Communication device, base station, and communication method
By dynamically updating security keys using counter values for each cell change, the communication device and base station systems address the issue of inadequate protection in dual connectivity, ensuring secure communication in mobile systems.
Patent Information
- Application Number
- JP2024574467
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-01-31
- Filing Date
- 2024-01-23
- Publication Date
- 2025-11-26
- Estimated Expiration
- 2044-01-23
AI Technical Summary
In mobile communication systems with dual connectivity, the communication device faces inadequate protection of communication with the secondary node due to the reuse of the same security key when changing primary secondary cells without receiving the latest counter value, which can compromise the security of the communication.
The communication device and base station systems are configured to derive and update security keys using updated counter values for each candidate target primary secondary cell, ensuring appropriate protection by changing the security key with each cell change.
This approach ensures secure and continuous communication protection by dynamically updating security keys, preventing the reuse of the same key across cell changes, thereby maintaining effective security in dual connectivity scenarios.
Smart Images

Figure 0007776030000001 
Figure 0007776030000002 
Figure 0007776030000003
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application is based on and claims the benefit of priority from patent application serial number 2023-013393, filed January 31, 2023, the entire contents of which are incorporated herein by reference. [Technical Field]
[0002] The present disclosure relates to a communication device, a base station, and a communication method. [Background technology]
[0003] Dual Connectivity (DC) has been introduced in mobile communication systems that comply with the technical specifications of 3GPP (Third Generation Partnership Project), a standardization project for mobile communication systems. In DC, a communication device communicates with a master cell group (MCG) associated with a master node (also referred to as a "master base station") and a secondary cell group (SCG) associated with a secondary node (also referred to as a "secondary base station").
[0004] In the 3GPP technical specifications, the master node transmits a security key (specifically, KSN) to the secondary node and also transmits a counter value (specifically, SN counter) used to derive the security key to the communication device. The communication device derives the security key using the counter value, and then derives a key used to protect communication with the secondary node using the derived security key (see Non-Patent Document 1).
[0005] Recently, selective SCG activation has been discussed to enable continuous cell changes when a communication device moves at high speed, for example. In selective SCG activation, multiple conditional reconfigurations are configured for the communication device to set multiple candidate target primary secondary cells (candidate target PS cells) while the communication device remains connected to the same primary cell (P cell). The communication device changes the PS cell from the source PS cell to the candidate target PS cell by performing conditional reconfiguration for a candidate target PS cell for which an execution condition is satisfied among the multiple conditional reconfigurations. Even after the PS cell change, the communication device can continuously change cells by changing the PS cell using the multiple conditional reconfigurations it has retained. [Prior art documents] [Non-patent literature]
[0006] [Non-Patent Document 1] 3GPP TS 33.501 V17.8.0 “Security architecture and procedures for 5G System” Summary of the Invention
[0007] A communication device according to a first aspect is a communication device (100) that communicates with a master cell group associated with a master node (MN200M) and a secondary cell group associated with a secondary node (SN200S). The communication device includes: a receiver (112) that receives, from the master node, a radio resource control (RRC) reconfiguration message including configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells in the communication device and information on a counter value used to derive a security key for the secondary node; a controller (120) that determines a cell for which an execution condition is satisfied from the plurality of candidate cells and derives the security key for the secondary node associated with the determined cell using the counter value; and a transmitter (111) that transmits the counter value used to derive the security key to a network (10).
[0008] A base station according to a second aspect is a base station (200) that operates as a master node in a network (10) including a master node (MN200M) associated with a master cell group configured in a communication device (100) and a secondary node (SN200S) associated with a secondary cell group configured in the communication device. The base station includes: a transmitter (211) that transmits, to the communication device, a radio resource control (RRC) reconfiguration message including configuration information used to configure, in the communication device, a plurality of conditional reconfigurations for configuring a plurality of candidate cells; and a receiver (212) that receives a counter value used when the communication device derives a security key of the secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate cells.
[0009] A base station according to a third aspect is a base station (200) operating as the secondary node in a network (10) including a master node (MN200M) associated with a master cell group configured in a communication device (100) and a secondary node (SN200S) associated with a secondary cell group configured in the communication device. The base station includes a receiving unit (212) that receives, from the master node that transmits to the communication device configuration information used to configure, in the communication device, a plurality of conditional reconfigurations for configuring a plurality of candidate cells, a counter value used in the communication device to derive a security key of the secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate cells.
[0010] A communication method according to a fourth aspect is a communication method executed by a communication device (100) that communicates with a master cell group associated with a master node (MN200M) and a secondary cell group associated with a secondary node (SN200S). The communication method includes the steps of receiving a radio resource control (RRC) reconfiguration message from the master node, the radio resource control (RRC) reconfiguration message including configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells in the communication device and information on a counter value used to derive a security key for the secondary node, determining a cell from the plurality of candidate cells for which an execution condition is satisfied, deriving the security key for the secondary node associated with the determined cell using the counter value, and transmitting the counter value used to derive the security key to a network (10). [Brief explanation of the drawings]
[0011] The objects, features, advantages, and other features of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings. [Figure 1] FIG. 1 is a diagram showing a configuration of a mobile communication system according to an embodiment. [Figure 2]FIG. 2 is a diagram illustrating an example of the configuration of a protocol stack in the mobile communication system according to the embodiment. [Figure 3] FIG. 3 is a diagram illustrating an overview of dual connectivity (DC) according to the embodiment. [Figure 4] FIG. 4 is a sequence diagram illustrating an example of security in a DC. [Figure 5] FIG. 5 is a diagram for explaining the assumed scenario. [Figure 6] FIG. 6 is a diagram illustrating a configuration of a user equipment (UE) according to the embodiment. [Figure 7] FIG. 7 is a diagram illustrating a configuration of a base station according to the embodiment. [Figure 8] FIG. 8 is a sequence diagram (part 1) of the first operation example according to the embodiment. [Figure 9] FIG. 9 is a sequence diagram (part 2) of the first operation example according to the embodiment. [Figure 10] FIG. 10 is a sequence diagram (part 3) of the first operation example according to the embodiment. [Figure 11] FIG. 11 is a diagram illustrating a configuration example of an RRC Reconfiguration message according to the embodiment. [Figure 12] FIG. 12 is a sequence diagram of an operation example 2 according to the embodiment. [Figure 13] FIG. 13 is a sequence diagram of an operation example 3 according to the embodiment. [Figure 14] FIG. 14 is a sequence diagram of an operation example 4 according to the embodiment. [Figure 15] FIG. 15 is a sequence diagram of an operation example 5 according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] A mobile communication system according to an embodiment will be described with reference to the drawings. In the description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.
[0013] In order to enable continuous cell changes, the communication device uses multiple conditional reconfigurations without resetting even after changing the PS cell, so it is expected that the latest counter value cannot be received from the master node every time the PS cell is changed.
[0014] In this case, the communication device must derive a security key using the same counter value every time it changes the PS cell, for example, to the same cell. As a result, the key used to protect the communication between the communication device and the secondary node becomes the same as the key used previously, which may result in inadequate protection of the communication between the communication device and the secondary node.
[0015] Therefore, one object is to provide a communication device, a base station, and a communication method that can appropriately protect communication between the communication device and a secondary node.
[0016] (Configuration of a mobile communication system) The configuration of a mobile communication system 1 according to an embodiment will be described with reference to Fig. 1. The mobile communication system 1 is, for example, a system that complies with the 3GPP Technical Specification (TS). In the following, the mobile communication system 1 will be described using as an example a 5th Generation System (5GS) of the 3GPP standard, that is, a mobile communication system based on NR (New Radio).
[0017] The mobile communication system 1 includes a network 10 and user equipment (UE) 100 that communicates with the network 10. The network 10 includes a next generation radio access network (NG-RAN) 20 that is a 5G radio access network, and a 5G core network (5GC) 30 that is a 5G core network.
[0018] The UE 100 is an example of a communication device. The UE 100 may be a device used by a user. The UE 100 may be user equipment defined in the 3GPP technical specifications. The UE 100 may be a mobile device such as a mobile phone terminal such as a smartphone, a tablet terminal, a laptop PC, a communication module, or a communication card. The UE 100 may be a vehicle (e.g., a car, a train, etc.) or a device provided therein (e.g., a Vehicle UE). The UE 100 may be a transport vehicle other than a vehicle (e.g., a ship, an airplane, etc.) or a device provided therein (e.g., an Aerial UE). The UE 100 may be a sensor or a device provided therein. The UE 100 may be called by other names such as a mobile station, a mobile terminal, a mobile device, a mobile unit, a subscriber station, a subscriber terminal, a subscriber device, a subscriber unit, a wireless station, a wireless terminal, a wireless device, a wireless unit, a remote station, a remote terminal, a remote device, or a remote unit. Furthermore, the UE 100 is an example of a terminal, and the terminal may include factory equipment or the like.
[0019] The NG-RAN 20 includes multiple base stations 200. Each base station 200 manages at least one cell. A cell constitutes the smallest unit of a communication area. For example, one cell belongs to one frequency (carrier frequency) and is composed of one component carrier. The term "cell" may refer to wireless communication resources or to a communication target of the UE 100. Each base station 200 can perform wireless communication with the UE 100 located in its own cell. The base station 200 communicates with the UE 100 using a RAN protocol stack. The base station 200 is connected to other base stations 200 (which may be referred to as neighbor base stations) via an Xn interface. The base station 200 communicates with the neighbor base stations via the Xn interface. The base station 200 also provides NR user plane and control plane protocol termination for the UE 100 and is connected to the 5GC 30 via an NG interface. Such an NR base station 200 may be referred to as a gNodeB (gNB).
[0020] The 5GC 30 includes a core network device 300. The core network device 300 includes, for example, an Access and Mobility Management Function (AMF) and / or a User Plane Function (UPF). The AMF performs mobility management for the UE 100. The UPF provides functions specialized for user plane processing. The AMF and the UPF are connected to the base station 200 via an NG interface.
[0021] An example of the configuration of a protocol stack in the mobile communication system 1 according to the embodiment will be described with reference to FIG.
[0022] The protocol for the wireless section between UE 100 and base station 200 includes a physical (PHY) layer, a medium access control (MAC) layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, and a radio resource control (RRC) layer.
[0023] The PHY layer performs encoding / decoding, modulation / demodulation, antenna mapping / demapping, and resource mapping / demapping. Data and control information are transmitted between the PHY layer of the UE 100 and the PHY layer of the base station 200 via a physical channel.
[0024] A physical channel consists of multiple Orthogonal Frequency Division Multiplexing (OFDM) symbols in the time domain and multiple subcarriers in the frequency domain. One subframe consists of multiple OFDM symbols in the time domain. A resource block is a resource allocation unit and consists of multiple OFDM symbols and multiple subcarriers. A frame can be configured for 10 ms and can include 10 subframes, each of which is 1 ms long. A subframe can include a number of slots according to the subcarrier spacing.
[0025] Among physical channels, the physical downlink control channel (PDCCH) plays a central role for purposes such as downlink scheduling assignment, uplink scheduling grant, and transmit power control. For example, the UE 100 performs blind decoding of the PDCCH using a Cell-Radio Network Temporary Identifier (C-RNTI) and a Modulation and Coding Scheme-C-RNTI (MCS-C-RNTI) or a Configured Scheduling-RNTI (CS-RNTI) assigned to the UE 100 by the base station 200, and acquires successfully decoded DCI as DCI addressed to the UE. Here, CRC parity bits scrambled by the C-RNTI and the MCS-C-RNTI or the CS-RNTI are added to the DCI transmitted from the base station 200.
[0026] In NR, the UE 100 can use a bandwidth narrower than the system bandwidth (i.e., the cell bandwidth). The base station 200 configures the UE 100 with a bandwidth portion (BWP) consisting of consecutive PRBs. The UE 100 transmits and receives data and control signals in the active BWP. For example, up to four BWPs can be configured for the UE 100. Each BWP may have a different subcarrier spacing or may overlap in frequency. When multiple BWPs are configured for the UE 100, the base station 200 can specify which BWP to activate by controlling the downlink. This allows the base station 200 to dynamically adjust the UE bandwidth according to the amount of data traffic of the UE 100, etc., and can reduce UE power consumption.
[0027] For example, base station 200 can configure up to three control resource sets (CORESETs) for each of up to four BWPs on the serving cell. A CORESET is a radio resource for control information to be received by UE 100. Up to 12 CORESETs can be configured for UE 100 on the serving cell. Each CORESET has an index of 0 to 11. For example, a CORESET consists of six resource blocks (PRBs) and one, two, or three consecutive OFDM symbols in the time domain.
[0028] The MAC layer performs data priority control, retransmission processing using Hybrid ARQ (HARQ), random access procedures, etc. Data and control information are transmitted between the MAC layer of UE 100 and the MAC layer of base station 200 via a transport channel. The MAC layer of base station 200 includes a scheduler. The scheduler determines the uplink and downlink transport format (transport block size, modulation and coding scheme (MCS)) and the resources to be allocated to UE 100.
[0029] The RLC layer transmits data to the RLC layer on the receiving side using the functions of the MAC layer and PHY layer. Data and control information are transmitted between the RLC layer of the UE 100 and the RLC layer of the base station 200 via logical channels.
[0030] The PDCP layer performs header compression / decompression and encryption / decryption.
[0031] An SDAP (Service Data Adaptation Protocol) layer may be provided above the PDCP layer, which maps IP flows, which are units for Quality of Service (QoS) control by the core network, to radio bearers, which are units for QoS control by the AS (Access Stratum).
[0032] The RRC layer controls logical channels, transport channels, and physical channels according to the establishment, re-establishment, and release of radio bearers. RRC signaling for various settings is transmitted between the RRC layer of the UE 100 and the RRC layer of the base station 200. When there is an RRC connection between the RRC of the UE 100 and the RRC of the base station 200, the UE 100 is in an RRC connected state. When there is no RRC connection between the RRC of the UE 100 and the RRC of the base station 200, the UE 100 is in an RRC idle state. When the RRC connection between the RRC of the UE 100 and the RRC of the base station 200 is suspended, the UE 100 is in an RRC inactive state.
[0033] The NAS layer located above the RRC layer performs session management and mobility management for the UE 100. NAS signaling is transmitted between the NAS layer of the UE 100 and the NAS layer of the core network device 300 (AMF). Note that the UE 100 has an application layer and the like in addition to a radio interface protocol.
[0034] (DC Overview) An overview of dual connectivity (DC) according to the embodiment will be described with reference to FIG.
[0035] In DC, the UE 100 simultaneously communicates with a master cell group (MCG) managed by a master node (MN) 200M and a secondary cell group (SCG) managed by a secondary node (SN) 200S. The MN 200M may be an NR base station (gNB) or an LTE base station (eNB). The MN 200M is also referred to as a master base station. In MR-DC (Multi-Radio Dual Connectivity), the master node is a radio access node that provides a control plane connection to the core network. The master node may be a Master eNB (in EN-DC (E-UTRA-NR Dual Connectivity)), a Master ng-eNB (in NGEN-DC (NG-RAN E-UTRA-NR Dual Connectivity)), or a Master gNB (in NR-DC (NR-NR Dual Connectivity) and NE-DC (NR-E-UTRA Dual Connectivity)).
[0036] The SN 200S may be an NR base station (gNB) or an LTE base station (eNB). The SN 200S is also referred to as a secondary base station. In MR-DC, the secondary node is a radio access node that does not have a control plane connection to the core network and provides additional resources to the UE 100. The secondary node may be an en-gNB (in EN-DC), a Secondary ng-eNB (in NE-DC), or a Secondary gNB (in NR-DC and NGEN-DC).
[0037] For example, the MN 200M transmits a predetermined message (for example, an SN Addition Request message) to the SN 200S, and the MN 200M transmits an RRC Reconfiguration message to the UE 100, thereby starting the DC.
[0038] The UE 100 in the RRC connected state is assigned radio resources by the respective schedulers of the MN 200M and the SN 200S, which are connected to each other via a backhaul network communication unit, and performs radio communication using the radio resources of the MN 200M and the radio resources of the SN 200S. S The network communication unit between the MN 200M and the SN 200 may be an Xn interface or an X2 interface. S communicate with each other via the network communication unit.
[0039] The MN 200M may have a control plane connection with the core network. The MN 200M provides primary radio resources for the UE 100. The MN 200M manages an MCG. The MCG is a group of serving cells associated with the MN 200M. The MCG has a primary cell (PCell) and optionally has one or more secondary cells (SCells).
[0040] The SN200S may not have a control plane connection with the core network. The SN200S provides additional radio resources to the UE100. The SN200S manages the SCG. The SCG is associated with the SN200S. The SCG has a primary and secondary cell (PS cell) and optionally one or more SCells. The PCell of the MCG and the PS cell of the SCG are also called special cells (SpCells).
[0041] (DC security) An example of security in a DC will be explained with reference to FIG.
[0042] In step S11, the UE 100 and the MN 200M establish an RRC connection.
[0043] In step S12, the MN 200M sends an SN addition request message or an SN change request message to the SN 200S. The message may include a security key (KSN) of the target secondary node (specifically, the SN 200S). The security key may be referred to as a secondary key. In addition to the notation "KSN", the security key may be expressed as "KeNB", "KgNB", "S-KeNB", "S-KgNB", or "S-KeNB".
[0044] The MN 200M can calculate a security key and distribute the security key to the SN 200S. The SN 200S derives a key used to protect communication between the UE 100 and the SN 200S based on the security key. The SN 200S can derive, for example, an RRC key and a UP key used between the UE 100 and the SN 200S as the key.
[0045] The RRC key is a key for RRC signaling. The RRC key is a key derived from a security key by the UE 100 and the base station 200. The RRC key may include a key (KRRCint) that is used only for protecting RRC signaling with a specific integrity algorithm, and a key (KRRCenc) that is used only for protecting RRC signaling with a specific encryption algorithm.
[0046] The UP key is a key for uplink (UP) traffic. The UP key is a key derived by the UE 100 and the base station 200 from a security key. The UP key may include a key (KRRCint) that is used only for protecting UP traffic between the UE 100 and the base station 200 with a particular integrity algorithm, and a key (KRRCenc) that is used only for protecting UP traffic with a particular encryption algorithm.
[0047] The MN 200M uses the UE security function and the UP security policy received from the SMF (Session Management Function). of The MN 200M may also include information indicating a decision to enable UP integrity protection and encryption in the message.
[0048] The SN 200S can allocate the necessary resources, select the encryption and integrity algorithms from the configured list that have the highest priority and are also present in the UE security function, and activate the UP security policy.
[0049] In step S13, the SN 200S sends an SN addition request acceptance message or an SN change request consent The UE 100 sends a message to the MN 200M, which may indicate the availability of the requested resources and the identifier of the selected algorithm for the requested Data Radio Bearer (DRB) and / or Signaling Radio Bearer (SRB) for the UE 100.
[0050] In step S14, the MN 200M sends an RRC reconfiguration message to the UE 100 to instruct the UE 100 to configure a new DRB and / or SRB for the SN 200S.
[0051] The MN 200M may include an SN counter in the RRC reconfiguration message. The SN counter indicates a counter value used to derive a security key. The SN counter may be a parameter indicating that a new KSN is required.
[0052] In addition, the MN 200M may include this information in the RRC reconfiguration message in order to transfer UE configuration parameters including, for example, an algorithm identifier received from the SN 200S, UP integrity protection, and encryption instruction.
[0053] After verifying the integrity, the UE 100 accepts the RRC reconfiguration message. If the message includes an SN counter, the UE 100 derives (calculates) a security key for the SN 200S based on the counter value indicated by the SN counter. The UE 100 also derives (calculates) the required RRC and UP keys based on the derived security key. The UE 100 activates RRC and UP protection according to the received instructions for each associated SRB and / or DRB.
[0054] In step S15, the UE 100 sends an RRC reconfiguration complete message to the MN 200M. The UE 100 activates the selected ciphering / decryption and integrity protection keys with the SN 200S at this point.
[0055] In step S16, the MN 200M sends an SN reconfiguration completion message to the SN 200S to notify the SN 200S of the configuration result. In response to receiving the message, the SN 200S can activate the selected encryption / decryption and integrity protection with the UE 100. If the SN 200S does not activate encryption / decryption and integrity protection at this stage, it activates encryption / decryption and integrity protection in response to receiving a random access request from the UE 100.
[0056] In step S17, the UE 100 and the SN 200S execute a random access procedure. As a result, the UE 100 communicates with the MCG managed by the MN 200M and the SCG managed by the SN 200S in the DC. In this way, the SN 200S applies the security key to derive the RRC key and the UP key, enables encryption and decryption for the UE 100, and can communicate with the UE 100.
[0057] (Assumed scenario) An assumed scenario will be described with reference to FIG. 5. In recent years, selective SCG activation has been discussed to enable continuous cell changes when, for example, the UE 100 moves at high speed. In selective SCG activation, multiple conditional reconfigurations are configured for the UE 100 to set multiple candidate target primary secondary cells (candidate target PS cells) while the UE 100 remains connected to the same P cell. The UE 100 performs conditional reconfiguration for a candidate target PS cell for which an execution condition is satisfied among the multiple conditional reconfigurations, thereby changing the PS cell from the source PS cell to the candidate target PS cell. Even after the PS cell change, the UE 100 can continuously change cells by changing the PS cell using the multiple conditional reconfigurations it has retained.
[0058] Here, in order to enable continuous cell changes, UE100 uses multiple conditional reconfigurations without resetting them even after changing the PS cell, so it is assumed that UE100 will not be able to receive the latest counter value (specifically, the SN counter) from MN200M every time it changes the PS cell.
[0059] In this case, the UE 100 must derive a security key using the same counter value every time the UE 100 changes the PS cell, for example, to the same cell. As a result, the key used to protect the communication between the UE 100 and the SN 200S becomes the same as the key used previously, which may result in inappropriate protection of the communication between the UE 100 and the SN 200S.
[0060] For example, as shown in Fig. 5, the MN 200M manages the MCG (P cell). The SN 200S1 manages cells C11 and C12. The SN 200S2 manages cells C21 and C22. The SN 200S3 manages cells C31 and C32.
[0061] The UE 100 communicates with a cell C11, which is an MCG of the MN 200M and an SCG of the SN 200S1, via DC. Assume that the UE 100 has been configured with a plurality of conditional reconfigurations for each of the cells C11, C12, C21, C22, C31, and C32.
[0062] As shown by path A in Fig. 5, in a case where UE 100 changes the PS cell from cell C11 to cell C21 using multiple pre-set conditional reconfigurations and then changes the PS cell from cell C21 to cell C11, the PS cell can be changed without receiving an RRC reconfiguration message from MN 200M as in step S14 in Fig. 4. Therefore, when changing the PS cell from cell C21 to cell C11, UE 100 derives a security key by using the counter value used before changing the PS cell to cell C21 as it is. As a result, even if multiple PS cell changes are performed, UE 100 will protect communication by using the same security key when using cell C11 as the PS cell.
[0063] Furthermore, since the SN 200S1 associated with the cell C11 and the cell C12 is the same, in a case where the UE 100 changes the PS cell from the cell C11 to the cell C21 and then changes the PS cell from the cell C21 to the cell C12 using multiple pre-configured conditional reconfigurations as shown in path B in Fig. 5, the counter values are currently the same in the respective settings of the cell C11 and the cell C12. Therefore, as with path A, even if multiple PS cell changes are performed, the UE 100 will protect its communications by using the same security key when it uses the cell C11 and the cell C12 as the PS cell.
[0064] Conventionally, a security key was changed for safety reasons every time the PS cell was changed, but with selective SCG activation, when the PS cell is changed to a specific cell, the same security key is used to protect communication, which raises concerns that communication between the UE 100 and the SN 200S may not be properly protected. In one embodiment described later, an operation for enabling proper protection of communication between the UE 100 and the SN 200S will be described.
[0065] (Configuration of user device) The configuration of the UE 100 according to the embodiment will be described with reference to Fig. 6. The UE 100 includes a communication unit 110 and a control unit 120.
[0066] The communication unit 110 performs wireless communication with the base station 200 by transmitting and receiving radio signals to and from the base station 200. The communication unit 110 has at least one transmission unit 111 and at least one reception unit 112. The transmission unit 111 and the reception unit 112 may be configured to include multiple antennas and RF circuits. The antenna converts a signal into radio waves and radiates the radio waves into space. The antenna also receives radio waves in space and converts the radio waves into a signal. The RF circuit performs analog processing of the signal transmitted and received via the antenna. The RF circuit may include a high-frequency filter, an amplifier, a modulator, a low-pass filter, etc.
[0067] The control unit 120 performs various controls in the UE 100. The control unit 120 controls communication with the base station 200 via the communication unit 110. The operations of the UE 100 described above and below may be controlled by the control unit 120. The control unit 120 may include at least one processor capable of executing a program and a memory that stores the program. The processor may execute the program to perform the operations of the control unit 120. The control unit 120 may include a digital signal processor that performs digital processing of signals transmitted and received via the antenna and the RF circuit. The digital processing includes processing of a RAN protocol stack. The memory stores programs executed by the processor, parameters related to the programs, and data related to the programs. The memory may include at least one of a read-only memory (ROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a random access memory (RAM), and a flash memory. All or a part of the memory may be included in the processor.
[0068] The UE 100 configured in this manner communicates with the MCG associated with the MN 200M and the SCG associated with the SN 200S. The receiving unit 112 receives from the MN 200M configuration information used to configure the UE 100 with multiple conditional reconfigurations for configuring multiple candidate target primary secondary (PS) cells. The control unit 120 executes the conditional reconfiguration for a cell among the multiple candidate target PS cells for which an execution condition is satisfied. The configuration information includes information on a counter value used to derive a security key for the target SN 200S associated with the cell. The control unit 120 updates the counter value when executing the conditional reconfiguration. As a result, even when the PS cell is changed to a specific cell, communication protection is achieved using a different security key, so that communication between the UE 100 and the SN 200S can be appropriately protected.
[0069] Furthermore, the receiving unit 112 receives from the MN 200M configuration information used to configure the UE 100 with multiple conditional reconfigurations for configuring multiple candidate target primary secondary (PS) cells. The control unit 120 updates a counter value used to derive a security key for the target SN 200S associated with a cell for which an execution condition is satisfied from among the multiple candidate target PS cells. The transmitting unit 111 transmits, to the network 10, identification information for identifying the security key derived based on the updated counter value. This allows the network 10 to know the security key derived based on the counter value updated by the UE 100, thereby enabling appropriate protection of communication between the UE 100 and the SN 200S.
[0070] (Base station configuration) The configuration of the base station 200 according to the embodiment will be described with reference to Fig. 7. The base station 200 includes a communication unit 210, a network communication unit 220, and a control unit 230.
[0071] The communication unit 210 receives a radio signal from the UE 100 and transmits the radio signal to the UE 100, for example. The communication unit 210 has at least one transmission unit 211 and at least one reception unit 212. The transmission unit 211 and the reception unit 212 may be configured to include an RF circuit. The RF circuit performs analog processing of a signal transmitted and received via an antenna. The RF circuit may include a high-frequency filter, an amplifier, a modulator, a low-pass filter, etc.
[0072] The network communication unit 220 transmits and receives signals to and from the network. For example, the network communication unit 220 receives signals from adjacent base stations connected via an Xn interface, which is an interface between base stations, and transmits the signals to the adjacent base stations. The network communication unit 220 also receives signals from the core network device 300 connected via an NG interface, and transmits the signals to the core network device 300.
[0073] The control unit 230 performs various controls in the base station 200. The control unit 230 controls, for example, communication with the UE 100 via the communication unit 210. The control unit 230 also controls, for example, communication with a node (e.g., a neighboring base station, the core network device 300) via the network communication unit 220. The operations of the base station 200 described above and below may be operations controlled by the control unit 230. The control unit 230 may include at least one processor capable of executing a program and a memory that stores the program. The processor may execute the program to perform the operations of the control unit 230. The control unit 230 may include a digital signal processor that performs digital processing of signals transmitted and received via the antenna and the RF circuit. The digital processing includes processing of a protocol stack of the RAN. The memory stores the program executed by the processor, parameters related to the program, and data related to the program. All or a part of the memory may be included in the processor.
[0074] The base station 200 configured in this manner operates as the MN 200M in the network 10 including the MN 200M associated with the MCG configured in the UE 100 and the SN 200S associated with the SCG configured in the UE 100. In the base station 200, the transmitter 211 transmits, to the UE 100, configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells in the communication device. The receiver 212 receives, from the UE 100 that has updated a counter value used to derive a security key of a target secondary node associated with a cell for which an execution condition is satisfied from the plurality of candidate target PS cells, identification information for identifying the security key derived based on the updated counter value.
[0075] Furthermore, the base station 200 operates as the SN 200S in the network 10 including the MN 200M associated with the MCG configured in the UE 100 and the SN 200S associated with the SCG configured in the UE 100. In the base station 200, the receiver 212 receives, via a master node that transmits to the UE 100, configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells in the communication device, from the UE 100 that has updated a counter value used to derive a security key of a target secondary node associated with a cell for which an execution condition is satisfied from among a plurality of candidate target PS cells, identification information for identifying the security key derived based on the updated counter value.
[0076] This allows MN200M or SN200S that receives specific information from MN200M to understand the security key derived based on the counter value updated by UE100, thereby making it possible to appropriately protect communication between UE100 and SN200S.
[0077] (Example of operation of a mobile communication system) An example of the operation of the mobile communication system will be described below. Note that the description of the same content as that already explained may be omitted.
[0078] (Example 1) With reference to Fig. 4 to Fig. 11, an operation example 1 of the mobile communication system 1 according to the embodiment will be described. As shown in Fig. 5 and Fig. 8, it is assumed that DC is set by the UE 100, the MN 200M, and the SN 200S1. At the beginning of Fig. 8, the UE 100 communicates with the MCG (P cell) of the MN 200M and the SCG of the SN 200S1. The cell C11 of the SN 200S1 is the PS cell. In the following, communication between the UE 100 and the MCG (P cell) will be described as communication between the UE 100 and the MN 200M, as appropriate. Similarly, communication between the UE 100 and each SCG (PS cell) will be described as communication between the UE 100 and each SN 200S, as appropriate. Note that the SN 200S3 is omitted in Fig. 8.
[0079] In this operation example, a case where the UE 100 moves along a route B in FIG. 5 will be described as an example.
[0080] As shown in Fig. 8, in step S101, the control unit 230 of the MN 200M initiates a conditional SN change by requesting a candidate target SN to allocate resources to the UE through an SN addition procedure. Specifically, the network (NW) communication unit 220 of the MN 200M transmits an SN addition request message to each candidate target SN. In this operation example, the candidate target SNs are SN 200S1, SN 200S2, and SN 200S3. The NW communication units 220 of the SNs 200S1 to SN 200S3 receive the SN addition request message. Note that the request may indicate that it is for CPAC (Conditional PS Cell Addition / Change).
[0081] The NW communication unit 220 of the MN 200M can provide a candidate cell recommended by the MN 200M based on the latest measurement result so that the candidate target SN selects and configures an SCG cell. The NW communication unit 220 of the MN 200M may be able to provide an upper limit number of PS cells that the candidate target SN can prepare.
[0082] The control unit 230 of each candidate target SN determines a list of PS cells from the list of cells indicated in the measurement results, and also determines SCells of other SCGs.
[0083] In addition, the MN 200M and each SN 200S may also be able to perform the same operation as step S12.
[0084] In step S102, the NW communication unit 220 of each candidate target SN transmits an SN addition request acceptance message to the MN 200M. The NW communication unit 220 of the MN 200M receives the SN addition request acceptance message from each candidate target SN.
[0085] The control unit 230 of each candidate target SN may include an RRC reconfiguration message including a new SCG radio resource configuration in the SN addition request acceptance message. Note that the MN 200M and each SN 200S may also be able to perform an operation similar to step S13.
[0086] In step S103, the transmitting unit 211 of the MN 200M transmits an RRC reconfiguration message to the UE 100. The receiving unit 112 of the UE 100 receives the RRC reconfiguration message from the MN 200M.
[0087] The RRC reconfiguration message includes configuration information used to configure multiple conditional reconfigurations in the UE 100. The multiple conditional reconfigurations are for configuring multiple candidate target PS cells. The configuration information may be information of CPC configuration. As shown in FIG. 11 , the configuration information may be, for example, "RRCReconfiguration-IEs" or "conditionalReconfiguration". The configuration information includes one or more conditional reconfiguration information (e.g., condRRCReconfig). Each conditional reconfiguration information (condRRCReconfig) includes an RRC reconfiguration (RRCReconfiguration) message to be applied when an execution condition is met. The configuration information may be a list of RRC reconfiguration messages associated with the execution conditions.
[0088] The RRC reconfiguration message included in the conditional reconfiguration information includes configuration information for configuring a candidate target PS cell. The RRC reconfiguration message does not include a predetermined field (e.g., a "conditionalReconfiguration" field or a "daps-Config" field). The RRC reconfiguration message includes information on a counter value for deriving a security key for the target SN.
[0089] The counter value information may include an SN counter indicating the counter value. The SN counter may be referred to as an "sk-Counter." The SN counter may be a counter used in initializing and refreshing the security key of the target SN.
[0090] The counter value information may include an initial counter value and an offset value. The initial counter value and the offset value are used to update the counter value. The receiving unit 112 of the UE 100 receives the initial counter value and the offset value from the MN 200M as the counter value information.
[0091] As shown in E11 of FIG. 11, the initial counter value (sk-Counter_ini) and the offset value (OffSN) may be included in the conditional reconfiguration information (condRRCReconfig). In this case, the offset value may be a value that is set individually in each of the multiple pieces of conditional reconfiguration information. Alternatively, as shown in E12 of FIG. 11, the initial counter value (sk-Counter_ini) may be included in the conditional reconfiguration information. As shown in E13 of FIG. 11, the offset value (OffSN) may be included in RRCReconfiguration separately from conditionalReconfiguration. In this case, the offset value may be a value that is set commonly in the multiple pieces of conditional reconfiguration information.
[0092] Furthermore, the counter value information may include a list in which each of a plurality of counter values is associated with the number of PS cell changes. The list may be associated with a setting of an execution condition (e.g., Trigger Event Cfg). The number of PS cell changes NKSN may be a value common to all candidate target PS cells. Therefore, the number of PS cell changes may be counted regardless of which PS cell is changed.
[0093] The counter value information may include a list in which each of a plurality of counter values is associated with the number of PS cell changes for each of a plurality of candidate target SNs. The number of changes NKSN may be a value set individually for each candidate target SN. As the counter value information, for example, a list of a plurality of counter values for each candidate target SN may be arranged in parallel within the RRC reconfiguration information. Furthermore, as the counter value information, for example, each of a plurality of conditional reconfiguration information (condRRCReconfig) may include a list of a plurality of counter values for the target SN that manages the PS cell associated with the conditional reconfiguration information.
[0094] The counter value information may include a list in which each of a plurality of counter values is associated with a PS cell change count NKSN for each of a plurality of candidate target PS cells, and the PS cell change count NKSN may be a value set individually for each candidate target PS cell.
[0095] The configuration information may include information that sets the execution conditions that must be met to trigger execution of the conditional reconfiguration (such as "condExecutionCond", "condExecutionCondSCG", etc.).
[0096] The control unit 120 of the UE 100 applies the RRC reconfiguration completion message and stores the configuration information. Note that the UE 100 and the MN 200M may also be able to perform the same operation as in step S14.
[0097] In step S104, the transmitting unit 111 of the UE 100 transmits an RRC reconfiguration complete message to the MN 200M. The receiving unit 212 of the MN 200M receives the RRC reconfiguration complete message from the UE 100. The UE 100 and the MN 200M can perform the same operation as in step S15. Thereafter, the MN 200M and each SN 200S can perform the same operation as in step S16.
[0098] In step S105, the control unit 120 of the UE 100 measures the radio signals from each cell.
[0099] In step S106, the control unit 120 of the UE 100 evaluates the execution condition based on the measurement result. Specifically, the control unit 120 determines whether the execution condition (event) of the candidate target PS cell is satisfied based on the measurement result. If the execution condition is satisfied, the control unit 120 of the UE 100 regards the target candidate cell associated with the satisfied execution condition as a triggered cell. If there are multiple triggered cells, the control unit 120 selects one cell from the multiple triggered cells for executing conditional reconfiguration. If there is one triggered cell, the control unit 120 regards the cell as a cell selected for executing conditional reconfiguration. The control unit 120 starts executing conditional reconfiguration for the selected cell and performs the following operations. In this operation example, the control unit 120 selects cell C21 and starts executing conditional reconfiguration.
[0100] In step S107, control unit 120 of UE 100 applies the conditional reconfiguration information of the selected cell. As a result, control unit 120 of UE 100 applies the RRC reconfiguration included in the conditional reconfiguration information of the selected cell.
[0101] In step S108, control unit 120 of UE 100 updates the counter value. When conditional reconfiguration is executed, control unit 120 updates the counter value. In this operation example, control unit 120 of UE 100 updates the counter value before starting a random access (RA) procedure by executing conditional reconfiguration.
[0102] The control unit 120 may update the counter value in response to applying the conditional reconfiguration information of the selected cell. The control unit 120 may update the counter value in response to applying the RRC reconfiguration included in the conditional reconfiguration information of the selected cell. The control unit 120 may update the counter value based on the change count NKSN of the PS cell changed from the source PS cell to the target PS cell using the configuration information. The change count NKSN may be replaced with the number of times RRC reconfiguration has been applied. The control unit 120 can update the counter value using any of the following methods.
[0103] In a first method, the control unit 120 may update the counter value by calculating the counter value. The control unit 120 may determine (calculate) the counter value using, for example, the following formula: The control unit 120 may regard the determined counter value (sk-Counter_Mob) as the updated counter value.
[0104] sk-Counter_Mob = sk-Counter_ini + OffKSN × NKSN The initial counter value (sk-Counter_ini) may be a value commonly set for all candidate target PS cells. Alternatively, the initial counter value may be a value individually set for each candidate target PS cell. The initial counter value may be a value individually set for each candidate target SN.
[0105] The offset value (OffKSN) may be a value based on the number of candidate target SNs set by the configuration information. The offset value may be a value that increases according to the number of candidate target SNs. The offset value may, for example, be a value equal to or greater than the number of candidate target SNs set by the configuration information. The control unit 230 of the base station 200 may set the number of candidate target SNs to the offset value. The control unit 120 of the UE 100 may set the number of candidate target SNs to the offset value. Note that the control unit 120 may determine the number of candidate target SNs based on the number of pieces of conditional reconfiguration information. The control unit 120 may determine the number of candidate target SNs based on the number of candidate target SNs included in the conditional reconfiguration information.
[0106] (a) When the change count NKSN is a common value for all candidate target PS cells: As in step S104, when an RRC reconfiguration message is received directly from the MN 200M, the control unit 120 may set the change count NKSN to 0. When the control unit 120 determines that an RRC reconfiguration message included in the conditional reconfiguration information is received because the execution condition is satisfied, the control unit 120 may increment the change count NKSN by 1. Therefore, the control unit 120 counts the number of times the PS cell is changed using the configuration information as the change count NKSN. The control unit 120 may count the change count NKSN of the PS cell every time the PS cell is changed, regardless of which PS cell is changed to.
[0107] (b) When the change count NKSN is a value set individually for each candidate target SN: When an RRC reconfiguration message is received directly from the MN 200M, the control unit 120 may reset the change counts NKSN for all candidate target SNs that have been set in the UE 100 up to that point. The control unit 120 may set the change counts NKSN for all candidate target SNs that have been newly set based on the directly received RRC reconfiguration message, and set each change count NKSN to 0. When the control unit 120 determines that an RRC reconfiguration included in the conditional reconfiguration information has been received because the execution condition is satisfied, and determines that the target SN is different from the source SN (it is an inter-SN CPC), the control unit 120 may increment the change count NKSN associated with the target SN by 1. Therefore, the control unit 120 counts the change count NKSN individually for each candidate target secondary node.
[0108] (c) When the change count NKSN is a value set individually for each candidate target PS cell: When an RRC reconfiguration message is received directly from the MN 200M, the control unit 120 may reset the change counts NKSN for all candidate target PS cells that have been set in the UE 100 up to that point. The control unit 120 may set the change counts NKSN for all candidate target PS cells that have been newly set based on the directly received RRC reconfiguration message, and set each change count NKSN to 0. When the control unit 120 determines that an RRC reconfiguration included in the conditional reconfiguration information has been received because the execution condition is satisfied, the control unit 120 may increment the change count NKSN associated with the target PS cell by 1. Therefore, the control unit 120 counts the change count NKSN individually for each candidate target PS cell.
[0109] In the second method, the control unit 120 updates the counter value based on a list in which each of a plurality of counter values is associated with the change count NKSN. The control unit 120 may set the counter value corresponding to the change count NKSN as the updated counter value. In this case, the control unit 120 may count the change count NKSN of the PS cell every time the PS cell is changed, regardless of which PS cell is changed.
[0110] In a third method, the control unit 120 updates the counter value based on a list in which each of multiple counter values for a corresponding candidate target SN is associated with a change count NKSN. In this case, the control unit 120 sets the change count NKSN for each candidate target SN. The control unit 120 may count the change count NKSN individually for each candidate target SN, and use the counter value corresponding to the change count NKSN associated with the target SN among the multiple counter values as the updated counter value. In this case, the control unit 120 may count the change count NKSN individually for each candidate target secondary node.
[0111] In a fourth method, the control unit 120 updates the counter value based on a list in which each of a plurality of counter values for a corresponding candidate target PS cell is associated with a change count NKSN. In this case, the control unit 120 sets a change count NKSN for each candidate target PS cell. The control unit 120 may count the change count NKSN individually for each candidate target PS cell, and set the counter value corresponding to the change count NKSN associated with the target PS among the plurality of counter values as the updated counter value. In this case, the control unit 120 may count the change count NKSN individually for each candidate target PS cell.
[0112] The control unit 120 may skip updating the counter value when the target SN is associated with both the source PS cell and the target PS cell, i.e., the control unit 230 may skip updating the counter value when performing a PS cell change within the same SN 200S (intra-SN CPC).
[0113] The control unit 120 may determine whether the target SN is associated with both the source PS cell and the target PS cell (is an intra-SN CPC) based on the configuration information currently configured in the UE 100 (e.g., information included in SpCellConfig) and the information included in the conditional reconfiguration information of the selected cell (e.g., MeasObject and / or RRCReconfiguration). The control unit 120 may compare the configuration information currently configured in the UE 100 with the information included in the conditional reconfiguration information of the selected cell, and if the information regarding the source PS cell and the target PS cell is the same, determine that the target SN is associated with both the source PS cell and the target PS cell. Otherwise, the control unit 120 may determine that the target SN is not associated with both the source PS cell and the target PS cell.
[0114] Furthermore, the control unit 120 of the UE 100 may derive (update) a security key based on the updated counter value. The control unit 120 may derive an RRC key and a UP key using the derived security key.
[0115] In step S109, the transmitting unit 111 of the UE 100 transmits an RRC reconfiguration completion message to the MN 200M. The receiving unit 212 of the MN 200M receives the RRC reconfiguration completion message from the UE 100.
[0116] The control unit 120 of the UE 100 may include, in the RRC reconfiguration completion message, identification information for identifying the security key derived based on the updated counter value. As a result, the transmission unit 111 transmits the identification information to the network 10.
[0117] The control unit 120 may include the specific information in a message (for example, an SN RRC reconfiguration complete message described later) that passes through the MN 200M and is sent to the target SN. The control unit 120 may include the message in the RRC reconfiguration complete message. This allows the transmission unit 111 to transmit the specific information to the network 10 by means of a message that passes through the MN 200M and is sent to the target SN.
[0118] The control unit 120 may include the specific information in a message terminated at the MN 200M. The specific information may be included in a field other than the field of the message that is included in the RRC reconfiguration completion message and is sent to the target SN through the MN 200M. This allows the transmission unit 111 to transmit the specific information to the network 10 by a message terminated at the MN 200M.
[0119] The specific information may include an updated security key. The specific information may include an updated counter value. The specific information may include calculation information used to calculate the updated counter value. The calculation information may include, for example, a PS cell change count NKSN used to calculate the updated counter value.
[0120] The control unit 230 of the MN 200M can acquire the specific information when the specific information is included in a field other than the SN RRC reconfiguration complete message field in the RRC reconfiguration complete message, whereas the control unit 230 of the MN 200M does not acquire the specific information when the specific information is included in the SN RRC reconfiguration complete message field in the RRC reconfiguration complete message.
[0121] 9, in step S110, the NW communication unit 220 of the MN 200M may transmit an SN release request message to the SN 200S1. The NW communication unit 220 of the SN 200S1 may receive the SN release request message from the MN 200M. As a result, the MN 200M notifies the SN 200S1, which is the source SN, to stop providing user data.
[0122] In step S111, the NW communication unit 220 of the SN 200S1 may transmit an SN release request acceptance message to the MN 200M. consent The message may be received from SN200S1.
[0123] In step S112, the NW communication unit 220 of the MN 200M transmits an SN reconfiguration completion message to the SN 200S2. The NW communication unit 220 of the SN 200S2 receives the SN reconfiguration completion message from the MN 200M. As a result, the MN 200M notifies the SN 200S2 of the PS cell selected by the UE 100.
[0124] The control unit 230 of the MN 200M may include an SN RRC reconfiguration complete message including the specific information in the SN reconfiguration complete message. As a result, the NW communication unit 220 of the MN 200M transmits the SN RRC reconfiguration complete message including the specific information to the SN 200S2. Alternatively, the control unit 230 of the MN 200M may include the specific information in the SN reconfiguration complete message together with the SN RRC reconfiguration complete message. As a result, if the specific information includes a security key, the NW communication unit 220 of the MN 200M transmits the security key to the SN 200S2. The control unit 230 of the MN 200M may include information for calculating the security key in the SN reconfiguration complete message.
[0125] In step S113, the control unit 230 of the SN 200S2 identifies a security key. In this operation example, the control unit 230 identifies the security key based on the identification information.
[0126] When the identification information includes a security key, the control unit 230 may identify the security key included in the identification information as the security key to be used for protecting communication with the UE 100.
[0127] The control unit 230 may derive a security key based on the information for calculating the security key and the identification information. The control unit 230 may identify the derived security key as the security key to be used for protecting communication with the UE 100.
[0128] The control unit 230 can derive an RRC key and a UP key to be used between the UE 100 and the SN 200S2 based on the identified security key. Note that the MN 200M and the SN 200S2 may also be able to perform the same operation as in step S16.
[0129] In step S114, the UE 100 and the SN 200S2 execute a random access procedure. After that, the UE 100 communicates with the MCG and the cell C21 in the DC.
[0130] Note that control unit 230 of UE 100 may update the counter value at a timing other than step S108. For example, control unit 230 may update the counter value after starting the RA procedure to cell C21 by executing conditional reconfiguration, and before transmitting an RRC message to cell C21 in the RA procedure. The RRC message here is, for example, message 3.
[0131] As shown in Fig. 10, steps S115 to S119 are steps S105 to S109. In this operation example, the control unit 120 of the UE 100 selects the cell C12 as the PS cell.
[0132] In step S120, similar to step S110, the NW communication unit 220 of the MN 200M transmits an SN release request message to the SN 200S2. In step S121, similar to step S111, the NW communication unit 220 of the SN 200S2 transmits an SN release request acceptance message to the MN 200M.
[0133] In step S122, similar to step S112, the NW communication unit 220 of the MN 200M transmits an SN reconfiguration completion message to the SN 200S1. In step S123, similar to step S113, the control unit 230 of the SN 200S1 identifies a security key. In step S124, similar to step S114, the UE 100 and the SN 200S1 execute an RA procedure. Thereafter, the UE 100 communicates with the MCG and cell C12 in the DC.
[0134] As described above, in this operation example, the receiving unit 112 of the UE 100 receives from the MN 200M configuration information used to configure the UE 100 with multiple conditional reconfigurations for configuring multiple candidate target PS cells. The control unit 120 executes the conditional reconfiguration for a cell among the multiple candidate target PS cells for which an execution condition is satisfied. The configuration information includes information on a counter value used to derive a security key for a target SN associated with the cell for which the conditional reconfiguration is executed. The control unit 120 updates the counter value when executing the conditional reconfiguration. As a result, even when the PS cell is changed to a specific cell, communication protection is achieved using a different security key, so that communication between the UE 100 and the SN 200S can be appropriately protected. Furthermore, the control unit 120 updates the counter value when executing the conditional reconfiguration, i.e., before changing the PS cell. Therefore, the UE 100 updates the counter value before a security key is used for communication protection, so that communication between the UE 100 and the SN 200S can be appropriately protected.
[0135] Furthermore, the control unit 120 may update the counter value before starting the RA procedure to the cell by performing the conditional reconfiguration. This eliminates the need for the UE 100 to update the counter value in the RA procedure, and allows the RA procedure and subsequent communication to be performed while appropriately protecting the communication between the UE 100 and the SN 200S.
[0136] Furthermore, after starting the RA procedure to the cell by executing the conditional reconfiguration, the control unit 120 updates the counter value before transmitting an RRC message to the cell in the RA procedure. This allows the counter value to be updated before starting communication protection using a key derived based on the security key, and allows the RA procedure and subsequent communication to be performed while appropriately protecting the communication between the UE 100 and the SN 200S.
[0137] Furthermore, the control unit 120 may update the counter value based on the change count NKSN of the PS cell changed from the source PS cell to the target PS cell using the configuration information. Since the change count NKSN changes every time the PS cell is changed, it is possible to avoid deriving a security key using the same counter value.
[0138] Furthermore, the control unit 120 may count the number of times the PS cell is changed using the configuration information as the number of changes. This makes it possible to avoid the UE 100 from storing the number of changes individually for each PS cell, for example, and to reduce the processing load.
[0139] Furthermore, the control unit 120 may count the number of changes individually for each candidate target SN 200S. This allows the UE 100 to avoid, for example, storing the number of changes individually for each PS cell, thereby reducing the processing load. Furthermore, when the PS cell is changed within the SN 200S, the counter value is not changed, thereby suppressing unnecessary increases in the counter value (and the overhead associated therewith).
[0140] Furthermore, the control unit 120 may count the number of changes individually for each candidate target PS cell. This allows the number of changes NKSN to change every time the PS cell is changed, so that it is possible to avoid deriving the same security key even if other items for calculating the counter value are the same.
[0141] Furthermore, the receiving unit 112 may receive, as counter value information, an initial counter value and an offset value used to update the counter value from the MN 200M. As a result, by appropriately changing the initial counter value and the offset value, it becomes possible to change the counter value without significantly changing the existing system that complies with the 3GPP technical specifications in which an SN counter (sk-Counter) is set for each SN 200S. As a result, even when the PS cell is changed to a specific cell, communication protection is achieved using a different security key, so that communication between the UE 100 and the SN 200S can be appropriately protected.
[0142] Furthermore, the initial counter value may be a value that is set individually for each candidate target PS cell, which enables the MN 200M to flexibly control the counter value.
[0143] Furthermore, the initial counter value may be a value that is set commonly to all of the candidate target PS cells. This eliminates the need for the UE 100 to hold multiple initial counter values or select a corresponding initial counter value from the multiple initial counter values regardless of the number of candidate target PS cells, thereby reducing the processing load.
[0144] The offset value may be a value based on the number of candidate target SNs 200S set by the configuration information, so that even if the number of candidate target SNs 200S increases, the counter values calculated based on the offset value will not overlap, making it possible to avoid deriving a security key using the same counter value.
[0145] Furthermore, the counter value information may include a list in which each of a plurality of counter values is associated with the number of changes. The control unit 120 may set the counter value corresponding to the number of changes NKSN as the updated counter value. This eliminates the need for the UE 100 to calculate the counter value using an equation, thereby reducing the processing load.
[0146] Furthermore, the counter value information may include a list in which each of a plurality of counter values is associated with the number of changes for each of a plurality of candidate target PS cells. The control unit 120 may count the number of changes individually for each candidate target PS cell. The control unit 120 may set the counter value corresponding to the number of changes among the plurality of counter values for the corresponding candidate target PS cell as the updated counter value. This eliminates the need for the UE 100 to calculate the counter value using an equation, thereby reducing the processing load.
[0147] Furthermore, the control unit 120 may skip updating the counter value when the target SN 200S is associated with the source PS cell and the target PS cell. Since a security key is assigned to each target SN 200S, when changing the PS cell in the same target SN 200S, the communication between the UE 100 and the SN 200S can be appropriately protected even if the derivation of the security key is omitted. Therefore, the processing load of the UE 100 can be reduced while appropriately protecting the communication.
[0148] In this operation example, the receiving unit 112 of the UE 100 receives from the MN 200M configuration information used to configure the UE 100 with multiple conditional reconfigurations for configuring multiple candidate target primary secondary (PS) cells. The control unit 120 updates a counter value used to derive a security key for a target SN associated with a cell for which an execution condition is satisfied from among the multiple candidate target PS cells. The transmitting unit 111 transmits, to the network 10, identification information for identifying the security key derived based on the updated counter value. This allows the network 10 to know the security key derived based on the counter value updated by the UE 100, thereby enabling appropriate protection of communication between the UE 100 and the SN 200S.
[0149] Furthermore, the transmitting unit 111 of the UE 100 may transmit the specific information including the security key to the network 10. This allows the network 10 to know the security key itself derived by the UE 100. This makes it possible to omit the process of calculating the security key, thereby reducing the processing load.
[0150] Furthermore, the transmitting unit 111 may transmit the specific information including the updated counter value to the network 10. The network 10 can know the security key derived by the UE 100 based on the updated counter value.
[0151] Furthermore, the transmitter 111 may transmit the identification information including the calculation information used to calculate the updated counter value to the network 10. This allows the network 10 to know the security key derived by the UE 100 based on the calculation information.
[0152] Furthermore, the transmitting unit 111 may transmit the identification information to the network 10 by a message that passes through the MN 200M and is sent to the target SN 200S. This allows the UE 100 to transmit directly to the target SN 200S. The target SN 200S can identify the security key by the identification information.
[0153] Furthermore, the transmitting unit 111 may transmit the specific information to the network 10 by a message terminated at the MN 200M. This allows the UE 100 to transmit to the MN 200M. The MN 200M can grasp the specific information.
[0154] In this operation example, in the base station 200 operating as the MN 200M, the transmitter 211 transmits to the UE 100 configuration information used to configure a communication device with multiple conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells. The receiver 212 receives, from the UE 100 that has updated a counter value used to derive a security key of a target secondary node associated with a cell for which an execution condition is satisfied from the plurality of candidate target PS cells, specific information for identifying the security key derived based on the updated counter value. In the base station 200 operating as the SN 200S, the receiver 212 receives, via the MN 200M that transmits to the UE 100 configuration information used to configure a communication device with multiple conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells, specific information for identifying the security key derived based on the updated counter value from the UE 100 that has updated a counter value used to derive a security key of a target SN associated with a cell for which an execution condition is satisfied from the plurality of candidate target PS cells. The MN 200M or the SN 200S that receives the specific information from the MN 200M can grasp the security key derived based on the counter value updated by the UE 100, so that the communication between the UE 100 and the SN 200S can be appropriately protected.
[0155] Furthermore, the receiving unit 212 may receive a message that passes through the master node and is sent to the target secondary node, the message including the identification information. The NW communication unit 220 may transmit the message to the target SN 200S. This allows the target SN 200S to identify the security key using the identification information.
[0156] Furthermore, the identification information may include a security key. The receiving unit 212 may receive the identification information by a message terminated at the MN 200M. The NW communication unit 220 may transmit the security key to the target secondary node. This allows the control unit 230 to grasp the security key itself derived by the UE 100. The process of calculating the security key can be omitted, thereby reducing the processing load.
[0157] (Example 2) An operation example 2 of the mobile communication system 1 according to the embodiment will be described with reference to Fig. 12. In this operation example, the SN 200S2 requests a security key or information for calculating a security key from the MN 200M. Explanations of parts similar to the operation example 1 will be omitted.
[0158] Steps S140 to S142 are the same as steps S110 to S112. In this operation example, the control unit 120 of the UE 100 may include specific information in a message (for example, an SN RRC reconfiguration complete message) sent to the target SN through the MN 200M.
[0159] If the SN reconfiguration completion message (specific information included therein) does not include a security key, the control unit 230 of the SN 200S2 may perform the following operations.
[0160] In step S143, the NW communication unit 220 of the SN 200S2 transmits a request message for requesting a security key or information for calculating a security key to the MN 200M. The NW communication unit 220 of the MN 200M receives the request message from the SN 200S2.
[0161] The request message may include specific information. As a result, the NW communication unit 220 of the MN 200M receives the specific information from the SN 200S2. Note that the request message may be an existing message or a new message.
[0162] In step S144, the NW communication unit 220 of the MN 200M transmits a response message to the request message to the SN 200S2. The NW communication unit 220 of the SN 200S2 receives the response message from the MN 200M.
[0163] The control unit 230 of the MN 200M may derive a security key based on the identification information, similar to step S113. The control unit 230 may include the derived security key in the response message. Alternatively, the control unit 230 may identify calculation information for calculating (deriving) the security key from the identification information based on the identification information. The control unit 230 may include the calculation information in the response message.
[0164] In step S145, similar to step S113, the control unit 230 of the SN 200S2 identifies a security key based on the security key or calculation information included in the response message.
[0165] The control unit 230 may identify the security key included in the response message as the security key to be used for protecting communication with the UE 100. Alternatively, the control unit 230 may derive the security key based on the calculation information and the identification information included in the response message. The control unit 230 may identify the derived security key as the security key to be used for protecting communication with the UE 100.
[0166] Step S146 is similar to step S114.
[0167] As described above, the NW communication unit 220 of the MN 200M may receive the specific information from the SN 200S2. The NW communication unit 220 may transmit the security key or information for calculating the security key to the SN 200S2.
[0168] (Example 3) An operation example 3 of the mobile communication system 1 according to the embodiment will be described with reference to Fig. 13. In this operation example, the MN 200M identifies a security key. Descriptions of parts that are the same as those in the above operation examples will be omitted.
[0169] Steps S160 to S162 are the same as steps S110 to S112. In this operation example, the control unit 120 of the UE 100 may include specific information in a message terminated at the MN 200M (for example, a field other than the SN RRC reconfiguration complete message field in the RRC reconfiguration complete message). The specific information may include an updated counter value or calculation information used to calculate the updated counter value.
[0170] In step S163, similarly to step S113, the control unit 230 of the MN 200M identifies a security key based on the identification information. The control unit 230 may calculate an updated counter value based on the calculation information. The control unit 230 derives a security key based on the updated counter value.
[0171] In step S164, the NW communication unit 220 of the MN 200M transmits the security key to the SN 200S2. The NW communication unit 220 of the MN 200M can transmit the security key to the SN 200S2 by an existing message or a new message. The NW communication unit 220 of the SN 200S2 receives the security key from the MN 200M. The security key is a security key included in the specific information or a security key derived by the control unit 230.
[0172] Step S165 is similar to step S114.
[0173] As described above, the specific information may include the updated counter value or calculation information used to calculate the updated counter value. The control unit 230 may derive a security key based on the updated counter value. The NW communication unit 220 may transmit the security key derived by the control unit 230 to the SN 200S2. This makes it possible to prevent the MN 200M from deriving the security key and the SN 200S2 from deriving the security key, as in existing operations. This makes it possible to reduce the impact on the SN 200S2.
[0174] (Example 4) An operation example 4 of the mobile communication system 1 according to the embodiment will be described with reference to Fig. 14. Descriptions of parts that are the same as those in the operation examples described above will be omitted.
[0175] Currently, when the MN 200M decides to release a connection offloaded to the SN 200S and then decides to resume offloading to the same SN 200S, it keeps the security key fresh by continuing to increment the counter value. Here, because an upper limit value of the counter value is specified, the MN 200M needs to refresh the root key of the 5GAS security key context associated with the counter value (SN counter) before the SN counter rounds up. The MN 200M refreshes the root key by performing an intra-cell handover. The MN 200M resets the counter value when refreshing the root key. Every time the MN 200M changes the SN 200S, the MN 200M notifies the UE 100 of the counter value updated by incrementing or resetting the counter value as the SN counter, so that the UE 100 does not need to maintain the SN counter.
[0176] However, when UE 100 itself updates the counter value, there is a concern that a malfunction may occur if the counter value held by UE 100 is not reset. Therefore, in this operation example, an operation that enables the counter value to be reset appropriately will be described.
[0177] As shown in FIG. 14, step S201 is similar to step S109.
[0178] In step S202, the control unit 230 of the MN 200M determines whether to round up the counter value. In this operation example, the control unit 230 determines whether to round up the counter value based on the specific information received from the UE 100 or the SN 200S.
[0179] If the identification information includes a counter value, the control unit 230 may determine whether the counter value exceeds an upper limit value. If the identification information does not include a counter value, the control unit 230 calculates a counter value based on the identification information. The control unit 230 may determine whether the calculated counter value exceeds an upper limit value. Note that the upper limit value is a value equal to or less than the value at which the counter value is rounded up.
[0180] If the counter value exceeds the upper limit, the control unit 230 may determine that the counter value is rounded up. In this case, the control unit 230 may reset the counter value and execute the process of step S203.
[0181] On the other hand, if the counter value does not exceed the upper limit, the control unit 230 may determine that the counter value will not be rounded up, and in this case, the control unit 230 may end the process.
[0182] In step S203, the transmitting unit 211 transmits the reset counter value to the UE 100. The receiving unit 112 of the UE 100 receives the counter value from the MN 200M.
[0183] The transmitting unit 211 of the MN 200M may transmit the counter value by an RRC reconfiguration message including configuration information for configuring a plurality of conditional reconfigurations, similar to step S103. Alternatively, the transmitting unit 211 of the MN 200M may transmit the counter value to the UE 100 in a new message for resetting the counter value held by the UE 100.
[0184] The control unit 230 of the UE 100 may set the counter value received from the MN 200M, and may set the counter value to, for example, 0. As a result, the counter value held by the UE 100 is reset.
[0185] As described above, the control unit 230 determines whether the counter value is rounded up based on the specific information. As a result, when the counter value is rounded up, the control unit 230 executes a process of resetting the counter value held by the UE 100, thereby making it possible to prevent the counter value held by the UE 100 from being reset and causing a malfunction.
[0186] (Example 5) An operation example 5 of the mobile communication system 1 according to the embodiment will be described with reference to Fig. 15. In this operation example, the UE 100 determines whether to round up the counter value. Descriptions of parts that are the same as those in the operation examples described above will be omitted.
[0187] In step S221, the transmitting unit 211 of the MN 200M may transmit an RRC reconfiguration message including the counter value, similarly to step S103. The receiving unit 112 of the UE 100 may receive the RRC reconfiguration message including the counter value. The RRC reconfiguration message may include an upper limit value.
[0188] In step S222, the control unit 120 of the UE 100 determines whether to round up the counter value, similarly to step S202. If the control unit 120 determines that the counter value is to be rounded up, the control unit 120 may execute the process of step S223. 12 0 may end the process if the counter value does not exceed the upper limit.
[0189] The control unit 120 may make this determination based on a change in the PS cell, or may make this determination based on an update of the counter value.
[0190] In step S223, the transmitting unit 111 of the UE 100 transmits reset information for resetting the counter value to the MN 200M. The transmitting unit 111 can transmit the reset information for resetting the counter value to the MN 200M before the counter value is rounded up. The receiving unit 212 of the MN 200M receives the reset information from the UE 100.
[0191] The control unit 120 of the UE 100 may include the reset information in, for example, the RRC reconfiguration complete message. RRC The reset information may be transmitted to the MN 200M by a reconfiguration completion message. Furthermore, the control unit 120 may include the reset information in a UE assistance information message used to indicate information about the UE 100 to the network. The reset information may be transmitted to the MN 200M by the UE assistance information message.
[0192] The reset information may be, for example, information requesting resetting of a counter value, or may include specific information (for example, a counter value).
[0193] Step S224 is the same as step S203. Based on the reset information, the transmission unit 211 may transmit the reset counter value to the UE 100. Note that, when the reset information includes specific information, the control unit 230 of the MN 200M may execute the process of step S202.
[0194] As described above, the transmitting unit 111 of the UE 100 may transmit reset information for resetting the counter value to the MN 200M before the counter value is rounded up. The receiving unit 212 of the MN 200M receives the reset information from the UE 100. This allows the MN 200M to receive the reset information before the counter value is rounded up. This allows the MN 200M to execute a process of resetting the counter value held by the UE 100 based on the reset information, thereby preventing the counter value held by the UE 100 from being reset and causing a malfunction.
[0195] [Other embodiments] In the above-described embodiment, the processing of steps S110 and S111 (and similar steps thereto) may be omitted. For example, the control unit 230 of the MN 200M may stop (skip) the transmission of an SN release request message when selective SCG activation is being executed. The control unit 230 of the MN 200M may stop (skip) the transmission of an SN release request message when the SN release request message is for a UE 100 configured for selective SCG activation configuration (e.g., multiple conditional reconfigurations). Furthermore, the control unit 230 of the MN 200M may stop (skip) the transmission of the SN release request message based on, for example, specific information received from the UE 100.
[0196] In the third operational example of the above-described embodiment, the processing of step S163 may be executed before the processing of step S162 is executed. In this case, the control unit 230 of the MN 200M may include the identified security key in the SN reconfiguration completion message. In step S162, the NW communication unit 220 of the MN 200M may transmit the security key to the SN 200S2 by the SN reconfiguration completion message. In this case, the processing of step S164 may be omitted.
[0197] In the above-described embodiment, a case where the RA procedure is successful has been described as an example. When the RA procedure fails, the transmitting unit 111 of the UE 100 may transmit failure information indicating the failure of the RA procedure to the MN 200M. Based on the reception of the failure information, the transmitting unit 211 of the MN 200M may transmit, to the UE 100, configuration information for setting a counter value. For example, similar to step S103, the MN 200M may transmit, to the UE 100, configuration information used for setting a plurality of conditional reconfigurations in the UE 100. The control unit 120 of the UE 100 may discard the configuration information stored for selective SCG activation, and perform selective SCG activation based on the configuration information.
[0198] The operational sequences (and operational flows) in the above-described embodiments do not necessarily have to be executed in chronological order according to the order depicted in the flow diagrams or sequence diagrams. For example, the steps in the operations may be executed in an order different from that depicted in the flow diagrams or sequence diagrams, or may be executed in parallel. Some of the steps in the operations may be deleted, or additional steps may be added to the processing. The operational sequences (and operational flows) in the above-described embodiments may be executed independently, or two or more operational sequences (and operational flows) may be executed in combination. For example, some steps in one operational flow may be added to another operational flow, or some steps in one operational flow may be replaced with some steps in another operational flow.
[0199] In the above-described embodiment, an NR-based mobile communication system has been described as an example of the mobile communication system 1. However, the mobile communication system 1 is not limited to this example. The mobile communication system 1 may be a system compliant with a TS of any of LTE (Long Term Evolution) or other generation systems (e.g., 6th generation) of the 3GPP standard. The base station 200 may be an eNB that provides E-UTRA user plane and control plane protocol termination for the UE 100 in LTE. The mobile communication system 1 may be a system compliant with a TS of a standard other than the 3GPP standard. The base station 200 may be an IAB (Integrated Access and Backhaul) donor or an IAB node.
[0200] A program may be provided that causes a computer to execute each process performed by UE 100 or base station 200. The program may be recorded in a computer-readable medium. Using the computer-readable medium, the program can be installed in a computer. Here, the computer-readable medium on which the program is recorded may be a non-transitory recording medium. The non-transitory recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM (Compact Disk Read Only Memory) or a DVD-ROM (Digital Versatile Disk Read Only Memory). Furthermore, circuits that execute each process performed by UE 100 or base station 200 may be integrated, and at least a part of UE 100 or base station 200 may be configured as a semiconductor integrated circuit (chip set, SoC (System On Chip)).
[0201] In the above embodiments, "transmit" may mean processing at least one layer in a protocol stack used for transmission, or may mean physically transmitting a signal wirelessly or via a wired connection. Alternatively, "transmit" may mean a combination of processing at least one layer and physically transmitting a signal wirelessly or via a wired connection. Similarly, "receive" may mean processing at least one layer in a protocol stack used for reception, or may mean physically receiving a signal wirelessly or via a wired connection. Alternatively, "receive" may mean a combination of processing at least one layer and physically receiving a signal wirelessly or via a wired connection. Similarly, "obtain / acquire" may mean obtaining information from stored information, obtaining information from information received from another node, or obtaining information by generating information. Similarly, the terms "based on" and "depending on / in response to" do not mean "based only on" or "depending only on," unless otherwise specified. The phrase "based on" means both "based only on" and "based at least in part on." Similarly, the phrase "depending on" means both "depending only on" and "depending at least in part on." Similarly, "include" and "comprise" do not mean including only the listed items, but may mean including only the listed items or may include additional items in addition to the listed items. Similarly, in this disclosure, "or" does not mean an exclusive or, but does mean a logical or. Furthermore, any reference to elements using designations such as "first," "second," etc., as used in this disclosure does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements.Thus, a reference to a first and a second element does not imply that only two elements may be employed therein or that the first element must precede the second element in some way. In this disclosure, where articles are added by translation, such as a, an, and the in English, these articles shall include the plural unless the context clearly indicates otherwise.
[0202] Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and equivalent modifications. In addition, various combinations and forms, including only one element, more than one element, or less than one element, are also within the scope and spirit of the present disclosure.
[0203] (Addendum) The following additional notes are about the features of the above-described embodiment.
[0204] (Appendix 1) A communication device that communicates with a master cell group associated with a master node and a secondary cell group associated with a secondary node, a receiving unit that receives from the master node configuration information used to configure the communication device with a plurality of conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells; a control unit that updates a counter value used to derive a security key of a target secondary node associated with a cell among the plurality of candidate target PS cells for which an execution condition is satisfied; and a transmitting unit that transmits, to a network, identification information for identifying the security key derived based on the updated counter value; Communication equipment.
[0205] (Appendix 2) The transmitting unit transmits the specific information including the security key to the network. 2. The communication device of claim 1.
[0206] (Appendix 3) The transmitting unit transmits the specific information including the updated counter value to the network. 3. The communication device according to claim 1 or 2.
[0207] (Appendix 4) The transmitting unit transmits the specific information including calculation information used to calculate the updated counter value to the network. 4. A communication device according to any one of claims 1 to 3.
[0208] (Appendix 5) The transmitter transmits the specific information to the network in a message that passes through the master node and is sent to the target secondary node. 5. A communication device according to any one of claims 1 to 4.
[0209] (Appendix 6) The transmitter transmits the specific information to the network by a message terminated at the master node. 6. A communication device according to any one of claims 1 to 5.
[0210] (Appendix 7) The transmitter transmits reset information for resetting the counter value to the master node before the counter value is rounded up. 7. A communication device according to any one of claims 1 to 6.
[0211] (Appendix 8) In a network including a master node associated with a master cell group configured in a communication device and a secondary node associated with a secondary cell group configured in the communication device, a base station operating as the master node, a transmitter configured to transmit, to the communication device, configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells; a receiving unit that receives, from the communication device that has updated a counter value used to derive a security key of a target secondary node associated with a cell among the plurality of candidate target PS cells for which an execution condition is satisfied, identification information for identifying the security key derived based on the updated counter value. Base station.
[0212] (Appendix 9) the receiving unit receives a message that passes through the master node and is sent to the target secondary node, the message including the specific information; a network communication unit that transmits the message to the target secondary node; 9. A base station as defined in claim 8.
[0213] (Appendix 10) The network communication unit receiving the identifying information from the target secondary node; Sending the security key or information for calculating the security key to the target secondary node. 10. The base station described in Supplementary Note 9.
[0214] (Appendix 11) the specific information includes the security key, the receiving unit receives the specific information by a message terminated at the master node, a network communication unit that transmits the security key to the target secondary node; 11. The base station of any one of Supplementary Notes 8 to 10.
[0215] (Appendix 12) the specific information includes the updated counter value or calculation information used to calculate the updated counter value, a control unit that derives the security key based on the updated counter value; a network communication unit that transmits the security key derived by the control unit to the target secondary node. 11. The base station of any one of Supplementary Notes 8 to 10.
[0216] (Appendix 13) a control unit that determines whether the counter value is rounded up based on the specific information; 13. The base station of any one of Supplementary Notes 8 to 12.
[0217] (Appendix 14) The receiving unit receives reset information for resetting the counter value before the counter value is rounded up from the communication device. 13. The base station of any one of Supplementary Notes 8 to 12.
[0218] (Appendix 15) In a network including a master node associated with a master cell group configured in a communication device and a secondary node associated with a secondary cell group configured in the communication device, a base station operating as the secondary node, a receiving unit that receives, via the master node that transmits to the communication device, configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells, from the communication device that has updated a counter value used to derive a security key of a target secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate target PS cells, identification information for identifying the security key derived based on the updated counter value; Base station.
[0219] (Appendix 16) 1. A communication method executed in a communication device that communicates with a master cell group associated with a master node and a secondary cell group associated with a secondary node, comprising: receiving configuration information from the master node used to configure the communication device with a plurality of conditional reconfigurations for configuring a plurality of candidate target primary secondary (PS) cells; updating a counter value used to derive a security key of a target secondary node associated with a cell among the plurality of candidate target PS cells for which an execution condition is satisfied; transmitting identification information to a network for identifying the security key derived based on the updated counter value. Communication method.
[0220] (Appendix 17) A communication device (100) that communicates with a master cell group associated with a master node (MN200M) and a secondary cell group associated with a secondary node (SN200S), a receiving unit (112) that receives a radio resource control (RRC) reconfiguration message from the master node, the radio resource control (RRC) reconfiguration message including configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells in the communication device and information on a counter value used to derive a security key of the secondary node; a control unit (120) that determines a cell that satisfies an execution condition from among the plurality of candidate cells, and derives the security key of the secondary node associated with the determined cell using the counter value; a transmission unit (111) that transmits the counter value used to derive the security key to a network (10). Communication equipment.
[0221] (Appendix 18) The transmitter transmits the counter value used to derive the security key to the master node. 18. The communication device of claim 17.
[0222] (Appendix 19) The transmitter transmits the counter value used to derive the security key to the network in a message that passes through the master node and is sent to the secondary node. 19. The communication device of claim 17 or 18.
[0223] (Appendix 20) The transmitter transmits the counter value used to derive the security key to the network by a message terminated at the master node. 20. The communication device of any one of appendices 17 to 19.
[0224] (Appendix 21) The transmitter transmits an RRC reconfiguration complete message including the counter value to the network. 21. A communication device according to any one of appendices 17 to 20.
[0225] (Appendix 22) In a network (10) including a master node (MN200M) associated with a master cell group set in a communication device (100) and a secondary node (SN200S) associated with a secondary cell group set in the communication device, a base station (200) operating as the master node, a transmitter (211) configured to transmit, to the communication device, a radio resource control (RRC) reconfiguration message including configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells in the communication device; a receiving unit (212) for receiving a counter value used when the communication device derives a security key of the secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate cells. Base station.
[0226] (Appendix 23) the receiving unit receives a message that passes through the master node and is sent to the secondary node, the message including the counter value used to derive the security key; a network communication unit (220) for transmitting the message to the secondary node; 23. The base station of claim 22.
[0227] (Appendix 24) The network communication unit transmits an SN RRC reconfiguration complete message including the message to the secondary node. 24. The base station of claim 23.
[0228] (Appendix 25) In a network (10) including a master node (MN200M) associated with a master cell group set in a communication device (100) and a secondary node (SN200S) associated with a secondary cell group set in the communication device, a base station (200) operating as the secondary node, a receiving unit (212) for receiving, from the master node that transmits to the communication device configuration information used to configure a plurality of conditional resets for configuring a plurality of candidate cells to the communication device, a counter value used in the communication device to derive a security key of the secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate cells; Base station.
[0229] (Appendix 26) a control unit (230) that derives the security key based on the counter value received from the master node; 26. The base station of claim 25.
[0230] (Appendix 27) A communication method executed by a communication device (100) that communicates with a master cell group associated with a master node (MN200M) and a secondary cell group associated with a secondary node (SN200S), receiving a radio resource control (RRC) reconfiguration message from the master node, the message including configuration information used to configure the communication device with a plurality of conditional reconfigurations for configuring a plurality of candidate cells and information on a counter value used to derive a security key for the secondary node; determining a cell from the plurality of candidate cells for which an execution condition is satisfied; deriving the security key of the secondary node associated with the determined cell using the counter value; transmitting the counter value used to derive the security key to a network (10). Communication method.
Claims
1. A communication device (100) that communicates with a master cell group associated with a master node (MN200M) and a secondary cell group associated with a secondary node (SN200S), a receiver (112) for receiving a radio resource control (RRC) reconfiguration message from the master node, the radio resource control (RRC) reconfiguration message including configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells in the communication device and information on a counter value used to derive a security key of the secondary node; a control unit (120) for determining a cell for which an execution condition is satisfied from among the plurality of candidate cells, deriving the security keys of the secondary node associated with the determined cell using the counter value, and deriving from the derived security keys a key used for protecting user plane (UP) traffic with a specific integrity algorithm and a key used for protecting UP traffic with a specific encryption algorithm; a transmission unit (111) that transmits the counter value used to derive the security key to the master node. Communication equipment.
2. The transmitter transmits the counter value used to derive the security key to the master node by a message terminated at the master node. The communication device according to claim 1 .
3. The transmitter transmits an RRC reconfiguration completion message including the counter value to the master node.
3. The communication device according to claim 1 or 2.
4. The transmitter transmits the counter value used to derive the security key to the master node before starting a random access procedure to a cell among the plurality of candidate cells for which an execution condition is satisfied.
3. The communication device according to claim 1 or 2.
5. In a network (10) including a master node (MN200M) associated with a master cell group set in a communication device (100) and a secondary node (SN200S) associated with a secondary cell group set in the communication device, a base station (200) operating as the master node, A transmitter (211) for transmitting a radio resource control (RRC) reconfiguration message to the communication device, the radio resource control (RRC) reconfiguration message including configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells in the communication device; a receiving unit (212) for receiving a counter value used when the communication device derives a security key of the secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate cells; The derived security keys are used to derive keys used for protecting user plane (UP) traffic with a particular integrity algorithm and keys used for protecting UP traffic with a particular encryption algorithm. Base station.
6. the receiving unit receives an RRC reconfiguration completion message including the counter value used to derive the security key; a network communication unit (220) for transmitting an SN RRC reconfiguration complete message including the counter value to the secondary node; The base station of claim 5.
7. The receiving unit receives the counter value used to derive the security key from the communication device before the communication device starts a random access procedure to a cell for which an execution condition is satisfied from among the plurality of candidate cells.
7. The base station according to claim 5 or 6.
8. In a network (10) including a master node (MN200M) associated with a master cell group set in a communication device (100) and a secondary node (SN200S) associated with a secondary cell group set in the communication device, a base station (200) operating as the secondary node, a network communication unit (220) that receives, from the master node that transmits to the communication device configuration information used to configure a plurality of conditional reconfigurations for configuring a plurality of candidate cells to the communication device, a counter value used in the communication device to derive a security key of the secondary node associated with a cell for which an execution condition is satisfied from among the plurality of candidate cells; The derived security keys are used to derive keys used for protecting user plane (UP) traffic with a particular integrity algorithm and keys used for protecting UP traffic with a particular encryption algorithm. Base station.
9. a control unit (230) for deriving the security key based on the counter value received from the master node; The base station of claim 8.
10. The network communication unit (220) receives from the master node the counter value that was transmitted from the communication device to the master node and used to derive the security key before the communication device starts a random access procedure to a cell for which an execution condition is satisfied from among the plurality of candidate cells. The base station according to claim 8 or 9.
11. A communication method executed by a communication device (100) that communicates with a master cell group associated with a master node (MN200M) and a secondary cell group associated with a secondary node (SN200S), receiving a radio resource control (RRC) reconfiguration message from the master node, the message including configuration information used to configure the communication device with a plurality of conditional reconfigurations for configuring a plurality of candidate cells and information on a counter value used to derive a security key for the secondary node; determining a cell from the plurality of candidate cells for which an execution condition is satisfied; deriving the security key of the secondary node associated with the determined cell using the counter value; deriving from the derived security keys a key used for protecting user plane (UP) traffic with a particular integrity algorithm and a key used for protecting UP traffic with a particular encryption algorithm; transmitting the counter value used to derive the security key to the master node. Communication method.
Citation Information
Patent Citations
Method, device and computer storage medium of communication
WO2023155103A1