Introduction of enhanced level of security (e.g. 256-bit) to a network and / or various network entities

By allowing UEs to indicate their 256-bit security capabilities during mobility procedures, the system ensures that wireless communication systems maintain high security levels, addressing the challenge of reduced security during UE mobility.

WO2025120623A1PCT designated stage Publication Date: 2025-06-12LENOVO (SINGAPORE) PTE LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/051337
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-09
Filing Date
2025-02-07
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing wireless communication systems face challenges in maintaining security during user equipment (UE) mobility, particularly when a UE supports 256-bit security capabilities but connects to network entities that only support 128-bit security, leading to reduced security levels.

Method used

The system enables UEs to indicate their 256-bit security capabilities to the network during mobility procedures, such as Xn handovers or N2 handovers, allowing base stations and network functions to select target entities that match or exceed the UE's security capabilities, ensuring uniform 256-bit security is applied.

Benefits of technology

This approach mitigates the risk of reduced security levels during UE mobility by ensuring that the selected target base stations or network functions support the same or higher security capabilities as the UE, thereby maintaining a consistent and secure communication environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025051337_12062025_PF_FP_ABST
    Figure IB2025051337_12062025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to UE mobility. For example, a UE may indicate its security capabilities (e.g., 256-bit security capabilities) to a network (e.g., a RAN or AMF) during a registration procedure and / or a subsequent mobility procedure, such as during an Xn handover or N2 handover. The network can utilize the security capabilities to ensure suitable levels of security when moving the UE between RANs during a handover procedure.
Need to check novelty before this filing date? Find Prior Art

Description

INTRODUCTION OF ENHANCED LEVEL OF SECURITY (E.G. 256-BIT) TO A NETWORK AND / OR VARIOUS NETWORK ENTITIESCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 551,866, filed on February 9, 2024, which is hereby incorporated by reference in its entirety.TECHNICAL FIELD

[0002] The present disclosure relates to wireless communications, and more specifically to selecting a radio access network (RAN) during user equipment (UE) mobility scenarios.BACKGROUND

[0003] A wireless communications system may include one or multiple network communication devices, such as base stations, which may support wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).

[0004] Wireless communications systems apply a security context for communications between UEs and base stations or other network communications devices. For example, to activate security for a UE, a Non Access Stratum (NAS) security context may be established between the UE and an Application Mobility and Management Function (AMF)of a network. The security context, which can include authentication, integrity protection, and ciphering applied to communications, may be created during a primary authentication and / or key agreement procedure between the UE and the AMF (or other network function).SUMMARY

[0005] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.

[0006] The present disclosure relates to methods, apparatuses, and systems that enable a UE to indicate its security capabilities (e.g., 256-bit security capabilities) to a network during a mobility procedure, such as an Xn handover or N2 handover.

[0007] Some implementations of the method and apparatuses described herein may further include a base station for wireless communication, comprising at least one memory; and at least one processor coupled with the at least one memory and configured to cause the base station to initiate a handover procedure for a UE served by the base station, select a target base station having a security capability similar to a security capability of the base station and a security capability of the UE and complete the handover procedure for the UE with the selected target base station.

[0008] In some implementations of the method and apparatuses described herein, the at least one processor is further configured to cause the base station to transmit securitycapability information for the base station to the target base station over an Xn interface and receive security capability information from the target base station over the Xn interface.

[0009] In some implementations of the method and apparatuses described herein, the security capability information includes a list of ciphering algorithms supported by the base station or the target base station.

[0010] In some implementations of the method and apparatuses described herein, the security capability information includes a list of integrity protection algorithms supported by the base station or the target base station.

[0011] In some implementations of the method and apparatuses described herein, the security capability information includes 256-bit Access Stratum (AS) key capabilities of the base station or the target base station.

[0012] In some implementations of the method and apparatuses described herein, the base station and the target base station are an NR Node B (gNB) or a Next Generation Evolved Node-B (ng-eNB).

[0013] Some implementations of the method and apparatuses described herein may further include a network function for wireless communication, comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the network function to initiate a handover procedure for a UE served by a source base station associated with the network function, determine security capability information of a target network function, and when the security capability information indicates a same level of security at the target network function and the network function, complete the handover procedure for the UE with a target base station associated with the target network function.

[0014] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network function to determine the security capability information of the target network function by performing an exchange of security capability information with the target network function, comprising transmitting security capability information for the network function to the target network function over an N14interface, and receiving the security capability information from the target network function over the N14 interface.

[0015] In some implementations of the method and apparatuses described herein, the security capability information includes a list of ciphering algorithms supported by the network function or the target network function.

[0016] In some implementations of the method and apparatuses described herein, the security capability information includes a list of integrity protection algorithms supported by the network function or the target network function.

[0017] In some implementations of the method and apparatuses described herein, the security capability information includes 256-bit NAS key capabilities of the network function or the target network function.

[0018] In some implementations of the method and apparatuses described herein, the network function and the target network function is an Access and Mobility Management Function (AMF).

[0019] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network function to determine the security capability information of the target network function by transmitting a discovery request to a Network Repository Function (NRF) that contains security capabilities for network function, including the target network function.

[0020] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network function to determine the security capability information of the target network function by performing configuration transfer signaling with the target network function.

[0021] Some implementations of the method and apparatuses described herein may further include a network function for wireless communication, comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the base station to initiate a handover procedure for a UE served by a source base station associated with the network function, perform a configuration transfer between thesource base station and the network function, wherein the configuration transfer includes an exchange of security capability information between the source base station and the network function, perform a configuration transfer between the network function and target base station, and select the target base station based on the performed configuration transfer.

[0022] In some implementations of the method and apparatuses described herein, the exchanged security capability information includes one or more of: a list of ciphering algorithms supported by the source base station, the network function, and the target base station.

[0023] In some implementations of the method and apparatuses described herein, the exchanged security capability information includes one or more of: a list of integrity protection algorithms supported by the source base station, the network function, and the target base station.

[0024] In some implementations of the method and apparatuses described herein, the exchanged security capability information includes one or more of: 256-bit Access Stratum (AS) key capabilities of the source base station, 256-bit NAS key capabilities of the network function, and 256-bit AS key capabilities of the target base station.

[0025] In some implementations of the method and apparatuses described herein, the network function is an AMF.

[0026] In some implementations of the method and apparatuses described herein, the at least one processor is configured to cause the network function to perform the configuration transfer between the source base station and the network function over an N2 interface.

[0027] Some implementations of the method and apparatuses described herein may further include a network function for wireless communication, comprising at least one memory and at least one processor coupled with the at least one memory and configured to cause the base station to initiate a handover procedure for a UE served by a source base station associated with the network function, receive security capability information for the source base station via configuration transfer signaling between the source base station and the network function, transmit the security capability information for the source basestation to target base station via configuration transfer signaling between the network function and the target base station, receive security capability information for the target base station via configuration transfer signaling between the target base station and the network function, and transmit the security capability information for the target base station to the source base station via configuration transfer signaling between the network function and the source base station.

[0028] In some implementations of the method and apparatuses described herein, the exchanged security capability information includes a list of ciphering algorithms supported by the source base station or the target base station.

[0029] In some implementations of the method and apparatuses described herein, the security capability information includes a list of integrity protection algorithms supported by the source base station or the target base station.

[0030] In some implementations of the method and apparatuses described herein, the security capability information includes 256-bit AS key capabilities of the source base station or the target base station.

[0031] In some implementations of the method and apparatuses described herein, the network function is an AMF.BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0033] Figure 2A illustrates a messaging flow of an Xn handover procedure in accordance with aspects of the present disclosure.

[0034] Figure 2B illustrates a messaging flow of a base station security capabilities transfer / exchange procedure over an Xn interface in accordance with aspects of the present disclosure.

[0035] Figure 3 A illustrates a messaging flow of an N2 handover procedure with an AMF change in accordance with aspects of the present disclosure.

[0036] Figure 3B illustrates a messaging flow for selecting a peer AMF in accordance with aspects of the present disclosure.

[0037] Figure 3C illustrates a messaging flow for a Configuration Transfer Procedure in accordance with aspects of the present disclosure.

[0038] Figure 4 illustrates a messaging flow of an N2 handover procedure without an AMF change in accordance with aspects of the present disclosure.

[0039] Figure 5 illustrates a messaging flow for a configuration transfer in accordance with aspects of the present disclosure.

[0040] Figure 6 illustrates a messaging flow for a Configuration Transfer Procedure via an AMF in accordance with aspects of the present disclosure.

[0041] Figure 7 illustrates an example of a UE in accordance with aspects of the present disclosure.

[0042] Figure 8 illustrates an example of a processor in accordance with aspects of the present disclosure.

[0043] Figure 9 illustrates an example of a network equipment (NE) in accordance with aspects of the present disclosure.

[0044] Figure 10 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure.

[0045] Figure 11 illustrates a flowchart of a method performed by a NE in accordance with aspects of the present disclosure.

[0046] Figure 12 illustrates a flowchart of another method performed by a NE in accordance with aspects of the present disclosure.

[0047] Figure 13 illustrates a flowchart of another method performed by a NE in accordance with aspects of the present disclosure.DETAILED DESCRIPTION

[0048] Legacy cryptographic algorithms for ciphering and integrity protection (e.g., of AS and NAS layer connections) in 5G systems utilize 128-bit algorithms (e.g., AES-128). The security of these algorithms, such as AES- 128, can be compromised by quantum computing and other powerful computing systems. To counter such threats to symmetric cryptography (e.g., from bad actors using quantum computers), the 5G systems may update their algorithms by doubling the key-size of an algorithm, and thus doubling the number of bits used in classical security mechanisms.

[0049] Recently, 265-bit algorithms and other security mechanisms have been introduced to wireless communications systems, such as to core networks and radio access networks (RANs). The introduction of 265-bit capabilities enables 256-bit capable UEs to connect to base stations (e.g., gNBs) that support the 256-bit algorithms and / or Access and Mobility Management Functions (AMFs) that support the 256-bit algorithms. However, such support for 256-bit capabilities is not ubiquitous across networks or UEs.

[0050] Thus, there may be scenarios where a UE supports 256-bit security, but a network entity or function does not support 256-bit security (e.g., a gNB or AMF only supports 128-bit security). Similarly, there may be scenarios where one or more network nodes support 256-bit security, but the UE, or another network node, does not support 256- bit security (e.g., the UE only supports 128-bit security).

[0051] Further, during UE mobility (e.g., Xn handover, N2 handover, and so on), the UE may connect with different gNBs / RAN nodes or different AMFs, where each RAN node or AMF utilizes an independent selection process or algorithm during the handover. When the selection processes are not based on or aware of the security capabilities (e.g., 256-bit security capabilities) of the UE, various problems may arise. For example:

[0052] When the UE supports 256-bit algorithms and a source gNB supports 256-bit security handovers to a target gNB that only supports 128-bit algorithms, the AS connection for the UE may have a reduced level of security;

[0053] When the UE supports both 256-bit algorithms and 128-bit algorithms and a source gNB supports 256-bit security handovers the UE to a target gNB that supports both128-bit algorithms and 256-bit algorithms, the target gNB may select and use 128-bit algorithms, and the AS connection for the UE may have a reduced level of security;

[0054] Currently, 256-bit radio resource control (RRC) keys (KRRCint and KRRCenc), and user plane (UP) keys (KuPint and KuPenc) are truncated by the gNB / ng-eNB and used with 128-bit algorithms for ciphering and integrity protection. Thus, during mobility of the UE, when any RAN node similarly truncates and uses 128-bit keys for ciphering and integrity protection (e.g., even using a 256-bit algorithm), the AS connection for the UE may have a reduced level of security due to a lack of entropy;

[0055] Also, 256-bit Non Access Stratum (NAS) keys (KNASint and KNAS enc) are truncated by the AMF and used with 128-bit algorithms for ciphering and integrity protection. Thus, during mobility of the UE, when an AMF similarly truncates and uses 128-bit keys for ciphering and integrity protection (e.g., even using a 256-bit algorithm), the NAS connection for the UE may have a reduced level of security due to a lack of entropy; and so on.

[0056] The technology described herein provides solutions to such problems, by enabling a UE to indicate its security capabilities (e.g., 256-bit security capabilities) to a network during a mobility procedure, such as an Xn handover or N2 handover. For example, the UE may send an indication to the network in a NAS message or N1 transport.

[0057] The security capabilities (256-bit capabilities) for the UE may include support of a 256-bit key size (e.g., a 256-bit permanent key, a 256-bit key derivation function, such as HMAC-SHA-256) and indicate the supported security capabilities via a “256-bit key size supported” indication. Further, the security capabilities (256-bit capabilities) for the UE may include 256-bit cryptographic algorithms for ciphering and integrity protection (e.g., a 256-bit SNOW 3G based algorithm, a 256-bit AES based algorithm, a 256-bit ZUC based algorithm, and so on) and indicate the supported security capabilities via a “256-bits cryptographic algorithms support” indication, along with algorithm identities / identifiers.

[0058] Thus, the systems and method described herein can mitigate or avoid reduced levels of security during mobility procedures arising from the introduction or roll out of anenhanced level of security (e.g., 256-bit) to a network and / or various network entities, among other benefits.

[0059] Aspects of the present disclosure are described in the context of a wireless communications system.

[0060] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G- Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.

[0061] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0062] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.

[0063] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.

[0064] A UE 104 may be able to support wireless communication directly with otherUEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0065] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other or indirectly (e.g., via the CN 106. In some implementations, one or more NE 102 may include subcomponents, suchas an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).

[0066] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.

[0067] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).

[0068] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single framestructure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0069] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0070] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0071] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l, / r=2, jU=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively.Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0072] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0073] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.

[0074] As described herein, the systems and method exchange levels / capabilities / strengths supported by UEs and networks during UE mobility procedures, to prevent or avoid reduced levels of security when the UE moves from a source base station to a target base station, among other benefits.

[0075] In some embodiments, a source (or serving) gNB (or other base station) determines to initiate a handover for the UE 104. The source gNB checks the security capabilities of the UE 104. When the security capabilities of the UE 104 include only 128- bit algorithms, the source gNB selects a target gNB that has a capability / configuration to support 128-bit algorithms. Also, when the security capabilities of the UE 104 include 128- bit algorithms and 256-bit algorithms, the source gNB selects a target gNB that has a capability / configuration to support 256-bit algorithms. Finally, when the security capabilities of the UE 104 include only 256-bit algorithms, the source gNB selects a target gNB that has a capability / configuration to support 256-bit algorithms.

[0076] The source gNB transmits or otherwise provides the target gNB with the security capabilities of the UE 104, such as the support of 256-bit encryption algorithms, 256-bit integrity algorithms, and a 256-bit key size indication and / or Use 256 bit AS key indication. The target gNB, using the information provided by the source gNB, applies uniform 256-bit ciphering and integrity protection algorithms using 256 bit AS keys (e.g., RRC keys (KRRCintand KRRCenc), UP Keys (KuPintand KuPenc)) for the AS security (e.g., RRC and User Plane security), and so on.

[0077] Figure 2A illustrates a messaging flow 200 of an Xn handover procedure in accordance with aspects of the present disclosure. In some cases, the messaging flow 200 represents how to implement uniform application of a 256-bit algorithm for AS security (e.g., RRC and UP ciphering and integrity protection) during an Xn handover scenario for the UE 104 (e.g., where the UE 104 moves from a source gNB to a target gNB).

[0078] Further, the messaging flow 200 depicts the UE 104 and a new target gNB uniformly using 256-bit AS security keys (e.g., RRC keys (KRRCint and KRRCenc) and UP Keys (KuPint and KuPenc)) while using 256-bit algorithms for the RRC and UP ciphering and integrity protection. The messaging flow 200 also depicts how a source gNB selects a targetgNB with sufficient security capabilities / configurations (e.g., to apply 256-bit algorithms and security) to serve the UE 104, when the UE 104 can support 256-bit cryptographic algorithms (or 256-bit security).

[0079] In some cases, before commencement of step 1, when the UE 104 can support 256-bit security, the UE 104 transmits or shares the corresponding UE 256-bit security capabilities to the network in a NAS message / Nl transport (e.g., Registration Request / Mobility Registration update / Periodic Registration update / any initial NAS message / PDU session establishment / modification request message, and so on), along with a UE identifier (subscription concealed identifier (SUCI), 5G globally unique temporary UE identity (5G-GUTI)).

[0080] As described herein, the UE 256-bit security capabilities may include (1) the UE 104 supporting a 256-bit key size (e.g., 256 bit permanent key, 256 bits key derivation function, such as HMAC-SHA-256), (2) the UE 104 supporting 256-bit cryptographic algorithms (e.g., 256-bit SNOW 3G based algorithm, 256-bit AES based algorithm, 256-bit ZUC based algorithm, and so on).

[0081] For example, a UE supported ciphering algorithms list can be part of an Encryption Algorithms information element (IE) in a UE Security Capabilities IE and include: NEA0 (Null ciphering algorithm), 128-NEA1 (128-bit SNOW 3G based algorithm), 128-NEA2 (128-bit AES based algorithm), 128-NEA3 (128-bit ZUC based algorithm), 256-NEA1 / 4 (256-bit SNOW 3G based algorithm), 256-NEA2 / 5 (256-bit AES based algorithm), 256-NEA3 / 6 (256-bit ZUC based algorithm), and so on.

[0082] As another example, a UE supported integrity protection algorithms list can be part of an Integrity Algorithms IE in a UE Security Capabilities IE and include: NIA0 (Null integrity protection algorithm), 128-NIA1 (128-bit SNOW 3G based algorithm), 128-NIA2 (128-bit AES based algorithm), 128-NIA3 (128-bit ZUC based algorithm), 256-NIA1 / 4 (256-bit SNOW 3G based algorithm), 256-NIA2 / 5 (256-bit AES based algorithm), 256- NIA3 / 6 (256-bit ZUC based algorithm), and so on.

[0083] Further, in some cases, the UE 104 and the network (e.g., via the NE 102) may perform primary authentication, NAS and AS security establishment (e.g., via a securitymode command procedure) to connect the UE to the network. Due to the mobility of the UE 104, or due to other reasons, the serving gNB may initiate a handover for the UE (e.g., towards a target gNB), as described herein.

[0084] In step 1, during handover from a source RAN, or gNB / ng-eNB 210 over Xn to a target RAN, or gNB / ng-eNB 220, the source gNB / ng-eNB 210 includes the 5G security capabilities of the UE 104 with the 256-bit security capabilities of the UE 104. For example, the source gNB 210 may include a “Use 256 bit AS key” indication and 256-bit ciphering and 256-bit integrity algorithms used in the source gNB 210 in a handover request message sent to the target gNB 220.

[0085] When the UE 104 supports 256-bit security capabilities, the source gNB / ng- eNB 210 may select a target gNB / ng-eNB having the 256-bit algorithm configurations / support to enable uniform security, to ensure a same level of protection (e.g., a same cryptographic key length) for AS, as described herein.

[0086] In step 2, target gNB / ng-eNB 220 determines to select and apply a 256-bit cryptographic algorithm (e.g., for AS security, such as RRC integrity and ciphering protection and UP integrity and ciphering protection) upon receipt of UE security capabilities to support 256 algorithms from the source gNB / ng-eNB 210 (e.g., in the handover request) and / or when an operator configuration policy includes 256-bit algorithms in a prioritized list.

[0087] When the target gNB / ng-eNB 220 determines to apply 256-bit cryptographic algorithm for AS (RRC and UP) security, based on a received, “Use 256-bit AS key” indication, the target gNB / ng-eNB 220, following the RRC integrity and encryption key derivation (KRRCint and KRRCenc) and UP integrity and encryption key derivation (KuPint and KuPenc), retains the 256-bit keys of KRRCintand KRRCenc and skips RRC key truncation. The target gNB / ng-eNB 220 may also retain the 256-bit keys of KuPint and KuPenc and skip the UP key truncation.

[0088] The target gNB / ng-eNB 220 may select the 256-bit algorithm with a highest priority from the received 5G security capabilities (e.g., supported 256-bit cryptographicalgorithm) of the UE 104 according to the prioritized locally configured list of 256-bit algorithms (e.g., applicable for both integrity and ciphering algorithms).

[0089] In some cases, the source gNB / ng-eNB 210 selects a suitable target gNB / ng- eNB 220 based on the security capabilities of the target gNB / ng-eNB 220 (e.g., when the target gNB / ng-eNB 220 supports 256-bit security / 256-bit key size handling / 256-bit ciphering and integrity algorithms). In these cases, the target gNB / ng-eNB 220 is selected to perform UE Xn handover to enable application of a same level of AS security (RRC and UP) for the UE 104. An example gNB / ng-eNB security capabilities exchange procedure is described herein.

[0090] In step 3, the target gNB / ng-eNB 220 sends to the source gNB / ng-eNB 210 the handover request acknowledge message, which includes a “handover command” with selected 256-bits RRC and UP encryption and integrity algorithms and may also contain the “Use 256-bit AS key” indication. The handover command may be a transparent container sent by the target gNB / ng-eNB 220 that is forwarded to the UE 104 by the source gNB / ng- eNB 210.

[0091] The target gNB / ng-eNB 220 may skip truncation for newly derived RRC keys (KRRCintand KRRCenc) and UP keys (KuPintand KuPenc) based on the received “Use 256 bit AS key” indication. The handover command message may be integrity protected with a 256-bit RRC integrity key based on the new RRC keys (KRRCint) and the selected 256-bit cryptographic algorithm for integrity protection (e.g., if the target gNB / ng-eNB 220 selects and uses the 256-bit integrity algorithm). The handover command message may be also ciphered with 256-bit RRC encryption key based on the new RRC keys (KRRCenc) and the selected 256-bit cryptographic algorithm for ciphering protection (e.g., if the target gNB / ng-eNB 220 selects and uses the 256-bit ciphering algorithm).

[0092] In step 4, the chosen algorithms (e.g., 256-bit RRC and UP encryption and integrity algorithms), such as when the target gNB / ng-eNB 220 selects different algorithms from the source gNB / ng-eNB 210, and the “Use 256-bit AS key” indication is indicated to the UE 104 in the handover command message. When the UE 104 does not receive a selection of integrity and ciphering algorithms, the UE 104 continues to use the samealgorithms as before the handover (see TS 38.331 for a gNB or TS 36.331 for an ng-eNB) and uses 256-bit keys for RRC and UP security with no truncation to 128-bits (e.g., based on the “Use 256-bit AS key” indication received in the handover command). When a Xn- handover takes place from a ng-eNB to a gNB or vice versa, then the selected 256-bit algorithms in the target node and the “Use 256-bit AS key” indication may be signaled in the handover command to the UE 104.

[0093] In step 5, the UE 104 determines to derive and retain 256-bit keys (for AS keys, such as RRC keys: KRRCint, KRRCenc and UP Keys: KuPintand KuPenc) and skips the RRC and UP key truncation based on the received selected RRC and UP algorithms (indicating 256- bit integrity and 256-bit ciphering algorithms) and / or based on the received “Use 256-bit AS key” indication in the handover command message.

[0094] The UE 104 determines to use 256-bit algorithms for ciphering and integrity protection based on the 256-bit integrity algorithm and the 256-bit ciphering algorithm indicated by the target gNB / ng-eNB 220 in the handover command message. For example, the UE 104 uses the integrity protection with the indicated (256-bit) RRC integrity algorithm and the RRC integrity key for further RRC connections with the target gNB / eNB 220 in step 6.

[0095] In step 6a, the UE 104 sends the RRC Reconfiguration complete and / or Handover complete message to the target gNB / ng-eNB 220. In step 6b, the target gNB / ng- eNB 220 may send a handover success message to the source gNB / ng-eNB 210.

[0096] In step 7, the target gNB / ng-eNB 220 sends a Path-Switch message with the 5G security capabilities of the UE 104, including 256-bit security capabilities, received from the source gNB / ng-eNB 210 to a source AMF 230.

[0097] In step 8, the AMF 230 verifies that the 5G security capabilities of the UE 104 such as 256-bit security capabilities, received from the target gNB / ng-eNB 220 are the same as the security capabilities of the UE 104 locally stored at the source AMF 230.

[0098] In step 9, when there is a mismatch, the source AMF 230 sends its locally stored 5G security capabilities (e.g., 256-bit security capabilities) of the UE 104 to the target gNB / ng-eNB 330 in the Path-Switch Acknowledge message. The source AMF 230supports logging capabilities for this event and may take additional measures, such as raising an alarm.

[0099] In step 10, when the target gNB / ng-eNB 220 receives 5G security capabilities (e.g., 256-bit security capabilities) of the UE 104 from the AMF 230 in the Path-Switch Acknowledge message, the target gNB / ng-eNB 220 updates the AS security context of the UE 104 with these 5G security capabilities containing the 256-bit security capabilities of the UE 104. The target gNB / ng-eNB 220 selects the 256-bit algorithm with a highest priority from these 5G security capabilities, containing the 256-bit security capabilities, according to the locally configured prioritized list of algorithms (applicable for both integrity and ciphering algorithms).

[0100] When the algorithms selected by the target gNB / ng-eNB 220 are different than the algorithms used at the source gNB / ng-eNB 210, then the target gNB / ng-eNB 220 may initiate an intra-cell handover procedure, which can include an RRC Connection Reconfiguration procedure indicating the selected 256-bit algorithms and a Next Hop Chaining Counter (NCC) parameter to the UE 104. Further, the target gNB / ng-eNB 220 can send the source gNB / ng-eNB 210 the UE context release message.

[0101] In some cases, by transferring the 256-bit ciphering and integrity algorithms used in a source RAN along with a “Use 256 bit AS key” indication to a target RAN, the handover request message allows for the target RAN to decipher and verify the integrity of the RRC Reestablishment Complete message on SRB1 in a potential RRC Connection Reestablishment procedure using the 256-bit integrity and ciphering algorithms and to use the 256-bit RRC keys. The target RAN may also use the information to determine whether to include a new selection of 256-bit security algorithms in the Handover Command message.

[0102] As described herein, in some embodiments, a source RAN (e.g., a gNB / ng-eNB) selects a suitable target RAN (e.g., a gNB / ng-eNB), which supports 256-bit security / 256-bit key size handling / 256-bit ciphering and integrity algorithms), to perform Xn handover for the UE 104. By selecting a suitable RAN, the source RAN enables application of a same level of security in RRC ciphering and integrity protection and UP ciphering and integrity protection, among other benefits.

[0103] Figure 2B illustrates a messaging flow 250 of a base station security capabilities transfer / exchange procedure over an Xn interface in accordance with aspects of the present disclosure. The messaging flow 250 depicts a configuration information exchange between RAN nodes, such as a source RAN 210a and a target RAN 210b. The source RAN 210a transmits over Xn to the target RAN 210b information identifying its security capabilities. Also, the target RAN 210b transmits over Xn to the source RAN 210a information its security capabilities. Example security capabilities include:

[0104] A supported ciphering algorithms list (e.g., NEA0 (Null ciphering algorithm), 128-NEA1 (128-bit SNOW 3G based algorithm), 128-NEA2 (128-bit AES based algorithm), 128-NEA3 (128-bit ZUC based algorithm), 256-NEA1 / 4 (256-bit SNOW 3G based algorithm), 256-NEA2 / 5 (256-bit AES based algorithm), 256-NEA3 / 6 (256-bit ZUC based algorithm), and so on);

[0105] A supported integrity protection algorithms list (e.g., NIA0 (Null integrity protection algorithm), 128-NIA1 (128-bit SNOW 3G based algorithm), 128-NIA2 (128-bit AES based algorithm), 128-NIA3 (128-bit ZUC based algorithm), 256-NIA1 / 4 (256-bit SNOW 3G based algorithm), 256-NIA2 / 5 (256-bit AES based algorithm), 256-NIA3 / 6 (256-bit ZUC based algorithm), and so on);

[0106] A usage 256-bit AS Key capability, which can indicate the gNB after derivation of AS (RRC and UP) integrity and ciphering keys will skip 128-bit truncation and use the derived 256-bit key for AS ciphering and integrity protection (e.g., RRC and UP), and so on.

[0107] In some embodiments, a source or serving gNB may determine to initiate an N2 handover (with an AMF change). The source gNB may generate a source to target transparent container (STC) with the security capabilities of the UE 104 (as described herein). The source gNB may send the STC to a source AMF, which forwards the STC to a target gNB via a target AMF.

[0108] Figure 3A illustrates a messaging flow 300 of an N2 handover procedure with an AMF change in accordance with aspects of the present disclosure. In some cases, the messaging flow 300 depicts how a 256-bit algorithm can be uniformly applied for NASsecurity (e.g., NAS ciphering and integrity protection) and AS security (e.g., RRC and UP ciphering and integrity protection) during an N2 handover scenario for the UE 104. The messaging flow 300 also depicts how the UE 104 and a target AMF 310 can uniformly use / apply 256-bit NAS security keys (KNASintand KNASenc) while using 256-bit algorithms for NAS ciphering and integrity protection.

[0109] Further, the messaging flow 300 may depict how the UE 104 and the target gNB 230 can uniformly use 256-bit AS security keys (e.g,, RRC keys (KRRCintand KRRCenc) or UP Keys (KuPintand KuPenc)) while using 256-bit algorithms for the RRC and UP ciphering and integrity protection; and / or how the source AMF 230 selects a target AMF 310 having sufficient or matching security capabilities / configurations (e.g., to apply 256-bit algorithms based ciphering and integrity protection) to serve the UE 104, which can support 256-bit cryptographic algorithms (or 256-bit security).

[0110] In step 1, at handover from the source gNB / ng-eNB 210 to the target gNB / ng- eNB 220 over N2 (e.g., including an AMF change), the source gNB / ng-eNB 210 includes the 5G security capabilities (e.g., UE 256-bit security capabilities, via a “Use 256 bit AS key” indication) of the UE 104 and 256-bit ciphering and 256-bit integrity algorithms used by the source gNB / ng-eNB 210 in the handover request message.

[0111] In some cases, the source gNB / ng-eNB 210 may send the 5G security capabilities of the UE 104, with 256-bit security capabilities, and 256-bit ciphering and 256-bit integrity algorithms used by the gNB / ng-eNB 210 inside or contained in a source to target transparent container (STC), where the STC is sent to the source AMF 230 in the handover request message. The STC can enable transparent forwarding to the target 220 gNB / ng-eNB via the source AMF 230 and the target AMF 310 in a transparent manner.The receiving target gNB / ng-eNB 220 can use the information received in the STC to select the necessary cryptographic algorithms and key size (e.g., 256-bit ciphering algorithms and 256-bit key size in this case) and perform the AS security establishment.

[0112] In step 2, the source AMF 230 sends to the target AMF 310 theNamf Communication CreateUEContext Request message, which includes 5G security capabilities of the UE 104 with the UE 256-bit security capabilities, Use 256 bit NAS keyindications. The request message may include an STC, such as “STC(Used AS algorithms- Indicating 256-bit Integrity algorithm, 256-bit Ciphering algorithm, Use 256 bit AS key indication)).”

[0113] In some cases, when the UE 104 supports 256-bit security capabilities, the source AMF 230 may select a target AMF having the 256-bit algorithm configurations / support to enable uniform security, such as to ensure the same level of protection (e.g., cryptographic key length) for the NAS (based on the AMF configuration exchanged over N14 interface as part of a configuration transfer, as described herein.

[0114] In some cases, the source AMF 230 selects a suitable target AMF based on the security capabilities of the target AMF (e.g., supporting 256-bit security / 256-bit key size handling / 256-bit ciphering and integrity algorithms. The target AMF (e.g., the target AMF 310) is selected to perform UE N2 handover to enable application of a same level of NAS security (e.g., NAS ciphering and integrity protection) for the UE 104.

[0115] In step 3, the target AMF 310 selects and applies a 256-bit cryptographic algorithm (for NAS security, such as integrity and ciphering protection) upon receipt of UE security capabilities that support 256-bit algorithm from the source AMF 230 and / or when the operator configuration policy includes 256-bit algorithms in a prioritized list.

[0116] When the target AMF 310 determines to apply a 256-bit cryptographic algorithm for NAS security, based on a “Use 256-bit NAS key” indication, the target AMF 310 follows the NAS integrity and encryption key derivation (KNASintand KNASenc) and retains the 256-bit keys of KNASintand KNASenc, skipping NAS key truncation. The target AMF 310 may select the 256-bit algorithm with a highest priority from the received 5G security capabilities (e.g., based on supported 256-bit cryptographic algorithm) of the UE 104 according to the prioritized locally configured list of 256-bit algorithms (applicable to both integrity and ciphering algorithms).

[0117] In step 4, when the change of the AMF at N2-Handover (or mobility registration update) results in a change of an algorithm to be used for establishing NAS security, the target AMF 310 indicates the 256-bit selected algorithm to the UE 104 as described hereinfor N2-Handover (e.g., using a NAS Container (NASC)). The target AMF 310 may select the NAS algorithm having highest priority according to the ordered lists.

[0118] In some cases, such as a mobility registration update (e.g., using NAS SMC), the target AMF 310 indicates the 256-bit selected algorithm to the UE 104 along with the “Use 256-bit NAS key” indication. The target AMF 310 may create a NASC containing the selected 256-bit NAS security algorithms (for integrity and ciphering protection, which indicate selected 256-bit integrity algorithms and / or256-bit ciphering algorithms), and a “Use 256-bit NAS key” indication, along with other information (e.g., related to AMF key derivation) and NAS MAC.

[0119] In some cases, the target AMF 310 sends the 5G security capabilities (e.g., 256- bit security capabilities) of the UE 104, the STC (e.g., used AS algorithms and / or an indication of 256-bit integrity algorithm, 256-bit Ciphering algorithm), a “Use 256 bit AS key” indication, a NASC (e.g., indicating a selected 256-bit integrity algorithm, 256-bit ciphering algorithm, “Use 256 bit NAS key” indication, and so on), along with other information (e.g., related to AMF key derivation) and NAS MAC, in a NGAP HANDOVER REQUEST message to the target ng-eNB / gNB 220. The use of the NASC may be similar to use of a NAS SMC message.

[0120] In step 5, upon receipt of the NGAP HANDOVER REQUEST message from the target AMF 310, the target ng-eNB / gNB 220 uses the information received in the STC, such as used AS algorithms (e.g., an indication of 256-bit integrity algorithm, 256-bit ciphering algorithm), “Use 256 bit AS key” indication). The target gNB / ng-eNB 220 determines to select and apply the 256-bit cryptographic algorithm (for AS security, such as RRC integrity and ciphering protection and UP integrity and ciphering protection) upon receipt of UE security capabilities to support of 256-bit algorithms from the source gNB / ng-eNB 210 (in the STC) via the target AMF 310 and if an operator configuration policy includes 256-bit algorithms in a prioritized list.

[0121] If the target gNB / ng-eNB 220 determines to apply 256-bit cryptographic algorithm for AS (RRC and UP) security, based on the “Use 256-bit AS key” indication and when the target gNB / ng-eNB 220 follows the RRC integrity and encryption keyderivation (KRRCint and KRRCenc) and UP integrity and encryption key derivation (KuPint and KuPenc), the target gNB / ng-eNB 220 retains the 256-bit keys of KRRCint and KRRCenc and skips RRC key truncation. Similarly retains the 256-bit keys of KuPint and KuPenc and skips the UP key truncation. The target gNB / ng-eNB 220 selects the 256-bit algorithm with a highest priority from the received 5G security capabilities (based on supported 256-bit cryptographic algorithm) of the UE 104 according to the prioritized locally configured list of 256-bit algorithms (applicable to both integrity and ciphering algorithms).

[0122] In some cases, the target ng-eNB / gNB 220 constructs a ‘Target to Source transparent Container’ (TSC), which contains the selected 256-bit integrity algorithm, 256- bit ciphering algorithm for AS, and “Use 256 bit AS key” indication. The TSC provided by the target gNB / ng-eNB 220 enables transparent forwarding to the source gNB / ng-eNB 210 via the target AMF 310 and source AMF 230 in a transparent manner. Thus, the receiving source gNB / ng-eNB 210 can provide the information received in the TSC to the UE 104 in a handover command message (see step 9) to enable the UE 104 to select suitable cryptographic algorithms and key sizes (e.g., 256-bit ciphering algorithms and 256-bit key size), similar to the target gNB / ng-eNB 220 for a successful AS security establishment.

[0123] In step 6, the target ng-eNB / gNB 20 can send to the target AMF 310 a Handover Request Acknowledge message, which includes the TSC (e.g., selected 256-bit integrity algorithm, 256-bit ciphering algorithm for AS, and “Use 256 bit AS key” indication), and the NASC (e.g., Indicate selected 256-bit integrity algorithm, 256-bit ciphering algorithm, “Use 256 bit NAS key indication”), along with other information (e.g., related to AMF key derivation) and NAS MAC that is received in step 4.

[0124] In step 7, the target AMF 310 sends to the source AMF 230,Namf Communication CreateUEContext Response message, which includes the TSC (Selected 256-bit Integrity algorithm, 256-bit Ciphering algorithm for AS, and Use 256-bit AS key indication), and the NASC (Indicate selected 256-bit Integrity algorithm, 256-bit Ciphering algorithm, Use 256-bit NAS key indication, along with other information (e.g., related to AMF key derivation) and NAS MAC).

[0125] In step 8, the source AMF 230 sends the received TSC (Selected 256-bit Integrity algorithm, 256-bit Ciphering algorithm for AS, and Use 256-bit AS key indication), and the NASC (Indicate selected 256-bit Integrity algorithm, 256-bit Ciphering algorithm, Use 256-bit NAS key indication, along with other information (e.g., related to AMF key derivation) and NAS MAC) to the source gNB / ng-eNB 210 in a handover command message.

[0126] In step 9, the source gNB / ng-eNB 210 sends the chosen algorithms (e.g., 256-bit RRC and UP encryption and integrity algorithms, when the target gNB / ng-eNB 220 selects different algorithms compared to the source gNB / ng-eNB 210, and a “Use 256-bit AS key” indication (received in TSC in step 8) is indicated to the UE 104 along with the received NASC in the Handover Command message. For example, the source gNB / ng-eNB 210 sends the UE Handover Command message with the selected 256-bit integrity algorithm, 256-bit ciphering algorithm for AS, “Use 256 bit AS key” indication, and the NASC (indicate selected 256-bit integrity algorithm, 256-bit ciphering algorithm, “Use 256 bit NAS key” indication).

[0127] In step 10, the UE 104 derives and retains 256-bit keys (for NAS keys, such as KNASint, KNASenc) and skips the NAS key truncation based on the received selected NAS algorithms (indicating 256-bit integrity and 256-bit ciphering algorithms) and / or based on the received “Use 256-bit NAS key” indication (as part of the NASC) in the handover command message. The UE 104 may determine to use 256-bit algorithms for ciphering and integrity protection based on the 256-bit integrity algorithm, 256-bit ciphering algorithm indicated by the target AMF 310 (as part of the NASC) in the handover command message.

[0128] In some cases, The UE 104 derives and retains 256-bit keys (for AS keys, such as RRC keys: KRRCint, KRRCenc, and UP Keys: KuPintand KuPenc) and skips the RRC and UP key truncation based on the received selected RRC and UP algorithms (indicating 256-bit integrity and 256-bit ciphering algorithms) and / or based on the received “Use 256-bit AS key” indication in the handover command message. The UE 104 may determine to use 256- bit algorithms for ciphering and integrity protection based on the 256-bit integrity algorithm, 256-bit ciphering algorithm indicated by the target gNB / ng-eNB 220 in the handover command message. For example, the UE 104 may utilize the integrity protectionwith the indicated (256-bit) RRC integrity algorithm and the RRC integrity key for further RRC connections with the target gNB / eNB 220 in step 11 (e.g., for the handover confirm message).

[0129] In some cases, when the UE 104 does not receive a selection of integrity and ciphering algorithms, the UE 104 continues to use the same algorithms as before the handover (see TS 38.331 for gNB or TS 36.331 for ng-eNB) and uses 256-bit keys for RRC and UP security with no truncation to 128-bits (based on the “Use 256-bit AS key” indication received in the handover command.

[0130] In step 11, the UE 104 sends a handover confirm message to the target gNB / ng- eNB 220 by applying the newly selected 256-bit integrity and ciphering algorithms with 256-bit RRC keys (KRRCint, KRRCenc).

[0131] In step 12, the target gNB / ng-eNB 220 may send a handover notify message to the target AMF 310.

[0132] In step 13a, the target AMF 310 may send a Namf_Communication_N2InfoNotify to the source AMF. In step 13b, the source AMF 230 may send a Namf_Communication_N2InfoNotify acknowledgement to the target AMF 310.

[0133] In step 14a, the source AMF 230 may send a UE context release command to the source gNB / ng-eNB 210. In step 14b, the source gNB / ng-eNB 210 may send a UE context release complete to the source AMF 230.

[0134] In some embodiments, a source AMF may select a suitable target AMF (e.g., if the target AMF supports 256-bit security / 256-bit key size handling / 256-bit ciphering and integrity algorithms). The source AMF performs an N2 handover for the UE 104 with the selected target AMF to enable an application of a same level of security in NAS ciphering and integrity protection.

[0135] For example, an AMF Security Algorithm(s) / Capabilities Configuration Transfer may be performed between a source AMF (e.g., the source AMF 230) and a target AMF (e.g., the target AMF 310, over an N14 interface. The source AMF 230 and the targetAMF 310 may, at any time, exchange their own security capabilities / configurations, as described herein, to ensure / apply a same level of security for the UE 104 during mobility / handover of a connection from the source AMF 230 to the target AMF 310.

[0136] In some embodiments, the network may employ AMF Security Algorithms / Capabilities management as part of network function (NF) profile information in a Network Repository Function (NR). Figure 3B illustrates a messaging flow 350 for selecting a peer AMF in accordance with aspects of the present disclosure.

[0137] The source AMF 230 selects a suitable target AMF (e.g., the target AMF 310) based on the security capabilities of the target AMF 310 (e.g., if it supports 256-bit security / 256-bit key size handling / 256-bit ciphering and integrity algorithms. The source AMF 230 selects the target AMF 310 to perform UE N2 handover to enable application of a same level of NAS security (e.g., NAS ciphering and integrity protection) for the UE 104. An NRF 360 maintains NF profile information for AMF instances, such as security capability information, as follows:

[0138] A supported ciphering algorithms list (e.g., NEA0 (Null ciphering algorithm), 128-NEA1 (128-bit SNOW 3G based algorithm), 128-NEA2 (128-bit AES based algorithm), 128-NEA3 (128-bit ZUC based algorithm), 256-NEA1 / 4 (256-bit SNOW 3G based algorithm), 256-NEA2 / 5 (256-bit AES based algorithm), 256-NEA3 / 6 (256-bit ZUC based algorithm), and so on);

[0139] A supported integrity protection algorithms list (e.g., NIA0 (Null integrity protection algorithm), 128-NIA1 (128-bit SNOW 3G based algorithm), 128-NIA2 (128-bit AES based algorithm), 128-NIA3 (128-bit ZUC based algorithm), 256-NIA1 / 4 (256-bit SNOW 3G based algorithm), 256-NIA2 / 5 (256-bit AES based algorithm), 256-NIA3 / 6 (256-bit ZUC based algorithm), and so on);

[0140] A usage 256-bit AS Key capability, which can indicate the gNB after derivation of AS (RRC and UP) integrity and ciphering keys will skip 128-bit truncation and use the derived 256-bit key for AS ciphering and integrity protection (e.g., RRC and UP), and so on.

[0141] In response to receiving a handover request from a source gNB, the source AMF 230 may select a suitable target AMF (with 256-bit security capabilities) to perform the N2 handover (with AMF change).

[0142] In step 1 of the messaging flow 350, the source AMF 230 sends to the NRF, 360 a Nnrf_NFDiscovery_Request message with Target NF service Name(s): ‘Namf_Communication_CreateUEContext, N2InfoNotify’, NF type of target NF ‘AMF’, NF type of the NF service Consumer: ‘AMF’, Support of 256-bit Security (Support of 256- bit integrity algorithms, Support of 256-bit ciphering algorithms, Support of 256-bit NAS Key(s) indication.

[0143] The NRF 360 manages the NF profile, where the AMF profile can include for each AMF / AMF instance the AMF security capabilities described herein. For example, the NRF 360 selects the AMFs / AMF instances having a capability to support one or more of: Support of 256-bit Security (Support of 256-bit integrity algorithms, Support of 256-bit ciphering algorithms, Support of 256-bit NAS Key(s) as indicated by the source AMF 230 in step 1.

[0144] In step 2, the NRF 260 sends to the source AMF 230 theNnrf NFDiscovery Response message with AMF Type, AMF Instance ID(s), FQDN or IP address(es) of the NF instance, Per AMF Instance / AMF list of ciphering, integrity and key size security capabilities.

[0145] The source AMF 230 may select a target AMF (e.g., an AMF instance) that has the most or suitable 256-bit algorithm support and 256-bit key size support based on the UE 256-bit security capabilities to perform the N2 handover for the UE 104.

[0146] In some embodiments, a Configuration Transfer between two RAN nodes provides a generic mechanism for the exchange of information between applications belonging to the RAN nodes. Such a mechanism may be enhanced to enable the RANs (e.g., the gNBs or ng-eNBs) to exchange / transfer 256-bit security capabilities between a source RAN and a target RAN (via associated AMFs).

[0147] Figure 3C illustrates a messaging flow 370 for a Configuration Transfer Procedure in accordance with aspects of the present disclosure. The source gNB 210, thesource AMF 230, the target AMF 310, and the target gNB 220 may exchange security capability information (as described herein) with one another utilizing Configuration Transfer signaling via N2 and / or N14 interfaces.

[0148] In some cases, the target AMF 310 selects a suitable target RAN (e.g., the target gNB 220 based on the exchanged security information and by enhancing an N2 Configuration Transfer to exchange the 256-bit security capabilities, as described herein.

[0149] In some embodiments, a source or serving gNB may determine to initiate an N2 handover (without an AMF change). The source gNB may generate a source to target transparent container (STC) with the security capabilities of the UE 104 (as described herein). The source gNB may send the STC to a source AMF, which forwards the STC to a target gNB.

[0150] Figure 4A illustrates a messaging flow 400 of an N2 handover procedure without an AMF change in accordance with aspects of the present disclosure. In some cases, the messaging flow 400 depicts how a 256-bit algorithm can be uniformly applied for AS security (e.g., RRC and UP ciphering and integrity protection) during an N2 handover scenario for the UE 104.

[0151] Further, the messaging flow 400 may depict how the UE 104 and the target gNB 230 can uniformly use 256-bit AS security keys (e.g,, RRC keys (KRRCintand KRRCenc) or UP Keys (KuPintand KuPenc)) while using 256-bit algorithms for the RRC and UP ciphering and integrity protection; and / or how the source AMF 230 selects a target gNB having sufficient or matching security capabilities / configurations (e.g., to apply 256-bit algorithms based ciphering and integrity protection) to serve the UE 104, which can support 256-bit cryptographic algorithms (or 256-bit security).

[0152] In step 1, during handover from the source gNB / ng-eNB 210 to the target gNB / ng-eNB 220 over N2 (via a same AMF 410), the source gNB / ng-eNB 210 includes the 5G security capabilities of the UE 104 (e.g., 256-bit security capabilities, “Use 256 bit AS key” indication), and 256-bit ciphering and 256-bit integrity algorithms used by the source gNB / ng-eNB 210 in the handover request message.

[0153] In some cases, the source gNB / ng-eNB 210 may send the 5G security capabilities (e.g., 256-bit security capabilities and / or “Use 256 bit AS key” indication, and 256-bit ciphering and 256-bit integrity algorithms used by the source gNB / ng-eNB 210 inside an STC, which is sent by the AMF 410 in the handover request message. The STC enables transparent forwarding to the target gNB / ng-eNB 220 via the AMF 410 in a transparent manner. The receiving target gNB / ng-eNB 220 may use the information received in the STC to select the suitable cryptographic algorithms and key size (e.g., 256- bit ciphering algorithms and 256-bit key size in this case) and perform an AS security establishment.

[0154] In step 2, the AMF 410 sends to the target gNB / ng-eNB 220 the Handover Request message, which includes the 5G security capabilities (e.g., 256-bit security capabilities of the UE 104, and STC (used AS algorithms, indicating 256-bit integrity algorithm, 256-bit ciphering algorithm, “Use 256 bit AS key” indication) received in step 1. When the UE 104 supports 256-bit security capabilities, the AMF 410 may select a target gNB / ng-eNB 220 having 256-bit algorithm configurations / support to enable uniform security, such as to ensure the same level of protection (e.g., cryptographic key length) for AS (based on the N2 configuration exchanged over N2 / NGAP interface as part of a configuration transfer described herein).

[0155] In step 3, upon receipt of an NGAP HANDOVER REQUEST message from the AMF 410, the target ng-eNB / gNB 220 uses the information received in the STC. The target gNB / ng-eNB 220 selects and applies a 256-bit cryptographic algorithm (for AS security, such as RRC integrity and ciphering protection and UP integrity and ciphering protection) upon receipt of UE security capabilities to support 256-bit algorithms from the source gNB / ng-eNB 210 (in the STC) via the AMF 410 and / or when the operator configuration policy includes 256-bit algorithms in a prioritized list.

[0156] If the target gNB / ng-eNB 220 determines to apply a 256-bit cryptographic algorithm for AS (RRC and UP) security, based on the “Use 256-bit AS key” indication and the target gNB / ng-eNB 220 follows the RRC integrity and encryption key derivation (KRRCint and KRRCenc) and UP integrity and encryption key derivation (KuPint and KuPenc), the target gNB / ng-eNB 220 retains the 256-bit keys of KRRCint and KRRCenc and skips an RRCkey truncation. Similarly, the target gNB / ng-eNB 220 retains the 256-bit keys of KuPintand KuPenc, and skips a UP key truncation.

[0157] The target gNB / ng-eNB 220 may select the 256-bit algorithm with highest priority from the received 5G security capabilities (based on supported 256-bit cryptographic algorithm) of the UE according to the prioritized locally configured list of 256-bit algorithms (this applies for both integrity and ciphering algorithms).

[0158] The target ng-eNB / gNB 220 may construct a TSC, which contains the selected 256-bit integrity algorithm, 256-bit ciphering algorithm for AS, and “Use 256 bit AS key” indication. In some cases, the TSC provided by the target gNB / ng-eNB 220 enables transparent forwarding to the source gNB / ng-eNB 210 via the AMF 410 in a transparent manner. Thus, the receiving source gNB / ng-eNB 210 can provide the information received in the TSC to the UE 104 in a handover command message (see step 6) to enable the UE 104 to select suitable or matching cryptographic algorithms and key sizes (e.g., 256-bit ciphering algorithms and 256-bit key size), similar to the target gNB 220 for a successful AS security establishment.

[0159] In step 4, the target ng-eNB / gNB 220 can send to the AMF 410 a Handover Request Acknowledge message, which includes the TSC (e.g., selected 256-bit integrity algorithm, 256-bit ciphering algorithm for AS, and “Use 256 bit AS key” indication).

[0160] In step 5, the AMF 410 sends the received TSC to the source gNB / ng-eNB 210 in a handover command message.

[0161] In step 6, the source gNB / ng-eNB 210 sends the chosen algorithms (e.g., 256-bit RRC and UP encryption and integrity algorithms, when the target gNB / ng-eNB 220 selects different algorithms compared to the source gNB / ng-eNB 210 and the “Use 256-bit AS key” indication (received in TSC in step 5) is indicated to the UE 104 along with the received NASC in the Handover Command message. For example, the source gNB / ng-eNB 210 sends the UE Handover Command message with selected 256-bit integrity algorithm, 256-bit ciphering algorithm for AS, and “Use 256 bit AS key” indication.

[0162] In step 7, the UE 104 derives and retains 256-bit keys (for AS keys, such as RRC keys: KRRCint, KRRCenc and UP Keys: KuPintand KuPenc) and skips the RRC and UP keytruncation based on the received selected RRC and UP algorithms (indicating 256-bit integrity and 256-bit ciphering algorithms) and / or based on the received “Use 256-bit AS key” indication in the handover command message. Further, the UE 104 determines to use 256-bit algorithms for ciphering and integrity protection based on the 256-bit integrity algorithm, 256-bit ciphering algorithm indicated by the target gNB / ng-eNB 220 in the handover command message. This may include using the integrity protection with the indicated (256-bit) RRC integrity algorithm and the RRC integrity key for further RRC connections with the target gNB / eNB 220 in step 8 (e.g., for the handover confirm message).

[0163] In some cases, when the UE 104 does not receive a selection of integrity and ciphering algorithms, the UE 104 may use the same algorithms as before the handover (see TS 38.331 for gNB or TS 36.331 for ng-eNB) and uses 256-bit keys for RRC and UP security with no truncation to 128-bits (based on the “Use 256-bit AS key” indication received in the handover command).

[0164] In step 8, the UE 104 sends a handover confirm message to the target gNB / ng- eNB 220 by applying the newly selected 256-bit integrity and ciphering algorithms with 256-bit RRC keys (KRRCint, KRRCenc).

[0165] In step 9, the target gNB / ng-eNB 220 may send a handover notify message to the AMF 410.

[0166] In step 10a, the AMF 410 may send a UE context release command to the source gNB / ng-eNB 210, and in step 10b, the source gNB / ng-eNB 210 may send a UE context release complete to the AMF 410.

[0167] In some embodiments, a source AMF may select a suitable target RAN (e.g., a gNB / ng-eNB) when the RAN supports 256-bit security / 256-bit key size handling / 256-bit ciphering and integrity algorithms, to perform N2 handover for the UE 104. In doing so, the source AMF may ensure an application of a same level of security in AS level RRC and User Pane (UP) ciphering and integrity protection.

[0168] Figure 5 illustrates a messaging flow 500 for a configuration transfer in accordance with aspects of the present disclosure. The AMF 410 may exchange securityinformation (e.g., 256-bit security capabilities) with a RAN 510, and vice versa. The information exchange may employ a Configuration Transfer Procedure via an N2 interface.

[0169] In some cases, such as at power up, restart and when modifications may be applied, the RAN 510 and the AMF 410 may utilize non-UE related N2 signaling to exchange configuration data, which can be leveraged to exchange supported 256-bit ciphering and integrity protection algorithms (capabilities) lists.

[0170] For example, the AMF 410 may transmit or otherwise supply the RAN 510 with various types of information, including:

[0171] the AMF Name and the GUAMI(s) configured on that AMF Name;

[0172] the set of TNL associations to be established between the RAN 510 and the AMF 410;

[0173] a weight factor associated with each of the TNL association within the AMF 410;

[0174] a weight factor for each AMF Name within the AMF Set;

[0175] (optionally) for each GUAMI(s) configured on the AMF 410 the corresponding backup AMF Name;

[0176] a supported ciphering algorithms list (e.g., NEA0 (Null ciphering algorithm), 128-NEA1 (128-bit SNOW 3G based algorithm), 128-NEA2 (128-bit AES based algorithm), 128-NEA3 (128-bit ZUC based algorithm), 256-NEA1 / 4 (256-bit SNOW 3G based algorithm), 256-NEA2 / 5 (256-bit AES based algorithm), 256-NEA3 / 6 (256-bit ZUC based algorithm), and so on;

[0177] a supported integrity protection algorithms list (e.g., NIA0 (Null integrity protection algorithm), 128-NIA1 (128-bit SNOW 3G based algorithm), 128-NIA2 (128-bit AES based algorithm), 128-NIA3 (128-bit ZUC based algorithm), 256-NIA1 / 4 (256-bit SNOW 3G based algorithm), 256-NIA2 / 5 (256-bit AES based algorithm), 256-NIA3 / 6 (256-bit ZUC based algorithm), and so on;

[0178] usage 256-bit NAS Key capability, which indicates the AMF 410 after derivation of NAS integrity and ciphering keys will skip the 128-bit truncation and use the derived 256-bit key as such for the NAS ciphering and integrity protection, and so on.

[0179] The RAN 510 transmits or supplies the AMF 410 over the N2 interface with information about tracking areas) it serves and the S-NSSAIs it supports in each of these tracking areas. Additionally, the RAN 510 may also provide the following information:

[0180] Supported ciphering algorithms list (e.g., NEA0 (Null ciphering algorithm), 128-NEA1 (128-bit SNOW 3G based algorithm), 128-NEA2 (128-bit AES based algorithm), 128-NEA3 (128-bit ZUC based algorithm), 256-NEA1 / 4 (256-bit SNOW 3G based algorithm), 256-NEA2 / 5 (256-bit AES based algorithm), 256-NEA3 / 6 (256-bit ZUC based algorithm), and so on;

[0181] Supported integrity protection algorithms list (e.g., NIA0 (Null integrity protection algorithm), 128-NIA1 (128-bit SNOW 3G based algorithm), 128-NIA2 (128-bit AES based algorithm), 128-NIA3 (128-bit ZUC based algorithm), 256-NIA1 / 4 (256-bit SNOW 3G based algorithm), 256-NIA2 / 5 (256-bit AES based algorithm), 256-NIA3 / 6 (256-bit ZUC based algorithm), and so on;

[0182] Usage 256-bit AS Key capability, whichbindicates the gNB / ng-eNB after derivation of AS (e.g., RRC and UP) integrity and ciphering keys will skip the 128-bit truncation and use the derived 256-bit key as such for the AS (e.g., RRC and UP) ciphering and integrity protection; and so on.

[0183] As described herein, a Configuration Transfer between two RAN nodes provides a generic mechanism for the exchange of information between applications belonging to the RAN nodes. Such a mechanism may be enhanced to enable the RANs (e.g., the gNBs or ng-eNBs) to exchange / transfer 256-bit security capabilities between a source RAN and a target RAN (via associated AMFs).

[0184] Figure 6 illustrates a messaging flow 600 for a Configuration Transfer Procedure via an AMF in accordance with aspects of the present disclosure. The source gNB 210 and the target gNB 220 may exchange security capability information (asdescribed herein) via the AMF 410, with one another utilizing Configuration Transfer signaling via N2 interfaces to exchange their 256-bit security capabilities.

[0185] Figure 7 illustrates an example of a UE 700 in accordance with aspects of the present disclosure. The UE 700 may include a processor 702, a memory 704, a controller 706, and a transceiver 708. The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0186] The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0187] The processor 702 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 702 may be configured to operate the memory 704. In some other implementations, the memory 704 may be integrated into the processor 702. The processor 702 may be configured to execute computer-readable instructions stored in the memory 704 to cause the UE 700 to perform various functions of the present disclosure.

[0188] The memory 704 may include volatile or non-volatile memory. The memory 704 may store computer-readable, computer-executable code including instructions when executed by the processor 702 cause the UE 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 704 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitorystorage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0189] In some implementations, the processor 702 and the memory 704 coupled with the processor 702 may be configured to cause the UE 700 to perform one or more of the functions described herein (e.g., executing, by the processor 702, instructions stored in the memory 704). For example, the processor 702 may support wireless communication at the UE 700 in accordance with examples as disclosed herein.

[0190] The controller 706 may manage input and output signals for the UE 700. The controller 706 may also manage peripherals not integrated into the UE 700. In some implementations, the controller 706 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 706 may be implemented as part of the processor 702.

[0191] In some implementations, the UE 700 may include at least one transceiver 708. In some other implementations, the UE 700 may have more than one transceiver 708. The transceiver 708 may represent a wireless transceiver. The transceiver 708 may include one or more receiver chains 710, one or more transmitter chains 712, or a combination thereof.

[0192] A receiver chain 710 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 710 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 710 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 710 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 710 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.

[0193] A transmitter chain 712 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 712 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one ormore techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 712 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 712 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0194] Figure 8 illustrates an example of a processor 800 in accordance with aspects of the present disclosure. The processor 800 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 800 may include a controller 802 configured to perform various operations in accordance with examples as described herein. The processor 800 may optionally include at least one memory 804, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 800 may optionally include one or more arithmetic-logic units (ALUs) 806. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).

[0195] The processor 800 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 800) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).

[0196] The controller 802 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 800 to cause the processor 800 to support various operations in accordance with examplesas described herein. For example, the controller 802 may operate as a control unit of the processor 800, generating control signals that manage the operation of various components of the processor 800. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0197] The controller 802 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 804 and determine subsequent instruction(s) to be executed to cause the processor 800 to support various operations in accordance with examples as described herein. The controller 802 may be configured to track memory address of instructions associated with the memory 804. The controller 802 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 802 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 800 to cause the processor 800 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 802 may be configured to manage flow of data within the processor 800. The controller 802 may be configured to control transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 800.

[0198] The memory 804 may include one or more caches (e.g., memory local to or included in the processor 800 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 804 may reside within or on a processor chipset (e.g., local to the processor 800). In some other implementations, the memory 804 may reside external to the processor chipset (e.g., remote to the processor 800).

[0199] The memory 804 may store computer-readable, computer-executable code including instructions that, when executed by the processor 800, cause the processor 800 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 802 and / or the processor 800 may be configured to execute computer-readable instructions stored in the memory 804 to cause the processor 800 to perform various functions. For example, the processor 800 and / or the controller 802 may be coupled with orto the memory 804, the processor 800, the controller 802, and the memory 804 may be configured to perform various functions described herein. In some examples, the processor 800 may include multiple processors and the memory 804 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0200] The one or more ALUs 806 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 806 may reside within or on a processor chipset (e.g., the processor 800). In some other implementations, the one or more ALUs 806 may reside external to the processor chipset (e.g., the processor 800). One or more ALUs 806 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 806 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 806 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 806 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not- AND (NAND), enabling the one or more ALUs 806 to handle conditional operations, comparisons, and bitwise operations.

[0201] The processor 800 may support wireless communication in accordance with examples as disclosed herein.

[0202] Figure 9 illustrates an example of a NE 900 in accordance with aspects of the present disclosure. The NE 900 may include a processor 902, a memory 904, a controller 906, and a transceiver 908. The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0203] The processor 902, the memory 904, the controller 906, or the transceiver 908, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0204] The processor 902 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 902 may be configured to operate the memory 904. In some other implementations, the memory 904 may be integrated into the processor 902. The processor 902 may be configured to execute computer-readable instructions stored in the memory 904 to cause the NE 900 to perform various functions of the present disclosure.

[0205] The memory 904 may include volatile or non-volatile memory. The memory 904 may store computer-readable, computer-executable code including instructions when executed by the processor 902 cause the NE 900 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 904 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0206] In some implementations, the processor 902 and the memory 904 coupled with the processor 902 may be configured to cause the NE 900 to perform one or more of the functions described herein (e.g., executing, by the processor 902, instructions stored in the memory 904). For example, the processor 902 may support wireless communication at the NE 900 in accordance with examples as disclosed herein. The NE 900 may be configured to support a means for initiating a handover procedure for a UE served by the base station, selecting a target base station having a security capability similar to a security capability of the base station and a security capability of the UE, and completing the handover procedure for the UE with the selected target base station.

[0207] As another example, the NE 900 may be configured to support a means for initiating a handover procedure for a UE served by a source base station associated with the network function, determining security capability information of a target network function, and when the security capability information indicates a same level of security at the target network function and the network function, complete the handover procedure for the UE with a target base station associated with the target network function.

[0208] As another example, the NE 900 may be configured to support a means for initiating a handover procedure for a UE served by a source base station associated with the network function, performing a configuration transfer between the source base station and the network function, wherein the configuration transfer includes an exchange of security capability information between the source base station and the network function, performing a configuration transfer between the network function and target base station, and selecting the target base station based on the performed configuration transfer.

[0209] As another example, the NE 900 may be configured to support a means for initiating a handover procedure for a UE served by a source base station associated with the network function, receiving security capability information for the source base station via configuration transfer signaling between the source base station and the network function, transmitting the security capability information for the source base station to target base station via configuration transfer signaling between the network function and the target base station, receiving security capability information for the target base station via configuration transfer signaling between the target base station and the network function, and transmitting the security capability information for the target base station to the source base station via configuration transfer signaling between the network function and the source base station.

[0210] The controller 906 may manage input and output signals for the NE 900. The controller 906 may also manage peripherals not integrated into the NE 900. In some implementations, the controller 906 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 906 may be implemented as part of the processor 902.

[0211] In some implementations, the NE 900 may include at least one transceiver 908. In some other implementations, the NE 900 may have more than one transceiver 908. The transceiver 908 may represent a wireless transceiver. The transceiver 908 may include one or more receiver chains 910, one or more transmitter chains 912, or a combination thereof.

[0212] A receiver chain 910 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 910 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 910 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 910 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 910 may include at least one decoder for decoding the processing the demodulated signal to receive the transmitted data.

[0213] A transmitter chain 912 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 912 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 912 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 912 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0214] Figure 10 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0215] At 1002, the method may include for initiating a handover procedure for a UE served by the base station. The operations of 1002 may be performed in accordance withexamples as described herein. In some implementations, aspects of the operations of 1002 may be performed by a NE as described with reference to Figure 9.

[0216] At 1004, the method may include selecting a target base station having a security capability similar to a security capability of the base station and a security capability of the UE. The operations of 1004 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1004 may be performed by a NE as described with reference to Figure 9.

[0217] At 1006, the method may include completing the handover procedure for the UE with the selected target base station. The operations of 1006 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1006 may be performed by a NE as described with reference to Figure 9.

[0218] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0219] Figure 11 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0220] At 1102, the method may include initiating a handover procedure for a UE served by a source base station associated with the network function. The operations of 1102 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1102 may be performed by a NE as described with reference to Figure 9.

[0221] At 1104, the method may include determining security capability information of a target network function. The operations of 1104 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1104 may be performed by a NE as described with reference to Figure 9.

[0222] At 1106, the method may include and when the security capability information indicates a same level of security at the target network function and the network function, complete the handover procedure for the UE with a target base station associated with the target network function. The operations of 1106 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1106 may be performed by a NE as described with reference to Figure 9.

[0223] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0224] Figure 12 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0225] At 1202, the method may include initiating a handover procedure for a UE served by a source base station associated with the network function. The operations of 1202 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1202 may be performed by a NE as described with reference to Figure 9.

[0226] At 1204, the method may include performing a configuration transfer between the source base station and the network function, wherein the configuration transfer includes an exchange of security capability information between the source base station and the network function. The operations of 1204 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1204 may be performed by a NE as described with reference to Figure 9.

[0227] At 1206, the method may include performing a configuration transfer between the network function and target base station. The operations of 1206 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1206 may be performed by a NE as described with reference to Figure 9.

[0228] At 1208, the method may include selecting the target base station based on the performed configuration transfer. The operations of 1208 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1208 may be performed by a NE as described with reference to Figure 9.

[0229] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0230] Figure 13 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.

[0231] At 1302, the method may include initiating a handover procedure for a UE served by a source base station associated with the network function. The operations of 1302 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1302 may be performed by a NE as described with reference to Figure 9.

[0232] At 1304, the method may include receiving security capability information for the source base station via configuration transfer signaling between the source base station and the network function. The operations of 1304 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1304 may be performed by a NE as described with reference to Figure 9.

[0233] At 1306, the method may include transmitting the security capability information for the source base station to target base station via configuration transfer signaling between the network function and the target base station. The operations of 1306 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1306 may be performed by a NE as described with reference to Figure 9.

[0234] At 1308, the method may include receiving security capability information for the target base station via configuration transfer signaling between the target base stationand the network function. The operations of 1308 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1308 may be performed by a NE as described with reference to Figure 9.

[0235] At 1310, the method may include transmitting the security capability information for the target base station to the source base station via configuration transfer signaling between the network function and the source base station. The operations of 1310 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1310 may be performed by a NE as described with reference to Figure 9.

[0236] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.

[0237] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

CLAIMSWhat is claimed is:

1. A base station for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the base station to: initiate a handover procedure for a user equipment (UE) served by the base station; select a target base station having a security capability similar to a security capability of the base station and a security capability of the UE; and complete the handover procedure for the UE with the selected target base station.

2. The base station of claim 1, wherein the at least one processor is further configured to cause the base station to: transmit security capability information for the base station to the target base station over an Xn interface; and receive security capability information from the target base station over the Xn interface.

3. The base station of claim 2, wherein the security capability information includes a list of ciphering algorithms supported by the base station or the target base station.

4. The base station of claim 2, wherein the security capability information includes a list of integrity protection algorithms supported by the base station or the target base station.

5. The base station of claim 2, wherein the security capability information includes 256-bit Access Stratum (AS) key capabilities of the base station or the target base station.

6. A network function for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network function to: initiate a handover procedure for a user equipment (UE) served by a source base station associated with the network function; determine security capability information of a target network function; and when the security capability information indicates a same level of security at the target network function and the network function, complete the handover procedure for the UE with a target base station associated with the target network function.

7. The network function of claim 6, wherein the at least one processor is configured to cause the network function to determine the security capability information of the target network function by performing an exchange of security capability information with the target network function, comprising: transmitting security capability information for the network function to the target network function over an N14 interface; and receiving the security capability information from the target network function over the N14 interface.

8. The network function of claim 6, wherein the security capability information includes a list of ciphering algorithms supported by the network function or the target network function.

9. The network function of claim 6, wherein the security capability information includes a list of integrity protection algorithms supported by the network function or the target network function.

10. The network function of claim 6, wherein the security capability information includes 256-bit Non Access Stratum (NAS) key capabilities of the network function or the target network function.

11. The network function of claim 6, wherein the network function and the target network function is an Access and Mobility Management Function (AMF).

12. The network function of claim 6, wherein the at least one processor is configured to cause the network function to determine the security capability information of the target network function by transmitting a discovery request to a Network Repository Function (NRF) that contains security capabilities for network function, including the target network function.

13. The network function of claim 6, wherein the at least one processor is configured to cause the network function to determine the security capability information of the target network function by performing configuration transfer signaling with the target network function.

14. A network function for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the base station to: initiate a handover procedure for a user equipment (UE) served by a source base station associated with the network function; perform a configuration transfer between the source base station and the network function, wherein the configuration transfer includes an exchange of security capability information between the source base station and the network function; perform a configuration transfer between the network function and target base station; andselect the target base station based on the performed configuration transfer.

15. The network function of claim 14, wherein the exchanged security capability information includes one or more of: a list of ciphering algorithms supported by the source base station, the network function, and the target base station.

16. The network function of claim 14, wherein the exchanged security capability information includes one or more of: a list of integrity protection algorithms supported by the source base station, the network function, and the target base station.

17. The network function of claim 14, wherein the exchanged security capability information includes one or more of: 256-bit Access Stratum (AS) key capabilities of the source base station, 256-bit Non Access Stratum (NAS) key capabilities of the network function, and 256-bit Access Stratum (AS) key capabilities of the target base station.

18. A network function for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the base station to: initiate a handover procedure for a user equipment (UE) served by a source base station associated with the network function; receive security capability information for the source base station via configuration transfer signaling between the source base station and the network function; transmit the security capability information for the source base station to target base station via configuration transfer signaling between the network function and the target base station; receive security capability information for the target base station via configuration transfer signaling between the target base station and the network function; andtransmit the security capability information for the target base station to the source base station via configuration transfer signaling between the network function and the source base station.

19. The network function of claim 18, wherein the exchanged security capability information includes a list of ciphering algorithms supported by the source base station or the target base station.

20. The network function of claim 18, wherein the security capability information includes a list of integrity protection algorithms supported by the source base station or the target base station.

Citation Information

Patent Citations

  • Pre-authentication method for mobile communication system switching

    CN101552985B

  • Key update methods and related entities

    CN109819439B

  • System and method for selection of security algorithms

    EP2213115B1

  • Communication method, apparatus, and system

    US20200205045A1