Security information for a cell handover
By incorporating an index value for the next hop chaining counter in the LTM MAC CE and using RRC signaling for sensitive information, the solution addresses the challenge of protecting security information during cell handover, reducing latency and maintaining security in wireless communications systems.
Patent Information
- Application Number
- PCT/IB2025/052857
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-04
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-26
AI Technical Summary
Current cell handover procedures in wireless communications systems face challenges in protecting security-sensitive information, particularly during lower layer mobility where the MAC CE used for LTM is not protected, potentially exposing security-related information.
The proposed solution involves protecting security-sensitive information by including an index value for the next hop chaining counter in the LTM MAC CE and sending the mapping from index to next hop chaining count or security key counter apriori in an RRC signaling, ensuring that sensitive information is hashed and protected during handover.
This approach reduces latency and overhead in cell handover processes while maintaining the security of sensitive information, enhancing the overall reliability and security of wireless communications systems.
Smart Images

Figure IB2025052857_26062025_PF_FP_ABST
Abstract
Description
SECURITY INFORMATION FOR A CELL HANDOVERRELATED APPLICATION
[0001] This application claims priority to U.S. Provisional Application Serial No. 63 / 574,672, filed 04 April 2024, entitled “SECURITY INFORMATION FOR A CELL HANDOVER,” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to wireless communications, and more specifically to user equipment (UE) cell mobility.BACKGROUND
[0003] A wireless communications system may include one or multiple network communication devices, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as UE, or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY
[0004] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or“one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on”. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0005] A UE for wireless communication is described. The UE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the UE may be configured to, capable of, or operable to receive, from a serving cell, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; receive Layer 1 / Layer 2 Triggered Mobility (LTM) for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiate handover execution to the target cell; derive one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmit a handover complete message to the target cell using the derived one or more security keys.
[0006] A processor (e.g., a standalone processor chipset, or a component of a UE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive, from a serving cell, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; receive LTM for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiate handover execution to the target cell; derive one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmit a handover complete message to the target cell using the derived one or more security keys.
[0007] A method performed or performable by a UE for wireless communication is described. The method may include receiving, from a serving cell, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radionetwork identity; receiving LTM for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiating handover execution to the target cell; deriving one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmitting a handover complete message to the target cell using the derived one or more security keys.
[0008] In some implementations of the UE, the processor, and the method described herein, the UE radio network identity includes a Cell Radio Network Temporary Identifier (C-RNTI).
[0009] In some implementations of the UE, the processor, and the method described herein, the first message includes a Layer 3 (L3) Radio Resource Control (RRC) reconfiguration message.
[0010] In some implementations of the UE, the processor, and the method described herein, the LTM includes a lower layer mobility command message.
[0011] In some implementations of the UE, the processor, and the method described herein, the LTM includes identification for the target cell, timing advance for use by the target cell, and an index pointing to the next hop chaining counter for use for security protection of transmission of the handover complete message.
[0012] In some implementations of the UE, the processor, and the method described herein, the handover complete message includes a L3 RRC reconfiguration complete message.
[0013] An NE (e.g., a base station) for wireless communication is described. The NE may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the NE may be configured to, capable of, or operable to transmit, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmit LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM.
[0014] A processor (e.g., a standalone processor chipset, or a component of a NE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to transmit, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radionetwork identity; and transmit LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM.
[0015] A method performed or performable by an NE (e.g., a base station) for wireless communication is described. The method may include transmitting, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmitting LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM.
[0016] In some implementations of the NE, the processor, and the method described herein, the UE radio network identity includes a C-RNTI.
[0017] In some implementations of the NE, the processor, and the method described herein, the first message includes a L3 RRC reconfiguration message.
[0018] In some implementations of the NE, the processor, and the method described herein, the LTM includes a lower layer mobility command message.
[0019] In some implementations of the NE, the processor, and the method described herein, the LTM includes identification of the at least one candidate cell, timing advance for use by the at least one candidate cell, and an index pointing to the next hop chaining counter for use for security protection.BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0021] Figure 2 illustrates an example procedure for LTM.
[0022] Figure 3 illustrates an example system for UE mobility in accordance with aspects of the present disclosure.
[0023] Figure 4 illustrates an example master key update information element (IE) in accordance with aspects of the present disclosure.
[0024] Figure 5 illustrates an example of a UE in accordance with aspects of the present disclosure.
[0025] Figure 6 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0026] Figure 7 illustrates an example of a NE in accordance with aspects of the present disclosure.
[0027] Figure 8 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
[0028] Figure 9 illustrates a flowchart of a method in accordance with aspects of the present disclosure.DETAILED DESCRIPTION
[0029] In a wireless communications system, a UE and a NE (e.g., a base station) may support wireless communication (e.g., reception and / or transmission of wireless communication). Further, a UE may move between different NE (e.g., different cells) in mobility scenarios. When the UE moves from the coverage area of one cell to another cell, at some point a serving cell change is to be performed since a current serving cell does not remain a radio viable option. Currently, serving cell change is triggered by L3 measurements and is done by RRC signalling triggered reconfiguration with synchronisation for change of primary cell (PCell) and primary secondary cell (PSCell), as well as release add for secondary cells (Scells) when applicable. Such cases may involve complete LI and L2 resets, which can lead to longer latency, larger overhead, and longer interruption time than beam switch mobility. A goal of L1 / L2 mobility enhancements is to enable a serving cell change via L1 / L2 signalling in order to reduce the latency, overhead and interruption time. Such mobility can be achieved using a LTM procedure utilizing a cell switch command which is conveyed in a MAC CE, which according to 3GPP TS 38.300 involves a cell switch command conveyed in a MAC CE which includes the information to perform the LTM cell switch. Such cell switching scenarios can involve a source central unit (CU) to target CU change which can involve a change of packet data convergence protocol (PDCP) location and the PDCP location change involves a change in security parameter. Thus an issue is how the security changes are to be performed using a MAC CE (LTM) which itself is not protected (neither integrity protected nor ciphered), thus potentially exposing the security related information in the open.
[0030] Accordingly, aspects of the present disclosure provide for protection of securitysensitive information as part of LTM. For instance, aspects of the present disclosure enable protection of security information to derive new keys during a lower layer mobility. As an example, an index value is included in the LTM MAC CE, and the mapping from index to next hop chaining count (NCC) (or security key (SK)-Counter) is sent apriori in an RRC signaling. For instance, at least a portion of sensitive information is provided apriori in an RRC protected message and remains hashed (e.g., indexed) in the LTM MAC CE. Further, both subsequent and non-subsequent cases covered. A Nas-container and other information can be sent apriori in an RRC signaling.
[0031] In implementations, part of the Master Key Update is sent to the UE apriori in a protected RRC message, e.g., before transmitting LTM MAC CE. As an example, the nas-Container and Key Set Indicator can be included by the gNB in an RRCReconfiguration message to the UE including the corresponding LTM candidate cell configurations of one or multiple candidate cells. The NCC is included in the LTM. In at least one example, instead of the NCC an index to an NCC table (such as defined below) is included in the LTM MAC CE.
[0032] By utilizing the described techniques, latency and overhead in enabling a UE to change serving cells can be reduced while maintaining security of security-sensitive information as part of cell change procedures.
[0033] Aspects of the present disclosure are described in the context of a wireless communications system.
[0034] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more network equipment (NE) 102, one or more UE 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G- Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE)802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
[0035] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a nextgeneration NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0036] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
[0037] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of- Everything (loE) device, or machine-type communication (MTC) device, among other examples.
[0038] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0039] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N6, or other network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other indirectly (e.g., via the CN 106). In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as a radio heads, smart radio heads, or transmission-reception points (TRPs).
[0040] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
[0041] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N6, or other network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information,data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).
[0042] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0043] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0044] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0045] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, jU=l , / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0046] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0047] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing.FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.
[0048] According to implementations, one or more of the NEs 102 and the UEs 104 are operable to implement various aspects of the techniques described with reference to the present disclosure. For example, a NE 102 transmits to a UE 104 a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity. The NE 104 also transmits to the UE 104 LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM. The UE 104 receives the first message and the LTM and designates the at least one candidate cell as a target cell. The UE 104 initiates a handover execution to the target cell, derives one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM, and transmits a handover complete message to the target cell using the derived one or more security keys.
[0049] Figure 2 illustrates an example procedure 200 for LTM. The procedure 200, for instance, includes communication between a NE 102 and a UE 104. Subsequent LTM can be performed by repeating the early synchronization, LTM execution, and LTM completion steps without releasing other LTM candidate cell configurations after each LTM completion.
[0050] In the procedure 200 for LTM:
[0051] 1. The UE sends a MeasurementReport message to the gNB. The gNB decides to configure LTM and initiates candidate cell(s) preparation.
[0052] 2. The gNB transmits an RRCReconfiguration message to the UE including the LTM candidate cell configurations of one or multiple candidate cells.
[0053] 3. The UE stores the LTM candidate cell configurations and transmits anRRCReconfigurationComplete message to the gNB.
[0054] 4a. The UE [may] performs DL synchronization with candidate cell(s) before receiving the cell switch command.
[0055] 4b. The UE [may] performs early TA acquisition with candidate cell(s) requested by the network before receiving the cell switch command. This is done via CFRA triggered by a PDCCH order from the source cell, following which the UE sends preamble towards the indicated candidate cell. In order to minimize the data interruption of the source cell due to CFRA towards the candidate cell(s), the UE doesn’t receive RAR for the purpose of TA value acquisition and the TA value of the candidate cell is indicated in the cell switch command. The UE doesn’t maintain the TA timer for the candidate cell and relies on network implementation to guarantee the TA validity.
[0056] 5. The UE performs LI measurements on the configured candidate cell(s) and transmits lower-layer measurement reports to the gNB. LI measurement should be performed as long as apply the RRC reconfiguration in step 2.
[0057] 6. The gNB decides to execute cell switch to a target cell and transmits a MAC CE triggering cell switch (LTM) by including the candidate configuration index of the target cell. The UE switches to the target cell and applies the configuration indicated by candidate configuration index.
[0058] 7. The UE performs the random access procedure towards the target cell, if UE does not have valid TA of the target cell.
[0059] 8. The UE completes the LTM cell switch procedure [by sendingRRCReconfigurationComplete message to target cell]. If the UE has performed a RA procedure in step 7 the UE considers that LTM execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM, the UE considers that LTM execution is successfully completed when the UE determines that the network has successfully received its first UL data. The UE determines successful reception of its first UL data by receiving a PDCCH addressing the UE’s C-RNTI in the target cell, which schedules a new transmission following the first UL data.
[0060] R2 can assume RRCReconfigurationComplete message is sent at each LTM execution. The steps 4-8 can be performed multiple times for subsequent LTM cell switch using the LTM candidate cell configuration(s) provided in step 2.
[0061] Figure 3 illustrates an example system 300 for UE mobility in accordance with aspects of the present disclosure. The system 300, for instance, illustrates intra-CU mobility 302 and inter-CU mobility 304. The intra-CU mobility 302 may not involve a security key change since the DU-a and DU-b are served in a same CU-1. In the inter-CU mobility 304, however, a security key change may be involved since DU-c and DU-b are served in a different CU-2.
[0062] The currently specified LTM MAC CE based mobility does not require security key change as both the target and source DU (Distributed Unit, a base station / cell) in under the same CU (Central Unit).
[0063] In Release 19 this is to be extended to Inter-CU cases including: Layer 1 / Layer 2 Triggered mobility (LTM) was introduced in Rel- 18 and can offer improvements in handover latency and interruption time compared to Layer 3 based mobility. However, LTM as introduced in Rel- 18 also has a number of limitations compared to Layer 3 mobility. This Rel- 19 work item aims to remove a number of these limitations. LTM operation may be supported for mobility between cells of the same gNB (same CU). Depending on the deployment of the network this may significantly limit the opportunities to use LTM. By enabling LTM operation between cells of different gNBs (i.e., inter-CU) then the network will be able gain the benefits of LTM for a far greater number of handovers. The source CU to target CU change also means a change of PDCP location. The PDCP location change is to obtain a change in security parameter. Thus an issue is how the security changes are to be manifested using a MAC CE (LTM) which itself is not protected (neither integrity protected nor ciphered), thus exposing the security related information in the open.
[0064] The present disclosure thus presents techniques for protecting security related information in such scenarios such as in inter-CU mobility scenarios. The described implementations, for example, enable security key changes in inter-CU mobility using lower layers, such as via LTM MAC CE.
[0065] Figure 4 illustrates an example master key update information element (IE) 400 in accordance with aspects of the present disclosure. In implementations a network (e.g., NE) includes the Master key Update IE 400 in the LTM MAC CE for Inter-CU PCell change involving KgNB change. Upon receiving the IE 400 the UE computes the new AS keys (KgNB, KRRCint, KRRCenc, Kupint and Kupenc). Prior to this a security configuration (securityConfig) can be sent to the UE using RRC signalling indicating Security Algorithm to be used in a corresponding candidate cell and also informing the UE for a bearer if a master or secondary key is to be used. After deriving the newkeys, UE configures the PDCP entity with the security algorithms according to securityConfig and apply the keys (KRRCenc and KRRCint) associated with the master key (K§NB).
[0066] In implementations, a network includes sk-Counter in the LTM MAC CE for Inter-CU PSCell change involving S-KgNB change. Upon receiving this UE derives or updates the secondary key (S-KgNB) based on the KgNB key and using the received or selected sk-Counter value, as specified in 3GPP TS 33.501. Thereafter it derives the KRRCenc key and the Kupenc key using the ciphering algorithms indicated in the Radio Bearer Config associated with the secondary key (S- KgNB) as indicated by keyToUse. It further derives the KRRCint key and the Kupint key using the integrity protection algorithms indicated in the Radio Bearer Config associated with the secondary key (S-KgNB) as indicated by keyToUse received earlier in a prior RRC message.
[0067] In implementations, part of the Master Kex Update is sent to the UE apriori in a protected RRC message, e.g., before transmitting LTM MAC CE. As an example, the nas-Container and Key Set Indicator can be included in the by the gNB in an RRCReconfiguration message to the UE including the corresponding LTM candidate cell configurations of one or multiple candidate cells. The NCC (Next Hop Chaining Count) is included in the LTM. In at least one example, instead of the NCC and an index to an NCC table, defined in the following Table 1, is included in the LTM MAC CE.Table 1: 3 candidate cells are configured to the UE and a pair of Index value and NCC is configured for up to 3 subsequent visit to the candidate cell
[0068] In Table 1, a subsequent LTM case is described where at least one candidate cell are configured to the UE and a pair of Index value and NCC is configured for up to 3 subsequent visit to the candidate cell. For example, network will include the index ‘ 1 ’ when sending the LTM MAC CE for the target cell as the Candidate Cell#l (corresponding to cell index ‘1’ with a corresponding physical cell identity) for the first time, network will include the index ‘2’ when sending the LTM MAC CE for the target cell as the Candidate Cell#l for the second time etc. In some scenarios the UE was on another cell (e.g., Candidate Cell#3) in between the time the UE visits the candidate cell#l again. In a variation the index ‘2’ can be included before index ‘1’ e.g., network may not start with the lower index. For non-subsequent LTM cases, the network may configure single NCC indices for each of the candidate cells.
[0069] In implementations, a list of SK-counter is sent to the UE apriori in a protected RRC message, e.g., before transmitting LTM MAC CE. As an example, the list can be included by the gNB in an RRCReconfiguration message to the UE including the corresponding LTM candidate cell configurations of one or multiple candidate cells for PSCell changes. The index to SK-Counter is included in the LTM. In a variation, instead of the index to SK-Counter directly the counter itself is included in the LTM MAC CE.Table 2: 3 PSCells are configured to the UE and a pair of Index value and SK-Counter is configured for up to 3 subsequent visit to the said candidate cell.
[0070] In Table 2, a subsequent LTM case is described where at least one candidate cell is configured to the UE and a pair of Index value and SK-Counter is configured for up to 3 subsequent visit to the said candidate PSCell. For example, network will include the index ‘ 1 ’ when sending the LTM MAC CE for the target cell as the Candidate PSCell#! (corresponding to cell index ‘1’ with a corresponding physical cell identity) for the first time, network will include the index ‘2’ when sending the LTM MAC CE for the target cell as the Candidate PSCell#! for the second time etc. In scenarios the UE was on another PSCell (e.g., Candidate PSCell#3) in between the time the UE visits the candidate PSCell#! again. In a variation the index ‘2’ can be included before index ‘1’ e.g., network may not start with the lower index. For non-subsequent LTM cases, the network may configure single NCC indices for each of the included PSCell candidates.
[0071] Figure 5 illustrates an example of a UE 500 in accordance with aspects of the present disclosure. The UE 500 may include a processor 502, a memory 504, a controller 506, and a transceiver 508. The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0072] The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereofconfigured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0073] The processor 502 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 502 may be configured to operate the memory 504. In some other implementations, the memory 504 may be integrated into the processor 502. The processor 502 may be configured to execute computer-readable instructions stored in the memory 504 to cause the UE 500 to perform various functions of the present disclosure.
[0074] The memory 504 may include volatile or non-volatile memory. The memory 504 may store computer-readable, computer-executable code including instructions when executed by the processor 502 cause the UE 500 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 504 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0075] In some implementations, the processor 502 and the memory 504 coupled with the processor 502 may be configured to cause the UE 500 to perform one or more of the functions described herein (e.g., executing, by the processor 502, instructions stored in the memory 504). For example, the processor 502 may support wireless communication at the UE 500 in accordance with examples as disclosed herein. The UE 500 may be configured to or operable to support a means for receiving, from a serving cell, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; receiving LTM for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiating handover execution to the target cell; deriving one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmitting a handover complete message to the target cell using the derived one or more security keys.
[0076] Additionally, the UE 500 may be configured to support any one or combination of where the UE radio network identity includes a C-RNTI; the first message includes a L3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification for the target cell, timing advance for use by the target cell, and an index pointing to the next hop chaining counter for use for security protection of transmission of the handover complete message; the handover complete message includes a L3 RRC reconfiguration complete message.
[0077] Additionally, or alternatively, the UE 500 may support at least one memory (e.g., the memory 504) and at least one processor (e.g., the processor 502) coupled with the at least one memory and configured to cause the UE to receive, from a serving cell, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; receive LTM for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiate handover execution to the target cell; derive one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmit a handover complete message to the target cell using the derived one or more security keys.
[0078] Additionally, the UE 500 may be configured to support any one or combination of where the UE radio network identity includes a C-RNTI; the first message includes a L3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification for the target cell, timing advance for use by the target cell, and an index pointing to the next hop chaining counter for use for security protection of transmission of the handover complete message; the handover complete message includes a L3 RRC reconfiguration complete message.
[0079] The controller 506 may manage input and output signals for the UE 500. The controller 506 may also manage peripherals not integrated into the UE 500. In some implementations, the controller 506 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 506 may be implemented as part of the processor 502.
[0080] In some implementations, the UE 500 may include at least one transceiver 508. In some other implementations, the UE 500 may have more than one transceiver 508. The transceiver 508 may represent a wireless transceiver. The transceiver 508 may include one or more receiver chains 510, one or more transmitter chains 512, or a combination thereof.
[0081] A receiver chain 510 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 510 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 510 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 510 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 510 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0082] A transmitter chain 512 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 512 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 512 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 512 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0083] Figure 6 illustrates an example of a processor 600 in accordance with aspects of the present disclosure. The processor 600 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 600 may include a controller 602 configured to perform various operations in accordance with examples as described herein. The processor 600 may optionally include at least one memory 604, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 600 may optionally include one or more arithmetic-logic units (ALUs) 606. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0084] The processor 600 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 600) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
[0085] The controller 602 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 600 to cause the processor 600 to support various operations in accordance with examples as described herein. For example, the controller 602 may operate as a control unit of the processor 600, generating control signals that manage the operation of various components of the processor 600. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0086] The controller 602 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 604 and determine subsequent instruction(s) to be executed to cause the processor 600 to support various operations in accordance with examples as described herein. The controller 602 may be configured to track memory addresses of instructions associated with the memory 604. The controller 602 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 602 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 600 to cause the processor 600 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 602 may be configured to manage flow of data within the processor 600. The controller 602 may be configured to control transfer of data between registers, ALUs 606, and other functional units of the processor 600.
[0087] The memory 604 may include one or more caches (e.g., memory local to or included in the processor 600 or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flashmemory, etc. In some implementations, the memory 604 may reside within or on a processor chipset (e.g., local to the processor 600). In some other implementations, the memory 604 may reside external to the processor chipset (e.g., remote to the processor 600).
[0088] The memory 604 may store computer-readable, computer-executable code including instructions that, when executed by the processor 600, cause the processor 600 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 602 and / or the processor 600 may be configured to execute computer-readable instructions stored in the memory 604 to cause the processor 600 to perform various functions. For example, the processor 600 and / or the controller 602 may be coupled with or to the memory 604, the processor 600, and the controller 602, and may be configured to perform various functions described herein. In some examples, the processor 600 may include multiple processors and the memory 604 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0089] The one or more ALUs 606 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 606 may reside within or on a processor chipset (e.g., the processor 600). In some other implementations, the one or more ALUs 606 may reside external to the processor chipset (e.g., the processor 600). One or more ALUs 606 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 606 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 606 may be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 606 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 606 to handle conditional operations, comparisons, and bitwise operations.
[0090] The processor 600 may support wireless communication in accordance with examples as disclosed herein. The processor 600 may be configured to or operable to support at least one controller (e.g., the controller 602) coupled with at least one memory (e.g., the memory 604) and configured to cause the processor to receive, from a serving cell, a first message including candidatecell configuration including security configuration for at least one candidate cell and a UE radio network identity; receive LTM for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiate handover execution to the target cell; derive one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmit a handover complete message to the target cell using the derived one or more security keys.
[0091] Additionally, the processor 600 may be configured to or operable to support any one or combination of where the UE radio network identity includes a C-RNTI; the first message includes a L3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification for the target cell, timing advance for use by the target cell, and an index pointing to the next hop chaining counter for use for security protection of transmission of the handover complete message; the handover complete message includes a L3 RRC reconfiguration complete message.
[0092] The processor 600 may support wireless communication in accordance with examples as disclosed herein. The processor 600 may be configured to or operable to support at least one controller (e.g., the controller 602) coupled with at least one memory (e.g., the memory 604) and configured to cause the processor to transmit, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmit LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM.
[0093] Additionally, the processor 600 may be configured to or operable to support any one or combination of where the UE radio network identity includes a C-RNTI; the first message includes L3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification of the at least one candidate cell, timing advance for use by the at least one candidate cell, and an index pointing to the next hop chaining counter for use for security protection.
[0094] Figure 7 illustrates an example of a NE 700 in accordance with aspects of the present disclosure. The NE 700 may include a processor 702, a memory 704, a controller 706, and a transceiver 708. The processor 702, the memory 704, the controller 706, or the transceiver 708, orvarious combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0095] The processor 702, the memory 704, the controller 706, or the transceiver 708, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0096] The processor 702 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 702 may be configured to operate the memory 704. In some other implementations, the memory 704 may be integrated into the processor 702. The processor 702 may be configured to execute computer-readable instructions stored in the memory 704 to cause the NE 700 to perform various functions of the present disclosure.
[0097] The memory 704 may include volatile or non-volatile memory. The memory 704 may store computer-readable, computer-executable code including instructions when executed by the processor 702 cause the NE 700 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 704 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0098] In some implementations, the processor 702 and the memory 704 coupled with the processor 702 may be configured to cause the NE 700 to perform one or more of the functions described herein (e.g., executing, by the processor 702, instructions stored in the memory 704). For example, the processor 702 may support wireless communication at the NE 700 in accordance with examples as disclosed herein. The NE 700 may be configured to or operable to support a means fortransmitting, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmitting LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM.
[0099] Additionally, the NE 700 may be configured to or operable to support any one or combination of where the UE radio network identity includes a C-RNTI; the first message includes a L3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification of the at least one candidate cell, timing advance for use by the at least one candidate cell, and an index pointing to the next hop chaining counter for use for security protection.
[0100] Additionally, or alternatively, the NE 700 may support at least one memory (e.g., the memory 704) and at least one processor (e.g., the processor 702) coupled with the at least one memory and configured to cause the NE to transmit, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmit LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM.
[0101] Additionally, the NE 700 may be configured to support any one or combination of where the UE radio network identity includes a C-RNTI; the first message includes a L3 RRC reconfiguration message; the LTM includes a lower layer mobility command message; the LTM includes identification of the at least one candidate cell, timing advance for use by the at least one candidate cell, and an index pointing to the next hop chaining counter for use for security protection.
[0102] The controller 706 may manage input and output signals for the NE 700. The controller 706 may also manage peripherals not integrated into the NE 700. In some implementations, the controller 706 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 706 may be implemented as part of the processor 702.
[0103] In some implementations, the NE 700 may include at least one transceiver 708. In some other implementations, the NE 700 may have more than one transceiver 708. The transceiver 708may represent a wireless transceiver. The transceiver 708 may include one or more receiver chains710, one or more transmitter chains 712, or a combination thereof.
[0104] A receiver chain 710 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 710 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 710 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 710 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 710 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0105] A transmitter chain 712 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 712 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 712 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 712 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0106] Figure 8 illustrates a flowchart of a method 800 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0107] At 802, the method may include receiving, from a serving cell, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity. The operations of 802 may be performed in accordance with examples asdescribed herein. In some implementations, aspects of the operations of 802 may be performed by a UE as described with reference to Figure 5.
[0108] At 804, the method may include receiving LTM for the at least one candidate cell and designate the at least one candidate cell as a target cell. The operations of 804 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 804 may be performed by a UE as described with reference to Figure 5.
[0109] At 806, the method may include initiating handover execution to the target cell. The operations of 806 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 806 may be performed a UE as described with reference to Figure 5.
[0110] At 808, the method may include deriving one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM. The operations of 808 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 808 may be performed a UE as described with reference to Figure 5.
[0111] At 810, the method may include transmitting a handover complete message to the target cell using the derived one or more security keys. The operations of 810 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 810 may be performed a UE as described with reference to Figure 5.
[0112] Figure 9 illustrates a flowchart of a method 900 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0113] At 902, the method may include transmitting, to a UE, a first message including candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity. The operations of 902 may be performed in accordance with examples asdescribed herein. In some implementations, aspects of the operations of 902 may be performed by a NE as described with reference to Figure 7.
[0114] At 904, the method may include transmitting LTM including the at least one candidate cell and an index value for a next hop chaining counter in LTM. The operations of 904 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 904 may be performed by a NE as described with reference to Figure 7.
[0115] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
CLAIMSWhat is claimed is:
1. A user equipment (UE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the UE to: receive, from a serving cell, a first message comprising candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; receive Layer 1 / Layer 2 Triggered Mobility (LTM) for the at least one candidate cell and designate the at least one candidate cell as a target cell; initiate handover execution to the target cell; derive one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmit a handover complete message to the target cell using the derived one or more security keys.
2. The UE of claim 1, wherein the UE radio network identity comprises a Cell Radio Network Temporary Identifier (C-RNTI).
3. The UE of claim 1, wherein the first message comprises a Layer 3 (L3) Radio Resource Control (RRC) reconfiguration message.
4. The UE of claim 1, wherein the LTM comprises a lower layer mobility command message.
5. The UE of claim 1, wherein the LTM comprises identification for the target cell, timing advance for use by the target cell, and an index pointing to the next hop chaining counter for use for security protection of transmission of the handover complete message.
6. The UE of claim 1 , wherein the handover complete message comprises a Layer 3 (L3) Radio Resource Control (RRC) reconfiguration complete message.
7. A network equipment (NE) for wireless communication, comprising: at least one memory; and at least one processor coupled with the at least one memory and operable to cause the NE to: transmit, to a user equipment (UE), a first message comprising candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmit Layer 1 / Layer 2 Triggered Mobility (LTM) comprising the at least one candidate cell and an index value for a next hop chaining counter in LTM.
8. The NE of claim 7, wherein the UE radio network identity comprises a Cell Radio Network Temporary Identifier (C-RNTI).
9. The NE of claim 7, wherein the first message comprises a Layer 3 (L3) Radio Resource Control (RRC) reconfiguration message.
10. The NE of claim 7, wherein the LTM comprises a lower layer mobility command message.
11. The NE of claim 7, wherein the LTM comprises identification of the at least one candidate cell, timing advance for use by the at least one candidate cell, and an index pointing to the next hop chaining counter for use for security protection.
12. A method performed by a user equipment (UE), the method comprising: receiving, from a serving cell, a first message comprising candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; receiving Layer 1 / Layer 2 Triggered Mobility (LTM) for the at least one candidate cell and designating the at least one candidate cell as a target cell; initiating handover execution to the target cell;deriving one or more security keys using information received in the first message and an index value for a next hop chaining counter in the LTM; and transmitting a handover complete message to the target cell using the derived one or more security keys.
13. The method of claim 12, wherein the UE radio network identity comprises a Cell Radio Network Temporary Identifier (C-RNTI).
14. The method of claim 12, wherein the first message comprises a Layer 3 (L3) Radio Resource Control (RRC) reconfiguration message.
15. The method of claim 12, wherein the LTM comprises a lower layer mobility command message.
16. The method of claim 12, wherein the LTM comprises identification for the target cell, timing advance for use by the target cell, and an index pointing to the next hop chaining counter for use for security protection of transmission of the handover complete message.
17. The method of claim 12, wherein the handover complete message comprises a Layer 3 (L3) Radio Resource Control (RRC) reconfiguration complete message.
18. A method performed by a network equipment (NE), the method comprising: transmitting, to a user equipment (UE), a first message comprising candidate cell configuration including security configuration for at least one candidate cell and a UE radio network identity; and transmitting Layer 1 / Layer 2 Triggered Mobility (LTM) comprising the at least one candidate cell and an index value for a next hop chaining counter in LTM.
19. The method of claim 18, wherein the UE radio network identity comprises a Cell Radio Network Temporary Identifier (C-RNTI).
20. The method of claim 18, wherein the first message comprises a Layer 3 (L3) RadioResource Control (RRC) reconfiguration message.
Citation Information
Patent Citations
Key updating method, equipment and system for switching base station eNB in LTE (Long Term Evolution) system
CN101772100A
Packet data convergence protocol (PDCP) placement
WO2014113686A2
Method for controlling cell change operation, and device thereof
WO2023128730A1
NR mobility – security considerations for l1 / l2 mobility switching of an spcell
WO2024031042A1