Security master key handling for inter-CU l1 / l2 triggered mobility
The method of deriving and transmitting new security keys during inter-CU mobility addresses the robustness and security challenges of LTM, enhancing the reliability and efficiency of key updates in LTM systems.
Patent Information
- Application Number
- PCT/KR2025/002004
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-22
- Filing Date
- 2025-02-12
- Publication Date
- 2025-08-28
Smart Images

Figure KR2025002004_28082025_PF_FP_ABST
Abstract
Description
SECURITY MASTER KEY HANDLING FOR INTER-CU L1 / L2 TRIGGERED MOBILITY
[0001] The present disclosure relates to a security master key handling for inter-Centralized Unit (CU) L1 / L2 Triggered Mobility (LTM).
[0002] 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a technology for enabling high-speed packet communications. Many schemes have been proposed for the LTE objective including those that aim to reduce user and provider costs, improve service quality, and expand and improve coverage and system capacity. The 3GPP LTE requires reduced cost per bit, increased service availability, flexible use of a frequency band, a simple structure, an open interface, and adequate power consumption of a terminal as an upper-level requirement.
[0003] 3GPP New Radio (NR) targets a single technical framework addressing all usage scenarios, requirements and deployment scenarios including enhanced Mobile BroadBand (eMBB), massive Machine Type Communications (mMTC), Ultra-Reliable and Low Latency Communications (URLLC), etc. The NR shall be inherently forward compatible. Further, the NR should be able to use any spectrum band ranging at least up to 100 GHz that may be made available for wireless communications even in a more distant future.
[0004] 6G is the successor to 5G cellular technology. 6G networks will be able to use higher frequencies than 5G networks and provide substantially higher capacity and much lower latency. The 6G technology market is expected to facilitate large improvements in the areas of imaging, presence technology and location awareness. Working in conjunction with Artificial Intelligence (AI), the 6G computational infrastructure will be able to identify the best place for computing to occur. This includes decisions about data storage, processing and sharing.
[0005] Layer 3 based mobility has evolved over several releases. Conditional Handover (CHO) and other conditional mobility procedures (Conditional PSCell Addition and Change (CPAC), Subsequent CPAC (SCPAC)) were developed to achieve high robustness by enabling the procedure to be executed without necessitating a signaling exchange with source cell beforehand. L1 / L2 Triggered Mobility (LTM) as introduced in Rel-18 offers short interruption time but not with the same level of robustness as the conditional L3 mobility procedures. In Rel-19, enhancements should be specified so that the system can benefit from both the high robustness and short interruption.
[0006] In an aspect, a method is provided. The method comprises receiving, by a second base station serving a second cell, a handover related message from a first base station serving a first cell. The handover related message includes security keys to be used by the second base station and information related to a security key update. The method further comprises, after a cell change from the first cell to the second cell is completed, deriving new security keys based on a current security and the information related to the security key update, and transmitting the new security keys to other base stations for subsequent mobility.
[0007] In another aspect, an apparatus for implementing the above method is provided.
[0008] FIG. 1 shows an example of a communication system to which implementations of the present disclosure are applied.
[0009] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure are applied.
[0010] FIG. 3 shows an example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0011] FIG. 4 shows another example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0012] FIG. 5 shows an example of inter-gNB handover procedures to which implementations of the present disclosure are applied.
[0013] FIG. 6 shows an example of signaling procedure for LTM to which implementations of the present disclosure are applied.
[0014] FIG. 7 shows an example of a method to which implementations of the present disclosure are applied.
[0015] FIG. 8 shows an example of an initial configuration procedure for inter-CU LTM security master key update to which implementations of the present disclosure are applied.
[0016] FIG. 9 shows an example of an intra-CU serving cell change for inter-CU LTM security master key update procedure to which implementations of the present disclosure are applied.
[0017] FIG. 10 shows an example of an inter-CU serving cell change for inter-CU LTM security master key update procedure to which implementations of the present disclosure are applied.
[0018] FIGS. 11 and 12 show an example of LTM re-attempt to another CU after failure of cell switch to which implementations of the present disclosure are applied.
[0019] FIGS. 13 and 14 show an example of LTM re-attempt to same CU after failure of cell switch to which implementations of the present disclosure are applied.
[0020] The following techniques, apparatuses, and systems may be applied to a variety of wireless multiple access systems. Examples of the multiple access systems include a Code Division Multiple Access (CDMA) system, a Frequency Division Multiple Access (FDMA) system, a Time Division Multiple Access (TDMA) system, an Orthogonal Frequency Division Multiple Access (OFDMA) system, a Single Carrier Frequency Division Multiple Access (SC-FDMA) system, and a Multi Carrier Frequency Division Multiple Access (MC-FDMA) system. CDMA may be embodied through radio technology such as Universal Terrestrial Radio Access (UTRA) or CDMA2000. TDMA may be embodied through radio technology such as Global System for Mobile communications (GSM), General Packet Radio Service (GPRS), or Enhanced Data rates for GSM Evolution (EDGE). OFDMA may be embodied through radio technology such as Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, or Evolved UTRA (E-UTRA). UTRA is a part of a Universal Mobile Telecommunications System (UMTS). 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a part of Evolved UMTS (E-UMTS) using E-UTRA. 3GPP LTE employs OFDMA in Downlink (DL) and SC-FDMA in Uplink (UL). Evolution of 3GPP LTE includes LTE-Advanced (LTE-A), LTE-A Pro, 5G New Radio (NR) and / or 6G.
[0021] For convenience of description, implementations of the present disclosure are mainly described in regards to a 3GPP based wireless communication system. However, the technical features of the present disclosure are not limited thereto. For example, although the following detailed description is given based on a mobile communication system corresponding to a 3GPP based wireless communication system, aspects of the present disclosure that are not limited to 3GPP based wireless communication system are applicable to other mobile communication systems.
[0022] For terms and technologies which are not specifically described among the terms of and technologies employed in the present disclosure, the wireless communication standard documents published before the present disclosure may be referenced.
[0023] In the present disclosure, "A or B" may mean "only A", "only B", or "both A and B". In other words, "A or B" in the present disclosure may be interpreted as "A and / or B". For example, "A, B or C" in the present disclosure may mean "only A", "only B", "only C", or "any combination of A, B and C".
[0024] In the present disclosure, slash ( / ) or comma (,) may mean "and / or". For example, "A / B" may mean "A and / or B". Accordingly, "A / B" may mean "only A", "only B", or "both A and B". For example, "A, B, C" may mean "A, B or C".
[0025] In the present disclosure, "at least one of A and B" may mean "only A", "only B" or "both A and B". In addition, the expression "at least one of A or B" or "at least one of A and / or B" in the present disclosure may be interpreted as same as "at least one of A and B".
[0026] In addition, in the present disclosure, "at least one of A, B and C" may mean "only A", "only B", "only C", or "any combination of A, B and C". In addition, "at least one of A, B or C" or "at least one of A, B and / or C" may mean "at least one of A, B and C".
[0027] Also, parentheses used in the present disclosure may mean "for example". In detail, when it is shown as "control information (PDCCH)", "PDCCH" may be proposed as an example of "control information". In other words, "control information" in the present disclosure is not limited to "PDCCH", and "PDCCH" may be proposed as an example of "control information". In addition, even when shown as "control information (i.e., PDCCH)", "PDCCH" may be proposed as an example of "control information".
[0028] Technical features that are separately described in one drawing in the present disclosure may be implemented separately or simultaneously.
[0029] Although not limited thereto, various descriptions, functions, procedures, suggestions, methods and / or operational flowcharts of the present disclosure disclosed herein can be applied to various fields requiring wireless communication and / or connection (e.g., 5G) between devices.
[0030] Hereinafter, the present disclosure will be described in more detail with reference to drawings. The same reference numerals in the following drawings and / or descriptions may refer to the same and / or corresponding hardware blocks, software blocks, and / or functional blocks unless otherwise indicated.
[0031] FIG. 1 shows an example of a communication system to which implementations of the present disclosure are applied.
[0032] The 5G usage scenarios shown in FIG. 1 are only exemplary, and the technical features of the present disclosure can be applied to other 5G usage scenarios which are not shown in FIG. 1.
[0033] Three main requirement categories for 5G include (1) a category of enhanced Mobile BroadBand (eMBB), (2) a category of massive Machine Type Communication (mMTC), and (3) a category of Ultra-Reliable and Low Latency Communications (URLLC).
[0034] Referring to FIG. 1, the communication system 1 includes wireless devices 100a to 100f, Base Stations (BSs) 200, and a network 300. Although FIG. 1 illustrates a 5G network as an example of the network of the communication system 1, the implementations of the present disclosure are not limited to the 5G system, and can be applied to the future communication system beyond the 5G system.
[0035] The BSs 200 and the network 300 may be implemented as wireless devices and a specific wireless device may operate as a BS / network node with respect to other wireless devices.
[0036] The wireless devices 100a to 100f represent devices performing communication using Radio Access Technology (RAT) (e.g., 5G NR or LTE) and may be referred to as communication / radio / 5G devices. The wireless devices 100a to 100f may include, without being limited to, a robot 100a, vehicles 100b-1 and 100b-2, an eXtended Reality (XR) device 100c, a hand-held device 100d, a home appliance 100e, an Internet-of-Things (IoT) device 100f, and an Artificial Intelligence (AI) device / server 400. For example, the vehicles may include a vehicle having a wireless communication function, an autonomous driving vehicle, and a vehicle capable of performing communication between vehicles. The vehicles may include an Unmanned Aerial Vehicle (UAV) (e.g., a drone). The XR device may include an Augmented Reality (AR) / Virtual Reality (VR) / Mixed Reality (MR) device and may be implemented in the form of a Head-Mounted Device (HMD), a Head-Up Display (HUD) mounted in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance device, a digital signage, a vehicle, a robot, etc. The hand-held device may include a smartphone, a smartpad, a wearable device (e.g., a smartwatch or a smartglasses), and a computer (e.g., a notebook). The home appliance may include a TV, a refrigerator, and a washing machine. The IoT device may include a sensor and a smartmeter.
[0037] In the present disclosure, the wireless devices 100a to 100f may be called User Equipments (UEs). A UE may include, for example, a cellular phone, a smartphone, a laptop computer, a digital broadcast terminal, a Personal Digital Assistant (PDA), a Portable Multimedia Player (PMP), a navigation system, a slate Personal Computer (PC), a tablet PC, an ultrabook, a vehicle, a vehicle having an autonomous traveling function, a connected car, an UAV, an AI module, a robot, an AR device, a VR device, an MR device, a hologram device, a public safety device, an MTC device, an IoT device, a medical device, a FinTech device (or a financial device), a security device, a weather / environment device, a device related to a 5G service, or a device related to a fourth industrial revolution field.
[0038] The wireless devices 100a to 100f may be connected to the network 300 via the BSs 200. An AI technology may be applied to the wireless devices 100a to 100f and the wireless devices 100a to 100f may be connected to the AI server 400 via the network 300. The network 300 may be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, and a beyond-5G network. Although the wireless devices 100a to 100f may communicate with each other through the BSs 200 / network 300, the wireless devices 100a to 100f may perform direct communication (e.g., sidelink communication) with each other without passing through the BSs 200 / network 300. For example, the vehicles 100b-1 and 100b-2 may perform direct communication (e.g., Vehicle-to-Vehicle (V2V) / Vehicle-to-everything (V2X) communication). The IoT device (e.g., a sensor) may perform direct communication with other IoT devices (e.g., sensors) or other wireless devices 100a to 100f.
[0039] Wireless communication / connections 150a, 150b and 150c may be established between the wireless devices 100a to 100f and / or between wireless device 100a to 100f and BS 200 and / or between BSs 200. Herein, the wireless communication / connections may be established through various RATs (e.g., 5G NR) such as uplink / downlink communication 150a, sidelink communication (or Device-to-Device (D2D) communication) 150b, inter-base station communication 150c (e.g., relay, Integrated Access and Backhaul (IAB)), etc. The wireless devices 100a to 100f and the BSs 200 / the wireless devices 100a to 100f may transmit / receive radio signals to / from each other through the wireless communication / connections 150a, 150b and 150c. For example, the wireless communication / connections 150a, 150b and 150c may transmit / receive signals through various physical channels. To this end, at least a part of various configuration information configuring processes, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, and resource mapping / de-mapping), and resource allocating processes, for transmitting / receiving radio signals, may be performed based on the various proposals of the present disclosure.
[0040] NR supports multiples numerologies (and / or multiple Sub-Carrier Spacings (SCS)) to support various 5G services. For example, if SCS is 15 kHz, wide area can be supported in traditional cellular bands, and if SCS is 30 kHz / 60 kHz, dense-urban, lower latency, and wider carrier bandwidth can be supported. If SCS is 60 kHz or higher, bandwidths greater than 24.25 GHz can be supported to overcome phase noise.
[0041] The NR frequency band may be defined as two types of frequency range, i.e., Frequency Range 1 (FR1) and Frequency Range 2 (FR2). The numerical value of the frequency range may be changed. For example, the frequency ranges of the two types (FR1 and FR2) may be as shown in Table 1 below. For ease of explanation, in the frequency ranges used in the NR system, FR1 may mean "sub 6 GHz range", FR2 may mean "above 6 GHz range," and may be referred to as millimeter Wave (mmW).
[0042] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1450MHz - 6000MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz
[0043] As mentioned above, the numerical value of the frequency range of the NR system may be changed. For example, FR1 may include a frequency band of 410MHz to 7125MHz as shown in Table 2 below. That is, FR1 may include a frequency band of 6GHz (or 5850, 5900, 5925 MHz, etc.) or more. For example, a frequency band of 6 GHz (or 5850, 5900, 5925 MHz, etc.) or more included in FR1 may include an unlicensed band. Unlicensed bands may be used for a variety of purposes, for example for communication for vehicles (e.g., autonomous driving).
[0044] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1410MHz - 7125MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz
[0045] Here, the radio communication technologies implemented in the wireless devices in the present disclosure may include NarrowBand IoT (NB-IoT) technology for low-power communication as well as LTE, NR and 6G. For example, NB-IoT technology may be an example of Low Power Wide Area Network (LPWAN) technology, may be implemented in specifications such as LTE Cat NB1 and / or LTE Cat NB2, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may communicate based on LTE-M technology. For example, LTE-M technology may be an example of LPWAN technology and be called by various names such as enhanced MTC (eMTC). For example, LTE-M technology may be implemented in at least one of the various specifications, such as 1) LTE Cat 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-bandwidth limited (non-BL), 5) LTE-MTC, 6) LTE Machine Type Communication, and / or 7) LTE M, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may include at least one of ZigBee, Bluetooth, and / or LPWAN which take into account low-power communication, and may not be limited to the above-mentioned names. For example, ZigBee technology may generate Personal Area Networks (PANs) associated with small / low-power digital communication based on various specifications such as IEEE 802.15.4 and may be called various names.
[0046] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure are applied.
[0047] In FIG. 2, The first wireless device 100 and / or the second wireless device 200 may be implemented in various forms according to use cases / services. For example, {the first wireless device 100 and the second wireless device 200} may correspond to at least one of {the wireless device 100a to 100f and the BS 200}, {the wireless device 100a to 100f and the wireless device 100a to 100f} and / or {the BS 200 and the BS 200} of FIG. 1. The first wireless device 100 and / or the second wireless device 200 may be configured by various elements, devices / parts, and / or modules.
[0048] The first wireless device 100 may include at least one transceiver, such as a transceiver 106, at least one processing chip, such as a processing chip 101, and / or one or more antennas 108.
[0049] The processing chip 101 may include at least one processor, such a processor 102, and at least one memory, such as a memory 104. Additional and / or alternatively, the memory 104 may be placed outside of the processing chip 101.
[0050] The processor 102 may control the memory 104 and / or the transceiver 106 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 102 may process information within the memory 104 to generate first information / signals and then transmit radio signals including the first information / signals through the transceiver 106. The processor 102 may receive radio signals including second information / signals through the transceiver 106 and then store information obtained by processing the second information / signals in the memory 104.
[0051] The memory 104 may be operably connectable to the processor 102. The memory 104 may store various types of information and / or instructions. The memory 104 may store a firmware and / or a software code 105 which implements codes, commands, and / or a set of commands that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may implement instructions that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more protocols. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more layers of the radio interface protocol.
[0052] Herein, the processor 102 and the memory 104 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 106 may be connected to the processor 102 and transmit and / or receive radio signals through one or more antennas 108. Each of the transceiver 106 may include a transmitter and / or a receiver. The transceiver 106 may be interchangeably used with Radio Frequency (RF) unit(s). In the present disclosure, the first wireless device 100 may represent a communication modem / circuit / chip.
[0053] The second wireless device 200 may include at least one transceiver, such as a transceiver 206, at least one processing chip, such as a processing chip 201, and / or one or more antennas 208.
[0054] The processing chip 201 may include at least one processor, such a processor 202, and at least one memory, such as a memory 204. Additional and / or alternatively, the memory 204 may be placed outside of the processing chip 201.
[0055] The processor 202 may control the memory 204 and / or the transceiver 206 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 202 may process information within the memory 204 to generate third information / signals and then transmit radio signals including the third information / signals through the transceiver 206. The processor 202 may receive radio signals including fourth information / signals through the transceiver 106 and then store information obtained by processing the fourth information / signals in the memory 204.
[0056] The memory 204 may be operably connectable to the processor 202. The memory 204 may store various types of information and / or instructions. The memory 204 may store a firmware and / or a software code 205 which implements codes, commands, and / or a set of commands that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may implement instructions that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more protocols. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more layers of the radio interface protocol.
[0057] Herein, the processor 202 and the memory 204 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 206 may be connected to the processor 202 and transmit and / or receive radio signals through one or more antennas 208. Each of the transceiver 206 may include a transmitter and / or a receiver. The transceiver 206 may be interchangeably used with RF unit. In the present disclosure, the second wireless device 200 may represent a communication modem / circuit / chip.
[0058] Hereinafter, hardware elements of the wireless devices 100 and 200 will be described more specifically. One or more protocol layers may be implemented by, without being limited to, one or more processors 102 and 202. For example, the one or more processors 102 and 202 may implement one or more layers (e.g., functional layers such as Physical (PHY) layer, Media Access Control (MAC) layer, Radio Link Control (RLC) layer, Packet Data Convergence Protocol (PDCP) layer, Radio Resource Control (RRC) layer, and Service Data Adaptation Protocol (SDAP) layer). The one or more processors 102 and 202 may generate one or more Protocol Data Units (PDUs), one or more Service Data Unit (SDUs), messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The one or more processors 102 and 202 may generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure and provide the generated signals to the one or more transceivers 106 and 206. The one or more processors 102 and 202 may receive the signals (e.g., baseband signals) from the one or more transceivers 106 and 206 and acquire the PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure.
[0059] The one or more processors 102 and 202 may be referred to as controllers, microcontrollers, microprocessors, or microcomputers. The one or more processors 102 and 202 may be implemented by hardware, firmware, software, or a combination thereof. As an example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in the one or more processors 102 and 202. For example, the one or more processors 102 and 202 may be configured by a set of a communication control processor, an Application Processor (AP), an Electronic Control Unit (ECU), a Central Processing Unit (CPU), a Graphic Processing Unit (GPU), and a memory control processor.
[0060] The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 and store various types of data, signals, messages, information, programs, code, instructions, and / or commands. The one or more memories 104 and 204 may be configured by Random Access Memory (RAM), Dynamic RAM (DRAM), Read-Only Memory (ROM), electrically Erasable Programmable Read-Only Memory (EPROM), flash memory, volatile memory, non-volatile memory, hard drive, register, cash memory, computer-readable storage medium, and / or combinations thereof. The one or more memories 104 and 204 may be located at the interior and / or exterior of the one or more processors 102 and 202. The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 through various technologies such as wired or wireless connection.
[0061] The one or more transceivers 106 and 206 may transmit user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, to one or more other devices. The one or more transceivers 106 and 206 may receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, from one or more other devices. For example, the one or more transceivers 106 and 206 may be connected to the one or more processors 102 and 202 and transmit and receive radio signals. For example, the one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may transmit user data, control information, or radio signals to one or more other devices. The one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may receive user data, control information, or radio signals from one or more other devices.
[0062] The one or more transceivers 106 and 206 may be connected to the one or more antennas 108 and 208. Additionally and / or alternatively, the one or more transceivers 106 and 206 may include one or more antennas 108 and 208. The one or more transceivers 106 and 206 may be adapted to transmit and receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, through the one or more antennas 108 and 208. In the present disclosure, the one or more antennas 108 and 208 may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports).
[0063] The one or more transceivers 106 and 206 may convert received user data, control information, radio signals / channels, etc., from RF band signals into baseband signals in order to process received user data, control information, radio signals / channels, etc., using the one or more processors 102 and 202. The one or more transceivers 106 and 206 may convert the user data, control information, radio signals / channels, etc., processed using the one or more processors 102 and 202 from the base band signals into the RF band signals. To this end, the one or more transceivers 106 and 206 may include (analog) oscillators and / or filters. For example, the one or more transceivers 106 and 206 can up-convert OFDM baseband signals to OFDM signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202 and transmit the up-converted OFDM signals at the carrier frequency. The one or more transceivers 106 and 206 may receive OFDM signals at a carrier frequency and down-convert the OFDM signals into OFDM baseband signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202.
[0064] Although not shown in FIG. 2, the wireless devices 100 and 200 may further include additional components. The additional components 140 may be variously configured according to types of the wireless devices 100 and 200. For example, the additional components 140 may include at least one of a power unit / battery, an Input / Output (I / O) device (e.g., audio I / O port, video I / O port), a driving device, and a computing device. The additional components 140 may be coupled to the one or more processors 102 and 202 via various technologies, such as a wired or wireless connection.
[0065] In the present disclosure, a BS is also referred to as a node B (NB), an eNode B (eNB), or a gNB.
[0066] FIG. 3 shows an example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0067] A Next Generation Radio Access Network (NG-RAN) node is either:
[0068] - a gNB, providing NR user plane and control plane protocol terminations towards the UE; or
[0069] - an ng-eNB, providing E-UTRA user plane and control plane protocol terminations towards the UE.
[0070] The gNBs and ng-eNBs are interconnected with each other by means of the Xn interface. The gNBs and ng-eNBs are also connected by means of the NG interfaces to the 5GC, more specifically to the Access and Mobility Management Function (AMF) by means of the NG-C interface and to the User Plane Function (UPF) by means of the NG-U interface.
[0071] FIG. 4 shows another example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0072] A gNB may consist of a gNB-Centralized Unit (CU) and one or more gNB-Distributed Unit(s) (DU(s)). A gNB-CU and a gNB-DU is connected via F1 interface.
[0073] A gNB-CU is a logical node hosting Radio Resource Control (RRC), Service Data Adaptation Protocol (SDAP) and Packet Data Convergence Protocol (PDCP) protocols of the gNB or RRC and PDCP protocols of the en-gNB that controls the operation of one or more gNB-DUs. The gNB-CU terminates the F1 interface connected with the gNB-DU.
[0074] A gNB-DU is a logical node hosting Radio Link Control (RLC), Media Access Control (MAC) and Physical (PHY) layers of the gNB or en-gNB, and its operation is partly controlled by gNB-CU. One gNB-DU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the F1 interface connected with the gNB-CU. For Dual Connectivity (DC) operation, the Master gNB (MgNB)-DU designates the gNB-DU of an en-gNB or a gNB acting as master node, and the Secondary gNB (SgNB)-DU designates the gNB-DU of an en-gNB or a gNB acting as secondary node.
[0075] One gNB-DU is connected to only one gNB-CU.
[0076] In case of network sharing with multiple cell Identity (ID) broadcast, each cell ID associated with a subset of Public land Mobile Networks (PLMNs) corresponds to a gNB-DU and the gNB-CU it is connected to, i.e., the corresponding gNB-DUs share the same physical layer cell resources.
[0077] For resiliency, a gNB-DU may be connected to multiple gNB-CUs by appropriate implementation.
[0078] NG, Xn and F1 are logical interfaces.
[0079] Network controlled mobility applies to UEs in RRC_CONNECTED and is categorized into two types of mobility: cell level mobility and beam level mobility. Beam level mobility includes intra-cell beam level mobility and inter-cell beam level mobility.
[0080] Cell level mobility requires explicit RRC signaling to be triggered, i.e., handover (HO).
[0081] FIG. 5 shows an example of inter-gNB handover procedures to which implementations of the present disclosure are applied.
[0082] For inter-gNB handover, the signaling procedures consist of at least the following elemental components described in FIG. 5.
[0083] 1. Step 1: The source gNB initiates handover and issues a HANDOVER REQUEST over the Xn interface.
[0084] 2. Step 2: The target gNB performs admission control and provides the new RRC configuration as part of the HANDOVER REQUEST ACKNOWLEDGE.
[0085] 3. Step 3: The source gNB provides the RRC configuration to the UE by forwarding theRRCReconfigurationmessage received in the HANDOVER REQUEST ACKNOWLEDGE. TheRRCReconfigurationmessage includes at least cell ID and all information required to access the target cell so that the UE can access the target cell without reading system information. For some cases, the information required for contention-based and contention-free random access can be included in theRRCReconfigurationmessage. The access information to the target cell may include beam specific information, if any.
[0086] 4. Step 4: The UE moves the RRC connection to the target gNB and replies with theRRCReconfigurationComplete.
[0087] User data may also be sent in step 4 if the grant allows.
[0088] Beam level mobility does not require explicit RRC signaling to be triggered. Beam level mobility can be within a cell, or between cells, the latter is referred to as Inter-Cell Beam Management (ICBM). For ICBM, a UE can receive or transmit UE dedicated channels / signals via a Transmission / Reception Point (TRP) associated with a Physical Cell ID (PCI) different from the PCI of a serving cell, while non-UE-dedicated channels / signals can only be received via a TRP associated with a PCI of the serving cell. The gNB provides via RRC signaling the UE with measurement configuration containing configurations of Synchronization Signal Block (SSB) / Channel State Information (CSI) resources and resource sets, reports and trigger states for triggering channel and interference measurements and reports. In case of ICBM, a measurement configuration includes SSB resources associated with PCIs different from the PCI of a serving cell. Beam level mobility is then dealt with at lower layers by means of physical layer and MAC layer control signaling, and RRC is not required to know which beam is being used at a given point in time.
[0089] SSB-based beam level mobility is based on the SSB associated to the initial DL Bandwidth Part (BWP) and can only be configured for the initial DL BWPs and for DL BWPs containing the SSB associated to the initial DL BWP. For other DL BWPs, beam level mobility can only be performed based on CSI-Reference Signal (RS).
[0090] A Conditional Handover (CHO) is defined as a handover that is executed by the UE when one or more handover execution conditions are met. The UE starts evaluating the execution condition(s) upon receiving the CHO configuration, and stops evaluating the execution condition(s) once a handover is executed.
[0091] The following principles apply to CHO:
[0092] - The CHO configuration contains the configuration of CHO candidate cell(s) generated by the candidate gNB(s) and execution condition(s) generated by the source gNB.
[0093] - An execution condition may consist of one or two trigger condition(s) (CHO events A3 / A5). Only single RS type is supported and at most two different trigger quantities (e.g., Reference Signal Received Power (RSRP) and Reference Signal Received Quality (RSRQ), RSRP and Signal-to-Interference plus Noise Ratio (SINR), etc.) can be configured simultaneously for the evaluation of CHO execution condition of a single candidate cell.
[0094] - Before any CHO execution condition is satisfied, upon reception of HO command (without CHO configuration), the UE executes the HO procedure, regardless of any previously received CHO configuration.
[0095] - While executing CHO, i.e., from the time when the UE starts synchronization with target cell, the UE does not monitor source cell.
[0096] L1 / L2 Triggered Mobility (LTM) is a procedure in which a gNB receives L1 measurement report(s) from a UE, and on their basis the gNB changes UE's serving cell by a cell switch command signaled via a MAC Control Element (CE). The cell switch command indicates an LTM candidate cell configuration that the gNB previously prepared and provided to the UE through RRC signaling. Then the UE switches to the target cell according to the cell switch command. The LTM procedure can be used to reduce the mobility latency.
[0097] When configured by the network, it is possible to activate Transmission Configuration Index (TCI) states of one or multiple cells that are different from the current serving cell. For instance, the TCI states of the LTM candidate cells can be activated in advance before any of those cells become the serving cell. This allows the UE to be DL synchronized with those cells, thereby facilitating a faster cell switch to one of those cells when cell switch is triggered.
[0098] When configured by the network, it is possible to initiate UL Timing Advance (TA) acquisition procedure to one or multiple cells that are different from the current serving cell. For instance, the network may request the UE to perform early TA acquisition of a candidate cell before a cell switch. The early TA acquisition is triggered by Physical Downlink Control Channel (PDCCH) order or realized through UE-based TA measurement. In the former case, the gNB to which the candidate cell belongs calculates the TA value and sends it to the gNB to which the serving cell belongs. The serving cell sends the TA value in the LTM cell switch command MAC CE when triggering LTM cell switch. In the latter case, the UE applies the TA value measured by itself and performs Random Access Channel (RACH)-less LTM upon receiving the cell switch command.
[0099] If UE-based TA measurement is configured, the UE performs RACH-less LTM upon receiving the cell switch command. Otherwise, the UE determines whether to access the target cell with the RA procedure depending on whether a TA value is provided in the cell switch command. For RACH-less LTM, the UE accesses the target cell via a configured grant provided in the LTM candidate cell configuration and selects the configured grant occasion associated with the beam indicated in the cell switch command. If the LTM candidate cell configuration does not include a configured grant, the UE may monitor PDCCH for dynamic scheduling from the target cell upon LTM cell switch. Before RACH-less LTM procedure completion, the UE may not trigger random access procedure if it does not have a valid Physical Uplink Control Channel (PUCCH) resource for triggered Scheduling Requests (SRs).
[0100] The following principles apply to LTM:
[0101] - The UE does not update its security key after an intra-gNB LTM cell switch.
[0102] - Subsequent LTM is supported.
[0103] LTM supports both intra-gNB-DU and intra-gNB-CU inter-gNB-DU mobility. LTM supports both intra-frequency and inter-frequency mobility, including mobility to inter-frequency cell that is not a current serving cell. The following scenarios are supported:
[0104] - Primary Cell (PCell) change in non-Carrier Aggregation (CA) scenario and non-DC scenario,
[0105] - PCell change in CA scenario,
[0106] - DC scenario, Master Cell Group (MCG) PCell change and Secondary Cell Group (SCG) Primary Secondary Cell (PSCell) change without Master Node (MN) involvement case (i.e., intra-Secondary Node (SN) PSCell change).
[0107] While the UE has stored LTM candidate cell configurations, the UE can also execute any L3 handover command sent by the network.
[0108] FIG. 6 shows an example of signaling procedure for LTM to which implementations of the present disclosure are applied.
[0109] Cell switch command is conveyed in a MAC CE, which contains the necessary information to perform the LTM cell switch.
[0110] Subsequent LTM is done by repeating the early synchronization, LTM cell switch execution, and LTM cell switch completion steps without releasing other LTM candidate cell configurations after each LTM cell switch completion.
[0111] The signaling procedure for LTM is as follows.
[0112] 1. Step 1: The UE sends aMeasurementReportmessage to the gNB. The gNB decides to configure LTM and initiates candidate cell(s) preparation.
[0113] 2. Step 2: The gNB transmits anRRCReconfigurationmessage to the UE including the LTM candidate cell configurations of one or multiple candidate cells.
[0114] 3. Step 3: The UE stores the LTM candidate cell configurations and transmits anRRCReconfigurationCompletemessage to the gNB.
[0115] 4a. Step 4a: The UE may perform DL synchronization with the candidate cell(s) before receiving the cell switch command.
[0116] 4b. Step 4b: When UE-based TA measurement is configured, the UE may acquire the TA value(s) of the candidate cell(s) by measurement. Otherwise, the UE may perform early TA acquisition with the candidate cell(s) as requested by the network before receiving the cell switch command. This may be done via Contention-Free Random Access (CFRA) triggered by a PDCCH order from the source cell, following which the UE may send preamble towards the indicated candidate cell. In order to minimize the data interruption of the source cell due to CFRA towards the candidate cell(s), the UE may not receive random access response from the network for the purpose of TA value acquisition and the TA value of the candidate cell is indicated in the cell switch command. The UE may not maintain the TA timer for the candidate cell and relies on network implementation to guarantee the TA validity.
[0117] 5. Step 5: The UE performs L1 measurements on the configured candidate cell(s) and transmits L1 measurement reports to the gNB. L1 measurement should be performed as long as RRC reconfiguration (step 2) is applicable.
[0118] 6. Step 6: The gNB decides to execute cell switch to a target cell and transmits a MAC CE triggering cell switch by including the candidate configuration index of the target cell. The UE switches to the target cell and applies the configuration indicated by candidate configuration index.
[0119] 7. Step 7: The UE may perform the random access procedure towards the target cell, if the UE does not have valid TA of the target cell. The UE may perform CFRA if the LTM cell switch command MAC CE contains information for CFRA.
[0120] 8. Step 8: The UE completes the LTM cell switch procedure by sendingRRCReconfigurationCompletemessage to target cell. If the UE has performed a random access procedure in step 7, the UE considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM, the UE considers that LTM cell switch execution is successfully completed when the UE determines that the network has successfully received its first UL data. The UE determines successful reception of its first UL data by receiving a PDCCH addressing the UE's Cell Radio Network Temporary Identity (C-RNTI) in the target cell, which schedules a new transmission following the first UL data. The PDCCH carries either a DL assignment or an UL grant addressing the same HARQ process as the first UL data.
[0121] The steps 4-8 can be performed multiple times for subsequent LTM using the LTM candidate cell configuration(s) provided in step 2.
[0122] Currently, the security master key (KNG-RAN) change process in 5G systems during handover is as follows. Hereinafter, the security master key may be used interchangeably with a security key, a master key, or just a key.
[0123] - 5G Non-Access Stratum (NAS) and AS security contexts (e.g., KAMF, KNG-RAN, Next Hop (NH) parameter and Next Hop Chaining Counter (NCC), etc.) are per-UE basis. In other words, those KAMFor KNG-RAN(as their name suggests) does not imply that they are some node-specific security key that can be used for multiple UEs.
[0124] - The security key handling during Xn handover has been that it is the source NG-RAN node who computes a new KNG-RAN* using the PCI and frequency Absolute Radio Frequency Channel Number (ARFCN)-DL / Evolved-UTRA AFRCH (EARFCN)-DL of the cell in the target NG-RAN node that the UE will be handover to, either by using its current key (i.e., KNG-RAN) in case of the horizontal key derivation or by using the fresh (i.e., unused) NH in case of vertical key derivation.
[0125] - The source NG-RAN node forwards the derived {KNG-RAN*, NCC} to the target NG-RAN node, to be used when the UE successfully accesses the target cell.
[0126] - If a fresh NH is available for a UE, the source NG-RAN node uses the vertical key derivation for handover. The fresh NH (and associated NCC value) used for vertical key derivation is computed by the AMF (by increasing its locally kept NCC value by one) and provided to the target NG-RAN node during path switch procedure after handover is completed. The received {NH, NCC} pair is stored for further handovers of the UE and replace the existing pair if any.
[0127] - A UE does not receive a security key over the air. Instead, a UE computes the next master key to use at the target cell. That is, the UE derives a new KNG-RAN* (or may retain the same KNG-RANbased on indication from the network in case of intra-CU handover) depending on NCC value received in the handover command from the target NG-RAN node (whose value is the same to what the target received from the source). If the received NCC value is the same to the one already stored, the UE performs horizontal key derivation, same as the source NG-RAN node. Otherwise, the UE first synchronizes the locally kept NH parameter iteratively until the NCC values match and then performs the vertical key derivation (same as the source NG-RAN node).
[0128] - For CHO, the legacy mechanism for master key is re-utilized. That is, during the preparation phase, HO signalling is exchanged between the source and a candidate target node individually per each candidate cell basis, where the source derives a new KNG-RAN* for each candidate cell (except ones belonging to the source for which the source may decide to re-use the same master key and indicate the UE to retain the same key), which is provided to each candidate target node accordingly. Their associated NCC value is also sent to each candidate target node and forwarded to the UE, same as legacy.
[0129] - Moreover, for CHO, conditional reconfigurations are released in the UE and network (except some special failure case which is rare) once successfully executed and one of candidate cells is selected for access, which means that actual serving cell change (and master key change, if applicable) happens only once.
[0130] The detailed security handling in mobility is described.
[0131] Whenever an initial AS security context needs to be established between UE and gNB / ng-eNB, The AMF and the UE derive a KgNBand a NH parameter. The KgNBand the NH are derived from the KAMF. An NCC is associated with each KgNBand NH parameter. Every KgNBis associated with the NCC corresponding to the NH value from which it was derived. At initial setup, the KgNBis derived directly from KAMF, and is then considered to be associated with a virtual NH parameter with NCC value equal to zero. At initial setup, the derived NH value is associated with the NCC value one.
[0132] The AMF does not send the NH value to gNB / ng-eNB at the initial connection setup. The gNB / ng-eNB initializes the NCC value to zero after receiving NGAP Initial Context Setup Request message.
[0133] Since the AMF does not send the NH value to gNB / ng-eNB at the initial connection setup, the NH value associated with the NCC value one cannot be used in the next Xn handover or the next intra-gNB / intra-ng-eNB-CU handover, for the next Xn handover or the next intra-gNB-CU / intra-ng-eNB handover, the horizontal key derivation will apply.
[0134] The AMF always computes a fresh {NH, NCC} pair that is given to the target gNB / ng-eNB. An implication of this is that the first {NH, NCC} pair will never be used to derive a KgNB. It only serves as an initial value for the NH chain.
[0135] The UE and the gNB / ng-eNB use the KgNBto secure the communication between each other. On handovers and at transitions from RRC_INACTIVE to RRC_CONNECTED states, the basis for the KgNBthat will be used between the UE and the target gNB / ng-eNB, called KNG-RAN*, is derived from either the currently active KgNBor from the NH parameter. If KNG-RAN* is derived from the currently active KgNB, this is referred to as a horizontal key derivation and if the KNG-RAN* is derived from the NH parameter, the derivation is referred to as a vertical key derivation.
[0136] As NH parameters are only computable by the UE and the AMF, it is arranged so that NH parameters are provided to gNB / ng-eNBs from the AMF in such a way that forward security can be achieved.
[0137] On handovers with vertical key derivation, the NH is further bound to the target PCI and its frequency ARFCN-DL before it is taken into use as the KgNBin the target gNB / ng-eNB. On handovers with horizontal key derivation, the currently active KgNBis further bound to the target PCI and its frequency ARFCN-DL before it is taken into use as the KgNBin the target gNB / ng-eNB.
[0138] In intra-gNB-CU handover and intra-ng-eNB handover, the gNB has a policy deciding at which intra-gNB-CU handovers the KgNBcan be retained and at which a new KgNBneeds to be derived. At an intra-gNB-CU handover, the gNB indicates to the UE whether to change or retain the current KgNBin the HO Command message. Retaining the current KgNBis only be done during intra-gNB-CU handover.
[0139] If the current KgNBis to be changed, the gNB / ng-eNB and the UE derive a KNG-RAN* using target PCI, its frequency ARFCN-DL / EARFCN-DL, and either NH or the current KgNBdepending on the following criteria: the gNB uses the NH for deriving KNG-RAN* if an unused {NH, NCC} pair is available in the gNB (this is referred to as a vertical key derivation), otherwise if no unused {NH, NCC} pair is available in the gNB, the gNB derives KNG-RAN* from the current KgNB(this is referred to as a horizontal key derivation). The gNB sends the NCC used for the KNG-RAN* derivation to UE in HO Command message. The gNB / ng-eNB and the UE uses the KNG-RAN* as the KgNB, after handover.
[0140] If the current KgNBis to be retained, the gNB and the UE continue using the current KgNB, after handover.
[0141] The key derivation mechanism described herein is also be applicable when gNB is implemented as a single unit, i.e., when the gNB is not split into CU and DU.
[0142] In Xn handovers, the source gNB / ng-eNB performs a vertical key derivation in case it has an unused {NH, NCC} pair. The source gNB / ng-eNB first computes KNG-RAN* from target PCI, its frequency ARFCN-DL / EARFCN-DL, and either from currently active KgNBin case of horizontal key derivation or from the NH in case of vertical key derivation.
[0143] Next, the source gNB / ng-eNB forwards the {KNG-RAN*, NCC} pair to the target gNB / ng-eNB. The target gNB / ng-eNB uses the received KNG-RAN* directly as KgNBto be used with the UE. The target gNB / ng-eNB associates the NCC value received from source gNB / ng-eNB with the KgNB. The target gNB / ng-eNB includes the received NCC into the prepared HO Command message, which is sent back to the source gNB / ng-eNB in a transparent container and forwarded to the UE by source gNB / ng-eNB.
[0144] When the target gNB / ng-eNB has completed the handover signaling with the UE, it sends a NGAP PATH SWITCH REQUEST message to the AMF. Upon reception of the NGAP PATH SWITCH REQUEST, the AMF increases its locally kept NCC value by one and compute a new fresh NH from its stored data using the function. The AMF uses the KAMFfrom the currently active 5G NAS security context for the computation of the new fresh NH. The AMF then sends the newly computed {NH, NCC} pair to the target gNB / ng-eNB in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The target gNB / ng-eNB stores the received {NH, NCC} pair for further handovers and remove other existing unused stored {NH, NCC} pairs if any.
[0145] If the AMF had activated a new 5G NAS security context with a new KAMF, different from the 5G NAS security context on which the currently active 5G AS security context is based, but has not yet successfully performed a UE Context Modification procedure, the sent NGAP PATH SWITCH REQUEST ACKNOWLEDGE message in addition contains a New Security Context Indicator (NSCI). The AMF in this case derives a new initial KgNBfrom the new KAMFand the uplink NAS COUNT in the most recent NAS Security Mode Complete message. The AMF associates the derived new initial KgNBwith a new NCC value equal to zero. Then, the AMF uses {the derived new initial KgNB, the new NCC value initialized to zero} pair as the newly computed {NH, NCC} pair to be sent in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The gNB / ng-eNB in this case sets the value ofkeySetChangeIndicatorfield to true in further handovers. The gNB / ng-eNB should in this case perform an intra-gNB-CU / intra-ng-eNB handover immediately.
[0146] Because the NGAP PATH SWITCH REQUEST message is transmitted after the radio link handover, it can only be used to provide keying material for the next handover procedure. Thus, for Xn-handovers, key separation happens only after two hops because the source gNB / ng-eNB knows the target gNB / ng-eNB keys. The target gNB / ng-eNB can immediately initiate an intra-gNB-CU / intra-ng-eNB handover to take the new NH into use once the new NH has arrived in the PATH SWITCH REQUEST ACKNOWLEDGE message.
[0147] The key derivation mechanism described herein is also applicable to CHO.
[0148] Scenarios considered in LTM have been limited to intra-CU case only, i.e., serving cell change within cells under a single CU. For NR mobility enhancement, support for inter-CU LTM has been studied.
[0149] Specifically, it has been studied to support for subsequent LTM mobility procedures aiming to avoid RRC configuration between cell switches as per current LTM mechanism. In other words, inter-CU mobility should support initial and subsequent serving cell changes based on a single mobility configuration (i.e., no RRC reconfiguration between cell switches). This requires supporting consecutive updates of security master key from one node to another node, and so on, as the UE moves between nodes. From the UE's perspective, once inter-CU LTM is configured, a new master key will be derived based on the previous key whenever serving cell changes across CUs. In other words, when a serving cell changes from one CU to another CU, the new serving CU becomes the source for the next serving cell change and its master key should serve as the basis for next key derivation.
[0150] The security master key update process in inter-CU LTM should cater these aspects and maintain key synchronization seamlessly between the UE and the current serving CU (among multiple CUs) regardless of how the UE moves between nodes. Moreover, the network should always be ready to use the right master key regardless of how serving cells change during inter-CU LTM, without having to reconfigure the UE in the middle or delaying data exchanges.
[0151] The present disclosure proposes some mechanisms to address the challenges mentioned above and / or support security master key update seamlessly during inter-CU LTM.
[0152] According to implementations of the present disclosure, necessary signaling procedures to ensure seamless updates of the security master key during inter-CU LTM operations are proposed. Furthermore, according to implementations of the present disclosure, horizontal and vertical key derivation methods for inter-CU LTM are proposed. According to implementations of the present disclosure, scenarios involving cell switch failures / re-attempt are also handled.
[0153] In order to support security master key update process seamlessly during inter-CU LTM according to implementations of the present disclosure, the following reasonings are used to guide and optimize the solution design.
[0154] (1) A potential target CU should receive the next master key to use from the current serving CU, before the UE is handed over to the target CU.
[0155] Before handover, the UE applies the target cell configuration, and if it contains the security master key update indication, the UE derives the new master key. This means that the UE derives the master key (if configured to do so) before executing handover, so that the UE can be ready to communicate with the target cell safely and immediately after successfully accessed. From this perspective, the network should also be ready to use the right key at the new serving CU (i.e., the target CU to which the UE is handed over) immediately whenever serving cell changes.
[0156] This is also in conformity with the legacy mechanisms. In the legacy handover, the network decided handover for a specific target cell (only one target CU to consider) and it is executed immediately once configured to the UE. As a result, it was the source (i.e., current serving CU) who derives the next key to use (using the target cell information) and the source sent it to the target during handover preparation. In case of conditional mobility for which is not executed immediately after configured to the UE, the source does not know which target cell (among candidate target cells) will be accessed by the UE. However, the legacy mechanism was re-utilized in a sense that the source (i.e., current serving CU) derives a new key for each candidate target cell in advance and configures them to the potential target CU(s), before it configures the UE. In conditional mobility, any potential target node was made ready to use the right key regardless of which cell the UE accesses to. Since LTM aims the same principle of preparing / pre-configuring one or more candidate target cell(s), it may be better to apply the similar mechanism for inter-CU LTM as well.
[0157] (2) Considering the subsequent mobility nature of LTM, a new serving CU should derive next master key(s) to use for potential next target CU(s) in advance (including itself for the case of intra-CU serving cell change, if the new serving CU configured the UE to update key for intra-CU LTM (which could be controlled per candidate cell basis)).
[0158] (3) The timing of when the new serving CU derives next master key(s) to use for potential next target CU(s) should be after handover to the new serving CU is successfully confirmed.
[0159] If the new serving CU derives next master key to use for potential next target CU(s) when the new serving CU (e.g., CU1) receives the LTM cell switch notification from the previous serving CU (who sent LTM cell switch command to the UE towards a candidate cell in CU1), it may be complicated, especially in a scenario of failure / single-reattempt allowed for LTM (controlled by the network).
[0160] For example, when LTM fails once, the UE may be pre-configured to try LTM once more if the suitable cell found by cell re-selection is one of the candidate cells configured to the UE. In such scenario, the UE reverts back to the original configuration and re-starts from there. If the selected candidate cell belongs to a different CU (e.g., CU2), CU2 becomes a new source who should derive the next key(s) to use for potential next target CU(s). The key(s) that had been derived by CU1 based on the LTM cell switch notification and provided to other CU(s) (including CU2) should be rescinded. Moreover, from CU2 point of view, CU2 should newly derive based on the old key of that candidate cell before receiving new key of that candidate cell from CU1. The old key should not be replaced by the new key received from CU1, and CU2 should also know to use the old key instead of the new key received from CU1 when deriving next master key(s) for potential next target CU(s).
[0161] The similar issue also exists when the UE fails and single-reattempts to another candidate cell in the same serving CU, because the serving CU (based on LTM cell switch notification from its serving DU) may have already derived new key(s) and configured them to potential next target CU(s) before even knowing that the UE in fact accessed a different candidate cell. Those keys provided to other CU(s) should be rescinded, or the serving CU has to re-do the derivation of new keys.
[0162] (4) For intra-CU LTM, the timing of when the new serving CU derives next master key(s) to use for potential next target CU(s) describe above in (3) may be further optimized, by having the new serving CU (i.e., same as the previous serving CU) derive only one new key to use after knowing intra-CU LTM is commanded to the UE, instead of deriving multiple new keys in advance for applicable candidate cells for potential intra-CU serving cell change (i.e., following (2) described above).
[0163] In other words, as a special optimization for intra-CU serving cell change, the new serving CU (i.e., same as the previous serving CU) may be allowed to minimize key derivation efforts after handover is confirmed, at least in terms of preparing new keys towards itself for potential intra-CU serving cell change.
[0164] However, when the UE fails and single-reattempts to access another candidate cell within the same serving CU, if the serving CU has already derived a new key to use with the UE based on LTM cell switch notification and the candidate cell indicated, it has to re-derive the key upon knowing that the UE accessed a different candidate cell (which is confirmed via Access Success message from its DU). That is, the master key to use with the UE may not be ready, until the serving CU receives the message from its DU informing different cell access and re-derives again. While this re-derivation may introduce some delay, it may be typically negligible. Also, this delay may be somewhat unavoidable as the UE accessed an unintended candidate cell due to failure, which necessitates the serving CU to correct the key derivation process. On the other hand, if the same key is retained for intra-CU serving cell change, there would be no need for new key derivation for the case of intra-CU LTM and thus no need to discuss such delay.
[0165] Based on the reasonings described above, various implementations of the present disclosure will be described.
[0166] The following drawings are created to explain specific embodiments of the present disclosure. The names of the specific devices or the names of the specific signals / messages / fields shown in the drawings are provided by way of example, and thus the technical features of the present disclosure are not limited to the specific names used in the following drawings.
[0167] FIG. 7 shows an example of a method to which implementations of the present disclosure are applied.
[0168] In step S700, the method comprises receiving, by a second base station, a handover related message from a first base station serving a first cell. The handover related message includes security keys to be used by the second base station and information related to security key update.
[0169] In some implementations, the information related to security key update may include one or more values assigned for security key update of candidate cells belonging to the first base station. Additionally and / or alternatively, the information related to security key update may include a value range for security key update of candidate cells belonging to the second base station. The value range for security key update of candidate cells belonging to the second base station may not be overlapped with one or more value ranges for security key update of candidate cells belonging to the other base stations.
[0170] In step S710, the method comprises transmitting, by the second base station, an acknowledgement message to the first base station in response to the handover related message.
[0171] In some implementations, the acknowledgement message may include information related to security key update of admitted candidate cells belonging to the second base station. For example, the information related to security key update of admitted candidate cells belonging to the second base station may include one or more values assigned for security key update of the admitted candidate cells belonging to the second base station.
[0172] In step S720, the method comprises performing an access with a wireless device based on a cell change from the first cell to a second cell.
[0173] In step S730, the method comprises, after the cell change from the first cell to the second cell is completed, deriving new security keys for candidate cells based on a current security and the information related to security key update.
[0174] In step S740, the method comprises transmitting the new security keys to other base stations for subsequent mobility.
[0175] For an inter-CU LTM, the cell change may be performed from the first cell belonging to the first base station to the second cell belonging to the second base station. In this case, steps S720 to S740 may be performed by the second base station.
[0176] In some implementations, the current security may correspond to a security key included in the handover related message. In other words, the handover related message (e.g., handover request message) may include the security key related to the second cell. For example, the second base station may receive the security keys to be used after cell change via the handover related message, and derive the new security keys based on the current security key.
[0177] In some implementations, the new security keys may be derived for candidate cells belonging to the second base station and the other base stations.
[0178] In some implementations, the method may further comprise transmitting a path switch request message to a core network. The path switch request message may inform that a path switch is due to the inter-CU LTM.
[0179] In some implementations, the method may further comprise receiving a path switch request acknowledge message from a core network in response to the path switch request message. The path switch request acknowledge message may not include a new pair of NH parameter and NCC. For example, the path switch request acknowledge message may include an existing pair of the NH parameter and the NCC. Additionally and / or alternatively, the path switch request acknowledge message may inform to ignore an included pair of the NH parameter and the NCC.
[0180] For an intra-CU LTM, the cell change may be performed from the first cell belonging to the first base station to the second cell belonging to the first base station. In this case, steps S720 to S740 may be performed by the first base station.
[0181] In some implementations, the new security keys may be derived for candidate cells belonging to the first base station and the other base stations.
[0182] In some implementations, an NCC value used for deriving the new security keys may be transmitted together with the new security keys to the other base stations.
[0183] For LTM re-attempt after failure of cell switch, the method may further comprise performing an access with the wireless device based on a cell change from the second cell to a third cell, after the cell change from the second cell to the third cell is completed, deriving second new security keys for candidate cells based on a security related to the third cell, and transmitting the second new security keys to the other base stations for subsequent mobility. For example, the third cell may be accessed based on cell selection due to a failure of LTM execution.
[0184] In some implementations, the third cell may be same as the first cell or the second cell. For example, after the second base station becomes a new serving base station, next subsequent mobility may be performed to another base station. However, cell change execution to the third cell may fail, upon which the first cell or the second cell is selected by the cell selection.
[0185] In some implementations, the third cell may be different from the first cell or the second cell.
[0186] In some implementations, the first base station may correspond to a CU belonging to the first base station. The second base station may correspond to a CU belonging to the second base station.
[0187] Furthermore, the method described above in FIG. 7 may be performed by a base station. The base station may be implemented by the second wireless device 200 shown in FIG. 2.
[0188] The base station comprises at least one transceiver, at least one processor, and at least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method described in FIG. 7.
[0189] More specifically, the second base station receives a handover related message from a first base station serving a first cell. The handover related message includes security keys to be used by the second base station and information related to security key update.
[0190] In some implementations, the information related to security key update may include one or more values assigned for security key update of candidate cells belonging to the first base station. Additionally and / or alternatively, the information related to security key update may include a value range for security key update of candidate cells belonging to the second base station. The value range for security key update of candidate cells belonging to the second base station may not be overlapped with one or more value ranges for security key update of candidate cells belonging to the other base stations.
[0191] The second base station transmits an acknowledgement message to the first base station in response to the handover related message.
[0192] In some implementations, the acknowledgement message may include information related to security key update of admitted candidate cells belonging to the second base station. For example, the information related to security key update of admitted candidate cells belonging to the second base station may include one or more values assigned for security key update of the admitted candidate cells belonging to the second base station.
[0193] In case of inter-CU LTM, the second base station performs an access with a wireless device based on a cell change from the first cell to a second cell belonging to the second base station. After the cell change from the first cell to the second cell is completed, the second base station derives new security keys for candidate cells based on the current security and the information related to security key update. The second base station transmits the new security keys to other base stations for subsequent mobility.
[0194] In some implementations, the current security may correspond to a security key included in the handover related message. In other words, the handover related message (e.g., handover request message) may include the security key related to the second cell. For example, the second base station may receive the security keys to be used after cell change via the handover related message, and derive the new security keys based on the current security key.
[0195] In some implementations, the new security keys may be derived for candidate cells belonging to the second base station and the other base stations.
[0196] In some implementations, the second base station may transmit a path switch request message to a core network. The path switch request message may inform that a path switch is due to the inter-CU LTM.
[0197] In some implementations, the second base station may receive a path switch request acknowledge message from a core network in response to the path switch request message. The path switch request acknowledge message may not include a new pair of NH parameter and NCC. For example, the path switch request acknowledge message may include an existing pair of the NH parameter and the NCC. Additionally and / or alternatively, the path switch request acknowledge message may inform to ignore an included pair of the NH parameter and the NCC.
[0198] For an intra-CU LTM, the first base station performs an access with a wireless device based on a cell change from the first cell to a second cell belonging to the first base station. After the cell change from the first cell to the second cell is completed, the first base station derives new security keys for candidate cells based on the current security and the information related to security key update. The first base station transmits the new security keys to other base stations for subsequent mobility.
[0199] In some implementations, the new security keys may be derived for candidate cells belonging to the first base station and the other base stations.
[0200] In some implementations, an NCC value used for deriving the new security keys may be transmitted together with the new security keys to the other base stations.
[0201] For LTM re-attempt after failure of cell switch, the first base station or second base station may perform an access with the wireless device based on a cell change from the second cell to a third cell, after the cell change from the second cell to the third cell is completed, derive second new security keys for candidate cells based on a security related to the third cell, and transmit the second new security keys to the other base stations for subsequent mobility. For example, the third cell may be accessed based on cell selection due to a failure of LTM execution.
[0202] In some implementations, the third cell may be same as the first cell or the second cell. For example, after the second base station becomes a new serving base station, next subsequent mobility may be performed to another base station. However, cell change execution to the third cell may fail, upon which the first cell or the second cell is selected by the cell selection.
[0203] In some implementations, the third cell may be different from the first cell or the second cell.
[0204] In some implementations, the first base station may correspond to a CU belonging to the first base station. The second base station may correspond to a CU belonging to the second base station.
[0205] The exemplary operations and / or interaction procedures involving at least one of a UE, DU, CU, and Core Network (CN) for inter-CU LTM security master key handling, including initial configuration, intra-CU, and inter-CU serving cell change will be described.
[0206] FIG. 8 shows an example of an initial configuration procedure for inter-CU LTM security master key update to which implementations of the present disclosure are applied.
[0207] In step S800, a source CU (S-CU) may decide to configure inter-CU LTM and candidate cell(s) to a UE.
[0208] In step S810, upon deciding to configure the inter-CU LTM and the corresponding candidate cell(s) to the UE, the S-CU may derive new security master key (e.g., KNG-RAN*) for each candidate cell belonging to other CU(s).
[0209] If there was an unused {NH, NCC} pair available in the S-CU, the S-CU may perform the vertical key derivation. Otherwise, the S-CU may perform the horizontal key derivation using its current master key of the UE (e.g., KNG-RAN).
[0210] In intra-CU LTM, the same security master key may always be retained for intra-CU serving cell change. In Inter-CU LTM, the security master key may be updated for serving cell change within the same CU (or per candidate cell basis). If so, then during step S810, the S-CU may derive new key KNG-RAN* for those key-update-required / configured candidate cells belonging to the S-CU. However, as described above, the case of intra-CU cell switch may be further optimized in a way that the S-CU derives only one new key to use after knowing that intra-CU cell switch is commanded to the UE and to which candidate cell. In other words, new keys for those key-update-required / configured candidate cells under the current serving CU may not have to be derived in advance as opposed for key derivation of candidate cell(s) belonging to other CU(s).
[0211] In step S820, for each candidate cell lying in other CU(s), the S-CU may request handover to other CU(s). For example, the S-CU may transmit a handover request message for LTM to each candidate CU (e.g., C-CU1 and / or C-CU2).
[0212] Each handover request message for each candidate cell may include the newly derived security master key (i.e., KNG-RAN*) corresponding to each candidate cell and NCC value that was used for key derivation at the S-CU.
[0213] Each handover request message for each candidate cell may include information related to the control of the master key update of candidate cell(s) during serving cell change, which may include at least one of the followings.
[0214] - One or more values already assigned to control the master key update of candidate cell(s) belonging to the S-CU; or
[0215] - A value range to be used by a C-CU to assign to control the master key update of the candidate cell(s) belonging to the corresponding C-CU.
[0216] One way to configure the UE with no master key update for intra-CU serving cell change could be following intra-CU LTM mechanism (such as UE-based Timing Advance (TA) measurement configuration via RRC). Namely, the network may assign an integer value to each candidate cell, and once cell switch command is received, the UE may determine whether to update the master key or not by comparing an integer value assigned by the previous serving cell with an integer value assigned by the new serving cell (if equal, then no update; if different, then update).
[0217] For this approach to work in inter-CU LTM, the S-CU may provide C-CU(s) with some integer values already assigned to control candidate cell grouping of the S-CU. Upon receiving integer values assigned to candidate cell grouping of the S-CU, a C-CU may use and assign different integer value ranges for candidate cell grouping of the corresponding C-CU (based on the assumption that serving cell change across CU should always result in master key update). If there are multiple C-CUs, the S-CU may provide each C-CU with a distinct range of integer values to prevent overlapping of each range of integer values.
[0218] While it is envisioned that such 1-dimentional candidate cell grouping effectively controls the master key update of the UE for the serving cell change in inter-CU LTM, it may lack more precise control (e.g., key update from cell A to cell B or cell C; but not from cell B to cell C, etc.).
[0219] In step S830, for each cell for which the inter-CU LTM is requested from the S-CU, each C-CU (e.g., C-CU1 and / or C-CU2) may perform admission control with its corresponding DU and may establish UE context to prepare for inter-CU LTM. Each C-CU generates the handover command for each admitted candidate cell, whose reconfiguration message (e.g.,RRCReconfigurationmessage) may include the NCC value received from the S-CU. Each C-CU may transmit a handover request acknowledge message for LTM including the handover command to the S-CU.
[0220] The handover request acknowledge message may include information related to the control of the master key update of admitted candidate cell(s) of each C-CU during serving cell change. For example, such information may include some values assigned to each candidate cell admitted by the corresponding C-CU. Such information may be compiled by the S-CU and delivered to the UE via reconfiguration message (e.g.,RRCReconfigurationmessage) of the S-CU. Or, such information may be compiled by each C-CU and delivered to the UE via its respective reconfiguration message (e.g.,RRCReconfigurationmessage).
[0221] In step S840, the S-CU may compile the final LTM handover command including LTM configurations generated for all the accepted / prepared candidate cell(s) and may reconfigure the UE via S-DU.
[0222] FIG. 9 shows an example of an intra-CU serving cell change for inter-CU LTM security master key update procedure to which implementations of the present disclosure are applied.
[0223] The operations of FIG. 9 may follow the operations of FIG. 8.
[0224] In step S900, the UE may report L1 measurements as configured to the current serving DU (e.g., S-DU).
[0225] In step S902, the S-DU may decide cell switch and command the UE to handover to a target cell (one of the prepared candidate cells) under the current serving CU (e.g., S-CU). For example, the S-DU may transmit an LTM command to the UE to handover the UE to a target cell A belonging to the S-CU.
[0226] Upon commanding the UE, in step S904, the S-DU may notify cell switch to the S-CU. For example, the S-DU may transmit an LTM cell change notification message indicating the target cell A to the S-CU.
[0227] If the S-CU configured the UE to update key for the commanded target cell, the S-CU may start using the corresponding KNG-RAN* if the S-CU has already derived in step S810 in FIG. 8.
[0228] In step S910, unless the UE was configured to retain the same key for the commanded target cell, the UE may derive new master key (e.g., KNG-RAN*).
[0229] In step S912, if the current serving CU previously configured the UE to update key for the commanded target cell, the S-CU may also derive new master key (e.g., KNG-RAN*) to be synchronized with the UE, if the S-CU has not derived it before in step S810 in FIG. 8.
[0230] In step S920, the UE may perform random access procedure and access the commanded target cell (e.g., target cell A).
[0231] In step S922, the S-DU may inform access success to the S-CU. For example, S-DU may transmit an access success message indicating the target cell A to the S-CU.
[0232] In step S924, the UE is still served under S-CU, e.g., via the target cell A.
[0233] Data exchanges may continue over the new serving cell.
[0234] In step S930, after the cell switch is successfully confirmed, the S-CU mayderive new master key (e.g., KNG-RAN**) for the candidate cell(s) to be used for next serving cell change based on the current master key (e.g., KNG-RAN) or based on updated master key (e.g., KNG-RAN*). The S-CU may configure those newly derived keys to other CU(s) for subsequent LTM operations (e.g., via an LTM Configuration Update message). The NCC value that was used for deriving the new master key (e.g., KNG-RAN**) may also be provided to other CU(s).
[0235] Step S930 may occur as soon as the S-CU becomes aware that the LTM cell switch is commanded to the UE and to which candidate cell (i.e., after steps S900 / S902 / S904). However, this may incur unnecessary network efforts to rescind the derived keys and re-derive keys to be synchronized with the UE, if the UE fails and accesses to a different candidate cell.
[0236] In case of master key update for some candidate cells belonging to the S-CU for subsequent intra-CU serving cell change, the S-CU may derive new key KNG-RAN** for those key-update-required / configured candidate cells belonging to the S-CU.
[0237] FIG. 10 shows an example of an inter-CU serving cell change for inter-CU LTM security master key update procedure to which implementations of the present disclosure are applied.
[0238] The operations of FIG. 10 may follow the operations of FIG. 9. Or, the operations of FIG. 10 may follow the operations of FIG. 8, without performing the operations of FIG. 9.
[0239] In step S1000, the UE may report L1 measurements as configured to the current serving DU (e.g., S-DU).
[0240] In step S1002, the S-DU may decide cell switch and command the UE to handover to a target cell (one of the prepared candidate cells) under a different current (new serving CU). For example, the S-DU may transmit an LTM command to the UE to handover the UE to a target cell B belonging to the C-CU1.
[0241] Upon commanding the UE, in step S1004, the S-DU may notify cell switch to the S-CU. For example, the S-DU may transmit an LTM cell change notification message indicating the target cell B to the S-CU. The notification may be forwarded to the new serving CU and the new serving DU, e.g., C-CU1 and C-DU. The notification may also include selected beam information.
[0242] The new serving CU (e.g., C-CU1) may start using the corresponding KNG-RAN** provided from the current serving CU (e.g., S-CU) in step S930 in FIG. 9.
[0243] In step S1010, theUE may derive new master key (e.g., KNG-RAN**) for the commanded target cell (e.g., target cell B).
[0244] In step S1020, the UE may perform random access procedure and access the commanded target cell (e.g., target cell B).
[0245] In step S1022, the new serving DU (e.g., C-CU) may inform access success to the new serving CU (e.g., C-CU1). For example, the C-DU may transmit an access success message indicating the target cell B to the C-CU1.
[0246] In step S1024, the UE is served under C-CU, e.g., via the target cell B.
[0247] Data exchanges may continue over the new serving cell.
[0248] In step S1026, the new serving CU (e.g., C-CU1) may inform access success to the previous serving CU (e.g., S-CU). For example, the C-CU1 may transmit an LTM success message indicating the target cell B to the S-CU.
[0249] In step S1030, after the cell switch is successfully confirmed, the new serving CU (e.g., C-CU1) now becomes the source. The C-CU1 mayderive new master key (e.g., KNG-RAN***) for the candidate cell(s) to be used for next serving cell change based on the current master key (e.g., KNG-RAN**). The C-CU1 may configure those newly derived keys to other CU(s) for subsequent LTM operations (e.g., via an LTM Configuration Update message). The NCC value that was used for deriving the new master key (e.g., KNG-RAN***) may also be provided to other CU(s).
[0250] Step S1030 may occur as soon as the C-CU1 becomes aware that the LTM cell switch is commanded to the UE and to which candidate cell (i.e., after steps S1000 / S1002 / S1004). However, as described above, this may incur unnecessary network efforts to rescind the derived keys and re-derive keys to be synchronized with the UE, if the UE fails and accesses to a different candidate cell.
[0251] In case of master key update for some candidate cells belonging to the C-CU1 for subsequent intra-CU serving cell change, the C-CU1 may derive new key KNG-RAN*** for those key-update-required / configured candidate cells belonging to the C-CU1.
[0252] Informing LTM success (e.g., step S1026) and configuring newly derived keys for subsequent LTM (e.g., step S1030) to the previous serving CU (e.g., S-CU) may be executed together by a single message.
[0253] In step S1040, after the cell switch is successfully confirmed, the new serving CU (e.g., C-CU1) may execute path switch with the CN. For example, the C-CU1 may transmit a path switch request message to the CN. The new serving CU may indicate that path switch request is due to inter-CU LTM, so that the CN does not provide the new {NH, NCC} pair to be used for next mobility operation of the UE.
[0254] In step S1042, the CN may respond to path switch request of the new serving CU. For example, the CN may transmit a path switch request acknowledge message to the C-CU1.
[0255] For example, the CN may not compute the new {NH, NCC} pair and provide the existing {NH, NCC} pair to the new serving CU instead in the path switch request acknowledge message. Or, the CN may indicate to the new serving CU to ignore the {NH, NCC} pair provided in the path switch request acknowledge message.
[0256] If the new serving CU should use the new fresh {NH, NCC} pair provided by the CN during path switch (and thus has to perform the vertical key derivation for subsequent LTM operation), the key derivation step by the new serving CU (e.g., step S1030) may happen after steps S1040 / S1042. However, such change of {NH, NCC} pair may incur RRC reconfiguration to the UE in the middle of LTM, which is not desired.
[0257] The exemplary operations and / or interaction procedures when the UE fails but re-attempts to access another candidate cell in a different CU (i.e., inter-CU) and in the same CU (i.e., intra-CU) will be described.
[0258] FIGS. 11 and 12 show an example of LTM re-attempt to another CU after failure of cell switch to which implementations of the present disclosure are applied.
[0259] The operations of FIGS. 11 and 12 may follow the operations of FIG. 10. Or, the operations of FIGS. 11 and 12 may follow the operations of FIG. 9, without performing the operations of FIG. 10. Or, the operations of FIGS. 11 and 12 may follow the operations of FIG. 8, without performing the operations of FIG. 9 and / or FIG. 10.
[0260] First, FIG. 11 is described.
[0261] In step S1100, the UE may report L1 measurements as configured to the current serving DU (e.g., C-DU).
[0262] In step S1102, the C-DU may decide cell switch and command the UE to handover to a target cell (one of the prepared candidate cells) under a different CU (new serving CU). For example, the C-DU may transmit an LTM command to the UE to handover the UE to a target cell C belonging to the C-CU2.
[0263] Upon commanding the UE, in step S1104, the C-DU may notify cell switch to the C-CU1. For example, the C-DU may transmit an LTM cell change notification message indicating the target cell C to the C-CU1. The notification may be forwarded via the S-CU or direct delivered to the new serving CU (e.g., C-CU2). The notification may also include selected beam information.
[0264] In step S1110, theUE may derive new master key (e.g., KNG-RAN***) for the commanded target cell (e.g., target cell C).
[0265] In step S1120, the cell switch may fail and the UE may perform cell selection. Another candidate cell under a different CU (new serving CU) may be selected for access. For example, as a result of cell selection, suitable cell A which is candidate cell of LTM and belongs to the S-CU may be selected.
[0266] In step S1130, the UE may revert back to the original configuration with KNG-RAN** and may derive new master key (e.g., KNG-RAN***) for the selected cell for access by cell reselection (e.g., target cell A).
[0267] In step S1132, the new serving CU (e.g., S-CU) may already have received the correct KNG-RAN*** to use with the UE from the previous serving CU (e.g., C-CU1) in step S1030 in FIG. 10.
[0268] FIG. 12 whose operation follows the operation of FIG. 11 is described.
[0269] In step S1200, the UE may perform random access procedure and access the commanded target cell (e.g., target cell A).
[0270] In step S1202, the new serving DU (e.g., S-DU) may inform access success to the new serving CU (e.g., S-CU). For example, the S-DU may transmit an access success message indicating the target cell A to the S-CU.
[0271] In step S1204, the UE is served under S-CU, e.g., via the target cell A.
[0272] Data exchanges may continue over the new serving cell.
[0273] In step S1206, the new serving CU (e.g., S-CU) may inform access success to the previous serving CU (e.g., C-CU1). For example, the S-CU may transmit an LTM success message indicating the target cell A to the C-CU1.
[0274] In step S1210, after the cell switch is successfully confirmed, the new serving CU (e.g., S-CU) now becomes the source. The S-CU mayderive new master key (e.g., KNG-RAN****) for the candidate cell(s) to be used for next serving cell change based on the current master key (e.g., KNG-RAN***). The S-CU may configure those newly derived keys to other CU(s) for subsequent LTM operations (e.g., via an LTM Configuration Update message). The NCC value that was used for deriving the new master key (e.g., KNG-RAN****) may also be provided to other CU(s).
[0275] In case of master key update for some candidate cells belonging to the S-CU for subsequent intra-CU serving cell change, the S-CU may derive new key KNG-RAN**** for those key-update-required / configured candidate cells belonging to the S-CU.
[0276] Informing LTM success (e.g., step S1206) and configuring newly derived keys for subsequent LTM (e.g., step S1210) to the previous serving CU (e.g., C-CU1) may be executed together by a single message.
[0277] In step S1220, after the cell switch is successfully confirmed, the new serving CU (e.g., C-CU1) may execute path switch with the CN. Step S1220 may be performed as same as steps S1040 / S1042 described in FIG. 10.
[0278] FIGS. 13 and 14 show an example of LTM re-attempt to same CU after failure of cell switch to which implementations of the present disclosure are applied.
[0279] The operations of FIGS. 13 and 14 may follow the operations of FIGS. 11 and 12. Or, the operations of FIGS. 13 and 14 may follow the operations of FIG. 10 without performing the operations of FIGS. 11 and 12. Or, the operations of FIGS. 13 and 14 may follow the operations of FIG. 9, without performing the operations of FIG. 10 and / or FIGS. 11 and 12. Or, the operations of FIGS. 13 and 14 may follow the operations of FIG. 8, without performing the operations of FIG. 9 and / or FIG. 10 and / or FIGS. 11 and 12.
[0280] First, FIG. 13 is described.
[0281] In step S1300, the UE may report L1 measurements as configured to the current serving DU (e.g., S-DU).
[0282] In step S1302, the S-DU may decide cell switch and command the UE to handover to a target cell (one of the prepared candidate cells) under the current serving CU (e.g., S-CU). For example, the S-DU may transmit an LTM command to the UE to handover the UE to a target cell D belonging to the S-CU.
[0283] Upon commanding the UE, in step S1304, the S-DU may notify cell switch to the S-CU. For example, the S-DU may transmit an LTM cell change notification message indicating the target cell D to the S-CU.
[0284] If the S-CU configured the UE to update key for the commanded target cell, the S-CU may start using the corresponding KNG-RAN**** if the S-CU has already derived in step S1210 in FIG. 12.
[0285] In step S1310, unless the UE was configured to retain the same key for the commanded target cell, the UE may derive new master key (e.g., KNG-RAN****).
[0286] In step S1312, if the current serving CU previously configured the UE to update key for the commanded target cell, the S-CU may also derive new master key (e.g., KNG-RAN****) to be synchronized with the UE, if the S-CU has not derived it before in step S1210 in FIG. 12.
[0287] In step S1320, the cell switch may fail and the UE may perform cell selection. Another candidate cell under the same serving CU may be selected for access. For example, as a result of cell selection, suitable cell E which is candidate cell of LTM and belongs to the S-CU may be selected.
[0288] In step S1330, the UE may revert back to the original configuration with KNG-RAN***.
[0289] In step S1332, if the UE was also configured to update key for the selected cell for access by cell re-selection, the UE may derive new master key (e.g., KNG-RAN****) for the selected cell (e.g., target cell E).
[0290] FIG. 14 whose operation follows the operation of FIG. 13 is described.
[0291] In step S1400, the UE may perform random access procedure and access the commanded target cell (e.g., target cell E).
[0292] In step S1402, the S-DU may inform access success to the S-CU. For example, S-DU may transmit an access success message indicating the target cell E to the S-CU.
[0293] In step S1404, the S-CU mayknow that the UE accessed a different candidate cell than the cell commanded via step S1302 in FIG. 13. If the S-CU previously configured the UE to update key for the cell the UE accessed, the S-CU may also derive new KNG-RAN**** to be synchronized with the UE, if it has not derived it before in step S1210 in FIG. 12.
[0294] In step S1406, the UE is still served under S-CU, e.g., via the target cell E.
[0295] Data exchanges may continue over the new serving cell.
[0296] In step S1410, after the cell switch is successfully confirmed, the S-CU mayderive new master key (e.g., KNG-RAN*****) for the candidate cell(s) to be used for next serving cell change based on the current master key (e.g., KNG-RAN***) or based on updated master key (e.g., KNG-RAN****). The S-CU may configure those newly derived keys to other CU(s) for subsequent LTM operations (e.g., via an LTM Configuration Update message). The NCC value that was used for deriving the new master key (e.g., KNG-RAN*****) may also be provided to other CU(s).
[0297] Step S1410 may occur as soon as the S-CU becomes aware that the LTM cell switch is commanded to the UE and to which candidate cell (i.e., after steps S1300 / S1302 / S1304 in FIG. 13). In this case, the S-CU may have to rescind the derived keys and re-derive keys to be synchronized with the UE.
[0298] In case of master key update for some candidate cells belonging to the S-CU for subsequent intra-CU serving cell change, the S-CU may derive new key KNG-RAN***** for those key-update-required / configured candidate cells belonging to the S-CU.
[0299] The present disclosure may have various advantageous effects.
[0300] For example, the security master key update can be enabled seamlessly during inter-CU LTM operation.
[0301] Advantageous effects which can be obtained through specific embodiments of the present disclosure are not limited to the advantageous effects listed above. For example, there may be a variety of technical effects that a person having ordinary skill in the related art can understand and / or derive from the present disclosure. Accordingly, the specific effects of the present disclosure are not limited to those explicitly described herein, but may include various effects that may be understood or derived from the technical features of the present disclosure.
[0302] Claims in the present disclosure can be combined in a various way. For instance, technical features in method claims of the present disclosure can be combined to be implemented or performed in an apparatus, and technical features in apparatus claims can be combined to be implemented or performed in a method. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in an apparatus. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in a method. Other implementations are within the scope of the following claims.
Claims
1.A method comprising:receiving, by a second base station, a handover related message from a first base station serving a first cell,wherein the handover related message includes security keys to be used by the second base station and information related to security key update;transmitting, by the second base station, an acknowledgement message to the first base station in response to the handover related message;performing an access with a wireless device based on a cell change from the first cell to a second cell;after the cell change from the first cell to the second cell is completed, deriving new security keys for candidate cells based on a current security and the information related to security key update; andtransmitting the new security keys to other base stations for subsequent mobility.2.The method of claim 1, wherein the information related to security key update includes one or more values assigned for security key update of candidate cells belonging to the first base station.3.The method of claim 1 or 2, wherein the information related to security key update includes a value range for security key update of candidate cells belonging to the second base station.4.The method of claim 3, wherein the value range for security key update of candidate cells belonging to the second base station is not overlapped with one or more value ranges for security key update of candidate cells belonging to the other base stations.5.The method of any claims 1 to 4, wherein the acknowledgement message includes information related to security key update of admitted candidate cells belonging to the second base station.6.The method of claim 5, wherein the information related to security key update of admitted candidate cells belonging to the second base station includes one or more values assigned for security key update of the admitted candidate cells belonging to the second base station.7.The method of any claims 1 to 6, wherein the cell change is based on an inter-centralized unit (CU) L1 / L2 triggered mobility (LTM),wherein the second cell is served by the second base station, andwherein the new security keys are derived and transmitted by the second base station.8.The method of claim 7, wherein the current security correspond to a security key included in the handover related message.9.The method of claim 7 or 8, wherein the new security keys are derived for candidate cells belonging to the second base station and the other base stations.10.The method of any claims 7 to 9, wherein the method further comprises transmitting a path switch request message to a core network, andwherein the path switch request message informs that a path switch is due to the inter-CU LTM.11.The method of claim 10, wherein the method further comprises receiving a path switch request acknowledge message from a core network in response to the path switch request message, andwherein the path switch request acknowledge message does not include a new pair of a next hop (NH) parameter and a NH chaining counter (NCC).12.The method of claim 11, wherein the path switch request acknowledge message includes an existing pair of the NH parameter and the NCC, or informs to ignore an included pair of the NH parameter and the NCC.13.The method of any claims 1 to 6, wherein the cell change is based on an intra-CU LTM,wherein the second cell is served by the first base station, andwherein the new security keys are derived and transmitted by the first base station.14.The method of claim 13, wherein the new security keys are derived for candidate cells belonging to the first base station and the other base stations.15.The method of any claims 1 to 14, wherein an NCC value used for deriving the new security keys is transmitted together with the new security keys to the other base stations.16.The method of any claims 1 to 15, wherein the method further comprises:performing an access with the wireless device based on a cell change from the second cell to a third cell;after the cell change from the second cell to the third cell is completed, deriving second new security keys for candidate cells based on a security related to the third cell; andtransmitting the second new security keys to the other base stations for subsequent mobility.17.The method of claim 16, wherein the third cell is accessed based on cell selection due to a failure of LTM execution.18.The method of claim 16 or 17, wherein the third cell is same as the first cell or the second cell.19.The method of claim 16 or 17, wherein the third cell is different from the first cell or the second cell.20.The method of any claims 1 to 19, wherein the first base station corresponds to a CU belonging to the first base station.21.The method of any claims 1 to 20, wherein the second base station corresponds to a CU belonging to the second base station.22.A second station comprising:at least one transceiver;at least one processor; andat least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method of any claims 1 to 21.
Citation Information
Patent Citations
Mobility features for next generation cellular networks
US20230388871A1
Enabling layer 1 and layer 2 mobility
WO2024031044A1