Methods, devices, and systems for SCG security in wireless networks

By updating SN counters and pre-configuring candidate SNs, the method addresses delays and security issues in SCG transitions, enhancing network performance and security in dual connectivity scenarios.

JP7850294B2Active Publication Date: 2026-04-22ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
ZTE CORP
Filing Date
2023-01-06
Publication Date
2026-04-22

AI Technical Summary

Technical Problem

Existing wireless communication technologies face challenges in minimizing execution time and improving performance during switching between secondary carrier groups (SCGs) and secondary nodes (SNs) within wireless networks, particularly in dual connectivity scenarios.

Method used

A method involving a wireless device that selects a target PScell associated with a target SN, updates the SN counter, and transmits a refreshed SN counter value to a master node to facilitate a secure switch, along with pre-configured candidate SN configurations to expedite SCG addition or modification procedures.

Benefits of technology

This approach reduces service interruptions and enhances security by synchronizing SN counters and keys, enabling efficient and secure transitions between SCGs and SNs, thus improving network performance and reducing service delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007850294000003
    Figure 0007850294000003
  • Figure 0007850294000004
    Figure 0007850294000004
  • Figure 0007850294000005
    Figure 0007850294000005
Patent Text Reader

Abstract

The present disclosure generally relates to a method, device, and system for ensuring security related to an SCG in a wireless network. One method implemented by a wireless device is disclosed. The method may include selecting a target PS cell, determining whether an SN counter associated with the target SN needs to be updated, determining that the SN counter associated with the target SN needs to be updated, selecting a refreshed SN counter value, and updating at least the SN counter associated with the target SN with the refreshed SN counter value, and transmitting a first message to a master node requesting a switch from a current PS cell to the target PS cell.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure generally covers wireless communications, and more specifically, methods, devices, and systems for ensuring security related to secondary carrier groups (SCGs) and / or secondary nodes (SNs) within a wireless network. [Background technology]

[0002] With the rapid evolution of wireless communication technology, dual connectivity is being introduced to meet the demands for higher speeds, higher throughput and capacity, higher efficiency, and lower latency. This involves two base stations supporting a Master Carrier Group (MCG) and a SCG. Switching between SCGs, adding new SCGs, and switching between cells within the same SCG are supported to achieve robust secondary connectivity. Minimizing execution time for these procedures and improving performance is crucial. [Overview of the project] [Means for solving the problem]

[0003] This disclosure pertains to methods, devices, and systems for ensuring security related to SCG and / or SN within wireless networks.

[0004] In some embodiments, a method implemented by a wireless device is disclosed. The method may include the steps of: selecting a target primary secondary cell (PScell) in a wireless access network (RAN) in response to satisfying execution conditions, wherein the target PScell ​​is associated with a target secondary node (SN), the target SN is a component of a list of SNs, each SN in the list of SNs is associated with an SN counter, the SN counter associated with each SN in the list of SNs is used to calculate a security key for each SN in the list of SNs; determining whether the SN counter associated with the target SN needs to be updated; determining that the SN counter associated with the target SN needs to be updated, selecting a refreshed SN counter value, and updating at least the SN counter associated with the target SN using the refreshed SN counter value, wherein the refreshed SN counter value is different from any previous SN counter value shared between the wireless device and the master node; and transmitting a first message to the master node requesting a switch from the current PScell ​​to the target PScell, the first message including the refreshed SN counter value.

[0005] In some embodiments, a method is disclosed that is implemented by a master network node in a radio access network (RAN). The method may include the step of receiving a first message from a radio device requesting the radio device to switch from the current PScell ​​to a target PScell, the first message including a refreshed SN counter value for updating the SN counter, the refreshed SN counter value indicating that the target SN associated with the target PScell ​​is different from the SN associated with the current PScell.

[0006] In some embodiments, there exists a wireless device, network element, or network node comprising a processor and a memory, wherein the processor is configured to read code from the memory and implement any method enumerated in any of the embodiments.

[0007] In some embodiments, a computer program product comprises computer-readable media code stored thereon, which, when executed by a processor, causes the processor to implement any method enumerated in any of the embodiments.

[0008] The above embodiments, and other aspects and alternatives of their implementations, are described in more detail in the following drawings, description, and claims. The present invention provides, for example, the following: (Item 1) A method for wireless communication performed by wireless devices within a wireless network, In response to fulfilled execution conditions, the selection of a target primary secondary cell (PScell) within a radio access network (RAN), wherein the target PScell ​​is associated with a target secondary node (SN), the target SN is a component of a list of SNs, each SN in the list of SNs is associated with an SN counter, and the SN counter associated with each SN in the list of SNs is used to calculate a security key for each SN in the list of SNs. To determine whether the SN counter associated with the target SN needs to be updated, It is determined that the SN counter associated with the target SN needs to be updated, a refreshed SN counter value is selected, and the SN counter associated with the target SN is updated using the refreshed SN counter value, wherein the refreshed SN counter value is different from any previous SN counter value shared between the wireless device and the master node. A first message is transmitted to the master node requesting a switch from the current PScell ​​to the target PScell, wherein the first message includes the refreshed SN counter value. Methods that include... (Item 2) Determining whether the SN counter associated with the target SN needs to be updated is: In response to the fact that the SN associated with the target PScell ​​is different from the SN associated with the current PScell, it is determined that the SN counter associated with the target SN needs to be updated. The method described in item 1, including the method described in item 1. (Item 3) The method according to item 1, wherein the wireless device has a dual connection to the RAN, and the dual connection includes a connection between the wireless device and the current PScell. (Item 4) The method according to item 3, wherein the dual connection further includes a primary connection between the wireless device and the master node. (Item 5) The method according to item 1, wherein the initial value of the SN counter associated with each SN in the list of SNs is preconfigured to an integer value. (Item 6) The method according to item 5, wherein the initial value of the SN counter associated with each SN in the list of SNs is pre-configured to the same integer value by the master node. (Item 7) Updating at least the SN counter associated with the target SN using the refreshed SN counter value is: To update the SN counter associated with each of the SNs in the list of SNs. The method described in item 6, including the method described in item 6. (Item 8) Selecting the refreshed SN counter value means The maximum value among all values ​​in the SN counter associated with the aforementioned list of SNs is monotonically increased by a predefined number, and the refreshed SN counter value is obtained. The method described in any one of items 1-7, including the method described in item 1. (Item 9) Selecting the refreshed SN counter value means The method according to any one of items 1-7, comprising selecting a random integer value as the refreshed SN counter value. (Item 10) The master node receives a second message indicating that the target SN is ready to establish a secure connection with the wireless device based on the target SN key, the target SN key being derived based on the refreshed SN counter value. The method described in any one of items 1-7, further including the method described in any one of items 1-7. (Item 11) Based on the refreshed SN counter value, the target SN key is derived. Based on the target SN key, activate the security configuration associated with the target PScell. The method described in item 10, further including the method described in item 10. (Item 12) Each of the master node and the SN comprises a base station, and the base station is gNodeB (gNB), eNodeB (eNB), ng-eNodeB (ng-eNB), or NodeB The method described in any one of items 1-7, comprising one of the following: (Item 13) A method for wireless communication performed by a master network node within a wireless network's RAN, Receiving a first message from a wireless device requesting the wireless device to switch from the current PScell ​​to a target PScell, wherein the first message includes a refreshed SN counter value for updating the SN counter, the refreshed SN counter value indicating that the target SN associated with the target PScell ​​is different from the SN associated with the current PScell. Methods that include... (Item 14) The method according to item 13, wherein the wireless device has a dual connection to the RAN, and the dual connection includes a secondary connection between the wireless device and the current PScell. (Item 15) The method of item 14, wherein the dual connection further includes a primary connection between the wireless device and the master network node. (Item 16) The refreshed SN counter value is used to update the SN counter, The method involves updating the target SN key based on the refreshed SN counter value, wherein the updated target SN key is used to secure the link between the target PScell ​​and the wireless device. To transmit a second message to the target SN, including the updated target SN key. The method described in any one of items 13-15, further including the method described in any one of items 13-15. (Item 17) The third message is received from the target SN as a response to the second message, The method involves transmitting a fourth message to the wireless device as a response to the first message, the fourth message triggering the wireless device to activate a security configuration associated with the target PScell ​​based on the updated target SN key. The method described in item 16, further including the method described in item 16. (Item 18) Each of the master network node and the SN comprises a base station, and the base station is gNodeB (gNB), eNodeB (eNB), ng-eNodeB (ng-eNB), or NodeB The method described in any one of items 13-15, including one of the following. (Item 19) A device for wireless communication comprising a memory for storing computer instructions and a processor for communicating with the memory, wherein when the processor executes the computer instructions, the processor is configured to perform the method described in any one of items 1-18. (Item 20) A computer program product comprising a non-transient computer-readable program medium, the non-transient computer-readable program medium having computer code stored thereon, the computer code, when executed by one or more processors, causes the one or more processors to perform the method described in any one of items 1-18. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 shows an exemplary wireless communication network.

[0010] [Figure 2] Figure 2 shows an example of a wireless network node.

[0011] [Figure 3] Figure 3 shows an example of user equipment.

[0012] [Figure 4] Figure 4 shows an exemplary dual connectivity configuration with a gNB acting as a master node (MN) and an eNB acting as a secondary node (SN).

[0013] [Figure 5] Figure 5 shows an exemplary SN addition / modification procedure initiated by MN.

[0014] [Figure 6] Figure 6 shows an exemplary SN configuration pre-configured within the UE.

[0015] [Figure 7]Figure 7 shows an exemplary conditional PScell ​​modification (CPC) or conditional PScell ​​addition (CPA) procedure initiated by a UE, pre-configured with a candidate SCG (or candidate SN).

[0016] [Figure 8] Figure 8 shows a candidate SN pool with three candidate SNs and candidate cells within each candidate SN. [Modes for carrying out the invention]

[0017] Detailed explanation Wireless communication network Figure 1 shows an exemplary radio communication network 100, which includes a core network 110 and a radio access network (RAN) 120. The core network 110 further includes at least one mobility management entity (MME) 112 and / or at least one access and mobility management function (AMF). Other functions that may be included within the core network 110 are not shown in Figure 1. The RAN 120 further includes several base stations, e.g., base stations 122 and 124. The base stations may include at least one evolved NodeB (eNB) for 4G LTE, an enhanced LTE eNB (ng-eNB), or a next-generation NodeB (gNB) for 5G new radio (NR), or any other type of signal transmission / reception device such as a UMTS NodeB. The eNB 122 communicates with the MME 112 via the S1 interface. Both the eNB 122 and the gNB 124 may be connected to the AMF 114 via the Ng interface. Each base station manages and supports at least one cell. For example, the base station gNB124 may be configured to manage and support cell 1, cell 2, and cell 3.

[0018] The gNB124 may include a central unit (CU) and at least one distributed unit (DU). The CU and DU may be located together in the same location, or they may be separated into different locations. The CU and DU may be connected via an F1 interface. As an alternative, with respect to an eNB that can be connected to a 5G network, this may also be similarly divided into a CU and at least one DU, referred to as ng-eNB-CU and ng-eNB-DU, respectively. The ng-eNB-CU and ng-eNB-DU may be connected via a W1 interface.

[0019] The wireless communication network 100 may include one or more tracking areas. A tracking area may include a set of cells managed by at least one base station. For example, tracking area 1, labeled as 140, includes cell 1, cell 2, and cell 3, and may include more cells, which may be managed by other base stations and are not shown in Figure 1. The wireless communication network 100 may also include at least one UE 160. The UE may select a cell from among several cells supported by the base station to communicate with the base station through an over-the-air (OTA) wireless communication interface and resources, and this may be re-selected for communication as the UE 160 progresses within the wireless communication network 100. For example, the UE 160 may initially select cell 1 to communicate with base station 124, and this may then be re-selected for cell 2 at some later point in time. Cell selection or re-selection by the UE 160 may be based on the radio signal strength / quality of the various cells and other factors.

[0020] The wireless communication network 100 may be implemented as, for example, a 2G, 3G, 4G / LTE, or 5G cellular communication network. Correspondingly, base stations 122 and 124 may be implemented as a 2G base station, a 3G NodeB, an LTE eNB, or a 5G NR gNB. The UE 160 may be implemented as a mobile or fixed communication device capable of accessing the wireless communication network 100. The UE 160 may include, but is not limited to, mobile phones, laptop computers, tablets, personal digital assistants, wearable devices, Internet of Things (IoT) devices, MTC / eMTC devices, distributed remote sensor devices, roadside assistance equipment, XR devices, and desktop computers. The UE 160 may also be generally referred to as a wireless communication device or wireless terminal. The UE 160 may support sidelink communication to another UE via the PC5 interface.

[0021] The following explanation focuses on cellular wireless communication systems, as shown in Figure 1, but the underlying principles are applicable to other types of wireless communication systems for paging wireless devices. These other wireless systems may include, but are not limited to, Wi-Fi, Bluetooth®, ZigBee®, and WiMAX networks.

[0022] Figure 2 shows an embodiment of an electronic device 200 for implementing a network base station (e.g., a radio access network node), a core network (CN), and / or operation and maintenance (OAM). Optionally, in one implementation, the exemplary electronic device 200 may include a radio transmission / reception (Tx / Rx) network 208 for transmitting / receiving communications with UEs and / or other base stations. Optionally, in one implementation, the electronic device 200 may also include a network interface network 209 for communication between the base station and other base stations and / or core networks, e.g., optical or wired interconnects, Ethernet®, and / or other data transmission media / protocols. Optionally, the electronic device 200 may include an input / output (I / O) interface 206 for communication with an operator or equivalent.

[0023] The electronic device 200 may also include a system network 204. The system network 204 may include a processor 221 and / or memory 222. Memory 222 may include an operating system 224, instructions 226, and parameters 228. Instructions 226 may be configured for one or more of the processors 221 to perform the functions of a network node. Parameters 228 may include parameters to support the execution of instructions 226. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.

[0024] Figure 3 shows an embodiment of an electronic device for implementing a terminal device 300 (e.g., a user device (UE)). The UE 300 may be a mobile device, such as a smartphone or a mobile communication module, located in a vehicle. The UE 300 may include some or all of the following: a communication interface 302, a system network 304, an input / output interface (I / O) 306, a display network 308, and a storage device 309. The display network may include a user interface 310. The system network 304 may include any combination of hardware, software, firmware, or other logic / circuit networks. The system network 304 may be implemented with, for example, one or more system-on-a-chip (SoCs), application-specific integrated circuits (ASICs), discrete analog and digital circuits, and other networks. The system network 304 may be part of the implementation of any desired functionality within the UE 300. In this regard, the system circuitry 304 may, in an embodiment, include logic to facilitate music and video decoding and playback, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback, application startup, user input approval, application data storage and retrieval, in one embodiment, establishment, maintenance, and termination of cellular telephone calls or data connections for Internet connectivity, establishment, maintenance, and termination of wireless network connections, Bluetooth® connections, or other connections, and display of relevant information regarding the user interface 310. The user interface 310 and the input / output (I / O) interface 306 may include a graphical user interface, a touch sensor display, tactile feedback or other tactile output, voice or facial recognition input, buttons, switches, speakers, and other user interface elements.Additional embodiments of the I / O interface 306 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors), and other types of inputs.

[0025] Referring to Figure 3, the communication interface 302 may also include a radio frequency (RF) transmission (Tx) and reception (Rx) network 316, which handles the transmission and reception of signals through one or more antennas 314. The communication interface 302 may also include one or more transceivers. The transceivers may be wireless transceivers including a modulation / demodulation network, digital-to-analog converters (DACs), shaping tables, analog-to-digital converters (ADCs), filters, waveform shapers, filters, preamplifiers, power amplifiers, and / or other logic for transmission and reception through one or more antennas or (with respect to some devices) through a physical (e.g., wired) medium. The transmitted and received signals may conform to any of the following diverse array formats, protocols, modulation (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM), frequency channels, bit rates, and encodings. As one specific embodiment, the communication interface 302 may include transceivers that support transmission and reception under 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS), High-Speed ​​Packet Access (HSPA)+, 4G / Long-Term Evolution (LTE), and 5G standards. However, the techniques described below are also applicable to other wireless communication technologies, whether they originate from the Third Generation Partnership Project (3GPP®), the GSM® Association, 3GPP2, IEEE, or other partnerships or standards bodies.

[0026] Referring to Figure 3, the system network 304 may include one or more processors 321 and memory 322. Memory 322 stores, for example, an operating system 324, instructions 326, and parameters 328. Processor 321 is configured to execute instructions 326 to perform desired functionality for UE300. Parameters 328 may provide and define configuration and operation options for instructions 326. Memory 322 may also store any BT, WiFi, 3G, 4G, 5G, or other data that UE300 will transmit or receive through the communication interface 302. In various implementations, system power for UE300 may be supplied by a battery or a power storage device such as a converter. Network deployment with dual connectivity

[0027] With the rapid evolution of wireless communication technology, dual connectivity (DC) features are being introduced to meet the demands for higher speeds, higher throughput and capacity, higher efficiency, and lower latency. Generally, in a DC deployment, a UE is connected to two base stations (i.e., two nodes), enabling it to transmit / receive data through both base stations. The two base stations may be of the same type. For example, both base stations may be eNBs, gNBs, ng-eNBs, and equivalents. The two base stations may also be of different types. The core network to support the DC deployment may include, for example, an LTE evolved packet core (EPC) or a 5G core.

[0028] In a data center (DC) deployment, one node acts as the master node (MN), and the other as the secondary node (SN). In some exemplary implementations, the MN is the node to which the UE first connects. Subsequently, the UE may connect to the SN.

[0029] In some exemplary implementations, the MN is used solely to provide control plane connectivity between the UE and the core network, while the SN provides additional resources for carrying user plane traffic.

[0030] In some exemplary implementations, the signaling message (SN) may also carry the signaling message.

[0031] Exemplary DC configurations include EN-DC (E-UTRA-NR dual connectivity), NE-DC (NR-E-UTRA dual connectivity), NR-DC (New Wireless Dual Connectivity), NGEN-DC (NG-RAN-E-UTRA dual connectivity), etc. Exemplary, MN may be eNB (in EN-DC), ng-eNB (in NGEN-DC), or gNB (in NR-DC and NE-DC). SN may be en-gNB (in EN-DC), ng-eNB (in NE-DC), or gNB (in NR-DC and NGEN-DC).

[0032] Under certain conditions, a DC may be configured in combination with carrier aggregations (CAs) in which both MNs and SNs can be associated with multiple cells or carriers. These aggregated carriers are collectively called master cell groups (MCGs) and secondary cell groups (SCGs). Note that MCGs are associated with MNs, and SCGs are associated with SNs. Furthermore, note that an MCG may implicitly imply the MNs it associates with, and an SCG may implicitly imply the SNs it associates with.

[0033] Refer to Figure 4 for an exemplary DC configuration. In this embodiment, MCG410 is associated with MN, which is a gNB, and SCG412 is associated with SN, which is an eNB.

[0034] An MCG may include a group of serving cells associated with an MN, comprising a primary cell (PCell) and optionally one or more secondary cells (Scells). An SCG may include a group of serving cells associated with an SN, comprising a primary SCG cell (PScell) and optionally one or more Scells. In Figure 4, MCG410 consists of one PCell and two Scells, namely Scell1 and Scell2. SCG412 consists of one PScell ​​and two Scells, namely Scell1 and Scell2.

[0035] In some implementations, the UE may connect to one MN, switch from one SCG to another, or switch PScells within the same SCG. SN Add / Modify Procedure (MN Start)

[0036] In some exemplary implementations, SNs may be added or modified (corrected) by MNs. For example, a UE may switch from one SCG to another (i.e., from one SN to another), which would result in a PScell ​​change. Figure 5 illustrates an exemplary overall message / signaling flow regarding SN addition / modification.

[0037] Step 1 The UE establishes a Radio Resource Control (RRC) connection with the MN.

[0038] Step 2 The MN sends an SN addition / modification request to the SN via Xn-C and negotiates the resources, configurations, and algorithms (e.g., security algorithms) available in the SN. A new security key (K) for the SN is then generated. SN If required, the MN may calculate and send this to the SN. UE security capabilities and user plane (UP) security policies may also be sent to the SN.

[0039] UE security capabilities may include capabilities for Next Generation Radio Access Networks (NG-RAN), 5G Non-Access Layer (NAS), and 5G Access Layer (AS), and further, if these access types are supported by the UE, capabilities for Evolutionary Packet Systems (EPS), Universal Terrestrial Radio Access Networks (UTRAN), and GSM® EDGE Radio Access Networks (GERAN). UP security policies may be used to activate UP confidentiality and / or UP integrity with respect to one or more DRBs belonging to a PDU session associated with the UE.

[0040] In the case of PDU partitioning, UP integrity protection from MN and cryptographic processing activation decisions may also be included in the requirements.

[0041] Step 3 The SN allocates necessary resources such as wireless resources and transport network resources. The SN may also select cryptographic processing algorithms and integrity algorithms that have the highest priority from its constituent list and also reside within the UE security capabilities. SN However, in step 2, if delivered to SN, SN may calculate the RRC key and the UP key. SN may then activate the UP security policy based on the UP key.

[0042] Step 4 The SN sends an SN Addendum / Modification Acknowledgment to the MN indicating the availability of the requested resources and identifiers for the selected algorithms for the requested Data Radio Bearer (DRB) and / or Signaling Radio Bearer (SRB) for the UE. UP integrity protection and encryption indications may also be sent to the MN.

[0043] Step 5 The MN sends an RRC connection reconfiguration request to the UE, instructing it to configure a new DRB and / or SRB for the SN. The MN then sends a new K SN It is required that UE is K for SN SN The SN may include an SN counter parameter to indicate that it is necessary to calculate the . The MN automatically forwards the UE configuration parameters (including the algorithm identifier received from the SN in step 4) and the UP integrity protection and encryption indications (received from the SN in step 4) to the UE.

[0044] This message is sent via the RRC connection between the MN and the UE, and this is the K of the MN. RRCint Please note that the integrity is protected using the (RRC security key). Therefore, the SN counter is tamper-proof.

[0045] Step 6 The UE receives the RRC connection reconfiguration request after the step of demonstrating its integrity. The UE then receives the K for SN if the SN counter parameter is included. SN The UE calculates the RRC key and UP key required and may activate RRC and UP protection according to the indications received for the associated SRB and / or DRB. The UE sends an RRC reconstruction complete message to the MN. The UE may choose to activate the selected encryption / decryption and integrity protection keys using the SN at this point.

[0046] Step 7 MN sends a SN reconfiguration completion message to the SN via, for example, the Xn-C interface to notify the SN of the configuration result. In response to the reception of this message, the SN may select to activate the encryption / decryption and integrity protection selected using the UE. Alternatively, if the SN does not activate the encryption / decryption and integrity protection using the UE at this stage, the SN may activate the encryption / decryption and integrity protection in response to receiving a random access request from the UE.

[0047] In this SN addition / modification procedure, K SN is used to security protect the connection between the UE and the SN. The UE can calculate K SN by itself, while the SN relies on the MN for the delivery of K SN .

[0048] In some exemplary implementations, K SN may be derived by a key derivation function (KDF). The KDF may be based on the hash-based message authentication code secure hash algorithm 256 (HMAC-SHA-256). Equation 1 below shows an example for deriving K SN using the KDF.

Chemical formula

[0049] In Equation 1, the KDF has two inputs, namely, an input key and a string S. The string S may be, for example, a concatenation of multiple strings by using Equation 2 below.

Chemical formula

[0050] In Equation 2, FC is a function code. For the concatenation, there are multiple parameters (from P0 to Pn (n is a non-negative integer)) and the length for each parameter (i.e., L0, L1,... Ln).

[0051] As an example, K SN The following inputs may be used to derive the result. FC = 0 × 79 P0 = the value of the SN counter as a non-negative integer L0 = Length of P0 (i.e., length of the SN counter value)

[0052] The input key may also be a key for MN, which is K when MN is ng-eNB. eNB When MN is gNB, K gNB It may include. Selective SCG addition / modification using pre-configuration

[0053] In the SN addition / modification procedures described in the preceding section, the decision for adding / modifying the SN is made by the MN. Once the MN triggers the procedure, preparatory effort, including resource allocation, capability negotiation, and algorithm selection, must be undertaken by the SN and UE. Service delays may be introduced by the preparatory effort. Therefore, in order to expedite the procedure and reduce the duration of service interruptions, it is desirable to reduce or even eliminate preparatory effort so that, once the SN addition / modification decision has been made, the link between the UE and the SN can be established with minimal effort.

[0054] One solution is to move the preparation effort or preparation phase to an earlier stage before the decision to add / modify SN is made.

[0055] The UE may be pre-configured with a pool of candidate SNs, which may include multiple candidate SNs. For each candidate SN, the UE may be configured with configurations related to, for example, resource allocation, capability negotiation, algorithm selection, etc. The UE may also be configured with execution conditions used to evaluate and trigger SN addition or modification. For the same candidate SN, there may be different execution conditions serving different purposes, such as execution conditions for SN addition and execution conditions for SN modification. Furthermore, in some exemplary implementations, a candidate SN may support multiple configurations, for example, configurations that serve different quality of service (QoS), different security levels, or different throughputs. Accordingly, the UE may evaluate multiple execution conditions for a candidate SN and select an SN configuration that matches the satisfied execution conditions.

[0056] The SN configuration may be used for conditional PScell ​​addition (CPA) and / or conditional PScell ​​modification (CPC), in the sense that PScell ​​addition and PScell ​​modification are triggered when the conditions defined by the execution conditions are met.

[0057] Refer to Figure 6 for an example. The UE is configured with a candidate SN pool containing three candidate SNs (SN1 to SN3). SN configurations and execution conditions 610, 612, and 614 are pre-configured in the UE. Based on these pre-configured configurations, the UE may add one of these SNs, add an SCG, or change the SCG from one SN to another. The UE may also change its PScell ​​within the same SCG.

[0058] Similarly, for each candidate SN, pre-configuration may also be performed to support CPA / CPC procedures. For example, a candidate SN may be configured with UE capabilities and UE security preferences to minimize negotiation effort after the candidate SN has been selected for SN addition or modification. Embodiment 1: Selective SCG addition / modification using security key refresh

[0059] In this embodiment, the UE is pre-configured with candidate SN / SCG configurations to facilitate the CPC / CPA procedure. SN This is synchronized between the UE and the target SN when the UE triggers the CPC / CPA procedure. SN However, it should be noted that, as explained above, it can be derived based on equation 1.

[0060] Under CPA / CPC procedures, the UE may either add a new PScell ​​according to the PCell in the MCG, or switch to a different PScell ​​in a different or identical SCG (or SN). The UE may maintain a pre-configured SN / SCG configuration and may switch to the same PScell ​​alternately multiple times. Depending on the different PScell ​​addition / switching scenarios, a K for the SN is used to secure the link between the UE and the SN. SN It may be reused or may need to be refreshed to enhance security. In this embodiment, K SN The refresh mechanism is explained in great detail.

[0061] When a UE is configured with multiple candidate SNs, a security key for the candidate SNs, i.e., K, is used to secure the link between the UE and the candidate SNs. SN However, it is used. K SN This may be derived based on equations 1 and 2 as described above. In particular, the input key is the security key for MN, for example, K if MN is gNB. gNB , or if MN is ng-eNB, K ng-eNB Alternatively, P0 may be an SN counter corresponding to a candidate SN.

[0062] In the exemplary implementation, all candidate SNs may be associated with the same MN, and therefore their individual K SN The input keys used to derive the result may also be the same.

[0063] K SN Several security requirements exist regarding this. Firstly, each candidate SN must have its own unique K SN It has. Secondly, with respect to the same candidate SN, under certain conditions, K SN However, refresh requirements exist, meaning that it may need to be refreshed or updated. Further details will be explained in later paragraphs.

[0064] Figure 7 shows an exemplary signaling / messaging flow for a UE-initiated CPC / CPA procedure, including the following steps: Step 0

[0065] The UE may be pre-configured with a candidate SN pool (or SCG pool) containing multiple candidate SNs (or multiple candidate SCGs). Referring back to Figure 6, for each candidate SN, the UE maintains a configuration that includes a conditional PScell ​​addition (CPA) configuration and / or a conditional PScell ​​modification (CPC) configuration. The UE may also be pre-configured with execution conditions corresponding to the CPA and CPC configurations. For example, when the CPA execution condition is met, a subsequent PScell ​​addition may be performed according to the CPA configuration. For each candidate SN (or candidate SCG), the UE may also be pre-configured with SN counters. For example, in Figure 6, SN counters 616, 618, and 620 are assigned to SN1, SN2, and SN3, respectively. Once the SN counters are pre-configured with their individual initial values, the UE continues to maintain / update these counters.

[0066] In some exemplary implementations, the MN may assign a unique initial value to each of the SN counters. For example, the initial values ​​for the three SN counters 616, 618, and 620, as shown in Figure 6, may be 0, 1, and 2, respectively.

[0067] On the SN side, each candidate SN can be prepared in advance for subsequent CPC / CPA execution.

[0068] Step 1 The UE evaluates the execution conditions. If the CPA / CPC execution conditions are met with respect to a specific PScell ​​under a candidate SN, the UE will select the PScell ​​(and its associated candidate SN, also referred to as the target SN) and proceed with the CPA / CPC procedure. The execution conditions for CPA and CPC may differ.

[0069] Referring to Figure 8 as an example, the UE is pre-configured with three candidate SNs, namely SN1, SN2, and SN3. Each SN has three cells, namely cell 1, cell 2, and cell 3. The UE has current dual connectivity, and the current PScell ​​is cell 1 under SN1. The UE may select cell 2 under SN2 and execute the CPC procedure if the CPC execution conditions are met. In this case, SN2 is the target SN.

[0070] Step 2 The UE triggers the CPC / CPA procedure toward the selected PScell ​​by sending a CPC / CPA request message to the MN. The message may include at least one of the following: an SN counter for the target SN (i.e., a candidate SN associated with the selected PScell), or an identifier such as the PScell ​​ID of the selected PScell ​​to identify the target SN associated with the selected PScell. One of the goals of the UE's automatic transfer of the SN counter to the MN is to keep the SN counter synchronized between the UE and the MN. Therefore, instead of the SN counter itself, it is also possible to include an SN counter update indication within the CPC / CPA request message, so that the UE and MN may update the SN counter in a synchronized manner.

[0071] The SN counter for the target SN associated with the selected PScell ​​may or may not need to be refreshed (updated) from its current value. If the selected PScell ​​is associated with a different SN than the SN associated with the current PScell ​​in dual connectivity, the SN counter must be refreshed. K for candidate SNs SN It also needs to be updated, and the UE, based on the refreshed SN counter, K SN It will be necessary to recalculate (i.e., the refresh regarding the SN counter is K SN (Triggers an update).

[0072] As an example, referring to Figure 8, assuming that the current dual connectivity uses cell 1 as the PScell ​​within SN1 (i.e., SN1 is the current SN), the UE determines that the PScell ​​needs to be changed to cell 2 under SN2. In this case, since the selected PScell ​​is associated with a different SN than the current SN, the SN counter for SN2 (the target SN, which is the SN associated with the selected PScell) needs to be refreshed, and the K for SN2 SN It needs to be updated.

[0073] As another embodiment, referring to Figure 8, assuming that the current dual connectivity uses cell 1 as the PScell ​​within SN1 (i.e., SN1 is the current SN), the UE determines that the PScell ​​needs to be changed to cell 2 under the same SN. In this case, there is no SN change, and therefore the SN counter for the target SN, which is SN1, does not need to be refreshed, and the K for SN1 SN It may be reused without updating.

[0074] In some exemplary implementations, the UE maintains an SN counter for each SN. When refreshing the SN counter for a selected (target) SN, the UE may determine the maximum value of all SN counters thus maintained, increment the maximum value by an offset (e.g., a predefined positive integer such as 1), and obtain the refreshed value for the SN counter of the selected SN, the refreshed value being K for any candidate SN. SN Note that it is not used to calculate the offset. The offset may be constructed by MN.

[0075] As an example, assume that before an SN counter refresh, the UE maintains three SN counters with the following values: SN1 counter: 0, SN2 counter: 1, SN3 counter: 2.

[0076] Assuming that the UE needs to refresh the SN counter for SN2 based on the decision logic described above, the UE first determines that the maximum value of all SN counters is 2 (i.e., the SN3 counter value), increments this by 1 to obtain the refreshed value for the SN2 counter, and updates the SN2 counter. After the refresh, the three SN counters will have the following values ​​(with the updated SN2 counter value): SN1 counter: 0, SN2 counter: 3, SN3 counter: 2.

[0077] Since the SN counter has an upper limit, a reset of the counter will need to occur when the SN counter reaches that upper limit. Each reset brings about a new cycle for the SN counter. In such a reset event, all SN counters may be reset to their initial pre-configured values ​​(e.g., set by MN). On the other hand, K SNThe input key to the KDF for deriving the result will also be updated to a new key that has not been used previously. Thus, considering the SN counter reset, the requirement is that within each cycle of the SN counter, the refreshed counter value will be K for any candidate SN. SN It should not be used to calculate [the value].

[0078] In some exemplary implementations, the UE maintains an SN counter for each SN. The UE keeps a K for any candidate SN. SN The SN counter may be refreshed using random numbers that are not used to calculate it. SN counter reset rules may also be applied.

[0079] Upon receiving the updated SN counter, the MN stores it and, based on it, updates the K SN Calculate.

[0080] Step 3 The MN sends SN addition / modification requests to the SN (i.e., target SN) via, for example, the Xn-C interface. The MN also sends new K SN If K is calculated in step 2, SN Send it to SN.

[0081] Step 4 The SN sends an SN Addition / Modification Request Acknowledgment message to the MN, for example, via the Xn-C interface. The SN may activate the selected encryption / decryption and integrity protection using the UE based on the pre-configured configuration. If the SN does not activate the encryption / decryption and integrity protection using the UE at this stage, the SN may choose to activate the encryption / decryption and integrity protection in response to receiving a random access request from the UE. In step 3, the updated K SN When it is sent to the SN, encryption / decryption and integrity protection are applied to the updated K SN Based on this, otherwise, the current K SNHowever, please note that it may be used for security purposes.

[0082] Step 5 The MN sends a CPC / CPA request acknowledgment message to the UE. Upon receiving this message, the UE may use the SN to activate the selected encryption / decryption and integrity protection keys at that time.

[0083] In this embodiment, the UE maintains an SN counter (e.g., SN counters 616, 618, and 620 in Figure 6) for each candidate SN in the candidate SN pool. These counters may be configured with different initial values ​​by, for example, the MN. When the UE switches to a PScell ​​under a target SN that is different from the current SN associated with the current PScell, the SN counters for the target SN are refreshed and a new K SN However, that will be calculated. Embodiment 2: Selective SCG addition / modification using security key refresh

[0084] This embodiment is similar to Embodiment 1, except that the UE maintains the SN counter in a different manner.

[0085] In some exemplary implementations, the UE maintains an SN counter for each candidate SN in the candidate SN pool. Each of these SN counters is pre-configured with the same initial value (e.g., 0). When the UE determines that the SN counter associated with a target SN needs to be refreshed (by following similar logic as described in step 2 of Embodiment 1), the UE may uniformly increment all SN counters by a predefined offset (e.g., a predefined positive integer such as 1), so that all SN counters maintain the same value. Alternatively, the UE may increment all SN counters by K for any candidate SN. SN It may also be uniformly set to the same random integer, which is not used to calculate the result. Note that the SN counter cycle concept, as described in Embodiment 1, can still be applied.

[0086] In some exemplary implementations, instead of maintaining an SN counter for each candidate SN, a single SN counter is employed by the UE, which covers all candidate SNs. When the UE determines that the SN counter associated with a target SN needs to be refreshed (by following similar logic, as described in step 2 of Embodiment 1), the UE may increment the SN counter by a predefined offset (e.g., a predefined positive integer such as 1). Alternatively, the UE may increment the SN counter by K for any candidate SN. SN It may be set to a random integer that is not used to calculate the value. Note that the SN counter cycle concept, as described in Embodiment 1, may still be applicable.

[0087] The above description and accompanying drawings provide specific exemplary embodiments and implementations. However, the subject matter described may be embodied in a variety of different forms, and therefore, the subject matter covered or claimed is intended to be construed as not being limited to any exemplary embodiments described herein. A reasonably broad scope for the claimed or covered subject matter is intended. In particular, for example, the subject matter may be embodied as a method, device, component, system, or non-transient computer-readable medium for storing computer code. Thus, embodiments may take the form of, for example, hardware, software, firmware, storage medium, or any combination thereof. For example, the method embodiment described above may be implemented by a component, device, or system including memory and a processor by executing computer code stored in memory.

[0088] Throughout this specification and the claims, terms may have nuances implied or suggested in context beyond their explicitly stated meanings. Similarly, the phrase "in one embodiment / implementation" as used herein does not necessarily refer to the same embodiment, and the phrase "in another embodiment / implementation" as used herein does not necessarily refer to a different embodiment. For example, the claimed subject matter is intended to include a combination of exemplary embodiments, whether in whole or in part.

[0089] In general, technical terms can be understood, at least in part, from their usage in context. For example, terms such as “and,” “or,” or “and / or,” as used herein, can have various meanings, at least in part, depending on the context in which such terms are used. Typically, when “or” is used to relate a list such as “A, B, or C,” it is intended to mean both “A, B, and C,” used here in an inclusive sense, and “A, B or C,” used here in an exclusive sense. In addition, as used herein, the term “one or more” can be used, at least in part, depending on the context, to describe any feature, structure, or characteristic in a singular sense, or to describe a combination of features, structures, or characteristics in a plural sense. Similarly, terms such as "a," "an," or "the" can be understood, at least partially, depending on the context, to convey singular or plural usage. In addition, the term "based on" can be understood not as intended to convey an exclusive set of factors, but rather, again, at least partially, depending on the context, to allow for the presence of additional factors that are not necessarily explicitly stated.

[0090] Throughout this specification, references to features, benefits, or similar terms do not imply that all features and benefits that can be realized using the Solution should be included in, or are included in, any single implementation thereof. Rather, terms referring to features and benefits should be understood to mean that specific features, benefits, or characteristics described in relation to a particular embodiment are included in at least one embodiment of the Solution. Accordingly, discussions of features and benefits, as well as similar terms, throughout this specification may, but not necessarily, refer to the same embodiment.

[0091] Furthermore, the described features, benefits, and characteristics of this solution may be combined in any preferred manner in one or more embodiments. Those skilled in the art will recognize, in light of the description herein, that this solution may be practiced without any particular features or benefits of a specific embodiment being surpassed. In other instances, additional features and benefits that may not be present in all embodiments of this solution may be recognized in certain embodiments.

Claims

1. A method for wireless communication, wherein the method is performed by a wireless device in a wireless network, and the method is In response to the fulfillment of execution conditions, the system selects a target primary secondary cell (PScell) within a radio access network (RAN), wherein the target PScell ​​is associated with a target secondary node (SN), the target SN is a component of a list of multiple SNs, each SN in the list of multiple SNs is associated with an SN counter, and the SN counter associated with each SN in the list of multiple SNs is used to calculate a security key for each SN in the list of multiple SNs. To determine whether the SN counter associated with the target SN needs to be updated, When it is determined that the SN counter associated with the target SN needs to be updated, a refreshed SN counter value is selected, and the SN counter associated with the target SN is updated using the refreshed SN counter value, wherein the refreshed SN counter value is different from any previous SN counter value shared between the wireless device and the master node. Transmitting a first message to the master node requesting a switch from the current PScell ​​to the target PScell, wherein the first message includes the refreshed SN counter value. Receiving a second message from the master node, the second message indicating that the target SN is ready to establish a secure connection with the wireless device based on the target SN key, the target SN key being derived based on the refreshed SN counter value, In response to the second message, the target SN key is derived based on the refreshed SN counter value, Based on the target SN key, activate the security configuration associated with the target PScell. Methods that include...

2. Determining whether the SN counter associated with the target SN needs to be updated is: In response to the fact that the SN associated with the target PScell ​​is different from the SN associated with the current PScell, it is determined that the SN counter associated with the target SN needs to be updated. The method according to claim 1, including the method described in claim 1.

3. The method according to claim 1, wherein the wireless device has a dual connection with the RAN, the dual connection includes a connection between the wireless device and the current PScell, and the dual connection further includes a primary connection between the wireless device and the master node.

4. The initial value of the SN counter associated with each SN in the list of multiple SNs is pre-configured to an integer value, or The method according to claim 1, wherein the initial value of the SN counter associated with each SN in the list of plurality of SNs is pre-configured to the same integer value by the master node.

5. Selecting the refreshed SN counter value means The refreshed SN counter value is obtained by monotonically increasing the maximum value among all the values ​​in the SN counter associated with the list of multiple SNs by a predefined number. The method according to claim 1, including the method described in claim 1.

6. Selecting the refreshed SN counter value means Select a random integer value as the refreshed SN counter value. The method according to claim 1, including the method described in claim 1.

7. Each of the master node and the SN includes a base station, and the base station is gNodeB (gNB), eNodeB (eNB), ng-eNodeB (ng-eNB), or, NodeB The method according to claim 1, comprising one of the following.

8. A method for wireless communication, the method being performed by a master network node in the RAN of a wireless network, the method is Receiving a first message from a wireless device requesting the wireless device to switch from the current PScell ​​to a target PScell, wherein the first message includes a refreshed SN counter value for updating the SN counter, the refreshed SN counter value indicating that the target SN associated with the target PScell ​​is different from the SN associated with the current PScell, The refreshed SN counter value is used to update the SN counter, The method involves updating the target SN key based on the refreshed SN counter value, wherein the updated target SN key is used to secure the link between the target PScell ​​and the wireless device. The second message, including the updated target SN key, is transmitted to the target SN. Receiving an acknowledgment of receipt for the second message from the target SN, The method involves transmitting a response message to the first message to the wireless device, the response message indicating that the target SN is ready to establish a secure connection with the wireless device based on the target SN key, the target SN key being derived based on the refreshed SN counter value. Methods that include...

9. The method according to claim 8, wherein the wireless device has a dual connection with the RAN, and the dual connection includes a secondary connection between the wireless device and the current PScell ​​and a primary connection between the wireless device and the master network node.

10. Each of the master network node and the SN includes a base station, and the base station is gNodeB (gNB), eNodeB (eNB), ng-eNodeB (ng-eNB), or, NodeB The method according to claim 8, comprising one of the following.

11. A wireless device comprising a memory for storing computer instructions and a processor for communicating with the memory, wherein when the processor executes the computer instructions, the processor In response to the fulfillment of execution conditions, the system selects a target primary secondary cell (PScell) within a radio access network (RAN), wherein the target PScell ​​is associated with a target secondary node (SN), the target SN is a component of a list of multiple SNs, each SN in the list of multiple SNs is associated with an SN counter, and the SN counter associated with each SN in the list of multiple SNs is used to calculate a security key for each SN in the list of multiple SNs. To determine whether the SN counter associated with the target SN needs to be updated, When it is determined that the SN counter associated with the target SN needs to be updated, a refreshed SN counter value is selected, and the SN counter associated with the target SN is updated using the refreshed SN counter value, wherein the refreshed SN counter value is different from any previous SN counter value shared between the wireless device and the master node. Transmitting a first message to the master node requesting a switch from the current PScell ​​to the target PScell, wherein the first message includes the refreshed SN counter value. Receiving a second message from the master node, the second message indicating that the target SN is ready to establish a secure connection with the wireless device based on the target SN key, the target SN key being derived based on the refreshed SN counter value, In response to the second message, the target SN key is derived based on the refreshed SN counter value, Based on the target SN key, activate the security configuration associated with the target PScell. A wireless device configured to cause the wireless device to perform the aforementioned action.

12. When the processor is configured to cause the wireless device to determine whether the SN counter associated with the target SN needs to be updated, the processor: In response to the fact that the SN associated with the target PScell ​​is different from the SN associated with the current PScell, it is determined that the SN counter associated with the target SN needs to be updated. The wireless device according to claim 11, configured to cause the wireless device to perform the above.

13. When the processor is configured to cause the wireless device to select the refreshed SN counter value, the processor: The refreshed SN counter value is obtained by monotonically increasing the maximum value among all the values ​​in the SN counter associated with the list of multiple SNs by a predefined number. The wireless device according to claim 11, configured to cause the wireless device to perform the above.

14. When the processor is configured to cause the wireless device to select the refreshed SN counter value, the processor: Select a random integer value as the refreshed SN counter value. The wireless device according to claim 11, configured to cause the wireless device to perform the above.

15. Each of the master node and the SN includes a base station, and the base station is gNodeB (gNB), eNodeB (eNB), ng-eNodeB (ng-eNB), or, NodeB The wireless device according to claim 11, comprising one of the following.