Terminal device, base station device, and control method for efficient updating of security keys

The implementation of security key updates in LTM handovers across gNB-CUs addresses the inefficiencies in conventional LTM by efficiently updating security keys, ensuring secure communication.

JP7851981B2Active Publication Date: 2026-04-27KDDI CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
KDDI CORP
Filing Date
2024-03-29
Publication Date
2026-04-27

Smart Images

  • Figure 0007851981000001
    Figure 0007851981000001
  • Figure 0007851981000002
    Figure 0007851981000002
  • Figure 0007851981000003
    Figure 0007851981000003
Patent Text Reader

Abstract

To efficiently update parameters related to a security key in handover using LTM.SOLUTION: A terminal device conforming to a 3GPP cellular communication standard: receives, from a first base station device being connected, first configuration information of LTM, for each of a plurality of base station devices, of handover destination candidates including a second base station device and a third base station device, and second configuration information associated with the first configuration information and for updating a security key; holds the first configuration information and the second configuration information in association with each of the plurality of base station devices; executes handover to the second base station device; updates the security key by using the second configuration information associated with the first configuration information of the second base station device in response to the handover to the second base station device; and updates the second configuration information associated with the first configuration information while maintaining the held first configuration information of the third base station device after the execution of the handover.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to a security key renewal technique for cellular communication systems. [Background technology]

[0002] In cellular communication standards such as 5G, which comply with the 3rd Generation Partnership Project (3GPP®), the Layer 1 / Layer 2 Triggered Mobility (LTM) mechanism has been introduced to reduce the time required for handover. Conventional LTM applies to handovers within the range of a common gNB-Central Unit (CU) and does not apply to handovers across gNB-CUs. Therefore, with conventional LTM, there is no need to update parameters related to security keys for encryption and integrity protection. [Overview of the Initiative] [Problems that the invention aims to solve]

[0003] In the future, it is expected that LTM will be applied to handovers across gNB-CUs. In this case, it will be necessary to update the security key-related parameters as described above. [Means for solving the problem]

[0004] This invention provides an efficient technique for updating parameters related to security keys during handover by LTM.

[0005] A terminal device according to an aspect of the present invention is a terminal device compliant with a cellular communication standard of the 3rd Generation Partnership Project (3GPP), and for each of a plurality of base station devices that are candidates for a handover destination including a second base station device and a third base station device from a first base station device during connection, reception means for receiving first setting information of Layer 1 / Layer 2 Triggered Mobility (LTM) and second setting information respectively associated with the first setting information for updating a security key; holding means for associating and holding the first setting information and the second setting information for each of the plurality of base station devices; execution means for executing a handover to the second base station device; and updating means for updating the security key using the second setting information associated with the first setting information of the second base station device in response to the handover to the second base station device, and for updating the second setting information associated with the first setting information while maintaining the first setting information for the third base station device held after the execution of the handover.

[0006] A base station device according to an aspect of the present invention is a base station device compliant with the cellular communication standard of the Third Generation Partnership Project (3GPP). The base station device provides, as candidates for a handover destination, to a first other base station device to which a terminal device is connected, first setting information of Layer 1 / Layer 2 Triggered Mobility (LTM), and second setting information respectively associated with the first setting information for updating a security key. The base station device further includes connection means for connecting to the terminal device upon handover of the terminal device, generation means for generating a security key used in communication with the terminal device using the second setting information, acquisition means for acquiring the first setting information and the second setting information for a second other base station device which is a candidate for the handover destination of the terminal device from the base station device after the handover is executed, and transmission means for transmitting, to the terminal device, a message that does not include the first setting information and includes the second setting information for the second other base station device when the terminal device holds the first setting information for the second other base station device.

Advantages of the Invention

[0007] According to the present invention, parameters related to a security key during handover by LTM can be efficiently updated. <000,098>

Brief Description of the Drawings

[0008] [Figure 1] It is a diagram showing a configuration example of a wireless communication system. [Figure 2] It is a diagram showing an example of a process related to update of a conventional security key. [Figure 3] It is a diagram showing an example of a process related to update of a conventional security key. [Figure 4] It is a diagram showing an example of a process related to update of the security key of the present embodiment. [Figure 5] It is a diagram showing an example of a process related to update of the security key of the present embodiment. [Figure 6]This figure shows an example of the hardware configuration of a base station device and a terminal device. [Figure 7] This figure shows an example of the functional configuration of a terminal device. [Figure 8] This figure shows an example of the functional configuration of a base station device. [Modes for carrying out the invention]

[0009] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims, and not all combinations of features described in the embodiments are essential to the invention. Two or more of the features described in the embodiments may be combined in any way. Furthermore, identical or similar configurations will be given the same reference numeral, and redundant descriptions will be omitted.

[0010] Figure 1 shows an example configuration of a wireless communication system according to this embodiment. This wireless communication system is a cellular communication system compliant with the 3GPP® cellular communication standard and consists of base station equipment (e.g., base station equipment 101, base station equipment 102) and terminal equipment (e.g., terminal equipment 111). Terminal equipment 111 is connected to base station equipment 101 and then moves towards base station equipment 102 to perform a handover to base station equipment 102. In Figure 1, only two base station equipment and one terminal equipment are shown for simplicity of explanation, but of course, many more of these devices can exist.

[0011] In such a wireless communication system, when terminal device 111 performs a handover, the processing flow regarding security keys may differ depending on whether base station device 101 and base station device 102 are associated with a common Access and Mobility Management Function (AMF) (or whether an Xn interface has been established). This difference in procedure will be explained using examples from Figures 2 and 3. In Figures 2 and 3, only the parts particularly relevant to this embodiment will be explained in detail, while other matters will only be described in outline.

[0012] Figure 2 shows an example of the processing flow when the base station device that is the source of the handover (base station device 101) and the base station device that is the destination of the handover (base station device 102) are associated with a common AMF and an Xn interface is established between these base station devices. In this process, for example, when the conditions for initiating a handover are met in terminal device 111, a measurement report is notified from terminal device 111 to base station device 101 (S201). Based on this measurement report, base station device 101 determines to hand over terminal device 111 to base station device 102, and then K, which is the parameter used before the handover in base station device 101, the current destination of terminal device 111, is NG-RAN * Based on parameters such as nextHopChainingCount (NCC), the post-handover K should be used in communication between the base station device 102 and the terminal device 111. NG-RAN * The derived K is derived (S202). Then, base station device 101 sends a HANDOVER REQUEST message to base station device 102 (S203). At this time, the HANDOVER REQUEST message contains the derived K NG-RAN *and the value of the NCC used when deriving the value are included. Note that, between the terminal device 111 and the base station device 101, similar to a normal handover, processes such as the base station device 101 notifying the terminal device 111 of the setting information for connection to the handover destination base station device 102 are performed (not shown). Then, the terminal device 111 executes a random access procedure with the base station device 102 and establishes a connection with the base station device 102. At that time, the base station device 102 sets keySetChangeIndicator to False and transmits an RRC Reconfiguration message including the value of the NCC to the terminal device 111 (S204). Note that RRC is an abbreviation for Radio Resource Control. Thereby, the terminal device 111 uses the value of the NCC and the K NG-RAN * and other parameters to derive the K NG-RAN * used for generating a security key in communication with the base station device 102. In response thereto, the terminal device 111 transmits an RRC Reconfiguration Complete message to the base station device 102 (S205). Then, the base station device 102 transmits an NGAP PATH SWITCH REQUEST message to the AMF associated with itself (S206). In response to that message, the AMF transmits an NGAP PATH SWITCH REQUEST ACKNOWLEDGE message to the base station device 102 (S207). This message includes, when the terminal device 111 performs a handover from the base station device 102 to yet another base station device, the base station device 102 can derive the K NG-RAN * and includes Next Hop (NH) and NCC as parameters for that purpose. The base station device 102 stores the received NH and NCC (S208). Thus, when the base station device 101 and the base station device 102 are associated with a common AMF, the terminal device 111 uses the value of the NCC obtained from the base station device 102 and the K heldNG-RAN * Using this, K is used to generate a security key used for communication with the base station device 102. NG-RAN * It can be updated.

[0013] Figure 3 shows an example of the processing flow when the handover source base station device (base station device 101) and the handover destination base station device (base station device 102) are associated with different AMFs. In this process, similar to the example in Figure 2, a measurement report is sent from the terminal device 111 to the base station device 101 (S301), and the handover process is started based on it. Base station device 101 sends an NGAP HANDOVER REQUIRED message to the AMF it is associated with, and the handover request is forwarded to the other AMF to which the handover destination base station device 102 is associated (S302). Then, the handover destination AMF sends an NGAP HANDOVER REQUEST message to the handover destination base station device 102 (S303). Note that this message contains K NG-RAN * The information used to generate a new one includes the NAS container, NH, and NCC. NAS stands for Non-Access Stratum. The base station device 102 stores the received NH and NCC (S304), and based on the received information, K NG-RAN * This generates (S305). In other words, in the process shown in Figure 3, K NG-RAN * A new one was generated, and the K that was used before the handover was replaced. NG-RAN * This is not used to generate a new key. Subsequently, base station device 102 sends an NGAP HANDOVER REQUEST ACKNOWLEDGE to the AMF (S306), and in response, an NGAP HANDOVER COMMAND is sent to base station device 101 via the AMF that handed over to the base station (S307). At this time, K NG-RAN *Information that enables the derivation of is notified to the terminal device 111 via the base station device 101 through an RRC Reconfiguration message (S308). Subsequently, the terminal device 111 completes the connection with the base station device 102 by performing random access procedures, etc. (S309).

[0014] Furthermore, the same K NG-RAN * A K is generated, and that K NG-RAN * Using this, key K for user data confidentiality. UPsec This is generated.

[0015] In this embodiment, the terminal device 111 changes the connected base station device using Layer 1 / Layer 2 Triggered Mobility (LTM) to shorten the time required for handover. LTM may be understood as an abbreviation for Lower Layer Triggered Mobility. Conventionally, LTM has only been applied to handovers between base station devices connected to a common gNB-Central Unit (CU). Therefore, in conventional LTM handovers, configuration information (parameters) related to security keys are not updated. In contrast, in handovers across gNB-CUs, it is necessary to update the configuration information related to security keys. This embodiment provides a procedure for efficiently updating the configuration information (parameters) for generating security keys in LTM handovers across gNB-CUs.

[0016] Figure 4 shows an example of a handover procedure across gNB-CUs according to this embodiment. Figure 4 shows an example where there are two candidate base station devices for the handover. These candidate base station devices for the handover are assumed to be associated with a different AMF than the base station device to which they are connected. For this reason, the AMF is omitted in the example of Figure 4, but each base station device is assumed to perform processing that involves communication with the AMF as shown in Figures 2 and 3.

[0017] In this process, the base station device that is the source of the handover (connected to the terminal device) sends a HANDOVER REQUEST message to other base station devices that are candidates for handover, based on, for example, the measurement results from the terminal device (S401). The candidate base station devices that are candidates for handover then respond to this message by sending back a HANDOVER REQUEST ACK message (S402, S403). This HANDOVER REQUEST ACK message includes configuration information for LTM (LTM configuration), and this configuration information includes MasterKeyUpdate, which is information for updating the security key. This is just an example, and LTM configuration may not include MasterKeyUpdate, and they may be notified and managed as separate pieces of information. However, LTM configuration and MasterKeyUpdate are assumed to be related to each other. Here, MasterKeyUpdate includes, for example, KeySetChangeIndicator (set to True), NAS container, and NCC when the associated AMF is changed. Furthermore, if the associated AMF is not changed, MasterKeyUpdate includes KeySetChangeIndicator (set to False) and NCC. The handover originating base station device transfers the LTM configuration, including the MasterKeyUpdate, to the terminal device (S404). Upon receiving this information, the terminal device sends a response message to the handover originating (connected) base station device (S405). Note that the transfer of the LTM configuration in S404 may be performed using, for example, an RRC Reconfiguration message, and the response to that message may be performed using an RRC Reconfiguration Complete message.

[0018] Subsequently, based on the Layer 1 (physical layer) measurement results (L1 measurement) measured by the terminal device, the base station device to which the terminal device is connected decides to perform a handover, and a Cell Switch Command instructing the handover is sent from the base station device to the terminal device (S406, S407). The terminal device performs random access procedures, etc., with the base station device to which the handover is to be performed as instructed by the command (S408, S409), and establishes a connection with that base station device using the LTM configuration for that base station device. At this time, the terminal device also uses the MasterKeyUpdate information included in the LTM configuration to K NG-RAN * Update the KeySetChangeIndicator, NAS container, and NCC that were previously used. For example, if a terminal device receives a MasterKeyUpdate that includes KeySetChangeIndicator (set to True), NAS container, and NCC, it will update the KeySetChangeIndicator that was previously used. NG-RAN * Regardless, based on the information received, a new K NG-RAN * It generates a MasterKeyUpdate that includes a KeySetChangeIndicator (set to False) and NCC. NG-RAN * Using NCC, the K used after the handover NG-RAN * Generates.

[0019] Here, we will explain how to update the configuration information related to security keys after a handover. First, after connecting with the base station device to which the handover is taking place, if the candidate base station device to which the handover is taking place from that base station device is associated with a common AMF, that is, the base station device to which the handover is taking place (the base station device that will become the base station device communicating after the handover) is K NG-RAN *An example of the process when generating this will be explained. When the handover destination base station device receives the RRC Reconfiguration Complete message from the terminal device, it sends a HANDOVER SUCCESS message to the handover originating base station device indicating that the handover was successful (S410). At this time, the HANDOVER SUCCESS message contains the K held by the handover destination base station device. NG-RAN * and NCC (i.e., K generated based on MasterKeyUpdate included in the LTM configuration of the device) NG-RAN * This includes K (and NCC). The handover originating base station device notifies other candidate base station devices (candidate base station device #2 in the example of Figure 4) that the base station device to which the terminal device is connected has changed (in the example of Figure 4, the connection destination has changed to candidate base station device #1). At this time, the handover originating base station device includes K in HANDOVER SUCCESS. NG-RAN * The NCC information is transmitted to other candidate base station devices, requesting that the LTM configuration, including the updated MasterKeyUpdate, be forwarded to the handover base station device (S411). In response to this request, the candidate base station device updates the MasterKeyUpdate and transmits the LTM configuration, including the information of the updated MasterKeyUpdate, to the handover base station device (S412).

[0020] Next, if, after connecting with the base station device to which the handover will take place, the candidate base station device to which the handover will take place from that base station device is associated with a different AMF, that is, if the candidate base station device after the handover (the base station device that continues to be a candidate base station device after the handover) is K NG-RAN *An example of the process when generating this will be explained. When the handover destination base station device receives the RRC Reconfiguration Complete message from the terminal device, it sends a HANDOVER SUCCESS message to the handover originating base station device indicating that the handover was successful (S410). At this time, the HANDOVER SUCCESS message contains the K held by the handover destination base station device. NG-RAN * And NCC may not be included. The handover originating base station device notifies the candidate base station device that the base station device to which the terminal device is connected has changed (in the example in Figure 4, the connection destination has changed to candidate base station device #1) via the first AMF to which the handover originating base station device is associated, and the second AMF to which the base station device that was not selected as the handover destination and will remain a candidate base station device after the handover is associated. At this time, the second AMF associated with the candidate base station device is K NG-RAN * As information for generating a new MasterKeyUpdate, the NAS container, NH, and NCC are notified to the candidate base station device. Subsequently, the candidate base station device updates the MasterKeyUpdate using the NAS container, NH, and NCC, and transmits the LTM configuration containing the MasterKeyUpdate information to the handover base station device via the second AMF to which it is associated and the third AMF to which the handover target base station device (candidate base station device #1 in the example of Figure 4) is associated.

[0021] The candidate base station device determines, for example, whether it is connected to a common AMF (An Xn interface has been established) with the handover target base station device, and then determines the contents of the MasterKeyUpdate. For example, if the candidate base station device is associated with a common AMF with the handover target base station device, it may generate a MasterKeyUpdate that includes a keySetChangeIndicator set to False and the notified NCC. If the candidate base station device is associated with a different AMF than the handover target base station device, it may obtain the NAS container, NH, and NCC by querying the AMF to which it is associated, and generate a MasterKeyUpdate that includes a keySetChangeIndicator set to True, a NAS container, and NCC. The candidate base station device then transmits the generated MasterKeyUpdate to the handover target base station device.

[0022] When the handover destination base station device (candidate base station device #1 in the example in Figure 4) receives MasterKeyUpdate update information from the candidate base station device, it transmits the received MasterKeyUpdate information to the terminal device in a format that associates it with the candidate base station device's LTM configuration (S413). When the terminal device receives the MasterKeyUpdate, it updates the MasterKeyUpdate information included in the LTM configuration of the candidate base station device (candidate base station device #2 in the example in Figure 4) with the received information. After the MasterKeyUpdate update is complete, the terminal device sends a response message to the handover destination base station device (S414). In one example, an RRC Reconfiguration message may be used when transmitting information in S413, and the terminal device may send RRC Reconfiguration Complete as the response message in S414 to the handover destination base station device. However, this is just one example, and other messages may be used.

[0023] In this example, the terminal device receives parameters related to the security key (MasterKeyUpdate) as part of the LTM configuration. When an LTM handover is performed, the terminal device can reuse the LTM configuration of a candidate base station that was not selected as the handover destination. However, given that the configuration information related to the security key within the LTM configuration should be updated, this configuration information can be obtained via the handover destination base station. This allows the terminal device to efficiently update the security key-related configuration information for candidate base stations that should still be treated as handover destinations after the handover, while maintaining much of the LTM configuration.

[0024] Figure 4 shows an example where there is only one candidate base station device that was not selected by the handover, but it is naturally assumed that there may be multiple such candidate base station devices. In this case, when configuration information related to the security key (MasterKeyUpdate) is notified from the handover destination base station device, information indicating which candidate base station device the configuration information pertains to is also notified. For example, if each LTM configuration set in the terminal device is assigned identification information (LTM configuration id), the configuration information related to the security key may be notified in association with that identification information. In one example, if the MasterKeyUpdate is updated for only some candidate base station devices, the LTM configuration id for those candidate base station devices and the MasterKeyUpdate for those candidate base station devices are notified in association with each other. The identification information of the base station device may also be notified in association with the configuration information related to the security key. In other words, any identification information may be used as long as it can identify the configuration information related to the security key to be updated. Furthermore, when configuration information for all candidate base station devices is notified, the configuration information may be notified in a predetermined order, such as ascending or descending order of the LTM configuration id. In this case, the order in which the configuration information is notified allows for identification of which candidate base station device (LTM configuration id) the configuration information pertains to; therefore, explicit notification of identification information is not necessary.

[0025] The above explanation describes the processing for Master Cell Groups (MCGs), but similar processing may be performed for Secondary Cell Groups (SCGs). That is, for base station equipment that provides candidate cells for secondary cells, the LTM configuration may include information on the SK-Counter parameter related to the security key for the SCG and notify the terminal equipment. Then, after the destination cell is changed by Cell Switch Command, update information regarding SK-Counter in the LTM configuration may be notified to the terminal equipment from the base station equipment that provides the changed destination cell. In addition, the LTM configuration may include both MasterKeyUpdate for MCGs and SK-Counter for SCGs. In this case, after the handover is performed by the LTM configuration, the terminal equipment and base station equipment will communicate using Dual Connectivity with both master and secondary cells, but MasterKeyUpdate will be used to generate the security key for the master cell, and SK-Counter will be used to generate the security key for the secondary cell. Furthermore, if there are any unselected LTM configurations after the handover, and those LTM configurations include both MasterKeyUpdate for MCG and SK-Counter for SCG, then update information for both MasterKeyUpdate and SK-Counter will be notified to the terminal device after the handover.

[0026] Figure 4 shows an example where the originating base station sends a message to a candidate base station that was not selected as the handover destination, requesting the transfer of the LTM configuration to the handover destination base station. However, this is just one example; for example, the handover destination base station may request the candidate base station to send the LTM configuration. Figure 5 shows an example of the processing flow in this case. In the example in Figure 5, the same reference numerals are used for processes similar to those in Figure 4, and their explanation is omitted.

[0027] In this process, when the handover originating base station device receives a HANDOVER SUCCESS message from the handover destination base station device, it forwards the LTM configuration of the candidate base station device that was not selected as the handover destination, which was received in S403, to the handover destination base station device (S501). This forwarding of the LTM configuration may be done by a HANDOVER SUCCESS ACK message, which is a response to the HANDOVER SUCCESS message. However, this is just one example, and the forwarding of the LTM configuration may be done by other messages. The handover destination base station device then requests configuration information for updating the security key from the candidate base station device that was not selected as the handover destination, corresponding to the received LTM configuration (S502). The handover destination base station device may request MasterKeyUpdate using, for example, a HANDOVER REQUEST message. This message contains the K used by the handover destination base station device. NG-RAN *The message may include NCC information held by the base station device. The message may also include information indicating that the LTM configuration corresponding to the configuration information for updating the security key to be obtained has already been notified to the terminal device (from the handover base station device). The candidate base station device recognizes that an update to the configuration information for the security key is necessary with respect to the LTM configuration previously notified to the handover base station device, performs the update, and sends the updated configuration information to the handover destination base station device (S503). At this time, information included in the LTM configuration other than MasterKeyUpdate does not need to be sent to the handover destination base station device. The candidate base station device may send the updated configuration information to the handover destination base station device using, for example, a HANDOVER REQUEST ACK message. When the handover destination base station device obtains MasterKeyUpdate, it forwards that information to the terminal device (S413).

[0028] In this way, in the process shown in Figure 5, as in the case of Figure 4, updated configuration information regarding the security key can be notified to the terminal device. In the above embodiment, if the base station device to which the handover is to take place and the candidate base station device after the handover are associated with a common AMF, that is, if the base station device to which the handover is to take place (the base station device that will become the base station device communicating after the handover) is K NG-RAN * The process for generating this was explained, but the candidate base station device after the handover (the base station device that will continue to be a candidate base station device after the handover) is K NG-RAN *It is also possible to generate a K. That is, the base station device to which the handover is to take place and the candidate base station device after the handover may be associated with different AMFs. In this case, the base station device to which the handover is to take place notifies the candidate base station device (candidate base station device #2 in the example of Figure 5) that the base station device to which the terminal device is connected has changed (in the example of Figure 5, the connection destination has changed to candidate base station device #1), via the first AMF to which the base station device is associated and the second AMF to which the candidate base station device that will continue to be the handover destination is associated. At this time, the second AMF generates a K NG-RAN * As information for generating a new MasterKeyUpdate, the NAS container, NH, and NCC are notified to the candidate base station device. Subsequently, the candidate base station device (candidate base station device #2 in the example in Figure 5) updates the MasterKeyUpdate using the NAS container, NH, and NCC, and transmits the MasterKeyUpdate information, or the LTM configuration containing the MasterKeyUpdate information, to the handover destination base station device (candidate base station device #1 in the example in Figure 5) via the second AMF and the first AMF. Then, when the handover destination base station device obtains the MasterKeyUpdate, it forwards that information to the terminal device (S413).

[0029] In the above embodiment, an example was described in which the LTM configuration includes configuration information (MasterKeyUpdate) for updating the security key and is sent, but this is not limited to this. For example, the configuration information may not be included in the LTM configuration, but may be included in the Cell Switch Command in S407. For example, if the base station device that is the source of the handover and the base station device that is the destination of the handover are associated with a common AMF, as shown in S204 of Figure 2, the NAS container may not be notified to the terminal device, and the NCC information may be notified to the terminal device. In such a case, the base station device that is the source of the handover may send the LTM configuration without including the configuration information, and send the Cell Switch Command with the configuration information (NCC) included. In this case, the keySetChangeIndicator may be omitted. Also, when performing a handover by Cell Switch Command, the LTM configuration id, or information that can identify the LTM configuration id, is included in Cell Switch Command. The terminal device uses the LTM configuration id, or information that can identify the LTM configuration id, to identify the base station device that is the destination of the handover. The terminal device uses the NCC included in Cell Switch Command to communicate with the base station device to which it is handing over. NG-RAN *The following is updated. Note that the Cell Switch Command may include the NCC value itself, or it may include other information that can identify the NCC. For example, the LTM configuration may pre-assign identification information to each of multiple NCCs, and that identification information may be included in the Cell Switch Command. In this case, in an environment where encryption is performed by signaling at the RRC layer, the LTM configuration notified will send identification information to identify the NCC, and the Cell Switch Command, which is not encrypted, will send only the identification information, thus preventing the interceptor from identifying the NCC even if the Cell Switch Command is intercepted.

[0030] Furthermore, for some candidate base station devices, the LTM configuration may include configuration information for updating the security key, as described above, while for other candidate base station devices, the LTM configuration may not include configuration information for updating the security key, and this information may be notified via Cell Switch Command. Also, even if the LTM configuration includes configuration information for updating the security key, at least a portion of this information may be transmitted via Cell Switch Command. In this case, the configuration information included in the LTM configuration may be updated and used by the configuration information specified by Cell Switch Command. In one example, suppose the first base station device that is the source of the handover and the second base station device that is the destination of the handover are associated with different AMFs, and the second base station device and the third base station device, which is a candidate not selected as the handover destination, are associated with a common AMF. In this case, before the handover from the first base station device to the second base station device takes place, MasterKeyUpdate is associated with the LTM configurations for the second and third base station devices and notified to the terminal devices, as described above. In this case, MasterKeyUpdate includes the keySetChangeIndicator set to True, the NAS container, and the NSS. Subsequently, when a handover occurs from the first base station device to the second base station device, the MasterKeyUpdate on the third base station device becomes outdated and requires updating. On the other hand, when a handover occurs from the second base station device to the third base station device, information such as the NAS container is not required to update the security key; NCC information is sufficient. For this reason, after a handover from the first base station device to the second base station device, notification of MasterKeyUpdate for the third base station device can be omitted, and information that can identify the NCC can be notified by a subsequent Cell Switch Command.According to this, the terminal device will continue to retain outdated information about the third base station device, but the NCC can be identified by Cell Switch Command, and the security key can be updated using that NCC without using the outdated information.

[0031] Furthermore, if the LTM configuration only contains SCG configuration information, when adding a secondary cell corresponding to that LTM configuration, the security key for the MCG does not need to be updated; only the security key for the secondary cell needs to be generated / updated. In this case, updating the configuration information (SK-Counter) related to the security key for the secondary cell may be performed using a different procedure than described above.

[0032] For example, a base station device may include a list of configuration information (SK-Counter) related to the SCG security key for each base station device that provides a candidate cell for the MCG in the LTM configuration (using the RRC Reconfiguration message) and send it to the connected terminal device. For example, a separate list of SK-Counters is set for each of candidate base station devices #1 and candidate base station device #2 in Figure 4 or Figure 5, and this list is sent to the terminal device. The terminal device also maintains this list of SK-Counters for the connected base station device that provides the MCG cell. For example, the terminal device may maintain SK-CounterA1, SK-CounterA2, ..., SK-CounterA16 for the connected base station device, and SK-CounterB1, SK-CounterB2, ..., SK-CounterB16 for candidate base station device #1. In other words, a separate list of SK-Counters is defined for each candidate base station device that can provide an MCG cell. Then, when the terminal device receives a Cell Switch Command indicating the addition of a secondary cell while communicating with the connected base station device, it generates a security key for that secondary cell using SK-CounterA1, which is at the top of the list. Subsequently, when the terminal device receives a Cell Switch Command instructing another cell to be designated as a secondary cell while communicating with the connected base station device, it updates the security key for the changed secondary cell using SK-CounterA2. At this time, the terminal device removes the previously used SK-CounterA1 from the list. In this way, if the SCG is changed without the MCG being changed, the terminal device can update the security key for the SCG sequentially using the SK-Counters included in the previously notified list. That is, the list of SK-Counters may be provided in common for each MCG, for multiple candidate SCGs that can be configured with that MCG.Therefore, as long as there are no changes to the MCG, the terminal device can repeatedly update the security key for the SCG using the SK-Counter included in the list each time the SCG is changed. As a result, it is not necessary to query the base station device (which provides the candidate SCG) as shown in Figures 4 and 5 each time the SCG is changed.

[0033] Subsequently, the terminal device receives a Cell Switch Command instructing it to change the MCG (handover) and assumes it has handed over to candidate base station device #1. Then, if the terminal device receives a Cell Switch Command instructing it to add an SCG, it generates the security key for that SCG using SK-CounterB1, which is at the top of the list associated with candidate base station device #1. The terminal device then removes SK-CounterA2, which was previously used, from the list. In this way, by setting a separate list of SK-Counters for each MCG, the security keys for secondary cells can be efficiently generated after a handover.

[0034] Furthermore, a base station connected to a terminal device may instruct the terminal device to delete some or all of the configured SK-Counter list. This instruction may be sent from the base station to the terminal device, for example, using an RRC Reconfiguration message. Note that the deletion of the list may be performed by such an explicit instruction from the base station device, or it may be performed without instruction from the base station device when certain conditions are met. For example, if the MCG has been changed by a Cell Switch Command or a conventional handover, the list associated with the MCG from which the handover originated, which is held in the terminal device, may be deleted. Note that if the MCG from which the handover originated is treated as a candidate for the handover destination after the handover, it is assumed that the LTM configuration for that MCG and its corresponding SCG will not be deleted. In this case, the list may not be deleted either. Also, if the MCG has been changed, the list configured for candidate MCGs that were not selected as the handover destination of the terminal device may be deleted. In this case as well, whether or not the list is deleted may be determined depending on whether or not the LTM configuration is maintained. For example, a list of MCG candidates that are excluded from the handover candidates may be deleted along with the LTM configuration, while lists of other MCG candidates may remain. Alternatively, the decision of whether or not to delete the list may be made depending on the handover base station equipment. In this case, configuration information for that decision may be notified to the terminal equipment in advance. Furthermore, the base station equipment may notify the terminal equipment of information specifying the criteria for deleting the list, and the terminal equipment may delete the list according to those criteria.

[0035] The above example described how the LTM configuration is handled when a terminal device receives the LTM configuration from the connected base station device and then a handover occurs. This process also applies to the LTM configuration that was maintained before the handover. That is, the terminal device receives configuration information for updating the LTM configuration and security key from the base station device that was connected to the currently connected base station device. The terminal device can then update the configuration information for updating the security key while maintaining the LTM configuration for the candidate base station device that was not selected as the handover destination due to the handover to the currently connected base station device. Subsequently, if the terminal device performs another handover, it can perform the above process. That is, the terminal device can update only the configuration information for updating the security key contained within or associated with the LTM configuration received and held from a base station device that is not currently connected.

[0036] Figure 6 shows an example of the hardware configuration of a base station device and a terminal device according to this embodiment. In one example, the base station device and terminal device include a processor 601, ROM 602, RAM 603, storage device 604, and communication circuit 605. The processor 601 is a computer that includes one or more processing circuits, such as a general-purpose CPU (Central Processing Unit) or an ASIC (Application-Specific Integrated Circuit), and executes the overall control processing of the device and the above-mentioned processing by reading and executing programs stored in the ROM 602 and storage device 604. The ROM 602 is a read-only memory that stores information such as programs and various parameters related to the processing performed by the base station device and terminal device. The RAM 603 functions as a workspace when the processor 601 executes programs and is a random access memory that stores temporary information. The storage device 604 is composed of, for example, a removable external storage device. The communication circuit 605 is composed of, for example, a circuit for wireless communication of 5G or its successor standards. Although Figure 6 shows one communication circuit 605, base station equipment and terminal equipment may have multiple communication circuits. For example, base station equipment and terminal equipment may have wireless communication circuits for 5G and its successor standards, respectively, and an antenna common to those circuits. Base station equipment and terminal equipment may also have separate antennas suitable for each standard. Furthermore, base station equipment may also have wired communication circuits used when communicating with other base station equipment or nodes in the core network. Furthermore, terminal equipment may also have communication circuits compliant with wireless communication standards other than cellular communication standards, such as wireless local area networks (LANs) and Bluetooth®. Base station equipment and terminal equipment may have separate communication circuits 605 for each of the multiple usable frequency bands, or they may have a common communication circuit 605 for at least a portion of those frequency bands.

[0037] Figure 7 shows an example of the functional configuration of a terminal device. The terminal device includes, for example, a setting information receiving unit 701, an LTM setting holding unit 702, a key information management unit 703, a key generation unit 704, and a communication unit 705. Note that Figure 7 shows only the functions particularly relevant to this embodiment, and various other functions that the terminal device may have are omitted from the illustration. For example, the terminal device naturally has other functions that terminal devices compliant with 5G and subsequent standards generally have. Also, the functional blocks in Figure 7 are shown schematically, and each functional block may be implemented as an integrated unit or further subdivided. Furthermore, each function in Figure 7 may be implemented, for example, by the processor 601 executing a program stored in the ROM 602 or storage device 604, or by a processor located inside the communication circuit 605 executing predetermined software. Note that the details of the processing performed by each functional unit are as described above, so only the general functions of the terminal device will be outlined here.

[0038] The configuration information receiving unit 701 receives various configuration information from the connected base station device. For example, the configuration information receiving unit 701 receives pre-configuration information for LTM for candidate base station devices to be handed over to. This pre-configuration information is, for example, configuration information for establishing an RRC layer connection with the candidate base station device, and is notified to the terminal device when the handover has not actually taken place. The pre-configuration information corresponds to the LTM configuration described above. The configuration information receiving unit 701 also receives configuration information for generating and updating security keys (for example, MasterKeyUpdate and SK-Counter). The LTM configuration holding unit 702 holds the LTM pre-configuration information received by the configuration information receiving unit 701. The LTM configuration holding unit 702 is configured to, for example, continue to hold pre-configuration information (LTM configuration) for candidate base station devices that were not selected as the handover destination after the handover has been performed. The LTM configuration holding unit 702 can, for example, delete the held pre-configuration information in response to instructions from the handover source base station device or the handover destination base station device. Furthermore, the LTM setting retention unit 702 may, for example, set an expiration date for the pre-configuration information and delete the pre-configuration information when that expiration date has passed. In this case, the expiration date may be notified by the base station equipment that was connected when the pre-configuration information was received.

[0039] The key information management unit 703 maintains and manages configuration information, such as security keys or parameters for generating those security keys, for both the connected base station device and the candidate base station devices for handover. For example, the key information management unit 703 manages the security key configuration information received from the connected base station device along with the LTM configuration, and manages it to ensure that the configuration information is up-to-date. For example, if the key information management unit 703 receives configuration information (MasterKeyUpdate) from the handover base station device for at least some of the candidate base station devices that were not selected as handover destinations, it replaces the configuration information it holds with the received configuration information. The key information management unit 703 may also obtain configuration information for generating security keys via Cell Switch Command. This allows the key information management unit 703 to maintain the security key configuration information in an up-to-date state. Furthermore, the key information management unit 703 maintains a list of SK-Counters for each MCG, for SCGs that may be used as secondary cells when that MCG is used, and can retrieve the SK-Counter values ​​sequentially from the list each time a connected SCG is changed or added, and generate a security key for that SCG. In addition, if an SCG is changed or deleted, the key information management unit 703 can remove the SK-Counter values ​​that were used to generate the security key for the SCG that is no longer in use from the list.

[0040] The key generation unit 704 generates a security key using configuration information (MasterKeyUpdate, SK-Counter) maintained by the key information management unit 703. The communication unit 705 communicates with the base station device to which it is connected using the security key generated by the key generation unit 704.

[0041] Figure 8 shows an example of the functional configuration of a base station device. The base station device includes, for example, a configuration information acquisition unit 801, a configuration information provision unit 802, a configuration information notification unit 803, a key generation unit 804, and a communication unit 805. Note that Figure 8 shows only the functions particularly relevant to this embodiment, and various other functions that the base station device may have are omitted from the illustration. For example, the base station device naturally has other functions that base station devices compliant with 5G and subsequent standards generally have. Also, the functional blocks in Figure 8 are shown schematically, and each functional block may be implemented as an integrated unit or further subdivided. Furthermore, each function in Figure 8 may be implemented, for example, by the processor 601 executing a program stored in the ROM 602 or storage device 604, or by a processor located inside the communication circuit 605 executing predetermined software. Note that the details of the processing performed by each functional unit are as described above, so only the general functions of the base station device will be outlined here.

[0042] The configuration information acquisition unit 801 acquires configuration information from other base station devices. For example, while connected to a terminal device, the configuration information acquisition unit 801 acquires the LTM configuration for LTM to other base station devices and configuration information (MasterKeyUpdate or SK-Counter) for generating or updating security keys in communication with other base station devices. The configuration information acquisition unit 801 may also acquire the LTM configuration and configuration information for generating or updating security keys by sending a request message (e.g., HANDOVER REQUEST) to a base station device that is a candidate for handover from its own device. Furthermore, if the configuration information acquisition unit 801 connects to a terminal device that has been handed over from another base station device, for example, it acquires the LTM configuration and configuration information for generating or updating security keys for the base station device that is a candidate for handover from its own device. Here, the configuration information related to the LTM configuration and security keys may be acquired from the candidate base station device in response to a request from the handover source base station device to transfer the configuration information related to the LTM configuration and security keys to the candidate base station device. Furthermore, the LTM configuration may be received from the base station device that is the handover source, and configuration information related to the security key may be received from the base station device that is a candidate for the handover destination. The configuration information provision unit 802 provides the LTM configuration and configuration information related to the security key to the other base station device. That is, the information provided by the configuration information provision unit 802 of the first base station device is acquired by the configuration information acquisition unit 801 of the second base station device.

[0043] The configuration information notification unit 803 notifies the connected terminal device of the acquired configuration information. For example, for base station devices where the LTM configuration is not held by the terminal device, the configuration information notification unit 803 notifies both the LTM configuration and the configuration information related to the security key. On the other hand, for base station devices where the LTM configuration is held by the terminal device, the configuration information notification unit 803 may notify only the configuration information related to the security key without notifying the LTM configuration. For example, during a handover, the configuration information notification unit 803 may receive an RRC Reconfiguration Complete message from the terminal device during the handover process, and after the connection is established, it may send the configuration information related to the security key (and the LTM configuration) via an RRC Reconfiguration message. The configuration information notification unit 803 may also include the configuration information (NCC) related to the security key of the handover destination base station device in the Cell Switch Command. In this case, the configuration information notification unit 803 retains the configuration information previously acquired by the configuration information acquisition unit 801 until the handover occurs, and can notify the terminal device of that configuration information when the handover takes place.

[0044] The key generation unit 804, for example, stores configuration information (such as MasterKeyUpdate) for generating a security key for communication with a terminal device, and generates a security key using that information when the terminal device is connected via handover. The key generation unit 804 also updates its configuration information in response to requests from other base station devices (for example, the first or second base station device when the terminal device is handed over from a first base station device to a second base station device) or AMF, and stores the updated configuration information. The updated configuration information can be provided to other base station devices by the configuration information provision unit 802 and notified from other base station devices to the terminal device. The communication unit 805 establishes a connection with the terminal device and communicates using the security key generated by the key generation unit 804.

[0045] As described above, in this embodiment, security keys can be efficiently shared and updated between terminal devices and the network (base station equipment) performing handover using LTM. Therefore, it is possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation."

[0046] The invention is not limited to the embodiments described above, and various modifications and changes are possible within the scope of the gist of the invention.

Claims

1. A terminal device that complies with the cellular communication standards of the Third Generation Partnership Project (3GPP), A receiving means for receiving, from a connected first base station device, first configuration information for Layer 1 / Layer 2 Triggered Mobility (LTM) for each of a plurality of candidate base station devices for handover, including the second and third base station devices, and second configuration information associated with the first configuration information for updating security keys, Each of the above-mentioned multiple base station devices is provided with a holding means for associating and holding the first setting information and the second setting information, An execution means for performing a handover to the second base station device, An update means that updates the security key using the second configuration information associated with the first configuration information of the second base station device in response to a handover to the second base station device, and updates the second configuration information associated with the first configuration information while maintaining the first configuration information for the third base station device that is held after the handover is performed, A terminal device characterized by having the following features.

2. The receiving means, after the handover to the second base station device, receives the updated second configuration information for the third base station device from the second base station device. The update means updates the second setting information by replacing the second setting information held for the third base station device with the received second setting information. The terminal device according to feature 1.

3. The receiving means receives identification information that enables it to identify the second configuration information for a fourth base station device which is at least a part of the plurality of third base station devices, and updated second configuration information for the fourth base station device. The update means replaces the second setting information identified by the identification information with the received second setting information. The terminal device according to feature 2.

4. The terminal device according to claim 3, characterized in that the first configuration information is LTM configuration and the identification information is LTM configuration id.

5. A predetermined order is assigned to the multiple third base station devices. The receiving means receives information in which the updated second configuration information is arranged in the predetermined order for all of the multiple third base station devices. The update means identifies, in a predetermined order, which of the plurality of third base station devices each of the plurality of second configuration information received corresponds to, and replaces the second configuration information held for each of the plurality of third base station devices with the received second configuration information according to the result of this identification. The terminal device according to claim 2, characterized by the following:

6. The terminal device according to claim 2, characterized in that the receiving means receives the updated second configuration information from the second base station device via an RRC Reconfiguration message after the RRC Reconfiguration Complete message has been transmitted during the handover by the execution means.

7. The second setting information is MasterKeyUpdate, The aforementioned MasterKeyUpdate is, The keySetChangeIndicator, nextHopChainingCount (NCC), and Non-Access Stratum (NAS) container are set to True, or Including keySetChangeIndicator and NCC set to False, The terminal device according to feature 1.

8. The terminal device according to claim 1, characterized in that the second setting information includes SK-Counter.

9. When the execution means receives a Cell Switch Command instructing a handover to the second base station device, it executes the handover. The update means updates the security key using the second configuration information contained in the Cell Switch Command, provided that the Cell Switch Command contains the second configuration information relating to the second base station device and that there is second configuration information held for the second base station device. The terminal device according to feature 1.

10. The receiving means further receives the first configuration information for each of a plurality of fifth base station devices that provide candidate cells for secondary cells when the cell provided by the connected base station device is the master cell, and a list of the second configuration information common to the plurality of fifth base station devices. The update means, if the secondary cell is changed while the master cell remains unchanged, removes the second configuration information used before the secondary cell was changed from the list and updates the security key for communication of the changed secondary cell using one of the second configuration information included in the list. The terminal device according to feature 1.

11. The receiving means further receives a list of the first configuration information for each of the plurality of fifth base stations and a list of the second configuration information common to the plurality of fifth base stations, in the case where a cell provided by each of the plurality of base station devices becomes a master cell. The second list of configuration information for the second base station device is defined separately from the second list of configuration information for the third base station device. The terminal device according to feature 10.

12. The terminal device according to claim 11, characterized in that the holding means holds a list of the second setting information for the case when a cell provided by the connected base station device and each of the plurality of base station devices becomes a master cell.

13. The terminal device according to claim 12, characterized in that the holding means deletes the list of second setting information based on instructions from the connected base station device.

14. The terminal device according to claim 12, characterized in that when the terminal device performs a handover to the second base station device, the holding means deletes the list of second setting information for cases where a cell provided by a base station device that is no longer a candidate for the handover destination after the handover becomes the master cell.

15. A base station device that conforms to the cellular communication standards of the Third Generation Partnership Project (3GPP), A means for providing to a first base station device to which a terminal device is connected, first configuration information of Layer 1 / Layer 2 Triggered Mobility (LTM) as a candidate for handover destination, and second configuration information associated with the first configuration information for updating security keys, Upon handover of the aforementioned terminal device, the connection means for connecting to the terminal device, A generation means for generating a security key to be used in communication with the terminal device using the second configuration information, After the handover is performed, acquisition means for acquiring the first and second configuration information for a second other base station device that is a candidate for the handover destination of the terminal device from the base station device, If the terminal device holds the first configuration information for the second other base station device, a transmission means sends a message to the terminal device that does not include the first configuration information but includes the second configuration information for the second other base station device. A base station device characterized by having the following features.

16. The base station device according to claim 15, characterized in that the transmitting means, after receiving an RRC Reconfiguration Complete message from the terminal device during the handover, transmits an RRC Reconfiguration message containing the second configuration information for the second other base station device to the terminal device.

17. The base station device according to claim 15, characterized in that the transmitting means transmits the second configuration information for the second base station device to the Cell Switch Command when instructing the terminal device to hand over to the second other base station device.

18. The providing means further provides the updated second configuration information to the third base station device when the terminal device is handed over from the first base station device to the third base station device. The base station device according to claim 15, characterized in that the generation means generates the security key using the updated second configuration information provided to the third other base station device when the terminal device is handed over from the third other base station device to the base station device.

19. The base station device according to claim 15, characterized in that the acquisition means acquires the first configuration information and the second configuration information for the second other base station device transmitted by the second other base station device in response to a request from the base station device from which the handover originated.

20. The base station device according to claim 15, characterized in that the acquisition means receives a message containing the first configuration information for the second other base station device from the handover source base station device, and based on that message, sends a message to the second other base station device requesting the second configuration information, thereby acquiring the first configuration information and the second configuration information for the second other base station device.

21. A control method performed by a terminal device compliant with the cellular communication standards of the Third Generation Partnership Project (3GPP), Receiving from the connected first base station device the first configuration information for Layer 1 / Layer 2 Triggered Mobility (LTM) for each of the multiple candidate base station devices for handover, including the second and third base station devices, and second configuration information associated with the said first configuration information for updating the security key, For each of the aforementioned multiple base station devices, the first setting information and the second setting information are associated and stored. Performing a handover to the second base station device, In response to the handover to the second base station device, the security key is updated using the second configuration information associated with the first configuration information of the second base station device, and after the handover is performed, the second configuration information associated with the first configuration information is updated while maintaining the first configuration information for the third base station device that is being held. A control method characterized by including

22. A control method performed by base station equipment compliant with the cellular communication standards of the Third Generation Partnership Project (3GPP), To provide the terminal device with a first base station device to which it is connected, the first configuration information of Layer 1 / Layer 2 Triggered Mobility (LTM) as a candidate for handover destination, and second configuration information associated with the first configuration information for updating security keys, The handover of the aforementioned terminal device connects to the said terminal device, The security key used in communication with the terminal device is generated using the second configuration information, After the handover is performed, the first and second configuration information for a second base station device that is a candidate for the handover destination of the terminal device from the base station device is obtained. If the terminal device holds the first configuration information for the second other base station device, a message is sent to the terminal device that does not include the first configuration information but includes the second configuration information for the second other base station device. A control method characterized by including

Citation Information

Patent Citations

  • Security aspects for layer 1 or layer 2 triggered mobility

    US20250274818A1