User equipment, RAN node, user equipment method and RAN node method

The method addresses the challenge of determining security keys for subsequent conditional cell changes in MR-DC by using distinct counter values, enhancing security and efficiency in wireless networks.

JP7740569B2Active Publication Date: 2025-09-17NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024548542
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-17
Publication Date
2025-09-17
Estimated Expiration
2042-02-17

AI Technical Summary

Technical Problem

Existing Multi-Random access technology Dual Connectivity with Selective Activation of Cell Groups (MR-DC) in 3GPP Release 17 requires a single security key for subsequent conditional Primary Secondary Cell (PSCell) changes, leading to unclear security key determination for subsequent Conditional PSCell Addition (CPC) procedures, which can result in inefficient signaling and increased interruption time.

Method used

A method for determining a different security key for subsequent conditional cell changes by using a distinct counter value for each subsequent Conditional PSCell change, allowing flexible and efficient key management through incremental counter value updates or pre-configured sets of keys.

Benefits of technology

Enables secure and efficient subsequent conditional cell changes by ensuring unique security keys for each change, reducing signaling overhead and minimizing interruption time in wireless communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007740569000001
    Figure 0007740569000001
  • Figure 0007740569000002
    Figure 0007740569000002
  • Figure 0007740569000003
    Figure 0007740569000003
Patent Text Reader

Abstract

The embodiments of the present disclosure relate to a method, an apparatus, and a computer-readable medium for communication. A terminal device receives a conditional reconfiguration from a first network device, indicating that a subsequent conditional cell change is enabled. If the subsequent conditional cell change to a candidate cell is performed after a cell change or addition is performed, the terminal device determines a first counter value, the first counter value being different from a second counter value used for the cell change or addition, and determines a security key for communication with a second network device providing the candidate cell based on the first counter value. Thus, a security key is determined for the subsequent conditional cell change.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] FIELD Embodiments of the present disclosure relate generally to the field of telecommunications, and more particularly to a communication method, apparatus, and computer storage medium for subsequent conditional cell changes. [Background technology]

[0002] Currently, Multi-Random access technology Dual Connectivity with Selective Activation of Cell Groups (MR-DC) aims to enable subsequent conditional Primary Secondary Cell (PSCell) change (CPC) after Secondary Cell Group (SCG) change without reconfiguration and reinitialization during CPC / Conditional PSCell Addition (CPA) preparation from the network side, thereby reducing signaling overhead and interruption time for SCG change.

[0003] When subsequent CPC is enabled, the terminal device may perform CPC multiple times using the same Radio Resource Control (RRC) reconfiguration. However, in the CPC / CPA procedure of 3GPP (3rd Generation Partnership Project) Release 17, RRC reconfiguration is applied only once, and therefore, a secondary node (SN) counter configured in the RRC reconfiguration is used only once to generate a security key for the CPC / CPA procedure. Therefore, it is necessary to address how to determine a security key for a subsequent CPC after the CPC / CPA procedure. Summary of the Invention [Problem to be solved by the invention]

[0004] Generally, the exemplary embodiments of the present disclosure provide a communication method, apparatus, and computer storage medium for subsequent conditional cell changes. [Means for solving the problem]

[0005] In a first aspect, a method of communication is provided, the method including: receiving, in a terminal device, from a first network device, a conditional reconfiguration for a set of candidate cells, the conditional reconfiguration including information indicating that a subsequent conditional cell change is enabled; determining a first counter value according to a determination that the subsequent conditional cell change to a candidate cell in the set of candidate cells will be performed after a cell change or addition is performed, the first counter value being different from a second counter value used for the cell change or addition; and determining a security key for communication with a second network device that serves the candidate cell based on the first counter value.

[0006] In a second aspect, a method of communication is provided, the method including: determining, in a first network device, a set of security keys based on a set of first counter values ​​to be used for a subsequent conditional cell change to a candidate cell in the set of candidate cells after a cell change or addition is performed, the set of first counter values ​​being different from a second counter value used for the cell change or addition; and transmitting the set of security keys to the second network device providing the candidate cell for communication between a terminal device and a second network device.

[0007] In a third aspect, there is provided a method of communication, the method including: receiving, in a second network device, a set of security keys from a first network device; and performing communication between a terminal device and the second network device providing a candidate cell based on security keys in the set of security keys, wherein a subsequent conditional cell change to the candidate cell is performed after a cell change or add is performed, and the security keys are different from previous security keys used for the cell change or add.

[0008] In a fourth aspect, there is provided a method of communication, the method including: receiving, in a terminal device, from a first network device, a conditional reconfiguration for a set of candidate cells, the conditional reconfiguration including information indicating that a subsequent conditional cell change is enabled; and applying the conditional reconfiguration for a second network device providing the candidate cell according to a determination that the subsequent conditional cell change to a candidate cell in the set of candidate cells is performed after a cell change or addition is performed, wherein a security key used for the cell change or addition is the same as a security key used for the subsequent conditional cell change.

[0009] In a fifth aspect, there is provided a method of communication, the method comprising: sending, at a first network device, to a terminal device, a conditional reconfiguration for a set of candidate cells such that a security key used for a cell change or add is the same as a security key used for a subsequent conditional cell change made after the cell change or add is performed.

[0010] In a sixth aspect, there is provided a terminal device, the terminal device comprising a processor configured to cause the terminal device to execute a method according to the first or fourth aspect of the present disclosure.

[0011] In a seventh aspect, there is provided a network device, comprising a processor configured to cause the network device to perform a method according to any one of the second, third and fifth aspects of the present disclosure.

[0012] In an eighth aspect, there is provided a computer-readable medium storing instructions that, when executed on at least one processor, cause the at least one processor to perform a method according to the first or fourth aspect of the present disclosure.

[0013] In a ninth aspect, there is provided a computer-readable medium having stored thereon instructions that, when executed on at least one processor, cause the at least one processor to perform a method according to any one of the second, third and fifth aspects of the present disclosure.

[0014] Other features of the present disclosure will be readily apparent from the following description. [Brief explanation of the drawings]

[0015] The above and other objects, features and advantages of the present disclosure will become more apparent from the following detailed description of several embodiments of the present disclosure in the accompanying drawings.

[0016] [Figure 1A] FIG. 1 illustrates an exemplary communication network in which some embodiments of the present disclosure may be implemented.

[0017] [Figure 1B] 1 is a schematic diagram illustrating network protocol layer entities that may be established for a User Plane (UP) protocol stack in an apparatus according to some embodiments of the present disclosure. FIG.

[0018] [Figure 1C]1 is a schematic diagram illustrating network protocol layer entities that may be established for a control plane (CP) protocol stack in an apparatus according to some embodiments of the present disclosure.

[0019] [Figure 2] FIG. 1 is a schematic diagram illustrating an exemplary process for determining security keys for a subsequent CPC, according to an embodiment of the present disclosure.

[0020] [Figure 3] FIG. 10 is a schematic diagram illustrating another exemplary process for determining security keys for a subsequent CPC, according to an embodiment of the present disclosure.

[0021] [Figure 4] FIG. 1 illustrates an exemplary communication method implemented in a terminal device, according to some embodiments of the present disclosure.

[0022] [Figure 5] FIG. 2 illustrates an exemplary communication method implemented in a first network device, according to some embodiments of the present disclosure.

[0023] [Figure 6] FIG. 10 illustrates an exemplary communication method implemented in a second network device, according to some embodiments of the present disclosure.

[0024] [Figure 7] FIG. 10 illustrates another exemplary communication method implemented in a terminal device, according to some embodiments of the present disclosure.

[0025] [Figure 8] FIG. 10 illustrates another exemplary communication method implemented in a first network device, according to some embodiments of the present disclosure.

[0026] [Figure 9]FIG. 1 is a schematic block diagram of an apparatus suitable for implementing embodiments of the present disclosure.

[0027] In the drawings, the same or similar reference numbers represent the same or similar elements. DETAILED DESCRIPTION OF THE INVENTION

[0028] The principles of the present disclosure will now be described with reference to some embodiments. It should be understood that these embodiments are provided for illustrative purposes only to assist those skilled in the art in understanding and practicing the present disclosure, and do not imply any limitation on the scope of the present disclosure. The disclosure described herein can be implemented in various ways different from those described below.

[0029] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0030] As used herein, the term "terminal device" refers to any device with wireless or wired communication capabilities. Examples of terminal devices include User Equipment (UE), personal computers, desktops, mobile phones, cellular phones, smartphones, personal digital assistants (PDAs), portable computers, tablets, wearable devices, Internet of Things (IoT) devices, Ultra-Reliable and Low Latency Communications (URLLC) devices, Internet of Everything (IoE) devices, Machine Type Communication (MTC) devices, in-vehicle devices for V2X communications where X means pedestrian, vehicle, or infrastructure / network, devices for Integrated Access and Integrated Access and Backhaul (IAB), Small Data Transmission (SDT), Multicast and Broadcast Services (MBS), positioning, dynamic / flexible duplication in commercial networks, reduced capability (RedCap), High Altitude Platforms (HAP) including satellites and Unmanned Aircraft Systems (UAS). These include satellite-based vehicles or airborne vehicles within a non-terrestrial network (NTN) including a satellite-based platform (SAT), extended reality (XR) devices that include different types of reality such as augmented reality (AR), mixed reality (MR), and virtual reality (VR), unmanned aerial vehicles (UAVs), which are aircraft without a human pilot and are commonly referred to as drones, and high-speed trains (HSTs).This includes, but is not limited to, devices on a mobile network (UE), image capture devices such as digital cameras, sensor gaming devices, music storage and playback devices, or internet appliances that enable wireless or wired internet access and browsing. A "terminal device" may also have "multicast / broadcast" capabilities to support public safety and mission-critical V2X applications, transparent IPv4 / IPv6 multicast distribution, IPTV, smart TV, wireless services, over-the-air software distribution, group communications, and IoT applications. It may also incorporate one or more subscriber identity modules (SIMs), known as multi-SIMs. The term "terminal device" may be used interchangeably with UE, mobile station, subscriber station, mobile terminal, user terminal, or wireless device.

[0031] The term "network device" refers to a device that can provide or host a cell or coverage area over which terminal devices can communicate. Examples of network devices include, but are not limited to, a Node B (Node B or NB), an evolved Node B (eNode B or eNB), a next generation Node B (gNB), a transmit / receive point (TRP), a remote radio unit (RRU), a radio head (RH), a remote radio head (RRH), an IAB node, a femto node, a pico node, a reconfigurable intelligent surface (RIS), a low-power node such as a network-controlled repeater, etc.

[0032] The terminal device or network device may have artificial intelligence (AI) or machine learning capabilities, which generally include a model trained from a large amount of data collected for a specific function and can be used to predict some information.

[0033] The terminal device or network device may operate on several frequency ranges, such as FR1 (410 MHz to 7125 MHz), FR2 (24.25 GHz to 71 GHz), frequency bands greater than 100 GHz, and Terahertz (THz). It can also operate on licensed, unlicensed, and shared spectrum. The terminal device may have two or more connections with the network device under a Multi-Radio Dual Connectivity (MR-DC) application scenario. The terminal device or network device can operate in full duplex, flexible duplex, and cross-division duplex modes.

[0034] The network device may have a function of network energy saving, self-organizing networks (SON) / minimization of drive test (MDT). The terminal may have a function of power saving.

[0035] Embodiments of the present disclosure may be implemented in test equipment, such as, for example, a signal generator, a signal analyzer, a spectrum analyzer, a network analyzer, a test terminal device, a test network device, a channel emulator, and the like.

[0036] In one embodiment, a terminal device can connect to a first network device and a second network device. One of the first network device and the second network device may be a master node and the other a secondary node. The first network device and the second network device may use different radio access technologies (RATs). In one embodiment, the first network device may be a first RAT device, and the second network device may be a second RAT device. In one embodiment, the first RAT device is an eNB, and the second RAT device is a gNB. Information related to the different RATs may be transmitted to the terminal device from at least one of the first network device and the second network device. In one embodiment, the first information may be transmitted from the first network device to the terminal device, and the second information may be transmitted from the second network device directly or via the first network device to the terminal device. In one embodiment, information related to the terminal device configuration configured by the second network device may be transmitted from the second network device via the first network device. The information regarding the reconfiguration of the terminal device configured by the second network device may be transmitted to the terminal device directly from the second network device or via the first network device.

[0037] As used herein, the singular forms "a," "an," and "said" include the plural forms unless the context clearly indicates otherwise. The term "comprises" and variations thereof should be understood as open-ended terms meaning "including, but not limited to." The term "based on" should be understood as "based at least in part on." The terms "one embodiment" and "embodiment" should be understood as "at least one embodiment." The term "another embodiment" should be understood as "at least one other embodiment." Terms such as "first," "second," etc. may refer to different or the same object. The following may include other explicit and implicit definitions.

[0038] In some instances, values, procedures, or devices are referred to as "best," "lowest," "highest," "minimum," "maximum," etc. It should be understood that such descriptions are intended to illustrate that choices may be made from among many functional alternatives used, and that such choices are not necessarily better, smaller, higher, or otherwise more preferred than other choices.

[0039] In this application, the term "cell change or addition" may be used interchangeably with "reconfigurationWithSync for an SCG or Master Cell Group (MCG)." In the context of this application, the term "PCell" refers to an SpCell of an SCG, and the term "PCell" refers to an SpCell of an MCG, and "SpCell" refers to a primary cell of an SCG or MCG.

[0040] As described above, there is a need to address how to determine a security key for a subsequent CPC after a CPC / CPA procedure. In view of this, an embodiment of the present disclosure provides a solution for determining a security key for a conditional cell change after a cell change or addition. In one aspect, when a subsequent conditional cell change is performed after a cell change or addition is performed, a counter value different from the counter value used for the cell change or addition is determined. Based on the determined counter value, a security key is determined for the subsequent conditional cell change. In this way, security key changes are supported for subsequent conditional cell changes.

[0041] In another aspect, when a subsequent conditional cell change is performed after a cell change or add is performed, the same counter value as that used for the cell change or add is determined. Based on the determined counter value, a security key is determined for the subsequent conditional cell change. Thus, a security key change is not required for the subsequent conditional cell change.

[0042] It should be understood that this solution may be applied to an SCG change or an MCG change. That is, this solution may also be applied to a subsequent CPC or a subsequent conditional handover. A subsequent CPC or a subsequent conditional handover may also be referred to as a selective activation of a cell group, a selective activation of an SCG, a subsequent SCG change, a subsequent cell group change, or a subsequent conditional cell change. For convenience, an embodiment of the present disclosure will be described using a subsequent CPC as an example.

[0043] The principles and embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Example of a communication network

[0044] 1A is a schematic diagram of an exemplary communication network 100A in which embodiments of the present disclosure can be implemented. As shown in FIG. 1A, communication network 100A may include a network device 110 and a terminal device 120. Network device 110 provides a cell 111, and terminal device 120 is located within cell 111 and served by network device 110.

[0045] The communication network 100A may also include one or more other network devices, such as network devices 130, 140, and 150. The network device 130 provides cells 131, 132, and 133. The network device 140 provides cells 141, 142, and 143, and the network device 150 provides cells 151, 152, and 153. Note that the number of cells is not limited to three, and the number of terminal devices may be any number. 120 Therefore, more or fewer cells may be configured.

[0046] Assume that the terminal device 120 is capable of establishing a dual connection (i.e., simultaneous connection) with two network devices. For example, the network device 110 may function as an MN (hereinafter, for convenience, also referred to as an MN 110), and the network device 130 may function as an SN (hereinafter, for convenience, also referred to as an SN 130). Although only cell 111 is shown, the MN 110 may provide multiple cells, and these cells may form an MCG for the terminal device 120. Assume that the cell 111 is a primary cell (i.e., a PCell) in the MCG. Furthermore, cells 131, 132, and 133 provided by the network device 130 may form an SCG for the terminal device 120. Assume that the cell 131 is a primary cell (i.e., a PSCell) in the SCG.

[0047] The SN 130 may communicate with the terminal device 120 over a channel such as a wireless communication channel. Similarly, the MN 110 may communicate with the terminal device 120 over a channel such as a wireless communication channel. The SN 130 may communicate with the MN 110 over a control plane interface such as Xn-C. The MN 110 may communicate with the core network 160, e.g., the AMF 162, over a control plane interface such as NG-C. The SN 130 may also communicate with the MN 110 over a user plane interface such as Xn-U and with the core network 160, e.g., the UPF 161, over a user plane interface such as NG-U.

[0048] It should be understood that the number of devices or cells in Figure 1A is given for illustrative purposes and does not imply any limitations on the present disclosure. Communications network 100A may include any suitable number of network devices and / or terminal devices and / or cells suitable for implementing embodiments of the present disclosure.

[0049] Communications in communication network 100A may conform to any suitable standard, including, but not limited to, Global System for Mobile communications (GSM), Long Term Evolution (LTE), LTE-Evolution, LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), Code Division Multiple Access (CDMA), GSM EDGE Radio Access Network (GERAN), Machine Type Communications (MTC), etc. Embodiments of the present disclosure may be performed in accordance with any currently known or future-developed generation of communication protocols. Examples of communication protocols include, but are not limited to, first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G) communication protocols, 5.5G, 5G-Advanced networks, or sixth generation (6G) networks.

[0050] Communications in the direction from terminal device 120 to network device 110, 130, 140, or 150 are referred to as UL communications, and communications in the direction from network device 110, 130, 140, or 150 to terminal device 120 are referred to as DL communications. Terminal device 120 may travel between cells of network device 110, 130, 140, or 150, and possibly other network devices. In UL communications, terminal device 120 may transmit UL data and control information to network device 110, 130, 140, or 150 over an UL channel. In DL communications, network device 110, 130, 140, or 150 may transmit DL data and control information to terminal device 120 over a DL channel.

[0051] Communications in the communication network 100A may be performed according to UP and CP protocol stacks. Generally speaking, for a communication device (e.g., a terminal device or a network device), there may be multiple entities at multiple network protocol layers in the protocol stack, and these entities may be configured to perform corresponding processes on data or signaling transmitted from and received by the communication device. FIG. 1B is a schematic diagram 100B illustrating network protocol layer entities that may be established for the UP protocol stack in a device according to some embodiments of the present disclosure. For convenience, the following description will be given by taking communication between the terminal device 120 and the network device 110 as an example. It should be understood that the following description is also applicable to communication between the terminal device 120 and the network device 130, 140, or 150.

[0052] 1B , in the UP, each of the terminal device 120 and the network device 110 may include an L1 layer entity, i.e., a physical (PHY) layer entity (also referred to as a PHY entity), and one or more entities of upper layers (L2 layer and Layer 3 (L3) layer, i.e., higher layers), including a media access control (MAC) layer entity (also referred to as a MAC entity), a radio link control (RLC) layer entity (also referred to as an RLC entity), a packet data convergence protocol (PDCP) layer entity (also referred to as a PDCP entity), and a service data application protocol (SDAP) layer entity (also referred to as an SDAP entity, which will be established in 5G and subsequent generation networks). In some cases, the PHY, MAC, RLC, PDCP, and SDAP entities have a stack structure.

[0053] FIG. 1C is a schematic diagram 100C illustrating network protocol layer entities that may be established for a CP protocol stack in an apparatus according to some embodiments of the present disclosure. As shown in FIG. 1C , in a CP, each of the terminal device 120 and the network device 110 may include one or more entities of higher layers (L2 and L3 layers), including an L1 layer entity, i.e., a PHY layer entity (also referred to as a PHY entity), a MAC layer entity (also referred to as a MAC entity), an RLC layer entity (also referred to as an RLC entity), a PDCP layer entity (also referred to as a PDCP entity), and a Radio Resource Control (RRC) layer entity (also referred to as an RRC entity). The RRC layer may also be referred to as an Access Stratum (AS) layer, and therefore, the RRC entity may also be referred to as an AS entity. As shown in FIG. 1C , the terminal device 120 may also include a Non-Access Stratum (NAS) layer entity (also referred to as a NAS entity). The NAS layer on the network side is located in a core network (CN, not shown) rather than in a network device. In some cases, these entities are in a stack structure.

[0054] Generally, communication channels are divided into logical channels, transmission channels, and physical channels. Physical channels are channels through which the PHY layer actually transmits information. For example, physical channels may include a physical uplink control channel (PUCCH), a physical uplink shared channel (PUSCH), a physical random-access channel (PRACH), a physical downlink control channel (PDCCH), a physical downlink shared channel (PDSCH), and a physical broadcast channel (PBCH).

[0055] The transmission channel is a channel between the PHY layer and the MAC layer, and may include, for example, a Broadcast Channel (BCH), a Downlink Shared Channel (DL-SCH), a Paging Channel (PCH), an Uplink Shared Channel (UL-SCH), and a Random Access Channel (RACH).

[0056] A logical channel is a channel between the MAC layer and the RLC layer. For example, the logical channel may include a dedicated control channel (DCCH), a common control channel (CCCH), a paging control channel (PCCH), a broadcast control channel (BCCH), and a dedicated traffic channel (DTCH).

[0057] Generally, a channel between the RRC layer and the PDCP layer is called a radio bearer. The terminal device 120 may be configured with at least one data radio bearer (DRB) for carrying data plane data and at least one signaling radio bearer (SRB) for carrying control plane data.

[0058] In some embodiments, the network device 110 may configure the terminal device 120 with a conditional reconfiguration (also referred to as RRC reconfiguration) for a set of candidate cells. The conditional reconfiguration may indicate that subsequent CPC is enabled.

[0059] Cells 131 to 133, 141 to 143, and 151 to 153 are candidate cells. To 120 Assume that the SN addition is configured. In some scenarios, terminal device 120 may initially communicate only with network device 110. As terminal device 120 moves, if the conditions for a candidate cell (e.g., cell 131) are met, terminal device 120 may establish a dual connection with network device 110 and network device 130. This process of SN addition may be referred to as CPA.

[0060] In some scenarios, terminal device 120 may establish a dual connection with network devices 110 and 130. Network device 110 functions as an MN, and network device 130 functions as an SN. As terminal device 120 moves, if a condition for another candidate cell (e.g., cell 142) is met, the SN serving terminal device 120 may change from network device 130 (also referred to as source SN or current SN 130) to network device 140 (also referred to as target SN 140). This PScell ​​change process may be referred to as CPC. In some scenarios, after conditional reconfiguration is configured for the terminal device and subsequent CPC is enabled, but before at least one execution condition is met for any candidate PScell, terminal device 120 may receive an RRC reconfiguration message including reconfigurationWithSync from network device 110 and perform a PScell ​​change or addition accordingly. This procedure is referred to as conventional PScell ​​change or addition. As an example, after a conventional PSCell change or addition procedure, the SN serving the terminal device 120 is the network device 140.

[0061] After the above CPA, CPC, or conventional PSCell change / add procedure, if the conditions for yet another candidate cell (e.g., cell 152) are met as terminal device 120 moves further, the SN serving terminal device 120 may be changed from network device 140 to network device 150 (also referred to as target SN 150). This SN change process may be referred to as subsequent CPC. As terminal device 120 moves further, several more rounds of subsequent CPC may be performed.

[0062] In the conventional solution, when the MN first establishes a security context between the SN and the terminal device for a given AS security context shared between the MN and the terminal device, the MN acquires a security key K for the SN. SNand generates the security key K on the Xn-C interface. SN The security key K is sent to the SN. SN To generate K, the MN associates a counter with the current AS security context. The counter is called the SN counter or sk counter (sk-counter). The SN counter is a counter that is used to generate K as described in section 6.10.3.2 of the 3GPP specification TS 33.501. SN The MN transmits the value of the SN counter to the terminal device over the RRC signaling path. The terminal device uses the value of the SN counter to derive the security key K SN The security key K may be generated. SN is used to derive other RRC and UP keys used in communication between the terminal device and the SN.

[0063] In a conventional cell change or addition procedure or a CPC / CPA procedure, an RRC reconfiguration with reconfigurationWithSync for an SN is applied only once, so the configured SN counter is used only once. However, if a subsequent CPC is enabled, the terminal device may perform CPC multiple times using the same RRC reconfiguration. In this case, the security key for the subsequent CPC is unclear.

[0064] Embodiments of the present disclosure provide a solution for determining security keys for conditional cell changes, eg, subsequent CPC. Implementation of security key change for subsequent CPC

[0065] In this solution, the conditional reconfiguration includes information indicating that a subsequent conditional cell change is enabled for at least one candidate cell in a set of candidate cells. When a cell change or addition is performed, at least a part of the conditional reconfiguration is maintained for the at least one candidate cell. In this way, the subsequent conditional cell change can be flexibly enabled. For convenience, a more detailed description will be given below by taking a subsequent CPC as an example.

[0066] 2 is a schematic diagram illustrating an example process 200 for determining a security key for a subsequent CPC according to an embodiment of the present disclosure. For illustrative purposes, the process 200 will be described with reference to FIG. 1A. The process 200 may involve terminal device 120 and network devices 110 and 140 as shown in FIG. 1A. In this example, network device 110 is a MN (hereinafter referred to as MN 110 for convenience) serving terminal device 120, and network device 140 is a potential target SN (hereinafter referred to as SN 140 for convenience) serving terminal device 120. Assume that network device 130 is a source SN serving terminal device 120, and terminal device 120 is in cell 131 (i.e., a source cell or a current cell).

[0067] 2, the mobile node 110 sends 210 to the terminal device 120 a conditional reconfiguration for a set of candidate cells, which may refer to one or more candidate cells, indicating that a subsequent CPC has been enabled.

[0068] The terminal device 120 determines (220) whether a CPC (i.e., a subsequent CPC) is to be performed after the cell change or addition is performed, from the current cell to a candidate cell (e.g., cell 142 provided by SN 140) in the set of candidate cells.

[0069] When a subsequent CPC is performed, the terminal device 120 determines a counter value (also referred to as a first counter value for convenience) that is different from the counter value (also referred to as a second counter value for convenience) used for a previously performed cell change or addition (230). The previously performed cell change or addition may be a conventional cell change or addition or a conditional cell change / addition. The previously performed cell change or addition may be a first cell change / addition or a subsequent cell change. One or more cell changes / additions may be performed before the subsequent CPC. Some exemplary embodiments for determining the first counter value will be described in relation to Embodiment 1 to Embodiment 2. Embodiment 1

[0070] In this embodiment, the conditional reset may include a counter value configured for the terminal device 120. The terminal device 120 may derive a security key for the SN by autonomously incrementing the counter value.

[0071] 2, in some embodiments, terminal device 120 may store 231 the counter value set for terminal device 120. In some embodiments, terminal device 120 may store the counter value in a variable of terminal device 120. In some embodiments, terminal device 120 may store the counter value in an AS security context of terminal device 120. Of course, the counter value may be stored in any other suitable manner.

[0072] In some embodiments, terminal device 120 may store the counter value when performing a cell change or addition. In other words, terminal device 120 may store the counter value when performing a cell change or addition for the first time after receiving a conditional reconfiguration. In some embodiments, terminal device 120 may store the counter value when receiving the counter value within a conditional reconfiguration. In this way, it is possible to store the initial value of the counter value.

[0073] In some embodiments, terminal device 120 may determine the first counter value by incrementing the stored counter value (232). In other words, for each subsequent CPC procedure, terminal device 120 may increment the stored counter value and derive a security key for the subsequent CPC procedure based on the incremented counter value. For example, terminal device 120 may increment the stored counter value by 1 or in any other suitable manner. In this manner, a different counter value may be maintained for each subsequent CPC procedure. Embodiment 2

[0074] In this embodiment, the conditional reconfiguration may include at least one set of counter values ​​configured for the terminal device 120. One set of counter values ​​in the at least one set of counter values ​​is used for the candidate cell. The terminal device 120 may select one counter value from the set of counter values ​​that is unused before the subsequent CPC.

[0075] In some embodiments, the at least one set of counter values ​​includes only one set of counter values. For example, the set of counter values ​​is used for each candidate cell in the set of candidate cells. That is, one set of counter values ​​may be configured for each UE. In this case, the set of counter values ​​is the same for all candidate cells.

[0076] In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, where the first set of counter values ​​is used for a first candidate cell in the set of candidate cells and the second set of counter values ​​is used for a second candidate cell in the set of candidate cells. In other words, a set of counter values ​​may be set for each candidate cell. In this case, the sets of counter values ​​may be the same or different between the candidate cells.

[0077] In some embodiments, terminal device 120 may determine a set of counter values ​​used for the candidate cell on which the subsequent CPC is performed from the at least one set of counter values. Referring to FIG. 2, terminal device 120 may determine a counter value in the set of counter values ​​that is unused before the subsequent CPC as the first counter value (233). If there are multiple unused counter values, terminal device 120 may select one from the multiple counter values ​​in a predetermined order or randomly. In some alternative embodiments, terminal device 120 deletes a counter value after using it.

[0078] In some embodiments, terminal device 120 may determine whether there are no counter values ​​in the set of counter values ​​to be used, i.e., whether all counter values ​​have already been used or whether there are no counter values ​​available (234). If there are no counter values ​​to be used, terminal device 120 may discard (235) the conditional reconfiguration entry and measurement configuration for at least one candidate cell.

[0079] For example, in some embodiments where one set of counter values ​​is configured per UE, if the spare counter values ​​to use run out, terminal device 120 may discard the conditional reconfiguration entries and measurement configurations for all candidate cells. In another example, in some embodiments where one set of counter values ​​is configured per candidate cell, if the spare counter values ​​for one candidate cell run out, terminal device 120 may discard the corresponding conditional reconfiguration entry and measurement configuration for that candidate cell.

[0080] Thus, for each subsequent CPC procedure, a different counter value may be determined.

[0081] 2, once the first counter value is determined, terminal device 120 determines (240) a security key based on the first counter value. The security key may be used in communications between terminal device 120 and SN 140. For example, the first counter value may be determined as K SN Thus, the security key (K SN ) can be derived. It should be understood that determining the security key based on the first counter value may be performed in any other suitable manner, and the present disclosure is not limited in this respect.

[0082] Up to this point, it has been described that the terminal device 120 determines a security key for communication with the SN 140. In response, the SN 140 may also determine a security key for communication with the terminal device. The SN 140 may determine the security key based on security key information received from the MN 110.

[0083] 2, the MN 110 determines (250) a set of security keys based on a set of first counter values ​​and transmits (260) the set of security keys to the SN 140. The SN 140 determines (270) security keys in the set of security keys for communication with the terminal device 120 in a subsequent CPC, where the security keys used for the subsequent CPC are different from the security keys used for the previous cell change or addition. Some exemplary embodiments of the determination of security keys in the SN 140 will be described in relation to embodiments 3 to 4. Embodiment 3

[0084] In this embodiment, the MN 110 determines a security key based on the first counter value and sends this security key to the SN 140, thus making the security key for the subsequent CPC different from the security key for the previous cell change or addition.

[0085] 2, after the subsequent CPC trigger, the terminal device 120 may send an RRC reconfiguration complete message to the MN 110 (251). The RRC reconfiguration complete message may include a conditional reconfiguration identity (ID).

[0086] Upon receiving the RRC reconfiguration complete message, the MN 110 may determine a first counter value (252). In some embodiments in which the conditional reconfiguration includes one counter value configured for the terminal device 120, the MN 110 may determine the first counter value by incrementing the counter value configured for the terminal device 120. For example, the counter value may be incremented by 1 for each subsequent CPC procedure, or may be incremented in any other suitable manner.

[0087] In some embodiments in which the conditional reconfiguration includes at least one set of counter values ​​configured for the terminal device 120, the MN 110 may determine a set of counter values ​​used for the candidate cell within the at least one set of counter values ​​and determine a counter value within the set of counter values ​​as the first counter value. For example, the MN 110 may select one of the set of counter values ​​in a predetermined order. For another example, the MN 110 may select the one unused counter value from the set of counter values.

[0088] In some embodiments, the at least one set of counter values ​​includes only one set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, where the first set of counter values ​​is used for a first candidate cell in the set of candidate cells and the second set of counter values ​​is used for a second candidate cell in the set of candidate cells. In some embodiments, the first set of counter values ​​may be the same as the second set of counter values. In some embodiments, the first set of counter values ​​may be different from the second set of counter values.

[0089] In some embodiments, the MN 110 may receive information of the first counter value from the terminal device 120. For example, the information of the first counter value may be included in an RRC reconfiguration complete message to the MN 110. It should be understood that the information of the first counter value may be conveyed in any other suitable format. In some embodiments, the information of the first counter value may include at least one of the first counter value used by the terminal device 120, the difference between the first counter value and a counter value configured for the terminal device 120, or a count for the subsequent CPC. The count for the subsequent CPC may be the number of subsequent CPC procedures that have already been performed. It should be understood that any other suitable information is also possible. Based on the information of the first counter value, the MN 110 can determine the first counter value.

[0090] Upon determining the first counter value, the MN 110 may determine 253 a security key for the SN 140 based on the first counter value. For example, the first counter value may be K SN Thus, the security key (K SN ) can be derived. It should be understood that determining the security key based on the first counter value may be performed in any other suitable manner, and the present disclosure is not limited in this respect.

[0091] Once the security key is determined, the MN 110 may transmit the security key in an SN reconfiguration complete message or an SN modification confirmation message to the SN 140. Of course, the MN 110 may also transmit the security key to the SN 140 in any other appropriate message.

[0092] Upon receiving the security key, the SN 140 may use 271 the security key for communication with the terminal device 120 in subsequent CPC procedures.

[0093] Thus, after a subsequent CPC is triggered, a security key for the SN may be derived, and the security key used for the subsequent CPC is different from the security key used for the previous cell change or addition. Embodiment 4

[0094] In this embodiment, the MN 110 pre-configures a set of security keys for the SN and provides the set of security keys to the target SN or source SN (e.g., SN 140). The SN 140 determines a security key from the set of security keys for transmission of one subsequent CPC procedure with the terminal device 120 based on the security key information provided by or forwarded by the MN 110.

[0095] In some embodiments, the MN 110 may determine a set of counter values ​​used for a candidate cell from at least one set of counter values ​​configured for the terminal device 120. Referring to FIG. 2, the MN 110 may determine 254 at least one counter value in the determined set of counter values ​​as a set of first counter values, the at least one counter value being unused before the subsequent CPC. The first counter values ​​in the set of first counter values ​​are different from each other.

[0096] In some embodiments, the MN 110 may determine the first set of counter values ​​by incrementing a counter value configured for the terminal device 120 .

[0097] Based on the set of first counter values, the MN 110 may determine the set of security keys (255). The security keys in the set of security keys are different from each other. For example, the first counter value in the set of first counter values ​​may be K SNmay be used as a freshness input to the derivation of the corresponding security key (K SN ) can be derived. Thus, a set of K SN It is possible to derive a value based on the first counter value. It should be understood that determining the security key based on the first counter value may be performed in any other suitable manner, and the present disclosure is not limited in this respect.

[0098] Once the set of security keys is determined, the MN 110 may transmit the set of security keys to the SN. In some embodiments, the MN 110 may transmit the set of security keys to the target SN in an SN Addition Request message. In some embodiments, the MN 110 may transmit the set of security keys to the source SN in an SN Modification Request message. It should be understood that the MN 110 may transmit the set of security keys in any other suitable manner.

[0099] In some embodiments, after the triggering of the subsequent CPC, the terminal device 120 may send an RRC reconfiguration complete message to the MN 110 (272). Upon receiving the RRC reconfiguration complete message, the MN 110 may determine a security key in the set of security keys. In some embodiments, the RRC reconfiguration complete message may include information of a first counter value in the set of first counter values. In some embodiments, the information of the first counter value may include at least one of the first counter value, a difference between the first counter value and a counter value configured for the terminal device 120, or a count for the subsequent CPC. The count for the subsequent CPC may be the number of subsequent CPC procedures that have already been performed. Of course, any other suitable information is also possible.

[0100] Upon receiving the RRC reconfiguration complete message, the MN 110 may determine a security key in the set of security keys based on the information of the first counter value (273). The MN 110 may then transmit the security key information to the SN 140 (274). For example, the MN 110 may transmit the security key information in an SN reconfiguration complete message, an SN modification confirmation message, or any other appropriate message. In some embodiments, the security key information may include at least one of a count for the subsequent CPC or an index of the security key. The count for the subsequent CPC may be the number of subsequent CPC procedures that have already been performed. Of course, any other suitable information is also possible. Upon receiving the security key information, the SN 140 may determine the security key from the set of security keys (275).

[0101] In some embodiments, after triggering the subsequent CPC, terminal device 120 may send an RRC reconfiguration complete message, referred to as an MN RRC reconfiguration complete message, to MN 110 (276). The MN RRC reconfiguration complete message includes an RRC reconfiguration complete message to SN 140, referred to as an SN RRC reconfiguration complete message. MN 110 may forward the SN RRC reconfiguration complete message to SN 140 (277). Upon receiving the SN RRC reconfiguration complete message, SN 140 may determine a security key from the set of security keys for transmission to and from terminal device 120. In some embodiments, the SN RRC reconfiguration complete message may include information of the security key used by terminal device 120. In some embodiments, the information of the security key may include at least one of a count for the subsequent CPC or an index of the security key. Of course, any other suitable information is possible. SN 140 may determine 278 the security key from the set of security keys based on the information for the security key.

[0102] In this way, a set of security keys for an SN may be pre-configured, and after a subsequent CPC is triggered, the security key used for the subsequent CPC may be determined from the set of security keys, and the security key used for the subsequent CPC is different from the security key used for the previous cell change or addition. Implementation example without changing security keys for subsequent CPC

[0103] 3 is a schematic diagram illustrating another example process 300 for determining security keys for a subsequent CPC according to an embodiment of the present disclosure. For illustrative purposes, the process 300 will be described with reference to FIG. 1A. The process 300 may involve terminal device 120 and network devices 110 and 140 as shown in FIG. 1A. In this example, network device 110 is an MN serving terminal device 120, and network device 140 is a potential target SN serving terminal device 120. Assume that network device 130 is a source SN serving terminal device 120, and terminal device 120 is in cell 131 (i.e., a source cell or a current cell).

[0104] As shown in Figure 3, the mobile node 110 sends a conditional reconfiguration for a set of candidate cells to the terminal device 120 (310). The set of candidate cells refers to one or more candidate cells. This conditional reconfiguration indicates that a subsequent CPC is enabled. In this embodiment, the PDCP anchors of all candidate cells are located in the same network entity. For example, all candidate cells supporting the subsequent CPC belong to one centralized unit (CU) or integrated network device.

[0105] The terminal device 120 determines (320) whether a CPC (i.e., a subsequent CPC) is to be performed after the cell change or addition is performed, from the current cell to a candidate cell (e.g., cell 142 provided by SN 140) in the set of candidate cells.

[0106] When a subsequent CPC is performed, the terminal device 120 applies (330) the conditional reconfiguration for the SN 140 so that the security key used for the cell change or addition is the same as the security key used for the subsequent CPC.

[0107] In some embodiments, terminal device 120 may maintain the security key used for the cell change or addition. In other words, terminal device 120 does not derive a security key for the SN. In some embodiments, terminal device 120 may perform PDCP recovery for at least one DRB. In some embodiments, terminal device 120 may perform PDCP service data unit (SDU) discard for at least one SRB. In other words, terminal device 120 does not perform PDCP re-establishment. Thus, terminal device 120 performs the above behavior regardless of network configuration.

[0108] In some alternative embodiments, the conditional reconfiguration may indicate at least one of: that there is no counter value configured for the security key determination; that PDCP recovery has been performed for at least one DRB; or that PDCP SDU discard has been performed for at least one SRB.

[0109] Thus, the terminal device does not need to change the security key for subsequent CPC procedures. Example of the method

[0110] Therefore, embodiments of the present disclosure provide communication methods implemented in a terminal device and a network device, which are described below with reference to FIGS.

[0111] 4 illustrates an exemplary communication method 400 implemented in a terminal device, according to some embodiments of the present disclosure. For example, method 400 may be performed in terminal device 120 as shown in FIG. 1A. For purposes of explanation, method 400 will be described below with reference to FIG. 1A. It should be understood that method 400 may include additional blocks not shown and / or omit some blocks shown, and that the scope of the present disclosure is not limited in this respect.

[0112] In block 410, the terminal device 120 receives a conditional reconfiguration for a set of candidate cells from a first network device (e.g., network device 110) as an MN, the conditional reconfiguration including information indicating that a subsequent conditional cell change has been enabled.

[0113] In block 420, the terminal device 120 determines whether a subsequent conditional cell change to the candidate cell is to be performed after the cell change or addition is performed. If the subsequent conditional cell change is to be performed, the process 400 proceeds to block 430.

[0114] In block 430, the terminal device 120 determines a first counter value such that the first counter value and a second counter value used for the cell change or addition are different.

[0115] In block 440, terminal device 120 determines a security key for communication with a second network device (eg, network device 140) as the SN serving the candidate cell based on the first counter value.

[0116] In some embodiments, the conditional reconfiguration may include a counter value configured for the terminal device 120. In these embodiments, the terminal device 120 may store the counter value configured for the terminal device 120. In some embodiments, the terminal device 120 may store the counter value in a variable of the terminal device 120. In some embodiments, the terminal device 120 may store the counter value in an AS security context of the terminal device 120. In some embodiments, the terminal device 120 may store the counter value upon performing a cell change or addition. In some embodiments, the terminal device 120 may store the counter value upon receiving the counter value within the conditional reconfiguration. In these embodiments, the terminal device 120 may determine a first counter value by incrementing the stored counter value.

[0117] In some embodiments, the conditional reconfiguration may include at least one set of counter values ​​configured for terminal device 120. In some embodiments, the at least one set of counter values ​​includes only one set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, the first set of counter values ​​being used for a first candidate cell in the set of candidate cells and the second set of counter values ​​being used for a second candidate cell in the set of candidate cells.

[0118] In these embodiments, terminal device 120 may determine a set of counter values ​​used for the candidate cell from the at least one set of counter values ​​and determine a counter value in the set of counter values ​​that is unused before the subsequent conditional cell change as the first counter value. In some embodiments, if there is no counter value in the set of counter values ​​that is unused before the subsequent conditional cell change, terminal device 120 may discard the conditional reconfiguration entry and measurement configuration for at least one candidate cell.

[0119] In some embodiments, when the subsequent conditional cell change is performed, terminal device 120 may transmit information of the first counter value to network device 110. In some embodiments, terminal device 120 may transmit an RRC reconfiguration complete message including information of the first counter value to network device 110. In some embodiments, the information of the first counter value may include at least one of the first counter value, a difference between the first counter value and a counter value configured for the terminal device, or a count for the subsequent conditional cell change.

[0120] In some embodiments, terminal device 120 may send an RRC reconfiguration complete message including information of the security key to network device 140 via network device 110. In some embodiments, the information of the security key may include at least one of a count for the subsequent conditional cell change or an index of the security key.

[0121] By method 400, a different counter value may be used to determine a security key for a subsequent conditional cell change that is different from the security key for a previous cell change or addition.

[0122] 5 illustrates an exemplary communication method 500 implemented in a first network device as a mobile node (MN) according to some embodiments of the present disclosure. For example, method 500 may be performed in network device 110 as shown in FIG. 1A. For purposes of explanation, method 500 will be described below with reference to FIG. 1A. It should be understood that method 500 may include additional blocks not shown and / or omit some blocks shown, and that the scope of the present disclosure is not limited in this respect.

[0123] In block 510, the network device 110 determines a set of security keys based on a first set of counter values ​​to be used for a subsequent conditional cell change performed after a cell change or addition is performed, the first counter values ​​being different from a second counter value used for the subsequent conditional cell change to a candidate cell in the set of candidate cells.

[0124] In block 520, the network device 110 transmits the set of security keys to a second network device (e.g., the network device 140) that provides the candidate cell for communication between the terminal device 120 and the network device 140.

[0125] In some embodiments, network device 110 may send to terminal device 120 a conditional reconfiguration for a set of candidate cells that includes at least one set of counter values. In some embodiments, the at least one set of counter values ​​includes only one set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, the first set of counter values ​​being used for a first candidate cell in the set of candidate cells and the second set of counter values ​​being used for a second candidate cell in the set of candidate cells.

[0126] In some embodiments, in which the set of security keys includes a security key and the set of first counter values ​​includes a first counter value, network device 110 may determine the security key by receiving an RRC reconfiguration complete message from a terminal device, determining the first counter value, and determining the security key based on the first counter value.

[0127] In some embodiments, network device 110 may determine the first counter value by incrementing a counter value configured for terminal device 120. In some embodiments, network device 110 may determine the first counter value by determining a set of counter values ​​used for the candidate cell from at least one set of counter values ​​configured for terminal device 120, and determining as the first counter value a counter value in the set of counter values ​​configured for terminal device 120, where the counter value is unused before the subsequent conditional cell change.

[0128] In some embodiments, network device 110 may determine the first counter value by receiving information of the first counter value from terminal device 120 and determining the first counter value based on the information of the first counter value. In some embodiments, network device 110 may receive the information of the first counter value from the RRC reconfiguration complete message. In some embodiments, the information of the first counter value may include at least one of the first counter value, a difference between the first counter value and a counter value configured for terminal device 120, or a count for the subsequent conditional cell change.

[0129] In some embodiments, network device 110 may send this security key in a SN Reconfiguration Complete message to network device 140. In some embodiments, network device 110 may send this security key to network device 140 in a SN Modification Confirmation message.

[0130] In some embodiments, network device 110 may determine the set of security keys by determining a set of counter values ​​used for candidate cells from at least one set of counter values ​​configured for terminal device 120, determining at least one counter value in the set of counter values ​​that is unused before the subsequent conditional cell change as the set of first counter values, and determining the set of security keys based on the set of first counter values. In some embodiments, the at least one set of counter values ​​includes only a set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, where the first set of counter values ​​is used for a first candidate cell in the set of candidate cells and the second set of counter values ​​is used for a second candidate cell in the set of candidate cells.

[0131] In some embodiments, network device 110 may determine the set of security keys by determining a first set of counter values ​​by incrementing a counter value set for terminal device 120, and determining the set of security keys based on the first set of counter values.

[0132] In some embodiments, network device 110 may determine a security key within the set of security keys and transmit information about the security key to network device 140. In some embodiments, network device 110 may receive information about a first counter value within the set of first counter values ​​from terminal device 120 and determine the security key within the set of security keys based on the information about the first counter value. Network device 110 may then transmit the security key information to network device 140.

[0133] In some embodiments, the network device 110 may further receive an RRC reconfiguration complete message from the terminal device 120, which is forwarded to a second network device, the RRC reconfiguration complete message including information of the security keys in the set of security keys, and transmit the RRC reconfiguration complete message to the network device 140.

[0134] In some embodiments, the information of the security key may include at least one of a count for the subsequent conditional cell change, or an index of the security key.

[0135] By method 500, a different counter value may be used to determine a security key for a subsequent conditional cell change that is different from the security key for a previous cell change or addition.

[0136] 6 illustrates an exemplary communication method 600 implemented in a second network device as an SN, according to some embodiments of the present disclosure. For example, method 600 may be performed in network device 130, 140, or 150 as shown in FIG. 1A. For purposes of explanation, method 600 will be described below with reference to network device 140 in FIG. 1A. It should be understood that method 600 may include additional blocks not shown and / or omit some blocks that are shown, and that the scope of the present disclosure is not limited in this respect.

[0137] At block 610, network device 140 receives a set of security keys from a first network device (e.g., network device 110). In some embodiments, network device 140 may receive the security keys from network device 110 in an SN reconfiguration complete message or an SN modification confirmation message. In some embodiments, network device 140 may receive the set of security keys from network device 110 via an SN addition request message or an SN modification request message.

[0138] In block 620, the network device 140 performs communication between the terminal device 120 and the network device 140 based on a security key in the set of security keys. The network device 140 provides candidate cells for a subsequent conditional cell change after a cell change or add is performed. The security key used for the subsequent conditional cell change is different from the previous security key used for the cell change or add.

[0139] In some embodiments, network device 140 may receive the security key information from network device 110 and determine the security key from the set of security keys based on the security key information. In some embodiments, network device 140 may receive the security key information by receiving an RRC reconfiguration complete message forwarded by network device 110 that includes the security key information. In some embodiments, network device 140 may receive the security key information by receiving an SN reconfiguration complete message from network device 110 that includes the security key information. In some embodiments, network device 140 may receive the security key information by receiving an SN modification confirmation message from network device 110 that includes the security key information.

[0140] In some embodiments, the information for the security key may include at least one of a count for the subsequent conditional cell change, or an index for the security key.

[0141] By method 600, a different security key is used for a subsequent conditional cell change compared to the security key for the previous cell change or add.

[0142] 7 illustrates another exemplary communication method 700 implemented in a terminal device, according to some embodiments of the present disclosure. For example, method 700 may be performed in terminal device 120 as shown in FIG. 1A. For purposes of explanation, method 700 will be described below with reference to FIG. 1A. It should be understood that method 700 may include additional blocks not shown and / or omit some blocks that are shown, and that the scope of the present disclosure is not limited in this respect.

[0143] In block 710, the terminal device 120 receives a conditional reconfiguration for a set of candidate cells from a first network device (e.g., network device 110) as an MN, the conditional reconfiguration including information indicating that a subsequent conditional cell change has been enabled.

[0144] In block 720, the terminal device 120 determines whether a subsequent conditional cell change to the candidate cell is to be performed after the cell change or addition is performed. If the subsequent conditional cell change is to be performed, the process 700 proceeds to block 730.

[0145] In block 730, the terminal device 120 applies the conditional reconfiguration to a second network device (e.g., network device 140) as the SN serving the candidate cell, and the security key used for the cell change or addition is the same as the security key used for the subsequent conditional cell change.

[0146] In some embodiments, terminal device 120 may apply the conditional reconfiguration by at least one of retaining the security key used for the cell change or addition, performing PDCP recovery for at least one DRB, or performing PDCP SDU discard for at least one SRB.

[0147] In some embodiments, the conditional reconfiguration may indicate at least one of: that there is no counter value configured for the security key determination; that PDCP recovery has been performed for at least one DRB; or that PDCP SDU discard has been performed for at least one SRB.

[0148] By the method 700, the security keys do not need to be changed for a subsequent conditional cell change compared to the security keys for a previous cell change or addition.

[0149] 8 illustrates another exemplary communication method 800 implemented in a first network device as a mobile node (MN) according to some embodiments of the present disclosure. For example, method 800 may be performed in network device 110 as shown in FIG. 1A. For purposes of explanation, method 800 will be described below with reference to FIG. 1A. It should be understood that method 800 may include additional blocks not shown and / or omit some blocks that are shown, and that the scope of the present disclosure is not limited in this respect.

[0150] In block 810, the network device 110 sends a conditional reconfiguration for a set of candidate cells to the terminal device 120 such that the security key used for the cell change or addition is the same as the security key used for a subsequent conditional cell change made after the cell change or addition is performed.

[0151] In some embodiments, the conditional reconfiguration may indicate at least one of: that there is no counter value configured for the security key determination; that PDCP recovery has been performed for at least one DRB; or that PDCP SDU discard has been performed for at least one SRB.

[0152] The method 800 allows for conditional resetting to be configured such that security keys do not need to be changed for subsequent conditional cell changes. Device and equipment implementation examples

[0153] 9 is a schematic block diagram of an apparatus 900 suitable for implementing embodiments of the present disclosure. The apparatus 900 may be considered another exemplary implementation of the terminal device 120 or the network device 110, 130, 140, or 150 shown in FIG. 1A. Accordingly, the apparatus 900 may be implemented in, or as at least a part of, the terminal device 120 or the network device 110, 130, 140, or 150.

[0154] As shown, the apparatus 900 comprises a processor 910, a memory 920 coupled to the processor 910, a suitable transmitter (TX) and receiver (RX) 940 coupled to the processor 910, and a communication interface coupled to the TX / RX 940. 920 is , and stores at least a portion of the program 930. The TX / RX 940 is used for bidirectional communication. The TX / RX 940 has at least one antenna to facilitate communication, although the access nodes referred to herein may actually have multiple antennas. The communication interface may represent any interface required for communication with other network elements, such as an X2 / Xn interface for bidirectional communication between eNBs / gNBs, an S1 / NG interface for communication between a Mobility Management Entity (MME) / Access and Mobility Management Function (AMF) / SGW / UPF and an eNB / gNB, an Un interface for communication between an eNB / gNB and a Relay Node (RN), or a Uu interface for communication between an eNB / gNB and a terminal device.

[0155] 1A-8, which, when executed by the associated processor 910, enables the device 900 to operate according to embodiments of the present disclosure. The embodiments herein may be implemented by computer software executable by the processor 910 of the device 900, by hardware, or by a combination of software and hardware. The processor 910 may be configured to implement various embodiments of the present disclosure. Furthermore, the combination of the processor 910 and the memory 920 may form a processing means 950 suitable for implementing various embodiments of the present disclosure.

[0156] Memory 920 may be of any type suitable for a local technology network and may be implemented using any suitable data storage technology, including, by way of non-limiting example, non-transitory computer-readable storage media, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. While only one memory 920 is shown in device 900, several physically distinct memory modules may be present within device 900. Processor 910 may be of any type suitable for a local technology network and may include, by way of non-limiting example, one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. Device 900 may have multiple processors, for example, application-specific integrated circuit chips time-slaved to a clock that synchronizes the main processor.

[0157] In some embodiments, a terminal device comprises circuitry configured to receive a conditional reconfiguration for a set of candidate cells from a first network device, the conditional reconfiguration including information indicating that a subsequent conditional cell change is enabled, and, in accordance with a determination that the subsequent conditional cell change to a candidate cell in the set of candidate cells will be performed after a cell change or addition is performed, determine a first counter value, the first counter value being different from a second counter value used for the cell change or addition, and determine a security key for communication with a second network device that provides the candidate cell based on the first counter value.

[0158] In some embodiments, the conditional reconfiguration includes a counter value configured for the terminal device, and the circuitry may be further configured to store the counter value configured for the terminal device. In some embodiments, the circuitry may be configured to store the counter value by at least one of: storing the counter value in a variable of the terminal device; storing the counter value in an AS security context of the terminal device; storing the counter value upon execution of the cell change or add; or storing the counter value upon receipt of the counter value in the conditional reconfiguration.

[0159] In some embodiments, the circuitry may be configured to determine the first counter value by determining the first counter value by incrementing a stored counter value.

[0160] In some embodiments, the conditional reconfiguration includes at least one set of counter values ​​configured for the terminal device. In some embodiments, the at least one set of counter values ​​includes only one set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, the first set of counter values ​​being used for a first candidate cell in the set of candidate cells and the second set of counter values ​​being used for a second candidate cell in the set of candidate cells.

[0161] In some embodiments, the circuitry may be configured to determine the first counter value by determining a set of counter values ​​used for the candidate cell from the at least one set of counter values, and determining as the first counter value a counter value in the set of counter values ​​that was unused before the subsequent conditional cell change.

[0162] In some embodiments, the circuitry may be further configured to discard conditional reconfiguration entries and measurement configurations for at least one candidate cell pursuant to a determination that an unused counter value prior to the subsequent conditional cell change is not within the set of counter values.

[0163] In some embodiments, the circuitry may be further configured to transmit information of the first counter value to the first network device in accordance with determining that the subsequent conditional cell change has been performed. In some embodiments, the circuitry may be configured to transmit the information of the first counter value by transmitting to the first network device an RRC reconfiguration complete message including the information of the first counter value. In some embodiments, the information of the first counter value includes at least one of the first counter value, a difference between the first counter value and a counter value configured for the terminal device, or a count for the subsequent conditional cell change.

[0164] In some embodiments, the circuitry may be further configured to send, via the first network device, to the second network device, an RRC reconfiguration complete message including information about the security key, wherein the information about the security key includes at least one of a count for the subsequent conditional cell change or an index of the security key.

[0165] In some embodiments, the first network device comprises circuitry configured to determine a set of security keys based on a set of first counter values, the set of first counter values ​​being used for a subsequent conditional cell change to a candidate cell in a set of candidate cells, performed after a cell change or addition is performed, and different from a second counter value used for the cell change or addition, and to transmit the set of security keys to the second network device providing the candidate cell for communication between the terminal device and the second network device.

[0166] In some embodiments, the circuitry may be further configured to send, to the terminal device, a conditional reconfiguration for at least one set of candidate cells, the conditional reconfiguration including a set of counter values. In some embodiments, the at least one set of counter values ​​includes only one set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, the first set of counter values ​​being used for a first candidate cell in the set of candidate cells and the second set of counter values ​​being used for a second candidate cell in the set of candidate cells.

[0167] In some embodiments, in which the set of security keys includes a security key and the set of first counter values ​​includes a first counter value, the circuitry may be configured to determine the security key by receiving an RRC reconfiguration complete message from the terminal device, determining the first counter value, and determining the security key based on the first counter value.

[0168] In some embodiments, the circuitry may be configured to determine the first counter value by incrementing a counter value configured for the terminal device.

[0169] In some embodiments, the circuitry may be configured to determine the first counter value by determining a set of counter values ​​used for the candidate cell from at least one set of counter values ​​configured for the terminal device, and determining as the first counter value a counter value in the set of counter values ​​that was unused before the subsequent conditional cell change.

[0170] In some embodiments, the circuitry may be configured to determine the first counter value by receiving information of the first counter value from the terminal device and determining the first counter value based on the information of the first counter value.

[0171] In some embodiments, the circuitry may be configured to receive the information of the first counter value by receiving the information of the first counter value from the RRC reconfiguration complete message.

[0172] In some embodiments, the information about the first counter value includes at least one of the first counter value, a difference between the first counter value and a counter value configured for the terminal device, or a count for the subsequent conditional cell change.

[0173] In some embodiments, the circuitry may be configured to transmit the security key by at least one of transmitting the security key to the second network device in an SN reconfiguration complete message or transmitting the security key to the second network device in an SN modification confirmation message.

[0174] In some embodiments, the circuitry may be configured to determine the set of security keys by: determining a set of counter values ​​used for the candidate cell from at least one set of counter values ​​configured for the terminal device; determining at least one counter value in the set of counter values ​​that is unused before the subsequent conditional cell change as the set of first counter values; and determining the set of security keys based on the set of first counter values. In some embodiments, the at least one set of counter values ​​includes only a set of counter values ​​used for each candidate cell in the set of candidate cells. In some embodiments, the at least one set of counter values ​​includes a first set of counter values ​​and a second set of counter values, the first set of counter values ​​being used for a first candidate cell in the set of candidate cells, and the second set of counter values ​​being used for a second candidate cell in the set of candidate cells.

[0175] In some embodiments, the circuitry may be configured to determine the set of security keys by determining a first set of counter values ​​by incrementing a counter value configured for the terminal device, and determining the set of security keys based on the first set of counter values.

[0176] In some embodiments, the circuitry may be further configured to determine a security key within the set of security keys and transmit information of the security key to the second network device. In some embodiments, the circuitry may be configured to determine the security key by receiving information of a first counter value within the set of first counter values ​​from the terminal device and determining the security key within the set of security keys based on the information of the first counter value.

[0177] In some embodiments, the circuitry may be further configured to receive from the terminal device an RRC reconfiguration complete message forwarded to the second network device, the RRC reconfiguration complete message including information of a security key in the set of security keys, and forward the RRC reconfiguration complete message to the second network device. In some embodiments, the information of the security key may include at least one of a count for the subsequent conditional cell change or an index of the security key.

[0178] In some embodiments, the second network device comprises circuitry configured to receive a set of security keys from the first network device and perform communication between a terminal device and the second network device providing a candidate cell based on a security key in the set of security keys, wherein a subsequent conditional cell change to the candidate cell is performed after a cell change or addition is performed, and the security key is different from a previous security key used for the cell change or addition.

[0179] In some embodiments, the circuitry may be configured to receive the set of security keys by receiving the security keys from the first network device in an SN reconfiguration complete message or an SN modification confirmation message.

[0180] In some embodiments, the circuitry may be configured to receive the set of security keys by receiving the set of security keys from the first network device via an SN addition request message or an SN modification request message.

[0181] In some embodiments, the circuitry may be further configured to receive security key information from the first network device and determine the security key from the set of security keys based on the security key information.

[0182] In some embodiments, the circuitry may be configured to receive the security key information by at least one of receiving an RRC reconfiguration complete message forwarded by the first network device, the RRC reconfiguration complete message including the security key information, receiving an SN reconfiguration complete message from the first network device, the SN reconfiguration complete message including the security key information, or receiving an SN modification confirmation message from the first network device, the SN reconfiguration complete message including the security key information.

[0183] In some embodiments, the information for the security key includes at least one of a count for the subsequent conditional cell change, or an index for the security key.

[0184] In some embodiments, a terminal device comprises circuitry configured to receive from a first network device a conditional reconfiguration for a set of candidate cells, the conditional reconfiguration including information indicating that a subsequent conditional cell change is enabled, and to apply the conditional reconfiguration for a second network device that provides the candidate cell according to a determination that the subsequent conditional cell change to a candidate cell in the set of candidate cells will be performed after a cell change or addition is performed, wherein the security key used for the cell change or addition is the same as the security key used for the subsequent conditional cell change.

[0185] In some embodiments, the circuitry may be configured to apply the conditional reconfiguration by at least one of: maintaining the security key used for the cell change or addition; performing PDCP recovery for at least one DRB; or performing PDCP SDU discard for at least one SRB.

[0186] In some embodiments, the conditional reconfiguration may indicate at least one of: that there is no counter value configured for the security key determination; that PDCP recovery has been performed for at least one DRB; or that PDCP SDU discard has been performed for at least one SRB.

[0187] In some embodiments, the first network device comprises circuitry configured to send a conditional reconfiguration for a set of candidate cells to the terminal device such that the security key used for the cell change or addition is the same as the security key used for a subsequent conditional cell change made after the cell change or addition is performed.

[0188] In some embodiments, the conditional reconfiguration may indicate at least one of: that there is no counter value configured for the security key determination; that PDCP recovery has been performed for at least one DRB; or that PDCP SDU discard has been performed for at least one SRB.

[0189] As used herein, the term "circuitry" may refer to a hardware circuit and / or a combination of a hardware circuit and software. For example, a circuit may be a combination of analog and / or digital hardware circuitry and software / firmware. As yet another example, a circuit may be any portion of a hardware processor with software, including a digital signal processor, software, and one or more memories, that cooperate to cause a device, such as a terminal device or a network device, to perform various functions. In yet another example, a circuit may be a hardware circuit and / or a processor, such as a microprocessor or portion thereof, that requires software / firmware for operation, although the software may not be present if not necessary for operation. As used herein, the term "circuitry" also includes an implementation of a hardware circuit or one or more processors only, or a hardware circuit or portion of one or more processors and its / their accompanying software and / or firmware.

[0190] Overall, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software executable by a controller, microprocessor, or other computing device. While various aspects of embodiments of the present disclosure have been illustrated and described using block diagrams, flowcharts, or other pictorial representations, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented, by way of non-limiting example, in hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing device, or any combination thereof.

[0191] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, that execute within a device on a target real or virtual processor to perform the processes or methods described above with reference to FIGS. 1A-8. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. In various embodiments, the functionality of the program modules may be combined or split between program modules as desired. The machine-executable instructions of the program modules may be executed within local or distributed devices. In a distributed device, program modules may be located in both local and remote storage media.

[0192] Program code for carrying out the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, and when executed by the processor or controller, cause the program code to implement the functions / acts specified in the flowcharts and / or block diagrams. The program code may run entirely on the machine, partially on the machine, as a separate software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0193] The above-described program code may be embodied on a machine-readable medium, which may be any tangible medium that can contain or store a program used by or associated with an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the aforementioned media. More specific examples of a machine-readable storage medium may include an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0194] It should be noted that, although operations have been described in a particular order, it should not be understood that performing such operations in the particular order shown, or in any sequential order, or performing all of the operations described, is required to achieve desirable results. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limitations on the scope of the disclosure, but rather as descriptions of features that may be specific to particular embodiments. Some features that are described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable subcombination.

[0195] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it should be understood that the present disclosure, as defined in the appended claims, is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A user equipment (UE), comprising: means for receiving a conditional reconfiguration from a master node (MN) in a dual connection, the conditional reconfiguration including a secondary node (SN) counter value; means for deriving a security key for subsequent mobility using a first unused SN counter value selected from the SN counter values; A UE comprising:

2. Means for transmitting a Radio Resource Control (RRC) reconfiguration complete message to the MN, the message including the first unused SN counter value; The UE of claim 1 further comprising:

3. means for selecting the first unused SN counter value from among the SN counter values; means for removing the first unused SN counter value from the SN counter values; The UE of claim 1 or 2, further comprising: Claim 4: The subsequent mobility includes a conditional PSCell change.

3. The UE according to claim 1 or 2.

5. Each of the SN counter values ​​is sk-Counter 3. The UE according to claim 1 or 2.

6. The dual connection is a multi-radio dual connection (MR-DC: Multi-Radio Dual Connectivity).

3. The UE according to claim 1 or 2.

7. A radio access network (RAN) node that functions as a master node (MN) in a dual connection, comprising: means for transmitting a conditional reconfiguration including a Secondary Node (SN) counter value to a User Equipment (UE); A security key for subsequent mobility is derived in the UE using a first unused SN counter value selected from the SN counter values. RAN node.

8. Means for receiving a Radio Resource Control (RRC) reconfiguration complete message from the UE, the message including the first unused SN counter value. The RAN node of claim 7 further comprising:

9. means for deriving a security key corresponding to said SN counter value; means for sending an Xn message including said security key to an SN; 9. The RAN node of claim 7 or 8, further comprising:

10. The subsequent mobility includes a conditional PSCell change.

9. A RAN node according to claim 7 or 8.

11. The method of claim 10, wherein each of the SN counter values ​​is a sk-Counter.

9. A RAN node according to claim 7 or 8.

12. The dual connectivity is multi-radio dual connectivity (MR-DC).

9. A RAN node according to claim 7 or 8.

13. A radio access network (RAN) node that functions as a secondary node (SN) in a dual connection, comprising: means for receiving an Xn message from a Master Node (MN) including a security key corresponding to an SN counter value; A security key for subsequent mobility is derived in a user equipment (UE) using a first unused SN counter value selected from the SN counter values. RAN node.

14. A means for selecting the first unused SN counter value of the UE; The RAN node of claim 13 further comprising:

15. A means for selecting an appropriate security key based on the SN counter value.

15. The RAN node of claim 13 or 14, further comprising:

16. The subsequent mobility includes a conditional PSCell change. RAN node according to claim 13 or 14.

17. The method of claim 16, wherein each of said SN counter values ​​is a sk-Counter. RAN node according to claim 13 or 14.

18. The dual connectivity is multi-radio dual connectivity (MR-DC). RAN node according to claim 13 or 14.

19. A method for a user equipment (UE), comprising: receiving a conditional reconfiguration from a master node (MN) in a dual connection, the conditional reconfiguration including a secondary node (SN) counter value; deriving a security key for subsequent mobility using a first unused SN counter value selected from the SN counter values; A method comprising:

20. A method of a Radio Access Network (RAN) node functioning as a Master Node (MN) in a dual connection, comprising: sending a conditional reconfiguration to a User Equipment (UE) that includes a Secondary Node (SN) counter value; A security key for subsequent mobility is derived in the UE using a first unused SN counter value selected from the SN counter values. method.

21. A method of a Radio Access Network (RAN) node functioning as a Secondary Node (SN) in a dual connection, comprising: receiving an Xn message from a Master Node (MN) including a security key corresponding to an SN counter value; A security key for subsequent mobility is derived in a user equipment (UE) using a first unused SN counter value selected from the SN counter values. method.

Citation Information

Patent Citations

  • Determining security keys

    WO2021064032A1