Handling security keys for inter-centralized unit layer triggered mobility in mobility network
By employing MAC CEs with ciphering and integrity protection to transmit NCC information, the patent addresses security key handling in inter-CU LTM, ensuring secure and efficient mobility without RRC signaling, thus maintaining key confidentiality and mobility integrity.
Patent Information
- Application Number
- PCT/CN2024/076109
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-05
- Publication Date
- 2025-08-14
AI Technical Summary
Existing wireless communication systems face challenges in securely handling security keys during inter-centralized unit (CU) layer triggered mobility (LTM) switches, particularly in scenarios where Radio Resource Control (RRC) signaling is bypassed, leading to potential security concerns and the need for protected transmission of Next Hop Chaining Count (NCC) information.
The use of Media Access Control (MAC) Control Elements (CE) to transmit NCC information, combined with ciphering and integrity protection, ensures secure inter-CU LTM by allowing the UE to derive security keys without direct RRC signaling, using index values to protect the actual NCC values, and maintaining security key confidentiality across network nodes.
This approach ensures secure and efficient inter-CU LTM by protecting NCC information, preventing source CUs from knowing future network node keys, thus maintaining security integrity and enabling seamless mobility without RRC signaling overhead.
Smart Images

Figure CN2024076109_14082025_PF_FP_ABST
Abstract
Description
HANDLING SECURITY KEYS FOR INTER-CENTRALIZED UNIT LAYER TRIGGERED MOBILITY IN MOBILITY NETWORKTECHNICAL FIELD
[0001] This application relates generally to wireless communication systems, including security keys for inter-CU LTM switches using MAC CEs.BACKGROUND
[0002] Wireless mobile communication technology uses various standards and protocols to transmit data between a base station and a wireless communication device. Wireless communication system standards and protocols can include, for example, 3rd Generation Partnership Project (3GPP) Long Term Evolution (LTE) (e.g., 4G) , 3GPP New Radio (NR) (e.g., 5G) , and Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard for Wireless Local Area Networks (WLAN) (commonly known to industry groups as ) .
[0003] As contemplated by the 3GPP, different wireless communication systems'standards and protocols can use various radio access networks (RANs) for communicating between a base station of the RAN (which may also sometimes be referred to generally as a RAN node, a network node, or simply a node) and a wireless communication device known as a user equipment (UE) . 3GPP RANs can include, for example, Global System for Mobile communications (GSM) , Enhanced Data Rates for GSM Evolution (EDGE) RAN (GERAN) , Universal Terrestrial Radio Access Network (UTRAN) , Evolved Universal Terrestrial Radio Access Network (E-UTRAN) , and / or Next-Generation Radio Access Network (NG-RAN) .
[0004] Each RAN may use one or more radio access technologies (RATs) to perform communication between the base station and the UE. For example, the GERAN implements GSM and / or EDGE RAT, the UTRAN implements Universal Mobile Telecommunication System (UMTS) RAT or other 3GPP RAT, the E-UTRAN implements LTE RAT (sometimes simply referred to as LTE) , and NG-RAN implements NR RAT (sometimes referred to herein as 5G RAT, 5G NR RAT, or simply NR) . In certain deployments, the E-UTRAN may also implement NR RAT. In certain deployments, NG-RAN may also implement LTE RAT.
[0005] A base station used by a RAN may correspond to that RAN. One example of an E-UTRAN base station is an Evolved Universal Terrestrial Radio Access Network (E-UTRAN) Node B (also commonly denoted as evolved Node B, enhanced Node B, eNodeB, or eNB) . One example of an NG-RAN base station is a next generation Node B (also sometimes referred to as a g Node B or gNB) .
[0006] A RAN provides its communication services with external entities through its connection to a core network (CN) . For example, E-UTRAN may utilize an Evolved Packet Core (EPC) while NG-RAN may utilize a 5G Core Network (5GC) .
[0007] BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
[0008] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.
[0009] FIG. 1 illustrates a flow chart of legacy inter-CU handover security dynamics in accordance with some embodiments.
[0010] FIG. 2 illustrates an example MAC CE for sending NCC information in accordance with some embodiments
[0011] FIG. 3 illustrates an example LTM configuration RRC message in accordance with some embodiments.
[0012] FIG. 4 illustrates an example an LTM configuration element for LTM candidate NCC in accordance with some embodiments.
[0013] FIG. 5 illustrates a signal flow diagram for an inter-CU LTM cell switch in accordance with some embodiments.
[0014] FIG. 6 illustrates a method of operation for a UE in accordance with some embodiments.
[0015] FIG. 7 illustrates a method of operation for a network node in accordance with some embodiments.
[0016] FIG. 8 illustrates an example architecture of a wireless communication system, according to embodiments disclosed herein.
[0017] FIG. 9 illustrates a system for performing signaling between a wireless device and a network device, according to embodiments disclosed herein.DETAILED DESCRIPTION
[0018] Various embodiments are described with regard to a UE. However, reference to a UE is merely provided for illustrative purposes. The example embodiments may be utilized with any electronic component that may establish a connection to a network and is configured with the hardware, software, and / or firmware to exchange information and data with the network. Therefore, the UE as described herein is used to represent any appropriate electronic component.
[0019] Layer triggered mobility (LTM) refers to the use of lower layers, such as layer 2, for triggering mobility. Traditionally mobility has been Layer 3 based, and is done via radio resource control (RRC) signaling. It may be desirable for triggering mobility procedures directly at the physical (PHY) and media access control (MAC) layers of the 5G network, bypassing the higher-level radio RRC signaling. In 3GPP Release 18, there was a feature developed that allowed layer 2 to be used for mobility, but the feature was limited to one centralized unit (CU) . A target of future 3GPP releases is to support inter-CU LTM in the mobility network (MN) .
[0020] In Release 19, one objective is to specify support for inter-CU Layer 2 (L2) Mobility (LTM) . A case that may be desired to be supported is when CU is acting as MN when dual connectivity (DC) is not configured. Another case that may be desired to be supported is when new radio-DC (NR-DC) is configured and CU is acting as Secondary Node (SN) and Master Cell Group (MCG) is unchanged. Another case that may be desired to be supported is when NR-DC is configured, CU is acting as MN and SCG is unchanged or SCG is released.
[0021] To support these cases LTM mobility procedures that avoid RRC configuration between cell switches as per Release-18 LTM should be specified. For example, procedures need to be developed with respect to security key handling. Embodiments herein provide procedures for security key handling for inter-CU LTM in MN.
[0022] Security keys in Release 18 LTM may be handled as follows. In L2, MAC CE, may trigger the LTM switch. When the CU remains the same, there is no change in security keys or context, and no change in the Packet Data Convergence Protocol (PDCP) . The switch can be inter-Distributed Unit (DU) (e.g., radio link control (RLC) and medium access control (MAC) reset) or intra-DU (e.g., MAC reset alone) . In this case the UE knows in advance. The UE can confirm the L2 trigger with a L3 RRC message (RRCReconfigComplete) . No RRC messages to the UE may be expected between LTM cell switches, even for subsequent LTM switches. Instead, an LTM MAC CE trigger can be used.
[0023] FIG. 1 illustrates a flow chart 102 of legacy inter-CU handover security dynamics. The flow chart 102 illustrates inter-CU dynamics, or even dynamics in intra-CU where the network node intends a security context change. The security key is managed by the access and mobility management function (AMF) of the core network and the UE. In the illustration, the security keys are labeled KgNB. These keys are used by a network node (e.g., a gNB) for security between the network node and the UE. When a UE switches between CUs, an updated security key is derived. The handover dynamics may be designed to limit a network node's ability to know security keys for other network nodes.
[0024] An initial key 104 is derived by the AMF and provided to the initial source network node for a first KgNB 106 The source network node provides the current UE security capabilities and KgNB (Kng-ran*108) to the target network node. Another KgNB may be derived for the target network node.
[0025] The KgNB for the target network node may be derived using either a horizontal derivation or a vertical derivation. For a horizontal derivation, the new KgNB (e.g., horizontal KgNB 110) may be derived from the previous KgNB (e.g., first KgNB 106) . A horizontal derivation may be used only when the source network node does not have a Next Hop (NH) and Next Hop Chaining Count (NCC) pair. This limitation prevents the source network node from knowing a key for a network node past one hop. For a vertical derivation, the new KgNB (e.g., vertical KgNB 112) may be derived from the NH / NCC pair (e.g., NH 114 and NCC 116) the source network node has. NCC is provided to the target network node. The source network node the KgNB as the security key and derives the Kng-ran (e.g., Kng-ran*108) based on the Physical Cell Identity (PCI) and downlink frequency of the target network node.
[0026] A target network node uses the Kng-ran (e.g., Kng-ran*108) as the KgNB key, and prepares the target configuration for the UE. The NCC used is also included along with target configuration. The UE derives the security keys based on the NCC. If the NCC is the same, then horizontal key derivation used. If the NCC is different, UE derives the NH until the NCC matches (with each increment) .
[0027] After the handover is complete, the target network node informs the AMF of the handover with a PATH SWITCH complete message. The AMF creates a fresh set of NH / NCC. The AMF provides the new NH / NCC to the target network node.
[0028] One of the aims of introducing the NH / NCC pairs is to disallow forward security key derivation. When the source network node provides the KgNB to the target network node, the source network node is aware of the keys used by the target network node. This may become a security concern if the source network node can know the keys used for future network nodes.
[0029] To disallow the tracking (or the ability) of the source network node to know the keys used by the UE through its mobility, NH may be used. The network node cannot derive (and is not aware) of the NH of the other network nodes for a particular UE. NH and KgNB may be a bit similar in this regard (e.g., 256 bit keys) . Both may be used to derive the Kng-ran using PCI and Absolute Radio Frequency Channel Number (ARFCN) and other parameters. NH is known only at the UE and AMF. The AMF distributes NH to network nodes as needed for mobility.
[0030] To derive the Kng-ran, a previous KgNB or NH is needed. If NH is used, then NCC is needed (and incremented after every use -by AMF and UE in sync) . NCC is used to track the number of KgNB derivations based on NH. NCC is also used by the UE to know whether horizontal or vertical derivation is to be performed at the UE. Otherwise the UE is not aware about how the network node handles the Kng-ran.
[0031] Currently, RRC signaling is used for transmitting the NCC. However, for inter-CU L2 triggered mobility, there is no RRC signaling. Accordingly, embodiments for inter-CU L2 triggered mobility must use a different mechanism. L2 based Inter-CU LTM should provide the same security requirements as L3 handover. That is, the source CU (and DUs) should not be able to know the security keys of the next-to-next network node in terms of mobility.
[0032] One approach for sending the NCC is to use MAC control element (CE) . However, MAC CE is not protected allowing other nodes to know an NCC within the MAC CE. Since L2 MAC CE is not protected, ways to protect the NCC information transmitted should be considered. Introduction of ciphering / integrity for L2 MAC CE may introduce additional complications that make it very unlikely to be adopted by wireless communication systems in the near future. Some embodiments consider ways to protect the NCC information in the MAC CE.
[0033] FIG. 2 illustrates an example MAC CE 202 for sending NCC information in accordance with some embodiments. A network node may transmit the MAC CE 202 to a UE. The UE may obtain NCC information from the MAC CE 202.
[0034] As shown, the MAC CE 202 may include MAC CE type indication field 204. The MAC CE type indication field 204 may indicate the type of the MAC CE. In the illustrated example, the MAC CE type indication field 204 indicates that the MAC CE 202 is for LTM cell switch. Accordingly, the UE should use the information in the MAC CE 202 to prepare for the LTM cell switch. For example, the MAC CE 202 may include candidate cell configuration field 206. The candidate cell configuration field 206 may indicate the target cell that the UE should switch too. The MAC CE 202 may also include other information such as a TCI configuration field 208 that includes TCI configuration information, and a RACH configuration field 210 that includes RACH configuration information.
[0035] Further, the MAC CE 202 may be include an additional index to carry information related to nextHopChainingCount (NCC) . In the illustrated embodiment, the MAC CE 202 includes an Inter-CU LTM NCC information field 212. The Inter-CU LTM NCC information field 212 may include NCC information for inter-CU LTM. In some embodiments, the Inter-CU LTM NCC information field 212 may reflect the actual value of the NCC. For instance, the Inter-CU LTM NCC information field 212 may be three bits and include a three bit value that reflects the actual value of NCC. In some embodiments, the Inter-CU LTM NCC information field 212 may include an index value that may be used by the UE to determine the actual NCC value. For instance, the Inter-CU LTM NCC information field 212 may include a three bit index value that points to a value in an array. That array may be provided via RRC configuration and have the NCC value for the particular candidate configuration mapped to the index value in the Inter-CU LTM NCC information field 212. Thus, the UE may use the index value and the RRC configured array to determine the NCC value.
[0036] For example, FIG. 3 illustrates an example LTM configuration RRC message 302 in accordance with some embodiments. The LTM configuration RRC message 302 may be per candidate. The LTM configuration RRC message 302 may include an LTM candidate ID 304 to indicate which cell is corresponds to the LTM configuration RRC message 302. The LTM configuration RRC message 302 may include an LTM configuration element 402.
[0037] FIG. 4 illustrates an example an LTM configuration element 402 for LTM candidate NCC in accordance with some embodiments. The LTM configuration element 402 may include an LTM NCC array configuration field 404 and indicate the size of the array. In the illustrated embodiment, there are eight possible NCC values. In other embodiments there may be more or less NCC values. The LTM NCC array configuration field 404 may include an array or sequence of values that may be used by the UE to determine a NCC for a candidate cell.
[0038] For example, in the illustration the array 406 is { [0] -5, [1] -4, [2] -7, [3] -0, [4] -1, [5] -3, [6] -2, [7] -6} for candidate cell 1. The values in the brackets (e.g., 0, 1, 2, 3, 4, 5, 6, and 7) may correspond to the index value, and the other values in the array may correspond to actual NCC values (e.g., 5, 4, 7, 0, 1, 3, 2, and 6) . The order of the actual NCC values may be scrambled and be mapped with one of the index values. In the illustrated embodiment, index value 0 is mapped to actual NCC value 5 for candidate cell 1.
[0039] The MAC CE provided to the UE may include the index value and the UE may use the array to determine the corresponding actual NCC value. The RRC message is ciphering and integrity protected. Thus, the actual NCC value can be protected by the network node including the index value in the NCC information field of the MAC CE, and encoding the array that maps the index value to the actual NCC value in the RRC message.
[0040] Each candidate cell may have a different configuration. The LTM configuration element 402 does not need to change with each inter-CU LTM cell switch. The UE may use the current cell (e.g., the cell from which the LTM cell switch MAC CE is received) , or the UE may use the candidate target cell for applying the index to derive the NCC value. For example, in some embodiments the UE may use the candidate target cell for applying the index to derive the NCC value.
[0041] Since after every LTM switch, the security contexts need to be updated in every participating candidate cell, and the update needs to come from the current source (ex-target cell) , and since the UE can derive the correct NH based on the NCC count (without any prior history, just the Kamf is needed) , the following steps can be used to achieve inter-CU LTM with subsequent LTM (MAC CE triggered) .
[0042] After every inter-CU LTM cell switch, where the new source cell gets the PATH SWITCH ACK message from the AMF, the source cell may derive and update all the candidate LTM cells (the inter-CU cells, from this cell perspective) with the Kng-ran*based on the fresh {NH, NCC} pair from AMF. The NCC may also be provided to each of the candidates.
[0043] In some embodiments, the cells may map the actual NCC values to indices. For example, in some embodiments the range of NCC may be 8 (3 bits) , each candidate cell can map the 8 values to 8 indices, such that there is 1-1 mapping, but the index does not need to match the actual NCC value. An example of indices mapped to the NCC values may be: { [0] -5, [1] -4, [2] -7, [3] -0, [4] -1, [5] -3, [6] -2, [7] -6 } for candidate cell 1. A different mapping may be configured for each candidate cell, to ensure that no candidate cell index scrambling is the same.
[0044] The source LTM cell may update the candidates via the Xn interface, without UE signaling. The NCC may be given to the UE in LTM MAC CE as an index value. Based on the candidate cell configuration, the UE may derive the actual NCC to use (to derive the NH) based on the index value. This may result in the inter-CU LTM using vertical derivation.
[0045] FIG. 5 illustrates a signal flow diagram 502 for an inter-CU LTM cell switch in accordance with some embodiments. A UE and network nodes may use the signaling shown for an inter-CU LTM cell switch with L2 (MAC CE) triggers. In the illustrated embodiment, there is an initial source cell (e.g., old source cell 506 and three candidate cells (e.g., first candidate cell 508, second candidate cell 510, and third candidate cell 512) . The UE 514 is initially connected with the old source cell 506.
[0046] Phase A 504 of the signal flow diagram 502 may involve configuration of the security keys to all candidate cells. In phase A 504 of the signal flow diagram 502, the source cell may configure the UE with LTM candidates and distributes the next to be used security key (Kng-ran1*) and NCC1 to all the participating candidates (e.g., first candidate cell 508, second candidate cell 510, and third candidate cell 512. The old source cell 506 gets the NH to derive this Kng-ran1*from the AMF 516 as the fresh {NH, NCC1} pair. In some embodiments, the old source cell 506 may use the {NH, NCC1} pair for horizontal derivation, then the next key to be used will be distributed by the old source cell 506 to the candidate cells using the horizontal derivation.
[0047] For example, the old source cell 506 may receive a fresh {NH, NCC} pair from AMF 516. Further, the old source cell 506 may derive the Kng-ran*based on the fresh {NH, NCC} pair and update the candidate LTM cells with the NCC and the Kng-ran* over Xn interface. In the illustrated embodiment, the old source cell 506 does not provide NH to the candidate cells.
[0048] Each of the candidate cells and the old source cell 506 may map the possible NCC values to index values such that each candidate cell has an array with scrambled NCC values. The arrays for the candidate cells and the old source cell 506 may be sent to the UE 514 from the old source cell 506 via RRC signaling 518. The RRC signaling 518 may include LTM configured with the candidate cells (e.g., old source cell 506, first candidate cell 508, second candidate cell 510, and third candidate cell 512) . For instance, the RRC signaling 518 may include LTM configuration RRC message 302 with a LTM configuration element 402 as shown in FIG. 3 and FIG. 4.
[0049] Based on measurement reports, the old source cell 506 may determine that it is time for the UE 514 to perform an LTM switch. In phase B 520, the old source cell 506 may trigger the LTM switch with a MAC CE. The old source cell 506 may provide the NCC (NCC1 in this example) to the UE 514 in LTM MAC CE 522 (e.g., MAC CE 202 of FIG. 2) . In some embodiments, instead of the NCC, the old source cell 506 can provide an index value to the NCC configuration. The UE may use the index value to determine the actual NCC value based on an NCC array from the LTM for the candidate cells that may be sent via the RRC signaling 518. The UE 514 may use NCC1 to derive the next key and use it in handover. The UE 514 completes the handover (LTM switch) and sends an RRC complete message 524 to the second candidate cell 510 (e.g., current source cell after the LTM switch) . The RRC complete message 524 and future communication with the second candidate cell 510 may be secured using the security key derived with NCC1.
[0050] The second candidate cell 510 informs the AMF 516 of the handover with PATH SWITCH complete message. The AMF 516 creates a fresh set of NH, NCC pair 526 (in this example it is {NH, NCC2} ) and sends the pair to the second candidate cell 510. Phase C 528 is the same as Phase A 504, except that the source network node has changed. In effect the second candidate cell 510 performs Phase A 504. That is, the second candidate cell 510 may distribute the next to be used security key Kng-ran1*and NCC2 to all the participating candidates. The second candidate cell 510 does not send an RRC configuration to the UE, as the UE may use the configuration from the first RRC signaling 518.
[0051] Phase D 530 is the same as Phase B 520, but done by the new source cell (e.g., second candidate cell 510) . For instance, the next LTM MAC CE 532 from the second candidate cell 510 includes the NCC information to allow the UE 514 to determine NCC2. In some embodiments, the NCC information may be the actual NCC value. In some embodiments, the NCC information may be an index value. The process may repeat when another LTM switch occurs.
[0052] FIG. 6 illustrates a method 600 of operation for a UE in accordance with some embodiments. The method 600 includes receiving 602 a MAC CE configured to trigger an inter-CU LTM switch from a source network node. The MAC CE may comprise NCC information. The method 600 further includes determining 604 a NCC value based on the NCC information. The method 600 further includes deriving 606 a security key for a candidate network node based on the NCC value. The method 600 further includes performing 608 the inter-CU LTM switch to move from the source network node the candidate network node. The method 600 further includes sending 610 a RRC message to the candidate network node using the security key.
[0053] In some embodiments, the NCC information comprises an actual NCC value.
[0054] In some embodiments, the method 600 further comprises receiving LTM configuration via RRC signaling from the source network node for one or more candidate nodes, wherein the LTM configuration includes arrays with NCC values scrambled differently for each of the one or more candidate nodes.
[0055] In some embodiments, the NCC information comprises an index value of one of the arrays.
[0056] In some embodiments, the method 600 further comprises determining the NCC value that corresponds to the index value of one of the arrays.
[0057] In some embodiments, the UE uses an array associated with the candidate network node to determine the NCC value.
[0058] In some embodiments, the UE uses an array associated with the source network node to determine the NCC value.
[0059] In some embodiments, the LTM configuration for each of the candidate nodes remains the same between inter-CU LTM cell switches.
[0060] Embodiments contemplated herein include an apparatus comprising means to perform one or more elements of the method 600. This apparatus may be, for example, an apparatus of a UE (such as a wireless device 902 that is a UE, as described herein) .
[0061] Embodiments contemplated herein include one or more non-transitory computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform one or more elements of the method 600. This non-transitory computer-readable media may be, for example, a memory of a UE (such as a memory 906 of a wireless device 902 that is a UE, as described herein) .
[0062] Embodiments contemplated herein include an apparatus comprising logic, modules, or circuitry to perform one or more elements of the method 600. This apparatus may be, for example, an apparatus of a UE (such as a wireless device 902 that is a UE, as described herein) .
[0063] Embodiments contemplated herein include an apparatus comprising: one or more processors and one or more computer-readable media comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform one or more elements of the method 600. This apparatus may be, for example, an apparatus of a UE (such as a wireless device 902 that is a UE, as described herein) .
[0064] Embodiments contemplated herein include a signal as described in or related to one or
[0065] FIG. 7 illustrates a method 700 of operation for a network node in accordance with some embodiments. The illustrated method 700 includes receiving 702 a NH and NCC from an AMF. The method 700 further includes deriving 704 a next security key based on the NH and the NCC. The method 700 further includes distributing 706 the next security key and the NCC to one or more candidate network nodes. The method 700 further includes generating 708 a MAC CE comprising NCC information. The method 700 further includes sending 710 the MAC CE to a UE to trigger an inter-CU LTM switch.
[0066] In some embodiments, the method 700 further comprises deriving a horizontal next security key based on a horizontal derivation; distributing the horizontal next security key and the NCC where the horizontal next security key is derived using Physical Cell Identity (PCI) and downlink (DL) frequency of the candidate network node; generating a second MAC CE comprising the NCC information corresponding to the horizontal security key; and sending the second MAC CE to the UE to trigger the inter-CU LTM switch.
[0067] In some embodiments, the NCC information comprises an actual NCC value.
[0068] In some embodiments, the method 700 further comprises sending LTM configuration via RRC signaling from the source network node for one or more candidate nodes, wherein the LTM configuration includes arrays with NCC values scrambled differently for each of the one or more candidate nodes.
[0069] In some embodiments, the NCC information comprises an index value of one of the arrays.
[0070] In some embodiments, the index value corresponds to an array associated with the source network node.
[0071] In some embodiments, the index value corresponds to an array associated with a target candidate network node.
[0072] In some embodiments, the LTM configuration for each of the one or more candidate nodes remains the same between inter-CU LTM cell switches.
[0073] Embodiments contemplated herein include an apparatus comprising means to perform one or more elements of the method 700. This apparatus may be, for example, an apparatus of a base station (such as a network device 918 that is a base station, as described herein) .
[0074] Embodiments contemplated herein include one or more non-transitory computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform one or more elements of the method 700. This non-transitory computer-readable media may be, for example, a memory of a base station (such as a memory 922 of a network device 918 that is a base station, as described herein) .
[0075] Embodiments contemplated herein include an apparatus comprising logic, modules, or circuitry to perform one or more elements of the method 700. This apparatus may be, for example, an apparatus of a base station (such as a network device 918 that is a base station, as described herein) .
[0076] Embodiments contemplated herein include an apparatus comprising: one or more processors and one or more computer-readable media comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform one or more elements of the method 700. This apparatus may be, for example, an apparatus of a base station (such as a network device 918 that is a base station, as described herein) .
[0077] Embodiments contemplated herein include a signal as described in or related to one or more elements of the method 700.
[0078] Embodiments contemplated herein include a computer program or computer program product comprising instructions, wherein execution of the program by a processing element is to cause the processing element to carry out one or more elements of the method 700. The processor may be a processor of a base station (such as a processor (s) 920 of a network device 918 that is a base station, as described herein) . These instructions may be, for example, located in the processor and / or on a memory of the base station (such as a memory 922 of a network device 918 that is a base station, as described herein) .
[0079] FIG. 8 illustrates an example architecture of a wireless communication system 800, according to embodiments disclosed herein. The following description is provided for an example wireless communication system 800 that operates in conjunction with the LTE system standards and / or 5G or NR system standards as provided by 3GPP technical specifications.
[0080] As shown by FIG. 8, the wireless communication system 800 includes UE 802 and UE 804 (although any number of UEs may be used) . In this example, the UE 802 and the UE 804 are illustrated as smartphones (e.g., handheld touchscreen mobile computing devices connectable to one or more cellular networks) , but may also comprise any mobile or non-mobile computing device configured for wireless communication.
[0081] The UE 802 and UE 804 may be configured to communicatively couple with a RAN 806. In embodiments, the RAN 806 may be NG-RAN, E-UTRAN, etc. The UE 802 and UE 804 utilize connections (or channels) (shown as connection 808 and connection 810, respectively) with the RAN 806, each of which comprises a physical communications interface. The RAN 806 can include one or more base stations (such as base station 812 and base station 814) that enable the connection 808 and connection 810.
[0082] In this example, the connection 808 and connection 810 are air interfaces to enable such communicative coupling, and may be consistent with RAT (s) used by the RAN 806, such as, for example, an LTE and / or NR.
[0083] In some embodiments, the UE 802 and UE 804 may also directly exchange communication data via a sidelink interface 816. The UE 804 is shown to be configured to access an access point (shown as AP 818) via connection 820. By way of example, the connection 820 can comprise a local wireless connection, such as a connection consistent with any IEEE 802.11 protocol, wherein the AP 818 may comprise a router. In this example, the AP 818 may be connected to another network (for example, the Internet) without going through a CN 824.
[0084] In embodiments, the UE 802 and UE 804 can be configured to communicate using orthogonal frequency division multiplexing (OFDM) communication signals with each other or with the base station 812 and / or the base station 814 over a multicarrier communication channel in accordance with various communication techniques, such as, but not limited to, an orthogonal frequency division multiple access (OFDMA) communication technique (e.g., for downlink communications) or a single carrier frequency division multiple access (SC-FDMA) communication technique (e.g., for uplink and ProSe or sidelink communications) , although the scope of the embodiments is not limited in this respect. The OFDM signals can comprise a plurality of orthogonal subcarriers.
[0085] In some embodiments, all or parts of the base station 812 or base station 814 may be implemented as one or more software entities running on server computers as part of a virtual network. In addition, or in other embodiments, the base station 812 or base station 814 may be configured to communicate with one another via interface 822. In embodiments where the wireless communication system 800 is an LTE system (e.g., when the CN 824 is an EPC) , the interface 822 may be an X2 interface. The X2 interface may be defined between two or more base stations (e.g., two or more eNBs and the like) that connect to an EPC, and / or between two eNBs connecting to the EPC. In embodiments where the wireless communication system 800 is an NR system (e.g., when CN 824 is a 5GC) , the interface 822 may be an Xn interface. The Xn interface is defined between two or more base stations (e.g., two or more gNBs and the like) that connect to 5GC, between a base station 812 (e.g., a gNB) connecting to 5GC and an eNB, and / or between two eNBs connecting to 5GC (e.g., CN 824) .
[0086] The RAN 806 is shown to be communicatively coupled to the CN 824. The CN 824 may comprise one or more network elements 826, which are configured to offer various data and telecommunications services to customers / subscribers (e.g., users of UE 802 and UE 804) who are connected to the CN 824 via the RAN 806. The components of the CN 824 may be implemented in one physical device or separate physical devices including components to read and execute instructions from a machine-readable or computer-readable medium (e.g., a non-transitory machine-readable storage medium) .
[0087] In embodiments, the CN 824 may be an EPC, and the RAN 806 may be connected with the CN 824 via an S1 interface 828. In embodiments, the S1 interface 828 may be split into two parts, an S1 user plane (S1-U) interface, which carries traffic data between the base station 812 or base station 814 and a serving gateway (S-GW) , and the S1-MME interface, which is a signaling interface between the base station 812 or base station 814 and mobility management entities (MMEs) .
[0088] In embodiments, the CN 824 may be a 5GC, and the RAN 806 may be connected with the CN 824 via an NG interface 828. In embodiments, the NG interface 828 may be split into two parts, an NG user plane (NG-U) interface, which carries traffic data between the base station 812 or base station 814 and a user plane function (UPF) , and the S1 control plane (NG-C) interface, which is a signaling interface between the base station 812 or base station 814 and access and mobility management functions (AMFs) .
[0089] Generally, an application server 830 may be an element offering applications that use internet protocol (IP) bearer resources with the CN 824 (e.g., packet switched data services) . The application server 830 can also be configured to support one or more communication services (e.g., VoIP sessions, group communication sessions, etc. ) for the UE 802 and UE 804 via the CN 824. The application server 830 may communicate with the CN 824 through an IP communications interface 832.
[0090] FIG. 9 illustrates a system 900 for performing signaling 934 between a wireless device 902 and a network device 918, according to embodiments disclosed herein. The system 900 may be a portion of a wireless communications system as herein described. The wireless device 902 may be, for example, a UE of a wireless communication system. The network device 918 may be, for example, a base station (e.g., an eNB or a gNB) of a wireless communication system.
[0091] The wireless device 902 may include one or more processor (s) 904. The processor (s) 904 may execute instructions such that various operations of the wireless device 902 are performed, as described herein. The processor (s) 904 may include one or more baseband processors implemented using, for example, a central processing unit (CPU) , a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , a controller, a field programmable gate array (FPGA) device, another hardware device, a firmware device, or any combination thereof configured to perform the operations described herein.
[0092] The wireless device 902 may include a memory 906. The memory 906 may be a non-transitory computer-readable storage medium that stores instructions 908 (which may include, for example, the instructions being executed by the processor (s) 904) . The instructions 908 may also be referred to as program code or a computer program. The memory 906 may also store data used by, and results computed by, the processor (s) 904.
[0093] The wireless device 902 may include one or more transceiver (s) 910 that may include radio frequency (RF) transmitter circuitry and / or receiver circuitry that use the antenna (s) 912 of the wireless device 902 to facilitate signaling (e.g., the signaling 934) to and / or from the wireless device 902 with other devices (e.g., the network device 918) according to corresponding RATs.
[0094] The wireless device 902 may include one or more antenna (s) 912 (e.g., one, two, four, or more) . For embodiments with multiple antenna (s) 912, the wireless device 902 may leverage the spatial diversity of such multiple antenna (s) 912 to send and / or receive multiple different data streams on the same time and frequency resources. This behavior may be referred to as, for example, multiple input multiple output (MIMO) behavior (referring to the multiple antennas used at each of a transmitting device and a receiving device that enable this aspect) . MIMO transmissions by the wireless device 902 may be accomplished according to precoding (or digital beamforming) that is applied at the wireless device 902 that multiplexes the data streams across the antenna (s) 912 according to known or assumed channel characteristics such that each data stream is received with an appropriate signal strength relative to other streams and at a desired location in the spatial domain (e.g., the location of a receiver associated with that data stream) . Certain embodiments may use single user MIMO (SU-MIMO) methods (where the data streams are all directed to a single receiver) and / or multi user MIMO (MU-MIMO) methods (where individual data streams may be directed to individual (different) receivers in different locations in the spatial domain) .
[0095] In certain embodiments having multiple antennas, the wireless device 902 may implement analog beamforming techniques, whereby phases of the signals sent by the antenna (s) 912 are relatively adjusted such that the (joint) transmission of the antenna (s) 912 can be directed (this is sometimes referred to as beam steering) .
[0096] The wireless device 902 may include one or more interface (s) 914. The interface (s) 914 may be used to provide input to or output from the wireless device 902. For example, a wireless device 902 that is a UE may include interface (s) 914 such as microphones, speakers, a touchscreen, buttons, and the like in order to allow for input and / or output to the UE by a user of the UE. Other interfaces of such a UE may be made up of transmitters, receivers, and other circuitry (e.g., other than the transceiver (s) 910 / antenna (s) 912 already described) that allow for communication between the UE and other devices and may operate according to known protocols (e.g., and the like) .
[0097] The wireless device 902 may include a security module 916. The security module 916 may be implemented via hardware, software, or combinations thereof. For example, the security module 916 may be implemented as a processor, circuit, and / or instructions 908 stored in the memory 906 and executed by the processor (s) 904. In some examples, the security module 916 may be integrated within the processor (s) 904 and / or the transceiver (s) 910. For example, the security module 916 may be implemented by a combination of software components (e.g., executed by a DSP or a general processor) and hardware components (e.g., logic gates and circuitry) within the processor (s) 904 or the transceiver (s) 910.
[0098] The security module 916 may be used for various aspects of the present disclosure, for example, aspects of FIGS. 1-8. The security module 916 is configured to receive a MAC CE with NCC information and determine a next security key.
[0099] The network device 918 may include one or more processor (s) 920. The processor (s) 920 may execute instructions such that various operations of the network device 918 are performed, as described herein. The processor (s) 920 may include one or more baseband processors implemented using, for example, a CPU, a DSP, an ASIC, a controller, an FPGA device, another hardware device, a firmware device, or any combination thereof configured to perform the operations described herein.
[0100] The network device 918 may include a memory 922. The memory 922 may be a non-transitory computer-readable storage medium that stores instructions 924 (which may include, for example, the instructions being executed by the processor (s) 920) . The instructions 924 may also be referred to as program code or a computer program. The memory 922 may also store data used by, and results computed by, the processor (s) 920.
[0101] The network device 918 may include one or more transceiver (s) 926 that may include RF transmitter circuitry and / or receiver circuitry that use the antenna (s) 928 of the network device 918 to facilitate signaling (e.g., the signaling 934) to and / or from the network device 918 with other devices (e.g., the wireless device 902) according to corresponding RATs.
[0102] The network device 918 may include one or more antenna (s) 928 (e.g., one, two, four, or more) . In embodiments having multiple antenna (s) 928, the network device 918 may perform MIMO, digital beamforming, analog beamforming, beam steering, etc., as has been described.
[0103] The network device 918 may include one or more interface (s) 930. The interface (s) 930 may be used to provide input to or output from the network device 918. For example, a network device 918 that is a base station may include interface (s) 930 made up of transmitters, receivers, and other circuitry (e.g., other than the transceiver (s) 926 / antenna (s) 928 already described) that enables the base station to communicate with other equipment in a core network, and / or that enables the base station to communicate with external networks, computers, databases, and the like for purposes of operations, administration, and maintenance of the base station or other equipment operably connected thereto.
[0104] The network device 918 may include a security module 932. The security module 932 may be implemented via hardware, software, or combinations thereof. For example, the security module 932 may be implemented as a processor, circuit, and / or instructions 924 stored in the memory 922 and executed by the processor (s) 920. In some examples, the security module 932 may be integrated within the processor (s) 920 and / or the transceiver (s) 926. For example, the security module 932 may be implemented by a combination of software components (e.g., executed by a DSP or a general processor) and hardware components (e.g., logic gates and circuitry) within the processor (s) 920 or the transceiver (s) 926.
[0105] The security module 932 may be used for various aspects of the present disclosure, for example, aspects of FIGS. 1-8. The security module 932 is configured to distribute the next security key to candidate cells, and send a MAC CE that includes NCC information to the wireless device 902.
[0106] For one or more embodiments, at least one of the components set forth in one or more of the preceding figures may be configured to perform one or more operations, techniques, processes, and / or methods as set forth herein. For example, a baseband processor as described herein in connection with one or more of the preceding figures may be configured to operate in accordance with one or more of the examples set forth herein. For another example, circuitry associated with a UE, base station, network element, etc. as described above in connection with one or more of the preceding figures may be configured to operate in accordance with one or more of the examples set forth herein.
[0107] Any of the above described embodiments may be combined with any other embodiment (or combination of embodiments) , unless explicitly stated otherwise. The foregoing description of one or more implementations provides illustration and description, but is not intended to be exhaustive or to limit the scope of embodiments to the precise form disclosed. Modifications and variations are possible in light of the above teachings or may be acquired from practice of various embodiments.
[0108] Embodiments and implementations of the systems and methods described herein may include various operations, which may be embodied in machine-executable instructions to be executed by a computer system. A computer system may include one or more general-purpose or special-purpose computers (or other electronic devices) . The computer system may include hardware components that include specific logic for performing the operations or may include a combination of hardware, software, and / or firmware.
[0109] It should be recognized that the systems described herein include descriptions of specific embodiments. These embodiments can be combined into single systems, partially combined into other systems, split into multiple systems or divided or combined in other ways. In addition, it is contemplated that parameters, attributes, aspects, etc. of one embodiment can be used in another embodiment. The parameters, attributes, aspects, etc. are merely described in one or more embodiments for clarity, and it is recognized that the parameters, attributes, aspects, etc. can be combined with or substituted for parameters, attributes, aspects, etc. of another embodiment unless specifically disclaimed herein.
[0110] It is well understood that the use of personally identifiable information should follow privacy policies and practices that are generally recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy of users. In particular, personally identifiable information data should be managed and handled so as to minimize risks of unintentional or unauthorized access or use, and the nature of authorized use should be clearly indicated to users.
[0111] Although the foregoing has been described in some detail for purposes of clarity, it will be apparent that certain changes and modifications may be made without departing from the principles thereof. It should be noted that there are many alternative ways of implementing both the processes and apparatuses described herein. Accordingly, the present embodiments are to be considered illustrative and not restrictive, and the description is not to be limited to the details given herein, but may be modified within the scope and equivalents of the appended claims.
Claims
1.A method of operation for a user equipment (UE) , the method comprising:receiving a media access control (MAC) control element (CE) configured to trigger an inter-centralized unit (CU) layer triggered mobility (LTM) switch from a source network node, the MAC CE comprising Next Hop Chaining Count (NCC) information;determining a NCC value based on the NCC information;deriving a security key for a candidate network node based on the NCC value;performing the inter-CU LTM switch to move from the source network node the candidate network node; andsending a radio resource control (RRC) message to the candidate network node using the security key.2.The method of claim 1, wherein the NCC information comprises an actual NCC value.3.The method of claim 1, further comprising receiving LTM configuration via RRC signaling from the source network node for one or more candidate nodes, wherein the LTM configuration includes arrays with NCC values scrambled differently for each of the one or more candidate nodes.4.The method of claim 3, wherein the NCC information comprises an index value of one of the arrays.5.The method of claim 4, further comprising determining the NCC value that corresponds to the index value of one of the arrays.6.The method of claim 5, wherein the UE uses an array associated with the candidate network node to determine the NCC value.7.The method of claim 5, wherein the UE uses an array associated with the source network node to determine the NCC value.8.The method of claim 3, wherein the LTM configuration for each of the candidate nodes remains the same between inter-CU LTM cell switches.9.A method of operation for a source network node, the method comprising:receiving a Next Hop (NH) and a Next Hop Chaining Count (NCC) from an access and mobility management function (AMF) ;deriving a next security key based on the NH and the NCC;distributing the next security key and the NCC to one or more candidate network nodes;generating a media access control (MAC) control element (CE) comprising NCC information; andsending the MAC CE to a user equipment (UE) to trigger an inter-centralized unit (CU) layer triggered mobility (LTM) switch.10.The method of claim 9, further comprising:deriving a horizontal next security key based on a horizontal derivation;distributing the horizontal next security key and the NCC where the horizontal next security key is derived using Physical Cell Identity (PCI) and downlink (DL) frequency of the candidate network node;generating a second MAC CE comprising the NCC information corresponding to the horizontal security key; andsending the second MAC CE to the UE to trigger the inter-CU LTM switch.11.The method of claim 9, wherein the NCC information comprises an actual NCC value.12.The method of claim 9, further comprising sending LTM configuration via RRC signaling from the source network node for one or more candidate nodes, wherein the LTM configuration includes arrays with NCC values scrambled differently for each of the one or more candidate nodes.13.The method of claim 12, wherein the NCC information comprises an index value of one of the arrays.14.The method of claim 13, wherein the index value corresponds to an array associated with the source network node.15.The method of claim 13, wherein the index value corresponds to an array associated with a target candidate network node.16.The method of claim 12, wherein the LTM configuration for each of the one or more candidate nodes remains the same between inter-CU LTM cell switches.17.A user equipment (UE) comprising:a processor; anda memory storing instructions that, when executed by the processor, configure the UE to:receive a MAC CE configured to trigger an inter-centralized unit (CU) layer triggered mobility (LTM) switch from a source network node, the MAC CE comprising Next Hop Chaining Count (NCC) information;determine a NCC value based on the NCC information;derive a security key for a candidate network node based on the NCC value;perform the inter-CU LTM switch to move from the source network node the candidate network node; andsend an radio resource control (RRC) to the candidate network node using the security key.18.The UE of claim 17, wherein the NCC information comprises an actual NCC value.19.The UE of claim 17, wherein the instructions further configure the UE to receive LTM configuration via RRC signaling from the source network node for one or more candidate nodes, wherein the LTM configuration includes arrays with NCC values scrambled differently for each of the one or more candidate nodes.20.The UE of claim 19, wherein the NCC information comprises an index value of one of the arrays.21.The UE of claim 20, wherein the instructions further configure the UE to determine the NCC value that corresponds to the index value of one of the arrays.22.The UE of claim 21, wherein the UE uses an array associated with the candidate network node to determine the NCC value.23.The UE of claim 21, wherein the UE uses an array associated with the source network node to determine the NCC value.24.An apparatus comprising means to perform the method of any of claim 1 to claim 16.25.A computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform the method of any of claim 1 to claim 16.26.An apparatus comprising logic, modules, or circuitry to perform the method of any of claim 1 to claim 16.27.A baseband processor for a user equipment (UE) configured to perform the method of any of claim 1 to claim 8.
Citation Information
Patent Citations
Access stratum (AS) security for centralized radio access network (c-ran)
CN111971987A
System and Method for Communicating with Provisioned Security Protection
US20190124506A1
Security Key Generation for Handling Data Transmissions from User Devices in an Inactive State
US20230144223A1
Network node, UE and method for handling handover with parameter for deriving security context
WO2020167211A1
Communication method and apparatus
WO2023186028A1