Terminal device, base station device, and control method for efficiently updating security key
The implementation of security key updating mechanisms in terminal and base station devices addresses the inefficiency of LTM across gNB-CUs, enhancing handover efficiency and security by managing and updating key settings effectively.
Patent Information
- Application Number
- PCT/JP2025/010171
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-29
- Filing Date
- 2025-03-17
- Publication Date
- 2025-10-02
AI Technical Summary
Existing Layer 1/Layer 2 Triggered Mobility (LTM) mechanisms in cellular communication systems do not efficiently update security keys during handovers across different gNB-Central Units (CUs), necessitating a solution for efficient key updates in such scenarios.
A terminal device and base station device implementation that includes receiving, holding, and updating security key settings during handovers using Layer 1/Layer 2 Triggered Mobility, involving a receiving means, holding means, execution means, and update means to efficiently manage and update security keys across gNB-CUs.
Enables efficient updating of security keys during handovers across gNB-CUs, reducing handover time and ensuring secure communication by maintaining and updating key settings for candidate base stations.
Smart Images

Figure JP2025010171_02102025_PF_FP_ABST
Abstract
Description
Terminal device, base station device, and control method for efficiently updating security keys
[0001] The present invention relates to a technique for updating security keys in a cellular communication system.
[0002] In cellular communication standards such as the fifth generation (5G) compliant with the Third Generation Partnership Project (3GPP (registered trademark)), a Layer 1 / Layer 2 Triggered Mobility (LTM) mechanism has been introduced to reduce the time required for handover. Conventional LTM applies to handovers within a common gNB-Central Unit (CU) and does not apply to handovers across gNB-CUs. For this reason, in conventional LTM, parameters related to security keys for encryption and integrity protection do not need to be updated.
[0003] In the future, it is expected that LTM will be applied to handovers across gNB-CUs. In this case, it will be necessary to update parameters related to the security keys as described above.
[0004] The present invention provides an efficient technique for updating parameters related to security keys during handover via LTM.
[0005] A terminal device according to one aspect of the present invention is a terminal device that complies with the cellular communication standard of the Third Generation Partnership Project (3GPP), and has: a receiving means for receiving, from a first base station device to which it is currently connected, first setting information for Layer 1 / Layer 2 Triggered Mobility (LTM) for each of a plurality of base station devices that are candidate handover destinations, including a second base station device and a third base station device, and second setting information associated with the first setting information for updating a security key; a holding means for associating and holding the first setting information and the second setting information for each of the plurality of base station devices; an execution means for executing a handover to the second base station device; and an update means for, in response to a handover to the second base station device, updating the security key using the second setting information associated with the first setting information of the second base station device, and, after the handover is executed, updating the second setting information associated with the first setting information while maintaining the held first setting information for the third base station device.
[0006] A base station device according to one aspect of the present invention is a base station device that complies with the cellular communication standard of the Third Generation Partnership Project (3GPP), and includes: a providing means for providing, to a first other base station device to which a terminal device is connected, as a candidate handover destination, first setting information for Layer 1 / Layer 2 Triggered Mobility (LTM) and second setting information associated with the first setting information for updating a security key; a connecting means for connecting to the terminal device through handover of the terminal device; a generating means for generating a security key to be used in communication with the terminal device using the second setting information; an acquiring means for acquiring, from the base station device after the handover is executed, the first setting information and the second setting information for a second other base station device that is a candidate handover destination of the terminal device; and a transmitting means for, if the terminal device holds the first setting information for the second other base station device, transmitting a message to the terminal device that does not include the first setting information but includes the second setting information for the second other base station device.
[0007] According to the present invention, parameters related to security keys can be updated efficiently during handover by LTM.
[0008] Other features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings, in which the same or similar elements are designated by the same reference numerals.
[0009] The accompanying drawings are incorporated in and constitute a part of the specification, illustrate embodiments of the present invention, and together with the description are used to explain the principles of the present invention. Figure 1 is a diagram showing an example of the configuration of a wireless communication system. Figure 2 is a diagram showing an example of processing related to conventional security key update. Figure 3 is a diagram showing an example of conventional security key update processing. Figure 4 is a diagram showing an example of processing related to security key update in this embodiment. Figure 5 is a diagram showing an example of processing related to security key update in this embodiment. Figure 6 is a diagram showing an example of the hardware configuration of a base station device and a terminal device. Figure 7 is a diagram showing an example of the functional configuration of a terminal device. Figure 8 is a diagram showing an example of the functional configuration of a base station device.
[0010] Hereinafter, the embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all combinations of features described in the embodiments are necessarily essential to the invention. Two or more of the features described in the embodiments may be combined in any desired manner. Furthermore, the same reference numerals are used to designate identical or similar components, and redundant descriptions will be omitted.
[0011] Fig. 1 shows an example of the configuration of a wireless communication system according to this embodiment. This wireless communication system is a cellular communication system conforming to the cellular communication standard of the Third Generation Partnership Project (3GPP (registered trademark)), and is configured to include base station devices (e.g., base station device 101, base station device 102) and terminal devices (e.g., terminal device 111). It is assumed that the terminal device 111 is currently connected to the base station device 101, and then moves toward the base station device 102 and executes handover to the base station device 102. It is to be noted that, for the sake of simplicity, Fig. 1 shows only two base station devices and one terminal device, but it goes without saying that a large number of these devices may exist.
[0012] In such a wireless communication system, when the terminal device 111 performs handover, the processing flow related to the security key may differ depending on whether the base station device 101 and the base station device 102 are associated with a common Access and Mobility Management Function (AMF) (or whether an Xn interface is established). This difference in procedure will be explained using the examples of Figures 2 and 3. Note that Figures 2 and 3 explain in detail the parts particularly related to this embodiment, and only provide an overview of other matters.
[0013] 2 shows an example of a processing flow in the case where a base station device (base station device 101) from which a handover is initiated and a base station device (base station device 102) to which the handover is initiated are associated with a common AMF and an Xn interface is established between these base station devices. In this processing, for example, when the conditions for initiating a handover are met in the terminal device 111, the terminal device 111 notifies the base station device 101 of a measurement report (S201). When the base station device 101 determines to hand over the terminal device 111 to the base station device 102 based on this measurement report, it notifies the base station device 101 of a parameter K NG-RAN * Based on parameters such as nextHopChainingCount (NCC), the K NG-RAN * (S202). Then, the base station device 101 transmits a HANDOVER REQUEST message to the base station device 102 (S203). At this time, the HANDOVER REQUEST message contains the derived K NG-RAN *The RRC Reconfiguration message includes the NCC value and the NCC value used to derive that value. As in a normal handover, processing such as notification from the base station device 101 to the terminal device 111 of setting information for connection with the handover destination base station device 102 is performed between the terminal device 111 and the base station device 101 (not shown). Then, the terminal device 111 executes a random access procedure with the base station device 102 and establishes connection with the base station device 102. At this time, the base station device 102 sets keySetChangeIndicator to False and transmits an RRC Reconfiguration message including the NCC value to the terminal device 111 (S204). RRC stands for Radio Resource Control. As a result, the terminal device 111 can reconfigure the NCC value and the KC value used to generate the security key for communication with the base station device 101, which is held within the terminal device. NG-RAN * The K used to generate a security key for communication with the base station device 102 is calculated using parameters such as NG-RAN * In response to this, the terminal device 111 transmits an RRC Reconfiguration Complete message to the base station device 102 (S205). Then, the base station device 102 transmits an NGAP PATH SWITCH REQUEST message to the AMF associated with the base station device 102 (S206). In response to this message, the AMF transmits an NGAP PATH SWITCH REQUEST ACKNOWLEDGE message to the base station device 102 (S207). This message includes the K NG-RAN * Next Hop (NH) and NCC are included as parameters for enabling the base station device 102 to derive the NH and NCC. The base station device 102 stores the received NH and NCC (S208). In this way, when the base station device 101 and the base station device 102 are associated with a common AMF, the terminal device 111 uses the NCC value acquired from the base station device 102 and the stored KNG-RAN * and K for generating a security key to be used in communication with the base station device 102. NG-RAN * can be updated.
[0014] 3 shows an example of a processing flow when a handover source base station device (base station device 101) and a handover destination base station device (base station device 102) are associated with different AMFs. In this processing, similar to the example of FIG. 2, a measurement report is transmitted from the terminal device 111 to the base station device 101 (S301), and handover processing is initiated based on the measurement report. The base station device 101 transmits an NGAP HANDOVER REQUIRED message to the AMF with which the base station device 101 is associated, and the handover request is forwarded to another AMF with which the handover destination base station device 102 is associated (S302). Then, the handover destination AMF transmits an NGAP HANDOVER REQUEST message to the handover destination base station device 102 (S303). Note that this message includes the K NG-RAN * The information for newly generating the K includes the NAS container, NH, and NCC. Note that NAS is an abbreviation for Non-Access Stratum. The base station device 102 stores the received NH and NCC (S304), and generates the K based on the received information. NG-RAN * In other words, in the process of FIG. NG-RAN * is newly generated and the K used before the handover is NG-RAN * is not used to generate a new key. After that, the base station device 102 transmits an NGAP HANDOVER REQUEST ACKNOWLEDGE to the AMF (S306), and in response, an NGAP HANDOVER COMMAND is transmitted to the base station device 101 via the handover source AMF (S307). At this time, K NG-RAN *The information that enables the derivation of the RRC Reconfiguration message is transmitted to the terminal device 111 via the base station device 101 (S308). After that, the terminal device 111 executes a random access procedure or the like with the base station device 102 to complete the connection (S309).
[0015] In addition, the same K NG-RAN * is generated, and the K NG-RAN * , and a key K for concealing user data is obtained. UPsec is generated.
[0016] Here, the terminal device 111 according to this embodiment changes the base station device to which it is connected using Layer 1 / Layer 2 Triggered Mobility (LTM) to shorten the time required for handover. Note that LTM may be interpreted as an abbreviation for Lower Layer Triggered Mobility. Conventionally, LTM has only been applied to handovers between base station devices connected to a common gNB-Central Unit (CU). For this reason, in handovers using conventional LTM, setting information (parameters) related to security keys are not updated. In contrast, in handovers across gNB-CUs, setting information related to security keys needs to be updated. In this embodiment, a procedure is provided for efficiently updating setting information (parameters) for generating security keys in handovers using LTM across gNB-CUs.
[0017] 4 is a diagram showing an example of a handover procedure across gNB-CU according to this embodiment. FIG. 4 shows an example in which there are two candidate base station devices for the handover destination. These candidate base station devices for the handover destination are assumed to be associated with an AMF different from the connection destination base station device. For this reason, although the AMF is omitted in the example of FIG. 4, each base station device is assumed to perform processing involving communication with the AMF as in FIG. 2 or FIG. 3.
[0018] In this process, a base station device (connected to a terminal device) that is a handover source transmits a HANDOVER REQUEST message to multiple other base station devices that are candidates for handover destinations, for example, based on measurement results by the terminal device (S401). The candidate base station devices then respond to the message by returning HANDOVER REQUEST ACK messages (S402, S403). This HANDOVER REQUEST ACK message includes setting information for LTM (LTM configuration), which includes MasterKeyUpdate, information for updating the security key. This is just an example, and the LTM configuration may not include MasterKeyUpdate, and each may be notified and managed as separate information. However, the LTM configuration and MasterKeyUpdate are assumed to be associated with each other. Here, MasterKeyUpdate includes, for example, a KeySetChangeIndicator (set to True), a NAS container, and an NCC when the associated AMF is changed. Furthermore, when the associated AMF is not changed, MasterKeyUpdate includes a KeySetChangeIndicator (set to False) and an NCC. The handover source base station device transfers the LTM configuration including the MasterKeyUpdate to the terminal device (S404). Then, when the terminal device receives the information, it transmits a response message to the handover source (connected) base station device (S405). Note that the transfer of the LTM configuration in S404 can be performed using, for example, an RRC Reconfiguration message, and a response to that message can be performed using an RRC Reconfiguration Complete message.
[0019] Thereafter, based on the measurement results (L1 measurement) of Layer 1 (physical layer) measured by the terminal device, the base station device to which the terminal device is connected decides to execute a handover, and the base station device transmits a Cell Switch Command instructing the terminal device to execute the handover (S406, S407). The terminal device executes a random access procedure or the like with the base station device of the handover destination instructed by the command (S408, S409), and establishes a connection with the base station device using the LTM configuration for that base station device. At this time, the terminal device also uses the MasterKeyUpdate information included in the LTM configuration to update the K NG-RAN * For example, when the terminal device receives a MasterKeyUpdate message containing KeySetChangeIndicator (set to True), NAS container, and NCC, it updates the K NG-RAN * Regardless of the received information, a new K NG-RAN * In addition, when the terminal device receives a MasterKeyUpdate containing a KeySetChangeIndicator (set to False) and an NCC, it generates the K NG-RAN * and NCC to be used after handover. NG-RAN * Generate.
[0020] Here, a method for updating setting information related to a security key after handover will be described. First, after connection with a base station device of a handover destination, if the base station device and a candidate base station device of a handover destination from the base station device are associated with a common AMF, that is, if the base station device of the handover destination (the base station device that will be the base station device in communication after handover) is associated with a K NG-RAN *When the handover destination base station device receives the RRC Reconfiguration Complete message from the terminal device, it transmits a HANDOVER SUCCESS message indicating that the handover has been successful to the handover source base station device (S410). At this time, the HANDOVER SUCCESS message contains the K held by the handover destination base station device. NG-RAN * and NCC (i.e., K generated based on MasterKeyUpdate included in the LTM configuration of the device itself) NG-RAN * The handover source base station notifies another candidate base station (candidate base station #2 in the example of FIG. 4) that the base station to which the terminal device is connected has been changed (in the example of FIG. 4, the connection destination has been changed to candidate base station #1). At this time, the handover source base station notifies the other candidate base station (candidate base station #2 in the example of FIG. 4) that the base station to which the terminal device is connected has been changed (in the example of FIG. 4, the connection destination has been changed to candidate base station #1). NG-RAN * The candidate base station transmits the information of the MasterKeyUpdate and NCC to the other candidate base station and requests that the LTM configuration including the updated MasterKeyUpdate be transferred to the target base station (S411). In response to the request, the candidate base station updates the MasterKeyUpdate and transmits the LTM configuration including the information of the MasterKeyUpdate to the target base station (S412).
[0021] Next, after connection with the handover destination base station device, if the candidate base station device of the handover destination from that base station device is associated with a different AMF, that is, if the candidate base station device after the handover (the base station device that will continue to be the candidate base station device after the handover) is K NG-RAN *When the handover destination base station device receives the RRC Reconfiguration Complete message from the terminal device, it transmits a HANDOVER SUCCESS message indicating that the handover has been successful to the handover source base station device (S410). At this time, the HANDOVER SUCCESS message contains the K held by the handover destination base station device. NG-RAN * The handover source base station device notifies the candidate base station device that the terminal device is connected to that has been changed (in the example of FIG. 4, the connection destination has been changed to candidate base station device #1) via the first AMF associated with the handover source base station device and the second AMF associated with the base station device that was not selected as the handover destination and will remain a candidate base station device after the handover. At this time, the second AMF associated with the candidate base station device notifies the candidate base station device that the handover source base station device is connected to that candidate base station device via the first AMF associated with the handover source base station device and the second AMF associated with the base station device that was not selected as the handover destination and will remain a candidate base station device after the handover. NG-RAN * The candidate base station device then notifies the candidate base station device of the NAS container, NH, and NCC as information for newly generating the MasterKeyUpdate. The candidate base station device then updates the MasterKeyUpdate using the NAS container, NH, and NCC, and transmits the LTM configuration including the MasterKeyUpdate information to the handover destination base station device via the second AMF with which the candidate base station device is associated and the third AMF with which the handover destination base station device (candidate base station device #1 in the example of FIG. 4) is associated.
[0022] Note that the candidate base station device determines, for example, whether it is connected to a common AMF with the handover destination base station device (an Xn interface is established) and determines the content of the MasterKeyUpdate. For example, if the candidate base station device is associated with a common AMF with the handover destination base station device, it can generate a MasterKeyUpdate that includes a keySetChangeIndicator set to False and the notified NCC. Furthermore, if the candidate base station device is associated with an AMF different from that of the handover destination base station device, it can acquire the NAS container, NH, and NCC by, for example, querying the AMF with which it is associated, and generate a MasterKeyUpdate that includes a keySetChangeIndicator, NAS container, and NCC that are set to True. The candidate base station then transmits the generated MasterKeyUpdate to the handover destination base station.
[0023] When the handover destination base station (candidate base station #1 in the example of FIG. 4) receives the MasterKeyUpdate update information from the candidate base station, it transmits the received MasterKeyUpdate information to the terminal device in a format in which it associates it with the LTM configuration of the candidate base station (S413). When the terminal device receives the MasterKeyUpdate, it updates the MasterKeyUpdate information included in the LTM configuration of the candidate base station (candidate base station #2 in the example of FIG. 4) with the received information. Then, after completing the MasterKeyUpdate update, the terminal device transmits a response message to the handover destination base station (S414). In one example, an RRC Reconfiguration message is used when transmitting information in S413, and the terminal device can transmit an RRC Reconfiguration Complete to the handover destination base station device as a response message in S414. However, this is just an example, and other messages may be used.
[0024] In this processing example, the terminal device receives parameters (MasterKeyUpdate) related to security keys as part of the LTM configuration. Then, when the terminal device performs a handover using LTM, it can reuse the LTM configuration of a candidate base station that was not selected as the handover destination. However, considering that the setting information related to security keys in the LTM configuration should be updated, the terminal device can acquire this setting information via the handover destination base station. This allows the terminal device to efficiently update the setting information related to security keys for candidate base stations that should still be treated as handover destination candidates after the handover, while maintaining most of the LTM configuration.
[0025] While FIG. 4 illustrates an example in which one candidate base station device is not selected by handover, it is naturally assumed that there are multiple such candidate base station devices. In this case, when the handover destination base station device notifies the configuration information (MasterKeyUpdate) related to the security key, information indicating which candidate base station device the configuration information relates to is also notified. For example, if identification information (LTM configuration ID) is assigned to each LTM configuration configured in the terminal device, the configuration information related to the security key may be associated with the identification information and notified. In one example, if the MasterKeyUpdate of only some candidate base station devices is updated, the LTM configuration ID of that candidate base station device and the MasterKeyUpdate of that candidate base station device are associated and notified to the terminal device. Note that the identification information of the base station device may be associated with the configuration information related to the security key and notified. That is, any identification information may be used as long as it is possible to identify the setting information related to the security key to be updated. Furthermore, when the setting information related to all candidate base station devices is notified, the setting information may be arranged and notified in a predetermined order, such as ascending or descending order of the LTM configuration ID. In this case, since it is possible to identify which candidate base station device (LTM configuration ID) the setting information relates to based on the order in which the setting information is notified, there is no need to explicitly notify the identification information.
[0026] Note that, although the above description describes processing related to a master cell group (MCG), similar processing may also be performed for a secondary cell group (SCG). That is, for a base station device that provides a candidate cell for a secondary cell, information on a parameter SK-Counter related to a security key for the SCG may be included in the LTM configuration and notified to a terminal device. Then, after a connection destination cell is changed by a Cell Switch Command, updated information related to the SK-Counter in the LTM configuration may be notified to the terminal device from the base station device that provides the connection destination cell after the change. Furthermore, the LTM configuration may include both a MasterKeyUpdate for the MCG and an SK-Counter for the SCG. In this case, after executing a handover using the LTM configuration, the terminal device and the base station device will communicate using Dual Connectivity using both the master cell and the secondary cell, but MasterKeyUpdate is used to generate a security key for the master cell, and SK-Counter is used to generate a security key for the secondary cell. Also, after executing the handover, if there is an LTM configuration that was not selected, and that LTM configuration includes both MasterKeyUpdate for the MCG and SK-Counter for the SCG, update information for both MasterKeyUpdate and SK-Counter is notified to the terminal device after the handover.
[0027] 4 shows an example in which a handover source base station transmits a message to a candidate base station that was not selected as the handover destination, requesting that the candidate base station transmit the LTM configuration to the target base station. However, this is just one example, and the target base station may request the candidate base station to transmit the LTM configuration. An example of the processing flow in this case is shown in FIG. 5. In the example of FIG. 5, the same processes as those in FIG. 4 are assigned the same reference numerals, and their description will be omitted.
[0028] In this process, when the handover source base station receives a HANDOVER SUCCESS message from the handover destination base station, it transfers the LTM configuration of the candidate base station not selected as the handover destination, which was received in S403, to the handover destination base station (S501). Note that this transfer of the LTM configuration can be performed by a HANDOVER SUCCESS ACK message, which is a response to the HANDOVER SUCCESS message. However, this is just one example, and the LTM configuration may be transferred by another message. The handover destination base station then requests setting information for updating the security key from the candidate base station not selected as the handover destination, which corresponds to the received LTM configuration (S502). The handover destination base station device can request a MasterKeyUpdate using, for example, a HANDOVER REQUEST message. Note that this message includes the K key used in the handover destination base station device. NG-RAN *, and may include information about the NCC held by the base station device. The message may also include information indicating that the LTM configuration corresponding to the configuration information for updating the security key to be acquired has already been notified to the terminal device (by the handover source base station device). The candidate base station device recognizes that the configuration information for the security key needs to be updated for the LTM configuration previously notified to the handover source base station device, performs the update, and transmits the updated configuration information to the handover destination base station device (S503). At this time, information included in the LTM configuration other than MasterKeyUpdate does not need to be transmitted to the handover destination base station device. The candidate base station device may transmit the updated configuration information to the handover destination base station device using, for example, a HANDOVER REQUEST ACK message. When the base station device of the handover destination acquires the MasterKeyUpdate, it transfers the information to the terminal device (S413).
[0029] In this way, in the process of Fig. 5, the terminal device can be notified of updated setting information related to the security key, as in the case of Fig. 4. In the above-described embodiment, when the base station device of the handover destination and the candidate base station device after the handover are associated with a common AMF, that is, when the base station device of the handover destination (the base station device that will be the communicating base station device after the handover) is associated with the K NG-RAN * The process for generating K has been described. However, if a candidate base station device after handover (a base station device that continues to be a candidate base station device after handover) is K NG-RAN *may be generated. That is, the handover destination base station device and the candidate base station device after handover may be associated with different AMFs. In this case, the handover destination base station device notifies the candidate base station device (candidate base station device #2 in the example of FIG. 5) that the base station device to which the terminal device is connected has been changed (in the example of FIG. 5, the connection destination has been changed to candidate base station device #1) via the first AMF associated with that base station device and the second AMF associated with the candidate base station device that will continue to be a candidate for handover. At this time, the second AMF NG-RAN * The candidate base station device notifies the candidate base station device of the NAS container, NH, and NCC as information for newly generating the MasterKeyUpdate. Thereafter, the candidate base station device (candidate base station device #2 in the example of FIG. 5) updates the MasterKeyUpdate using the NAS container, NH, and NCC, and transmits the MasterKeyUpdate information or the LTM configuration including the MasterKeyUpdate information to the handover destination base station device (candidate base station device #1 in the example of FIG. 5) via the second AMF and the first AMF. Then, upon acquiring the MasterKeyUpdate, the handover destination base station device transfers the information to the terminal device (S413).
[0030] In the above-described embodiment, an example has been described in which the LTM configuration is transmitted including configuration information (MasterKeyUpdate) for updating a security key, but this is not limited to this. For example, the LTM configuration may not include the configuration information, and the Cell Switch Command of S407 may include the configuration information. For example, when the handover source base station device and the handover destination base station device are associated with a common AMF, as shown in S204 of FIG. 2, the NAS container may not be notified to the terminal device, and NCC information may be notified to the terminal device. In such a case, the handover source base station device may transmit the LTM configuration without including the configuration information, and transmit the Cell Switch Command including the configuration information (NCC). In this case, the keySetChangeIndicator may be omitted. Furthermore, when a handover is performed by a Cell Switch Command, the LTM configuration ID or information that can identify the LTM configuration ID is included in the Cell Switch Command. The terminal device identifies the base station device of the handover destination using the LTM configuration ID or information that can identify the LTM configuration ID. For communication with the base station device of the handover destination, the terminal device uses the NCC included in the Cell Switch Command to perform K NG-RAN *is updated. Note that the Cell Switch Command may include the NCC value itself, or other information capable of identifying the NCC. For example, identification information may be assigned in advance to each of multiple NCCs by the LTM configuration, and the identification information may be included in the Cell Switch Command. According to this, identification information for identifying the NCC is transmitted in the LTM configuration notified by RRC layer signaling in an environment where encryption and the like are performed, and only the identification information is transmitted by the Cell Switch Command where encryption and the like are not performed, so that even if the Cell Switch Command is intercepted, the NCC can be prevented from being identified by an interceptor.
[0031] Note that, for some candidate base station devices, the LTM configuration may include setting information for updating the security key as described above, and for other candidate base station devices, the LTM configuration may not include setting information for updating the security key, and the setting information may be notified by a Cell Switch Command. Furthermore, even if the LTM configuration includes setting information for updating the security key, (at least a part of) the setting information may be transmitted by a Cell Switch Command. In this case, the setting information included in the LTM configuration may be updated and used by the setting information specified by the Cell Switch Command. In one example, a first base station device, which is a handover source, and a second base station device, which is a handover destination, are associated with different AMFs, and the second base station device and a third base station device, which is a candidate not selected as the handover destination, are associated with a common AMF. In this case, before handover from the first base station device to the second base station device, as described above, MasterKeyUpdate is associated with the LTM configuration for the second base station device and the third base station device and notified to the terminal device. In this case, MasterKeyUpdate includes a keySetChangeIndicator set to True, a NAS container, and an NSS. After that, when handover from the first base station device to the second base station device is performed, the MasterKeyUpdate of the third base station device becomes outdated and needs to be updated. On the other hand, when a handover is performed from the second base station to the third base station, information such as the NAS container is not required for updating the security key, and only information about the NCC is required. Therefore, after a handover is performed from the first base station to the second base station, the notification of the MasterKeyUpdate for the third base station may be omitted, and information that can identify the NCC may be notified by a subsequent Cell Switch Command.According to this, the terminal device continues to hold old information about the third base station device, but can identify the NCC using the Cell Switch Command and can use that NCC to update the security key without using the old information.
[0032] In addition, when the LTM configuration includes only the setting information of the SCG, when a secondary cell corresponding to that LTM configuration is added, the security key for the MCG does not need to be updated, and only the security key for the secondary cell needs to be generated / updated. In this case, the setting information (SK-Counter) related to the security key for the secondary cell may be updated using a procedure different from the above-described process.
[0033] For example, the base station device may include a list of configuration information (SK-Counter) related to the security key of the SCG for each base station device that provides a candidate cell for the MCG in the LTM configuration (using an RRC Reconfiguration message) and transmit the list to the connected terminal device. For example, a separate SK-Counter list is configured for each of candidate base station device #1 and candidate base station device #2 in FIG. 4 or 5, and the list is transmitted to the terminal device. The terminal device also holds this SK-Counter list for connected base station devices that provide MCG cells. For example, the terminal device may hold SK-Counter A1, SK-Counter A2, ..., SK-Counter A16 for the currently connected base station device, and may hold SK-Counter B1, SK-Counter B2, ..., SK-Counter B16 for candidate base station device #1. That is, a separate SK-Counter list is defined for each candidate base station device that can provide an MCG cell. Then, when the terminal device receives a Cell Switch Command indicating the addition of a secondary cell while communicating with the currently connected base station device, it generates a security key for that secondary cell using the SK-Counter A1 at the top of the list. Thereafter, when the terminal device receives a Cell Switch Command instructing that another cell be designated as a secondary cell while communicating with the connected base station device, the terminal device updates the security key for the changed secondary cell using SK-Counter A2. At this time, the terminal device deletes SK-Counter A1, which had been used until then, from the list. In this way, when the SCG is changed without changing the MCG, the terminal device can update the security key for the SCG sequentially using the SK-Counters included in the list notified in advance. In other words, a list of SK-Counters can be provided in common for each MCG for multiple SCG candidates that can be set together with that MCG.Therefore, as long as there is no change in the MCG, the terminal device can repeatedly update the security key for the SCG using the SK-Counter included in the list each time the SCG is changed. Therefore, there is no need to make an inquiry to the base station device (which provides SCG candidates) as shown in Figures 4 and 5 each time the SCG is changed.
[0034] Thereafter, the terminal device receives a Cell Switch Command instructing a change of MCG (handover) and is assumed to have handed over to candidate base station device #1. Then, when the terminal device receives a Cell Switch Command instructing the addition of an SCG, it generates a security key for that SCG using the SK-Counter B1 at the top of the list associated with candidate base station device #1. Then, the terminal device deletes the SK-Counter A2 that was previously used from the list. In this way, by separately setting a list of SK-Counters for each MCG, it is possible to efficiently generate a security key for the secondary cell after handover.
[0035] A base station device currently connected to a terminal device may instruct the terminal device to delete part or all of the configured SK-Counter list. This instruction may be transmitted from the base station device to the terminal device, for example, using an RRC Reconfiguration message. The list may be deleted by an explicit instruction from the base station device, or may be deleted without an instruction from the base station device when a predetermined condition is met. For example, a list associated with the MCG of the handover source held in the terminal device may be deleted on the condition that the MCG has been changed by a Cell Switch Command or a conventional handover. If the MCG of the handover source is treated as a candidate for the handover destination after the handover, it is assumed that the LTM configuration for the MCG and the SCG corresponding to that MCG will not be deleted. In this case, the list may not be deleted either. Furthermore, a list configured for candidates for MCGs not selected as the handover destination of the terminal device may be deleted on the condition that the MCG has been changed. In this case, too, whether or not the list is deleted may be determined depending on whether or not the LTM configuration is maintained. For example, a list set for an MCG candidate that is excluded from the handover destination candidates may be deleted together with the LTM configuration, and lists set for other MCG candidates may not be deleted. Also, whether or not the list is deleted may be determined depending on the base station device of the handover destination. In this case, setting information for this determination may be notified to the terminal device in advance. Also, the base station device may notify the terminal device of information specifying criteria for deleting the list, and the terminal device may delete the list according to the criteria.
[0036] In the above example, the handling of the LTM configuration when the terminal device receives the LTM configuration from the base station device to which it is currently connected and then performs a handover has been described. This process also applies to the LTM configuration maintained before the handover. That is, the terminal device receives setting information for updating the LTM configuration and security keys from the base station device that was connected before the currently connected base station device. Then, by handing over to the currently connected base station device, the terminal device can update the portion of the setting information for updating the security keys while maintaining the LTM configuration for the candidate base station device that was not selected as the handover destination. Thereafter, when the terminal device performs another handover, it can perform the above process. That is, the terminal device can maintain the LTM configuration that it has received and stored from a base station device to which it is not currently connected, and can update only the setting information for updating the security key that is included in the LTM configuration or that is stored in association with that information.
[0037] FIG. 6 shows an example of the hardware configuration of a base station device and a terminal device according to this embodiment. In one example, the base station device and the terminal device include a processor 601, a ROM 602, a RAM 603, a storage device 604, and a communication circuit 605. The processor 601 is a computer including one or more processing circuits, such as a general-purpose CPU (Central Processing Unit) or an ASIC (Application Specific Integrated Circuit), and executes programs stored in the ROM 602 and the storage device 604 to control the entire device and each of the above-mentioned processes. The ROM 602 is a read-only memory that stores information such as programs and various parameters related to the processes executed by the base station device and the terminal device. The RAM 603 functions as a workspace when the processor 601 executes the program and is a random access memory that stores temporary information. The storage device 604 is, for example, a removable external storage device. The communication circuit 605 is, for example, a circuit for wireless communication of 5G or its successor standards. Although FIG. 6 illustrates one communication circuit 605, the base station apparatus and the terminal apparatus may have multiple communication circuits. For example, the base station apparatus and the terminal apparatus may have wireless communication circuits for 5G and its successor standard, and a common antenna for these circuits. The base station apparatus and the terminal apparatus may have separate antennas suitable for each standard. The base station apparatus may also have a wired communication circuit used when communicating with other base station apparatuses or core network nodes. The terminal apparatus may also have a communication circuit conforming to a wireless communication standard other than the cellular communication standard, such as a wireless local area network (LAN) or Bluetooth (registered trademark). The base station apparatus and the terminal apparatus may have separate communication circuits 605 for each of multiple available frequency bands, or may have a common communication circuit 605 for at least some of these frequency bands.
[0038] FIG. 7 shows an example of the functional configuration of a terminal device. The terminal device includes, for example, a setting information receiving unit 701, an LTM setting storage unit 702, a key information management unit 703, a key generation unit 704, and a communication unit 705. Note that FIG. 7 only shows functions particularly related to this embodiment, and various other functions that the terminal device may have are omitted from the illustration. For example, the terminal device naturally has other functions that terminal devices compliant with 5G or subsequent standards generally have. The functional blocks in FIG. 7 are shown only schematically, and the respective functional blocks may be realized by being integrated or further subdivided. Furthermore, each function in FIG. 7 may be realized, for example, by the processor 601 executing a program stored in the ROM 602 or the storage device 604, or by a processor within the communication circuit 605 executing predetermined software. Since the details of the processing performed by each functional unit are as described above, only the general functions of the terminal device will be outlined here.
[0039] The setting information receiving unit 701 receives various setting information from the currently connected base station device. The setting information receiving unit 701 receives, for example, pre-setting information for LTM for a candidate base station device that is the handover destination. Note that the pre-setting information is, for example, setting information for establishing an RRC layer connection with a candidate base station device, and is setting information that is notified to a terminal device when a handover has not actually been performed. The pre-setting information corresponds to the above-mentioned LTM configuration. The setting information receiving unit 701 also receives setting information for generating and updating security keys (e.g., MasterKeyUpdate and SK-Counter). The LTM setting holding unit 702 holds the LTM pre-setting information received by the setting information receiving unit 701. Note that the LTM setting holding unit 702 is configured, for example, to be able to continue to hold pre-setting information (LTM configuration) for a candidate base station device that was not selected as the handover destination after a handover has been performed. The LTM setting holding unit 702 may delete the stored preset information in response to, for example, an instruction from a handover source base station or a handover destination base station. The LTM setting holding unit 702 may also set an expiration date for the preset information and delete the preset information upon expiration of the expiration date. In this case, the expiration date may be notified by the base station currently connected when the preset information was received.
[0040] The key information management unit 703 maintains and manages configuration information, such as security keys or parameters for generating the security keys, for each of the currently connected base station and the candidate base station for handover. The key information management unit 703 manages security key configuration information received, for example, from the currently connected base station along with the LTM configuration, and manages the configuration information so that it is up to date. For example, when the key information management unit 703 receives configuration information (MasterKeyUpdate) for at least some of the candidate base stations not selected as the handover destination from the target base station, the key information management unit 703 replaces the configuration information it holds with the received configuration information. The key information management unit 703 may also obtain configuration information for generating security keys via a Cell Switch Command. This allows the key information management unit 703 to maintain the security key configuration information in an up-to-date state. Furthermore, the key information management unit 703 may hold, for each MCG, a list of SK-Counters for SCGs that can be used as secondary cells when that MCG is used, and may extract SK-Counter values from the list in order each time a connected SCG is changed or added, and generate a security key for that SCG. Furthermore, when an SCG is changed or deleted, the key information management unit 703 may delete from the list the SK-Counter value that was used to generate a security key for the SCG that is no longer in use.
[0041] The key generation unit 704 generates a security key using the setting information (MasterKeyUpdate, SK-Counter) maintained and managed by the key information management unit 703. The communication unit 705 uses the security key generated by the key generation unit 704 to communicate with the destination base station device.
[0042] FIG. 8 shows an example of the functional configuration of a base station device. The base station device includes, for example, a setting information acquisition unit 801, a setting information provision unit 802, a setting information notification unit 803, a key generation unit 804, and a communication unit 805. Note that FIG. 8 only shows functions particularly related to this embodiment, and various other functions that the base station device may have are omitted from the illustration. For example, the base station device naturally has other functions that base station devices compliant with 5G and subsequent standards generally have. The functional blocks in FIG. 8 are shown schematically, and the respective functional blocks may be realized by being integrated or may be further subdivided. Furthermore, each function in FIG. 8 may be realized, for example, by the processor 601 executing a program stored in the ROM 602 or the storage device 604, or by a processor residing within the communication circuit 605 executing predetermined software. Since the details of the processing performed by each functional unit are as described above, only the general functions of the base station device will be outlined here.
[0043] The setting information acquisition unit 801 acquires setting information from another base station device. For example, while connected to a terminal device, the setting information acquisition unit 801 acquires an LTM configuration for LTM to another base station device and setting information (MasterKeyUpdate and SK-Counter) for generating or updating a security key in communication with the other base station device. Note that the setting information acquisition unit 801 may, for example, transmit a request message (e.g., HANDOVER REQUEST) to a base station device that is a candidate for a handover destination from the terminal device itself to acquire the LTM configuration and setting information for generating or updating a security key. Furthermore, for example, when a terminal device connects to the terminal device after handing over from another base station device, the setting information acquisition unit 801 acquires setting information for generating or updating an LTM configuration and a security key for the base station device that is a candidate for a handover destination from the terminal device itself. Here, the setting information related to the LTM configuration and the security key may be acquired from the candidate base station device as the handover destination in response to a transfer request for the setting information related to the LTM configuration and the security key from the handover source base station device to the candidate base station device as the handover destination. Alternatively, the LTM configuration may be received from the handover source base station device, and the setting information related to the security key may be received from the candidate base station device as the handover destination. The setting information providing unit 802 provides the setting information related to the LTM configuration and the security key to another base station device. In other words, the information provided by the setting information providing unit 802 of the first base station device is acquired by the setting information acquiring unit 801 of the second base station device.
[0044] The setting information notification unit 803 notifies the connected terminal device of the acquired setting information. For example, for a base station device for which an LTM configuration is not held in the terminal device, the setting information notification unit 803 notifies both the LTM configuration and setting information related to the security key. On the other hand, for a base station device for which an LTM configuration is held in the terminal device, the setting information notification unit 803 can notify only setting information related to the security key without notifying the LTM configuration. For example, during handover, the setting information notification unit 803 may receive an RRC Reconfiguration Complete message from the terminal device during handover processing, and after a connection is established, transmit setting information related to the security key (and the LTM configuration) by an RRC Reconfiguration message. Furthermore, the setting information notification unit 803 may transmit a Cell Switch Command including setting information (NCC) related to the security key of the handover destination base station device. In this case, the setting information notification unit 803 may hold the setting information previously acquired by the setting information acquisition unit 801 until the timing of handover, and may notify the terminal device of the setting information when handover is performed.
[0045] The key generation unit 804 stores, for example, configuration information (such as MasterKeyUpdate) for generating a security key for communication with a terminal device, and generates a security key using the information when the terminal device is connected by handover. The key generation unit 804 also updates the configuration information in response to a request from another base station device (for example, a first other base station device or a second other base station device when the terminal device hands over from a first other base station device to a second other base station device) or an AMF, and stores the updated configuration information. The updated configuration information can be provided to the other base station device by the configuration information providing unit 802 and notified to the terminal device from the other base station device. The communication unit 805 establishes a connection with the terminal device and communicates using the security key generated by the key generation unit 804.
[0046] As described above, in this embodiment, security keys can be efficiently shared and updated between a terminal device and a network (base station device) that perform handover using LTM, which makes it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "build resilient infrastructure, promote sustainable industrialization, and foster innovation."
[0047] The invention is not limited to the above-described embodiment, and various modifications and variations are possible within the scope of the gist of the invention.
[0048] This application claims priority based on Japanese Patent Application No. 2024-056621, filed March 29, 2024, the entire contents of which are incorporated herein by reference.
Claims
1. A terminal device conforming to the cellular communication standard of the Third Generation Partnership Project (3GPP), comprising: a receiving means for receiving, from a connected first base station device, first setting information for Layer 1 / Layer 2 Triggered Mobility (LTM) for each of a plurality of base station devices that are candidate handover destinations, including a second base station device and a third base station device, and second setting information associated with the first setting information for updating a security key; a holding means for holding, in association with each other, the first setting information and the second setting information for each of the plurality of base station devices; an executing means for executing a handover to the second base station device; and an updating means for, in response to a handover to the second base station device, updating the security key using the second setting information associated with the first setting information of the second base station device, and updating, after the handover is executed, the second setting information associated with the first setting information while maintaining the held first setting information for the third base station device.
2. The terminal device according to claim 1, wherein the receiving means receives updated second setting information for the third base station device from the second base station device after handover to the second base station device, and the updating means updates the second setting information by replacing the second setting information held for the third base station device with the received second setting information.
3. The terminal device according to claim 2, wherein the receiving means receives identification information that enables identification of the second setting information for a fourth base station device that is at least a part of the plurality of third base station devices, and updated second setting information for the fourth base station device, and the updating means replaces the second setting information identified by the identification information with the received second setting information.
4. The terminal device according to claim 3, wherein the first setting information is an LTM configuration, and the identification information is an LTM configuration id.
5. The terminal device according to claim 2, wherein a predetermined order is assigned to the plurality of third base station devices, the receiving means receives information in which the updated plurality of second setting information is arranged in the predetermined order for all of the plurality of third base station devices, and the updating means identifies, using the predetermined order, which of the plurality of third base station devices each of the received plurality of second setting information corresponds to, and replaces the second setting information held for each of the plurality of third base station devices with the received second setting information according to the identification result.
6. The terminal device according to claim 2, wherein the receiving means receives the updated second setting information from the second base station device by an RRC Reconfiguration message after an RRC Reconfiguration Complete message is transmitted during handover by the executing means.
7. The terminal device according to claim 1, wherein the second setting information is MasterKeyUpdate, and the MasterKeyUpdate includes: a keySetChangeIndicator, a nextHopChainingCount (NCC), and a Non-Access Stratum (NAS) container set to True, or a keySetChangeIndicator and an NCC set to False.
8. The terminal device according to claim 1, wherein the second setting information includes an SK-Counter.
9. The terminal device according to claim 1, wherein the execution means executes the handover when a Cell Switch Command instructing a handover to the second base station device is received, and the update means updates the security key using the second setting information included in the Cell Switch Command when the Cell Switch Command includes the second setting information related to the second base station device and when the second setting information is held for the second base station device.
10. The terminal device described in claim 1, wherein the receiving means further receives the first setting information for each of a plurality of fifth base station devices that provide cells that are candidates for a secondary cell when a cell provided by the currently connected base station device is used as a master cell, and a list of the second setting information common to the plurality of fifth base station devices, and when the secondary cell is changed without changing the master cell, the updating means deletes from the list the second setting information that was used before the secondary cell was changed, and updates the security key for communication of the changed secondary cell using one piece of second setting information included in the list.
11. The terminal device described in claim 10, wherein the receiving means further receives the first setting information for each of the plurality of fifth base station devices and a list of the second setting information common to the plurality of fifth base station devices when a cell provided by each of the plurality of base station devices becomes a master cell, and the list of second setting information for the second base station device is defined separately from the list of second setting information for the third base station device.
12. The terminal device according to claim 11, wherein the holding means holds a list of the second setting information for when a cell provided by the connected base station device and each of the plurality of base station devices becomes a master cell.
13. The terminal device according to claim 12, wherein said holding means deletes the list of said second setting information based on an instruction from the currently connected base station device.
14. The terminal device according to claim 12, wherein the holding means deletes the list of second setting information for the case where, when the terminal device is handed over to the second base station device, a cell provided by a base station device that is no longer a candidate for the handover destination after the handover becomes a master cell.
15. A base station device conforming to the cellular communication standard of the Third Generation Partnership Project (3GPP), comprising: a providing means for providing, to a first other base station device to which a terminal device is connected, first setting information for Layer 1 / Layer 2 Triggered Mobility (LTM) as a candidate handover destination, and second setting information associated with the first setting information for updating a security key; a connecting means for connecting to the terminal device upon handover of the terminal device; a generating means for generating a security key to be used in communication with the terminal device using the second setting information; an acquiring means for acquiring, from the base station device after the handover is executed, the first setting information and the second setting information for a second other base station device that is a candidate handover destination for the terminal device; and a transmitting means for transmitting, when the terminal device holds the first setting information for the second other base station device, a message to the terminal device that does not include the first setting information but includes the second setting information for the second other base station device.
16. The base station device according to claim 15, wherein the transmitting means transmits an RRC Reconfiguration message including the second setting information for the second other base station device to the terminal device after receiving an RRC Reconfiguration Complete message from the terminal device during the handover.
17. The base station device according to claim 15, wherein the transmitting means transmits the second setting information for the second other base station device together with a Cell Switch Command when instructing the terminal device to perform a handover to the second other base station device.
18. The base station device described in claim 15, wherein the providing means further provides the updated second setting information to the third other base station device when the terminal device is handed over from the first other base station device to a third other base station device, and the generating means generates the security key using the updated second setting information provided to the third other base station device when the terminal device is handed over from the third other base station device to the base station device.
19. The base station device according to claim 15, wherein the acquisition means acquires the first setting information and the second setting information for the second other base station device transmitted by the second other base station device in response to a request from the handover source base station device.
20. The base station device described in claim 15, wherein the acquisition means receives a message including the first setting information for the second other base station device from the handover source base station device, and acquires the first setting information and the second setting information for the second other base station device by transmitting a message requesting the second setting information to the second other base station device based on the message.
21. A control method executed by a terminal device that complies with the 3rd Generation Partnership Project (3GPP) cellular communication standard, comprising: receiving, from a connected first base station device, first setting information for Layer 1 / Layer 2 Triggered Mobility (LTM) for each of a plurality of base station devices that are candidate handover destinations, including a second base station device and a third base station device, and second setting information associated with the first setting information for updating a security key; associating and retaining the first setting information and the second setting information for each of the plurality of base stations; executing a handover to the second base station device; and, in response to the handover to the second base station device, updating the security key using the second setting information associated with the first setting information of the second base station device, and after executing the handover, updating the second setting information associated with the first setting information for the third base station device while maintaining the retained first setting information.
22. A control method executed by a base station device that complies with the 3rd Generation Partnership Project (3GPP) cellular communication standard, comprising: providing, to a first other base station device to which a terminal device is connected, as a candidate handover destination, first setting information for Layer 1 / Layer 2 Triggered Mobility (LTM) and second setting information associated with the first setting information for updating security keys; connecting to the terminal device by handing over the terminal device; generating a security key to be used in communication with the terminal device using the second setting information; after the handover is executed, acquiring from the base station device the first setting information and the second setting information for a second other base station device that is a candidate handover destination for the terminal device; and, if the terminal device holds the first setting information for the second other base station device, transmitting to the terminal device a message that does not include the first setting information but includes the second setting information for the second other base station device.