Secure inter-cell mobility execution centered on L1 / L2

By mapping physical cell identifiers to unique indices and securely transmitting this information, the method ensures secure inter-cell mobility in cellular networks, addressing security risks during handovers.

JP7839363B2Active Publication Date: 2026-04-01RAKUTEN SYMPHONY INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-02-23
Publication Date
2026-04-01

AI Technical Summary

Technical Problem

Current cellular networks face security risks during inter-cell handovers due to insecure message transmissions, which can lead to user location tracking or route tracing.

Method used

Implementing a method that maps physical cell identifiers of target cells to unique indices and securely transmitting this mapping from the base station's aggregated unit control plane to the user equipment, ensuring secure inter-cell mobility without compromising security.

Benefits of technology

Enables secure Layer 1/Layer 2 inter-cell mobility by preventing unauthorized access to user location information during handovers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007839363000001
    Figure 0007839363000001
  • Figure 0007839363000002
    Figure 0007839363000002
  • Figure 0007839363000003
    Figure 0007839363000003
Patent Text Reader

Abstract

In general, the present subject matter relates to secure Layer 1 / Layer 2 (L1 / L2)-centric inter-cell mobility execution. In some implementations, the secure L1 / L2-centric inter-cell mobility execution can include mapping a physical cell identifier (PCI) of at least one L1 / L2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for a user equipment (UE) to an index, and securely transmitting the mapping from a central control unit (CU CP) of the base station to the UE and a serving DU of the base station currently serving the UE for at least one service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] [Cross - reference to Related Applications] This application claims priority to Indian Patent Application No. 202221061428 titled "Method and System for Secure Cell - to - Cell Mobility Execution Centered around L1 / L2" filed on October 28, 2022, the entire content of which is incorporated herein by reference.

[0002] [Technical Field] In some implementations, the present subject matter relates to a communication system, and more particularly, to secure layer 1 / layer 2 (L1 / L2) centered cell - to - cell mobility execution.

Background Art

[0003] In today's world, cellular networks provide on - demand communication capabilities to individuals and business entities. Typically, a cellular network is a wireless network that can be distributed over geographical areas called cells. Each such cell is served by at least one fixed - location transceiver represented as a cell site or base station. Each cell can use a different set of frequencies from its neighboring cells to avoid interference and provide improved services within each cell. By combining cells, wireless coverage over a wide geographical area is provided such that a large number of mobile phones and / or other wireless devices or portable transceivers can communicate with each other and with fixed transceivers and telephones anywhere in the network. Such communication is carried out through base stations and is realized even when the mobile transceiver in communication passes through more than one cell. Major wireless communication providers have deployed such cell sites worldwide, enabling communication mobile phones and mobile computing devices to connect to the public switched telephone network and the public Internet.

[0004] A mobile phone is a portable phone capable of receiving and / or making phone and / or data calls via a cell site or communication tower by using radio waves to transmit signals to and from a mobile phone. From the perspective of a large number of mobile phone users, current mobile phone networks provide limited and shared resources. In this regard, cell sites and handsets can change frequencies and use low-power transmitters to allow simultaneous use of the network by many callers with less interference. Cell site coverage can depend on a particular geographical location and / or the number of users who could potentially use the network. For example, in a city, a cell site may have a range of up to about half a mile. In suburban areas, the range can be as much as 5 miles. In some areas, users can receive signals from cell sites as far as 25 miles away.

[0005] The following are some examples of digital cellular technologies used by telecommunications providers: Global System for Mobile Communications (“GSM”), General Packet Radio Service (“GPRS”), cdmaOne, CDMA2000, Evolution-Data Optimized (“EV-DO”), Enhanced Data Rates for GSM Evolution (“EDGE”), Universal Mobile Telecommunications System (“UMTS”), Digital Enhanced Cordless Telecommunications (“DECT”), Digital AMPS (“IS-136 / TDMA”), and Integrated Digital Enhanced Network (“iDEN”). Long Term Evolution, or 4G LTE, developed by the Third Generation Partnership Project (“3GPP”) standardization body, is a standard for high-speed data wireless communication for mobile phones and data terminals. Currently, 5G standards are under development and deployment. 3GPP cellular technologies such as LTE and 5G NR are evolutions of previous generation 3GPP technologies such as GSM / EDGE and UMTS / HSPA digital cellular technologies, enabling increased capacity and speed through improvements to the core network and the use of different radio interfaces.

[0006] A cellular network can be divided into a radio access network and a core network. The radio access network (RAN) may include network functions capable of handling radio layer communication processing. The core network may include network functions capable of handling higher layer communications (e.g., Internet Protocol (IP), transport layer, and application layer). In some cases, the RAN functions can be divided into baseband unit functions and radio unit functions. Here, radio units connected to baseband units via a fronthaul network may handle lower layer processing of the radio physical layer, for example, while baseband units may handle higher layer radio protocols (e.g., MAC, RLC, etc.). [Overview of the project] [Problems that the invention aims to solve]

[0007] A base station for a 5G cellular network may include an aggregation unit (CU), one or more distributed units (DUs) communicatively coupled to the CU, and one or more radio units (RUs), each configured to communicatively coupled to at least one of the one or more DUs and each to communicatively coupled to one or more cellular and / or other user equipment (UEs). The CU may be logically separated into a control plane portion (CU-CP) and one or more user plane portions (CU-UP). During communicative coupling of an UE to a base station, the DU supporting the UE may change. To achieve such a handover from one DU to another, an insecure message may be sent to the UE802, but this raises the risk of a security breach, which carries the risk of the user's route being tracked or the user's location being traced. [Means for solving the problem]

[0008] Some implementations describe how the subject is computer-implemented. The method may include mapping the physical cell identifier (PCI) of at least one L1 / L2 trigger mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for a user equipment (UE) to an index, and securely transmitting the mapping from the base station's aggregated unit control plane (CU CP) to the UE and the serving DU of the base station currently serving the UE for at least one service.

[0009] This method could enable inter-cell mobility, primarily L1 / L2, without compromising security.

[0010] In some implementations, the subject may include one or more of the following optional features:

[0011] In some implementations, the index for each of at least one LTM target cells may be unique in the mapping, such that each index is uniquely associated with at least one LTM target cell by PCI.

[0012] In some implementations, the method may also include securely sending the mapping from the CU-CP to a target DU containing one of the LTM target cells selected for the HO.

[0013] In some implementations, the mapping may be sent to the UE in a Radio Resource Control (RRC) reconfiguration message, and to the Serving DU in an F1 UE context change request message.

[0014] In some implementations, the method may also include updating the mapping in accordance with at least one of the following: at least one LTM target cell is excluded for the UE, at least one LTM target cell is replaced for the UE, and securely sending the updated mapping from the CU CP to the UE and the Serving DU.

[0015] In some implementations, the method may also include mapping the PCI of at least one LTM target cell of at least one target DU that is a candidate for HO for the second UE to an index, and securely sending the second mapping from the CU CP to the second UE, so that a second mapping is generated.

[0016] In some implementations, the serving DU can use the index received from the CU-CP when sending an LTM HO command to the UE.

[0017] In some implementations, each index can be a number, a letter, or an alphanumeric character.

[0018] In some implementations, the method may also include storing the mapping in at least one non-temporary storage medium.

[0019] In some implementations, a base station may include a Next Generation Radio Access Network (NG-RAN) node. Furthermore, an NG-RAN node may include a gNodeB or an ng-eNodeB.

[0020] In some implementations, the base station may include at least one processor and at least one non-temporary storage medium. Furthermore, the CU-CP may include at least one processor and at least one non-temporary storage medium.

[0021] Also described are non-temporary computer program products (i.e., physically embodied computer program products) that store instructions causing at least one data processor to perform the operations described herein when executed by one or more data processors of one or more computing systems. Similarly, computer systems that may include one or more data processors and memory coupled to one or more data processors are also described. The memory may temporarily or permanently store instructions causing at least one processor to perform one or more of the operations described herein. In addition, the method may be implemented by one or more data processors within a single computing system or distributed across two or more computing systems. Such computing systems are connected and can exchange data and / or commands or other instructions via one or more connections (including, but not limited to, connections on a network (e.g., the Internet, a wireless wide area network, a local area network, a wide area network, a wired network, etc.)) such as direct connections between one or more multi-computing systems.

[0022] Details of one or more variations of the subject matter described herein are presented in the accompanying drawings and the following description. Other features and advantages of the subject matter described herein will become apparent from the description, drawings, and claims. [Brief explanation of the drawing]

[0023] The following accompanying drawings, which are integrated into and form part of this specification, illustrate certain aspects of the subject matter disclosed herein and help to illustrate, along with the description, some of the principles related to the disclosed implementation.

[0024] Figure 1a shows an exemplary conventional "long term evolution" ("LTE") communication system.

[0025] Figure 1b shows further details of the exemplary LTE system shown in Figure 1a.

[0026] Figure 1c shows additional details of the "evolved packet core" of the exemplary LTE system shown in Figure 1a.

[0027] Figure 1d shows an exemplary "evolved Node B" of the exemplary LTE system shown in Figure 1a.

[0028] Figure 2 illustrates further details of the "evolved Node B" shown in Figures 1a - d.

[0029] Figure 3 shows an exemplary virtual radio access network according to some implementations of the present subject matter.

[0030] Figure 4 shows an exemplary 3GPP split architecture for providing a higher frequency band usage to its users.

[0031] Figure 5a shows an exemplary 5G wireless communication system.

[0032] Figure 5b shows an exemplary layer architecture of a split gNB and / or split ng-eNB (e.g., "next generation eNB" which may be connected to 5GC).

[0033] Figure 5c shows an exemplary functional split in the gNB architecture shown in Figures 5a - b.

[0034] Figure 6a shows an exemplary system according to some implementations of the present subject matter.

[0035] Figure 6b shows an exemplary alternate configuration of the system of Figure 6a according to some implementations of the present subject matter.

[0036] Figure 7 shows an exemplary method according to some implementations of the present subject matter.

[0037] Figure 8 shows illustrative signaling diagrams related to several implementations of the current topic.

[0038] Figure 9 shows an exemplary architecture of the gNB-CU-CP in the signaling diagram of Figure 8, relating to several implementations of the current topic.

[0039] Figure 10 shows exemplary systems related to several implementations of the current topic.

[0040] Figure 11 shows illustrative methods for several implementations of the current topic. [Modes for carrying out the invention]

[0041] The present subject can provide systems and methods that can be implemented in wireless communication systems. Such systems may include a variety of wireless communication systems, including 5G New Radio communication systems, "long term evolution" communication systems, and so on.

[0042] Generally speaking, the current topic concerns the execution of inter-cell mobility, primarily focusing on secure Layer 1 / Layer 2 (L1 / L2) infrastructure.

[0043] In some implementations of the current subject, the gNB-CU-CP (the control plane portion of the gNB (gNodeB) aggregation unit) is configured to generate an index for all cells that are configured as candidates for L1 / L2-centric inter-cell mobility targets. Currently, according to the 3GPP standard (RAN2 agreement), up to eight Layer 1 / Layer 2 Trigger Mobility (LTM) target cells can be prepared for a given user equipment (UE). The gNB-CU-CP is configured to store a mapping between the target cell physical cell identifier (PCI) and the target cell index for future use. Thus, L1 / L2-centric inter-cell mobility can be performed without compromising security.

[0044] 3GPP standards may relate to one or more aspects of the current subject matter. O-RAN Alliance standards may also relate to one or more aspects of the current subject matter.

[0045] One or more aspects of the current subject can be integrated into the transmitter and / or receiver components of base stations (e.g., gNodeB, eNodeB, etc.) in such communication systems. The following is a general discussion of long-term evolutionary communication systems and 5G New Radio communication systems. I. "Long-term evolution" communication systems

[0046] Figures 1a-c and 12 illustrate an exemplary conventional long-term evolution ("LTE") communication system 100 with its various components. The LTE system, or 4G LTE, conforms to the standards for high-speed data wireless communication for mobile phones and data terminals, as is commercially known. The standards are an evolution of GSM / EDGE ("Global System for Mobile Communications" / "Enhanced Data rates for GSM Evolution") and UMTS / HSPA ("Universal Mobile Telecommunications System" / "High Speed ​​Packet Access") network technologies. The standards were developed by 3GPP ("3rd Generation Partnership Project").

[0047] As shown in Figure 1a, System 100 may include an "evolved universal terrestrial radio access network" ("EUTRAN") 102, an "evolved packet core" ("EPC") 108, and a "packet data network" ("PDN") 101, which provides communication between user devices 104 and PDN 101 via EUTRAN 102 and EPC 108. EUTRAN 102 may include multiple "evolved Node B" ("eNodeB" or "ENODEB" or "enodeb" or "eNB") or base stations 106 (a, b, c) (as shown in Figure 1b) that provide communication capabilities to multiple user devices 104 (a, b, c). User devices 104 may be mobile phones, smartphones, tablets, personal computers, personal digital assistants ("PDAs"), servers, data terminals, and / or any other type of user device, and / or any combination thereof. The user device 104 can connect to the EPC 108 and subsequently to the PDN 101 via any eNodeB 106. Typically, the user device 104 can connect to the eNodeB 106 closest in terms of distance. In the LTE system 100, the EUTRAN 102 and EPC 108 work together to provide connectivity, mobility, and services to the user device 104.

[0048] Figure 1b illustrates further details of the network 100 shown in Figure 1a. As previously mentioned, EUTRAN 102 includes multiple eNodeB 106, also known as cell sites. The eNodeB 106 provides radio functionality and performs key control functions, including scheduling of airlink resources or radio resource management, active mode mobility or handover, and admission control for services. The eNodeB 106 is responsible for selecting which mobility management entity (MME, as shown in Figure 1c) serves the user equipment 104, and for protocol features such as header compression and encryption. The eNodeB 106 constituting EUTRAN 102 cooperate with each other for radio resource management and handover.

[0049] Communication between user equipment 104 and eNodeB 106 occurs via air interface 122 (also known as the “LTE-Uu” interface). As shown in Figure 1b, air interface 122 provides communication between user equipment 104b and eNodeB 106a. Air interface 122 uses orthogonal frequency division multiple access (“OFDMA”) and single-carrier frequency division multiple access (“SC-FDMA”), OFDMA variants, on the downlink and uplink, respectively. OFDMA enables the use of multiple known antenna techniques, such as “Multiple Input Multiple Output” (“MIMO”).

[0050] The air interface 122 uses various protocols, including Radio Resource Control ("RRC") for signaling between user equipment 104 and eNodeB 106, and Non-Access Layer ("NAS") for signaling between user equipment 104 and MME (as shown in Figure 1c). In addition to signaling, user traffic is forwarded between user equipment 104 and eNodeB 106. Both signaling and traffic in system 100 are carried by physical layer ("PHY") channels.

[0051] Multiple eNodeB106s can be interconnected using X2 interfaces 130(a, b, c). As shown in Figure 1b, X2 interface 130a provides interconnection between eNodeB106a and eNodeB106b, X2 interface 130b provides interconnection between eNodeB106a and eNodeB106c, and X2 interface 130c provides interconnection between eNodeB106b and eNodeB106c. The X2 interface can be established between two eNodeBs to provide signal exchange, which may include load or interference-related information and handover-related information. The eNodeB106 communicates with the "evolved packet core" 108 via S1 interfaces 124(a, b, c). S1 interface 124 can be divided into two interfaces. One is the control plane (shown as the control plane interface (S1-MME interface) 128 in Figure 1c), and the other is the user plane (shown as the user plane interface (S1-U interface) 125 in Figure 1c).

[0052] The EPC108 establishes and enables Quality of Service ("QoS") for user services, allowing user equipment 104 to maintain a consistent Internet Protocol ("IP") address while in transit. Each node in network 100 has its own IP address. The EPC108 is designed to work with legacy wireless networks. The EPC108 is also designed to separate the control plane (i.e., signaling) and the user plane (i.e., traffic) in the core network architecture, enabling greater flexibility in implementation and independent scalability of control and user data functions.

[0053] The architecture of EPC108 is for packet data and is shown in more detail in Figure 1c. EPC108 includes a Serving Gateway (S-GW) 110, a PDN Gateway (P-GW) 112, a Mobility Management Entity ("MME") 114, a Home Subscriber Server ("HSS") 116 (subscriber database for EPC108), and a Policy Control and Billing Rule Function ("PCRF") 118. Some of these (S-GW, P-GW, MME, and HSS, etc.) are often combined into a node according to the manufacturer's implementation.

[0054] S-GW110 functions as an IP packet data router and is the bearer path anchor for user equipment in EPC108. Therefore, as user equipment moves from one eNodeB106 to another during mobility operations, S-GW110 remains the same, and the bearer path toward EUTRAN102 is switched to speak with the new eNodeB106 serving user equipment 104. If user equipment 104 moves to the domain of another S-GW110, MME114 forwards all of the user equipment's bearer paths to the new S-GW. S-GW110 establishes bearer paths toward one or more P-GW112 for the user equipment. When downstream data is received for idle user equipment, S-GW110 buffers the downstream packets and requests MME114 to identify and re-establish the bearer paths toward and through EUTRAN102.

[0055] P-GW112 is the gateway between EPC108 (and user devices 104 and EUTRAN102) and PDN101 (shown in Figure 1a). P-GW112 acts as a router for user traffic, performing functions on behalf of the user devices. These include assigning IP addresses to user devices, packet filtering of downstream user traffic to ensure it is placed on the appropriate bearer path, and enabling downstream QoS, including data rates. Depending on the services used by the subscriber, there may be multiple user data bearer paths between user device 104 and P-GW112. Subscribers can use services on the PDN served by different P-GWs. In this case, user devices have at least one bearer path established to each P-GW112. If the S-GW110 also changes during a handover of user devices from one eNodeB to another, the bearer path from P-GW112 is switched to the new S-GW.

[0056] The MME114 manages user devices 104 within the EPC108 (including managing subscriber authentication, maintaining context about authenticated user devices 104, establishing data bearer paths in the network for user traffic, and continuing to track the location of idle mobile devices that are not disconnected from the network). For idle user devices 104 that need to be reconnected to the access network to receive downstream data, the MME114 initiates paging to identify the user device and re-establish the bearer path to and through the EUTRAN102. The MME114 for a particular user device 104 is selected by the eNodeB106 from which the user device 104 initiates system access. MMEs are typically part of a collection of MMEs in the EPC108 for load sharing and redundancy purposes. In establishing the user's data bearer path, the MME114 is responsible for selecting the P-GW112 and S-GW110 that constitute the ends of the data path through the EPC108.

[0057] PCRF118 is responsible for policy control decision-making and controlling the flow-based billing function within the policy control enablement function ("PCEF") located within P-GW110. PCRF118 determines how specific data flows are handled in PCEF and provides QoS authorization (QoS class identifier ("QCI") and bitrate) to ensure that this is in line with the user's subscription profile.

[0058] As previously mentioned, IP service 119 is provided by PDN101 (shown in Figure 1a).

[0059] Figure 1d shows an exemplary configuration of eNodeB106. eNodeB106 may include at least one “remote radio head” (“RRH”) 132 (typically there may be three RRHs) and a baseband unit (“BBU”) 134. The RRH 132 may be connected to the antenna 136. The RRH 132 and BBU 134 may be connected using an optical interface compliant with the “common public radio interface” (“CPRI”) / “enhanced CPRI” (“eCPRI”) 142 standard, using a custom control and user plane framing method specific to the RRH or a control and user plane framing method compliant with the O-RAN Alliance. The operation of the eNodeB106 can be characterized using the following standard parameters (and specifications): radio frequency band (Band 4, Band 9, Band 17, etc.), bandwidth (5, 10, 15, 20 MHz), access scheme (downlink: OFDMA; uplink: SC-OFDMA), antenna technology (single-user and multi-user MIMO; uplink: single-user and multi-user MIMO), number of sectors (up to 6), maximum transmit rate (downlink: 150 Mb / s; uplink: 50 Mb / s), S1 / X2 interface (1000Base-SX, 1000Base-T), and mobile environment (up to 350 km / h). The BBU134 can handle digital baseband signal processing, S1 line termination, X2 line termination, call processing, and monitoring control processing. IP packets received from EPC108 (not shown in Figure 1d) can be modulated into digital baseband signals and transmitted to RRH132. Conversely, digital baseband signals received from RRH132 can be demodulated into IP packets for transmission to EPC108.

[0060] The RRH132 can transmit and receive radio signals using antenna 136. The RRH132 can convert digital baseband signals from BBU134 into radio frequency ("RF") signals (using converter ("CONV") 140) and amplify the power for transmission to user equipment 104 (not shown in Figure 1d) (using amplifier ("AMP") 138). Conversely, RF signals received from user equipment 104 are amplified (using AMP 138) and converted into digital baseband signals for transmission to BBU134 (using CONV 140).

[0061] Figure 2 shows additional details of an exemplary eNodeB106. The eNodeB106 comprises multiple layers ("LTE Layer 1" 202, "LTE Layer 2" 204, and "LTE Layer 3" 206). LTE Layer 1 includes the physical layer ("PHY"). LTE Layer 2 includes Media Access Control ("MAC"), Radio Link Control ("RLC"), and Packet Data Convergence Protocol ("PDCP"). LTE Layer 3 includes various functions and protocols, including Radio Resource Control ("RRC"), Dynamic Resource Allocation, eNodeB Measurement Configuration and Provisioning, Radio Admission Control, Connectivity Mobility Control, and Radio Resource Management ("RRM"). The RLC protocol is an "automatic repeat request" ("ARQ") fragmentation protocol used on the cellular air interface. The RRC protocol handles LTE Layer 3 control plane signaling between user equipment and EUTRAN. RRC includes functions for connection establishment and release, broadcasting system information, establishing / reconfiguring and releasing radio bearers, RRC connection mobility procedures, paging notifications and releases, and outer loop power control. PDCP performs IP header compression and decompression, user data transfer, and maintaining sequence numbers for radio bearers. BBU134, shown in Figure 1d, may include LTE layers L1-L3.

[0062] One of the main functions of eNodeB106 is radio resource management, including scheduling of both uplink and downlink air interface resources for user equipment 104, control of bearer resources, and admission control. As an agent for EPC108, eNodeB106 is responsible for forwarding paging messages used to identify idle mobiles. eNodeB106 also communicates common control channel information for the radio, header compression, encryption and decryption of user data transmitted over the radio, and establishes handover reporting and trigger criteria. As previously mentioned, eNodeB106 can collaborate with other eNodeB106s on the X2 interface for handover and interference management purposes. eNodeB106 communicates with the EPC's MME via the S1-MME interface and with the S-GW on the S1-U interface. Furthermore, eNodeB106 exchanges user data with the S-GW on the S1-U interface. eNodeB106 and EPC108 have a many-to-many relationship to support load sharing and redundancy between MMEs and S-GWs. eNodeB106 selects an MME from a group of MMEs so that the load can be shared by multiple MMEs to avoid congestion. II.5G NR Wireless Communication Network

[0063] In some implementations, the current subject concerns the 5G New Radio ("NR") communication system. 5G NR is the successor communication standard to the 4G / IMT-Advanced standard. 5G networks offer higher capacity than current 4G, accommodating more mobile broadband users per unit area and enabling greater and / or unlimited data consumption in gigabytes per month and per user. This could allow users to stream high-definition media on their mobile devices for much of the day (even when it's not possible to do the same on a Wi-Fi network). 5G networks also offer improved support for device-to-device communication, lower costs, lower latency than 4G equipment, and lower battery consumption, among other things. Such networks offer data rates of tens of megabits per second for a large number of users, 100 Mb / s for metropolitan areas, 1 Gb / s for simultaneous users in restricted areas (e.g., office floors), numerous simultaneous connections for wireless sensor networks, improved spectral efficiency, improved coverage, improved signaling efficiency, 1-10 ms latency, and reduced latency compared to existing systems.

[0064] Figure 3 shows an exemplary virtual radio access network 300. The network 300 can provide communication between various components, including base stations (e.g., eNodeB, gNodeB) 301, radio equipment 303, aggregation units 302, digital units 304, and radio devices 306. Components in system 300 may be communicatively coupled to the core using backhaul links 305. Aggregation units ("CU") 302 may be communicatively coupled to distributed units ("DU") 304 using midhaul connections 308. Radio frequency ("RU") components 306 may be communicatively coupled to DU 304 using fronthaul connections 310.

[0065] In some implementations, CU302 can provide intelligent communication capabilities to one or more DU units 304. Units 302, 304 may include one or more base stations, macro base stations, micro base stations, "remote radio heads," etc., and / or any combination thereof.

[0066] In lower layer-split architecture environments, CPRI bandwidth requirements for NR can be several hundred Gb / s. CPRI compression can be implemented in DU and RU (shown in Figure 3). In 5G communication systems, compressed CPRI on Ethernet frames is represented as eCPRI and is the recommended fronthaul network. The architecture can enable fronthaul / midhaul standardization, which may include fronthaul with higher layer-split architectures (e.g., "Option 2" or "Option 3-1" (higher / lower RLC split architecture)) and L1 split architectures ("Option 7").

[0067] In some implementations, a lower layer split architecture (e.g., "Option 7") may include joint processing across multiple transmit points (TPs) for both receivers in the uplink and DL / UL, as well as transport bandwidth and latency requirements for ease of deployment. Furthermore, the lower layer split architecture of the present subject may include a split between cell-level and user-level processing, including cell-level processing at remote units ("RUs") and user-level processing at DUs. Moreover, by using the lower layer split architecture of the present subject, frequency-domain samples that can be compressed to reduce fronthaul bandwidth may be transmitted over the Ethernet fronthaul.

[0068] Figure 4 shows an exemplary communication system 400 that can implement 5G technology and provide users with the use of higher frequency bands (e.g., above 10 GHz). System 400 may include macrocells 402 and small cells 404, 406.

[0069] The mobile device 408 may be configured to communicate with one or more small cells 404, 406. System 400 may enable the separation of the control plane (C-plane) and user plane (U-plane), which utilize different frequency bands, between the macrocell 402 and the small cells 404, 406. In particular, the small cells 404, 406 may be configured to utilize higher frequency bands when communicating with the mobile device 408. The macrocell 402 can utilize existing cellular bands for C-plane communication. The mobile device 408 may be communicatively coupled via the U-plane 412. Here, the small cell (e.g., small cell 406) can provide higher data rates and more flexible / cost-effective / energy-efficient operations. The macrocell 402 can maintain good connectivity and mobility via the C-plane 410. Furthermore, in some cases, LTE and NR may be transmitted on the same frequency.

[0070] Figure 5a shows an exemplary 5G wireless communication system 500 relating to several implementations of the present subject. System 500 may be configured to have a lower layer-split architecture in accordance with "Option 7-2". System 500 may include a core network 502 (e.g., 5G Core) and one or more gNodeBs (or gNBs) which may have aggregation units gNB-CUs. A gNB-CU may be logically separated into a control plane portion (gNB-CU-CP) 504 and one or more user plane portions (gNB-CU-UP) 506. The control plane portion 504 and the user plane portion 506 may be configured to be communicatively coupled using an E1 communication interface 514 (as defined in the 3GPP standard). The control plane portion 504 may be configured to be responsible for executing the RRC and PDCP protocols of the radio stack.

[0071] The control plane and user plane portions 504, 506 of the gNB aggregation unit may be configured to communicate with one or more distributed units (DUs) 508, 510 according to a higher layer-split architecture. The distributed units 508, 510 may be configured to run the upper layers of the radio stack's RLC, MAC, and PHY layer protocols. The control plane portion 504 may be configured to communicate with the distributed units 508, 510 using an F1-C communication interface 516, and the user plane portion 506 may be configured to communicate with the distributed units 508, 510 using an F1-U communication interface 518. The distributed units 508, 510 can communicate with one or more remote radio units (RUs) 512 via a fronthaul network 520 (which may include switches, links, etc.) and communicate with one or more user devices (not shown in Figure 5a). The remote radio unit 512 may be configured to perform lower-level parts of the PHY layer protocol and provide antenna capabilities to the remote unit for communication with user equipment (similar to the above discussion regarding Figures 1a-2).

[0072] Figure 5b shows an exemplary layer architecture 530 of a split gNB. Architecture 530, which can be configured as a virtualized and decomposed radio access network (RAN) architecture (where layers L1, L2, L3 and radio processing can be virtualized and decomposed in the aggregate unit, distributed unit and radio unit), can be implemented in the communication system 500 shown in Figure 5a. As shown in Figure 5b, the gNB-DU 508 can be communicatively coupled with the gNB-CU-CP control plane portion 504 (also shown in Figure 5a) and the gNB-CU-UP user plane portion 506. Each of components 504, 506, and 508 can be configured to include one or more layers.

[0073] The gNB-DU508 may include RLC, MAC, and PHY layers, and various communication sublayers. These may include the F1 Application Protocol (F1-AP) sublayer, the GPRS Tunneling Protocol (GTPU) sublayer, the Stream Controlled Transmit Protocol (SCTP) sublayer, the User Datagram Protocol (UDP) sublayer, and the Internet Protocol (IP) sublayer. As previously stated, the distributed unit 508 may be communicatively coupled to the control plane portion 504 of the aggregation unit, which may include the F1-AP, SCTP, and IP sublayers, as well as the Radio Resource Control and PDCP Control (PDCP-C) sublayers. Furthermore, the distributed unit 508 may be communicatively coupled to the user plane portion 506 of the aggregation unit of the gNB. The user plane portion 506 may include the Service Data Adaptation Protocol (SDAP), PDCP User (PDCP-U), GTPU, UDP, and IP sublayers.

[0074] Figure 5c shows an exemplary functional split in the gNB architecture shown in Figures 5a and 5b. As shown in Figure 5c, gNB-DU508 may be communicatively coupled with gNB-CU-CP504 and GNB-CU-UP506 using the F1-C communication interface. gNB-CU-CP504 and GNB-CU-UP506 may be communicatively coupled using the E1 communication interface. The higher portion of the PHY layer (or Layer 1) may be performed by gNB-DU508, and the lower portion of the PHY layer may be performed by RU (not shown in Figure 5c). As shown in Figure 5c, the RRC and PDCP-C portions may be performed by the control plane portion 504, and the SDAP and PDCP-U portions may be performed by the user plane portion 506.

[0075] Some of the functions of the PHY layer in a 5G communication network may include error detection on the transport channel and suggestion to higher layers, FEC encoding / decoding of the transport channel, hybrid ARQ soft synthesis, rate matching of coded transport channels to physical channels, mapping of coded transport channels onto physical channels, power weighting of physical channels, modulation and demodulation of physical channels, frequency and time synchronization, radio characteristics measurement and suggestion to higher layers, MIMO antenna processing, digital and analog beamforming, RF processing, and other functions.

[0076] The Layer 2 MAC sublayer can perform beam management, random access procedures, mapping between logical and transport channels, concatenation of multiple MAC service data units (SDUs) belonging to a single logical channel into a transport block (TB), multiplexing / demultiplexing of SDUs belonging to logical channels to / from TBs delivered to / from the physical layer over transport channels, scheduling of information reporting, error correction via HARQ, priority handling between logical channels of a single UE, priority handling between UEs through dynamic scheduling, transport format selection, and other functions. The functions of the RLC sublayer may include forwarding upper layer packet data units (PDUs), error correction via ARQ, sorting of data PDUs, duplication and protocol error detection, and re-establishment. The PDCP sublayer may be responsible for forwarding user data, various functions during re-establishment procedures, retransmission of SDUs, discarding SDUs on the uplink, forwarding control plane data, and others.

[0077] The Layer 3 RRC sublayer can perform functions such as broadcasting system information to NAS and AS, establishing, maintaining, and releasing RRC connections, security, establishing, configuring, maintaining, and releasing point-to-point radio bearers, mobility functions, reporting, and other functions. III. Secure L1 / L2-centric inter-cell mobility execution

[0078] Several companies in RAN2 have expressed concerns about the security of low-layer mobility (LLM) execution. MAC control element (CE) messages issued by serving gNB-DUs on the downlink are insecure (unencrypted) and therefore vulnerable to security breaches. For example, certain MAC CEs are associated with the execution of mobility events, which could allow a user's route to be tracked or their location to be traced. In a handover (HO) where one or more services of a UE are handed over from a serving cell (also referred to here as a "source cell") to a target cell, the serving gNB-DU may send a MAC CE to the UE that contains the target cell physical cell identifier (PCI) or other identifiers that identify the target cell to the UE. Because MAC CE messages to the UE are insecure, information about the UE and / or target cell is at risk of security breaches.

[0079] Layer 1 / Layer 2 Triggered Mobility (LTM) is an updated item from LLM. RAN2 has agreed on the definition of LTM. In general, LTM is a mobility procedure that allows a network to switch a UE from a source cell to a target cell without necessarily requiring reconfiguration with "sync". Specifically, the network can, based on received L1 measurements, indicate in L2 signaling (e.g., messages such as MAC CE) which beams belong to LTM candidate cells on which the UE should perform the LTM cell switching procedure. The network provides the UE with at least one LTM candidate cell configuration before performing the LTM cell switching procedure.

[0080] In some implementations of the current subject, gNB-CU-CP is configured to generate an index for all cells that are configured as candidates for L1 / L2-centric inter-cell mobility targets. Currently, according to the 3GPP standard (RAN2 agreement), up to eight LTM target cells can be prepared for a given UE. gNB-CU-CP is configured to store a mapping between the target cell PCI and the target cell index for future use. Thus, L1 / L2-centric inter-cell mobility can be performed without compromising security.

[0081] In some implementations of the current subject, a base station (e.g., a next-generation RAN (NG-RAN) node such as gNodeB, eNodeB, or gNodeB in Figure 5a) of a wireless communication system (e.g., a 5G wireless communication system, a 6G or later generation wireless communication system) may have a subdivided architecture in which the base station includes one gNB-CU-CP (e.g., gNB-CU-CP504 in Figures 5a-5c), multiple CU-UPs (e.g., gNB-CU-UP506 in Figures 5a-5c), and gNB-DUs (e.g., gNB-DU508, 510 in Figures 5a-5c). The base station may be configured to perform secure L1 / L2-centric inter-cell mobility when a UE is handed off from one cell (serving cell) of the base station to another cell (target cell) of the base station.

[0082] Figure 6a shows an exemplary system 600 configured to perform secure L1 / L2-centric inter-cell mobility. In this exemplary implementation, base station 602 is a gNB configured as in a 5G wireless communication system similar to the 5G wireless communication system 500 in Figure 5a described above, but other base stations may be similarly configured and used when performing secure L1 / L2-centric inter-cell mobility. In the exemplary implementation of Figure 6a, base station 602 includes multiple CU-UPs 606a, 606b, and 606c. In this exemplary implementation, base station 602 includes three CU-UPs 606a, 606b, and 606c, but may include multiple other CU-UPs. The CUs of base station 602, including multiple CU-UPs 606a, 606b, and 606c, are configured to be communicably coupled to a core network (not shown in Figure 6a), such as 5GC502 in Figure 5a.

[0083] The CU of base station 602 also includes a CU-CP604 configured to communicate with the user plane portions 606a, 606b, and 606c of the CU using an E1 communication interface 614. In this exemplary implementation, the E1 interface 614 includes three communication links to reflect that there are three CU-UP606a, 606b, and 606c that the CU-CP604 may be configured to communicate with.

[0084] Base station 602 also includes multiple DU608,610. In this exemplary implementation, base station 602 includes two DU608,610, but may include multiple other DUs. CU-CP604 is configured to communicate with DU608,610 using F1-C communication interface 616. CU-UP606a,606b,606c are configured to communicate with DU608,610 using F1-U communication interface 618. In this exemplary implementation, to reflect that there are three CU-UP606a,606b,606c that each DU608,610 may be configured to communicate with, the F1-U interface 618 associated with each DU608,610 includes three communication links.

[0085] Base station 602 also includes multiple RU612s. In this exemplary implementation, base station 602 includes five RU612s, but may include other RUs. The RU612s are configured to communicate with DU608, 610 via the fronthaul network 620. In addition, each RU612 is configured to communicate with one or more UE622s. In this exemplary implementation, two RU612s are shown to communicate with one UE622, two RU612s are shown to communicate with two UE622s, and one RU612 is shown to communicate with three UE622s, but each RU612 may be connected to the same or different number of UEs as any of the other RU612s.

[0086] Secure L1 / L2-centric inter-cell mobility execution can be configured to occur when one UE, which is communicatively coupled to base station 602, is handed off from one of base station 602's DU608, 610 to the other DU608, 610 of the same base station 602. The DU608, 610 currently servicing UE622 is referred to as the "serving DU" because it is currently servicing UE622 (e.g., currently serving UE622). The other DU608, 610 to which the UE's service is handed off is referred to as the "target DU" because its goal is to serve UE622.

[0087] A system that can be configured to perform secure L1 / L2-centric inter-cell mobility is further described with respect to Figure 6b. Figure 6b illustrates CU-CP604 and CU-UP606a, 606b, and 606b of Figure 6a, but in the illustrated implementation of Figure 6b, base station 602 contains more than two DUs. In the illustrated implementation of Figure 6b, base station 602 contains 66 DUs. Three of the DU628a, 628b, and 628c are macrocells (labeled macro1, macro2, and macro3 in Figure 6b), and 63 DU626 are subcells (nine of which are labeled gNB-DU10, gNB-DU20, gNB-DU30, gNB-DU40, gNB-DU50, gNB-DU60, gNB-DU70, gNB-DU80, and gNB-DU90 in Figure 6b). Base station 602 may include other numbers of macrocells and / or other numbers of subcells. The 21 subcells DU626, including "macro1" DU628a, "macro2" DU628b, and gNB-DU10, gNB-DU20, and gNB-DU30, are configured to be served by the first cU-UP606a (labeled CU-UP1 in Figure 6b). The 21 subcells DU626, including "macro1" DU628a, "macro2" DU628b, "macro3" DU628c, and gNB-DU40, gNB-DU50, and gNB-DU60, are configured to be served by the second CU-UP606b (labeled CU-UP2 in Figure 6b). The 21 subcells DU626, including "macro2" DU628b, "macro3" DU628c, and gNB-DU70, gNB-DU80, and gNB-DU90, are configured to be served by the third CU-UP606c (labeled CU-UP3 in Figure 6b).

[0088] In the implementation shown in Figure 6b, each CU-UP 606a, 606b, and 606c serves a subset of DUs 626, 628a, 628, and 628c for all services. However, a CU-UP can serve all DUs at a base station for one service (e.g., enhanced mobile broadband (eMBB)) while serving a subset of DUs for other services (e.g., vehicle-to-everything (V2X) or ultra-reliable low latency communication (URLLC)).

[0089] Figure 7 shows exemplary methods 700 relating to several implementations of the present subject. Method 700 in Figure 7 is described in relation to the exemplary system 800 shown in Figure 8, but can be similarly implemented with other systems, such as system 100 in Figures 1a-1c and 2, system 400 in Figure 4, system 500 in Figure 5a, and systems in Figures 6a and 6b. While system 800 in Figure 8 is a 5G system, as previously stated, performing secure L1 / L2-centric inter-cell mobility as described herein can also be performed with other types of wireless communication systems, such as LTE wireless communication systems or 6G or later generation wireless communication systems. The various elements in Figure 8 are numbered as sequential steps, but this numbering is not intended to suggest that these numbered steps can only be performed in this sequential order in system 800. One or more additional steps may exist before and / or after any of the sequentially numbered steps shown in Figure 8.

[0090] In system 800, a UE802 (e.g., UE104 in Figures 1a-1c, UE622 in Figure 6a, etc.) is configured with an LTM in one or more target cells at a base station, which is a gNB (e.g., gNodeB in Figure 5a, gNodeB602 in Figures 6a and 6b, etc.), which is a gNB (e.g., DU508 in Figures 5a-5c, DU510 in Figure 5a, DU608 in Figure 6a, DU610 in Figure 6a, DU626 in Figure 6b, DU628a, 628b, 628c in Figure 6b, etc.). For simplicity of explanation, in Figure 8, system 800 is shown with a base station containing one UE802 and two DU804, 806 that are communicatively coupled to the base station, but multiple UEs may be communicatively coupled to a base station that may contain more than two DUs and / or to a base station. The base station of system 800 includes a CU containing a CU-CP808 (e.g., gNB-CU-CP504 in Figures 5a-5c, CU-CP604 in Figures 6a and 6b, etc.) and one or more CU-UPs (e.g., gNB-CU-UP506 in Figures 5a-5c, CU-UP606a, 606b, 606c, etc. in Figures 6a and 6b) (not shown in Figure 8), and also includes multiple RUs (e.g., RU512 in Figure 5a, RU612 in Figure 6a, etc.) (not shown in Figure 8). UE802 is currently served by servingDU804. In addition, the base station in Figure 8 is coupled to the core network (e.g., EPC108 in Figures 1a-1c and 2, 5GC502 in Figure 5a, etc.) (not shown in Figure 8) for communication.

[0091] Upon determining that a serving cell change should occur (702), the serving DU 804 notifies the UE 802 of the serving cell change (704). This notification to the UE 802 (704) may include the serving DU 804 sending a serving cell change command, such as MAC CE, to the UE 802.

[0092] Furthermore, upon determining that a cell service change should occur (702), the serving DU 804 notifies the CU-CP 808 that a serving cell change has occurred for UE 802 (704). In this way, the notification (704) allows the serving DU 804 to identify UE 802 to the CU-CP 808 using a 3GPP standard identifier known to the serving DU 804 that uniquely identifies UE 802 to the CU-CP 808. The notification to the CU-CP 808 (704) may include the serving DU 804 sending a serving cell change notification message to the CU-CP 808 using the F1 communication interface. The serving cell change notification message may include a cell identifier (ID) that uniquely identifies UE 802 after the serving cell change.

[0093] Upon receiving a serving cell change command from the serving DU804, the UE802 sends a Radio Resource Control (RRC) reconfiguration confirmation message to the CU-CP808. From the RRC reconfiguration confirmation message, the CU-CP808 recognizes that the UE802, which was uniquely identified to the CU-CP808 by the serving DU804, has confirmed the completion (success) of the serving cell change.

[0094] Furthermore, upon receiving the Layer 3 RRC measurement configuration, UE802 transmits an RRC measurement report to CU-CP808 in accordance with the 3GPP standard (812). In accordance with the 3GPP standard, the RRC measurement report may include Layer 3 (L3) measurement results that can be analyzed by CU-CP808 when making resource control decisions (which may include a decision to prepare at least one target DU cell for LTM so that at least one target cell from target DU (also referred to here as “neighboring DU”) 806 is ready to serve UE802 for at least one service, instead of serving DU 804).

[0095] In response to the decision to prepare at least one target cell for LTM, CU-CP808 prepares at least one target cell for LTM (706). As shown in Figure 8, in this exemplary embodiment, each of the at least one target cell is an inter-DU target cell, for example, such that the same CU (e.g., the CU containing CU-CP808) serves each DU804, 806 (a different DU portion from the serving DU804, but the same base station as the serving DU804). Also, in this exemplary embodiment, since there are only two gNB-DUs, at least one target cell contains only target DU806. However, as previously stated, a base station may contain more than two target cells. Currently, according to the 3GPP standard, up to eight LTM target cells can be prepared for a given UE.

[0096] Preparing at least one target cell for LTM (706) may include notifying at least one target DU806 that it may be later notified to initiate service provision to UE802 for at least one service. This allows the target DU806 to reserve the necessary resources for UE802. Preparing at least one target cell (706), which in this exemplary implementation is only target DU806 as shown in Figure 8, may include the CU-CP808 sending a UE context setup request message to target DU806 (814) using the F1 communication interface compliant with the 3GPP standard.

[0097] Upon receiving a UE context setup request message from CU-CP808, target DU806 prepares each of one or more target cells for the LTM (e.g., reserving necessary resources for UE802) and notifies CU-CP808 that preparation (828) is complete. In this exemplary implementation, at least one target cell contains only one target DU806 that prepares one target cell. In a DU-to-DU LTM scenario, one or more target cells prepared for at least one LTM belong to a different DU from the serving DU806. For example, referring to the system in Figure 6b, the serving DU may be a subcell 626 of "macro1" DU628a, and one or more target cells may be one or more subcells 626 of "macro2" DU628b and / or "macro3" DU628c. As shown in Figure 8, notification to CU-CP808 may include target DU806 sending a UE context setup response message to CU-CP808 using the F1 communication interface compliant with the 3GPP standard (816). Also as shown in Figure 8, the UE context setup response message includes integrated cell group configuration information for one or more target cells prepared in target DU806. The integrated cell group configuration information includes a PCI (or other unique identifier) ​​for each of the one or more prepared target cells.

[0098] In response to notification from target DU806 that at least one target cell has been prepared for LTM, CU-CP808 maps each of the prepared target cells to an index (708, 818). The mapping (708) includes CU-CP808 generating an index (818) for all target cells configured for UE802 as candidates for L1 / L2-centered inter-cell mobility targets, as shown in Figure 8. The maximum number of target cells prepared for UE802 is 8 according to the current 3GPP standard. Therefore, CU-CP808 maps a maximum of 8 target cells under the current 3GPP standard (708).

[0099] The mapping of at least one target cell (708, 818) involves correlating each of the at least one target cell with respect to an index. As previously stated, the CU-CP808 is informed by the target DU806 of the PCI (or other unique identifier) ​​for each of the prepared target cells. Thus, the CU-CP808 can map each of the prepared target cells with respect to an index by its PCI (or other unique identifier) ​​so that each of the prepared target cells can be uniquely identified by an index. The CU-CP808 stores the mapping between the target cell PCI (or other unique identifier) ​​and the target cell index for future use, for example, by storing the mapping as a table in memory.

[0100] In some implementations, the index may be a numeric value, such that each of one or more target cells is associated with a unique numeric value by PCI (another unique identifier). According to the current 3GPP standard, the maximum number of target cells prepared for UE802 is 8, so 8 different numeric values ​​(e.g., integers 1-8, integers 0-7, even numbers 2-16, or other numeric values) can be used for the index. For example, in an implementation where three target cells are prepared for LTM, the mapping (708, 818) may include correlating the first PCI of the first target to index 1, the second PCI of the second target to index 2, and the third PCI of the third target to index 3.

[0101] In some implementations, the index may be an alphanumeric value, such that each of one or more target cells is associated with a unique alphanumeric value by PCI (another unique identifier). According to the current 3GPP standard, the maximum number of target cells prepared for UE802 is 8, so 8 different alphanumeric values ​​(e.g., the letters AH, terms 1-8, or other alphanumeric values) could be used for the index. For example, in an implementation where three target cells are prepared for LTM, the mapping (708, 818) might include correlating the first PCI of the first target with index A, the second PCI of the second target with index B, and the third PCI of the third target with index C.

[0102] In some implementations, the index may be an alphanumeric value, such that each of one or more target cells is associated with a unique alphanumeric value by PCI (another unique identifier). According to the current 3GPP standard, the maximum number of target cells prepared for UE802 is 8, so 8 different alphanumeric values ​​(e.g., terms for cell1-cell8, terms for C1-C8, or other alphanumeric values) can be used for the index. For example, in an implementation where three target cells are prepared for LTM, the mapping (708, 818) may include correlating the first PCI of the first target with index "cell1", the second PCI of the second target with index "cell2", and the third PCI of the third target with index "cell3".

[0103] CU-CP808 can generate a mapping for each of multiple UEs, where UE802 is one of multiple UEs. Thus, multiple mappings may be stored simultaneously. Each UE has its own mapping, generated so that different UEs may have different LTM target cell candidates, so the same target cell may be associated with different indices in different mappings (e.g., the first UE is associated with index A in the first mapping, the second UE with index D in the second mapping, the first UE with index 3 in the first mapping, and the second UE with index 5 in the second mapping, etc.). Since each mapping is associated with a specific UE and used in relation to a specific UE, different indices in different mappings for the same PCI do not cause confusion in CU-CP808, serving DU804, target DU806, or multiple UEs.

[0104] After the mapping (708, 818) is performed, CU-CP808 notifies Serving DU804 of the mapping (708, 818) and at least one target cell prepared for LTM (710). Thus, Serving DU804 recognizes each of the prepared target cells by PCI (or other unique identifier) ​​and index. As shown in Figure 8, the notification to Serving DU804 (710) may include CU-CP808 sending a UE context change request message to Serving DU804 using the F1 communication interface (820). Also as shown in Figure 8, the UE context change request message may include, for example, an information element (IE) that correlates the PCI (or other unique identifier) ​​of each of the prepared target cells with an index. In this way, the serving DU804 securely receives identification information for each of the one or more target cells configured as candidates for inter-cell mobility targets, primarily L1 / L2, for the UE802.

[0105] In response to notification that a target DU cell prepared for at least one LTM has been announced (710), serving cell 804 stores received information for at least one LTM target cell (e.g., a mapping). Also in response to notification that at least one target DU has been announced (710), serving cell 804 sends a UE context change response message to CU-CP808 using the F1 communication interface (822). As shown in Figure 8, the UE context change response message may include integrated cell group configuration information for each of the one or more target cells identified by CU-CP808 to UE802. The UE context change request message and the UE context change response message are defined by 3GPP, respectively. Thus, serving DU804 can receive information for at least one target cell from CU-CP808 and can confirm receipt to CU-CP808 using a message already sent for HO in accordance with 3GPP standards.

[0106] Upon receiving the UE context change response message, CU-CP808 sends an RRC reconfiguration message to UE802 in accordance with the 3GPP standard (824). As shown in Figure 8, the RRC reconfiguration message includes LTM target cell configuration information (for example, provided to CU-CP808 from target DU806 in the transmitted (830) UE context setup response message) and an index generated by CU-CP808 for one or more target cells configured as candidates for L1 / L2-centric inter-cell mobility targets for UE802. Thus, UE802 is notified by CU-CP808 of the LTM target cell configuration information and index (712). Furthermore, since the index is sent to UE802 in a secure message (824), UE802 securely receives the identification information for each of the one or more target cells configured as candidates for L1 / L2-centric inter-cell mobility targets for UE802.

[0107] Upon receiving the target cell configuration in the RRC reconfiguration message, UE802 transmits an L1 measurement report in accordance with the 3GPP standard to serving DU804 (826). The L1 measurement report provides serving DU804 with UE measurement radio condition information for one or more configured target cells.

[0108] Upon receiving the (826)L1 measurement report transmitted from UE802, serving cell 804 selects a target cell from among the target cells prepared for one or more LTMs identified for serving DU804 (714, 828). In this exemplary embodiment, since there is only one target cell (target DU806) ​​identified for serving DU804 as a target cell prepared for the LTM by CU-CP808, the selection of the serving cell (714, 828) is straightforward (serving DU804 selects target DU806 (714, 828)). If there are multiple target cells prepared for the LTM that satisfy the handover criteria in serving DU804, serving DU804 is configured to select a target cell for handover.

[0109] In implementations where multiple target cells are identified for the serving DU804 by CU-CP808, the serving cell's target cell selection (714, 828) may include determining which of the multiple target cells has radio quality above a predetermined radio quality threshold, as shown in Figure 8. The predetermined radio quality threshold is determined by the UE's radio conditions, as received by the serving DU804 in the L1 measurement report from the UE802. Thus, when the serving DU804 selects a target cell for HO (710, 828), it can take into account the specific needs of a particular UE802 related to HO. In addition, the L1 measurement report transmitted by the UE802 to the serving DU804 (826) reports L1 measurement results, which may include the 3GPP-defined reference signal received power (RSRP) for each of the multiple target cells (whose IDs are known to the UE802 as they are provided to the UE802 in the RRC reconfiguration message by CU-CP808). Therefore, the serving DU804 can analyze the L1 measurement report received from the UE802 to determine which of the multiple target cells has a radio quality that exceeds a predetermined radio quality threshold.

[0110] If only one of several target cells meets the UE's radio conditions, for example, if the radio quality of a single target cell exceeds a predetermined radio quality threshold, serving cell 804 selects that target cell (714, 828). If more than one of several target cells meet the UE's radio conditions, for example, if the radio quality of each target cell exceeds a predetermined radio quality threshold, any one of these target cells can serve the UE's needs randomly or according to other desired criteria.

[0111] When a target cell (for example, target DU806 in the example implementation in Figure 8) is selected (710, 828), the serving DU804 triggers a serving cell change to the selected (714, 828) target cell (716). The serving DU804 identifies the selected (714, 828) target cell to the UE802 by the index (e.g., a numeric, alphanumeric value, etc.) associated with the selected (714, 828) target cell by the mapping performed by the CU-CP808. Thus, the serving DU804 does not need to send the PCI (or other unique identifier) ​​of the selected (714, 828) target cell to the UE802 in an insecure message or otherwise. Even in the case of a security breach where the index of the selected (714, 828) target cell becomes known to an unauthorized party, the index as a value that does not uniquely identify the target cell or UE802 (except for an authorized party with a mapping) improves security because it does not allow the user's path to be tracked or the user's location to be traced. As shown in Figure 8, triggering a serving cell change (716) may involve the serving DU804 sending a MAC CE to the UE802 (844) that includes a serving cell change command and identifies the selected (714, 828) target cell to the UE802. In this way, even if the MAC CE is an insecure message, the selected (714, 828) target cell can be identified to the UE802 without compromising security.

[0112] Furthermore, after selecting a target cell (710, 828), the serving DU804 sends a serving cell change (SCC) notification to the CU-CP808 via the F1 communication interface (832) that identifies target DU806 as the new current serving cell for UE802 for at least one service, for example by PCI (or other unique identifier).

[0113] The reception of the MAC CE in the UE indicates to UE802 that an LTM Serving Cell Change (SCC) must be performed for the target cell identified for UE802 (e.g., target DU806 in the example implementation in Figure 8). Therefore, upon receiving the MAC CE from serving cell 804, UE802 initiates an HO to the target cell (718). The HO may be performed according to the 3GPP standard. The UE uses an index received from serving DU804 to determine the ID of the target cell for the HO. Since UE802 has received a mapping from CU-CP808, it can look up the index received from serving DU804 in the mapping to determine the target cell corresponding to the index and identify the target cell for the HO. As shown in Figure 8a, UE802 initiating an HO to the target cell (718) may include UE802 accessing the target cell (834) in a RACH procedure for the HO based on RACH, which may be performed according to the 3GPP standard. As shown in Figure 8, UE access to the target cell (834) may include UE802 sending a preamble to target DU806.

[0114] Furthermore, upon receiving a MAC CE from serving cell 804, UE802 sends an RRC reconfiguration acknowledgment message to CU-CP808 (840). Thus, CU-CP808 receives acknowledgments from both UE802 (via the RRC reconfiguration acknowledgment message indicating the success of RRC reconfiguration on UE802) and serving DU804 (via a serving cell change notification indicating that target DU806 is now serving UE802 for at least one service handed over from serving DU804).

[0115] Upon receiving an SCC notification from serving DU804, CU-CP808 notifies target DU806 of the mapping generated by CU-CP808 for one or more target cells configured as candidates for L1 / L2-centric inter-cell mobility targets for UE802 (720). In this way, target DU806 securely receives the identification information for each of the one or more target cells configured as candidates for L1 / L2-centric inter-cell mobility targets for UE802. Target DU806 can use the mapping when an HO for UE802 occurs from target DU806, as previously described with respect to serving DU804 handing over to target DU806. As shown in Figure 8, the notification (820) may include CU-CP808 sending a UE context change request message to target DU806 using the F1 communication interface (836). As shown in Figure 8, a UE context change request message to target DU806 may include a mapping, for example, as an information element (IE). Upon receiving the UE context change request message from CU-CP808, target DU806 sends a UE context change response message to CU-CP808 using the F1 communication interface (838).

[0116] After CU-CP808 has generated a mapping for one or more target cells configured as candidates for L1 / L2-centric inter-cell mobility targets for UE802 (708, 818), CU-CP808 is configured to update the mapping. Updating the mapping allows the mapping to be dynamic and to reflect in real time the target cells that are LTM candidates for HO for UE802. CU-CP808 is configured to provide the updated mapping to UE802 in a secure message similar to that described above for CU-CP808 sending the mapping to UE802 (824). Furthermore, CU-CP808 is configured to provide the updated mapping to serving DU804 (or target DU806 if the mapping is updated after an HO to the selected (714, 828) target cell has already occurred) in a secure message similar to that described above for CU-CP808, sending the mapping to serving DU804 (820) and sending the mapping to target DU806 (836). In this way, UE802 and serving DU804 (or target DU806) ​​can obtain the current mapping for UE802 if an HO for UE802 occurs after the mapping has been updated.

[0117] The CU-CP808 is configured to update the mapping for one or more target cells that are candidates for L1 / L2 inter-cell mobility targets for the UE802 in response to a trigger event. One example of a trigger event is when a target cell is excluded from the UE802, such as when the target cell goes offline or is excluded from the wireless communication system including the CU-CP808. The CU-CP808 is configured to remove the index for the excluded target cell from the mapping (for example, by removing the entry for that target cell from the table that correlates the target cell to the index).

[0118] Another example of a trigger event is when a target cell is replaced for UE802, for example, when a target cell that was not previously a candidate becomes a better candidate than a target cell currently identified as a candidate due to a change in the requirements of UE802. CU-CP808 is configured to remove the index for the replaced target cell from the mapping (for example, by removing the entry for that target cell from the table that correlates the target cell to the index and associates that index with the target cell that has been added as a candidate instead).

[0119] When the mapping for one or more target cells configured as candidates for inter-cell mobility targets centered on L1 / L2 in UE802 is updated, the index may become non-sequential. Since the index remains valid, there is no need to reassign PCI to the index to make it sequential. For example, if integers 1-8 are used for eight target cells, and a target cell associated with index 2 is removed, the index will no longer be sequential for the remaining target cells associated with indices 1, 3, 4, 5, 6, 7, and 8. If other target cells are added to this mapping, the added target cells may be associated with the now-unused index 2.

[0120] Figure 9 shows an exemplary architecture of the gNB-CU-CP808 shown in Figure 8. As shown in Figure 9, the gNB-CU-CP808 includes memory 900, a processor 902, a communicator 904, and a security management controller 906. The communicator 906 is configured to communicate internally between the internal hardware components of the CU-CP808 and to communicate with external devices over one or more networks. The communicator 904 may include electronics specific to standards that enable wired or wireless communication. The security management controller 906 is configured to perform the aforementioned mappings, and memory 900 is configured to store the mappings. Multiple mappings (one mapping per UE) may be stored in memory 900 so that the CU-CP808 maintains mappings for multiple UEs. Figure 9 shows the hardware components of the gNB-CU-CP808, but other implementations of the CU-CP808 are possible. For example, the gNB-CU-CP808 may include fewer or more components.

[0121] In some implementations, the subject may be configured to be implemented in system 1000 as shown in Figure 10. System 1000 may include one or more of the following: processor 1010, memory 1020, storage device 1030, and input / output device 1040. Each of the components 1010, 1020, 1030, and 1040 may be interconnected using the system bus 1050. Processor 1010 may be configured to process instructions for execution within system 600. In some implementations, processor 1010 may be a single-threaded processor. In alternative implementations, processor 1010 may be a multi-threaded processor. Processor 1010 may be further configured to process instructions stored in memory 1020 or storage device 1030, including receiving or transmitting information through the input / output device 1040. Memory 1020 can store information within system 1000. In some implementations, memory 1020 may be computer-readable media. In alternative implementations, memory 1020 may be a volatile memory unit. In some further implementations, memory 1020 may be a non-volatile memory unit. Storage device 1030 may provide mass storage for system 1000. In some implementations, storage device 1030 may be a computer-readable medium. In alternative implementations, storage device 1030 may be a floppy disk device, a hard disk device, an optical disk device, a tape device, a non-volatile solid-state memory, or any other type of storage device. Input / output device 1040 may be configured to provide input / output operations for system 1000. In some implementations, input / output device 1040 may include a keyboard and / or a pointing device. In alternative implementations, input / output device 1040 may include a display unit for displaying a graphical user interface.

[0122] Figure 11 shows an exemplary method 1100 for performing secure Layer 1 / Layer 2 (L1 / L2) centered inter-cell mobility, relating to several implementations of the present subject. Method 1100 may be performed using, for example, the implementations shown and described with respect to Figures 6a-9.

[0123] Method 1100 includes mapping the PCI of at least one LTM target cell of at least one target DU of a base station that is a candidate for HO for UE to an index (1102), and securely transmitting the mapping from the base station's CU CP to the serving DU of the base station that is currently serving the UE for at least one service (1104).

[0124] In some implementations, the subject may include one or more of the following optional features:

[0125] In some implementations, the index for each of at least one LTM target cells may be unique in the mapping, such that each index is uniquely associated with at least one LTM target cell by PCI.

[0126] In some implementations, the method may also include securely sending the mapping from the CU-CP to a target DU containing one of the LTM target cells selected for the HO.

[0127] In some implementations, the mapping may be sent to the UE in a Radio Resource Control (RRC) reconfiguration message, and to the Serving DU in an F1 UE context change request message.

[0128] In some implementations, the method may also include updating the mapping in accordance with at least one of the following: at least one LTM target cell is excluded for the UE, at least one LTM target cell is replaced for the UE, and securely sending the updated mapping from the CU CP to the UE and the Serving DU.

[0129] In some implementations, the method may also include mapping the PCI of at least one LTM target cell of at least one target DU that is a candidate for HO for the second UE to an index, and securely sending the second mapping from the CU CP to the second UE, so that a second mapping is generated.

[0130] In some implementations, the serving DU can use the index received from the CU-CP when sending an LTM HO command to the UE.

[0131] In some implementations, each index can be a number, a letter, or an alphanumeric character.

[0132] In some implementations, the method may also include storing the mapping in at least one non-temporary storage medium.

[0133] In some implementations, a base station may include a Next Generation Radio Access Network (NG-RAN) node. Furthermore, an NG-RAN node may include a gNodeB or an ng-eNodeB.

[0134] In some implementations, the base station may include at least one processor and at least one non-temporary storage medium. Furthermore, the CU-CP may include at least one processor and at least one non-temporary storage medium.

[0135] The systems and methods disclosed herein can be embodied in various forms, including, for example, data processors such as computers, which may also include databases, digital electronic circuits, firmware, software, or combinations thereof. Furthermore, the aforementioned features and other aspects and principles of the disclosed implementations can be implemented in various environments. Such environments and associated applications may be specifically configured to perform various processes and operations relating to the disclosed implementations, or they may include general-purpose computers or computing platforms that are selectively activated or reconfigured by code to provide the necessary functions. The processes disclosed herein are not inherently related to any particular computer, network, architecture, environment, or other device, and can be implemented by an appropriate combination of hardware, software, and / or firmware. For example, various general-purpose devices may be used with programs written in accordance with the teachings of the disclosed implementations, or they may be more convenient for configuring dedicated devices or systems to perform the necessary methods and techniques.

[0136] The systems and methods disclosed herein may be implemented as computer program products (i.e., computer programs tangibly embodied in information carriers (e.g., machine-readable storage devices or propagating signals) for execution by or control of the operation of data processing devices (e.g., programmable processors, computers, or multicomputers)). Computer programs may be written in any form of programming language, including compiled or interpreted languages, and may be deployed in any form, including standalone programs or modules, components, subroutines, or other units appropriate for use in a computing environment. Computer programs may be deployed to run on a single computer or multicomputers, distributed across multiple sites and interconnected by a communication network, either at a single site or across multiple sites.

[0137] As used herein, the term “user” can refer to any entity, including a person or a computer.

[0138] While sequential numbers such as "1st," "2nd," etc., may indicate order in some contexts, the sequential numbers used in this document do not necessarily imply order. For example, sequential numbers may simply be used to distinguish one item from another. For instance, distinguishing the first event from the second event does not necessarily imply a temporal order or a fixed reference system (just as the first event in one paragraph of the description may differ from the first event in another paragraph of the description).

[0139] The above description is for illustrative purposes only and is not intended to limit the scope of the invention as defined by the attached claims. Other implementations are also within the scope of the following claims.

[0140] These computer programs, software, software applications, applications, components, or code, which may also be referred to as programs, contain machine instructions for a programmable processor and may be implemented in high-level procedural and / or object-oriented programming languages ​​and / or assembly / machine languages. As used herein, the term “machine-readable medium” refers to any computer program product, apparatus and / or device (e.g., magnetic disks, optical disks, memory and programmable logic devices (PLDs)) used to provide machine instructions and / or data to a programmable processor, and includes machine-readable medium that receives machine instructions as machine-readable signals. The term “machine-readable signal” refers to any signal used to provide machine instructions and / or data to a programmable processor. Machine-readable medium may store such machine instructions non-temporarily (e.g., non-temporarily solid-state memory or magnetic hard drives or any equivalent storage medium). Alternatively, machine-readable medium may store such machine instructions in a temporary manner (e.g., processor cache or other random-access memory associated with one or more physical processor cores).

[0141] To provide user interaction, the subject described herein may be implemented on a computer having a display device such as a cathode ray tube (CRT) or liquid crystal display (LCD) monitor for displaying information to the user, and a pointing device such as a keyboard and mouse or trackball to which the user can provide input to the computer. Other types of devices may also be used to provide user interaction. For example, the feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or haptic feedback. Input from the user may be received in any form, including but not limited to acoustic, speech, or haptic input.

[0142] The subject matter described herein may be implemented in a computing system that includes one or more backend components such as data servers, or one or more middleware components such as application servers, or one or more frontend components such as client computers having a graphical user interface or web browser on which users can interact with the implementation of the subject matter described herein, or any combination of such backend, middleware, or frontend components. The components of the system may be interconnected by digital data communication in any form or medium such as a communication network. Examples of communication networks include, but are not limited to, local area networks ("LANs"), wide area networks ("WANs"), and the Internet.

[0143] A computing system may include clients and servers. Clients and servers are generally (but not limited to) separate from each other and typically interact through a communication network. The client-server relationship arises from computer programs running on each computer, and these programs have a client-server relationship with each other.

[0144] The implementations presented in the above description do not represent all implementations consistent with the subject matter described herein. Rather, they are merely some examples consistent with aspects related to the subject matter described herein. A few variations have been described in detail prior to this, but other modifications or additions are possible. In particular, further features and / or variations may be provided in addition to those presented herein. For example, the implementations described herein may be directed toward various combinations and subcombinations of the disclosed features, and / or combinations and subcombinations of some of the further features disclosed above. In addition, the logical flows shown in the accompanying diagrams and / or described herein do not necessarily require a specific order or sequence shown to achieve the desired result. Other implementations may also be within the scope of the following claims.

Claims

1. At least one processor, When executed by at least one of the aforementioned processors, Mapping the physical cell identifier (PCI) of at least one Layer 1 / Layer 2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for user equipment (UE) to an index, The aggregation unit control plane (CU CP) of the base station securely transmits the mapping to the UE and the serving DU of the base station that is currently serving the UE for at least one service. An operation comprising at least one non-temporary storage medium storing instructions that cause at least one processor to execute such an operation, A device equipped with the following features.

2. The apparatus according to claim 1, wherein each index is unique in the mapping for each of the at least one LTM target cells, such that each index is uniquely associated with one of the at least one LTM target cells by PCI.

3. The apparatus according to claim 1, wherein the operation further comprises securely transmitting the mapping from the CU CP to a target DU which includes one of the at least one LTM target cells selected for the HO.

4. The mapping is transmitted to the UE in a Radio Resource Control (RRC) reconfiguration message. The mapping is transmitted to the serving DU in the F1 UE context change request message. The apparatus according to claim 1.

5. The aforementioned operation is The fact that at least one of the LTM target cells relating to the aforementioned UE was excluded, The fact that one of the at least one LTM target cells relating to the UE is replaced by at least one other LTM target cell that is different from the at least one LTM target cell, Updating the mapping according to at least one of the following: The CU CP securely transmits the updated mapping to the UE and the Serving DU, The apparatus according to claim 1, further comprising:

6. The aforementioned operation is To generate a second mapping, the PCI of at least one LTM target cell of the at least one target DU, which is a candidate for HO for the second UE, is mapped to the index. The CU CP securely transmits the second mapping to the second UE, The apparatus according to claim 1, further comprising:

7. The apparatus according to claim 1, wherein the serving DU uses the index received from the CU CP when sending an LTM HO command to the UE.

8. The apparatus according to claim 1, wherein each index is a number, a letter, or an alphanumeric character.

9. The apparatus according to claim 1, wherein the operation further comprises storing the mapping in the at least one non-temporary storage medium.

10. The apparatus according to claim 1, wherein the base station includes a Next Generation Radio Access Network (NG-RAN) node.

11. The apparatus according to claim 10, wherein the NG-RAN node includes a gNodeB or an ng-eNodeB.

12. The apparatus according to claim 1, wherein the base station includes the at least one processor and the at least one non-temporary storage medium.

13. The apparatus according to claim 12, wherein the CU CP includes the at least one processor and the at least one non-temporary storage medium.

14. When executed by at least one processor, Mapping the physical cell identifier (PCI) of at least one Layer 1 / Layer 2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for user equipment (UE) to an index, The aggregation unit control plane (CU CP) of the base station securely transmits the mapping to the UE and the serving DU of the base station that is currently serving the UE for at least one service. A non-temporary storage medium storing instructions that cause the at least one processor to perform an operation comprising the above.

15. The non-temporary storage medium according to claim 14, wherein the index for each of the at least one LTM target cells is unique in the mapping, such that each index is uniquely associated with one of the at least one LTM target cells by PCI.

16. The non-temporary storage medium according to claim 14, further comprising securely transmitting the mapping from the CU CP to a target DU which includes one of the at least one LTM target cells selected for the HO.

17. Mapping the physical cell identifier (PCI) of at least one Layer 1 / Layer 2 triggered mobility (LTM) target cell of at least one target distributed unit (DU) of a base station that is a candidate for handover (HO) for user equipment (UE) to an index, The aggregation unit control plane (CU CP) of the base station securely transmits the mapping to the UE and the serving DU of the base station that is currently serving the UE for at least one service. A computer implementation method that includes the following.

18. The method of claim 17, wherein the index for each of the at least one LTM target cells is unique in the mapping, such that each index is uniquely associated with one of the at least one LTM target cells by PCI.

19. The method according to claim 17, further comprising securely transmitting the mapping from the CU CP to a target DU which includes one of the at least one LTM target cells selected for the HO.

Citation Information

Patent Citations

  • Mapping a control resource to a physical cell

    US20210344436A1

  • Security key in layer 1 (L1) and layer 2 (L2) based mobility

    US20220007242A1