Method, device, and system for LTM handover in wireless networks
LTM handover in wireless networks addresses latency and disruption issues by implementing Layer 1/Layer 2 mobility with inter-base station transitions and enhanced security, ensuring seamless and secure connectivity across diverse scenarios.
Patent Information
- Application Number
- PCT/CN2024/078950
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-28
- Publication Date
- 2025-07-31
AI Technical Summary
Existing wireless networks face challenges in achieving low-latency and seamless handovers, particularly in scenarios involving inter-base station mobility, which can lead to increased latency and disruption due to the involvement of multiple network layers and lack of explicit security mechanisms.
The implementation of Layer 1/Layer 2 Triggered Mobility (LTM) handover mechanisms, including inter-base station and inter-CU handovers, with added security measures such as vertical and horizontal key derivations to ensure seamless and secure transitions between cells.
LTM handover reduces latency and ensures uninterrupted connectivity by proactively managing handovers, optimizing network performance, and enhancing security through explicit key management during inter-base station transitions.
Smart Images

Figure CN2024078950_31072025_PF_FP_ABST
Abstract
Description
METHOD, DEVICE, AND SYSTEM FOR LTM HANDOVER IN WIRELESS NETWORKSTECHNICAL FIELD
[0001] This disclosure is directed generally to wireless communications, and particularly to a method, device, and system for inter base station, or inter Central Unit (CU) Layer 1 / Layer 2 Triggered Mobility (LTM) handover in a wireless network.BACKGROUND
[0002] Low latency handover in a wireless network is essential to meet the stringent requirements of various services and support emerging applications that depend on real-time communication, autonomous vehicles, and industrial automation that require ultra-responsive connectivity. By implementing fast, efficient, and secure handover mechanisms, wireless network may deliver seamless mobility and ensure consistent user experience across diverse use cases.SUMMARY
[0003] This disclosure is directed to a method, device, and system for energy consumption management in a wireless network, such as 3G, 4G, 5G, or 6G wireless network. More specifically, the energy consumption management includes power consumption measurement configuration, power consumption measuring and reporting.
[0004] In some embodiments, a method performed by a wireless device is disclosed. The method may include: receiving, from a first network element, a first message carrying at least one of: an LTM (Layer 1 / Layer 2 Triggered Mobility) configuration of a second network element, wherein the second network element is an LTM candidate for handing over the wireless device from the first network element in an LTM handover; or a first Next Hop Chaining Counter (NCC) associated with the LTM candidate configuration.
[0005] In some embodiments, a method performed by a first network element is disclosed. The method may include: transmitting, to a wireless device, a first message carrying at least one of: an LTM configuration of a second network element, wherein the second network element is an LTM candidate for handing over the wireless device from the first network element in an LTM handover; or a first NCC associated with the LTM candidate configuration.
[0006] In some embodiments, there is a network element, a network node, or a wireless transmit / receive unit (WTRU) comprising a processor and a memory, wherein the processor is configured to read code from the memory and implement any methods recited in any of the embodiments.
[0007] In some embodiments, a computer program product comprising a computer-readable program medium code stored thereupon, the code, when executed by a processor, causing the processor to implement any method recited in any of the embodiments.
[0008] The above embodiments and other aspects and alternatives of their implementations are described in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] FIG. 1 shows an example wireless communication network.
[0010] FIG. 2 shows an example wireless network node.
[0011] FIG. 3 shows an example user equipment.
[0012] FIG. 4 shows an example LTM procedure without base station key update.
[0013] FIG. 5 shows an example LTM procedure using vertical key derivation.
[0014] FIG. 6 shows an example LTM procedure using horizontal key derivation.DETAILED DESCRIPTION
[0015] Wireless Communication Network
[0016] FIG. 1 shows an exemplary wireless communication network 100 that includes a core network 110 and a radio access network (RAN) 120. The core network 110 further includes at least one Mobility Management Entity (MME) 112 and / or at least one Access and Mobility Management Function (AMF) . Other functions that may be included in the core network 110 are not shown in FIG. 1. The RAN 120 further includes multiple base stations, for example, base stations 122 and 124. The base stations may include at least one evolved NodeB (eNB) for 4G LTE, an enhanced LTE eNB (ng-eNB) , or a Next generation NodeB (gNB) for 5G New Radio (NR) , or any other type of signal transmitting / receiving device such as a UMTS NodeB. The eNB 122 communicates with the MME 112 via an S1 interface. Both the eNB 122 and gNB 124 may connect to the AMF 114 via an Ng interface. Each base station manages and supports at least one cell. For example, the base station gNB 124 may be configured to manage and support cell 1, cell 2, and cell 3.
[0017] The gNB 124 may include a central unit (CU) and at least one distributed unit (DU) . The CU and the DU may be co-located in a same location, or they may be split in different locations. The CU and the DU may be connected via an F1 interface. Alternatively, for an eNB which is capable of connecting to the 5G network, it may also be similarly divided into a CU and at least one DU, referred to as ng-eNB-CU and ng-eNB-DU, respectively. The ng-eNB-CU and the ng-eNB-DU may be connected via a W1 interface.
[0018] The wireless communication network 100 may include one or more tracking areas. A tracking area may include a set of cells managed by at least one base station. For example, tracking area 1 labeled as 140 includes cell 1, cell 2, and cell 3, and may further include more cells that may be managed by other base stations and not shown in FIG. 1. The wireless communication network 100 may also include at least one UE 160. The UE may select a cell among multiple cells supported by a base station to communication with the base station through Over the Air (OTA) radio communication interfaces and resources, and when the UE 160 travels in the wireless communication network 100, it may reselect a cell for communications. For example, the UE 160 may initially select cell 1 to communicate with base station 124, and it may then reselect cell 2 at certain later time point. The cell selection or reselection by the UE 160 may be based on wireless signal strength / quality in the various cells and other factors.
[0019] The wireless communication network 100 may be implemented as, for example, a 2G, 3G, 4G / LTE, or 5G cellular communication network. Correspondingly, the base stations 122 and 124 may be implemented as a 2G base station, a 3G NodeB, an LTE eNB, or a 5G NR gNB. The UE 160 may be implemented as mobile or fixed communication devices which are capable of accessing the wireless communication network 100. The UE 160 may include but is not limited to mobile phones, laptop computers, tablets, personal digital assistants, wearable devices, Internet of Things (IoT) devices, MTC / eMTC devices, distributed remote sensor devices, roadside assistant equipment, XR devices, and desktop computers. The UE 160 may also be generally referred to as a wireless communication device, or a wireless terminal. The UE 160 may support sidelink communication to another UE via a PC5 interface.
[0020] While the description below focuses on cellular wireless communication systems as shown in FIG. 1, the underlying principles are applicable to other types of wireless communication systems for paging wireless devices. These other wireless systems may include but are not limited to Wi-Fi, Bluetooth, ZigBee, and WiMax networks.
[0021] FIG. 2 shows an example of electronic device 200 to implement a network base station (e.g., a radio access network node) , a core network (CN) , and / or an operation and maintenance (OAM) . Optionally in one implementation, the example electronic device 200 may include radio transmitting / receiving (Tx / Rx) circuitry 208 to transmit / receive communication with UEs and / or other base stations. Optionally in one implementation, the electronic device 200 may also include network interface circuitry 209 to communicate the base station with other base stations and / or a core network, e.g., optical or wireline interconnects, Ethernet, and / or other data transmission mediums / protocols. The electronic device 200 may optionally include an input / output (I / O) interface 206 to communicate with an operator or the like.
[0022] The electronic device 200 may also include system circuitry 204. System circuitry 204 may include processor (s) 221 and / or memory 222. Memory 222 may include an operating system 224, instructions 226, and parameters 228. Instructions 226 may be configured for the one or more of the processors 221 to perform the functions of the network node. The parameters 228 may include parameters to support execution of the instructions 226. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.
[0023] FIG. 3 shows an example of an electronic device to implement a terminal device 300 (for example, a user equipment (UE) ) . The UE 300 may be a mobile device, for example, a smart phone or a mobile communication module disposed in a vehicle. The UE 300 may include a portion or all of the following: communication interfaces 302, a system circuitry 304, an input / output interfaces (I / O) 306, a display circuitry 308, and a storage 309. The display circuitry may include a user interface 310. The system circuitry 304 may include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 304 may be implemented, for example, with one or more systems on a chip (SoC) , application specific integrated circuits (ASIC) , discrete analog and digital circuits, and other circuitry. The system circuitry 304 may be a part of the implementation of any desired functionality in the UE 300. In that regard, the system circuitry 304 may include logic that facilitates, as examples, decoding and playing music and video, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user inputs; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections for, as one example, internet connectivity; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 310. The user interface 310 and the inputs / output (I / O) interfaces 306 may include a graphical user interface, touch sensitive display, haptic feedback or other haptic output, voice or facial recognition inputs, buttons, switches, speakers and other user interface elements. Additional examples of the I / O interfaces 306 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors) , and other types of inputs.
[0024] Referring to FIG. 3, the communication interfaces 302 may include a Radio Frequency (RF) transmit (Tx) and receive (Rx) circuitry 316 which handles transmission and reception of signals through one or more antennas 314. The communication interface 302 may include one or more transceivers. The transceivers may be wireless transceivers that include modulation / demodulation circuitry, digital to analog converters (DACs) , shaping tables, analog to digital converters (ADCs) , filters, waveform shapers, filters, pre-amplifiers, power amplifiers and / or other logic for transmitting and receiving through one or more antennas, or (for some devices) through a physical (e.g., wireline) medium. The transmitted and received signals may adhere to any of a diverse array of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM) , frequency channels, bit rates, and encodings. As one specific example, the communication interfaces 302 may include transceivers that support transmission and reception under the 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS) , High Speed Packet Access (HSPA) +, 4G / Long Term Evolution (LTE) , 5G (also referred to as New Radio, or 5G NR) , and 6G standards. The techniques described below, however, are applicable to other wireless communications technologies whether arising from the 3rd Generation Partnership Project (3GPP) , GSM Association, 3GPP2, IEEE, or other partnerships or standards bodies.
[0025] Referring to FIG. 3, the system circuitry 304 may include one or more processors 321 and memories 322. The memory 322 stores, for example, an operating system 324, instructions 326, and parameters 328. The processor 321 is configured to execute the instructions 326 to carry out desired functionality for the UE 300. The parameters 328 may provide and specify configuration and operating options for the instructions 326. The memory 322 may also store any BT, WiFi, 3G, 4G, 5G, 6G or other data that the UE 300 will send, or has received, through the communication interfaces 302. In various implementations, a system power for the UE 300 may be supplied by a power storage device, such as a battery or a transformer.
[0026] Layer 1 / Layer 2 Triggered Mobility (LTM)
[0027] In wireless communication, various types of handovers are supported. Traditionally, a handover is triggered by at Layer 3 (L3) , for example, via L3 measurement, and is signaled by Radio Resource Control (RRC) signaling. Due to the number of layers involved, L3 handover may experience longer latency and longer interruption compared with a handover triggered / handled at lower layer.
[0028] Layer 1 / Layer 2 Triggered Mobility (LTM, also known as Lower layer Triggered Mobility) ) is a mechanism that facilitates seamless handover or mobility between different cells. It may operate at both Layer 1 and Layer 2.
[0029] At Layer 1, LTM monitors the radio signal strength and quality of neighboring cells. When the signal strength of the current cell degrades below a certain threshold or when the quality of the neighboring cells exceeds a predefined level, LTM triggers a handover.
[0030] At Layer 2, LTM initiates the handover procedure by coordinating with the network's radio resource management (RRM) system. It exchanges signaling messages with the network to negotiate configuration parameters for the handover, such as target cell selection, target cell configuration, timing, and resource allocation.
[0031] LTM aims to ensure uninterrupted connectivity and seamless mobility for users as they move within the coverage area of the wireless network. By proactively detecting and responding to changes in radio conditions, LTM helps optimize network performance and reduce handover latency.
[0032] In current LTM implementation, the handover is limited to intra base station. For example, the base station may be a gNB, and the LTM handover is intra-CU handover. Security and integrity protection mechanisms, such as encryption and authentication, are not explicitly applied to the LTM handover process.
[0033] In this disclosure, various embodiments are introduced for implementing inter base station LTM handover, such as inter-CU LTM handover. Specifically, security mechanisms are added in such implementations.
[0034] LTM Signaling Procedure
[0035] FIG. 4 illustrates an example LTM procedure. In FIG. 4, a gNB is used for exemplary purpose, and other types of base stations, such an eNB, ng-eNB, or a base station for future generation (such as 6G) may also apply. The LTM procedure may include following steps:
[0036] Step 1. The UE sends a MeasurementReport message to the gNB. The gNB decides to configure LTM and initiates LTM preparation.
[0037] Step 2. The gNB transmits an RRCReconfiguration message to the UE including the configuration of one or more LTM candidate target cells (hereinafter also referred to as candidate cells) . Note that the one or more LTM candidate target cells may reside in one or more target gNBs.
[0038] Step 3. The UE stores the configuration for the one or more LTM candidate target cells, and transmits an RRCReconfigurationComplete message to the gNB.
[0039] Step 4a. The UE may perform preparation for potential LTM handover. For example, UE performs downlink (DL) synchronization with the candidate cell (s) before receiving the LTM cell switch command.
[0040] Step 4b. When UE-based Timing Advance (TA) measurement is configured, UE acquires the TA value (s) of the candidate cell (s) by measurement. UE performs early TA acquisition with the candidate cell (s) as requested by the network before receiving the cell switch command. This may be done via a Contention Free Random Access (CFRA) triggered by a Physical Downlink Control Channel (PDCCH) order from the source cell (which is in the source gNB) , following which the UE sends a preamble towards the indicated candidate cell. In order to minimize the data interruption of the source cell due to CFRA towards the candidate cell (s) , the UE does not receive random access response from the network for the purpose of TA value acquisition, and the TA value of the candidate cell is indicated in the cell switch command. The UE does not maintain the TA timer for the candidate cell and relies on network implementation to guarantee the TA validity.
[0041] Step 5. The UE performs Layer 1 (L1) measurements on the configured candidate cell (s) and transmits L1 measurement reports to the gNB. L1 measurement may need to be performed as long as RRC reconfiguration (step 2) is applicable.
[0042] Step 6. The gNB decides to execute cell switch to a target cell (among the candidate cells) and transmits a Medium Access Control -Control Element (MAC CE) triggering cell switch by including, for example, a candidate configuration index of the target cell. The candidate configuration index may serve as an index for looking up a configuration for the target cell from the configuration of the one or more LTM candidate target cells. The UE switches to the target cell and applies the configuration indicated by candidate configuration index.
[0043] Step 7. The UE performs the Random Access (RA) procedure towards the target cell, if UE does not have valid TA of the target cell.
[0044] Step 8. The UE completes the LTM cell switch procedure by sending RRCReconfigurationComplete message to target cell. If the UE has performed an RA procedure in step 7, the UE considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM (i.e., LTM not using an RA procdure) , the UE considers that LTM cell switch execution is successfully completed when the UE determines that the network has successfully received its first UL data.
[0045] Steps 4-8 may be performed multiple times for subsequent LTM using the LTM candidate configuration (s) provided in step 2.
[0046] The above procedure may be applicable to both intra-gNB-DU LTM and inter-gNB-DU LTM.
[0047] Inter-CU LTM: Vertical Key Derivation
[0048] In this embodiment, the LTM handover is an inter type, which may include, for example, inter base station, or inter-CU. When the UE is handover to a target cell of a base station different from the source base station, a vertical key derivation is performed, to derive an intermediate key, KNG-RAN* (also known as negotiation key) between the UE and the target base station. In vertical key derivation, a Next Hop (NH) parameter is used, in conjunction with a Next Hop Chaining Counter (NCC) . The vertical key derivation may further use target PCI of the target cell, and its frequency ARFCN-DL / EARFCN-DL as input.
[0049] FIG. 5 illustrate an exemplary inter-CU LTM handover procedure based on vertical key derivation. In FIG. 5, a gNB is used for exemplary purpose, and other types of base stations, such an eNB, ng-eNB, or a base station for future generation (such as 6G) may also apply. The LTM procedure may include following steps:
[0050] Step 1. The UE sends a MeasurementReport message to the source gNB. The source gNB decides to configure LTM and initiates LTM preparation.
[0051] Step 2. The source gNB issues a Handover Request message to one or more candidate cells belonging to one or more candidate gNBs. The Handover Request passing a transparent RRC container with necessary information to prepare the handover at the target side. Keys for the target gNBs are not derived and not sent to the target gNB (s) .
[0052] In this step, Admission Control may be performed by the target gNB (s) .
[0053] Step 3. The target gNB prepares the handover with L1 / L2 (i.e., the preparation may be performed at L1 / L2 level) , and sends a HANDOVER REQUEST ACKNOWLEDGE to the source gNB, which includes a transparent container to be sent to the UE as an RRC message to perform the handover.
[0054] Step 4. The source gNB transmits a message, such as an RRCReconfiguration message to the UE including the LTM configurations for candidate target cells. The gNB may also include the NCC into the message. Note that the NCC is the currently NCC maintained by the source gNB.
[0055] Step 5. The UE stores the LTM configurations for candidate target cells and the corresponding NCC, and responds with, for example, an RRCReconfigurationComplete message to the source gNB.
[0056] Step 6a. The UE performs Downlink (DL) synchronization with the candidate target cell (s) before receiving the cell switch command for LTM handover.
[0057] Step 6b. When UE-based TA measurement is configured, UE acquires the TA value (s) of the candidate cell (s) by measurement. UE performs early TA acquisition with the candidate cell (s) as requested by the network before receiving the cell switch command. This may be achieved via, for exampole, CFRA triggered by a PDCCH order from the source cell (in the source gNB) , following which the UE sends preamble towards the indicated candidate target cell (s) . In order to minimize the data interruption of the source cell due to CFRA towards the candidate target cell (s) , the UE does not receive random access response from the network for the purpose of TA value acquisition and the TA value of the candidate target cell (s) is indicated in the later cell switch command. The UE does not maintain the TA timer for the candidate target cell (s) and relies on network implementation to guarantee the TA validity.
[0058] Step 7. The UE performs L1 (and / or L2) measurements on the configured candidate cell (s) and transmits L1 measurement reports to the gNB. L1 (and / or L2) measurement should be performed as long as RRC reconfiguration (step 4) is applicable.
[0059] Step 8. The source gNB decides to execute LTM. The source gNB may perform key update if the target cell lies in a different gNB from the source gNB, i.e., the LTM handover is and inter type (e.g., inter-CU handover, or inter base station handover) . That is, if the source gNB determines that the LTM handover is inter type (inter base station, or inter-CU) , it may determine that key update is needed. The source gNB may perform a vertical key derivation, to derive the intermediate key, KNG-RAN*, and forward the {KNG-RAN*, NCC} pair to the target gNB. The target gNB may use the received KNG-RAN*directly as KgNB to be used with the UE. The target gNB may also associate the received NCC value with the KgNB.
[0060] Step 9. The target gNB sends a response message, such as a Key Update Acknowledge to the source gNB.
[0061] Step 10. The gNB transmits a MAC CE triggering LTM cell switch by including the candidate configuration index of the target cell. The candidate configuration index may serve as an index for looking up a configuration for the target cell from the configurations for candidate target cells (described in step 4) . The gNB may also include the NCC in plain text into the message. For CU / DU split case, the source CU sends the NCC to the source DU through the F1 interface, and then the source DU encapsulates the NCC in the MAC CE. As soon as the UE receives the NCC, it compares the NCC value with its own NCC (or the NCC value received in Step 4) . UE’s own NCC is maintained / kept by the UE and is an active / current NCC associated with a currently active base station key (KgNB / KeNB) used by the wireless device. If the received NCC in this step is smaller than the NCC in UE (or the NCC received in Step 4) , it indicates that the message may have been tampered with (e.g., by Bidding-Down Attack) , and handover is canceled / aborted. If not, if the UE received an NCC value that was larger than the NCC maintained / kept by the UE, the UE may first synchronize the locally kept NH parameter with the network (e.g., core network) by, for example, computing an NH function iteratively and increasing the locally kept NCC value until it matches the received NCC. When the NCC values match, the UE may proceed to compute the intermediate key, KNG-RAN*from the synchronized NH parameter. If the UE received an NCC value that was the same as the locally kept NCC (which is associated with the currently active KgNB / KeNB) , the UE may compute the KNG-RAN*directly using the current NH parameters. The UE switches to the target cell and applies the configuration indicated by candidate configuration index.
[0062] Step 11. The UE performs the random access procedure towards the target cell, if UE does not have a valid TA of the target cell.
[0063] Step 12. The UE completes the LTM cell switch procedure by sending, for example, an RRCReconfigurationComplete message to target cell (in the target gNB) . If the UE has performed a RA procedure in step 11, the UE considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM (i.e., LTM with no random access involved) , the UE considers that LTM cell switch execution is successfully completed when the UE determines that the network has successfully received its first UL data.
[0064] Step 13. Path switch procedure between the target gNB, AMF and UPF.
[0065] Note that steps 6-13 may be performed multiple times for subsequent LTMs using the LTM candidate configuration (s) provided in step 4.
[0066] In this embodiment, during an inter-CU handover, the base station key (KgNB) to be used between the UE and target base station are updated on UE side and target base station side, using a vertical derivation method.
[0067] Inter-CU LTM: Horizontal Key Derivation
[0068] In this embodiment, the LTM handover is an inter type, which may include, for example, inter base station, or inter-CU. When the UE is handover to a target cell of a base station different from the source base station, a horizontal key derivation is performed, to derive an intermediate key, KNG-RAN* (also known as negotiation key) between the UE and the target base station. In horizontal key derivation, the current base station key, KGNB is used. The horizontal key derivation may further use PCI of target cell, and its frequency ARFCN-DL / EARFCN-DL as input.
[0069] FIG. 6 illustrate an exemplary inter-CU LTM handover procedure based on horizontal key derivation. In FIG. 6, a gNB is used for exemplary purpose, and other types of base stations, such an eNB, ng-eNB, or a base station for future generation (such as 6G) may also apply. The LTM procedure may include following steps:
[0070] Step 1. The UE sends a MeasurementReport message to the source gNB. The source gNB decides to configure LTM and initiates LTM preparation.
[0071] Step 2. The source gNB issues a Handover Request message to one or more candidate cells belonging to one or more candidate gNBs. The Handover Request passing a transparent RRC container with necessary information to prepare the handover at the target side. Keys for the target gNBs are not derived and not sent to the target gNB (s) .
[0072] In this step, Admission Control may be performed by the target gNB (s) .
[0073] Step 3. The target gNB prepares the handover with L1 / L2 (i.e., the preparation may be performed at L1 / L2 level) , and sends a HANDOVER REQUEST ACKNOWLEDGE to the source gNB, which includes a transparent container to be sent to the UE as an RRC message to perform the handover.
[0074] Step 4. The source gNB transmits a message, such as an RRCReconfiguration message to the UE including the LTM configurations for candidate target cells.
[0075] Step 5. The UE stores the LTM configurations for candidate target cells, and responds with, for example, an RRCReconfigurationComplete message to the source gNB.
[0076] Step 6a. The UE performs Downlink (DL) synchronization with the candidate target cell (s) before receiving the cell switch command for LTM handover.
[0077] Step 6b. When UE-based TA measurement is configured, UE acquires the TA value (s) of the candidate cell (s) by measurement. UE performs early TA acquisition with the candidate cell (s) as requested by the network before receiving the cell switch command. This may be achieved via, for exampole, CFRA triggered by a PDCCH order from the source cell (in the source gNB) , following which the UE sends preamble towards the indicated candidate target cell (s) . In order to minimize the data interruption of the source cell due to CFRA towards the candidate target cell (s) , the UE does not receive random access response from the network for the purpose of TA value acquisition and the TA value of the candidate target cell (s) is indicated in the later cell switch command. The UE does not maintain the TA timer for the candidate target cell (s) and relies on network implementation to guarantee the TA validity.
[0078] Step 7. The UE performs L1 (and / or L2) measurements on the configured candidate cell (s) and transmits L1 measurement reports to the gNB. L1 (and / or L2) measurement should be performed as long as RRC reconfiguration (step 4) is applicable.
[0079] Step 8. The source gNB decides to execute LTM. The source gNB may perform key update if the target cell lies in a different gNB from the source gNB, i.e., the LTM handover is and inter type (e.g., inter-CU handover, or inter base station handover) . The source gNB may perform a horizontal key derivation, to derive the intermediate key, KNG-RAN*, and forward the {KNG-RAN*, NCC} pair to the target gNB. The target gNB may use the received KNG-RAN*directly as KgNB to be used with the UE. The target gNB may also associate the received NCC value with the KgNB.
[0080] Step 9. The target gNB sends a response message, such as a Key Update Acknowledge to the source gNB.
[0081] Step 10. The source gNB may transmit a MAC CE triggering LTM cell switch by including the candidate configuration index of the target cell. As soon as the UE receives the cell switch command, if the UE determines that the security key updated is required (e.g., for inter-CU LTM) , it computes KNG-RAN*from currently active KgNB, by using horizontal key derivation. The UE then switches to the target cell and applies the configuration indicated by candidate configuration index.
[0082] Step 11. The UE performs the random access procedure towards the target cell, if UE does not have a valid TA of the target cell.
[0083] Step 12. The UE completes the LTM cell switch procedure by sending, for example, an RRCReconfigurationComplete message to target cell (in the target gNB) . If the UE has performed a RA procedure in step 11, the UE considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM (i.e., LTM with no random access involved) , the UE considers that LTM cell switch execution is successfully completed when the UE determines that the network has successfully received its first UL data.
[0084] Step 13. Path switch procedure between the target gNB, AMF and UPF.
[0085] Note that steps 6-13 may be performed multiple times for subsequent LTMs using the LTM candidate configuration (s) provided in step 4.
[0086] In this embodiment, during an inter-CU handover, the base station key (KgNB) to be used between the UE and target base station are updated on UE side and target base station side, using a horizontal derivation method.
[0087] A method according to embodiments in this disclosure includes a portion or all of the following steps: step 1: receiving, from a first network element, a first message carrying at least one of: an LTM configuration of a second network element, wherein the second network element is an LTM candidate for handing over the wireless device from the first network element in an LTM handover; or a first NCC associated with the LTM candidate configuration.
[0088] In any portion or combination of the implementations above, the first network element may include a base station, including a gNB, an eNB, an ng-eNB, etc.
[0089] In any portion or combination of the implementations above, the LTM handover include an inter-CU, or inter base station handover.
[0090] The description and accompanying drawings above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.
[0091] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment / implementation” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.
[0092] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for the existence of additional factors not necessarily expressly described, again, depending at least in part on context.
[0093] Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.
[0094] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the present solution may be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.
Claims
1.A method for wireless communication, performed by a wireless device, comprising:receiving, from a first network element, a first message carrying at least one of:an LTM (Layer 1 / Layer 2 Triggered Mobility) configuration of a second network element, wherein the second network element is an LTM candidate for handing over the wireless device from the first network element in an LTM handover; ora first Next Hop Chaining Counter (NCC) associated with the LTM candidate configuration.2.The method of claim 1, wherein the first message comprises an RRCReconfiguration message.3.The method of claim 1, wherein the first network element comprises a source base station for the wireless device, and the second network element comprises a candidate target base station for the wireless device in the LTM handover.4.The method of claim 3, wherein the LTM handover comprises at least one of: an inter base station handover; or an inter Central Unit (CU) handover.5.The method of claim 1, wherein before receiving the first message, the method further comprises:transmitting, to the first network element, a measurement report used by the first network element to determine whether a preparation for the LTM handover is desired.6.The method of any one of claims 1-5, further comprising:receiving, from the first network element, a second message triggering the LTM handover and carrying a base station side NCC, wherein the base station side NCC is maintained by the first network element and updated by the first network element after deriving an intermediate base station key using a vertical derivation, wherein the intermediate base station key is used by the wireless device and the second network element during the LTM handover.7.The method of claim 6, wherein the vertical derivation is based on the base station side NCC, and wherein the base station side NCC is incremented after each vertical derivation.8.The method of claim 6, wherein the second message comprises a Medium Access Control –Control Element (MAC CE) .9.The method of any one of claims 6, wherein:the first network element comprises a CU and a Distributed Unit (DU) ; andreceiving the second message comprises receiving the second message from the DU of the first network element.10.The method of any one of claims 6-9, further comprising:in response to the base station side NCC being less than the first NCC, or in response to the base station side NCC being less than an active NCC associated with a currently active base station key used by the wireless device, cancelling or aborting the LTM handover.11.The method of any one of claims 6-9, further comprising in response to the base station side NCC being larger than an active NCC associated with a currently active base station key used by the wireless device:iteratively refreshing a Next Hop (NH) parameter locally kept by the wireless device, and incrementing the active NCC by 1 in each iteration, until the active NCC matches the base station side NCC; andderiving the intermediate base station key based on the synchronized NH parameter.12.The method of claim 11, wherein, once the active NCC matching the base station side NCC, the NH parameter locally kept by the wireless device is synchronized with the second network element.13.The method of claim 11, further comprising in response to the base station side NCC being equal to the active NCC, deriving the intermediate base station key based on the NH parameter locally kept by the wireless device.14.The method of any one of claims 11-13, further comprising:performing the LTM handover to switch to the second network element based on the intermediate base station key.15.The method of any one of claims 14, wherein:the second message further carries a configuration index, the configuration index being used to lookup a target cell configuration from the LTM configuration of the second network element; andperforming the LTM handover comprises:performing the LTM handover to switch to the second network element based on the intermediate base station key; andapplying the target cell configuration indicated by the configuration index.16.The method of claim 15, further comprising:transmitting a third message to the second network element, wherein the third message comprises an RRCReconfigurationComplete message.17.The method of any one of claims 1-5, further comprising:receiving, from the first network element, a fourth message triggering the LTM handover;deriving an intermediate base station key based on an active base station key associated with the first network element by using a horizontal derivation, wherein the intermediate base station key is used by the wireless device and the second network element during the LTM handover; andperforming the LTM handover to switch to the second network element based on the intermediate base station key.18.The method of claim 17, wherein deriving the intermediate base station key comprises:determining whether a base station key of the wireless device to be used with the second network element needs to be updated for the LTM handover; andin a determination that the base station key of the wireless device needs to be updated, deriving an intermediate base station key based on an active base station key associated with the first network element by using the horizontal derivation.19.The method of any one of claims 17, wherein:the first message further carries a configuration information for a target cell of the second network element; andperforming the LTM handover comprises:performing the LTM handover to switch to the second network element based on the intermediate base station key; andapplying a target cell configuration indicated by the configuration information.20.A method for wireless communication, performed by a first network element, comprising:transmitting, to a wireless device, a first message carrying at least one of:an LTM (Layer 1 / Layer 2 Triggered Mobility) configuration of a second network element, wherein the second network element is an LTM candidate for handing over the wireless device from the first network element in an LTM handover; ora first Next Hop Chaining Counter (NCC) associated with the LTM candidate configuration.21.The method of claim 20, wherein the first message comprises an RRCReconfiguration message.22.The method of claim 20, wherein the first network element comprises a source base station for the wireless device, and the second network element comprises a candidate target base station for the wireless device in the LTM handover.23.The method of claim 22, wherein the LTM handover comprises at least one of: an inter base station handover; or an inter Central Unit (CU) handover.24.The method of claim 20, wherein before transmitting the first message, the method further comprises:transmitting, to the second network element, a second message carrying handing over information for preparing the LTM handover, wherein the second message does not carry a base station key for the second network element.25.The method of claim 24, wherein the second message comprises a handover request message.26.The method of claim 20, wherein before receiving the first message, the method further comprises:receiving, from the wireless device, a measurement report used by the first network element to determine whether a preparation for the LTM handover is desired.27.The method of any one of claims 20-26, further comprising:deriving an intermediate base station key using a vertical derivation, wherein the intermediate base station key is used by the wireless device and the second network element during the LTM handover.28.The method of claim 27, wherein deriving the intermediate base station key comprises:determining that a base station key of the second network for the wireless device needs to be updated for the LTM handover; andderiving the intermediate base station key using the vertical derivation.29.The method of claim 27, wherein the vertical derivation is based on a base station side NCC maintained by the first network element, and wherein the base station side NCC is incremented after each base station key vertical derivation.30.The method of claim 29, further comprising:transmitting, to the second network element, the intermediate base station key and the base station side NCC, wherein the second network element considers the intermediate base station key to be an active base station key associated with the wireless device for the LTM handover, and the second network element associates the base station side NCC with the active base station key associated with the wireless device.31.The method of any one of claims 29-30, further comprising:transmitting, to the wireless device, a third message triggering the LTM handover and carrying the base station side NCC, wherein the base station side NCC is used by the wireless device to determine the intermediate base station key.32.The method of claim 31, wherein the third message comprises a Medium Access Control –Control Element (MAC CE) .33.The method of any one of claims 31, wherein:the first network element comprises a CU and a Distributed Unit (DU) ; andtransmitting the third message comprises transmitting the third message from the DU of the first network element to the wireless device.34.The method of any one of claims 31-33, wherein the third message further carries a configuration index, the configuration index being used to lookup a target cell configuration from the LTM configuration of the second network element.35.The method of any one of claims 20-26, further comprising:deriving an intermediate base station key based on an active base station key associated with the wireless device by using a horizontal derivation, wherein the intermediate base station key is used by the wireless device and the second network element during the LTM handover.36.The method of claim 27, wherein deriving the intermediate base station key comprises:determining that a base station key of the second network for the wireless device needs to be updated for the LTM handover; andderiving the intermediate base station key using the horizontal derivation.37.The method of claim 35, further comprising:transmitting, to the second network element, the intermediate base station key and on a base station side NCC maintained by the first network element, wherein the second network element considers the intermediate base station key to be an active base station key associated with the wireless device for the LTM handover, and the second network element associates the base station side NCC with the active base station key associated with the wireless device.38.The method of any one of claims 35-37, further comprising:transmitting, to the wireless device, a fourth message triggering the LTM handover, wherein the fourth message triggers the wireless device to deriving the intermediate base station key based on an active base station key associated with the first network element by using a horizontal derivation.39.The method of claim 38, wherein the fourth message comprises a MAC CE message.40.A device for wireless communication comprising a memory for storing computer instructions and a processor in communication with the memory, wherein, when the processor executes the computer instructions, the processor is configured to implement a method in any one of claims 1-39.41.A computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement a method of any one of claims 1-39.
Citation Information
Patent Citations
Methods and nodes for performing a handover at resume
CN113196863A
Method and device for determining reference signal of candidate cell and storage medium
CN116965098A
COMMUNICATION METHOD, NODE, AND USER EQUIPMENT
JP7408030B1
NR mobility – security considerations for l1 / l2 mobility switching of an spcell
WO2024031042A1
Enabling layer 1 and layer 2 mobility
WO2024031044A1