Managing values usable for derivation of security keys for communication between a user equipment and a secondary node

By allowing the UE to receive further values for security key derivation and maintaining unused sequences, the method addresses inefficiencies in key management, ensuring secure and efficient key activation in dual connectivity scenarios.

WO2025176352A1PCT designated stage Publication Date: 2025-08-28TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/086315
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-19
Filing Date
2024-12-13
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

The advance provisioning of sequences of counter values for security keys in dual connectivity scenarios can be wasted due to scenarios like PDCP COUNT wrap-around or non-conditional mobility operations, leading to unclear status and inefficiency in key management.

Method used

The method involves the UE receiving a further value for security key derivation from the MN, maintaining unused values in the sequence, and activating new keys as needed, rather than discarding the entire sequence, ensuring fresh keys are used for each connection.

Benefits of technology

This approach ensures efficient and secure key management in dual connectivity, avoiding waste of pre-configured sequences and maintaining security even in scenarios like PDCP COUNT wrap-around, enhancing overall network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024086315_28082025_PF_FP_ABST
    Figure EP2024086315_28082025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments include methods for a user equipment (UE) configured to communicate with a master node (MN) and a secondary node (SN). Such methods include receiving a sequence of values from the MN. The values are usable for derivations of security keys for communication between the UE and the SN. Such methods include, while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receiving from the MN a further value usable for derivation of security keys for communication between UE and SN. Such methods include deriving one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence, and maintaining the at least one unused value for at least one subsequent derivation of security keys for communication between UE and SN.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] MANAGING VALUES USABLE FOR DERIVATION OF SECURITY KEYS FOR COMMUNICATION BETWEEN A USER EQUIPMENT AND A SECONDARY NODE

[0002] TECHNICAL FIELD

[0003] The present disclosure relates generally to wireless networks, and more specifically to techniques for managing values (e.g., counter values) usable for derivation of security keys for communication between a user equipment (UE) and a secondary node (SN) in dual connectivity, such as by the UE’s master node (MN) in dual connectivity.

[0004] BACKGROUND

[0005] Currently the fifth generation (5G) of cellular systems is being standardized within the Third-Generation Partnership Project (3GPP). 5G is developed for maximum flexibility to support many different use cases including enhanced mobile broadband (eMBB), machine type communications (MTC), ultra-reliable low latency communications (URLLC), side-link device- to-device (D2D), and several other use cases.

[0006] Figure 1 illustrates a high-level view of an exemplary 5G network architecture, consisting of a Next Generation Radio Access Network (NG-RAN, 199) and a 5G Core (5GC, 198). The NG-RAN can include one or more gNodeB’s (gNBs) connected to the 5GC via one or more NG interfaces, such as gNBs (100, 150) connected via respective interfaces (102, 152). More specifically, the gNBs can be connected to one or more Access and Mobility Management Functions (AMFs) in the 5GC via respective NG-C interfaces and to one or more User Plane Functions (UPFs) in 5GC via respective NG-U interfaces. The 5GC can include various other network functions (NFs), such as Session Management Function(s) (SMF).

[0007] Although not shown, in some deployments the 5GC can be replaced by an Evolved Packet Core (EPC), which conventionally has been used together with a Long-Term Evolution (LTE) Evolved UMTS RAN (E-UTRAN). In such deployments, gNBs (e.g., 100, 150) can connect to one or more Mobility Management Entities (MMEs) in the EPC via respective Sl-C interfaces and to one or more Serving Gateways (SGWs) in EPC via respective NG-U interfaces.

[0008] In addition, the gNBs can be connected to each other via one or more Xn interfaces, such as Xn interface (140) between gNBs (100, 150). The radio technology for the NG-RAN is often referred to as “New Radio” (NR). With respect to the NR interface to UEs, each of the gNBs can support frequency division duplexing (FDD), time division duplexing (TDD), or a combination thereof. Each of the gNBs can serve a geographic coverage area including one or more cells and, in some cases, can also use various directional beams to provide coverage in the respective cells. In general, a DL “beam” is a coverage area of a network-transmitted reference signal (RS) that may be measured or monitored by a UE.

[0009] NG RAN logical nodes (e.g., gNB 100) include a Central Unit (CU or gNB-CU, e.g., 110) and one or more Distributed Units (DU or gNB-DU, e.g., 120, 130). CUs are logical nodes that host higher-layer protocols and perform various gNB functions such controlling the operation of DUs. DUs are decentralized logical nodes that host lower layer protocols and can include, depending on the functional split option, various subsets of the gNB functions. Each CU and DU can include various circuitry needed to perform their respective functions, including processing circuitry, communication interface circuitry (e.g., transceivers), and power supply circuitry.

[0010] A gNB-CU connects to one or more gNB-DUs over respective Fl logical interfaces (e.g., 122 and 132 shown in Figure 1). However, each gNB-DU can be connected to only one gNB-CU. The gNB-CU and its connected gNB-DU(s) are only visible to other gNBs and the 5GC as a gNB. In other words, the Fl interface is not visible beyond gNB-CU.

[0011] 3 GPP Rel-10 introduced support for channel bandwidths larger than 20 MHz in fourthgeneration (4G) Long Term Evolution (LTE) networks. To remain compatible with UEs from earlier releases (e.g., LTE Rel-8), a wideband LTE Rel-10 carrier appears as multiple component carriers (CCs), each having the same structure as an LTE Rel-8 carrier. A Rel-10 UE can receive the multiple CCs based on Carrier Aggregation (CA). The CCs can also be considered “cells,” such that a UE in CA has one primary cell (PCell) and one or more secondary cells (SCells) that are referred to collectively as a “cell group.”

[0012] LTE Rel-12 introduced dual connectivity (DC) whereby a UE is connected simultaneously to a master node (MN) that provides a master cell group (MCG) and a secondary node (SN) that provides a secondary cell group (SCG). NR includes support for CA and DC in Rel-15 and thereafter. 3GPP TR 38.804 (vl4.0.0) describes various exemplary DC scenarios or configurations in which the MN and SN can apply NR, LTE, or both.

[0013] The MN controls the UE-RAN connection using the radio resource control (RRC) protocol, and can configure SNs with radio and security parameters enabling them to establish additional connections with the UE. The SN configuration is performed using the XnAP protocol. The security parameters included cryptographic keys and identifiers for encryption and integrity protection algorithms.

[0014] A UE may change or add SCGs by a procedure called conditional PSCell addition or change (CP AC). As a mobility enhancement for 3GPP Rel-18, prior to performing the CPAC, the UE may be configured to perform a subsequent CPAC (SCPAC) without any additional reconfiguration by the MN. In particular, the UE is configured with a list of conditional reconfigurations, each of which includes condition(s) and a configuration to apply when the condition(s) is / are fulfilled.

[0015] The UE may also configured with a list of sk-Counter values for a group of cells, with each sk-Counter being associated with a security configuration. If the UE changes cell group, the UE applies the next sk-Counter value in the list and the associated security configuration. Application of an sk-Counter value comprises computing a cryptographic key based on at least part of the counter value.

[0016] One aspect of the Rel-18 enhancement is that SNs may receive information about several cryptographic keys, each of which is derived by the UE and the MN individually using a common derivation process. The derivation process involves inputting a key KgNB (shared between UE and MN) and a counter C into a Key Derivation Function (KDF). The counter C is incremented for each derived key. Under the assumption that the KDF is secure, the monotonically increasing values of C ensure that each key will be different. This is important to mitigate attacks based on relations between multiple uses of keys, an example of which is referred to as “two-time pad”.

[0017] In addition to preparing SNs with several keys, the MN provides the UE with the sequence of counter values that was used to derive the keys for each SN. Because the UE has KgNB and the per-SN sequence of counter values, it can derive the correct key when connecting to an SN without the MN needing to derive and provide the UE with a new key. The UE takes the next value in the sequence when connecting to an SN, thereby ensuring that a fresh key is used for every new connection. As such, the counter values serve as unique identifiers for each key, at least with respect to an individual SN.

[0018] SUMMARY

[0019] However, there are various scenarios in which the MN’s advance provisioning of a UE with sequences of counter values for different CP AC candidate SNs may be wasted. For example, the UE may need to explicitly request a new key from the MN for a non-conditional mobility operation, or when the UE’s 32-bit packet counter rolls over due to a lot of data being sent in a particular cell. These scenarios cause the pre-configured sequences of counter values to become invalid or, at a minimum, have an unclear status for subsequent use. This is undesirable from the perspectives of MN and UE.

[0020] An object of embodiments of the present disclosure is to improve handling of security keys and counters used in UE multi-connectivity with a RAN, such as by providing, enabling, and / or facilitating solutions to overcome exemplary problems summarized above and described in more detail below.

[0021] Embodiments include methods (e.g., procedures) for a UE configured to communicate in dual connectivity with an MN and an SN.

[0022] These exemplary methods can include receiving a sequence of values from the MN. The values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN. These exemplary methods also include, while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receiving from the MN a further value usable for derivation of security keys for communication between the UE and the SN. These exemplary methods also include deriving one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence. These exemplary methods also include maintaining the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

[0023] In some embodiments, the UE is configured to communicate with the MN via an MCG and with the SN via an SCG. In some of these embodiments, these exemplary methods also include, using the derived one or more security keys, communicating with the SN via the SCG. In some variants of these embodiments, communicating with the SN via the SCG using the derived one or more security keys includes performing a random access towards a cell of the SCG and subsequently sending a RRCReconfigurationComplete message to SN using the derived one or more security keys.

[0024] Other embodiments include exemplary methods (e.g., procedures) for an SN configured to communicate with a UE in dual connectivity with an MN. In general, these exemplary methods can be complementary to the exemplary methods for a UE summarized above.

[0025] These exemplary methods include receiving a sequence of values from the MN. The values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN. These exemplary methods also include, while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receiving from the MN a further value usable for derivation of security keys for communication between the UE and the SN. These exemplary methods also include deriving one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence. These exemplary methods also include maintaining the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

[0026] In some embodiments, these exemplary methods also include, using the derived one or more security keys, communicating with the UE via an SCG provided by the SN. In some of these embodiments, communicating with the UE via the SCG using the derived one or more security keys includes receiving a random access from the UE a cell of the SCG and subsequently receiving a RRCReconfigurationComplete message from the UE using the derived one or more security keys.

[0027] Other embodiments include exemplary methods (e.g., procedures) for an MN configured to communicate with a UE in dual connectivity with an SN. In general, these exemplary methods can be complementary to the exemplary methods for a UE and for an SN, summarized above.

[0028] These exemplary methods include sending a sequence of values to the UE and to the SN. The values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN. These exemplary methods also include, while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, sending, to the UE and to the SN, a further value usable for derivation of one or more security keys for communication between the UE and the SN. More specifically, the further value is usable for derivation of the one or more security keys prior to using a next available one of the at least one unused value of the sequence.

[0029] In some embodiments, these exemplary methods also include sending to the UE an indication to use the received further value instead of the next available one of the at least one unused value of the sequence. The derivation of the one or more security keys by the UE is further based on the indication.

[0030] Various features summarized below are also applicable to the various embodiments summarized above.

[0031] In some embodiments, the sequence of values is part of a configuration for SCPAC associated with an SCG, and the further value is part of a configuration for CP AC associated with the SCG. In some embodiments, the one or more security keys are derived by the UE and the SN based on using the further value as an input to a KDF.

[0032] In some embodiments, the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence. In some embodiments, the sequence of values does not include the further value.

[0033] Other embodiments include UEs (e.g., wireless devices) as well as SNs and MNs (e.g., base stations, eNBs, gNBs, ng-eNBs, etc.) configured to perform operations corresponding to any of the exemplary methods described herein. Other embodiments include non-transitory, computer- readable media storing program instructions that, when executed by processing circuitry, configure such UEs, SNs, and MNs to perform operations corresponding to any of the exemplary methods described herein.

[0034] These and other embodiments described herein can provide various advantages, benefits, and / or solutions to problems. For example, unlike conventional techniques, embodiments may activate a new security key for SCPAC when there is a PDCP COUNT wrap-around about to occur in an SN. As another example, unlike conventional techniques, embodiments may avoid discarding an entire sequence of configured keys - even for other candidate SNs - that are unaffected by the connection between the UE and the specific SN for which a key update is needed. At a high level, embodiments may improve security of DC between UEs and a RAN.

[0035] These and other objects, features, and advantages of embodiments of the present disclosure will become apparent upon reading the following Detailed Description in view of the Drawings briefly described below.

[0036] BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 is a high-level view of an exemplary 5G / NR network architecture.

[0038] Figure 2 shows an exemplary configuration of NR user plane (UP) and control plane (CP) protocol stacks.

[0039] Figure 3 shows an exemplary security procedure for SCPAC, in which the MN prepares a UE and candidate SNs with a sequence of identifiers for keys and the candidate SNs with respective sequences of corresponding keys.

[0040] Figure 4 shows a signaling diagram of a procedure between a UE, a MN, and an SN, according to some embodiments of the present disclosure.

[0041] Figure 5 shows an exemplary ASN. l data structure for a ConditionalReconflguration information element (IE), according to various embodiments of the present disclosure.

[0042] Figure 6 shows a flow diagram of an exemplary method for a UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0043] Figure 7 shows a flow diagram of an exemplary method for a first RAN node (e.g., base station, eNB, gNB, ng-eNB, etc.), according to various embodiments of the present disclosure.

[0044] Figure 8 shows a flow diagram of an exemplary method for a second RAN node (e.g., base station, eNB, gNB, ng-eNB, etc.), according to various embodiments of the present disclosure.

[0045] Figure 9 shows a flow diagram of an exemplary method for a UE (e.g., wireless device), according to various embodiments of the present disclosure.

[0046] Figure 10 shows a flow diagram of an exemplary method for a master node (MN, e.g., base station, eNB, gNB, ng-eNB, etc.), according to various embodiments of the present disclosure.

[0047] Figure 11 shows a flow diagram of an exemplary method for a secondary node (SN, e.g., base station, eNB, gNB, ng-eNB, etc.), according to various embodiments of the present disclosure.

[0048] Figure 12 shows a communication system according to various embodiments of the present disclosure. Figure 13 shows a UE according to various embodiments of the present disclosure.

[0049] Figure 14 shows a network node according to various embodiments of the present disclosure.

[0050] Figure 15 is a block diagram of a virtualization environment in which various embodiments of the present disclosure may be virtualized.

[0051] DETAILED DESCRIPTION

[0052] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided as examples to convey the scope of the subject matter to those skilled in the art.

[0053] In general, all terms used herein are to be interpreted according to their ordinary meaning to a person of ordinary skill in the relevant technical field, unless a different meaning is expressly defined and / or implied from the context of use. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise or clearly implied from the context of use. The operations of any methods and / or procedures disclosed herein do not have to be performed in the exact order disclosed, unless an operation is explicitly described as following or preceding another operation and / or where it is implicit that an operation must follow or precede another operation. Any feature of any embodiment disclosed herein can apply to any other disclosed embodiment, as appropriate. Likewise, any advantage of any embodiment described herein can apply to any other disclosed embodiment, as appropriate.

[0054] Furthermore, the following terms are used throughout the description given below:

[0055] • Radio Access Node: As used herein, a “radio access node” (or equivalently “radio network node,” “radio access network node,” or “RAN node”) can be any node in a radio access network (RAN) that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., gNB in a 3GPP 5G / NR network or an enhanced or eNB in a 3 GPP LTE network), base station distributed components (e.g, CU and DU), a high-power or macro base station, a low-power base station (e.g., micro, pico, femto, or home base station, or the like), an integrated access backhaul (IAB) node, a transmission point (TP), a transmission reception point (TRP), a remote radio unit (RRU or RRH), and a relay node.

[0056] • Core Network Node: As used herein, a “core network node” is any type of node in a core network. Some examples of a core network node include, e.g., a Mobility Management Entity (MME), a serving gateway (SGW), a PDN Gateway (P-GW), a Policy and Charging Rules Function (PCRF), an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a Charging Function (CHF), a Policy Control Function (PCF), an Authentication Server Function (AUSF), a location management function (LMF), or the like.

[0057] • Wireless Device: As used herein, a “wireless device” (or “WD” for short) is any type of device that is capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Communicating wirelessly can involve transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information through air. Unless otherwise noted, the term “wireless device” is used interchangeably herein with the term “user equipment” (or “UE” for short), with both of these terms having a different meaning than the term “network node”.

[0058] • Radio Node: As used herein, a “radio node” can be either a “radio access node” (or equivalent term) or a “wireless device.”

[0059] • Network Node: As used herein, a “network node” is any node that is either part of the radio access network (e.g., a radio access node or equivalent term) or of the core network (e.g., a core network node discussed above) of a cellular communications network. Functionally, a network node is equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or equipment in the cellular communications network, to enable and / or provide wireless access to the wireless device, and / or to perform other functions (e.g, administration) in the cellular communications network.

[0060] • Node: As used herein, the term “node” (without prefix) can be any type of node that can in or with a wireless network (including RAN and / or core network), including a radio access node (or equivalent term), core network node, or wireless device. However, the term “node” may be limited to a particular type (e.g., radio access node, IAB node) based on its specific characteristics in any given context.

[0061] The above definitions are not meant to be exclusive. In other words, various ones of the above terms may be explained and / or described elsewhere in the present disclosure using the same or similar terminology. Nevertheless, to the extent that such other explanations and / or descriptions conflict with the above definitions, the above definitions should control.

[0062] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system and can be applied to any communication system that may benefit from them. In such case, a skilled person will readily understand how 3GPP-specific terms used to describe various embodiments are examples of more generic terms that be used to describe broader application to communication systems.

[0063] Figure 2 shows an exemplary configuration of NR user plane (UP) and control plane (CP) protocol stacks between a UE (210), a gNB (220), and an AMF (230). Physical (PHY), Medium Access Control (MAC), Radio Link Control (RLC), and Packet Data Convergence Protocol (PDCP) layers between UE and gNB are common to UP and CP. PDCP provides ciphering / deciphering, integrity protection, sequence numbering, reordering, and duplicate detection for both CP and UP, as well as header compression and retransmission for UP data.

[0064] On the UP side, Internet protocol (IP) packets arrive to PDCP as service data units (SDUs), and PDCP creates protocol data units (PDUs) to deliver to RLC. The Service Data Adaptation Protocol (SDAP) layer handles quality-of-service (QoS) including mapping between QoS flows and Data Radio Bearers (DRBs) and marking QoS flow identifiers (QFI) in UL and DL packets. RLC transfers PDCP PDUs to MAC through logical channels (LCH). RLC provides error detection / correction, concatenation, segmentation / reassembly, sequence numbering, reordering of data transferred to / from the upper layers. MAC provides mapping between LCHs and PHY transport channels, LCH prioritization, multiplexing into or demultiplexing from transport blocks (TBs), hybrid ARQ (HARQ) error correction, and dynamic scheduling (in gNB). PHY provides transport channel services to MAC and handles transfer over the NR radio interface, e.g., via modulation, coding, antenna mapping, and beam forming.

[0065] On the CP side, the non-access stratum (NAS) layer between UE and AMF handles UE / gNB authentication, mobility management, and security control. RRC sits below NAS in the UE but terminates in the gNB rather than the AMF. RRC controls communications between UE and gNB at the radio interface as well as the mobility of a UE between cells in the NG-RAN. RRC also broadcasts system information (SI) and performs establishment, configuration, maintenance, and release of DRBs and Signaling Radio Bearers (SRBs) and used by UEs. Additionally, RRC controls addition, modification, and release of carrier aggregation (CA) and dual-connectivity (DC) configurations for UEs, and performs various security functions such as key management.

[0066] After a UE is powered ON it will be in the RRC IDLE state until an RRC connection is established with the network, at which time the UE will transition to RRC CONNECTED state (e.g., where data transfer can occur). The UE returns to RRC IDLE after the connection with the network is released. In RRC IDLE state, the UE’s radio is active on a discontinuous reception (DRX) schedule configured by upper layers. During DRX active periods (also referred to as “DRX On durations”), an RRC IDLE UE receives SI broadcast in the cell where the UE is camping, performs measurements of neighbor cells to support cell reselection, and monitors a paging channel on PDCCH for pages from 5GC via gNB. An NR UE in RRC IDLE state is not known to the gNB serving the cell where the UE is camping. However, NR RRC includes an RRC_INACTIVE state in which a UE is known (e.g., via UE context) by the serving gNB. RRC INACTIVE has some properties similar to a “suspended” condition used in LTE.

[0067] Seamless mobility is a key feature of 3GPP radio access technologies (RATs) such as LTE and NR. In general, a RAN (e.g., NG-RAN) configures a UE in RRC_CONNECTED state to perform and report radio resource management (RRM) measurements to assist network- controlled mobility decisions, such as for handover from a serving cell to a target cell. Upon the reported measurements meeting a certain condition or threshold, the serving RAN node may send a handover command to the UE, indicating a target cell for the handover. In NR, the handover command is an RRCReconflguration message with a reconflgurationWithSync field. The procedure to perform a handover is sometimes also referred to as “L3 mobility”, as it is controlled by layer 3 (L3, i.e., RRC) and the messages exchanged are part of L3.

[0068] These reconfigurations are prepared in advance by a target RAN node serving a target cell, upon a request from the UE’s serving RAN node. This request is transmitted over the Xn interface in case the serving and target RAN nodes are part of the NG-RAN. The reconfiguration in the handover command considers the UE’s existing RRC configuration in its current serving cell (also referred to as “source cell”), which are provided in the inter-node request. In some cases, the reconfiguration can be provided as a “delta” to the UE’s existing configuration in the source cell, which reduces the size of the handover command.

[0069] The reconfiguration provided by the target RAN node contains all information the UE needs to access the target cell, e.g., random access configuration, a new cell radio network temporary identifier (C-RNTI) assigned to the UE in the target cell, and parameters enabling the UE to calculate security keys that it can use when communicating with the target cell (including sending a handover complete message).

[0070] In general, UE nobility in RRC CONNECTED state is network-based as the network has the most information about the current conditions such as cell loading (UEs and / or traffic), available node resources (e.g., processing), available frequencies, etc. Depending on the required QoS, either a seamless or a lossless handover is performed as appropriate for each user plane radio bearer, as explained below.

[0071] As briefly mentioned above, LTE Rel-12 introduced dual connectivity (DC) whereby a UE is connected simultaneously to an MN that provides an MCG and an SN that provides an SCG. 3GPP TR 38.804 (v!4.0.0) describes various exemplary DC scenarios or configurations in which the MN and SN can apply NR, LTE, or both. The MN controls the UE-RAN connection using the radio resource control (RRC) protocol, and can configure SNs with radio and security parameters enabling them to establish additional connections with the UE. The SN configuration is performed using the XnAP protocol. The security parameters included cryptographic keys and identifiers for encryption and integrity protection algorithms.

[0072] A UE may change or add SCGs by a procedure called conditional PSCell addition or change (CP AC). As a mobility enhancement for 3GPP Rel-18, prior to performing the CPAC, the UE may be configured to perform one or more subsequent CPACs (SCPAC) without any additional reconfiguration by the MN. In particular, the UE is configured with a list of conditional reconfigurations, each of which includes condition(s) and a configuration to apply when the condition(s) is / are fulfilled.

[0073] The UE may also configured with a list of sk-Counter values for a group of cells, with each sk-Counter being associated with a security configuration. If the UE changes cell group, the UE applies the next sk-Counter value in the list and the associated security configuration. Application of an sk-Counter value comprises computing a cryptographic key based on at least part of the counter value.

[0074] One aspect of the Rel-18 enhancement is that SNs may receive several cryptographic keys, each of which is derived by the UE and the MN individually using a common derivation process. The derivation process involves inputting a key KgNB (shared between UE and MN) and a counter C into a Key Derivation Function (KDF). The KDF may be a Pseudo Random Function (PRF) such as HMAC-SHA256. The counter C is incremented for each derived key. Under the assumption that the KDF is secure, the monotonically increasing values of C ensure that each key will be different. This is important to mitigate attacks based on relations between multiple uses of keys, an example of which is referred to as “two-time pad”.

[0075] In addition to preparing SNs with several keys, the MN provides the UE with the sequence of counter values that was used to derive the keys for each SN. Because the UE has KgNB and the per-SN sequence of counter values, it can derive the correct key when connecting to an SN without the MN needing to derive and provide the UE with a new key. The UE takes the next value in the sequence when connecting to an SN, thereby ensuring that a fresh key is used for every new connection. As such, the counter values serve as unique identifiers for each key, at least with respect to an individual SN.

[0076] Figure 3 shows an exemplary security procedure for SCPAC, in which an MN prepares a UE and candidate SNs with a sequence of identifiers for keys and the candidate SNs with respective sequences of corresponding keys. Although the operations in Figure 3 are given numerical labels, this is done to facilitate explanation rather than to require or imply any specific operational order, unless expressly stated otherwise. In operation 1, the UE (310) and the MN (320) establish an RRC connection. In operations 2a-b, the MN sends an SN Addition / Modification Request message to each candidate target SN (330, 340) over the Xn-C interface, to negotiate available resources, configuration, and algorithms at each candidate target SN. The MN assigns a sequence of distinct SN Counter values per candidate target SN during the SCPAC procedure. The MN derives the Ksx keys corresponding to the sequence of SN Counter values from the KNG-RAN. The MN delivers the sequence of SN Counter values and corresponding KSN keys to the respective candidate target SNs. The UE security capabilities and the UP security policy received from the SMF are also sent to SN.

[0077] In operation 3, the candidate target SNs store the received sequence of SN Counter values and corresponding KSN keys. Each SN allocates the necessary resources and chooses the ciphering algorithm and integrity algorithm which has the highest priority from its configured list and is also present in the UE’s security capability.

[0078] In operation 4, each candidate target SN sends an SN Addition / Modification Acknowledge message to the MN, indicating availability of requested resources and identifiers for the selected algorithm(s) for the requested DRBs for the UE. The UP integrity protection and encryption indications shall be sent to the MN. In operation 5, the MN sends an RRCReconflgurationRequest message to the UE, instructing it to configure the new DRBs for the selected target SN. The MN also includes all candidate SCG configuration(s) for one or multiple candidate SN(s) in the same RRCReconflgurationRequest message as the one that activates the new KNG-RAN in the UE.

[0079] In operation 6, the UE accepts the RRCReconflgurationRequest after validating its integrity using the KRRCint of the MN. In operation 7, when the UE selects a target SN (e.g., SN1) for the first time or a subsequent time, the UE takes an unused SN Counter value in the SCG configuration for the selected candidate target SN and computes the corresponding KSN. The UE also computes the needed UP keys and activates UP protection as per the indications received for the associated DRBs, respectively.

[0080] In operation 8, the UE sends an RRCReconflgurationComplete message to the MN including the unused SN Counter value. The UE activates the chosen encryption / decrypt! on and integrity protection keys with the SN at this point. In operation 9, the MN sends an SN Reconfiguration Complete message to the selected SN, including the unused SN Counter value received in operation 8, thereby informing the target SN of the configuration result.

[0081] In operation 10, when the Target SN receives SN Reconfiguration Complete message, then in case of failure in step 11, the Target SN chooses the KSN key of the UE corresponding to the unused SN Counter value, received in SN Reconfiguration Complete message, to establish the security association with the UE. The Target SN shall derive the user plane encryption key, and user plane integrity key when configured, from the KSN key for protecting their communications. In operation 11, the UE initiates a random access request to the selected target SN (e.g., SN1) and subsequently sends protected UP messages to the selected target SN using the UP encryption key (and UP integrity key when configured) computed in operation 7 and activates UP protection. The UE activates the chosen encryption / decry ption and integrity protection with SN for the associated DRBs. When the target SN receives the random access request and protected UP messages from the UE, the target SN chooses the first unused KSN key of the UE to establish the security association with the UE. The Target SN computes the UP encryption key (and UP integrity key when configured) and activates the chosen encryption / decryption and integrity protection with the UE for the associated DRBs.

[0082] However, there are various scenarios in which the MN’s advance provisioning of a UE with sequences of counter values for different CPAC candidate SNs (e.g., as illustrated in Figure 3) may be wasted. For example, the SN and the UE protect their connection using PDCP encryption and integrity protection. To synchronize encryption and ensure that each PDCP packet is encrypted with a different keystream (i.e., to avoid a two-time pad), the UE and SN PDCP layers input an initialization vector (IV) to the encryption function. The IV must be unique per PDCP packet, which is facilitated by using a 32-bit PDCP packet counter (PDCP COUNT) that is incremented (i.e., by one) for each transmitted / received packet.

[0083] If many PDCP packets are sent between UE and SN, the 32-bit PDCP COUNT may wrap around and result in keystream re-use, which may lead to leaked information and privacy problems. Previous 3GPP releases only configured a single key per SN and the solution to PDCP COUNT wrap-around was that the SN requested a new key from the MN, which derived a new key and informed the UE to do the same. In the Rel-18 enhancements, however, the MN provisions the UE with sequences of counter values for different candidate SNs. Applying the mechanism from previous 3GPP releases in this situation would waste all that preparation work.

[0084] As another example, while being configured for SCPAC, the UE may receive a configuration from the MN to perform a (non-conditional) mobility operation such as a PSCell / SN addition or a PSCell / SN change. In this operation, the UE will be configured with a new security key (or a counter value to generate the security key) to be used in the new PSCell in the new SN. However, if the new SN was one of the candidate SNs for which the UE was already configured with a sequence of counter values, the validity and / or handling of these previously configured parameters is unclear. Moreover, the SCPAC preparation work for this SN may be wasted, as in the other example above.

[0085] In general, SNs do not have a connection that can be used for signaling a key change to the UE. Furthermore, 3GPP have decided that the MN controls key changes between the SN and the UE. Accordingly, embodiments of the present disclosure provide flexible and efficient techniques in which the MN has a more granular policy for controlling key changes between a UE and different candidate SNs for the UE. Embodiments are based on Applicant’s recognition that it is possible to separate the actions of activating a new security key and of providing counter value sequences to the UE.

[0086] In some embodiments, an SN requests a new key for a specific UE from the MN, which may be aware that the UE has unused counter values usable with the SN. In this case, the MN indicates to the UE, and possibly also to the SN, to activate the next fresh key in the sequence. In other embodiments, the MN can provision a new counter value sequence in the UE for that SN. In the same RRC message provisioning the sequence, the MN can include an indication for the UE to activate a new key. The UE then interprets that as first replacing the previous sequence of counter values with the new one and then activating the key corresponding to the first counter value in the new sequence.

[0087] In general, embodiments involve a UE in DC with an MN and an SN. As a pre-condition, the MN has prepared the UE with a sequence of identifiers for keys, from which the UE can derive the corresponding key as illustrated in Figure 3. The keys corresponding to the sequence of identifiers can be considered a “sequence of keys”. The UE is connected to the SN and they secure their communication based on one of the keys in the sequence. The sequence is associated with a group of cells that may be controlled or provided by the same SN. In a variant, the UE is configured with multiple sequences of key identifiers, with different sequences being associated with different SCGs and / or different SNs that provide these different SCGs.

[0088] Some embodiments of the present disclosure may be summarized as follows. The MN receives a request from the SN to update the key for the current connection between the SN and the UE. The MN determines whether the UE has access to a sufficient number of keys (or key identifiers / sK-Counter values), based on a threshold that may be MN-configured, standardized, or implementation-specific. If the MN determines that the UE does not have access to a sufficient number, the MN sends the UE a new sequence of identifiers (possibly of length 0 or 1) that is associated with group of cells that the UE’s current PSCell belongs to and that is provided by the UE’s current SN. The MN also indicates to the UE that it should activate the next key in the sequence for the communication with the SN.

[0089] Embodiments of the present disclosure may provide various advantages, benefits, and / or solutions to problems. For example, unlike conventional techniques, embodiments may activate a new key for SCPAC when there is a PDCP COUNT wrap-around about to occur in an SN. As another example, unlike conventional techniques, embodiments may avoid discarding an entire sequence of configured keys - even for other candidate SNs - that are unaffected by the connection between the UE and the specific SN for which a key update is needed. At a high level, embodiments may improve security of DC between UEs and a RAN.

[0090] Figure 4 shows a signaling diagram between a UE (410), an MN (420), and an SN (430) according to some embodiments of the present disclosure. As a pre-condition, the UE is configured with one or more SCPAC configurations, each of which includes a configuration for a candidate PSCell / SCG and execution condition(s) whose fulfillment causes the UE to apply the configuration. The UE is also configured with a sequence (or list) of one or more sk-Counter values for a cell group, which are typically controlled by the SN. When the UE changes to a PSCell that belongs to another cell group (i.e., typically provided by another SN), the UE applies the next sk-Counter value in the sequence for that new cell group. In this manner, the UE obtains a new security key to be used for communication with the new PSCell / SN, via derivation or retrieval.

[0091] In Figure 4, the SN initiates a security key change for the UE by sending the MN an SN Modification Required message that includes a key change indication for SCPAC. The MN responds with an SN Modification Request message that includes a SN counter value and a security key (Ksn). The SN responds with an SN Modification Request Acknowledgement message.

[0092] Subsequently, the MN sends the UE an RRCReconflgurationRequest message including a sequence of counter values for the SN. In some variants, the message may also include an indication that the UE should activate a new security configuration (including activating a new key). For example, the indication may be a single bit, indicating that the UE shall take the next available sk-Counter value in the sequence. In Figure 4, this indication is called NextUnusedSNCounter . The UE may perform a reconfigurationWithSync to apply the new security configuration and activate the new security key for its existing connection with the SN.

[0093] In case the indication is not included in the RRCReconflgurationRequest message, the received new sequence of sk-Counter values - for a cell group that the UE currently is connected to - implicitly indicates for the UE to apply the new sk-Counter values for the existing SN connection. On the other hand, if the new sequence of sk-Counter values is for a cell group that the UE is not currently connected to, the UE stores the new sequence and applies anew sk-Counter value from the sequence when it connects to the associated cell group.

[0094] After applying the new security configuration (as appropriate) including activation of the new security key, the UE responds to the MN with an RRCReconfiguration-Complete message. The UE may also send an RRCReconfiguration-Complete message to the SN based on the SN counter value selected by the UE.

[0095] Another scenario addressed by embodiments of the present disclosure is PDCP COUNT wrap-around described above. In some embodiments, the UE may indicate to the MN that it is close to wrap around of a PDCP COUNT associated with the SN connection. In response, the MN may provide a new security configuration to the SN and the UE, according to the procedure above.

[0096] In other embodiments, the UE has a connection to the SN via a PSCell in which communication is secured based on a security key and was previously configured with a sequence of one or more sk-Counter values (possibly kept in a list) for obtaining new keys for the SCG to which the PSCell belongs. The UE receives a new sk-Counter value from the MN, obtains a new security key based on the received sk-Counter value, and activates the new security key to communicate with the PSCell / SN. In some embodiments, when activating the new security key, the UE performs a random access procedure towards the PSCell / SN and sends an RRCReconflgurationComplete message to the MN.

[0097] In general, the UE behaves in this manner even when the UE was previously configured with one or more other sk-Counter values for obtaining security keys to communicate with the PSCell / SN. In other words, the received sk-Counter value replaces the previously configured sk- Counter values, and the UE uses the received sk-Counter value while retaining the previously configured sk-Counter values (e.g., in storage).

[0098] In some of these embodiments, the UE also receives an indication to use the received sk- Counter value instead of any previously configured sk-Counter values applicable for the PSCell. In some of these embodiments, the sequence of sk-Counter values is associated with a group of cells that are provided by SN.

[0099] Embodiments also include procedures performed by an MN that has configured a UE with an SCPAC configuration. The MN determines that an update to the UE’s security configuration is needed, e.g., because the UE’s PSCell needs to be changed. In particular, the new PSCell is not configured as a candidate cell for CP AC or SCPAC, or is configured as a candidate cell but associated conditions have not been fulfilled in the UE.

[0100] In a variant, the MN determines that an update is needed based on receiving an SN request related to an update of the UE security configuration. For example, the SN may trigger PSCell change for the UE or indicate to the MN that the PDCP COUNT is close to wrap around.

[0101] Based on this determination, the MN sends anew sk-Counter value to the UE, even though the UE was previously configured with one or more other sk-Counter values for obtaining new keys. In other words, the sent sk-Counter replaces the previously configured sk-Counter values. The MN may receive a confirmation message from the UE (e.g. RRCReconflgurationComplete) that the new sk-Counter value has been applied.

[0102] In some of these embodiments, the MN also sends the UE an indication to use the provided sk-Counter value instead of any previously configured sk-Counter values applicable for the PSCell. In other of these embodiments, the MN sends the UE an indication to activate the next sk- Counter value in the list of previously configured sk-Counter values. The MN also sends the SN a new security configuration or an indication to activate the next sk-Counter value in the list of previously configured sk-Counter values. If the MN receives a confirmation message from the UE (e.g., RRCReconfigurationComplete), the MN may forward it to the SN.

[0103] Embodiments also include procedures performed by an SN that provides a PSCell for a UE in DC and that is configured for SCPAC. The SN may send an SN request related to an update of the UE security configuration. For example, the SN may trigger PSCell change for the UE or indicate to the MN that the PDCP COUNT is close to wrap around. The SN receives from the MN a responsive message including one of the following: a new security configuration for the UE, or an indication to activate the next sk-Counter value in the list of previously configured sk-Counter values. The SN may receive a confirmation message from the UE (possibly via the MN) indicating that the new sk-Counter value has been applied.

[0104] Some embodiments can be realized as 3GPP specifications of messages, information elements (IES), and / or message fields transmitted by a UE. Figure 5 shows an exemplary ASN.l data structure for an RRC ConditionalReconflguration IE used to add, modify, or remove conditional reconfigurations, according to embodiments of the present disclosure. The IE shown in Figure 5 includes an sk-CounterConfiguration field, which includes a list of sk-Counter configurations to add / modify and / or a list of sk-Counter configurations to release. Each sk- Counter configuration Includes a list of sk-Counter values used to derive S-KSNB for inter-SN subsequent CPAC. If this field is configured, the RAN shall not configure the field sk-Counter within the RRCReconflguration message for conditional reconfiguration execution for subsequent CPAC. Of particular interest to embodiments of the present disclosure is the applyNextCounter field, which indicates that the UE shall apply the next counter in the list.

[0105] Some embodiments can be realized as procedural text in 3GPP specifications, which specify UE and / or RAN implementation. The following text for 3 GPP TS 38.331 (18.0.0) illustrates one example of embodiments discussed above, with underline indicating added text and ellipses indicating existing text that has been omitted for brevity.

[0106] *** Begin exemplary text for 3GPP TS 38.331 ***

[0107] 5.3.5.13.7 sk-Counter configuration addition / modification / removal

[0108] The UE shall: l>for each securityCellSetld received in the sk-CounterConflgToAddModList IE:

[0109] 2> if an entry with the matching securityCellSetld exists in the sk-

[0110] CounterConfigToAddModList within the VarConditionalReconflg'.

[0111] 3> replace the sk-CounterList within the VarConditionalReconflg with the sk- CounterList according to the received securityCellSetld, 2>else:

[0112] 3>add a new entry for this securityCellSetld within the VarConditionalReconflg,' l>for each securityCellSetld value included in the sk-CounterConflgToRemoveList that is part of the current sk-CounterConflgToAddModList in VarConditionalReconflg'.

[0113] 2> remove the entry with the matching securityCellSetld from the sk-

[0114] CounterConfigToAddModList

[0115] 1> if applyNextCounter is set to true and the value of the securityCellSetld is equal to the value of servingSecurityCellSetld',

[0116] 2> perform security key update procedure as specified in 5, 3, 5, 7;

[0117] *** End exemplary text for 3GPP TS 38.331 ***

[0118] Another scenario addressed by embodiments of the present disclosure is when a UE is configured with a sequence of one or more sk-Counter values (e.g., in a list) for a plurality of cells (e.g., PSCells belonging to the same SN) to which the UE has no existing connection. For example, the UE is configured for SCPAC for the plurality of candidate PSCells, with each SCPAC configuration including execution condition(s) and a configuration to be applied when the execution condition(s) is / are fulfilled for a candidate PSCell.

[0119] In some variants, the UE may have a connection to another PSCell such that the SCPAC configurations are essentially conditional PSCell change (CPC) configurations. In other variants, the UE may have a PCell / MCG connection but no PSCell / SCG connection, such that the SCPAC configurations are essentially conditional PSCell addition (CPA) configurations.

[0120] When the UE changes SCGs (typically to an SCG provided by an SN) or when it enters DC and adds a connection to a new PSCell / SCG / SN due to execution of a subsequent CP AC configuration, the UE applies the next sk-Counter value in the list for that new SCG. Applying the next sk-Counter value includes the same UE operations as described above for other embodiments, and there are corresponding operations for MN and SN.

[0121] In some embodiments, the UE receives from the MN a command (e.g., RRCReconflguration message) to perform a non-conditional PSCell addition of a target PSCell / SN or a non-conditional PSCell change to a different target PSCell / SN. In doing so, the UE applies a new security key towards the new PSCell / SN and has been configured with a sequence of one or more sk-Counters associated the new PSCell / SN.

[0122] As part of the PSCell addition or PSCell change, the UE may perform a random access procedure to the target new PSCell / SN (e.g., reconflgurationWithSync) to apply the new security configuration and activate the new security key. In some of these embodiments, the UE sends an RRCReconflgurationComplete message to the MN as part of completing the PSCell addition or PSCell change procedure. The UE includes in the RRCReconfigurationComplete message an indication about which sk-Counter or security configuration that the UE applied for the connection to the new target PSCell / SN.

[0123] In some embodiments, the UE receives an indication to select and / or apply an sk-Counter that is part of a configured sequence of sk-Counter(s), to be used for the connection to the target PSCell. For example, the indication may be for the UE to select and apply the next available sk- Counter from a sequence of sk-Counters that is configured for a cell group that includes the target PSCell. If the UE is already configured with a sequence of sk-Counters for the cell group that includes the target PSCell, it selects and applies the next available sk-Counter from that list.

[0124] As another example, the indication may be for the UE to select and apply the next available sk-Counter from a sequence of sk-Counters that is configured for a cell group that does not include the target PSCell. This may occur when the UE is configured with SCPAC for one or more candidate PSCells provided by an SN, and the UE is then commanded to perform a (nonconditional) PSCell addition or change to another target PSCell provided by that same SN. Based on this indication, the UE uses the next available sk-Counter value for the different cell group but same SN.

[0125] In some variants, the UE receives an indication about which sequence of sk-Counters from which it should select and apply the next available sk-Counter. For example, different sequences of sk-Counters can be identified with different values in the securityCellSetld-r 18 field in the SK- CounterConfig-rl8 field in SK-CounterConfiguration-r 18. as illustrated in Figure 5. The UE selects (and applies) the first available sk-Counter value from the sequence that corresponds to the indicated securityCellSetld-r 18 value. In one example, the UE also stores the indicated securityCellSetld-r 18 value to the servingSecurityCellSetId-rl8 field in the UE variable VarServingSecurityCellSetID, so that the UE knows that it does not need to change security key if executing an SCPAC configuration with the same secur ityCellSetld-r 18 value (i.e., belonging to the same SN).

[0126] In other variants, as part of a configuration to perform a (non-conditional) PSCell addition or change, the UE receives an indication of which “security set” the target PSCell belongs to via the servingSecurityCellSetId-rl8 field of the ConditionalReconflguration IE illustrated in Figure 3. The UE then selects and applies the first available sk-Counter from the sequence that has a securityCellSetld-r 18 value that matches the value of the servingSecurityCellSetld-r 18 field.

[0127] In of these variants, if the servingSecurityCellSetld-r 18 value received in ConditionalReconflguration in the RRCReconfiguration message is different from the one that the UE has stored within VarServingSecurityCellSetID (i.e., indicating the current “security set” for the UE), the UE selects and applies the next available sk-Counter from the sequence with an securityCellSetld-r 18 value that matches the received servingSecurityCellSetld-r 18 value. On the other hand, if the received servingSecurityCellSetId-rl8 matches the value the UE has stored within VarServingSecurityCellSetID, then the UE does not select and apply any new sk-Counter. In other words, the UE does not change the security key for connection to the target PSCell.

[0128] In other variants, the UE receives a new sequence of sk-Counter values associated with the target PSCell / SN (or with another cell group). In some of these variants, the new list may be received with an indication that the UE shall apply a new sk-Counter value (i.e., first / next available), including obtaining a new key associated with the new sk-Counter value for the connection with the new PSCell / SN. In other of these variants, receiving the list implicitly indicates that the UE shall apply a new sk-Counter value (i.e., first / next available) for obtaining and activating a security key for the connection to the target PSCell / SN.

[0129] In some embodiments, the UE receives a new sk-Counter value to use for the target PSCell as part of a non-conditional PSCell addition or change procedure, but the UE has an SCPAC configuration for that target PSCell. In such case, the UE applies the received sk-Counter value even though the UE was already configured with one or more other sk-Counter values for obtaining new keys associated to the target PSCell / SN of the PSCell addition or PSCell change. In other words, the received sk-Counter overtakes the already configured sk-Counter values and the UE uses this value and it keeps the other configured sk-Counter values (in the configured sequence of sk-Counters values) stored.

[0130] In some variants, the UE receives an indication to use the received sk-Counter value even though the UE is configured with sk-Counter values applicable for the same cell (PSCell). In some variants, the sequence of sk-Counter values is associated with the target PSCell and possibly other cells, e.g., a group of cells that belong to the same SN.

[0131] In one example, the UE receives the configuration to perform the (non-conditional) PSCell addition or the (non-conditional) PSCell change from the MN. In one example, the UE receives the configuration (to perform the non-conditional PSCell change) from the SN.

[0132] Various features of some embodiments described above correspond to various operations illustrated in Figures 6-8, which show exemplary methods (e.g, procedures) for a UE, a first RAN node, and a second RAN node, respectively. In other words, various features of operations described for Figures 6-8 correspond to various embodiments described above. Furthermore, the exemplary methods shown in Figures 6-8 can be used cooperatively to provide various benefits, advantages, and / or solutions to problems described herein. Although Figures 6-8 show specific blocks in particular orders, the operations of the exemplary methods can be performed in different orders than shown and can be combined and / or divided into blocks having different functionality than shown. Optional blocks or operations are indicated by dashed lines. In particular, Figure 6 shows an exemplary method (e.g., procedure) for a UE configured to operate in dual connectivity (DC) with a radio access network (RAN), according to various embodiments of the present disclosure. The exemplary method can be performed by a UE (e.g., wireless device) such as described elsewhere herein.

[0133] The exemplary method includes the operations of block 610, where the UE communicates with a second RAN node via a secondary cell group (SCG). The communication via the SCG is secured using a first security key that is based on a first value from a first sequence of values. The exemplary method also includes the operations of block 640, where the UE receives one of the following information from a first RAN node via a master cell group (MCG):

[0134] • a first indication to activate a second security key based on a second value from the first sequence of values; or

[0135] • at least one of the following second information: a second indication to activate a second security key based on a first value from a second sequence of values, the second sequence of values, and an identifier of the second sequence of values.

[0136] The exemplary method also includes the operations of blocks 660-670, where the UE determines the second security key in accordance with the received information and, using the determined second security key, communicates with the SCG or with a second SCG provided by a third RAN node.

[0137] In some embodiments, the second value from the first sequence of values is a next available value in the first sequence. In some embodiments, the first value from the second sequence of values is a next available value in the second sequence. In some of these embodiments, determining the second security key in block 660 is based on using the next available value in the first or second sequence as an input to a key derivation function (KDF). In some of these embodiments, the first indication indicates that the UE should use the next available value in the first sequence. In some of these embodiments, the second indication indicates that the UE should use the next available value in the second sequence.

[0138] In some embodiments, the first and second sequences are respective sequences of sk- Counter values in increasing order, with each value in a sequence being one greater than an immediately preceding value in the same sequence.

[0139] In some embodiments, the exemplary method also includes the operations of block 620, where the UE sends to the first RAN node a request for activation of a fresh security key for communication between the UE and the SCG. The first indication is received in response to the request. In some embodiments, the request is a notification of a pending wrap-around for a packet counter associated with a packet data convergence protocol (PDCP) layer between the UE and the second RAN node. In other embodiments, the exemplary method also includes the operations of block 620, where the UE receives from the MN a configuration for subsequent conditional PSCell activation or change (SCPAC) associated with the second SCG. In some of these embodiments, the second information is received in conjunction with anon-conditional PSCell change or addition involving the second SCG, prior to any conditions associated with the SCPAC to the second SCG being fulfilled. In some variants of these embodiments, the received second information includes the identifier of the second sequence, and the configuration for SCPAC includes the second sequence of values and an associated sequence identifier that matches the received identifier of the second sequence.

[0140] In some embodiments, communicating with the SCG using the determined second security key in bloc 670 includes the following operations, labelled with corresponding sub-block numbers:

[0141] • (671) performing a random access procedure towards the SCG or the second SCG, and

[0142] • (672) sending a second RRCReconflgurationComplete message to one of the following: the second RAN node via the SCG, or the third RAN node via the second SCG.

[0143] In some of these embodiments, the second RRCReconflgurationComplete message to the third RAN node includes an identifier of the second sequence. In some of these embodiments, the exemplary method also includes the operations of block 680, where the UE sends a first RRCReconflgurationComplete message to the first RAN node via the MCG. The first RRCReconflgurationComplete message includes an identifier of the second sequence.

[0144] In some embodiments, one of the following indicates for the UE to use the first value from the second sequence instead of using a next available value of the first sequence: the second indication explicitly; or the second sequence or the identifier thereof implicitly, when received without the second indication.

[0145] In some embodiments, the exemplary method also includes the operations of block 650, where in response to the second indication, the UE stores the first sequence of values such that the first sequence can be retrieved for subsequent communication with the SCG.

[0146] In addition, Figure 7 shows an exemplary method (e.g., procedure) for a first RAN node configured to provide an MCG for a UE, according to various embodiments of the present disclosure. The exemplary method can be performed by a RAN node (e.g., base station, eNB, gNB, ng-eNB, etc.) such as described elsewhere herein.

[0147] The exemplary method includes the operations of block 720, where the first RAN node receives a request for activation of a fresh security key for communication between the UE and a secondary cell group (SCG) provided by a second RAN node. The UE is configured to communicate securely via the SCG using a first security key that is based on a first value from a first sequence of values. The exemplary method also includes the operations of block 740, where the first RAN node sends one of the following information to the UE via the MCG and to the second RAN node:

[0148] • a first indication to activate a second security key based on a second value from the first sequence of values; or

[0149] • at least one of the following second information: a second indication to activate a second security key based on a first value from a second sequence of values, the second sequence of values, and an identifier of the second sequence of values.

[0150] In some embodiments, sending the first indication or the second information is based on the operations of block 730, where the first RAN node determines whether the first sequence of values is sufficient information from which the UE can derive the second security key (e.g., based on a configured threshold, as mentioned above). The first indication is sent when it is determined that the first sequence of values is sufficient, and the second information is sent when it is determined that the first sequence of values is not sufficient.

[0151] In some embodiments, the request is received from one of the following: the second RAN node, or the UE. In some of these embodiments, the request is a notification of a pending wraparound for a packet counter associated with a packet data convergence protocol (PDCP) layer between the UE and the second RAN node, wherein the first indication is sent in response to the notification.

[0152] In other of these embodiments, the exemplary method also includes the operations of block 710, where the first RAN node sends to the UE a configuration for SCPAC associated with a second SCG for the UE. In some variants of these embodiments, the request from the second RAN node is a key change indication for SCPAC. In other variants of these embodiments, the request relates to a non-conditional PSCell change or addition involving the second SCG, prior to any conditions associated with the SCPAC to the second SCG being fulfilled. In other variants of these embodiments, the second information includes the identifier of the second sequence, and the configuration for SCPAC includes the second sequence of values and an associated sequence identifier that matches the received identifier of the second sequence.

[0153] In some embodiments, the second value from the first sequence of values is a next available value in the first sequence. In other embodiments, the first value from the second sequence of values is a next available value in the second sequence. In some of these embodiments, the second security key is based on using the next available value in the first or second sequence as an input to a KDF.

[0154] In some embodiments, the first indication indicates that the UE should use the next available value in the first sequence. In some embodiments, the second indication indicates that the UE should use the next available value in the second sequence.

[0155] In some embodiments, the first and second sequences are respective sequences of sk- Counter values in increasing order, with each value in a sequence being one greater than an immediately preceding value in the same sequence.

[0156] In some embodiments, the exemplary method also includes the operations of block 750, where the first RAN node receives a first RRCReconflgurationComplete message from the UE via the MCG. The first RRCReconflgurationComplete message includes an identifier of the second sequence.

[0157] In some embodiments, one of the following indicates for the UE to use the first value from the second sequence instead of using a next available value of the first sequence: the second indication explicitly; or the second sequence or the identifier thereof implicitly, when received without the second indication.

[0158] In addition, Figure 8 shows an exemplary method (e.g., procedure) for a second RAN node configured to provide an SCG for a UE, according to various embodiments of the present disclosure. The exemplary method can be performed by a RAN node (e.g., base station, eNB, gNB, ng-eNB, etc.) such as described elsewhere herein.

[0159] The exemplary method includes the operations of block 820, where the second RAN node sends, to a first RAN node, a request for activation of a fresh security key for UE-SCG communication. The UE is further configured to communicate via an MCG provided by the first RAN node. The exemplary method includes the operations of block 830, where in response to the request, the second RAN node receives one of the following information from the first RAN node:

[0160] • a first indication to activate a second security key based on a second value from a first sequence of values being used by at least the UE; or

[0161] • at least one of the following second information: a second indication to activate a second security key based on a first value from a second sequence of values, the second sequence of values, and an identifier of the second sequence of values.

[0162] The exemplary method also includes the operations of block 840, where the second RAN node determines the second security key in accordance with the received information.

[0163] In some embodiments, the exemplary method also includes the operations of block 810, where prior to sending the request, the second RAN communicates with the UE via the SCG. The communication with the UE in block 810 is secured using a first security key that is based on a first value from the first sequence of values, with the first value preceding the second value.

[0164] In some embodiments, the exemplary method also includes the operations of block 850, where the second RAN node communicates with the UE via the SCG using the determined second security key (e.g., from block 840). In some of these embodiments, communicating with the UE via the SCG using the determined second security key in block 850 includes the operations of subblocks 851-852, where the second RAN node performs a random access procedure with the UE in the SCG and receives a RRCReconflgurationComplete message from the UE via the SCG. For example, the RRCReconflgurationComplete message includes an identifier of the second sequence.

[0165] In some embodiments, the request is a notification of a pending wrap-around for a packet counter associated with a packet data convergence protocol (PDCP) layer between the UE and the second RAN node, wherein the first indication is sent in response to the notification.

[0166] In other embodiments, the request is a key change indication for subsequent conditional PSCell activation or change (SCPAC) associated with a second SCG for the UE, wherein the second information is sent in response to the key change indication. In some of these embodiments, the request relates to a non-conditional PSCell change or addition involving the second SCG, prior to any conditions associated with the SCPAC to the second SCG being fulfilled. In some variants of these embodiments, the second information includes the identifier of the second sequence, and a configuration for SCPAC includes the second sequence of values and an associated sequence identifier that matches the received identifier of the second sequence.

[0167] In some embodiments, the second value from the first sequence of values is a next available value in the first sequence. In other embodiments, the first value from the second sequence of values is a next available value in the second sequence. In some of these embodiments, the second security key is based on using the next available value in the first or second sequence as an input to a KDF.

[0168] In some embodiments, the first indication indicates that the UE should use the next available value in the first sequence. In some embodiments, the second indication indicates that the UE should use the next available value in the second sequence.

[0169] In some embodiments, the first and second sequences are respective sequences of sk- Counter values in increasing order, with each value in a sequence being one greater than an immediately preceding value in the same sequence.

[0170] In some embodiments, the exemplary method also includes the operations of block 750, where the first RAN node receives a first RRCReconflgurationComplete message from the UE via the MCG. The first RRCReconflgurationComplete message includes an identifier of the second sequence.

[0171] In some embodiments, one of the following indicates for the UE to use the first value from the second sequence instead of using a next available value of the first sequence: the second indication explicitly; or the second sequence or the identifier thereof implicitly, when received without the second indication.

[0172] Various features of other embodiments described above correspond to various operations illustrated in Figures 9-11, which show exemplary methods (e.g., procedures) for a UE, a secondary node (SN), and a master node (MN), respectively. In other words, various features of operations described for Figures 9-11 correspond to various embodiments described above. Furthermore, the exemplary methods shown in Figures 9-11 can be used cooperatively to provide various benefits, advantages, and / or solutions to problems described herein. Although 9-11 show specific blocks in particular orders, the operations of the exemplary methods can be performed in different orders than shown and can be combined and / or divided into blocks having different functionality than shown. Optional blocks or operations are indicated by dashed lines.

[0173] In particular, Figure 9 shows an exemplary method (e.g., procedure) for a UE configured to communicate in dual connectivity with an MN and an SN, according to various embodiments of the present disclosure. The exemplary method can be performed by a UE (e.g, wireless device) such as described elsewhere herein.

[0174] The exemplary method includes the operations of block 910, where the UE receives a sequence of values from the MN. The values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN. The exemplary method includes the operations of block 920, where while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, the UE receives from the MN a further value usable for derivation of security keys for communication between the UE and the SN. The exemplary method includes the operations of block 940, where the UE derives one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence. The exemplary method also includes the operations of block 960, where the UE maintains the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

[0175] In some embodiments, the sequence of values is part of a configuration for subsequent conditional PSCell activation or change (SCPAC) associated with a secondary cell group (SCG), and the further value is part of a configuration for conditional PSCell activation or change (CPAC) associated with the SCG. In some embodiments, deriving the one or more security keys in block 940 is based on using the further value as an input to a key derivation function (KDF).

[0176] In some embodiments, the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence. For example, as discussed above, each value in the sequence may be an sk-Counter value. In some embodiments, the sequence of values does not include the further value. For example, as discussed above, the further value may also be an sk-Counter value. In some embodiments, the exemplary method also includes the operations of block 930, where the UE receives from the MN an indication to use the received further value instead of the next available one of the at least one unused value of the sequence. In such embodiments, deriving the one or more security keys in block 940 is further based on the indication.

[0177] In some embodiments, the UE is configured to communicate with the MN via a master cell group (MCG) and with the SN via a secondary cell group (SCG). In some of these embodiments, the exemplary method also includes the operations of block 950, where using the derived one or more security keys, the UE communicates with the SN via the SCG. In some variants of these embodiments, communicating with the SN via the SCG using the derived one or more security keys in block 950 includes the following operations, labelled with corresponding sub-block numbers:

[0178] • (951) performing a random access towards a cell of the SCG, and

[0179] • (952) subsequently sending a RRCReconfigurationComplete message to SN using the derived one or more security keys.

[0180] In addition, Figure 10 shows an exemplary method (e.g., procedure) for an SN configured to communicate with a UE in dual connectivity with an MN, according to various embodiments of the present disclosure. The exemplary method can be performed by a RAN node (e.g., base station, eNB, gNB, ng-eNB, etc.) such as described elsewhere herein.

[0181] The exemplary method includes the operations of block 1010, where the SN receives a sequence of values from the MN. The values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN. The exemplary method also includes the operations of block 1020, where while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, the SN receives from the MN a further value usable for derivation of security keys for communication between the UE and the SN. The exemplary method also includes the operations of block 1040, where the SN derives one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence. The exemplary method also includes the operations of block 1060, where the SN maintains the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

[0182] In some embodiments, the sequence of values is part of a configuration for SCPAC associated with an SCG, and the further value is part of a configuration for CP AC associated with the SCG. In some embodiments, deriving the one or more security keys in block 1040 is based on using the further value as an input to a KDF.

[0183] In some embodiments, the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence. For example, as discussed above, each value in the sequence may be an sk-Counter value. In some embodiments, the sequence of values does not include the further value. For example, as discussed above, the further value may also be an sk-Counter value.

[0184] In some embodiments, the exemplary method also includes the operations of block 1050, where using the derived one or more security keys, the SN communicates with the UE via an SCG provided by the SN. In some of these embodiments, communicating with the UE via the SCG using the derived one or more security keys in block 1050 includes the following operations, labelled with corresponding sub-block numbers:

[0185] • (1051) receiving a random access from the UE a cell of the SCG, and

[0186] • (1052) subsequently receiving a RRCReconflgurationComplete message from the UE using the derived one or more security keys.

[0187] In addition, Figure 11 shows an exemplary method (e.g., procedure) for an MN configured to communicate with a UE in dual connectivity with an SN, according to various embodiments of the present disclosure. The exemplary method can be performed by a RAN node (e.g., base station, eNB, gNB, ng-eNB, etc.) such as described elsewhere herein.

[0188] The exemplary method includes the operations of block 1110, where the MN sends a sequence of values to the UE and to the SN. The values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN. The exemplary method includes the operations of block 1120, where while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, the MN sends, to the UE and to the SN, a further value usable for derivation of one or more security keys for communication between the UE and the SN. More specifically, the further value is usable for derivation of the one or more security keys prior to using a next available one of the at least one unused value of the sequence.

[0189] In some embodiments, the sequence of values is part of a configuration for SCPAC associated with an SCG, and the further value is part of a configuration for CP AC associated with the SCG. In some embodiments, derivation of the one or more security keys is based on using the further value as an input to a KDF.

[0190] In some embodiments, the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence. For example, as discussed above, each value in the sequence may be an sk-Counter value. In some embodiments, the sequence of values does not include the further value. For example, as discussed above, the further value may also be an sk-Counter value.

[0191] In some embodiments, the exemplary method also includes the operations of block 1130, where the MN sends to the UE an indication to use the received further value instead of the next available one of the at least one unused value of the sequence. The derivation of the one or more security keys by the UE is further based on the indication.

[0192] In some embodiments, the MN is configured to communicate with the UE via an MCG.

[0193] Although various embodiments are described above in terms of methods, techniques, and / or procedures, the person of ordinary skill will readily comprehend that such methods, techniques, and / or procedures can be embodied by various combinations of hardware and software in various systems, communication devices, computing devices, control devices, apparatuses, non-transitory computer-readable media, computer program products, etc.

[0194] Figure 12 shows an example of a communication system 1200 in accordance with some embodiments. In this example, communication system 1200 includes a telecommunication network 1202 that includes an access network 1204 (e.g., RAN) and a core network 1206, which includes one or more core network nodes 1208. Access network 1204 includes one or more access network nodes, such as network nodes 1210a-b (one or more of which may be referred to as network nodes 1210), or any other similar 3GPP access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor.

[0195] In other words, network nodes may include disaggregated implementations or portions thereof. For example, in some embodiments, telecommunication network 1202 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in telecommunication network 1202 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in telecommunication network 1202, including one or more network nodes 1210 and / or core network nodes 1208.

[0196] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O-CU- CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adj ective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the 0-RAN Alliance or comparable technologies. Network nodes 1210 facilitate direct or indirect connection of UEs, such as by connecting UEs 1212a-d (one or more of which may be referred to as UEs 1212) to core network 1206 over one or more wireless connections.

[0197] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, communication system 1200 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. Communication system 1200 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0198] UEs 1212 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with network nodes 1210 and other communication devices. Similarly, network nodes 1210 are arranged, capable, configured, and / or operable to communicate directly or indirectly with UEs 1212 and / or with other network nodes or equipment in telecommunication network 1202 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in telecommunication network 1202.

[0199] In the depicted example, core network 1206 connects network nodes 1210 to one or more hosts, such as host 1216. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. Core network 1206 includes one or more core network nodes (e.g., 1208) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are applicable to the corresponding components of core network node 1208. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF). Host 1216 may be under the ownership or control of a service provider other than an operator or provider of access network 1204 and / or telecommunication network 1202, and may be operated by the service provider or on behalf of the service provider. Host 1216 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0200] As a whole, communication system 1200 of Figure 12 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0201] In some examples, telecommunication network 1202 is a cellular network that implements 3GPP standardized features. Accordingly, telecommunication network 1202 may support network slicing to provide different logical networks to different devices that are connected to telecommunication network 1202. For example, telecommunication network 1202 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0202] In some examples, UEs 1212 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to access network 1204 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from access network 1204. Additionally, a UE may be configured for operating in single- or multi-RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e., being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC). In the example, hub 1214 communicates with access network 1204 to facilitate indirect communication between one or more UEs (e.g., 1212c and / or 1212d) and network nodes (e.g., 1210b). In some examples, hub 1214 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, hub 1214 may be a broadband router enabling access to core network 1206 for the UEs. As another example, hub 1214 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 1210, or by executable code, script, process, or other instructions in hub 1214. As another example, hub 1214 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, hub 1214 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, hub 1214 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which hub 1214 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, hub 1214 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0203] Hub 1214 may have a constant / persistent or intermittent connection to network node 1210b. Hub 1214 may also allow for a different communication scheme and / or schedule between hub 1214 and UEs (e.g., 1212c and / or 1212d), and between hub 1214 and core network 1206. In other examples, hub 1214 is connected to core network 1206 and / or one or more UEs via a wired connection. Moreover, hub 1214 may be configured to connect to an M2M service provider over access network 1204 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with network nodes 1210 while still connected via hub 1214 via a wired or wireless connection. In some embodiments, hub 1214 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to network node 1210b. In other embodiments, hub 1214 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 1210b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0204] In some embodiments, UE 1212 may be configured to perform operations attributed to a UE in above descriptions of various embodiments, including the exemplary methods shown in Figures 6 and 9. In some embodiments, network node 1210 may be configured to perform operations attributed to a RAN node in above descriptions of various embodiments, including the exemplary methods shown in Figures 7-8 and 10-11. Figure 13 shows a UE 1300 in accordance with some embodiments. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by 3 GPP, including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0205] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0206] UE 1300 includes processing circuitry 1302 that is operatively coupled via a bus 1304 to an input / output interface 1306, a power source 1308, a memory 1310, a communication interface 1312, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 13. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0207] Processing circuitry 1302 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in memory 1310. Processing circuitry 1302 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field- programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, processing circuitry 1302 may include multiple central processing units (CPUs).

[0208] In the example, input / output interface 1306 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into UE 1300. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0209] In some embodiments, power source 1308 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. Power source 1308 may further include power circuitry for delivering power from power source 1308 itself, and / or an external power source, to the various parts of UE 1300 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of power source 1308. Power circuitry may perform any formatting, converting, or other modification to the power from power source 1308 to make the power suitable for the respective components of UE 1300 to which power is supplied.

[0210] Memory 1310 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, memory 1310 includes one or more application programs 1314, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 1316. Memory 1310 may store, for use by UE 1300, any of a variety of various operating systems or combinations of operating systems.

[0211] Memory 1310 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ Memory 1310 may allow UE 1300 to access instructions, application programs and the like, stored on transitory or non- transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in memory 1310, which may be or comprise a device-readable storage medium.

[0212] Processing circuitry 1302 may be configured to communicate with an access network or other network using communication interface 1312. Communication interface 1312 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 1322. Communication interface 1312 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 1318 and / or a receiver 1320 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, transmitter 1318 and receiver 1320 may be coupled to one or more antennas (e.g., antenna 1322) and may share circuit components, software, or firmware, or alternatively be implemented separately.

[0213] In the illustrated embodiment, communication functions of communication interface 1312 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / intemet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0214] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 1312, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient). As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0215] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR), a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to UE 1300 shown in Figure 13.

[0216] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0217] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0218] In some embodiments, UE 1300 may be configured to perform operations attributed to a UE in above descriptions of various embodiments, including the exemplary methods shown in Figures 6 and 9.

[0219] Figure 14 shows a network node 1400 in accordance with some embodiments. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (e.g., radio base stations, Node Bs, eNBs, gNBs), and O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).

[0220] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0221] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0222] Network node 1400 includes processing circuitry 1402, memory 1404, communication interface 1406, and power source 1408. Network node 1400 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which network node 1400 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, network node 1400 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 1404 for different RATs) and some components may be reused (e.g., a same antenna 1410 may be shared by different RATs). Network node 1400 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 1400, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 1400.

[0223] Processing circuitry 1402 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 1400 components, such as memory 1404, to provide network node 1400 functionality.

[0224] In some embodiments, processing circuitry 1402 includes a system on a chip (SOC). In some embodiments, processing circuitry 1402 includes one or more of radio frequency (RF) transceiver circuitry 1412 and baseband processing circuitry 1414. In some embodiments, RF transceiver circuitry 1412 and baseband processing circuitry 1414 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 1412 and baseband processing circuitry 1414 may be on the same chip or set of chips, boards, or units.

[0225] Memory 1404 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by processing circuitry 1402. Memory 1404 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions (collected denoted computer program 1404a, which may be in the form of a computer program product) capable of being executed by processing circuitry 1402 and utilized by network node 1400. Memory 1404 may be used to store any calculations made by processing circuitry 1402 and / or any data received via communication interface 1406. In some embodiments, processing circuitry 1402 and memory 1404 is integrated. Communication interface 1406 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, communication interface 1406 comprises port(s) / terminal(s) 1416 to send and receive data, for example to and from a network over a wired connection. Communication interface 1406 also includes radio frontend circuitry 1418 that may be coupled to, or in certain embodiments a part of, antenna 1410. Radio front-end circuitry 1418 comprises filters 1420 and amplifiers 1422. Radio front-end circuitry 1418 may be connected to an antenna 1410 and processing circuitry 1402. The radio front-end circuitry may be configured to condition signals communicated between antenna 1410 and processing circuitry 1402. Radio front-end circuitry 1418 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. Radio front-end circuitry 1418 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 1420 and / or amplifiers 1422. The radio signal may then be transmitted via antenna 1410. Similarly, when receiving data, antenna 1410 may collect radio signals which are then converted into digital data by radio front-end circuitry 1418. The digital data may be passed to processing circuitry 1402. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0226] In certain alternative embodiments, network node 1400 does not include separate radio front-end circuitry 1418, instead, processing circuitry 1402 includes radio front-end circuitry and is connected to antenna 1410. Similarly, in some embodiments, all or some of RF transceiver circuitry 1412 is part of communication interface 1406. In still other embodiments, communication interface 1406 includes one or more ports or terminals 1416, radio front-end circuitry 1418, and RF transceiver circuitry 1412, as part of a radio unit (not shown), and communication interface 1406 communicates with baseband processing circuitry 1414, which is part of a digital unit (not shown).

[0227] Antenna 1410 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. Antenna 1410 may be coupled to radio front-end circuitry 1418 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, antenna 1410 is separate from network node 1400 and connectable to network node 1400 through an interface or port.

[0228] Antenna 1410, communication interface 1406, and / or processing circuitry 1402 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, antenna 1410, communication interface 1406, and / or processing circuitry 1402 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0229] Power source 1408 provides power to the various components of network node 1400 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). Power source 1408 may further comprise, or be coupled to, power management circuitry to supply the components of network node 1400 with power for performing the functionality described herein. For example, network node 1400 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of power source 1408. As a further example, power source 1408 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0230] Embodiments of network node 1400 may include additional components beyond those shown in Figure 14 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, network node 1400 may include user interface equipment to allow input of information into network node 1400 and to allow output of information from network node 1400. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for network node 1400.

[0231] In some embodiments, network node 1400 may be configured to perform operations attributed to a RAN node in above descriptions of various embodiments, including the exemplary methods shown in Figures 7-8 and 10-14

[0232] Figure 15 is a block diagram illustrating a virtualization environment 1500 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1500 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 1500 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an 0-2 interface.

[0233] Applications 1502 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 1500 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. For example, one or more virtual nodes 1402 may be configured to perform operations attributed to RAN nodes in above descriptions of various embodiments, including the exemplary methods shown in Figures 7-8 and 10-11.

[0234] Hardware 1504 includes processing circuitry, memory that stores software and / or instructions (collected denoted computer program 1504a, which may be in the form of a computer program product) executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1506 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1508a and 1508b (one or more of which may be referred to as VMs 1508), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. Virtualization layer 1506 may present a virtual operating platform that appears like networking hardware to the VMs 1508.

[0235] VMs 1508 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 1506. Different embodiments of the instance of a virtual appliance 1502 may be implemented on one or more of VMs 1508, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0236] In the context of NFV, each VM 1508 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each VM 1508, and that part of hardware 1504 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 1508 on top of the hardware 1504 and corresponds to the application 1502.

[0237] Hardware 1504 may be implemented in a standalone network node with generic or specific components. Hardware 1504 may implement some functions via virtualization. Alternatively, hardware 1504 may be part of a larger cluster of hardware (e.g., such as in a data center or customer premises equipment) where many hardware nodes work together and are managed via management and orchestration function 1510, which, among others, oversees lifecycle management of applications 1502. In some embodiments, hardware 1504 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 1512 which may alternatively be used for communication between hardware nodes and radio units.

[0238] The foregoing merely illustrates the principles of the disclosure. Various modifications and alterations to the described embodiments will be apparent to those skilled in the art in view of the teachings herein. It will thus be appreciated that those skilled in the art will be able to devise numerous systems, arrangements, and procedures that, although not explicitly shown or described herein, embody the principles of the disclosure and can be thus within the spirit and scope of the disclosure. Various embodiments can be used together with one another, as well as interchangeably therewith, as should be understood by those having ordinary skill in the art.

[0239] The term unit, as used herein, can have conventional meaning in the field of electronics, electrical devices and / or electronic devices and can include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.

[0240] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processor (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0241] As described herein, device and / or apparatus can be represented by a semiconductor chip, a chipset, or a (hardware) module comprising such chip or chipset; this, however, does not exclude the possibility that a functionality of a device or apparatus, instead of being hardware implemented, be implemented as a software module such as a computer program or a computer program product comprising executable software code portions for execution or being run on a processor. Furthermore, functionality of a device or apparatus can be implemented by any combination of hardware and software. A device or apparatus can also be regarded as an assembly of multiple devices and / or apparatuses, whether functionally in cooperation with or independently of each other. Moreover, devices and apparatuses can be implemented in a distributed fashion throughout a system, so long as the functionality of the device or apparatus is preserved. Such and similar principles are considered known to a skilled person.

[0242] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It will be further understood that terms used herein should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0243] In addition, certain terms used in the present disclosure, including the specification and drawings, can be used synonymously in certain instances (e.g., “data” and “information”). It should be understood that although such terms may be used synonymously herein, there may be instances when such words are not intended to not be used synonymously.

[0244] Embodiments of the techniques and apparatus described herein also include, but are not limited to, the following enumerated examples:

[0245] Al . A method for a user equipment (UE) configured to operate in dual connectivity (DC) with a radio access network (RAN), the method comprising: communicating with a second RAN node via a secondary cell group (SCG), wherein the communication via the SCG is secured using a first security key that is based on a first value from a first sequence of values; receiving one of the following information from a first RAN node via a master cell group (MCG): a first indication to activate a second security key based on a second value from the first sequence of values; or at least one of the following second information: a second indication to activate a second security key based on a first value from a second sequence of values, the second sequence of values, and an identifier of the second sequence of values; and determining the second security key in accordance with the received information; and using the determined second security key, communicating with the SCG or with a second SCG provided by a third RAN node.

[0246] A2. The method of embodiment Al, wherein one of the following applies: the second value from the first sequence of values is a next available value in the first sequence; or the first value from the second sequence of values is a next available value in the second sequence.

[0247] A3. The method of embodiment A2, wherein determining the second security key is based on using the next available value in the first or second sequence as an input to a key derivation function (KDF).

[0248] A4. The method of any of embodiments A2-A3, wherein one of the following applies: the first indication indicates that the UE should use the next available value in the first sequence; or the second indication indicates that the UE should use the next available value in the second sequence.

[0249] A5. The method of any of embodiments A1-A4, wherein the first and second sequences are respective sequences of sk-Counter values in increasing order, with each value in a sequence being one greater than an immediately preceding value in the same sequence.

[0250] A6. The method of any of embodiments A1-A5, further comprising sending to the first RAN node a request for activation of a fresh security key for communication between the UE and the SCG, wherein the first indication is received in response to the notification.

[0251] A6a. The method of embodiment A6, wherein the request is a notification of a pending wraparound for a packet counter associated with a packet data convergence protocol (PDCP) layer between the UE and the second RAN node. A7. The method of any of embodiments A1-A5, further comprising receiving from the MN a configuration for subsequent conditional PSCell activation or change (SCPAC) associated with the second SCG.

[0252] A8. The method of embodiment A7, wherein the second information is received in conjunction with a non-conditional PSCell change or addition involving the second SCG, prior to any conditions associated with the SCPAC to the second SCG being fulfilled.

[0253] A9. The method of embodiment A8, wherein the received second information includes the identifier of the second sequence, and the configuration for SCPAC includes the second sequence of values and an associated sequence identifier that matches the received identifier of the second sequence.

[0254] A10. The method of any of embodiments A1-A9, wherein communicating with the SCG using the determined second security key comprises: performing a random access procedure towards the SCG or the second SCG, and sending a second RRCReconflgurationComplete message to one of the following: the second RAN node via the SCG, or the third RAN node via the second SCG.

[0255] Al l. The method of embodiment A10, wherein the second RRCReconflgurationComplete message to the third RAN node includes an identifier of the second sequence.

[0256] A12. The method of any of embodiments Al 0-Al 1, further comprising sending a first RRCReconflgurationComplete message to the first RAN node via the MCG, wherein the first RRCReconflgurationComplete message includes an identifier of the second sequence.

[0257] A13. The method of any of embodiments A1-A12, wherein one of the following indicates for the UE to use the first value from the second sequence instead of using a next available value of the first sequence: the second indication explicitly; or the second sequence or the identifier thereof implicitly, when received without the second indication.

[0258] A14. The method of any of embodiments A1-A13, further comprising, in response to the second indication, storing the first sequence of values such that the first sequence can be retrieved for subsequent communication with the SCG. Bl . A method for a first radio access network (RAN) node configured to provide a master cell group (MCG) for a user equipment (UE), the method comprising: receiving a request for activation of a fresh security key for communication between the UE and a secondary cell group (SCG) provided by a second RAN node, wherein the UE is configured to communicate securely via the SCG using a first security key that is based on a first value from a first sequence of values; and sending one of the following information to the UE via the MCG and to a second RAN node: a first indication to activate a second security key based on a second value from the first sequence of values; or at least one of the following second information: a second indication to activate a second security key based on a first value from a second sequence of values, the second sequence of values, and an identifier of the second sequence of values.

[0259] B2. The method of embodiment Bl, wherein: sending the first indication or the second information is based on determining whether the first sequence of values is sufficient information from which the UE can derive the second security key; the first indication is sent when it is determined that the first sequence of values is sufficient; and the second information is sent when it is determined that the first sequence of values is not sufficient.

[0260] B3. The method of any of embodiments B1-B2, wherein the request is received from one of the following: the second RAN node, or the UE.

[0261] B4. The method of embodiment B3, wherein the request is a notification of a pending wraparound for a packet counter associated with a packet data convergence protocol (PDCP) layer between the UE and the second RAN node, wherein the first indication is sent in response to the notification.

[0262] B5. The method of embodiment B3, further comprising sending to the UE a configuration for subsequent conditional PSCell activation or change (SCPAC) associated with a second SCG for the UE.

[0263] B6. The method of embodiment B5, wherein the request from the second RAN node is a key change indication for SCPAC.

[0264] B7. The method of embodiment B5, wherein the request relates to a non-conditional PSCell change or addition involving the second SCG, prior to any conditions associated with the SCPAC to the second SCG being fulfilled.

[0265] B8. The method of embodiment B5, wherein the second information includes the identifier of the second sequence, and the configuration for SCPAC includes the second sequence of values and an associated sequence identifier that matches the received identifier of the second sequence.

[0266] B9. The method of any of embodiments B1-B8, wherein one of the following applies: the second value from the first sequence of values is a next available value in the first sequence; or the first value from the second sequence of values is a next available value in the second sequence.

[0267] BIO. The method of embodiment B9, wherein the second security key is based on using the next available value in the first or second sequence as an input to a key derivation function (KDF).

[0268] Bl 1. The method of any of embodiments B9-B10, wherein one of the following applies: the first indication indicates that the UE should use the next available value in the first sequence; or the second indication indicates that the UE should use the next available value in the second sequence.

[0269] Bl 2. The method of any of embodiments Bl-Bl 1, wherein the first and second sequences are respective sequences of sk-Counter values in increasing order, with each value in a sequence being one greater than an immediately preceding value in the same sequence.

[0270] Bl 3. The method of any of embodiments Bl -Bl 2, further comprising receiving a first RRCReconflgurationComplete message from the UE via the MCG, wherein the first RRCReconflgurationComplete message includes an identifier of the second sequence.

[0271] Bl 4. The method of any of embodiments Bl -Bl 3, wherein one of the following indicates for the UE to use the first value from the second sequence instead of using a next available value of the first sequence: the second indication explicitly; or the second sequence or the identifier thereof implicitly, when received without the second indication.

[0272] Cl . A method for a second radio access network (RAN) node configured to provide a secondary cell group (SCG) for a user equipment (UE), the method comprising: sending, to a first RAN node, a request for activation of a fresh security key for UE-SCG communication, wherein the UE is further configured to communicate via a master cell group (MCG) provided by the first RAN node; in response to the request, receiving one of the following information from the first RAN node: a first indication to activate a second security key based on a second value from a first sequence of values being used by at least the UE; or at least one of the following second information: a second indication to activate a second security key based on a first value from a second sequence of values, the second sequence of values, and an identifier of the second sequence of values; and determining the second security key in accordance with the received information.

[0273] C2. The method of embodiment Cl, further comprising, prior to sending the request, communicating with the UE via the SCG, wherein the communication with the UE is secured using a first security key that is based on a first value from the first sequence of values, wherein the first value precedes the second value.

[0274] C3. The method of any of embodiments C1-C2, further comprising communicating with the UE via the SCG using the determined second security key.

[0275] C4. The method of embodiment C3, wherein communicating with the UE via the SCG using the determined second security key comprises: performing a random access procedure with the UE in the SCG, and receiving a RRCReconflgurationComplete message from the UE via the SCG. C5. The method of embodiment C4, wherein the RRCReconfigurationComplete message includes an identifier of the second sequence.

[0276] C6. The method of any of embodiments C1-C5, wherein the request is a notification of a pending wrap-around for a packet counter associated with a packet data convergence protocol (PDCP) layer between the UE and the second RAN node, wherein the first indication is sent in response to the notification.

[0277] C7. The method of any of embodiments Cl and C6, wherein the request from the second RAN node is a key change indication for subsequent conditional PSCell activation or change (SCPAC) associated with a second SCG for the UE, wherein the second information is sent in response to the key change indication.

[0278] C8. The method of embodiment C7, wherein the request relates to a non-conditional PSCell change or addition involving the second SCG, prior to any conditions associated with the SCPAC to the second SCG being fulfilled.

[0279] C9. The method of embodiment C8, wherein the second information includes the identifier of the second sequence, and a configuration for SCPAC includes the second sequence of values and an associated sequence identifier that matches the received identifier of the second sequence.

[0280] CIO. The method of any of embodiments C1-C9, wherein one of the following applies: the second value from the first sequence of values is a next available value in the first sequence; or the first value from the second sequence of values is a next available value in the second sequence.

[0281] Cl 1. The method of embodiment CIO, wherein determining the second security key is based on using the next available value in the first or second sequence as an input to a key derivation function (KDF).

[0282] Cl 2. The method of any of embodiments C10-C11, wherein one of the following applies: the first indication indicates that the UE should use the next available value in the first sequence; or the second indication indicates that the UE should use the next available value in the second sequence.

[0283] Cl 3. The method of any of embodiments Cl-Cl 1, wherein the first and second sequences are respective sequences of sk-Counter values in increasing order, with each value in a sequence being one greater than an immediately preceding value in the same sequence.

[0284] Cl 4. The method of any of embodiments Cl -Cl 3, wherein one of the following indicates for the second RAN node to use the first value from the second sequence instead of using a next available value of the first sequence: the second indication explicitly; or the second sequence or the identifier thereof implicitly, when received without the second indication.

[0285] DI. A user equipment (UE) configured to operate in dual connectivity (DC) with a radio access network (RAN), the UE comprising: communication interface circuitry configured to communicate with the RAN node via a master cell group (MCG) and a secondary cell group (SCG); and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to perform operations corresponding to the methods of any of embodiments Al -Al 4.

[0286] D2. A user equipment (UE) configured to operate in dual connectivity (DC) with a radio access network (RAN), the UE being further arranged to perform operations corresponding to the methods of any of embodiments A1-A14.

[0287] D3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a user equipment (UE) configured to operate in dual connectivity (DC) with a radio access network (RAN), configure the UE to perform operations corresponding to the methods of any of embodiments Al -Al 4.

[0288] D4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of a user equipment (UE) configured to operate in dual connectivity (DC) with a radio access network (RAN), configure the UE to perform operations corresponding to the methods of any of embodiments Al -Al 4. El. A first radio access network (RAN) node configured to provide a master cell group (MCG) for a user equipment (UE), the first RAN node comprising: communication interface circuitry configured to communicate with the UE via the MCG and with a second RAN node configured to provide a secondary cell group (MCG) for the UE; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to perform operations corresponding to the methods of any of embodiments Bl -Bl 4.

[0289] E2. A first radio access network (RAN) node configured to provide a master cell group (MCG) for a user equipment (UE), the first RAN node being further arranged to perform operations corresponding to the methods of any of embodiments Bl -Bl 4.

[0290] E3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a first radio access network (RAN) node configured to provide a master cell group (MCG) for a user equipment (UE), configure the first RAN node to perform operations corresponding to the methods of any of embodiments B1-B14.

[0291] E4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of a first radio access network (RAN) node configured to provide a master cell group (MCG) for a user equipment (UE), configure the first RAN node to perform operations corresponding to the methods of any of embodiments Bl -Bl 4.

[0292] Fl. A second radio access network (RAN) node configured to provide a secondary cell group (SCG) for a user equipment (UE), the second RAN node comprising: communication interface circuitry configured to communicate with the UE via the SCG and with a first RAN node configured to provide a master cell group (MCG) for the UE; and processing circuitry operatively coupled to the communication interface circuitry, whereby the processing circuitry and the communication interface circuitry are configured to perform operations corresponding to the methods of any of embodiments Cl -Cl 4. F2. A second radio access network (RAN) node configured to provide a secondary cell group (SCG) for a user equipment (UE), the second RAN node being further arranged to perform operations corresponding to the methods of any of embodiments Cl -Cl 4. F3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a second radio access network (RAN) node configured to provide a secondary cell group (SCG) for a user equipment (UE), configure the second RAN node to perform operations corresponding to the methods of any of embodiments C1-C14.

[0293] F4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of a second radio access network (RAN) node configured to provide a secondary cell group (SCG) for a user equipment (UE), configure the second RAN node to perform operations corresponding to the methods of any of embodiments Cl -Cl 4.

Claims

CLAIMS1. A method for a user equipment, UE, configured to communicate in dual connectivity with a master node, MN, and a secondary node, SN, the method comprising: receiving (910) a sequence of values from the MN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receiving (920) from the MN a further value usable for derivation of security keys for communication between the UE and the SN; deriving (940) one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence; and maintaining (960) the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

2. The method of claim 1, wherein the sequence of values is part of a configuration for subsequent conditional PSCell activation or change, SCPAC, associated with a secondary cell group, SCG; and the further value is part of a configuration for conditional PSCell activation or change, CP AC, associated with the SCG.

3. The method of any of claims 1-2, wherein deriving (940) the one or more security keys is based on using the further value as an input to a key derivation function, KDF.

4. The method of any of claims 1-3, wherein the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence.

5. The method of any of claims 1-4, wherein the sequence of values does not include the further value.

6. The method of any of claims 1-5, further comprising receiving from the MN an indication to use the received further value instead of the next available one of the at least oneunused value of the sequence, wherein deriving the one or more security keys is further based on the indication.

7. The method of any of claims 1-6, wherein the UE is configured to communicate with the MN via a master cell group, MCG, and with the SN via a secondary cell group, SCG.

8. The method of claim 7, further comprising, using the derived one or more security keys, communicating (950) with the SN via the SCG.

9. The method of claim 8, wherein communicating (950) with the SN via the SCG using the derived one or more security keys comprises: performing (951) a random access towards a cell of the SCG, and subsequently sending (952) a RRCReconfigurationComplete message to SN using the derived one or more security keys.

10. A method for a secondary node, SN, configured to communicate with a user equipment, UE, in dual connectivity with a master node, MN, the method comprising: receiving (1010) a sequence of values from the MN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receiving (1020) from the MN a further value usable for derivation of security keys for communication between the UE and the SN; deriving (1040) one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence; and maintaining (1060) the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

11. The method of claim 10, wherein the sequence of values is part of a configuration for subsequent conditional PSCell activation or change, SCPAC, associated with a secondary cell group, SCG; and the further value is part of a configuration for conditional PSCell activation or change, CP AC, associated with the SCG.

12. The method of any of claims 10-11, wherein deriving (1040) the one or more security keys is based on using the further value as an input to a key derivation function, KDF.

13. The method of any of claims 10-12, wherein the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence.

14. The method of any of claims 10-13, wherein the sequence of values does not include the further value.

15. The method of any of claims 10-14, further comprising, using the derived one or more security keys, communicating (1050) with the UE via a secondary cell group, SCG, provided by the SN.

16. The method of claim 15, wherein communicating (1050) with the UE via the SCG using the derived one or more security keys comprises: receiving (1051) a random access from the UE in a cell of the SCG; and subsequently receiving (1052) a RRCReconflgurationComplete message from the UE using the derived one or more security keys.

17. A method for a master node, MN, configured to communicate with a user equipment, UE, in dual connectivity with a secondary node, SN, the method comprising: sending (1110) a sequence of values to the UE and to the SN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; and while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, sending (1120), to the UE and to the SN, a further value usable for derivation of one or more security keys for communication between the UE and the SN, wherein the further value is usable for derivation of the one or more security keys prior to using a next available one of the at least one unused value of the sequence.

18. The method of claim 17, wherein the sequence of values is part of a configuration for subsequent conditional PSCell activation or change, SCPAC, associated with a secondary cellgroup, SCG; and the further value is part of a configuration for conditional PSCell activation or change, CP AC, associated with the SCG.

19. The method of any of claims 17-18, wherein derivation of the one or more security keys is based on using the further value as an input to a key derivation function, KDF,.

20. The method of any of claims 17-19, wherein the values of the sequence are respective counter values in increasing order, with each value being one greater than an immediately preceding value in the sequence.

21. The method of any of claims 17-20, wherein the sequence of values does not include the further value.

22. The method of any of claims 17-21, further comprising sending (1130) to the UE an indication to use the received further value instead of the next available one of the at least one unused value of the sequence, wherein the derivation of the one or more security keys is further based on the indication.

23. The method of any of claims 17-22, wherein the MN is configured to communicate with the UE via a master cell group, MCG.

24. User equipment, UE (210, 310, 410, 1212, 1300) configured to communicate in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502) and a secondary node, SN (100, 220, 430, 1210, 1400, 1502), the UE comprising: communication interface circuitry (1312) configured to communicate with the MN and the SN; and processing circuitry (1302) operatively coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: receive a sequence of values from the MN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receive from the MN a further value usable for derivation of security keys for communication between the UE and the SN; derive one or more security keys based on the further value instead of based on a next availableone of the at least one unused value of the sequence; and maintain the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

25. The UE of claim 24, wherein the processing circuitry and the communication interface circuitry are further configured to perform operations corresponding to any of the methods of claims 2-9.

26. User equipment, UE (210, 310, 410, 1212, 1300) configured to communicate in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502) and a secondary node, SN (100, 220, 430, 1210, 1400, 1502), the UE being further configured to: receive a sequence of values from the MN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receive from the MN a further value usable for derivation of security keys for communication between the UE and the SN; derive one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence; and maintain the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

27. The UE of claim 26, being further configured to perform operations corresponding to any of the methods of claims 2-9.

28. Non-transitory, computer-readable medium (1310) storing computer-executable instructions that, when executed by processing circuitry (1302) of user equipment, UE (210, 310, 410, 1212, 1300) configured to communicate in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502) and a secondary node, SN (100, 220, 430, 1210, 1400, 1502), configure the UE to perform operations corresponding to any of the methods of claims 1-9.

29. Computer program product (1314) comprising computer-executable instructions that, when executed by processing circuitry (1302) of user equipment, UE (210, 310, 410, 1212, 1300) configured to communicate in dual connectivity with a master node, MN (100, 220, 420,1210, 1400, 1502) and a secondary node, SN (100, 220, 430, 1210, 1400, 1502), configure the UE to perform operations corresponding to any of the methods of claims 1-9.

30. Secondary node, SN (100, 220, 430, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502), the SN comprising: communication interface circuitry (1406, 1504) configured to communicate with the UE and with the MN; and processing circuitry (1402, 1504) operatively coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: receive a sequence of values from the MN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receive from the MN a further value usable for derivation of security keys for communication between the UE and the SN; derive one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence; and maintain the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

31. The SN of claim 30, wherein the processing circuitry and the communication interface circuitry are further configured to perform operations corresponding to any of the methods of claims 11-16.

32. Secondary node, SN (100, 220, 430, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502), the SN being further configured to: receive a sequence of values from the MN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, receive from the MN a further valueusable for derivation of security keys for communication between the UE and the SN; derive one or more security keys based on the further value instead of based on a next available one of the at least one unused value of the sequence; and maintain the at least one unused value of the sequence for at least one subsequent derivation of security keys for communication between the UE and the SN.

33. The SN of claim 32, being further configured to perform operations corresponding to any of the methods of claims 11-16.

34. Non-transitory, computer-readable medium (1404, 1504) storing computer-executable instructions that, when executed by processing circuitry (1402, 1504) of a secondary node, SN (100, 220, 430, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502), configure the SN to perform operations corresponding to the methods of any of claims 10-16.

35. A computer program product (1404a, 1504a) comprising computer-executable instructions that, when executed by processing circuitry (1402, 1504) of a secondary node, SN (100, 220, 430, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a master node, MN (100, 220, 420, 1210, 1400, 1502), configure the SN to perform operations corresponding to the methods of any of claims 10-16.

36. Master node, MN (100, 220, 420, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a secondary node, SN (100, 220, 430, 1210, 1400, 1502), the MN comprising: communication interface circuitry (1406, 1504) configured to communicate with the UE and with the SN; and processing circuitry (1402, 1504) operatively coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: send a sequence of values to the UE and to the SN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; andwhile at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, send, to the UE and to the SN, a further value usable for derivation of one or more security keys for communication between the UE and the SN, wherein the further value is usable for derivation of the one or more security keys prior to using a next available one of the at least one unused value of the sequence.

37. The MN of claim 36, wherein the processing circuitry and the communication interface circuitry are further configured to perform operations corresponding to any of the methods of claims 18-23.

38. Master node, MN (100, 220, 420, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a secondary node, SN (100, 220, 430, 1210, 1400, 1502), the MN being further configured to: send a sequence of values to the UE and to the SN, wherein the values of the sequence are usable for respective derivations of security keys for communication between the UE and the SN; and while at least one value of the sequence has not been used to derive security keys for communication between the UE and the SN, send, to the UE and to the SN, a further value usable for derivation of one or more security keys for communication between the UE and the SN, wherein the further value is usable for derivation of the one or more security keys prior to using a next available one of the at least one unused value of the sequence.

39. The MN of claim 38, being further configured to perform operations corresponding to any of the methods of claims 18-23.

40. Non-transitory, computer-readable medium (1404, 1504) storing computer-executable instructions that, when executed by processing circuitry (1402, 1504) of a master node, MN (100, 220, 420, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a secondary node, SN (100, 220, 430, 1210, 1400, 1502), configure the MN to perform operations corresponding to the methods of any of claims 17-23.

41. A computer program product (1404a, 1504a) comprising computer-executable instructions that, when executed by processing circuitry (1402, 1504) of a master node, MN (100, 220, 420, 1210, 1400, 1502) configured to communicate with a user equipment, UE (210, 310, 410, 1212, 1300) in dual connectivity with a secondary node, SN (100, 220, 430, 1210, 1400, 1502), configure the MN to perform operations corresponding to the methods of any of claims 17-23.