and if the current value of the NCC matches the value of the NCC received from the first target base station, the security key is calculated from the synchronized NH parameters. The UE according to claim 11, including the UE described in claim 11.

13. The aforementioned processor, Receiving an indicator via the transceiver and from the first target base station indicating whether a security update is required during cell switching to the target cell, If the indicator indicates that the aforementioned security update is required, the key derivation shall be performed. The UE according to claim 11, further configured to perform the following:

14. The aforementioned indicator is A security update indicator that shows whether the aforementioned security update is required, A CU indicator indicating that the CU of the target cell is different from the CU of the first target base station, A CU-to-CU LTM indicator that indicates the cell switch is associated with CU-to-CU LTM, and The CU node identifier (ID) indicating the ID of the CU of the target cell, The UE according to claim 13, comprising one of the following.

15. The UE according to claim 11, wherein the NCC is received by the UE from the first target base station by a media access control (MAC) control element (CE).

16. The UE according to claim 15, wherein the MAC CE is an LTM cell switch command.

17. The aforementioned processor, The UE according to claim 13, further configured to transmit a first security update failure message indicating the failure of the security update via the transceiver and to the first target base station.

18. The aforementioned processor, Receiving information about security update parameters issued by the Access and Mobility Management Function (AMF) via the transceiver and from the first target base station, Based on the information regarding the security update parameters, update the NH parameter associated with the first security key. The UE according to claim 11, further configured to perform the following:

19. The UE according to claim 18, wherein the information regarding security update parameters indicates that a NAS security context different from the currently active non-accessible layer (NAS) security context is activated by the AMF.

20. A method performed by user equipment (UE), The steps include receiving a next-hop (NH) chaining counter (NCC) from a first target base station for Layer 1 / Layer 2 (L1 / L2) triggered mobility (LTM) to be used for key derivation for cell switching by the UE, The steps include: performing key derivation using the NCC to determine a first security key to be used between the UE and the second target base station for the LTM; Methods that include...