Key derivation for inter central unit (CU) mobility using lower layers
By determining the appropriate key derivation method within the LTM Cell Switch Command MAC CE, the solution addresses the challenge of secure key changes during inter-CU mobility in wireless communication systems, reducing latency and maintaining security.
Patent Information
- Application Number
- PCT/IB2025/052854
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-23
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-26
AI Technical Summary
Existing wireless communication systems face challenges in efficiently managing security key changes during inter-Central Unit (CU) mobility, particularly when using Layer 1/Layer 2 (L1/L2) mobility commands, as these commands are not integrity protected or ciphered, potentially exposing security information.
The proposed solution involves determining whether to perform no key derivation, horizontal key derivation, or vertical key derivation based on information carried in the LTM Cell Switch Command MAC CE using reserved bits, ensuring secure key changes during inter-CU mobility.
This approach reduces latency and overhead in UE cell changes while maintaining the security of security-sensitive information, enhancing the efficiency of inter-CU mobility procedures.
Smart Images

Figure IB2025052854_26062025_PF_FP_ABST
Abstract
Description
KEY DERIVATION FOR INTER CENTRAL UNIT (CU) MOBILITY USING LOWER LAYERSRELATED APPLICATION
[0001] This application claims priority to U.S. Provisional Application Serial No. 63 / 637,844, filed 23 April 2024, entitled “KEY DERIVATION FOR INTER CENTRAL UNIT (CU) MOBILITY USING LOWER LAYERS,” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to wireless communications, and more specifically to user equipment (UE) cell mobility.BACKGROUND
[0003] A wireless communications system may include one or multiple network communication devices, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as UE, or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY
[0004] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims,“or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (e.g., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on”. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0005] A UE for wireless communication is described. The UE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the UE may be configured to, capable of, or operable to receive in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; receive layer 1 / layer 2 triggered mobility (LTM) medium access control (MAC) control element (CE) for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiate handover execution; determine whether to derive one or more security keys based on the received first information; determine, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more new security keys using second information; and transmit handover complete to the target cell applying the derived one or more new security keys.
[0006] A processor (e.g., a standalone processor chipset, or a component of a UE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; receive LTM MAC CE for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiate handover execution; determine whether to derive one or more security keys based on thereceived first information; determine, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more new security keys using second information; and transmit handover complete to the target cell applying the derived one or more new security keys.
[0007] A method performed or performable by a UE for wireless communication is described. The method may include receiving in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; receiving LTM MAC CE for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiating handover execution; determining whether to derive one or more security keys based on the received first information; determining, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more new security keys using second information; and transmitting handover complete to the target cell applying the derived one or more new security keys.
[0008] In some implementations of the UE, the processor, and the method described herein, the first message including candidate cell configuration includes a layer 3 radio resource control (RRC) Reconfiguration message from the serving cell.
[0009] In some implementations of the UE, the processor, and the method described herein, the LTM includes a lower layer mobility command message.
[0010] In some implementations of the UE, the processor, and the method described herein, the LTM includes identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information.
[0011] In some implementations of the UE, the processor, and the method described herein, the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed.
[0012] In some implementations of the UE, the processor, and the method described herein, the second information is included using 3 reserved bits in the MAC CE and indicates a next hop chaining counter (NCC) value.
[0013] In some implementations of the UE, the processor, and the method described herein, the UE radio network identity includes cell radio network temporary identifier (C-RNTI).
[0014] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to transmit a first message including candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmit LTM MAC CE including a target cell including a first and a second information.
[0015] A processor (e.g., a standalone processor chipset, or a component of a NE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to transmit a first message including candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmit LTM MAC CE including a target cell including a first and a second information.
[0016] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include transmitting a first message including candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmitting LTM MAC CE including a target cell including a first and a second information.
[0017] In some implementations of the NE, the processor, and the method described herein, the first message including candidate cell configuration includes a layer 3 RRC Reconfiguration message.
[0018] In some implementations of the NE, the processor, and the method described herein, the LTM includes a lower layer mobility command message.
[0019] In some implementations of the NE, the processor, and the method described herein, the LTM includes identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information.
[0020] In some implementations of the NE, the processor, and the method described herein, the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed.
[0021] In some implementations of the NE, the processor, and the method described herein, the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value.
[0022] In some implementations of the NE, the processor, and the method described herein, the UE radio network identity includes C-RNTI.BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0024] Figure 2 illustrates an example procedure for LTM.
[0025] Figure 3 illustrates an example system for UE mobility in accordance with aspects of the present disclosure.
[0026] Figure 4 illustrates a system for handover key chaining.
[0027] Figure 5 illustrates an example master key update information element (IE) in accordance with aspects of the present disclosure.
[0028] Figure 6 illustrates a scenario in accordance with aspects of the present disclosure.
[0029] Figure 7 illustrates an example LTM cell switch command MAC CE in accordance with aspects of the present disclosure.
[0030] Figure 8 illustrates an example LTM cell switch command MAC CE in accordance with aspects of the present disclosure.
[0031] Figure 9 illustrates an example LTM cell switch command MAC CE in accordance with aspects of the present disclosure.
[0032] Figure 10 illustrates an example of a UE in accordance with aspects of the present disclosure.
[0033] Figure 11 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0034] Figure 12 illustrates an example of a NE in accordance with aspects of the present disclosure.
[0035] Figure 13 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
[0036] Figure 14 illustrates a flowchart of a method in accordance with aspects of the present disclosure.DETAIEED DESCRIPTION
[0037] In a wireless communications system, a UE and a network equipment (NE) (e.g., a base station) may support wireless communication (e.g., reception and / or transmission of wireless communication). Further, a UE may move between different NE (e.g., different cells) in mobility scenarios. When the UE moves from the coverage area of one cell to another cell, at some point a serving cell change is to be performed since a current serving cell does not remain a radio viable option. In some wireless communications systems, serving cell change is triggered by L3 measurements and is done by RRC signalling triggered reconfiguration with synchronization for change of primary cell (PCell) and primary secondary cell (PSCell), as well as release add for secondary cells (Scells) when applicable. Such cases may involve complete LI and L2 resets, which can lead to longer latency, larger overhead, and longer interruption time than beam switch mobility. A goal of L1 / L2 mobility enhancements is to enable a serving cell change via L1 / L2 signalling in order to reduce the latency, overhead and interruption time. Such mobility can be achieved using a LTM procedure utilizing a cell switch command which is conveyed in a MAC CE, which can involve a cell switch command conveyed in a MAC CE which includes information to perform the LTM cell switch. Such cell switching scenarios can involve a source CU to target CU change which can involve a change of packet data convergence protocol (PDCP) location and the PDCP location change involves a change in security parameter. Thus an issue is how the security changes are to beperformed using a MAC CE (e.g., LTM) which itself is not protected (neither integrity protected nor ciphered), thus potentially exposing the security related information in the open.
[0038] LTM can offer improvements in handover latency and interruption time compared to Layer 3 based mobility. However, LTM can have a number of limitations compared to Layer 3 mobility. A source CU to target CU change may also cause a change of PDCP location, and PDCP location change may involve a change in security parameter. Another issue in such scenarios is which type of key change / key derivation is to be applied. In some scenarios, the key change may not be performed and when the key is to be changed, the key derivation itself can be based on horizontal key derivation procedure or on vertical key derivation procedure.
[0039] Accordingly, aspects of the present disclosure provide for utilizing an LTM MAC CE for a UE to determine if no key derivation is applied, or a horizontal key derivation or a vertical key derivation is to be applied. In implementations, the information on type A, B, or C mobility is carried in the LTM Cell Switch Command MAC CE by using reserved bits. In one variation, the first ‘R’ bit in the second row can be used to indicate if the next 3 ‘R’ bits in the same row carry a NCC value or not. A UE receiving the MAC CE can behave as follows: If the first ‘R’ bit in the second row is set to ‘O’, there is no key change to be performed.
[0040] By utilizing the described techniques, latency and overhead for a UE to change serving cells can be reduced while maintaining security of security-sensitive information as part of cell change procedures.
[0041] Aspects of the present disclosure are described in the context of a wireless communications system.
[0042] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NE 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be acombination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
[0043] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a nextgeneration NodeB (NE), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0044] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
[0045] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of- Everything (loE) device, or machine-type communication (MTC) device, among other examples.
[0046] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0047] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N6, or other network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other indirectly (e.g., via the CN 106). In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).
[0048] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
[0049] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N6, or other network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information,data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).
[0050] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (e.g., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0051] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0052] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0053] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (e.g., / r=0, jU=l, / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0054] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0055] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing.FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.
[0056] Figure 2 illustrates an example procedure 200 for LTM. The procedure 200, for instance, includes communication between a NE 102 and a UE 104. Subsequent LTM can be performed by repeating the early synchronization, LTM execution, and LTM completion steps without releasing other LTM candidate cell configurations after each LTM completion.
[0057] In the procedure 200 for LTM: 1. The UE 104 sends a MeasurementReport message to the NE. The NE decides to configure LTM and initiates candidate cell(s) preparation. 2. The NE transmits an RRCReconfiguration message to the UE including the LTM candidate cell configurations of one or multiple candidate cells. 3. The UE stores the LTM candidate cell configurations and transmits an RRCReconfigurationComplete message to the NE.
[0058] In the procedure 200: 4a. The UE may perform downlink (DL) synchronization with candidate cell(s) before receiving the cell switch command. 4b. The UE may perform early timing advance (TA) acquisition with candidate cell(s) requested by the network before receiving the cell switch command. This can be done via contention free random access channel (RACH) access (CFRA) triggered by a physical DL control channel (PDCCH) order from the source cell, following which the UE sends preamble towards the indicated candidate cell. In order to minimize the data interruption of the source cell due to CFRA towards the candidate cell(s), the UE may not receive random access response (RAR) for the purpose of TA value acquisition and the TA value of the candidate cell is indicated in the cell switch command. The UE may not maintain the TA timer for the candidate cell and relies on network implementation to guarantee the TA validity.
[0059] In the procedure 200: 5. The UE performs LI measurements on the configured candidate cell(s) and transmits lower-layer measurement reports to the NE. LI measurement can be performed with the RRC reconfiguration in step 2. 6. The NE may determine to execute a cell switch to a target cell and transmit a MAC CE triggering cell switch (LTM) by including the candidate configuration index of the target cell. The UE switches to the target cell and applies theconfiguration indicated by candidate configuration index. 7. The UE performs the random access procedure towards the target cell, e.g., if the UE does not have valid TA of the target cell.
[0060] In the procedure 200: 8. The UE completes the LTM cell switch procedure e.g., by sending RRCReconfigurationComplete message to target cell. If the UE has performed a random access (RA) procedure in step 7, the UE determines that LTM execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM, the UE determines that LTM execution is successfully completed when the UE determines that the network has successfully received its first uplink (UL) data. The UE determines successful reception of its first UL data by receiving a PDCCH addressing the UE’s C-RNTI in the target cell, which schedules a new transmission following the first UL data. R2 can determine that an RRCReconfigurationComplete message is sent at each LTM execution. The steps 4-8 can be performed multiple times for subsequent LTM cell switch using the LTM candidate cell configuration(s) provided in step 2.
[0061] Figure 3 illustrates an example system 300 for UE mobility in accordance with aspects of the present disclosure. The system 300, for instance, illustrates intra-CU mobility 302 and inter- CU mobility 304. The intra-CU mobility 302 may not involve a security key change since the distributed unit (DU)-a and DU-b are served in a same CU-1. In the inter-CU mobility 304, however, a security key change may be involved since DU-c and DU-b are served in a different CU-2. In some wireless communications systems, LTM MAC CE based mobility does not implement a security key change as both the target and source DU (e.g., a base station / cell) are under the same CU (Central Unit).
[0062] In some wireless communications systems, this can be extended to Inter-CU cases including LTM can offer improvements in handover latency and interruption time compared to Layer 3 based mobility. However, LTM may also have a number of limitations compared to Layer 3 mobility. LTM operation may be supported for mobility between cells of the same NE (same CU). This may significantly limit the opportunities to use LTM. By enabling LTM operation between cells of different NEs (e.g., inter-CU), the network may gain the benefits of LTM for more handovers. The source CU to target CU change may also result in a change of PDCP location. The PDCP location change may involve a change in security parameter.
[0063] Thus one issue is how the security changes are to be implemented using a MAC CE (LTM) which itself may not be protected (neither integrity protected nor ciphered), thus potentially exposing the security related information in the open. The issue is further augmented in view of which type of key change / key derivation is to be applied. In some scenarios, the key may not be changed and when the key is to be changed, and the key derivation itself can be based on horizontal key derivation procedure or on vertical key derivation procedure.
[0064] Figure 4 illustrates a system 400 for handover key chaining. The system 400, for instance, is implemented in the access stratum (AS) for key handling for KNG RAN* / NH at handovers.
[0065] The following is an outline of the key handling model to clarify the intended structure of the key derivations. When an initial AS security context is to be established between a UE and NE / ng-eNB, an AMF and the UE can derive a KgNB and a Next Hop (NH) parameter. The KgNB and the NH are derived from the KAMF. A NH Chaining Counter (NCC) is associated with each KgNB and NH parameter. Each KgNB is associated with the NCC corresponding to the NH value from which it was derived. At initial setup, the KgNB is derived from KAMF, and is then considered to be associated with a virtual NH parameter with NCC value equal to zero. At initial setup, the derived NH value is associated with the NCC value one. At the UE, the NH derivation associated with NCC=1 can be delayed until the first handover performing vertical key derivation. In N2 handover, when the KgNB is updated either due to KAMF change or synchronising the AS security context with the NAS security context, the KgNB can be derived. In inter-RAT handover, the KgNB is derived as specified in clause 8.4 of the present document. In UE context modification, the KgNB is derived.
[0066] Whether the AMF sends the KgNB key or the { NH, NCC } pair to the serving NE / ng-eNB can be specified. The AMF may not send the NH value to NE / ng-eNB at the initial connection setup. The NE / ng-eNB can initialize the NCC value to zero after receiving Next Generation Application Protocol (NGAP) Initial Context Setup Request message. Since the AMF may not send the NH value to NE / ng-eNB at the initial connection setup, the NH value associated with the NCC value one may not be used in the next Xn handover or the next intra-NE / intra-ng-eNB-CU handover, for the next Xn handover or the next intra-NE-CU / intra-ng-eNB handover the horizontal key derivation may apply. One parameter specified for the AMF states that the AMF can compute afresh {NH, NCC} pair that is given to the target NE / ng-eNB. An implication of this is that the first {NH, NCC} pair may not be used to derive a KgNB, and serves as an initial value for the NH chain.
[0067] The UE and the NE / ng-eNB may use the KgNB to secure the communication between each other. On handovers and at transitions from RRC_INACTIVE to RRC_CONNECTED states, the basis for the KgNB that may be used between the UE and the target NE / ng-eNB, called KNG RAN*, is derived from either the currently active KgNB or from the NH parameter. If KNG RAN* is derived from the currently active KgNB this is referred to as a horizontal key derivation and if the KNG RAN* is derived from the NH parameter the derivation is referred to as a vertical key derivation. As NH parameters may be computable by the UE and the AMF, it is arranged so that NH parameters are provided to NE / ng-eNB s from the AMF in such a way that forward security can be achieved.
[0068] On handovers with vertical key derivation, the NH can be bound to the target physical cell identity (PCI) and its frequency absolute radio frequency channel number (ARFCN)-DL before it is taken into use as the KgNB in the target NE / ng-eNB. On handovers with horizontal key derivation, the currently active KgNB can be bound to the target PCI and its frequency ARFCN-DL before it is taken into use as the KgNB in the target NE / ng-eNB.
[0069] The following discusses key derivations during handover. For intra-NE-CU handover and intra-ng-eNB handover the NE can have a policy deciding at which intra-NE -CU handovers the KgNB can be retained and at which a new KgNB is to be derived. At an intra-NE-CU handover, the NE can indicate to the UE whether to change or retain the current KgNB in the handover (HO) Command message. Retaining the current KgNB can be done during intra-NE-CU handover.
[0070] If the current KgNB is to be changed, the NE / ng-eNB and the UE can derive a KNG RAN* using target PCI, its frequency ARFCN-DL / evolved absolute radio frequency channel number (EARFCN)-DL, and either NH or the current KgNB based on the following criteria: the NE can use the NH for deriving KNG RAN* if an unused {NH, NCC} pair is available in the NE (this is referred to as a vertical key derivation), otherwise if no unused {NH, NCC} pair is available in the NE, the NE can derive KNG RAN* from the current KgNB (this is referred to as a horizontal key derivation). The NE can send the NCC used for the KNG-RAN*derivation to UE in HO Command message. The NE / ng-eNB and the UE can use the KNG RAN* as the KgNB, after handover.
[0071] If the current KgNB is to be retained, the NE and the UE can continue using the current KgNB, after handover. This is also applicable when a NE is implemented as a single unit, e.g., when the NE is not split into CU and DU. The described key derivation mechanism can also be applicable to conditional handover (CHO) defined in the 3GPP technical specification (TS) 38.300.
[0072] In Xn handovers, the source NE / ng-eNB can perform a vertical key derivation if it has an unused { NH, NCC } pair. The source NE / ng-eNB can first compute KNG RAN* from target PCI, its frequency ARFCN-DL / EARFCN-DL, and either from currently active KgNB in case of horizontal key derivation or from the NH in case of vertical key derivation.
[0073] Next, the source NE / ng-eNB can forward the { KNG.RAN*, NCC} pair to the target NE / ng-eNB. The target NE / ng-eNB can use the received KNG RAN* directly as KgNB to be used with the UE. The target NE / ng-eNB can associate the NCC value received from source NE / ng-eNB with the KgNB. The target NE / ng-eNB can include the received NCC into the prepared HO Command message, which is sent back to the source NE / ng-eNB in a transparent container and forwarded to the UE by source NE / ng-eNB.
[0074] When the target NE / ng-eNB has completed the handover signaling with the UE, it can send a NGAP PATH SWITCH REQUEST message to the AMF. Upon reception of the NGAP PATH SWITCH REQUEST, the AMF can increase its locally kept NCC value by one and compute a new fresh NH from its stored data using the function. The AMF can use the KAMF from the currently active 5G NAS security context for the computation of the new fresh NH. The AMF can then send the newly computed {NH, NCC} pair to the target NE / ng-eNB in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The target NE / ng-eNB can store the received {NH, NCC} pair for further handovers and remove other existing unused stored {NH, NCC} pairs, if any.
[0075] If the AMF has activated a new 5G NAS security context with a new KAMF, different from the 5G NAS security context on which the currently active 5G AS security context is based, but has not yet successfully performed a UE Context Modification procedure, the sent NGAP PATH SWITCH REQUEST ACKNOWLEDGE message can in addition include a New Security Context Indicator (NSCI). The AMF can in this case can derive a new initial KgNB from the new KAMF and the UL NAS COUNT in the most recent NAS Security Mode Complete message. TheAMF can associate the derived new initial KgNB with a new NCC value equal to zero. Then, the AMF can use the derived new initial KgNB, the new NCC value initialized to zero pair as the newly computed {NH, NCC} pair to be sent in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The NE / ng-eNB can in this case set the value of keySetChangelndicator field to true in further handovers. The NE / ng-eNB can in this case perform an intra-NE-CU / intra-ng-eNB handover.
[0076] Because the NGAP PATH SWITCH REQUEST message is transmitted after the radio link handover, it can be used to provide keying material for the next handover procedure. Thus, for Xn-handovers, key separation can occur after two hops because the source NE / ng-eNB knows the target NE / ng-eNB keys. The target NE / ng-eNB can initiate an intra-NE-CU / intra-ng-eNB handover to take the new NH into use once the new NH has arrived in the PATH SWITCH REQUEST ACKNOWLEDGE message.
[0077] For N2-handover, upon reception of the NGAP HANDOVER REQUIRED message, if the source AMF does not change the active KAMF (meaning no horizontal KAMF derivation) and if AS key re -keying is not to be performed, the source AMF can increment its locally kept NCC value by one and compute a fresh NH from its stored data. The source AMF can use the KAMF from the currently active 5GS NAS security context for the computation of the fresh NH. The source AMF can send the fresh {NH, NCC} pair to the target AMF in the Namf_Communication_CreateUEContext Request message. The Namf_Communication_CreateUEContext Request message can in addition include the KAMF that was used to compute the fresh {NH, NCC} pair and its corresponding Next Generation Key Set Identifier (ngKSI) and corresponding UL and DL NAS COUNTs.
[0078] If the source AMF had activated a new 5G NAS security context with a new KAMF, different from the 5G NAS security context on which the currently active 5G AS security context is based, but has not yet performed a UE Context Modification procedure, the Namf_Communication_CreateUEContext Request message can in addition include an indication that the KAMF sent by source AMF to target AMF is not in sync with the current KgNB used between the UE and the source NE (e.g., keyAmfChangelnd) which can indicate that AS key re-keying is to be implemented at the UE. Further, the source AMF can derive a new KgNB associated with NCC=0 using the new KAMF and the UL NAS COUNT from the last successful NAS security modecommand (SMC) procedure with the UE and provide the {NH= newly derived KgNB, NCC=0} pair to the target AMF in the Namf_Communication_CreateUEContext Request message.
[0079] The source AMF uses its local policy to determine whether to perform horizontal KAMF derivation on currently active KAMF. If horizontal KAMF derivation is performed, the Namf_Communication_CreateUEContext Request can include an indication (e.g., keyAmfHDerivationlnd ) that the new KAMF has been calculated, an indication (e.g., keyAmfChangelnd) that AS key re -keying is to be implemented at the UE, and the DL NAS COUNT used in the horizontal derivation of the sent KAMF. The ngKSI for the newly derived KAMF key has the same value and the same type as the ngKSI of the current KAMF. Further, the source AMF can derive a new KgNB associated with NCC=0 using the newly derived KAMF and the UE NAS COUNT value of 232-l. The source AMF can include the {NH=newly derived KgNB, NCC=0} pair and the ngKSI for the newly derived KAMF key in the Namf_Communication_CreateUEContext Request as well. The UE NAS COUNT value for the initial KgNB derivation is set to 232- 1.
[0080] The source AMF can increment the DE NAS COUNT by one after sending the Namf_Communication_CreateUEContext Request message to the target AMF. Unlike the S10 FORWARD REEOCATION REQUEST message in Evolved Packet System (EPS), the Namf_Communication_CreateUEContext Request message in 5G may not include data and metadata related to old 5G security context.
[0081] If the target AMF receives the indication of horizontal KAMF derivation (e.g., keyAmfHDerivationlnd), it can derive the NAS keys from the received KAMF as specified in clause A.8 and set the NAS COUNTs to zero. The target AMF can create a non-access stratum container (NASC) (NAS Container) including the K_AMF_change_flag, the received DL NAS COUNT, ngKSI, selected NAS security algorithms, and NAS MAC. The K_AMF_change_flag is set to one when the target AMF receives keyAmfHDerivationlnd-. Otherwise, the K_AMF_change_flag is set to zero. If the target AMF does not receive keyAmfHDerivationlnd but wants to change the NAS algorithms, it can create a NASC using the selected NAS security algorithms in the same manner as the case for the horizontal KAMF derivation. However, the target AMF may not set the NAS COUNTs to zero.
[0082] The target AMF can calculate a 32-bit NAS MAC over the parameters included in theNASC using the KNASIM key. The input parameters to the NAS 128-bit integrity algorithms can be set as follows when calculating NAS MAC. The calculation of NAS MAC can be the 32-bit output of the selected NR Integrity Algorithm (NIA) and can use the following inputs:- KEY : set to the corresponding KNASint;- COUNT : set to 232-l;- MESSAGE : set to the content of NAS Container as defined in TS 24.501
[0035] ;- DIRECTION : set to 1 ; and- BEARER : set to the value of the NAS connection identifier for 3GPP access.
[0083] The use of the 232- 1 as the value of the COUNT for the purpose of NAS MAC calculation / verification may not be set the NAS COUNT to 232- 1. One reason for choosing such a value not in the normal NAS COUNT range, e.g., [0, 224- 1 ] is to avoid any possibility that the value may be reused for normal NAS messages.
[0084] Replay protection is achieved by the UE checking if the DL NAS COUNT included in the NAS Container is replayed or not. The UE may not accept the same DL NAS COUNT value twice before a newly derived KAMF is taken into use and the corresponding DL NAS COUNT is set to zero. The target AMF can increment the DL NAS COUNT by one after creating a NASC.
[0085] The NASC is included in the NGAP HANDOVER REQUEST message to the target ng- eNB / NE. The purpose of this NASC can be compared to a NAS SMC message. If the target AMF receives the keyAmfChangelnd, it can further send the received {NCC, NH] pair and the New Security Context Indicator (NSCI) to the target ng-eNB / NE within the NGAP HANDOVER REQUEST message. The target AMF can further set the NCC to one and can further compute a NH. The target AMF can further store the {NCC=1, NH] pair. The NAS Container (NASC) is defined as Intra N1 mode NAS transparent container in TS 24.501. The DL NAS COUNT can be included in the Namf_Communication_CreateUEContext Request and used by the target AMF for NAS MAC computation. This provides replay protection for NASC. If the target AMF does not receive the keyAmfChangelnd, it can store locally the KAMF and {NH, NCC] pair received from the source AMF and then send the received {NH, NCC] pair to the target ng-eNB / NE within the NGAP HANDOVER REQUEST message.
[0086] Upon receipt of the NGAP HANDOVER REQUEST message from the target AMF, the target ng-eNB / NE can compute the KNG RAN* to be used with the UE by performing key derivation with the {NH, NCC} pair received in the NGAP HANDOVER REQUEST message and the target PCI and its frequency ARFCN-DL / EARFCN-DL. The NE uses the KNG RAN* corresponding to the selected cell as KgNB. The ng-eNB uses the KNG RAN* corresponding to the selected cell as K6NB. The target ng-eNB / NE can associate the NCC value received from AMF with the KgNB / KeNB. The target ng-eNB / NE can include the NCC value from the received {NH, NCC} pair, and the NASC if such was also received, into the HO Command message to the UE and remove existing unused stored {NH, NCC} pairs. If the target ng-eNB / NE received the NSCI, it can set the keySetChangelndicator field in the HO Command message to true. The source AMF may be the same as the target AMF. If so, the single AMF performs the roles of both the source and target AMF. In this case, actions related to N14 messages are handled internally in the single AMF.
[0087] The UE behavior can be the same regardless of whether the handover is intra-NE-CU, intra ng-eNB, Xn, or N2, with the exception that during intra-NE-CU handover, the UE may retain the same key based on an indication from the NE. The UE behavior is also same in case of conditional handover, as specified in TS 38.300, e.g., the UE can use the parameters of the selected target cell in KNG RAN* derivations.
[0088] If the UE also receives a NASC (NAS Container) in the HO Command message, the UE can update its NAS security context as follows:- The UE can verify the freshness of the DL NAS COUNT in the NASC.• If the NASC indicates a new KAMF has been calculated (e.g., K_AMF_change_flag is one),- The UE can compute the horizontally derived KAMF using the KAMF from the current 5G NAS security context identified by the ngKSI included in the NASC and the DL NAS COUNT in the NASC.- The UE can assign the ngKSI included in the NASC to the ngKSI of the new derived KAMF- The UE can further configure NAS security based on the horizontally derived KAMF and the selected NAS security algorithms in the NASC.- The UE can further verify the NAS MAC in the NASC, and if the verification is successful, the UE can further set the NAS COUNTs to zero.• If KAMF change is not indicated,- If the verification is successful, the UE can configure the NAS security based on the parameters included in the NASC but may not set the NAS COUNTs to zero.- The UE can verify the NAS MAC in the NASC.- The UE can further set the DL NAS COUNT value of the currently active NAS security context to the received DL NAS COUNT value in the NASC.
[0089] If verification of the NASC fails, the UE can abort the handover procedure. Furthermore, the UE can discard the new NAS security context if it was derived and continue to use the existing NAS and AS security contexts.
[0090] If keySetChangelndicator in the HO command is true• If the HO Command message included a NASC parameter with the K_AMF_change_flag set to one:- The UE can use the horizontally derived KAMF and the NAS COUNT value of 232- 1 in the derivation of the temporary KgNB. The UE can further process this temporary key as described in subclause 6.9.4.4.- Else:- The UE handling related to key derivation can be done as defined in clause 6.9.4.4.Else- If the NCC value the UE received in the HO Command message from target ng-eNB / NE via source ng-eNB / NE is equal to the NCC value associated with the currently active KgNB / KeNB, the UE can derive the KNG RAN* from the currently active KgNB / KeNB and the target PCI and its frequency ARFCN-DL / EARFCN-DL.- If the UE received an NCC value that was different from the NCC associated with the currently active KgNB / KeNB, the UE can first synchronize the locally kept NH parameter bycomputing a function iteratively and increasing the NCC value until it matches the NCC value received from the source ng-eNB / NE via the HO command message. When the NCC values match, the UE can compute the KNG RAN* from the synchronized NH parameter and the target PCI and its frequency ARFCN-DL / EARFCN-DL.
[0091] The UE can use the KNG RAN* as the KgNB when communicating with the target NE and as the KeNB when communicating with the target ng-eNB.
[0092] Accordingly, solutions described in the present disclosure provide for determination of whether no key derivation is to be applied or a horizontal key derivation or vertical key derivation is to be applied using RRC or MAC CE. Further, a keySetChangelndicator or security algorithm change can be implemented using layer 3 handover.
[0093] Figure 5 illustrates an example master key update IE 500 in accordance with aspects of the present disclosure. In implementations, a NE includes the Master key Update IE in the LTM MAC CE for Inter-CU PCell change involving KgNB change. Upon receiving this, a UE can compute the new AS keys (KgNB, KRRCint, KRRCenc, Kupint and Kupenc). Prior to this, a security configuration (securityConfig) can be sent to the UE using RRC signaling indicating security algorithm to be used in a corresponding candidate cell and also informing the UE for a bearer if a master or secondary key is to be used. After deriving the new keys, the UE can configure the PDCP entity with the security algorithms according to securityConfig and apply the keys (KRRCenc and KRRCint) associated with the master key (KgNB).
[0094] In implementations, a NE includes sk-Counter in the LTM MAC CE for Inter-CU PSCell change involving S-KgNB change. Upon receiving this, a UE can derive or update the secondary key (S-K§NB) based on the KgNB key and using the received or selected sk-Counter value. The UE can then derive the KRRCenc key and the Kupenc key using the ciphering algorithms indicated in the Radio Bearer Config associated with the secondary key (S-K§NB) as indicated by keyToUse. The UE can derive the KRRCint key and the Kupint key using the integrity protection algorithms indicated in the Radio Bearer Config associated with the secondary key (S-K§NB) as indicated by keyToUse received earlier in a prior RRC message.
[0095] In implementations, part of the Master Kex Update can be sent to the UE apriori in a protected RRC message e.g., before transmitting LTM MAC CE. As an example, the nas-Containerand Key Set Indicator can be included in the by the NE in an RRCReconfiguration message to the UE including the corresponding LTM candidate cell configurations of one or multiple candidate cells. The NCC (Next Hop Chaining Count) can be included in the LTM. In at least one example, an index to an NCC table, defined in the following example, can be included in the LTM MAC CE.Table 1: 3 candidate cells are configured to the UE and a pair of Index value and NCC is configured for 3 subsequent connections to the candidate cell.
[0096] In Table 1, a subsequent LTM case is described where at least one candidate cell can be configured to the UE and a pair of index values and NCC can be configured for 3 subsequent connections to the candidate cell. For example, a NE may include the index ‘ 1 ’ when sending the LTM MAC CE for the target cell as the Candidate Cell#l (corresponding to cell index ‘I’ with a corresponding physical cell identity) for the first time, the NE may include the index ‘2’ when sending the LTM MAC CE for the target cell as the Candidate Cell#l for the second time, etc. The UE may be on a different cell (e.g., Candidate Cell#3) in between the time the UE connects to the candidate cell#l and reconnects to the cell#l. In at least one implementation, the index ‘2’ can be included before index ‘I’, e.g., the NE may not start with the lower index. For non-subsequent LTM cases, the NE may configure single NCC indices for each of the candidate cells.
[0097] In implementations, a list of SK-counter can be sent to the UE apriori in a protected RRC message e.g., before transmitting LTM MAC CE. For example, the list can be included by the NE in an RRCReconfiguration message to the UE including the corresponding LTM candidate cell configurations of one or multiple candidate cells for PSCell changes. The index to SK-Counter can be included in the LTM. In implementations, alternatively to including the index to SK-Counter, the counter itself can be included in the LTM MAC CE.Table 2: 3 PSCells are configured to the UE and a pair of Index value and SK-Counter is configured for 3 subsequent connections to the candidate cell.
[0098] In Table 2 above, an example subsequent LTM case is described where at least one candidate cell is configured to the UE and a pair of index value and SK-Counter is configured for 3 subsequent connections to the said candidate PSCell. For example, a NE will include the index ‘I’ when sending the LTM MAC CE for the target cell as the Candidate PSCell#! (corresponding to cell index ‘1’ with a corresponding physical cell identity) for the first time, the NE will include the index ‘2’ when sending the LTM MAC CE for the target cell as the Candidate PSCell#! for the second time, etc. The UE may have connected to a different PSCell (e.g., Candidate PSCell#3) in between different connections to the candidate PSCell#!. Alternatively or additionally, the index ‘2’ can be included before index ‘ 1 ’, e.g., the NE may not start with the lower index. For non- subsequent LTM cases, the NE may configure single NCC indices for each of the included PSCell candidates.
[0099] Figure 6 illustrates a scenario 600 in accordance with aspects of the present disclosure. In the scenario 600, 3 CUs each include 3 cells. The scenario 600, for example, illustrates an example where the NE provides signalling to indicate if a security key change is to be performed, and if a security key change is to be performed, whether a horizontal or vertical key derivation is to be used.
[0100] In implementations, the network topology may not be determined by the UE, which can result in that a UE not being signaled that cells 1, 2, and 3 belong to CU-1, cells 4, 5 and 6 belong to CU-2, and cells 7, 8 and 9 belong to CU-3. Further, the network may support the following types of Key change, Type A, Type B, and / or Type C.
[0101] Type A: A no key change case, which can be implemented when the UE moves among the cells (e.g., DUs) of the same CU, e.g., an intra-CU case for LTM mobility. When a security key change is not involved, a PDCP Reestablishment can be avoided.
[0102] Type B: A horizontal key derivation case, which may be implemented between cells of two trusted CUs when a (NH, NCC) pair is not available for use. This may occur when a PATH SWITCH is not implemented. Alternatively, or in addition, after a target NE has completed the handover signaling with the UE, the target NE can send a NGAP PATH SWITCH REQUEST message to the AMF. Upon reception of the NGAP PATH SWITCH REQUEST, the AMF can increase its locally kept NCC value by one and compute a new fresh NH from its stored data. The AMF can use the KAMF from the currently active 5G NAS security context for the computation of the new fresh NH. The AMF can then send the newly computed {NH, NCC} pair to the target NE in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The target NE can store the received {NH, NCC} pair for further handovers and remove other unused stored {NH, NCC} pairs if any.
[0103] Type C: A vertical key derivation case, which may be implemented between cells of two CUs when a (NH, NCC) pair is not available for use, which may occur when a PATH SWITCH was used.
[0104] In implementations, an NE can determine which mobility (handover) between cells of different CUs will involve a path switch and for which mobility it will not, and the NE can provide this information to the UE. This can be done in an RRC Reconfiguration message, such as:Cell 1 NCC-value-a, groupld-l Cell 2 NCC-value-a, groupld- 1 Cell 3 NCC-value-a, groupld- 1 Cell 4 NCC-value-a, groupId-2 Cell 5 NCC-value-a, groupId-2 Cell 6 NCC-value-a, groupId-2 Cell 7 NCC-value-b, groupId-3 Cell 8 NCC-value-b, groupId-3 Cell 9 NCC-value-b, groupId-3
[0105] The Cell identity can be a PCI or an index towards the PCI. The NCC value can be a 3 bit number, e.g., ranging from 0 to 7. The groupld can be a 2 digit or 3 digit integer value. Upon receiving an LTM MAC CE for cell switch UE can first determine the target cell and compare theNCC value and groupld received for this cell as part of the RRC candidate cell configuration with that of the source cell. If the NCC values are different UE performs a vertical key derivation. If the NCC values are the same but the groupld is different, UE performs a horizontal key derivation; otherwise, same keys (as in source cell) can be continued to be used e.g., without deriving new security keys.
[0106] In implementations information on type A, B or C mobility can be carried in the LTM Cell Switch Command MAC CE by using some of the reserved bits.
[0107] Figure 7 illustrates an example LTM cell switch command MAC CE 700 in accordance with aspects of the present disclosure. The LTM cell switch command MAC CE 700, for example, can be implemented according to implementations described herein.
[0108] Figure 8 illustrates an example LTM cell switch command MAC CE 800 in accordance with aspects of the present disclosure. In the LTM cell switch command MAC CE 800, the first 'R' bit in the second row is 'O' in accordance with aspects of the present disclosure. For instance, the first ‘R’ bit in the second row can be used to indicate if the next 3 ‘R’ bits in the same row carry a NCC value or not.
[0109] A UE that receives the MAC CE 800 can function as follows: If the first ‘R’ bit in the second row is set to ‘O’, as shown in the example LTM cell switch command MAC CE 800, no key change may be performed. If the first ‘R’ bit in the second row is set to ‘1’, a key change may be performed. In this case, the UE can determine the NCC value applicable for the target cell (corresponding to the Target Config ID) and compare the NCC value with the NCC value currently in use in the source cell. The second ‘R’ bit in the second row is the most significant bit and the fourth ‘R’ bit in the second row is the least significant bit, as an example. If the values of the most significant bit and the least significant bit are same, a horizontal key derivation can be implemented. If these values are not the same, a vertical key derivation can be implemented.
[0110] Figure 9 illustrates an example LTM cell switch command MAC CE 900 in accordance with aspects of the present disclosure. The LTM cell switch command MAC CE 900 represents an example for signaling an NCC value. In the LTM cell switch command MAC CE 900, instead of an NCC value, an index pointing to the NCC value may be signaled in the MAC CE. The NCC values and the corresponding indices can be signaled (e.g., apriori) using RRC signaling. The ‘R’ bits ofthe second row of the MAC CE may be used as examples, and the disclosed implementations can be applied if other available ‘R’ bits are used and specified accordingly.
[0111] In implementations, a NE may use a layer 3 handover procedure (e.g., RRC Reconfiguration including a reconfiguration with Sync IE) when determining that a keySetChangelndicator field set to ‘true’ in the HO Command message is to be communicated to a UE. This determination can be performed upon receipt of the NGAP HANDOVER REQUEST message from the target AMF. If the target NE received a NSCI, the target NE can set the keySetChangelndicator field in the HO Command message to true.
[0112] The target NE can compute the KNG RAN* to be used with the UE by performing the key derivation with the {NH, NCC} pair received in the NGAP HANDOVER REQUEST message and the target PCI and its frequency EARFCN-DL. The NE can use the KNG RAN* corresponding to the selected cell as KgNB- The target NE can associate the NCC value received from AMF with the KgNB. The target NE can include the NCC value from the received {NH, NCC} pair, and the NASC if such was also received, into the HO Command message to the UE and remove any existing unused stored {NH, NCC} pairs. If the target NE received the NSCI, the target NE can set the keySetChangelndicator field in the HO Command message to true. In implementations, a NE may use a layer 3 handover procedure (e.g., RRC Reconfiguration including a reconfiguration with Sync IE) when determining that a security algorithm to be used in the target cell is different from a security algorithm currently in use in a source cell.
[0113] Figure 10 illustrates an example of a UE 1000 in accordance with aspects of the present disclosure. The UE 1000 may include a processor 1002, a memory 1004, a controller 1006, and a transceiver 1008. The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0114] The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specificintegrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0115] The processor 1002 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 1002 may be configured to operate the memory 1004. In some other implementations, the memory 1004 may be integrated into the processor 1002. The processor 1002 may be configured to execute computer-readable instructions stored in the memory 1004 to cause the UE 1000 to perform various functions of the present disclosure.
[0116] The memory 1004 may include volatile or non-volatile memory. The memory 1004 may store computer-readable, computer-executable code including instructions when executed by the processor 1002 cause the UE 1000 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1004 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0117] In some implementations, the processor 1002 and the memory 1004 coupled with the processor 1002 may be configured to cause the UE 1000 to perform one or more of the functions described herein (e.g., executing, by the processor 1002, instructions stored in the memory 1004). For example, the processor 1002 may support wireless communication at the UE 1000 in accordance with examples as disclosed herein. The UE 1000 may be configured to or operable to support means for and / or methods to: receive in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; receive LTM MAC CE for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiate handover execution; determine whether to derive one or more security keys based on the received first information; determine, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more newsecurity keys using second information; and transmit handover complete to the target cell applying the derived one or more new security keys.
[0118] Further, the first message including candidate cell configuration includes a layer 3 RRC Reconfiguration message from the serving cell; the LTM includes a lower layer mobility command message; the LTM includes identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information; the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed; the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value; the UE radio network identity includes C-RNTI.
[0119] The controller 1006 may manage input and output signals for the UE 1000. The controller 1006 may also manage peripherals not integrated into the UE 1000. In some implementations, the controller 1006 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1006 may be implemented as part of the processor 1002.
[0120] In some implementations, the UE 1000 may include at least one transceiver 1008. In some other implementations, the UE 1000 may have more than one transceiver 1008. The transceiver 1008 may represent a wireless transceiver. The transceiver 1008 may include one or more receiver chains 1010, one or more transmitter chains 1012, or a combination thereof.
[0121] A receiver chain 1010 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1010 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 1010 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1010 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1010 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0122] A transmitter chain 1012 may be configured to generate and transmit signals(e.g., control information, data, packets). The transmitter chain 1012 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over awireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1012 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1012 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0123] Figure 11 illustrates an example of a processor 1100 in accordance with aspects of the present disclosure. The processor 1100 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 1100 may include a controller 1102 configured to perform various operations in accordance with examples as described herein. The processor 1100 may optionally include at least one memory 1104, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 1100 may optionally include one or more arithmetic-logic units (ALUs) 1106. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0124] The processor 1100 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 1100) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
[0125] The controller 1102 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 1100 to cause the processor 1100 to support various operations in accordance with examples as described herein. For example, the controller 1102 may operate as a control unit of the processor 1100, generating control signalsthat manage the operation of various components of the processor 1100. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0126] The controller 1102 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 1104 and determine subsequent instruction(s) to be executed to cause the processor 1100 to support various operations in accordance with examples as described herein. The controller 1102 may be configured to track memory addresses of instructions associated with the memory 1104. The controller 1102 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1102 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 1100 to cause the processor 1100 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 1102 may be configured to manage flow of data within the processor 1100. The controller 1102 may be configured to control transfer of data between registers, ALUs 1106, and other functional units of the processor 1100.
[0127] The memory 1104 may include one or more caches (e.g., memory local to or included in the processor 1100 or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 1104 may reside within or on a processor chipset (e.g., local to the processor 1100). In some other implementations, the memory 1104 may reside external to the processor chipset (e.g., remote to the processor 1100).
[0128] The memory 1104 may store computer-readable, computer-executable code including instructions that, when executed by the processor 1100, cause the processor 1100 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 1102 and / or the processor 1100 may be configured to execute computer-readable instructions stored in the memory 1104 to cause the processor 1100 to perform various functions. For example, the processor 1100 and / or the controller 1102 may be coupled with or to the memory 1104, the processor 1100, and the controller 1102, and may be configured to perform various functions described herein. In some examples, the processor 1100 may include multiple processors and the memory 1104 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiplememories, which may, individually or collectively, be configured to perform various functions herein.
[0129] The one or more ALUs 1106 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 1106 may reside within or on a processor chipset (e.g., the processor 1100). In some other implementations, the one or more ALUs 1106 may reside external to the processor chipset (e.g., the processor 1100). One or more ALUs 1106 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 1106 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 1106 may be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 1106 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 1106 to handle conditional operations, comparisons, and bitwise operations.
[0130] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to or operable to support at least one controller (e.g., the controller 1102) coupled with at least one memory (e.g., the memory 1104) and configured to cause the processor to: receive in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding user equipment (UE) radio network identity from a serving cell; receive LTM MAC CE for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiate handover execution; determine whether to derive one or more security keys based on the received first information; determine, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more new security keys using second information; and transmit handover complete to the target cell applying the derived one or more new security keys.
[0131] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the first message including candidate cell configuration includes a layer 3 RRC Reconfiguration message from the serving cell; the LTM includes a lower layer mobilitycommand message; the LTM includes identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information; the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed; the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value; the UE radio network identity includes C-RNTI.
[0132] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to or operable to support at least one controller (e.g., the controller 1102) coupled with at least one memory (e.g., the memory 1104) and configured to cause the processor to transmit a first message including candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmit LTM MAC CE including a target cell including a first and a second information.
[0133] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the first message including candidate cell configuration includes a layer 3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information; the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed; the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value; the UE radio network identity includes C-RNTI.
[0134] Figure 12 illustrates an example of a NE 1200 in accordance with aspects of the present disclosure. The NE 1200 may include a processor 1202, a memory 1204, a controller 1206, and a transceiver 1208. The processor 1202, the memory 1204, the controller 1206, or the transceiver 1208, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0135] The processor 1202, the memory 1204, the controller 1206, or the transceiver 1208, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). Thehardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0136] The processor 1202 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 1202 may be configured to operate the memory 1204. In some other implementations, the memory 1204 may be integrated into the processor 1202. The processor 1202 may be configured to execute computer-readable instructions stored in the memory 1204 to cause the NE 1200 to perform various functions of the present disclosure.
[0137] The memory 1204 may include volatile or non-volatile memory. The memory 1204 may store computer-readable, computer-executable code including instructions when executed by the processor 1202 cause the NE 1200 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1204 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0138] In some implementations, the processor 1202 and the memory 1204 coupled with the processor 1202 may be configured to cause the NE 1200 to perform one or more of the functions described herein (e.g., executing, by the processor 1202, instructions stored in the memory 1204). For example, the processor 1202 may support wireless communication at the NE 1200 in accordance with examples as disclosed herein. The NE 1200 may be configured to or operable to support means for and methods to: transmit a first message including candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmit LTM MAC CE including a target cell including a first and a second information.
[0139] Further, the first message including candidate cell configuration includes a layer 3 RRC Reconfiguration message; the LTM includes a lower layer mobility command message; the LTMincludes identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information; the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed; the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value; the UE radio network identity includes C-RNTI.
[0140] The controller 1206 may manage input and output signals for the NE 1200. The controller 1206 may also manage peripherals not integrated into the NE 1200. In some implementations, the controller 1206 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1206 may be implemented as part of the processor 1202.
[0141] In some implementations, the NE 1200 may include at least one transceiver 1208. In some other implementations, the NE 1200 may have more than one transceiver 1208. The transceiver 1208 may represent a wireless transceiver. The transceiver 1208 may include one or more receiver chains 1210, one or more transmitter chains 1212, or a combination thereof.
[0142] A receiver chain 1210 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1210 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 1210 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1210 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1210 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0143] A transmitter chain 1212 may be configured to generate and transmit signals(e.g., control information, data, packets). The transmitter chain 1212 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1212 may also include at least one power amplifier configured to amplify the modulated signal toan appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1212 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0144] Figure 13 illustrates a flowchart of a method 1300 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0145] At 1302, the method may include receiving in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell. The operations of 1302 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1302 may be performed by a UE as described with reference to Figure 10.
[0146] At 1304, the method may include receiving LTM MAC CE for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information. The operations of 1304 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1304 may be performed by a UE as described with reference to Figure 10.
[0147] At 1306, the method may include initiating handover execution. The operations of 1306 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1306 may be performed a UE as described with reference to Figure 10.
[0148] At 1308, the method may include determining whether to derive one or more security keys based on the received first information. The operations of 1308 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1308 may be performed by a UE as described with reference to Figure 10.
[0149] At 1310, the method may include determining, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more newsecurity keys using second information. The operations of 1310 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1310 may be performed by a UE as described with reference to Figure 10.
[0150] At 1312, the method may include transmitting handover complete to the target side applying the derived one or more new security keys. The operations of 1312 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1312 may be performed a UE as described with reference to Figure 10.
[0151] Figure 14 illustrates a flowchart of a method 1400 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0152] At 1402, the method may include transmitting a first message including candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from the serving cell. The operations of 1402 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1402 may be performed by a NE as described with reference to Figure 12.
[0153] At 1404, the method may include transmitting LTM MAC CE including a target cell including a first and a second information. The operations of 1404 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1404 may be performed by a NE as described with reference to Figure 12.
[0154] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
CLAIMSWhat is claimed is:
1. A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the UE to: receive in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; receive layer 1 / layer 2 triggered mobility (LTM) medium access control (MAC) control element (CE) for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiate handover execution; determine whether to derive one or more security keys based on the received first information; determine, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more new security keys using second information; and transmit handover complete to the target cell applying the derived one or more new security keys.
2. The UE of claim 1 , wherein the first message including candidate cell configuration comprises a layer 3 radio resource control (RRC) Reconfiguration message from the serving cell.
3. The UE of claim 1 , wherein the LTM comprises a lower layer mobility command message.
4. The UE of claim 1 , wherein the LTM comprises identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information.
5. The UE of claim 1 , wherein the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed.
6. The UE of claim 1 , wherein the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value.
7. The UE of claim 1 , wherein the UE radio network identity comprises cell radio network temporary identifier (C-RNTI).
8. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the NE to: transmit a first message comprising candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmit layer 1 / layer 2 triggered mobility (LTM) medium access control (MAC) control element (CE) including a target cell including a first and a second information.
9. The NE of claim 8, wherein the first message including candidate cell configuration comprises a layer 3 radio resource control (RRC) Reconfiguration message.
10. The NE of claim 8, wherein the LTM comprises a lower layer mobility command message.
11. The NE of claim 8, wherein the LTM comprises identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information.
12. The NE of claim 8, wherein the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed.
13. The NE of claim 8, wherein the second information is included using 3 reserved bits in the MAC CE and indicates a NCC value.
14. The NE of claim 8, wherein the UE radio network identity comprises cell radio network temporary identifier (C-RNTI).
15. A method performed by a user equipment (UE), the method comprising: receiving in a first message candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; receiving layer 1 / layer 2 triggered mobility (LTM) medium access control (MAC) control element (CE) for the at least one candidate cell designating the at least one candidate cell as a target cell, MAC CE including a first information and a second information; initiating handover execution; determining whether to derive one or more security keys based on the received first information; determining, in response to determining that the one or more security keys are to be derived based on the received first information, whether to use a horizontal key derivation or vertical key derivation and subsequently derive one or more new security keys using second information; and transmitting handover complete to the target cell applying the derived one or more new security keys.
16. The method of claim 15, wherein the first message including candidate cell configuration comprises a layer 3 radio resource control (RRC) Reconfiguration message from the serving cell.
17. The method of claim 15, wherein the LTM comprises a lower layer mobility command message.
18. The method of claim 15, wherein the LTM comprises identification of the target cell, a timing advance to be used for the target cell, third information, and fourth information.
19. The method of claim 15, wherein the first information is included using a reserved bit in the MAC CE and indicates whether a security key rederivation is to be performed.
20. A method performed by a network equipment (NE), the method comprising: transmitting a first message comprising candidate cell configuration including security configuration for at least one candidate cell and a corresponding UE radio network identity from a serving cell; and transmitting layer 1 / layer 2 triggered mobility (LTM) medium access control (MAC) control element (CE) including a target cell including a first and a second information.
Citation Information
Patent Citations
Latency Reduction for Primary Cell Switching
US20240114406A1
Method for controlling cell change operation, and device thereof
WO2023128730A1
NR mobility – security considerations for l1 / l2 mobility switching of an spcell
WO2024031042A1
Secondary cell group configuration retention or release
WO2024072796A1