Terminal device, base station device, and wireless communication system
The proposed configuration for terminal and base station devices addresses the lack of standardized specifications for radio bearer processing during cell changes by executing LTM cell switches and requesting RRC connection re-establishment based on security key updates, thereby enhancing mobility handling in wireless communication systems.
Patent Information
- Application Number
- PCT/JP2023/043843
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-07
- Publication Date
- 2025-06-12
AI Technical Summary
Current wireless communication systems lack standardized specifications for efficient radio bearer establishment and release processing during cell change operations, particularly in LTM (L1/L2-triggered mobility) scenarios.
A terminal device and base station device configuration that includes a receiving unit for RRC reconfiguration messages and a processing unit to execute handovers. The processing unit performs an LTM cell switch according to specific settings when security key updates occur during handovers, and requests re-establishment of an RRC connection when security key updates do not occur.
Enables efficient radio bearer establishment and release processing during cell changes, improving mobility handling in wireless communication systems.
Smart Images

Figure JP2023043843_12062025_PF_FP_ABST
Abstract
Description
Terminal device, base station device, and wireless communication system
[0001] The present invention relates to a terminal device, a base station device, and a wireless communication system.
[0002] Currently, wireless communication networks using mobile devices (smartphones, feature phones, etc.) are expanding. With the expansion of wireless communication, there is a demand for even faster speeds and larger capacities.
[0003] The 3rd Generation Partnership Project (3GPP (registered trademark)), an international standardization project, is conducting technical studies and formulating standards for cellular mobile communication systems. For example, E-UTRA (Evolved Terrestrial Radio Access) has been standardized as the radio access technology (RAT) for 3.9th generation (3.9G) and 4th generation (4G), and EPC (Evolved Packet Core) has been standardized as the core network (CN) technology. NR (New Radio) has also been standardized as the RAT for 5th generation (5G), and 5G Core (5GC) has been standardized as the core network technology. Furthermore, these extension technologies are currently being continuously studied and standardized.
[0004] Technologies related to NR or 5G systems are described, for example, in the following Non-Patent Documents 1 to 9.
[0005] 3GPP TS38.300 V17.6.0 NR Overview Specification; 3GPP TS38.211 V17.6.0 NR PHY Channel and Modulation Specification; 3GPP TS38.321 V17.6.0 NR MAC Specification; 3GPP TS38.322 V17.3.0 NR RLC Specification; 3GPP TS38.323 V17.5.0 NR PDCP Specification; 3GPP TS37.324 V17.0.0 NR SDAP Specification; 3GPP TS38.304 V17.6.0 NR Idle Mode and Inactive Mode Specification; 3GPP TS38.331 V17.6.0 NR RRC Specification; 3GPP TS33.501 V17.11.1 5G System Security Specification; 3GPP RP-223520 "Revised WID on Further NR mobility enhancements"
[0006] As one of the extension technologies, technical studies on improving mobility are being conducted. One of the items under study is a technology called LTM (L1 / L2-triggered mobility), which aims to reduce delay time in mobility by changing the serving cell of a terminal device using layer 1 and / or layer 2 signaling (Non-Patent Document 10).
[0007] However, the specific method of LTM has not yet been determined as a standard specification, for example, the specific procedures for establishing and releasing radio bearers when performing cell change processing have not yet been determined.
[0008] Therefore, one object of the present disclosure is to provide a base station device, a terminal device, and a wireless communication system that enable efficient radio bearer establishment and release processing when performing cell change processing.
[0009] One disclosure relates to a terminal device including: a receiving unit that receives an RRC (Radio Resource Control) reconfiguration message including a reconfiguration with synchronization from a base station device; and a processing unit that executes a handover in accordance with the RRC reconfiguration message, wherein the processing unit controls to execute a first process when a handover failure is detected, and the first process is a process that controls to execute an LTM cell switch in accordance with a first setting including one or more cell change destination candidates in the case where a security key update has been performed at the time of the handover, and controls to request the base station device to re-establish an RRC connection in the case where the security key update has not been performed at the time of the handover.
[0010] Also, one disclosure is a base station device having a transmitting unit that transmits an RRC reconfiguration message including a synchronized reconfiguration to a terminal device, and a processing unit that causes the terminal device to perform a handover by transmitting the RRC reconfiguration message to the terminal device, wherein the processing unit controls the terminal device to perform a first process when the terminal device detects a failure of the handover, and the first process is a process that controls the terminal device to perform an LTM cell switch in accordance with a first setting including one or more cell change destination candidates if a security key update has been performed at the time of the handover, and controls the terminal device to request re-establishment of an RRC connection if a security key update has not been performed at the time of the handover.
[0011] Also, one disclosure provides a wireless communication system including a base station device that transmits an RRC (Radio Resource Control) reconfiguration message including a reconfiguration with synchronization, and a terminal device that receives the RRC reconfiguration message and executes a handover in accordance with the RRC reconfiguration message, wherein the terminal device controls to execute a first process when it detects a handover failure, and the first process is a process of controlling to execute an LTM cell switch in accordance with the first setting including one or more cell change destination candidates if a security key update has been performed at the time of the handover, and controlling to request the base station device to re-establish an RRC connection if the security key update has not been performed at the time of the handover.
[0012] One disclosure enables communication that enables efficient radio bearer establishment and release processing when a terminal device performs cell change processing.
[0013] FIG. 1 is a diagram showing an example of the configuration of a communication system 10. FIG. 2 is a diagram showing an example of the configuration of a base station device 200. FIG. 3 is a diagram showing an example of the configuration of a terminal device 100. FIG. 4 is a diagram showing an example of a protocol stack in the U-Plane. FIG. 5 is a diagram showing an example of a protocol stack in the C-Plane. FIG. 6 is a diagram showing an example of an RRCReconfiguration message format. FIG. 7 is a diagram showing an example of the configuration of a cell group in the communication system 10. FIG. 8 is a diagram showing an example of synchronized reconfiguration. FIG. 9 is a diagram showing an example of a handover procedure using four-step random access. FIG. 10 is a diagram showing an example of an LTM sequence. FIG. 11 is a diagram showing an example of a sequence of cell switching failure detection and cell switching failure processing. FIG. 12 is a diagram showing an example of a first cell switching failure processing method. FIG. 13 is a diagram showing an example of a second cell switching failure processing method. FIG. 14 is a diagram showing an example of a third cell switching failure processing method. FIG. 15 is a diagram showing an example of a fourth cell switching failure processing method. FIG. 16 is a diagram showing an example of processing according to a selected cell. FIG. 17 is a diagram showing an example of parameters related to LTM.
[0014] The present embodiment will be described in detail below with reference to the drawings. The problems and examples in this specification are merely examples and do not limit the scope of the rights of the present application. In particular, even if the expressions used are different, the technology of the present application can be applied as long as they are technically equivalent, and do not limit the scope of the rights.
[0015] In this embodiment, the names and processes of each device, node, function, protocol, entity, signaling, message, parameter, etc. when the radio access technology is E-UTRA or NR and when the core network is EPC or 5GC are described, but the embodiment may be used for other radio access technologies. The names of each node and entity in each embodiment may be different names.
[0016] <Configuration Example of Communication System 10> Fig. 1 is a diagram showing an example of the configuration of the communication system 10. The communication system 10 includes a terminal device 100, base station devices 200-1 and 200-2, and a core network 300. The communication system 10 may be a diagram of a wireless communication system in which the terminal device 100 communicates with the base station device 200-1 or the base station device 200-2, or may be a wireless communication system in which the terminal device 100 communicates with the base station device 200-1 and the base station device 200-2 using MR-DC (Multi Radio Dual Connectivity) described below. When communicating using MR-DC, for example, the base station device 200-1 is a master base station device, and the base station device 200-2 is a secondary base station device. Hereinafter, the master base station device may be referred to as an MN (Master Node), and the secondary base station device may be referred to as an SN (Secondary Node).
[0017] The terminal device 100 is wirelessly connected to one or both of the base station device 200-1 and the base station device 200-2 and performs wireless communication. The RAT providing the wireless connection is, for example, E-UTRA or NR. The terminal device 100 is a terminal device that supports either or both of E-UTRA and NR.
[0018] The base station devices 200-1 and 200-2 (hereinafter, sometimes referred to as base station devices 200) are communication devices that are wirelessly connected to the terminal device 100 and perform wireless communication. The base station devices 200-1 and 200-2 are, for example, connected to each other via a wire and perform communication. The base station device 200 is, for example, connected to the core network 300 via a wire and performs communication. The base station device 200 is, for example, a base station device that is either an eNodeB (eNB) that provides E-UTRA as the RAT or a gNodeB (gNB) that provides NR as the RAT.
[0019] The core network 300 is a network corresponding to a certain generation. For example, the core network 300 is a 5GC that is a core network standardized for 5G, or an EPC that is a core network standardized for 4G.
[0020] The MR-DC realized in the communication system 10 will be described in detail later.
[0021] 2 is a diagram showing an example of the configuration of the base station device 200. The base station device 200 is a communication device or a relay device having a CPU (Central Processing Unit) 210, a storage 220, a memory 230, a wireless communication circuit 240, and a network interface 250.
[0022] The storage 220 is an auxiliary storage device that stores programs and data, such as a flash memory, a hard disk drive (HDD), or a solid state drive (SSD). The storage 220 stores a wireless communication program 221 and a base station side program 222.
[0023] The memory 230 is an area into which the programs stored in the storage 220 are loaded. The memory 230 may also be used as an area in which the programs store data.
[0024] The wireless communication circuit 240 is a circuit that wirelessly connects to and communicates with the terminal device 100. The base station device 200 receives a signal transmitted from the terminal device 100 via the wireless communication circuit 240, and transmits a signal to the terminal device 100, for example.
[0025] The NI (Network Interface) 250 is, for example, a communication device that connects to other base station devices 200 and realizes inter-base station communication. The NI 250 is also, for example, a communication device that connects to the core network 300 (communication devices that constitute the core network 300) and performs communication. The NI 250 is, for example, a network interface card (NIC). The base station device 200 receives signals from other communication devices and transmits signals to other communication devices via the NI 250.
[0026] The CPU 210 is a processor that loads programs stored in the storage 220 into the memory 230, executes the loaded programs, configures each unit, and realizes each process.
[0027] The CPU 210 performs wireless communication processing by executing the wireless communication program 221. The wireless communication processing is processing for wirelessly connecting to the terminal device 100, communicating wirelessly with the terminal device 100, and relaying communication between the terminal device 100 and other communication devices.
[0028] The CPU 210 executes the base station side program 222 to configure a second transmitting unit, a second receiving unit, and a second processing unit, and perform base station side processing. When the base station device 200 communicates with the terminal device 100 using MR-DC, the base station side processing may include MR-DC master node processing and MR-DC secondary node processing. In this case, the MR-DC master node processing is processing for controlling the master node side of the MR-DC, and the MR-DC secondary node processing is processing for controlling the secondary node side of the MR-DC. In the MR-DC master node processing and the MR-DC secondary node processing, the base station device 200 performs communication corresponding to each type of MR-DC, which will be described later.
[0029] 3 is a diagram showing an example of the configuration of the terminal device 100. The terminal device 100 is a communication device having a CPU 110, a storage 120, a memory 130, and a wireless communication circuit 140.
[0030] The storage 120 is an auxiliary storage device such as a flash memory, HDD, or SSD that stores programs and data. The storage 120 stores a wireless communication program 121 and a terminal-side program 122.
[0031] The memory 130 is an area into which the programs stored in the storage 120 are loaded. The memory 130 may also be used as an area in which the programs store data.
[0032] The wireless communication circuit 140 is a circuit that wirelessly connects to and communicates with the base station device 200. The terminal device 100, for example, receives a signal transmitted from the base station device 200 via the wireless communication circuit 140 and transmits a signal to the base station device 200. The wireless communication circuit 140 is, for example, a network card that supports wireless connection.
[0033] The CPU 110 is a processor that loads programs stored in the storage 120 into the memory 130, executes the loaded programs, configures each unit, and realizes each process.
[0034] The CPU 110 performs terminal-side wireless communication processing by executing the wireless communication program 121. The terminal-side wireless communication processing is processing for wirelessly connecting to the base station device 200 and performing wireless communication with the base station device 200 or communication with another communication device via the base station device 200.
[0035] The CPU 110 executes the terminal-side program 122 to configure a transmitting unit, a receiving unit, and a processing unit, and to perform terminal-side processing. When the terminal device 100 communicates with the base station device 200 using MR-DC, the terminal-side processing may include terminal-side MR-DC processing. In this case, the terminal-side MR-DC processing is processing for controlling communication in the MR-DC. In the terminal-side MR-DC processing, the terminal device 100 performs communication corresponding to each type of MR-DC, which will be described later.
[0036] <Protocol Stack> An example of a protocol stack of the communication system 10 will be described. In the communication system 10, a series of protocols for transmitting and receiving data, shown in a hierarchical structure, is called a protocol stack. In the following example, the base station device 200 is an eNB or gNB, and the core network 300 is an EPC or 5GC. In addition, the terminal device 100 (UE: User Equipment) is assumed to support one or both of E-UTRA and NR.
[0037] The protocol stacks of the U-Plane (User Plane) and C-Plane (Control Plane) are explained below. The U-Plane is used, for example, to send and receive user data in communications. The C-Plane is used, for example, to send and receive control signals (messages) in communications. In each embodiment, unless otherwise specified, "user data" or "control signals (messages)" refers to either user data or control signals (messages), or both.
[0038] Figure 4 is a diagram showing an example of a protocol stack for the U-Plane when the core network 300 is 5GC. Also, Figure 5 is a diagram showing an example of a protocol stack for the C-Plane when the core network 300 is 5GC. In Figures 4 and 5, PHY (PHYsical), MAC (Medium Access Control), RLC (Radio Link Control), PDCP (Packet Data Convergence Protocol), SDAP (Service Data Adaptation Protocol), RRC (Radio Resource Control), and NAS (Non Access Stratum) respectively indicate the names of layers. Hereinafter, PHY, MAC, RLC, PDCP, SDAP, RRC, and NAS may be referred to as the PHY layer, MAC layer, RLC layer, PDCP layer, SDAP layer, RRC layer, and NAS layer, respectively. Furthermore, MAC, RLC, PDCP, and SDAP may be referred to as a MAC sublayer, an RLC sublayer, a PDCP sublayer, and an SDAP sublayer, respectively. Furthermore, MAC, RLC, PDCP, and SDAP may be referred to as a MAC entity, an RLC entity, a PDCP entity, and an SDAP entity, respectively. Note that when core network 300 is an EPC, the protocol stack of the U-Plane is a protocol stack in which SDAP does not exist in FIG. 4. That is, it is a protocol stack consisting of PHY, MAC, RLC, and PDCP. Furthermore, when core network 300 is an EPC, the protocol stack of the C-Plane is such that, in FIG. 5, NAS exists in an AMF (Access and Mobility management Function), whereas NAS exists in an MME (Mobility Management Entity).
[0039] The functions in each layer may be common or different between the E-UTRA and NR RATs. In the following description, if there is no specification of E-UTRA or NR, the functions are common to both E-UTRA and NR.
[0040] In each sublayer, data provided from and to an upper layer is called an SDU (Service Data Unit). That is, data provided from and to an upper layer to MAC, RLC, PDCP, and SDAP is called a MAC SDU, an RLC SDU, a PDCP SDU, and an SDAP SDU, respectively.
[0041] In each sublayer, data provided to and from the lower layer is called a PDU (Protocol Data Unit). That is, data provided from MAC, RLC, PDCP, and SDAP to the lower layer, and data provided from the lower layer to MAC, RLC, PDCP, and SDAP are called MAC PDU, RLC PDU, PDCP PDU, and SDAP PDU, respectively. RLC, PDCP, and SDAP also have control PDUs, which are sometimes called control PDUs. To distinguish them from control PDUs, other PDUs are sometimes called data PDUs.
[0042] In Figure 4, the U-Plane consists of PHY, MAC, RLC, PDCP, and SDAP, and terminates at the terminal device 100 (UE) and the base station device 200 (gNB).
[0043] An example of the function of the PHY will be described. The PHY is a wireless physical layer, and transmits control information and data between the terminal device 100 and the base station device 200 using a physical channel. The direction from the base station device 200 to the terminal device 100 is sometimes called the downlink (downlink, DL), and the direction from the terminal device 100 to the base station device 200 is sometimes called the uplink (uplink, UL). Furthermore, within the terminal device 100 and the base station device 200, the PHY is connected to the MAC, which is an upper layer, via a transport channel, and data moves between the PHY and the MAC via the transport channel. In the PHY, a Radio Network Temporary Identifier (RNTI) is used to identify various control information.
[0044] An example of MAC functions will be described. MAC is a medium access control layer, and performs mapping of transport channels and logical channels (LCHs), multiplexing and demultiplexing of MAC SDUs, scheduling reports (SRs), error correction through hybrid automatic repeat reQuest (HARQ), priority control, etc. In the terminal device 100 and the base station device 200, the MAC is connected to the RLC, which is an upper layer, via a logical channel, and data moves between the MAC and the RLC via the logical channel. The logical channel may be identified by a logical channel identifier (LCID). Furthermore, the base station device 200 controls the terminal device 100 using a MAC control element (CE). Furthermore, the terminal device 100 performs reports, etc. to the base station device 200 using a MAC CE.
[0045] RLC is the radio link control layer and has three modes: Transparent Mode (TM), Unacknowledged Mode (UM), and Acknowledged Mode (AM). On the transmitting side, RLC performs PDU transmission, sequence number assignment (in the case of UM and AM), SDU segmentation (in the case of UM and AM), and re-segmentation (in the case of AM). On the receiving side, RLC performs SDU reassembly (in the case of UM and AM), duplicate detection (in the case of AM), and SDU discarding (in the case of UM and AM). It also performs RLC re-establishment on the transmitting and receiving sides. Segmented SDUs are called SDU segments. RLC also has a data retransmission function and / or a retransmission request function (ARQ: Automatic Repeat reQuest) (in the case of AM). In addition, in the case of E-UTRA RLC, there are also other functions such as data combining on the transmitting side, and reordering and in-order delivery on the receiving side.
[0046] PDCP is a packet data convergence protocol layer, and performs data transfer between the U-Plane and C-Plane, PDCP sequence number management, header compression / decompression, encryption / decryption, integrity protection / integrity verification, timer-based SDU discard, routing for split bearers, reordering and in-order delivery, etc. In E-UTRA PDCP, functions such as timer-based SDU discard, reordering and in-order delivery may be limited to the case of, for example, a split bearer.
[0047] SDAP is a service data adaptation protocol layer that performs tasks such as mapping QoS (Quality of service) flows to Data Radio Bearers (DRBs), which will be described later, and marking downlink (DL) packets and uplink (UL) packets with QoS flow identifiers (QFIs).
[0048] The upper layers of the U-Plane include, for example, IP (Internet Protocol), TCP (Transmission Control Protocol), UDP (User Datagram Protocol), Ethernet (registered trademark), and application layers. A layer including IP, TCP, UDP, Ethernet, etc. may be called a PDU layer. Furthermore, IMS (IP Multimedia Subsystem), which controls sessions, may be included in the application layer.
[0049] 5, the C-Plane of the AS (Access Stratum) is composed of PHY, MAC, RLC, PDCP, and RRC, and terminates at the terminal device 100 and the base station device 200. The C-Plane of the NAS is composed of the NAS, and terminates between the terminal device 100 and the AMF, which is a device in the core network 300. The PHY, MAC, RLC, and PDCP are the same as those in the U-Plane.
[0050] The RRC performs functions such as broadcasting system information (SI) related to AS and NAS, paging, establishing / maintaining / releasing RRC connections between the terminal device 100 and the base station device 200, adding / changing / releasing carrier aggregation (CA), adding / changing / releasing dual connectivity (DC), security functions including security key management, establishing / setting / maintaining / releasing signaling radio bearers (SRBs) and data radio bearers (DRBs), mobility functions, QoS management functions, controlling terminal device measurement reports and reporting, detecting and recovering from radio link failures (RLFs), and forwarding NAS messages. Radio link failures include, for example, detection of a physical layer problem, random access failures, or the maximum number of retransmissions by RLC.
[0051] The NAS performs authentication, mobility management, security control, etc. on the core network side.
[0052] <Channels> The channels used in the communication system 10 will be described. Below, examples of channels corresponding to NR are shown, but the channels used are not limited to the following. In addition, channels with the same name can be used for the same or similar purposes in RATs other than NR, such as E-UTRA.
[0053] <1. Physical Channels> The PBCH (Physical Broadcast CHannel) is a channel used for transmitting broadcast information from the base station device 200 to the terminal device 100. The PDCCH (Physical Downlink Control CHannel) is a channel used for transmitting downlink control information (Downlink Control Information: DCI) and the like from the base station device 200 to the terminal device 100. The PDSCH (Physical Downlink Shared CHannel) is a channel used for transmitting data and the like from a higher layer from the base station device 200 to the terminal device 100. The PUCCH (Physical Uplink Control CHannel) is a channel used for transmitting uplink control information (Uplink Control Information: UCI) and the like from the terminal device 100 to the base station device 200. The PUSCH (Physical Uplink Shared CHannel) is a channel used for transmitting data and the like from a higher layer from the terminal device 100 to the base station device 200. The PRACH (Physical Random Access CHannel) is a channel used to transmit a random access preamble and the like from the terminal device 100 to the base station device 200 .
[0054] <2. Transport Channels> The BCH (Broadcast CHannel) is mapped to the PBCH, which is a physical channel. The DL-SCH (Downlink Shared CHannel) is mapped to the PDSCH, which is a physical channel. The PCH (Paging CHannel) is mapped to the PDSCH, which is a physical channel. The UL-SCH (Uplink Shared CHannel) is mapped to the PUSCH, which is a physical channel. The RACH (Random Access CHannel(s)) is mapped to the PRACH, which is a physical channel.
[0055] <3. Logical Channels> The BCCH (Broadcast Control CHannel) is a downlink channel for broadcasting system information, and is mapped to the transport channel BCH or DL-SCH. The PCCH (Paging Control CHannel) is a downlink channel for carrying paging messages, and is mapped to the transport channel PCH. The CCCH (Common Control CHannel) is a channel for transmitting control information (such as RRC messages) between the terminal device 100 and the base station device 200, and is a channel used for terminal devices 100 that do not maintain (do not have) an RRC connection with the base station device 200; the downlink is mapped to the transport channel DL-SCH, and the uplink is mapped to the transport channel UL-SCH. The Dedicated Control Channel (DCCH) is a point-to-point bidirectional channel used to transmit dedicated control information (such as RRC messages) between the terminal device 100 and the base station device 200. It is used for the terminal device 100 having an RRC connection with the base station device 200, with the downlink mapped to the DL-SCH transport channel and the uplink mapped to the UL-SCH transport channel. The Dedicated Transport Channel (DTCH) is a point-to-point bidirectional channel dedicated to the terminal device, used to transmit user information (user data). The downlink is mapped to the DL-SCH transport channel and the uplink is mapped to the UL-SCH transport channel. The MBS Control Channel (MCCH) is a point-to-multipoint downlink channel used to transmit MBS (Multicast Broadcast Service) broadcast control information corresponding to one or more MBS Traffic Channels (MTCHs) from the base station device 200 to the terminal device 100. It is mapped to the transport channel DL-SCH.The MTCH is a point-to-multipoint downlink channel used to transmit MBS multicast session data or broadcast session data from the base station device 200 to the terminal device 100. It is mapped to the transport channel DL-SCH.
[0056] <RRC State (Mode)> The RRC state of the terminal device 100 is a state related to the RRC connection of the terminal device 100. A state in which an RRC connection with the base station device 200 is not established is called an RRC idle mode (RRC_IDLE). A state in which an RRC connection with the base station device 200 is established is called an RRC connected mode (RRC_CONNECTED). A state in which the RRC connection with the base station device 200 is temporarily suspended is called an RRC inactive mode (RRC_INACTIVE). Note that when the core network 300 is an EPC, the state in which the RRC connection with the base station device 200 is temporarily suspended may be called another name, such as RRC suspended, instead of being called an RRC inactive mode.
[0057] <RRC Message> The RRC message will be explained. The RRC message is a message that includes information necessary for communication in a cell, and includes a MIB (Master Information Block), a system information group (SIB), etc. The parameters included in the RRC message may be called fields or information elements (IEs).
[0058] The RRC message also includes a message related to the establishment of an RRC connection. For example, in the case of NR, messages related to the establishment of an RRC connection include an RRC setup request message (RRCSetupRequest), an RRC setup message (RRCSetup), and an RRC setup complete message (RRCSetupComplete). For example, in the case of E-UTRA, messages related to the establishment of an RRC connection include an RRC connection setup request message (RRCConnectionSetupRequest), an RRC connection setup message (RRCConnectionSetup), and an RRC connection setup complete message (RRCConnectionSetupComplete).
[0059] The RRC message also includes a message related to the initial activation of AS (Access Stratum) security. Examples of messages related to the initial activation of AS security include a security mode command message (SecurityModeCommand).
[0060] Furthermore, the RRC message includes a message related to the reconfiguration of the RRC connection. For example, in the case of NR, messages related to the reconfiguration of the RRC connection include an RRC reconfiguration message (RRCReconfiguration) and an RRC reconfiguration complete message (RRCReconfigurationComplete). For example, in the case of E-UTRA, messages related to the reconfiguration of the RRC connection include an RRC connection reconfiguration message (RRCConnectionReconfiguration) and an RRC connection reconfiguration complete message (RRCConnectionReconfigurationComplete). Note that messages related to the reconfiguration of the RRC connection perform the establishment, configuration, modification, and release of radio bearers, cell groups, etc., as well as synchronized reconfiguration, as described below, and also the establishment, configuration, modification, and release of measurement information, etc.
[0061] After initial activation of AS security, the terminal device 100 receives the first RRC reconfiguration message from the base station device 200, thereby obtaining all settings or all minimum required settings necessary for communication (data communication) with the base station device 200 in the cell to which the terminal device 100 is connected. These all settings or all minimum required settings necessary for communication (data communication) with the base station device 200 may be referred to as, for example, complete settings.
[0062] After initial activation of AS security for the terminal device 100, the base station device 200 can transmit a first RRC reconfiguration message and then another RRC reconfiguration message to cause the terminal device 100 to update the settings required for communication (data communication) with the base station device 200. In this case, the base station device 200 transmits an RRC reconfiguration message containing a differential setting from the complete setting currently set in the terminal device 100. This differential setting is sometimes called a delta setting. When the terminal device 100 receives an RRC reconfiguration message including the delta setting, it generates a new setting by applying the delta setting to the complete setting currently being used.
[0063] The RRC message also includes a message related to the re-establishment of the RRC connection. For example, in the case of NR, messages related to the re-establishment of the RRC connection include an RRC re-establishment request message (RRCReestablishRequest), an RRC re-establishment message (RRCReestablish), and an RRC re-establishment complete message (RRCReestablishComplete). For example, in the case of E-UTRA, messages related to the establishment of the RRC connection include an RRC connection re-establishment request message (RRCConnectionReestablishRequest), an RRC connection re-establishment message (RRCConnectionReestablish), and an RRC connection re-establishment complete message (RRCConnectionReestablishComplete).
[0064] In addition, the RRC messages further include messages regarding the release or suspension of the RRC connection, messages regarding the resumption of the RRC connection, messages regarding the capabilities of the terminal device, messages regarding terminal information, messages regarding MCG failure information, and SCG failure information.
[0065] In MR-DC, when the master node is an eNB, the eNB may configure the terminal device 100 regarding NR by including the NR RRC message and parameters received from the gNB, which is the secondary node, as a container in the E-UTRA RRC message and transmitting it to the terminal device 100. The terminal device 100 may also include a completion message for the NR configuration as a container in the E-UTRA RRC message and transmit it to the eNB, which is the master node.
[0066] Also, in MR-DC, when the master node is a gNB, the gNB may configure the terminal device 100 for E-UTRA by including the E-UTRA RRC message and parameters received from the eNB, which is the secondary node, as a container in the NR RRC message and transmitting it to the terminal device 100. The terminal device 100 may also include a completion message for the E-UTRA configuration in the NR RRC message as a container and transmit it to the gNB, which is the master node.
[0067] 6 is a diagram showing an example of a message format of RRC Reconfiguration. Format E1 is a parameter of RRC Reconfiguration.
[0068] RRC Reconfiguration has radioBearerConfig, radioBearerConfig2, masterCellGroup, secondaryCellGroup, masterKeyUpdate, and sk-counter as parameters.
[0069] radioBearerConfig and radioBearerConfig2 are radio bearer settings related to an MN-terminated bearer or an SN-terminated bearer, and include SRB settings, DRB settings, security settings, etc. The SRB settings (DRB settings) include an SRB identifier (DRB identifier), PDCP settings, a parameter indicating PDCP re-establishment, etc. The security settings include a parameter (keyToUse) indicating whether to use a master key or a secondary key. The SRB identifier and / or DRB identifier are called radio bearer identifiers.
[0070] The masterCellGroup and secondaryCellGroup are MCG settings and SCG settings, respectively, and include a cell group identifier, an RLC bearer setting, an SpCell setting, etc. The RLC bearer setting includes a logical channel identifier, an RLC setting, a radio bearer identifier (SRB identifier or DRB identifier) associated with the RLC bearer, etc. The SpCell setting includes information necessary for synchronized reconfiguration, etc.
[0071] masterKeyUpdate contains the information necessary for a master key update.
[0072] The sk-counter contains the information necessary for secondary key generation.
[0073] Format E11 is a diagram showing an example of parameters of RadioBearerConfig included in RRCReconfiguration.
[0074] Format E12 is a diagram showing an example of parameters of CellGroupConfig included in RRCReconfiguration.
[0075] Format E111 is a diagram showing an example of parameters of SRB-ToAddMod included in RadioBearerConfig.
[0076] Format E112 is a diagram showing an example of the parameters of DRB-ToAddMod included in RadioBearerConfig.
[0077] Format E113 is a diagram showing an example of SecurityConfig parameters included in RadioBearerConfig.
[0078] Format E121 is a diagram showing an example of parameters of RLC-BearerConfig included in CellGroupConfig.
[0079] Format E122 is a diagram showing an example of parameters of SpCellConfig included in CellGroupConfig.
[0080] <Radio Bearer> An example of a radio bearer in the communication system 10 will now be described.
[0081] <1. Signaling Radio Bearer> A signaling radio bearer (SRB) is a radio bearer for transmitting RRC messages and NAS messages. SRB0 is a radio bearer for RRC messages using the CCCH logical channel. SRB1 is a radio bearer for RRC messages and NAS messages using the DCCH logical channel, which is established before SRB2, described later, is established. SRB2 is a radio bearer for transmitting and receiving NAS messages and transmitting RRC messages including logged measurement information, and uses the DCCH logical channel. The priority of SRB2 is lower than that of SRB1, and may be set by the base station device 200 after AS security is activated. SRB3 is a radio bearer for RRC messages when EN-DC, NGEN-DC, or NR-DC is configured in the terminal device 100, and uses the DCCH logical channel. EN-DC, NGEN-DC, and NR-DC are types of MR-DC, and details of the types of MR-DC will be described later.
[0082] <2. Data Radio Bearer> A data radio bearer (DRB) is a radio bearer for transmitting user data.
[0083] <SRB and DRB Protocol Configuration> The SRB and DRB protocol configuration of the terminal device 100 will be described.
[0084] SRB0 does not have a PDCP entity and is configured with an RLC bearer. The RLC bearer is configured with an RLC entity and a MAC logical channel. The mode of the RLC entity of SRB0 is TM.
[0085] Each of SRB1 and SRB2 consists of one PDCP entity and one or more RLC bearers, where the RLC entity is in AM mode.
[0086] SRB3 consists of one PDCP entity and one RLC bearer, and the mode of the RLC entity is AM.
[0087] A DRB consists of one PDCP entity and one or more RLC bearers. The mode of the RLC entity is UM or AM. A DBR is sometimes called a UM DBR when the RLC entity is UM, and sometimes called an AM DRB when the RLC entity is AM. Furthermore, a DRB is associated with one SDAP when the core network 300 is 5GC, and is associated with one EPS bearer (or EPS bearer identity) when the core network 300 is EPC.
[0088] It is assumed that one MAC entity exists for each cell group described below.
[0089] <Cells and Cell Groups> The cells and cell groups (CG) configured in the terminal device 100 will be described.
[0090] A cell group may be composed of one special cell (SpCell). Also, a cell group may be composed of one SpCell and one or more secondary cells (SCells). Note that an SpCell in a master cell group (MCG) (described later) may be called a primary cell (PCell). Also, an SpCell in a secondary cell group (SCG) (described later) may be called a primary SCG cell (PSCell).
[0091] The PCell is a primary frequency cell and is used to establish an RRC connection or re-establish an RRC connection. That is, when establishing an RRC connection or re-establishing an RRC connection, the cell selected by the terminal device 100 becomes the PCell. Furthermore, when the base station device 200 requests a handover (described later) from the terminal device 100, a new PCell designated by the base station device 200 is used for random access.
[0092] The SCell is a cell that provides additional radio resources in addition to the SpCell when carrier aggregation (CA) is configured in the terminal device 100.
[0093] The PSCell is a cell of the primary frequency on the SCG side. The PSCell is designated by the base station device 200 and is used for random access when adding or changing a PSCell in the SCG.
[0094] Note that the cell that the terminal device 100 in the RRC connected state uses for communication with the base station device 200 may be called the serving cell. When CA is not configured, the SpCell is the serving cell, and when CA is configured, the SpCell and SCell are the serving cells.
[0095] The MCG is a CG when DC (Dual Connectivity) is not set in the terminal device 100, or a CG that belongs to a master node (MN) when DC is set in the terminal device 100. DC is a technology in which the terminal device 100 is wirelessly connected to a base station device 200 that is a master node and a base station device 200 that is a secondary node (SN), and performs wireless communication using the carriers (cell groups) of the respective base station devices 200.
[0096] The SCG is a CG belonging to a secondary node that is set in addition to the MCG when a DC is set in the terminal device 100.
[0097] FIG. 7 is a diagram showing an example of the configuration of a cell group in the communication system 10. In FIG. 7, the master node (MN) is the base station device 200-1, and the secondary node (SN) is the base station device 200-2. The master node is, for example, a base station device 200 in an MR-DC that provides a C-Plane connection to the core network 300. The secondary node is, for example, a base station device 200 in an MR-DC that does not provide a C-Plane to the core network 300, but provides additional radio resources to the terminal device 100. In FIG. 7, the MCG is, for example, composed of one PCell and two SCells. Also, in FIG. 7, the SCG is, for example, composed of one PSCell and two SCells.
[0098] The base station device 200 may set a BWP (BandWidth Part) for the cell set for the terminal device 100, and adjust the cell so that a limited frequency band is used among the entire frequency band of the cell. The BWP may be configured from a portion of the frequency band of each cell. Furthermore, multiple BWPs (for example, up to four) may be set for each cell. The BWP may be set by an RRC reconfiguration message. In each cell, the BWP to be used may be specified or switched by an RRC reconfiguration message or by using DCI.
[0099] <Reconfiguration with Sync> Reconfiguration with Sync will now be described. Reconfiguration with Sync indicates a procedure executed in the terminal device 100 by including a parameter indicating that reconfiguration with Sync (reconfigurationWithSync: hereinafter, sometimes referred to as a reconfiguration parameter with sync) in an RRC reconfiguration message (RRCReconfiguration) that the base station device 200 transmits to the terminal device 100.
[0100] The synchronized reconfiguration parameters are included separately under parameters for MCG configuration (hereinafter, may be referred to as MCG configuration parameters) and under parameters for SCG configuration (hereinafter, may be referred to as SCG configuration parameters). In other words, when included under the MCG configuration parameters, it means synchronized reconfiguration of the MCG, and when included under the SCG configuration parameters, it means synchronized reconfiguration of the SCG.
[0101] The synchronized reconfiguration is a procedure in which the terminal device 100 changes the SpCell, and includes operations such as random access to the new (target, changed to) SpCell, MAC reset, and PDCP data recovery (in the case of AM DRB).
[0102] The process when the synchronized reconfiguration parameters are included under the MCG configuration parameters may be called handover. The process when the synchronized reconfiguration parameters are included under the SCG configuration parameters may be called PSCell addition and / or PSCell change. The source PCell / PSCell may be called the source PCell / source PSCell, and the destination PCell / PSCell may be called the target PCell / target PSCell. Because synchronized reconfiguration may involve CA, the term serving cell may be used, and the terms source serving cell and target serving cell may be used. The term "serving" may also be omitted, and the terms source cell and target cell may be used.
[0103] The terminal device 100 may generate the target cell configuration by applying the delta configuration included in the RRC reconfiguration message to the source cell configuration.
[0104] In addition, synchronized re-establishment may involve changing security keys. In this case, PDCP re-establishment is also performed in addition to the above.
[0105] When a security key is changed, a new key is generated by the RRC of the terminal device 100, and the PDCP is re-established, so that the new key is applied to the PDCP.
[0106] Fig. 8 is a diagram showing an example of synchronized reconfiguration. Fig. 8 is a diagram showing an example of processing when synchronized reconfiguration parameters are included under parameters for configuring an MCG. The synchronized reconfiguration parameters include settings such as a target PCell configuration, a new C-RNTI (Cell Radio Network Temporary Identifier), RACH configuration, and a timer for detecting handover failure. The terminal device 100 performs random access (RA) with the target PCell in accordance with the settings, and changes the current source PCell to the target PCell (S1).
[0107] <Random Access During Handover> Random access during handover can be classified into two types: contention-free random access (CFRA), which is random access without contention, and contention-based random access (CBRA), which is random access with contention, and each can be performed in four steps or two steps.
[0108] 9A and 9B are diagrams showing an example of a handover procedure using four-step random access. Fig. 9A shows an example of a handover procedure using four-step CFRA. Fig. 9B shows an example of a handover procedure using four-step CBRA.
[0109] The sequence of FIG. 9A will be described.
[0110] The base station device 200 transmits an RRC reconfiguration message including synchronization-attached reconfiguration parameters to the terminal device 100 (S901).
[0111] The terminal device 100 executes a handover using 4-step CFRA when the synchronization-based reconfiguration parameters include a 4-step CFRA configuration and when, among the reference signals specified in the 4-step CFRA configuration, there is a reference signal whose RSRP (Reference Signal Received Power) is equal to or greater than a threshold. Furthermore, the terminal device 100 executes a handover using 2-step CFRA when the synchronization-based reconfiguration parameters include a 2-step CFRA configuration and when, among the reference signals specified in the 2-step CFRA configuration, there is a reference signal whose RSRP is equal to or greater than a threshold. Furthermore, when the synchronization-based reconfiguration parameters do not include a 4-step CFRA configuration or a 2-step CFRA configuration, or when a 4-step CFRA configuration or a 2-step CFRA configuration is included but, among the reference signals specified in the 4-step CFRA configuration or the 2-step CFRA configuration, there is no reference signal whose RSRP is equal to or greater than a threshold, the terminal device 100 executes 4-step or 2-step CBRA.
[0112] The terminal device 100 transmits a random access preamble (RA preamble) to the base station device 200 via the target PCell (S902).
[0113] Upon receiving the random access preamble (S902), the base station device 200 transmits a random access response (RA response) (S903).
[0114] In the case of CFRA, the preamble is included in the CFRA configuration, so contention resolution is not required. Therefore, the handover is successful when the terminal device 100 receives a random access response from the target PCell.
[0115] When the terminal device 100 receives the random access response (S903), the terminal device 100 transmits an RRC reconfiguration complete message, which is a response message to the RRC reconfiguration message, to the base station device 200 via the target serving cell (S904).
[0116] Next, the sequence of FIG. 9B will be described.
[0117] The base station device 200 transmits an RRC reconfiguration message including synchronization-enabled reconfiguration parameters to the terminal device 100 (S905). Since the synchronization-enabled reconfiguration parameters do not include a CFRA setting, the terminal device 100 executes a handover (two steps or four steps) using CBRA.
[0118] The terminal device 100 transmits a random access preamble to the base station device 200 via the target PCell (S906).
[0119] Upon receiving the random access preamble (S906), the base station device 200 transmits a random access response (S907).
[0120] In the case of CBRA, an arbitrary random access preamble is used, which may conflict with a random access preamble transmitted by another terminal device. Therefore, when the terminal device 100 receives the random access response (S907), the handover is not considered to be successful.
[0121] When the terminal device 100 receives the random access response (S907), it transmits an RRC reconfiguration completion message to the base station device 200 via the target serving cell (S908).
[0122] Upon receiving the RRC reconfiguration completion message (S908), the base station device 200 transmits a MAC CE indicating contention resolution in the target serving cell to the terminal device 100 (S909).
[0123] In the case of CBRA, the handover is successful when the terminal device 100 receives a MAC CE (S909) indicating contention resolution.
[0124] That is, in a four-step CFRA handover, the RRC reconfiguration complete message is sent (S904) after the handover is successful, but in a four-step CBRA handover, the RRC reconfiguration complete message is sent (S908) before the handover is successful.
[0125] Furthermore, if the uplink resources allocated in step S907 are sufficiently large, the terminal device 100 can transmit uplink data generated in the DRB in addition to the RRC reconfiguration completion message in step S908. That is, in a four-step handover using CBRA, there is a possibility that uplink data generated in the DRB will be transmitted before the handover is successful.
[0126] In the case of a handover by two-step random access, in both CBRA and CFRA, the terminal device 100 transmits an RRC reconfiguration complete message in step S904 after transmitting the random access preamble in step S902 and before receiving the random access response in step S903. That is, in the case of a handover by two-step random access, in either the case of CFRA or CBRA, the RRC reconfiguration complete message is transmitted before the handover is successful, and therefore, uplink data generated in the DRB before the handover is successful may be transmitted.
[0127] Furthermore, in handovers in E-UTRA, RACH-less handover, which is handover without random access, may be performed. In RACH-less handover, an RRC reconfiguration complete message is transmitted from the target serving cell to the base station device 200 without performing random access, and the handover is successful when the target serving cell receives a MAC CE indicating contention resolution from the base station device 200. In other words, in RACH-less handover, the RRC reconfiguration complete message is sent before the handover is successful, and therefore, there is a possibility that uplink data generated in the DRB before the handover is successful may be transmitted.
[0128] <Handover Failure Processing> If the terminal device 100 receives an RRC reconfiguration message including a synchronization-enabled reconfiguration parameter and the handover is not successful within a certain time, the handover fails. The handover not being successful within the certain time may mean that the timer for detecting handover failure, which starts when the terminal device 100 receives an RRC reconfiguration message including a synchronization-enabled reconfiguration parameter, expires before the handover is successful.
[0129] If the handover fails, the terminal device 100 restores the settings to those used in the source PCell and performs an RRC connection re-establishment procedure. When restoring the settings of the terminal device 100 to those used in the source PCell, the values of the state variables in each entity of each radio bearer are also restored to the values used in the source (values immediately before the handover process).
[0130] In the RRC connection re-establishment procedure, the terminal device 100 performs cell selection, and if an NR cell is selected, it transmits an RRC re-establishment request message (RRCReestablishmentRequest) to the base station device 200. The RRC re-establishment request message is transmitted through SRB0. Since no PDCP entity exists in SRB0, security processing by PDCP is not performed on the RRC re-establishment request message. Furthermore, when an RRC re-establishment message (RRCReestablishment), which is a response message to the RRC re-establishment request message, is received from the base station device 200, the security key of the terminal device 200 is updated.
[0131] <Conditional Handover> A conditional handover (CHO) is a handover that is executed (initiated) by the terminal device 100 when one or more handover execution conditions are satisfied. The terminal device 100 receives an RRC reconfiguration message including conditional reconfiguration parameters from the base station device 200 and stores the conditional reconfiguration parameters. The conditional reconfiguration parameters include one or more pairs of configuration parameters for a PCell changeover target candidate, including synchronization reconfiguration parameters, and execution condition parameters for executing a handover to the PCell changeover target candidate. The execution condition parameters include, for example, parameters related to measurement configuration. Upon receiving the conditional reconfiguration parameters, the terminal device 100 starts cell measurement. If any PCell of the measured cells satisfies the execution conditions, the terminal device 100 applies the configuration parameters of the PCell changeover target candidate for the PCell that satisfies the execution conditions and performs a conditional handover to this PCell. After the conditional handover is successful, the terminal device 100 releases the conditional reconfiguration parameters.
[0132] The conditional reconfiguration parameters can include one or more pairs of SCG-side configuration, i.e., configuration parameters of a PSCell change destination candidate and execution condition parameters for executing a change to the PSCell change destination candidate. Upon receiving the SCG-side conditional reconfiguration parameters, the terminal device 100 starts measuring the execution conditions, and performs a conditional PSCell change (CPC) if the measurement result satisfies the execution conditions.
[0133] In a conditional handover, a handover failure is detected in the same way as in a non-conditional handover (hereinafter, sometimes simply referred to as a handover), and processing after the handover failure is performed. In a conditional handover failure or in a procedure for re-establishing an RRC connection after a handover failure, or in a procedure for re-establishing an RRC connection after a radio link failure, if the selected cell is a PCell changeover candidate, the terminal device 100 can transmit an RRC reconfiguration complete message to the base station device 200 instead of transmitting an RRC re-establishment request message to attempt handover and recover the RRC connection. Note that, when the cell selected by the terminal device 100 is a PCell changeover candidate, the terminal device 100 can transmit an RRC reconfiguration complete message to the base station device 200 instead of transmitting an RRC re-establishment request message only if a conditional reconfiguration attempt parameter (attemptCondReconfig), which is a parameter that permits this processing, is set in the terminal device 100.
[0134] Note that conditional handover and non-conditional handover may be referred to as handover without distinction.
[0135] <AS Security and Key Stream> The AS security processing is performed in the PDCP entity of the radio bearer other than SRB0, using security keys (ciphering key, integrity protection key) generated by the RRC. The AS security processing includes ciphering and integrity protection, which are performed using the ciphering key and integrity protection key, respectively.
[0136] When a PDCP entity of each radio bearer receives a PDCP SDU from a higher layer, it performs AS security processing on the received PDCP SDU using an input called a key stream, which consists of four elements, for example, KEY, COUNT, BEARER, and DIRECTION.
[0137] KEY indicates, for example, a security key.
[0138] COUNT is one of the state variables of the PDCP entity, and indicates, for example, a sequence number. The COUNT value is initially set to '0' and is incremented by 1 each time a PDCP PDU is passed to a lower layer. The maximum value of the COUNT value is, for example, 2^32 minus 1, i.e., '4294967295'.
[0139] BEARER indicates, for example, the value of a radio bearer identifier. DIRECTION indicates whether it is an uplink or a downlink, and is '0' for an uplink and '1' for a downlink.
[0140] In AS security, from a security perspective, key stream reuse is prohibited. For example, when the terminal device 100 transmits data from a certain radio bearer, it is prohibited to perform AS security processing using a COUNT value previously used on this radio bearer unless the security key is updated.
[0141] The definition of the term "keystream" may vary slightly depending on the specification. In this embodiment, the keystream will be explained as consisting of four elements: KEY, COUNT, BEARER, and DIRECTION. [Embodiments] Each embodiment will be explained below.
[0142] <L1 / L2 Triggered Mobility> An example of an overview of L1 / L2 Triggered Mobility (LTM), the specifications of which are currently being developed, will be described.
[0143] Fig. 17 is a diagram showing an example of parameters related to LTM included in the RRC Reconfiguration message. Note that the parameters described in Fig. 6 are omitted in Fig. 17. Furthermore, parameters other than the example parameters shown in Fig. 17 may be included in the RRC Reconfiguration message. Furthermore, the names of the parameters are merely examples and do not have to be as shown.
[0144] Format E2 is a parameter of RRC Reconfiguration. RRC Reconfiguration includes ltm-Config, which means LTM configuration. If LTM-Config is included in SetupRelease, ltm-Config means that the LTM configuration is newly configured or changed. If SetupRelease does not include any ltm-Config, it means that the LTM configuration is resolved.
[0145] Format E21 is a parameter included in the LTM setting. ltm-ReferenceConfiguration is a reference setting, which will be described later. ltm-CandidateToAddModList is a list of settings of candidate cell change destinations. In other words, ltm-CandidateToAddModList includes one or more settings of candidate cell change destinations. ltm-ServingCellNoResetID is an identifier used by the terminal device 100 when determining whether or not an L2 reset (Layer 2 reset) is required when switching cells, which will be described later. The ltm-ServingCellNoResetID or the initial value of ltm-ServingCellNoResetID may be a group identifier of the serving cell used when the base station device 200 transmits an RRC reconfiguration message including a configuration of cell change destination candidates to the terminal device 100 in step S1001, which will be described later. ltm-ServingCellNoResetID may be stored in the terminal device 100 as a variable indicating the group identifier of the current serving cell. Furthermore, ltm-ServingCellNoResetID is a parameter that is essential when an LTM configuration is newly configured and is not present in other cases. attemptLTM-Switch is a parameter that has the same meaning as the conditional reconfiguration attempt parameter (attemptCondReconfig) in conditional handover, and is a parameter that permits recovery of the RRC connection after a cell switch failure, a handover failure, or a radio link failure.
[0146] Format E211 is a parameter included in the configuration of a cell change destination candidate. LTM-Candidate is the configuration of a cell change destination candidate. ltm-CandidateId is an identifier or index that uniquely identifies one or more configured cell change destination candidate configurations within the terminal device 100. ltm-CandidateConfig is a parameter for generating a configuration to be used at the cell change destination (target). ltm-CandidateConfig may be a complete configuration or a delta configuration, as described below. ltm-CandidateConfig may be configured with parameters included in an RRC reconfiguration message. ltm-NoResetID is an identifier used by the terminal device 100 when determining whether or not an L2 reset (Layer 2 reset) is required at the time of cell change, as described below. ltm-NoResetID may be a group identifier of a cell that is a cell change destination candidate.
[0147] FIG. 10 is a diagram showing an example of an LTM sequence.
[0148] The base station device 200 includes one or more cell change destination candidate settings (target cell candidate settings) in an RRC reconfiguration message and transmits the message to the terminal device 100 (S1001).
[0149] Upon receiving an RRC reconfiguration message (S1001), the terminal device 100 stores the LTM configuration information (including the configuration of candidate cell change destinations) included in the received message. The terminal device 100 may also store the value of ltm-ServingCellNoResetID included in the LTM configuration in a variable indicating the group identifier of the current serving cell.
[0150] Note that the cell change destination candidate may be, for example, only the PCell or may include the SCell. The configuration of each cell change destination candidate may be uniquely identified within the terminal device 100 using an index (ltm-CandidateId). Furthermore, the configuration of the cell change destination candidate may not include a parameter indicating an update of the security key. In other words, the security key by LTM may not be updated. Furthermore, the configuration of the cell change destination candidate may include parameters similar to the synchronized reconfiguration parameters.
[0151] The terminal device 100 may retain the configuration of the cell change destination candidate received and stored in step S1001 without releasing it after the cell change is successful, as described below. In this case, the retained configuration of the cell change destination candidate may be used for a subsequent cell switch. However, when the configuration of the cell change destination candidate is retained and used for a subsequent cell switch, it may not be possible to set the configuration of the cell change destination candidate to a delta configuration and apply the delta configuration to the source configuration to generate a target cell configuration. This phenomenon occurs because the source configuration differs depending on the order of cells changed by cell switch.
[0152] For this reason, in step S1001, the RRC reconfiguration message may include a reference configuration in addition to the configuration of the cell change destination candidate, or as part of the configuration of the cell change destination candidate. The reference configuration is used, for example, to complete the configuration to be used at the cell change destination (target). When the RRC reconfiguration message includes a reference configuration, the configuration of each cell change destination candidate included in the RRC reconfiguration message may be a differential configuration (delta configuration) from the reference configuration. In other words, the terminal device 100 can generate the configuration to be used at the cell change destination (target), i.e., the complete configuration to be used at the cell change destination, from the reference configuration and the configuration of the cell change destination candidate (delta configuration). For example, when the terminal device 100 receives a cell change signal to cell X, which is a cell change destination candidate, from the base station device 200 in step S1002 described below, the terminal device 100 generates the configuration to be used in cell X by applying the configuration of cell X to the reference configuration.
[0153] Also, in step S1001, the RRC reconfiguration message may not include a reference configuration. When the RRC reconfiguration message does not include a reference configuration, the configuration of each cell change destination candidate included in the RRC reconfiguration message is, for example, a complete configuration. That is, the terminal device 100 can generate the configuration to be used at the cell change destination (target) by replacing the configuration used in the current cell with the configuration of the cell change destination candidate. For example, in step S1002 described below, when the terminal device 100 receives a cell change signal to cell X, which is a cell change destination candidate, from the base station device 200, the terminal device 100 generates the configuration to be used in cell X by replacing the configuration of the current cell with the configuration of cell X. However, when the configuration of the cell change destination candidate is set to a complete configuration, some of the configurations may not be included. The partial configuration includes, for example, configurations that do not change due to cell change (fixed configurations). The configurations that do not change due to cell change (fixed configurations) include, for example, some or all of the radio bearer configurations. In this case, when the terminal device 100 receives a cell switching signal from the base station device 200 to cell X, which is a candidate cell change destination, it generates settings to be used in cell X by replacing the current cell settings with the cell X settings, except for fixed settings.
[0154] Note that, regardless of whether or not the RRC reconfiguration message includes a reference configuration, when generating a configuration to be used at the cell switching destination, the terminal device 100 does not need to reset some or all of the values of state variables, timers, etc. used in each entity (SDAP entity, PDCP entity, RLC entity, MAC entity, etc.) to their initial states. Furthermore, the terminal device 100 does not need to discard some or all of the buffers in each entity. In other words, the terminal device 100 can retain some or all of the values of state variables, timers, etc. used in each entity. Furthermore, the terminal device 100 may retain some or all of the buffers in each entity.
[0155] The base station device 200 transmits to the terminal device 100 a cell switching signal for switching the serving cell of the terminal device 100 from the current serving cell to one of the cell switching destination candidates (S1002).
[0156] The terminal device 100 receives a cell switching signal in the current serving cell (S1002). The cell switching signal may be, for example, a MAC CE. Alternatively, the cell switching signal may be a physical layer signal such as DCI.
[0157] The cell switching signal includes at least an index (ltm-CandidateId). The terminal device 100 applies the setting of the cell change destination (cell X) specified by the received cell switching signal. Note that cell X may be configured only with a PCell, may be configured only with a PSCell, or may be configured with a PCell or a PSCell and one or more SCells.
[0158] The terminal device 100 performs four-step or two-step CFRA or CBRA with the base station device 200 in cell X in accordance with the configuration of cell X (S1003). Also, for example, if the configuration of cell X includes a parameter indicating that a RACH-less cell switch is to be performed, or if early TA acquisition, which will be described later, has been performed, the random access process in step S1003 is not executed. Also, if the ltm-NoResetID of cell X is the same as the ltm-ServingCellNoResetID or a variable indicating the group identifier of the current serving cell, the terminal device 100 does not perform L2 reset. Furthermore, if the ltm-NoResetID of cell X is not the same as the ltm-ServingCellNoResetID or the variable indicating the group identifier of the current serving cell, the terminal device 100 performs an L2 reset and overwrites the ltm-ServingCellNoResetID or the variable indicating the group identifier of the current serving cell with the ltm-NoResetID of cell X. The L2 reset is, for example, an RLC re-establishment. The L2 reset is, for example, a PDCP data recovery.
[0159] The terminal device 100 transmits a notification indicating that the cell has been switched to the base station device 200 in cell X (S1004). This notification corresponds to an RRC reconfiguration complete message in handover or conditional handover. The notification indicating that the cell has been switched may use an RRC message such as an RRC reconfiguration complete message or a MAC CE. Furthermore, the notification indicating that the cell has been switched may use a physical signal such as UCI.
[0160] Furthermore, the notification indicating that the cell has been switched may include at least an identifier of cell X of the terminal device 100. Note that, if two-step CFRA or CFRA has been performed in step S1003, the notification indicating that the cell has been switched is transmitted before receiving the random access response in step S1003. Furthermore, uplink data generated in the DRB may be transmitted together with the notification indicating that the cell has been switched.
[0161] If a four-step or two-step CBRA is performed in step S1003, or if a RACH-less cell switch is performed, the base station device 200 transmits to the terminal device 100 a signal including a contention resolution signal or information indicating that the notification transmitted from the terminal device 100 in step S1004 has been successfully received (hereinafter, this may be referred to as reception success information) (S1005).
[0162] The terminal device 100 receives, for example, a contention resolution signal or a signal including reception success information in cell X (S1005). The contention resolution signal or reception success information may include at least an identifier of the terminal device 100 in cell X.
[0163] The timing of successful cell switching may be the same as that of successful handover in handover or conditional handover. That is, in the case of cell switching using four-step or two-step CFRA, the cell switching is successful when a random access response is received. Also, in the case of cell switching using four-step or two-step CBRA, or RACH-less cell switching, the cell switching is successful when the processing of step S1005 is performed. If the timing of successful cell switching is the same as that of successful handover in handover or conditional handover, as in handover or conditional handover, in cell switching using four-step CFRA, no notification indicating the cell switching or uplink data generated in the DRB is transmitted before the cell switching is successful. However, in the case of cell switching using four-step CBRA, cell switching using two-step CFRA or CBRA, and RACH-less cell switching, a notification indicating the cell switching is transmitted before the cell switching is successful. Furthermore, uplink data generated by the DRB may be transmitted together with a notification indicating that the cell has been switched.
[0164] After executing step S1001, the terminal device 100 may perform downlink synchronization and / or uplink synchronization with one or more cell change destination candidates before transmitting the cell change destination signal in step S1002. In uplink synchronization, the base station device 200 may measure a timing advance (TA) of the terminal device 100 for one or more cell change destination candidates. Uplink synchronization may be performed by the base station device 200 instructing the terminal device 100 to transmit a random access preamble. The base station device 200 may instruct the terminal device 100 to transmit different random access preambles to one or more cell change destination candidates, or may instruct the terminal device 100 to transmit a common random access preamble to a group of multiple cell change destination candidates. The TA measured by the base station device 200 may be transmitted to the terminal device 100 using a random access response (RAR), or may be transmitted to the terminal device 100 using the cell change destination signal in step S1002. In this way, performing uplink synchronization after the terminal device 100 executes step S1001 and before the cell switching signal is sent in step S1002 may be called early TA measurement or early TA acquisition.
[0165] Note that cell switching may be referred to as LTM or LTM cell switching. Cell switching may also be referred to as other terms that represent cell switching by LTM. Hereinafter, cell switching and cell change may be treated as terms that mean the same thing.
[0166] In addition, in this embodiment, unless there is a particular distinction between cell switching of an MCG and cell switching of an SCG, cell switching is considered to be cell switching of an MCG.
[0167] In addition, in the setting of the cell change destination candidate of the MCG in the LTM setting, a synchronization reset parameter may be included under the MCG setting parameter. Similarly, in the setting of the cell change destination candidate of the SCG in the LTM setting, a synchronization reset parameter may be included under the SCG setting parameter. Therefore, the cell switching of the MCG may be referred to as a handover. Furthermore, the cell switching of the SCG may be referred to as a PSCell change.
[0168] <Cell Switching Failure Processing> When cell switching fails, an RRC connection re-establishment procedure may be executed, similar to the handover failure processing and the conditional handover failure processing.
[0169] Fig. 11 is a diagram showing an example of a sequence of detecting a cell switching failure and processing the cell switching failure. The processing of steps 1001 and 1002 in Fig. 11 is the same as the processing of steps 1001 and 1002 in Fig. 10, and therefore a description thereof will be omitted.
[0170] When the terminal device 100 receives a cell switching signal (S1002), it starts a timer for detecting cell switching failure (S1101) and starts cell switching processing to a cell (cell X) specified by the received cell switching signal (not shown). If the cell switching is successful before the timer expires, the terminal device 100 stops the timer (not shown). On the other hand, if the timer expires, the terminal device 100 detects failure of cell switching to cell X (S1102).
[0171] When the terminal device 100 detects a cell switching failure (S1102), the terminal device 100 performs a cell switching failure process (S1103). In the cell switching failure process, the terminal device 100 may restore the settings of the terminal device 100 to the settings used in the source PCell and perform an RRC connection re-establishment procedure. Note that part or all of the cell switching failure process is an example of the first process.
[0172] <Keystream reuse issue in cell switching failure processing> In LTM, in the procedure for re-establishing an RRC connection in cell switching failure processing or in the procedure for re-establishing an RRC connection after a radio link failure on the MCG side, if the selected cell is one of the candidate cell change destinations, it is agreed that the RRC connection is recovered as in the case of conditional handover, i.e., cell switching is performed to the selected cell instead of sending an RRC re-establishment request message in the selected cell.
[0173] However, in the RRC connection re-establishment procedure after a cell switch failure using four-step CBRA, or a cell switch failure using two-step CFRA or CBRA, or a RACH-less cell switch failure, if the selected cell is one of the cell change destination candidates, the process of cell switching to the selected cell instead of sending an RRC re-establishment request message in the selected cell may cause a key stream reuse problem.
[0174] As described above, in cell switch using four-step CBRA, cell switch using two-step CFRA or CBRA, and RACH-less cell switch, uplink data may be transmitted together with a notification indicating the cell switch before the cell switch is successful. If the notification indicating the cell switch is an RRC message transmitted from an SRB other than SRB0 (e.g., SRB1), the RRC message is processed, including security processing, in the PDCP entity of SRB1 and transmitted as a PDCP data PDU through a lower layer. Assume that the COUNT value used for security processing in the PDCP entity of the RRC message is, for example, n.
[0175] Furthermore, when uplink data is transmitted from a certain DRB (DRB1) together with a notification indicating a cell change, the uplink data undergoes processing, including security processing, in the PDCP entity of DRB1, and is transmitted as a PDCP data PDU through a lower layer. The COUNT value used for the security processing of the uplink data (in the PDCP entity of the uplink data) is assumed to be, for example, m.
[0176] If the cell switch fails, the terminal device 100 restores the settings of the terminal device 100 to the settings used in the source PCell and performs an RRC connection re-establishment procedure. When restoring the settings of the terminal device 100 to the settings used in the source PCell, the values of the state variables in each entity of each radio bearer are also restored to the values used in the source, so the COUNT value returns to the state before the cell switch signal was received. In the RRC connection re-establishment procedure, if the selected cell is one of the cell change destination candidates and cell switch is performed to the selected cell, the terminal device 100 transmits an RRC message that is a notification indicating that the cell has been switched in the cell. When transmitting the RRC message, the COUNT value n is used again in security processing in the PDCP entity of the SRB1. Furthermore, when the first uplink message is transmitted from the DRB1 in the cell, the COUNT value m is used again in security processing in the PDCP entity of the DRB1. In cell switching in LTM, no security key change is performed, and the same security key and the same COUNT value are used for the same radio bearer in the same direction (uplink), i.e., the key stream reuse problem may occur.
[0177] <Cell switching failure process 1 to avoid the key stream reuse problem> Fig. 12 is a diagram showing an example of a first cell switching failure process method. The first cell switching failure process method is a method in which, in a procedure for re-establishing an RRC connection after a cell switching failure, a handover failure, or a handover failure to a different RAT, if the cell selected by the terminal device 100 is an NR cell, the selected NR cell transmits an RRC re-establishment request message to the base station device 200, regardless of whether this NR cell is one of the cell change destination candidates.
[0178] In addition, handover to a different RAT can be rephrased as mobility from NR.
[0179] The terminal device 100 detects a failure in cell switching to cell X, a failure in handover, or a failure in handover to a different RAT (S1102).
[0180] Next, the terminal device 100 restores the settings of the terminal device 100 to the settings used in the source PCell, and performs an RRC connection re-establishment procedure (S1201). When restoring the settings of the terminal device 100 to the settings used in the source PCell, the values of the state variables in each entity of each radio bearer are also restored to the values used in the source (the values at the time of receiving the cell switching signal in step S1002 of FIG. 11 or the values immediately before the reception). Note that, when performing the RRC connection re-establishment procedure, the terminal device 100 may release the stored settings of cell change destination candidates. When releasing the stored settings of cell change destination candidates, the release process may be performed before the process of step S1202 described below.
[0181] In the RRC connection re-establishment procedure, the terminal device 100 performs cell selection, for example, selects an NR cell. The terminal device 100 transmits an RRC re-establishment request message to the base station device 200 in the selected NR cell (S1202).
[0182] In addition, in the procedure for re-establishing the RRC connection, if the selected cell is a RAT other than NR, the terminal device 100 transitions to the RRC idle mode. Also, if the terminal device 100 cannot select a cell within a certain time, it transitions to the RRC idle mode.
[0183] In the case of a procedure for re-establishing an RRC connection after a handover failure, if the cell selected by the terminal device 100 is an NR cell, the selected NR cell is a cell that satisfies the second condition, and the first parameter is set in the terminal device 100, if the handover before the failure was a handover involving a security key update, the terminal device 100 performs cell switching to the selected cell, and if the handover before the failure was a handover without a security key update, the terminal device 100 may transmit an RRC re-establishment request message to the base station device 200 in the selected NR cell. A handover failure may be rephrased as a cell switching failure. The processing including the processing when the handover is a handover involving a security key update and the processing when the handover is a handover without a security key update is an example of the first processing.
[0184] Also, in the case of a procedure for re-establishing an RRC connection after a radio link failure, if the cell selected by the terminal device 100 is an NR cell, this NR cell is a cell that satisfies the second condition, and the first parameter is set in the terminal device 100, the terminal device 100 may perform cell switching to the selected cell.
[0185] In addition, in the case of a procedure for re-establishing an RRC connection after a handover to a different RAT fails, if the cell selected by the terminal device 100 is an NR cell, this NR cell is a cell that satisfies the second condition, and the first parameter is set in the terminal device 100, the terminal device 100 may perform cell switching to the selected cell.
[0186] Also, in the case of a procedure for re-establishing an RRC connection after a handover to a different RAT fails, if the cell selected by the terminal device 100 is an NR cell, the selected NR cell is a cell that satisfies the second condition, and the first parameter is set in the terminal device 100, if the handover to a different RAT before the failure was a handover to a different RAT that involved a security key update, the terminal device 100 may perform cell switching to the selected cell, and if the handover to a different RAT before the failure was a handover to a different RAT that did not involve a security key update, the terminal device 100 may transmit an RRC re-establishment request message to the base station device 200 in the selected NR cell.
[0187] The first parameter is a parameter that means performing recovery of the RRC connection in a procedure for re-establishing the RRC connection after, for example, a cell switching failure, and / or a handover failure, and / or a handover failure to a different RAT, and / or a radio link failure. Note that the first parameter is, for example, an example of a parameter related to the recovery of the RRC connection.
[0188] Recovering the RRC connection means performing a cell switching process on a selected cell if this cell is one of the cells that satisfy the second condition, for example, in a procedure for re-establishing an RRC connection after a cell switching failure, and / or a handover failure, and / or a handover failure to a different RAT, and / or a radio link failure.
[0189] Furthermore, recovering the RRC connection means, for example, performing cell switching processing on a selected cell in a procedure for re-establishing an RRC connection after a cell switching failure, and / or a handover failure, and / or a handover failure to a different RAT, and / or a radio link failure, if the selected cell is one of the cells that satisfy the second condition and is the first cell selection after the detection of a cell switching failure in step S1102 or after a handover failure, or after a handover failure to a different RAT, or after a radio link failure.
[0190] The second condition includes, for example, that the cell is a cell change destination candidate stored in the terminal device 100. Furthermore, the second condition includes, for example, that the cell is a cell in which recovery of the RRC connection after cell change failure is permitted. Note that the second condition may also be described as a second condition related to cell change.
[0191] A cell for which recovery of the RRC connection after cell switching failure is permitted includes, for example, a cell that is a cell switching destination candidate stored by the terminal device 100 and that belongs to the same group as the cell for which cell switching failed (for example, cell X). Determination of whether a cell belongs to the same group as cell X is performed, for example, by a group identifier that is set in advance in the setting of the cell switching destination candidate. The group identifier may be rephrased as a reset-unnecessary identifier.
[0192] Furthermore, a cell in which recovery of the RRC connection after a cell switching failure is permitted includes, for example, a cell change destination candidate stored by the terminal device 100, and a cell in which the setting of the cell change destination candidate includes information indicating that recovery of the RRC connection after a cell switching failure is permitted.
[0193] Furthermore, a cell in which recovery of the RRC connection after a cell switching failure is permitted includes, for example, a cell change destination candidate stored by the terminal device 100, and also a cell selected in the first cell selection after detection of a cell switching failure in step S1102, or after a handover failure, or after a handover failure to a different RAT, or after a radio link failure.
[0194] The first parameter is, for example, the attemptLTM-Switch parameter.
[0195] <Cell switching failure process 2 to avoid the key stream reuse problem> Fig. 13 is a diagram showing an example of a second cell switching failure process method. The second cell switching failure method is a method in which, in a procedure for re-establishing an RRC connection in cell switching failure process, if the cell selected by the terminal device 100 is one of the cells that satisfies the second condition and also satisfies at least the first condition, the cell switching process to the selected cell is performed by applying the settings of the selected cell as a cell change destination candidate.
[0196] In addition, when the cell selected by the above-mentioned terminal device 100 is one of the cells that satisfies the second condition and also satisfies at least the first condition regarding cell switching, the process of applying the settings of the selected cell as a candidate cell change destination and performing the cell switching process to the selected cell may be performed, for example, when at least the first parameter is set in the terminal device 100.
[0197] The terminal device 100 detects a failure in cell switching to cell X (S1102).
[0198] Next, the terminal device 100 restores the settings of the terminal device 100 to the settings used in the source PCell, and performs an RRC connection re-establishment procedure (S1301). When restoring the settings of the terminal device 100 to the settings used in the source PCell, the terminal device 100 also restores the values of the state variables in each entity of each radio bearer to the values used in the source (the values at the time of receiving the cell switching signal in step S1002 of FIG. 11 or the values immediately before receiving the signal).
[0199] In the procedure for re-establishing the RRC connection, the terminal device 100 performs cell selection and performs processing according to the selected cell and the first condition (S1302).
[0200] The first condition is, for example, that the cell switching process to cell X after receiving the cell switching signal in step S1002 of FIG. 11 has been performed using a four-step CFRA, i.e., that the setting of the cell change destination candidate for cell X includes a four-step CFRA setting.
[0201] Furthermore, the first condition may be, for example, that after receiving the cell switching signal in step S1002 of FIG. 11, only the cell switching process using the four-step CFRA was performed during the cell switching process to cell X, i.e., that the setting of cell change destination candidates for cell X includes the four-step CFRA setting, and further, that in the initial random access resource selection, there was a reference signal whose RSRP was equal to or greater than a threshold value.
[0202] Furthermore, the first condition may be, for example, that a cell switching process using a four-step CFRA was performed during the cell switching process to cell X after receiving the cell switching signal in step S1002 of FIG. 11, i.e., that the setting of cell change destination candidates for cell X includes a four-step CFRA setting, and that this is the first cell selection after detecting a cell switching failure in step S1102.
[0203] Furthermore, the first condition may be, for example, that, during the cell switching process to cell X after receiving the cell switching signal in step S1002 of FIG. 11, only the cell switching process using the four-step CFRA has been performed; that is, the setting of cell change destination candidates for cell X includes a four-step CFRA setting, and in the initial random access resource selection, there is a reference signal whose RSRP is equal to or greater than a threshold, and this is the first cell selection after detecting a cell switching failure in step S1102.
[0204] Note that the fact that only the cell switching process by the 4-step CFRA has been performed may be rephrased as the fact that the cell switching process by the 4-step CFRA has been performed and the MAC PDU in the Msg3 (message 3) buffer has not been transmitted. In addition, the fact that only the cell switching process by the 4-step CFRA has been performed may be rephrased as the fact that the 4-step or 2-step CBRA has not been performed before the cell switching process by the 4-step CFRA.
[0205] Furthermore, the first condition may be, for example, that after receiving the cell switching signal in step S1002 of FIG. 11, until cell switching failure is detected in step S1102, no PDCP data PDU is transmitted from the terminal device 100 through a lower layer, i.e., no RRC message is transmitted from an SRB other than SRB0, and / or no uplink data is transmitted from a DRB.
[0206] Furthermore, the first condition may be, for example, that after receiving the cell switching signal in step S1002 of FIG. 11, no PDCP data PDU is transmitted from the terminal device 100 through a lower layer until a cell switching failure is detected in step S1102, i.e., that no RRC message is transmitted from an SRB other than SRB0, and / or that no uplink data is transmitted from a DRB, and that this is the first cell selection after the cell switching failure is detected in step S1102.
[0207] Furthermore, the first condition may be, for example, that only the first signal is sent from the terminal device 100 after receiving the cell switching signal in step S1002 of FIG. 11 and before detecting a cell switching failure in step S1102.
[0208] Furthermore, the first condition may be, for example, that after receiving the cell switching signal in step S1002 of FIG. 11, only the first signal is sent from the terminal device 100 until a cell switching failure is detected in step S1102, and that this is the first cell selection after the cell switching failure is detected in step S1102.
[0209] The first signal is the notification sent in step S1004 of Fig. 10. The first signal may be, for example, a MAC CE. The first signal may also be a physical layer signal.
[0210] Furthermore, the terminal device 100 may transmit only the first signal, which may mean that the terminal device 100 does not transmit a MAC SDU.
[0211] In the RRC connection re-establishment procedure, the terminal device 100 performs cell selection. The terminal device 100 selects an NR cell, and if this NR cell is one of the cells that satisfy the second condition (for example, cell Y) and also satisfies the first condition, it applies the cell change destination candidate setting for cell Y and performs cell switching processing to cell Y. Note that the cell switching processing to cell Y may be limited to cases where a first parameter has been set in the terminal device 100. The first parameter may be, for example, a parameter indicating that if the cell selected in the cell switching failure processing is one of the cells that satisfy the second condition and also satisfies the first condition, cell switching processing is to be performed on this cell.
[0212] Furthermore, in the procedure for re-establishing the RRC connection, if the selected cell is an NR cell and meets some or all of the following conditions A to D, the terminal device 100 transmits an RRC re-establishment request message to the base station device 200 in the selected cell. At this time, before transmitting the RRC re-establishment request message to the base station device 200, the terminal device 100 may release the stored settings of the cell change destination candidate.
[0213] Condition A: The selected cell is not one of the cells that meets the second condition.
[0214] Condition B: The first condition is not met.
[0215] Condition C: The first parameter is not set.
[0216] Condition D: In the procedure for re-establishing an RRC connection after a handover failure or a handover failure to a different RAT, the handover or handover to a different RAT before the failure is a handover or handover to a different RAT that does not involve a change of security key. Note that a handover failure may be rephrased as a cell switching failure.
[0217] In addition, in the RRC connection re-establishment procedure, if the selected cell is a cell of a RAT other than NR, or if cell selection cannot be made within a specified time, the terminal device 100 transitions to RRC idle mode.
[0218] Note that the terminal device 100 may be configured or designed (hereinafter, sometimes referred to as a transmission prohibition setting) so as not to transmit a PDCP data PDU during the period from when the terminal device 100 receives a cell switching signal in step S1002 in Fig. 11 until when a cell switching failure is detected in step S1102. The transmission prohibition setting means, for example, being configured or designed so as to use only a four-step CFRA for random access in the cell switching process. Also, being configured or designed so as to use only a four-step CFRA for random access in the cell switching process means including a four-step CFRA setting in the setting of each cell change destination candidate.
[0219] The transmission prohibition setting is, for example, using MAC CE or physical layer signaling for notification in step S1004 of Fig. 10, and not transmitting uplink data generated by DRB or the like in step S1004. Not transmitting uplink data generated by DRB or the like means, for example, not transmitting MAC SDU.
[0220] If transmission prohibition is set, the terminal device 100 performs the process of step S1302 as follows.
[0221] In the RRC connection re-establishment procedure, the terminal device 100 performs cell selection. If the selected cell is an NR cell and is one of the cells that satisfies the second condition (for example, cell Y), the terminal device 100 applies the cell change destination candidate setting to cell Y and performs cell switching processing to cell Y. Note that the cell switching processing to cell Y may be limited to cases where the first parameter has been set in the terminal device 100.
[0222] Furthermore, when transmission prohibition is set, in the procedure for re-establishing an RRC connection, if the cell selected by the terminal device 100 is an NR cell and meets some or all of the following conditions E to G, the terminal device 100 transmits an RRC re-establishment request message to the base station device 200 in the selected cell. At this time, before transmitting the RRC re-establishment request message to the base station device 200, the terminal device 100 releases the stored settings of the cell change destination candidate.
[0223] Condition E: The selected cell is not one of the cells that meets the second condition.
[0224] Condition F: The first parameter is not set.
[0225] Condition G: In the procedure for re-establishing an RRC connection after a handover failure or a handover failure to a different RAT, the handover or handover to a different RAT before the failure is a handover or handover to a different RAT that does not involve a change of security key. Note that a handover failure may be rephrased as a cell switching failure.
[0226] In addition, in the RRC connection re-establishment procedure, if the selected cell is a cell of a RAT other than NR, or if cell selection cannot be made within a specified time, the terminal device 100 transitions to RRC idle mode.
[0227] <Cell switching failure process 3 to avoid the key stream reuse problem> Figure 14 is a diagram showing an example of a third cell switching failure process method. The third cell switching failure method is a process in which, when the terminal device 100 restores the settings of the terminal device 100 to the settings used in the source PCell after detecting a cell switching failure, the values of some or all of the state variables are retained, and, if the cell selected by the terminal device 100 in the RRC connection re-establishment procedure is an NR cell and one of the cells that satisfies the second condition, the settings of the cell change destination candidate of the selected cell are applied, and cell switching process to the selected cell is performed. Note that, when the terminal device 100 restores the settings of the terminal device 100 to the settings used in the source PCell after detecting the above-mentioned cell switching failure, the process of retaining the values of some or all of the state variables is performed, for example, when at least a first parameter is set in the terminal device 100. Furthermore, in the procedure for re-establishing an RRC connection, if the cell selected by the terminal device 100 is one of the cells that satisfy the second condition, the process of applying the settings of the cell change destination candidate of the selected cell and performing cell switching to the selected cell is performed, for example, when at least the first parameter is set in the terminal device 100. Note that, when the terminal device 100 transmits an RRC re-establishment request message to the base station device 200 in the selected cell, it restores the state variables that it has held to the settings used in the source PCell before transmitting the RRC re-establishment request message.
[0228] The terminal device 100 detects a failure in cell switching to cell X (S1102).
[0229] Next, the terminal device 100 restores the settings of the terminal device 100 other than the state variables to the settings used in the source PCell, and performs an RRC connection re-establishment procedure (S1401). When the terminal device 100 restores the settings of the terminal device to the settings used in the source PCell, for example, if at least the third condition is satisfied, the terminal device 100 retains the values of some or all of the state variables in each entity of the radio bearer set in the terminal device 100 without restoring them to the values used in the source PCell (the values at the time of receiving the cell switch signal in step S1002 of FIG. 11 or the values immediately before the reception). The retained state variables include, for example, the COUNT value in the PDCP entity. Furthermore, when the terminal device 100 does not satisfy the third condition, when restoring the settings of the terminal device 100 to the settings used in the source PCell, the terminal device 100 also restores the values of the state variables in each entity of each radio bearer to the values used in the source (the values at the time of receiving the cell switch signal in step S1002 of FIG. 11 or the values immediately before the reception).
[0230] The third condition includes, for example, some or all of the following: a parameter indicating that LTM is to be performed is set in the terminal device 100; a first parameter is set in the terminal device 100; and cell switching to cell X has not been accompanied by updating of the security key. Including these, the third condition may be described as, for example, a third condition related to cell switching.
[0231] The radio bearer set in the terminal device 100 may be an SRB, and / or a DRB, and / or an MRB.
[0232] Next, in the procedure for re-establishing the RRC connection, the terminal device 100 performs cell selection and performs processing according to the selected cell (step S1402). Note that the cell selection procedure may be performed as part of the procedure for re-establishing the RRC connection, or may be performed separately from the procedure for re-establishing the RRC connection.
[0233] When the selected cell is an NR cell and is one of the cells that satisfies the second condition (for example, cell Y), the terminal device 100 applies the cell change destination candidate setting to cell Y and performs cell switching processing to cell Y. Note that the cell switching processing to cell Y is performed, for example, when a first parameter is set in the terminal device 100.
[0234] The terminal device 100 may apply the setting of the cell change destination candidate to cell Y, and before or when performing the cell switching process to cell Y, may re-establish some or all of the RLC entities configured in the terminal device 100. Some or all of the RLC entities are, for example, RLC entities associated with the MCG.
[0235] Furthermore, the terminal device 100 may apply the setting of the cell change destination candidate to cell Y, and before or when performing the cell switching process to cell Y, perform PDCP recovery in some or all PDCP entities configured in the terminal device 100. The some or all PDCP entities are, for example, PDCP entities of AM DRB.
[0236] The terminal device 100 may apply the processing of step S1401 even after a normal handover failure or a conditional handover failure. For example, when applying the processing of step S1401 after a normal handover failure or a conditional handover failure, the processing is performed if the normal handover or the conditional handover before the failure did not involve a security key update. In other words, if the normal handover or the conditional handover before the failure involved a security key update, the processing of step S1401 is not applied, and all settings including the state variables are restored to the settings used in the source PCell.
[0237] Furthermore, after a normal handover failure or a conditional handover failure, the terminal device 100 may not apply the processing of step S1401 and may return all settings, including state variables, to the settings used in the source PCell, regardless of whether the normal handover or conditional handover before the failure involved a security key update. Furthermore, in the case of an RRC connection re-establishment procedure after a normal handover failure or a conditional handover failure, if the cell selected by the terminal device 100 is an NR cell, this NR cell is a cell that satisfies the second condition, and the first parameter is set in the terminal device 100, if the handover before the failure was a handover involving a security key update, the terminal device 100 may perform cell switching to the selected cell, and if the handover before the failure was a handover without a security key update, the terminal device 100 may transmit an RRC re-establishment request message to the base station device 200 in the selected NR cell.
[0238] Note that a normal handover is, for example, a PCell switch that is initiated when the terminal device 100 receives an RRC reconfiguration message including reconfiguration parameters with synchronization from the base station device 200.
[0239] Furthermore, in the RRC connection re-establishment procedure, if the selected cell is an NR cell and meets some or all of the following conditions H to J, the terminal device 100 transmits an RRC re-establishment request message to the base station device 200 in the selected cell. At this time, the terminal device 100 releases the stored configuration of the cell change destination candidate, for example, before transmitting the RRC re-establishment request message to the base station device 200. Also, at this time, if the terminal device 100 retained the values of some or all of the state variables in each entity of the radio bearer set in the terminal device 100 in step S1401 before transmitting the RRC re-establishment request message to the base station device 200, for example, the terminal device 100 may restore the values of the retained state variables to the values used in the source PCell (the values at the time of receiving the cell switching signal in step S1002 of FIG. 11 or the values immediately before receiving the cell switching signal). Before transmitting this RRC re-establishment request message to the base station device 200, the process of restoring the value of the state variable held in step S1401 to the value used in the source is performed, for example, when the first parameter is set.
[0240] Condition H: The selected cell is not one of the cells that meets the second condition.
[0241] Condition I: The first parameter is not set.
[0242] Condition J: A procedure for re-establishing an RRC connection after a handover failure or a handover failure to a different RAT, in which the handover or handover to a different RAT before the failure is a handover or handover to a different RAT that does not involve a change of security key. Note that a handover failure may be rephrased as a cell switching failure.
[0243] In addition, in the RRC connection re-establishment procedure, if the selected cell is a cell of a RAT other than NR, or if cell selection cannot be made within a specified time, the terminal device 100 transitions to RRC idle mode.
[0244] <Cell Switching Failure Processing 4 to Avoid Keystream Reuse Problem> FIG. 15 is a diagram showing an example of a fourth cell switching failure processing method.
[0245] The terminal device 100 detects a failure in cell switching to cell X (S1102).
[0246] Next, the terminal device 100 performs a cell selection procedure (S1501). Before performing the cell selection procedure, the terminal device 100 may stop some or all of the timers that are running. Furthermore, the terminal device 100 may start a timer that limits the time during which the cell selection procedure is performed to a certain time.
[0247] Furthermore, when the third condition is satisfied, the terminal device 100 may perform the cell selection procedure using the setting of the terminal device 100 at the time of cell switching failure, without restoring the setting of the terminal device 100 to the setting used in the source PCell, when or before performing the cell selection procedure. Furthermore, when the third condition is not satisfied, the terminal device 100 may restore the setting of the terminal device 100 to the setting used in the source PCell.
[0248] Furthermore, the cell selection procedure may be performed as part of the RRC connection re-establishment procedure, or may be performed separately from the RRC connection re-establishment procedure.
[0249] Next, the terminal device 100 performs processing according to the selected cell (S1502).
[0250] 16 is a diagram showing an example of processing according to the selected cell in step S1502. The terminal device 100 starts processing according to the selected cell (S1601).
[0251] The terminal device 100 determines whether the selected cell is one of the cells that satisfies the second condition (S1602).
[0252] If the selected cell is one of the cells that satisfy the second condition (for example, cell Y) (step S1602: Yes), the terminal device 100 performs cell switching to this selected cell (cell Y) (S1603). The process of performing cell switching to the selected cell when the selected cell is one of the cells that satisfy the second condition is performed, for example, when a parameter indicating that LTM is to be performed is set in the terminal device 100, or when at least a first parameter is set in the terminal device 100, or when both of these conditions are met.
[0253] When performing cell switching to cell Y or before performing cell switching, the terminal device 100 may release some of the information it holds. The part of the information it holds may include, for example, information obtained by early TA measurement or early TA acquisition. The information obtained by early TA measurement or early TA acquisition may include, for example, information including TA information and the value of the TA timer for the TA.
[0254] When performing cell switching to cell Y or before performing cell switching, the terminal device 100 may generate a configuration of cell Y to be used in cell Y. That is, when storing a reference configuration, the terminal device 100 generates a configuration to be used in cell Y by applying the stored configuration of cell Y to the reference configuration. Furthermore, when not storing a reference configuration or when the stored configuration of the cell change destination candidate is a complete configuration, the terminal device 100 may generate a configuration to be used in cell Y by replacing the configuration to be used in the current cell with the stored configuration of cell Y, or by replacing the configuration to be used in the current cell, excluding the fixed configuration, with the stored configuration of cell Y. When generating a configuration to be used at the cell change destination, the terminal device 100 may not reset some or all of the values of state variables, timers, etc. used in each entity (SDAP entity, PDCP entity, RLC entity, MAC entity, etc.) to their initial states. That is, the terminal device 100 may retain some or all of the values of state variables, timers, etc. used in each entity. Furthermore, when generating a setting to be used at the cell switching destination, the terminal device 100 may not discard some or all of the buffers in each entity. That is, the terminal device 100 may hold some or all of the values of state variables, timers, etc. used in each entity. Furthermore, the terminal device 100 may hold some or all of the buffers in each entity.
[0255] Furthermore, when performing cell switching to cell Y or before performing the switching, the terminal device 100 may re-establish some or all of the RLC entities configured in the terminal device 100. Some or all of the RLC entities are, for example, RLC entities associated with the MCG.
[0256] Furthermore, when performing cell switching to cell Y or before performing the switching, the terminal device 100 may perform PDCP recovery in some or all of the PDCP entities configured in the terminal device 100. The some or all of the PDCP entities are, for example, PDCP entities of the AM DRB.
[0257] Furthermore, when performing cell switching to cell Y, the terminal device 100 may perform cell switching using four-step or two-step CFRA, four-step or two-step CBRA, or RACH-less. The terminal device 100 may determine which cell switching method to use (whether to use four-step or two-step CFRA, four-step or two-step CBRA, or RACH-less for cell switching) according to the configuration of cell Y. Furthermore, when performing cell switching to cell Y, the terminal device 100 may perform cell switching using RACH-less if a fourth condition is satisfied. The fourth condition includes, for example, a case where the terminal device 100 holds a valid TA for cell Y. A valid TA includes, for example, a case where the TA timer for the TA has not expired. Note that the fourth condition may also be described as a fourth condition related to cell switching.
[0258] The terminal device 100 transmits a notification indicating that the cell has been switched when switching to cell Y or after switching to cell Y (the process of step S1004 in FIG. 10 ). The notification indicating that the cell has been switched is, for example, an RRC reconfiguration completion message. The notification indicating that the cell has been switched may include information indicating that the RRC connection has been recovered after a cell switch failure. Furthermore, information regarding uplink resources for sending the notification indicating that the cell has been switched may be, for example, included in the RAR, dynamically assigned by the base station device 200 after the cell switch, or included in the configuration of cell Y.
[0259] Furthermore, in step S1602, the terminal device 100 determines whether the selected cell is one of the cells that satisfy the second condition. If the selected cell is not one of the cells that satisfy the second condition (S1602: No), the terminal device 100 restores the settings of the terminal device 100 to the settings used in the source PCell (step S1604). At this time, the terminal device 100 may also restore values of state variables, timers, and the like used in each entity to the values used in the source PCell. Note that whether at least a first parameter is set in the terminal device 100 may be added to the conditions of step S1602. In this case, for example, if the selected cell is not one of the cells that satisfy the second condition and / or if at least a first parameter is not set in the terminal device 100, the settings of the terminal device 100 are restored to the settings used in the source PCell.
[0260] Next, the terminal device 100 re-establishes the RRC connection or transitions to RRC idle mode (step S1605). For example, if the selected cell is an NR cell, the terminal device 100 re-establishes the RRC connection. If the selected cell is an NR cell, the terminal device 100 transmits an RRC re-establishment request message to the base station device 200 in the selected cell. At this time, before transmitting the RRC re-establishment request message to the base station device 200, the terminal device 100 releases, for example, the stored cell change destination candidate settings. Also, for example, if the selected cell is a cell of a RAT other than NR, or if cell selection cannot be performed within a specified time, the terminal device 100 transitions to RRC idle mode.
[0261] The processing of step S1605 is performed, for example, as part of the RRC connection re-establishment procedure. Note that if the cell selection procedure of step S1501 is performed separately from the RRC connection re-establishment procedure, the terminal device 100 does not need to perform the cell selection procedure in the RRC connection re-establishment procedure. Also, the terminal device 100 may reset the MAC and suspend some or all radio bearers before performing the processing of step S1605. The radio bearers to be suspended may not include at least SRB0. Also, the terminal device 100 may release some or all of the information it holds before performing the processing of step S1605. Also, the terminal device 100 may stop some or all of the timers that are running before performing the processing of step S1605.
[0262] As a result, the terminal device 100 and the base station device 200 can avoid the key stream reuse problem in the cell switching failure processing of the terminal device 100 and perform secure communication.
[0263] Furthermore, in the cell switching failure process, the selected cell being one of the cell switching destination candidates stored in the terminal device 100 includes, for example, the selected cell being one of the PC cells of the cell switching destination candidates stored in the terminal device 100. Furthermore, the selected cell being one of the cell switching destination candidates stored in the terminal device 100 includes, for example, the selected cell being one of the PC cells included in the setting of the cell switching destination candidates received in step S1001 of Fig. 11. In other words, in the cell switching failure process, even if the selected cell is one of the cells included in the cell switching destination candidates stored in the terminal device 100, if the selected cell is an SCell, there are cases in which the terminal device 100 does not regard the selected cell as one of the cell switching destination candidates stored.
[0264] Similarly, in the cell switching failure process, the selected cell being one of the cells that satisfy the second condition includes, for example, the selected cell being one of the PCells that satisfy the second condition.
[0265] Furthermore, a cell switch involving a security key update means, for example, that the configuration of a cell change destination candidate includes a parameter related to a master key update. Furthermore, a handover involving a security update means, for example, that an RRC reconfiguration message including a synchronization-attached reconfiguration parameter received or applied by the terminal device 100 includes a parameter related to a master key update. The parameter related to the master key update is, for example, a masterKeyUpdate parameter.
[0266] Furthermore, the terminal device 100 releases some or all of the LTM settings when, for example, cell switching or handover involving security key update is successful.
[0267] Note that, although the present embodiment has been described in terms of a case where cell change destination candidates in LTM are set and / or stored in the terminal device 100, it may be applied to other technologies, for example, a case where PCell change destination candidates for conditional handover are set and / or stored. Furthermore, the present embodiment may be applied to processing after a handover (synchronized reconfiguration) failure in, for example, an NTN (Non Terrestrial Network) or the like.
[0268] Although four cell switching failure processes have been disclosed in this embodiment, the cell switching failure process method to be applied may be selected depending on whether the process is a process after a cell switching failure due to LTM or a process after a normal handover (including conditional handover) failure. For example, in the case of a process after a cell switching failure due to LTM, cell switching failure 4 is applied, and in the case of a process after a handover (synchronized reconfiguration) failure, cell switching failure 1, cell switching failure 2, or cell failure process 3 is applied.
[0269] <Others> Some of the messages in the above-described sequence may not be executed in the correct order, or the order may be changed. Also, some of the messages in the sequence may not be executed at all.
[0270] Furthermore, what is described as a function or process of the terminal device 100 may be a function or process of the base station device 200. Furthermore, what is described as a function or process of the base station device 200 may be a function or process of the terminal device 100.
[0271] Furthermore, when the term "radio bearer" is used without distinguishing between a signaling radio bearer and a data radio bearer, the radio bearer may be a signaling radio bearer, a data radio bearer, or both a signaling radio bearer and a data radio bearer.
[0272] Furthermore, "A may be replaced with B" and "A may be replaced with B" include the meaning of replacing B with A in addition to replacing A with B.
[0273] Furthermore, if condition "A" and condition "B" are contradictory conditions, condition "B" may be expressed as an "other" condition of condition "A."
[0274] To summarize, the following is the case.
[0275] (1) A terminal device including: a receiving unit that receives an RRC (Radio Resource Control) reconfiguration message including a reconfiguration with synchronization from a base station device; and a processing unit that executes a handover in accordance with the RRC reconfiguration message, wherein the processing unit controls to execute a first process when a failure of the handover is detected; the first process is a process that controls to perform an LTM cell switch in accordance with a first configuration including one or more cell change destination candidates if a security key update has been performed at the time of the handover; and controls to request the base station device to re-establish an RRC connection if a security key update has not been performed at the time of the handover.
[0276] (2) The terminal device described in (1), wherein the processing unit performs processing to re-establish some or all RLC entities when LTM cell switching to a first cell according to the first setting fails and before LTM cell switching to a second cell that satisfies a first condition regarding cell switching.
[0277] (3) The terminal device according to (2), wherein the first condition is that the second cell is one of the one or more cell change destination candidates.
[0278] (4) The receiving unit receives a signal including information on one or more cell change destination candidates, and the processing unit performs the first setting in accordance with the signal. A terminal device described in any one of (1) to (3).
[0279] (5) A terminal device described in any of (1) to (4), wherein the processing unit performs cell selection when it detects a failure of the handover, and performs the first processing when the selected cell satisfies a second condition regarding cell selection and the cell has a first parameter set.
[0280] (6) The terminal device according to (5), wherein the second condition is that the selected cell is a cell in which recovery of the RRC connection is permitted, and the first parameter is a parameter related to recovery of the RRC connection.
[0281] (7) A base station apparatus according to (7), further comprising: a transmitting unit that transmits an RRC reconfiguration message including a synchronization-attached reconfiguration to a terminal device; and a processing unit that causes the terminal device to execute a handover by transmitting the RRC reconfiguration message to the terminal device, wherein the processing unit controls the terminal device to execute a first process when the terminal device detects a failure of the handover, the first process being a process of controlling the terminal device to perform an LTM cell switch in accordance with a first configuration including one or more cell change destination candidates if a security key update has been performed at the time of the handover, and controlling the terminal device to request re-establishment of an RRC connection if a security key update has not been performed at the time of the handover. (9) A wireless communication system including: a base station device that transmits an RRC (Radio Resource Control) reconfiguration message including a reconfiguration with synchronization; and a terminal device that receives the RRC reconfiguration message and executes a handover in accordance with the RRC reconfiguration message, wherein the terminal device controls to execute a first process when it detects a failure of the handover, and the first process is a process of controlling to perform an LTM cell switch in accordance with a first setting including one or more cell change destination candidates if a security key update has been performed at the time of the handover, and controlling to request the base station device to re-establish an RRC connection if a security key update has not been performed at the time of the handover.
[0282] Although an example of a device has been described in each embodiment, the method of the present disclosure is not limited to cellular phones, smartphones, tablet terminals, base station devices, etc., but can also be applied to other electronic devices, such as electronic devices mounted on automobiles, trains, airplanes, artificial satellites, electronic devices mounted on drones, robots, AV equipment, home appliances, office equipment, vending machines, other household equipment, industrial equipment, and other devices.
[0283] In addition, in each embodiment, E-UTRA and NR are used as radio access technologies, and EPC and 5GC are used as core networks. However, the application of the method of the present disclosure is not limited to these. For example, the method of the present disclosure may be applied to radio access technologies and networks of different generations, such as 6th generation and 7th generation.
[0284] Furthermore, the present invention is not limited to the above-described embodiment, and various modifications can be made.
[0285] Although each embodiment has been described in detail with reference to the drawings, the specific configuration is not limited to the disclosed drawings and the described embodiments.
[0286] 10: Communication system 100: Terminal device 110: CPU 120: Storage 121: Wireless communication program 122: Terminal side program 130: Memory 140: Wireless communication circuit 200: Base station device 210: CPU 220: Storage 221: Wireless communication program 222: Base station side program 230: Memory 240: Wireless communication circuit 250: Network interface 300: Core network
Claims
1. A terminal device comprising: a receiving unit that receives an RRC (Radio Resource Control) reconfiguration message including synchronized reconfiguration from a base station device; and a processing unit that performs a handover in response to the RRC reconfiguration message, wherein the processing unit is controlled to execute a first process when detecting a failure of the handover, and the first process is to control to perform an LTM cell switch according to a first setting including one or more cell change destination candidates when a security key update is performed during the handover, and when a security key update is not performed during the handover, it is a process of controlling to request re-establishment of an RRC connection to the base station device.
2. The processing unit performs a process to re-establish some or all RLC entities before performing an LTM cell switch to a second cell that fails to perform an LTM cell switch to a first cell according to the first setting and satisfies a first condition related to the cell switch, for the terminal device according to claim 1.
3. The first condition is that the second cell is any one of the one or more cell change destination candidates, for the terminal device according to claim 2.
4. The receiving unit receives a signal including information on one or more cell change destination candidates, and the processing unit performs the first setting according to the signal, for the terminal device according to claim 1.
5. The processing unit executes cell selection when detecting a failure of the handover, and performs the first process when the selected cell satisfies a second condition related to cell selection and the cell has a first parameter set, for the terminal device according to claim 1.
6. The second condition is that the selected cell is a cell in which recovery of an RRC connection is permitted, and the first parameter is a parameter related to recovery of the RRC connection, for the terminal device according to claim 5.
7. A base station device comprising: a transmission unit that transmits an RRC (Radio Resource Control) reconfiguration message including synchronized reconfiguration to a terminal device; and a processing unit that causes the terminal device to perform a handover by transmitting the RRC reconfiguration message to the terminal device, wherein the processing unit controls the terminal device to perform a first process when the terminal device detects a handover failure, and the first process is a process of controlling the terminal device to perform an LTM cell switch according to a first setting including one or more cell change destination candidates when security key update is performed during the handover, and a process of controlling the terminal device to request re-establishment of an RRC connection when security key update is not performed during the handover.
8. The base station device according to claim 7, further comprising a reception unit that receives a signal requesting re-establishment of the RRC connection when the terminal device is controlled to request re-establishment of the RRC connection.
9. A wireless communication system comprising: a base station device that transmits an RRC (Radio Resource Control) reconfiguration message including synchronized reconfiguration; and a terminal device that receives the RRC reconfiguration message and performs a handover according to the RRC reconfiguration message, wherein the terminal device controls to perform a first process when the terminal device detects a handover failure, and the first process is a process of controlling to perform an LTM cell switch according to a first setting including one or more cell change destination candidates when security key update is performed during the handover, and a process of controlling to request the base station device to re-establish an RRC connection when security key update is not performed during the handover.