Method and apparatus for layer1 / layer2 triggered mobility (LTM) operation
The method for LTM operation in wireless communication systems addresses the challenge of inter-CU handovers by using a UE and BS to manage security key updates, reducing latency and overhead in Layer1/Layer2 triggered mobility.
Patent Information
- Application Number
- PCT/JP2025/012228
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-27
- Filing Date
- 2025-03-26
- Publication Date
- 2025-10-02
AI Technical Summary
Existing wireless communication systems face challenges in efficiently managing Layer1/Layer2 triggered mobility (LTM) operations, particularly in inter-CU scenarios, due to the need for security key updates and handling during handovers, leading to increased latency and interruption times.
A UE and BS method for LTM operation that includes receiving a counter set and index, determining a target counter value, and performing a security update procedure using a derived security key when the counter index is not equal to a predefined value, enabling seamless handovers between cells belonging to different central units (CUs).
This approach reduces latency and overhead during handovers by facilitating secure and efficient inter-CU LTM operations, ensuring continuous network connectivity with minimized interruption times.
Smart Images

Figure JP2025012228_02102025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR LAYER1 / LAYER2 TRIGGERED MOBILITY (LTM) OPERATION
[0001] The present disclosure is related to wireless communication and, more specifically, to a User Equipment (UE), Base Station (BS), and method for performing a Layer1 / Layer2 Triggered Mobility (LTM) operation in the wireless communication networks.
[0002] Various efforts have been made to improve different aspects of wireless communication for the cellular wireless communication systems, such as the 5thGeneration (5G) New Radio (NR), by improving data rate, latency, reliability, and mobility. The 5G NR system is designed to provide flexibility and configurability to optimize network services and types, accommodating various use cases, such as enhanced Mobile Broadband (eMBB), massive Machine-Type Communication (mMTC), and Ultra-Reliable and Low-Latency Communication (URLLC). As the demand for radio access continues to grow, however, there exists a need for further improvements in the next-generation wireless communication systems, such as improvements in an LTM operation.
[0003] The present disclosure is related to a UE, a BS, and a method for performing an LTM operation in the wireless communication networks.
[0004] In a first aspect of the present disclosure, a UE for performing an LTM operation is provided. The UE includes at least one processor and at least one non-transitory computer-readable medium that is coupled to the at least one processor and that stores one or more computer-executable instructions. The computer-executable instructions, when executed by the at least one processor, cause the UE to: receive, from a source cell, a first LTM configuration indicating a first target cell and a counter set including multiple counter values; receive, from the source cell, an LTM cell switch command (CSC) indicating the first target cell and a counter index; determine a target counter value based on the counter set and the counter index; switch from the source cell to the first target cell in response to receiving the LTM CSC; and in response to determining that the counter index is not equal to a predefined value, perform a security update procedure in the first target cell using a security key that is derived from the target counter value.
[0005] In some implementations of the first aspect, receiving the first LTM configuration includes receiving the first LTM configuration via a Radio Resource Control (RRC) configuration, and receiving the LTM CSC includes receiving the LTM CSC via a Medium Access Control (MAC) Control Element (CE).
[0006] In some implementations of the first aspect, the one or more computer-executable instructions, when executed by the at least one processor, further cause the UE to: transmit, to the first target cell, a reconfiguration complete message indicating the target counter value.
[0007] In some implementations of the first aspect, the source cell belongs to a first central unit (CU), and the first target cell belongs to a second CU different from the first CU.
[0008] In some implementations of the first aspect, the one or more computer-executable instructions, when executed by the at least one processor, further cause the UE to: receive, from the source cell, a second LTM configuration indicating a second target cell and the counter set. The first target cell and the second target cell both belong to the second CU. The counter set is common to the first target cell and the second target cell.
[0009] In some implementations of the first aspect, determining the target counter value based on the counter set and the counter index includes: in response to determining that the counter index is not equal to the predefined value, selecting the target counter value from the plurality of counter values corresponding to the counter index; and in response to determining that the counter index is equal to the predefined value, setting the target counter value to a current counter value currently used by the UE.
[0010] In some implementations of the first aspect, the predefined value is 0.
[0011] In a second aspect of the present application, a BS for configuring an LTM operation is provided. The BS includes at least one processor and at least one non-transitory computer-readable medium that is coupled to the at least one processor and that stores one or more computer-executable instructions. The computer-executable instructions, when executed by the at least one processor, cause the BS to: transmit, via a source cell to the UE, a first LTM configuration indicating a first target cell and a counter set including multiple counter values; and transmit, via the source cell to the UE, an LTM CSC indicating the first target cell and a counter index. The UE determines a target counter value based on the counter set and the counter index. The UE switches from the source cell to the first target cell in response to receiving the LTM CSC. In response to determining that the counter index is not equal to a predefined value, the UE performs a security update procedure in the first target cell using a security key that is derived from the target counter value.
[0012] In some implementations of the second aspect, transmitting the first LTM configuration includes transmitting the first LTM configuration via an RRC configuration, and transmitting the LTM CSC includes transmitting the LTM CSC via a MAC CE.
[0013] In some implementations of the second aspect, the UE further transmits, to the first target cell, a reconfiguration complete message indicating the target counter value.
[0014] In some implementations of the second aspect, the source cell belongs to a first CU, and the first target cell belongs to a second CU different from the first CU.
[0015] In some implementations of the second aspect, the one or more computer-executable instructions, when executed by the at least one processor, further cause the BS to: transmit, via the source cell to the UE, a second LTM configuration indicating a second target cell and the counter set. The first target cell and the second target cell both belong to the second CU. The counter set is common to the first target cell and the second target cell.
[0016] In some implementations of the second aspect, the UE selects the target counter value from the plurality of counter values corresponding to the counter index in response to determining that the counter index is not equal to the predefined value. The UE sets the target counter value to a current counter value currently used by the UE in response to determining that the counter index is equal to the predefined value.
[0017] In some implementations of the second aspect, the predefined value is 0.
[0018] In a third aspect of the present application, a method performed by a UE for performing an LTM operation is provided. The method includes receiving, from a source cell, a first LTM configuration indicating a first target cell and a counter set including multiple counter values; receiving, from the source cell, an LTM CSC indicating the first target cell and a counter index; determining a target counter value based on the counter set and the counter index; switching from the source cell to the first target cell in response to receiving the LTM CSC; and in response to determining that the counter index is not equal to a predefined value, performing a security update procedure in the first target cell using a security key that is derived from the target counter value.
[0019] Aspects of the present disclosure are best understood from the following detailed disclosure when read with the accompanying drawings. Various features are not drawn to scale. Dimensions of various features may be arbitrarily increased or reduced for clarity of discussion.
[0020] FIG. 1 is a flowchart illustrating a method / process performed by a UE for performing an LTM operation, according to an example implementation of the present disclosure.
[0021] FIG. 2 is a flowchart illustrating a method / process performed by a BS for configuring an LTM operation, according to an example implementation of the present disclosure.
[0022] FIG. 3 is a block diagram illustrating a node for wireless communication, according to an example implementation of the present disclosure.
[0023] Some of the abbreviations used in the present disclosure include: Abbreviations Full name 3GPP 3rd Generation Partnership Project 5G 5th generation 5GC 5G Core Network ACK Acknowledgment BWP Bandwidth Part BS Base Station CA Carrier Aggregation CORESET Control resource set CC Component Carrier CCE Control Chanel Element CE Control Element CFRA Contention-Free RA CHO Conditional Handover CMAS Commercial Mobile Alert System CRC Cyclic Redundancy Check C-RNTI Cell Radio Network Temporary Identifier CSC Cell Switch Command CSI Channel State Information CU Central Unit DAPS Dual Active Protocol Stack DC Dual Connectivity DCI Downlink Control Information DL Downlink DMRS Demodulation Reference Signal EN-DC E-UTRA-NR Dual Connectivity EPC Evolved Packet Core ETWS Earthquake and Tsunami Warning System E-UTRA Evolved Universal Terrestrial Radio Access FR Frequency Range HARQ Hybrid Automatic Repeat Request ID Identifier IE Information Element L1 / L2 / L3 Layer 1 / Layer 2 / Layer 3 LSB Least Significant Bit LTE Long Term Evolution LTM Layer1 / Layer2 Triggered Mobility MAC Medium Access Control MCG Master Cell Group MIB Master Information Block MIMO Multi-Input Multi-Output MN Master Node MR-DC Multi-RAT Dual Connectivity MSB Most Significant Bit NACK Negative Acknowledgment NAS Non-Access Stratum NDI New Data Indicator NE-DC NR-E-UTRA Dual Connectivity NG-RAN Next Generation Radio Access Network NGEN-DC NG-RAN E-UTRA-NR Dual Connectivity NR New RAT / Radio NR-DC NR-NR Dual Connectivity NUL Normal Uplink NW Network PBCH Physical Broadcast Channel PCell Primary Cell PDCP Packet Data Convergence Protocol PDCCH Physical Downlink Control Channel PDSCH Physical Downlink Shared Channel PDU Protocol Data Unit PH Power Headroom PHR Power Headroom Report PHY Physical PLMN Public Land Mobile Network PRACH Physical Random Access Channel PSCell Primary SCG Cell PTAG Primary Timing Advance Group PUCCH Physical Uplink Control Channel PUSCH Physical Uplink Shared Channel RA Random Access RACH Random Access Channel RAN Radio Access Network RAT Radio Access Technology Rel Release RLC Radio Link Control RNTI Radio Network Temporary Identifier RRC Radio Resource Control RS Reference Signal RV Redundancy Version SCell Secondary Cell SCG Secondary Cell Group SCS Subcarrier Spacing SI System Information SIB System Information Block SN Secondary Node SP Semi-Persistent SpCell Special Cell SR Scheduling Request SRI SRS Resource Indicator SRS Sounding Reference Signal SS Synchronization Signal SSB Synchronization Signal Block STAG Secondary Timing Advance Group SUL Supplementary Uplink TA Timing Advance TAG Timing Advance Group TB Transport Block TCI Transmission Configuration Indication TPC Transmission Power Control TR Technical Report TRP Transmission Reception Point TS Technical Specification TX Transmission QCL Quasi Co-Location UE User Equipment UL Uplink UL-SCH Uplink Shared Channel URLLC Ultra Reliable Low Latency Communication XnAP Xn Application Protocol
[0024] The following contains specific information related to implementations of the present disclosure. The drawings and their accompanying detailed disclosure are merely directed to implementations. However, the present disclosure is not limited to these implementations. Other variations and implementations of the present disclosure will be obvious to those skilled in the art.
[0025] Unless noted otherwise, like or corresponding elements among the drawings may be indicated by like or corresponding reference numerals. Moreover, the drawings and illustrations in the present disclosure are generally not to scale and are not intended to correspond to actual relative dimensions.
[0026] For the purposes of consistency and ease of understanding, like features may be identified (although, in some examples, not illustrated) by the same numerals in the drawings. However, the features in different implementations may be different in other respects and may not be narrowly confined to what is illustrated in the drawings.
[0027] References to “one implementation,” “an implementation,” “example implementation,” “various implementations,” “some implementations,” “implementations of the present application,” etc., may indicate that the implementation(s) of the present application so described may include a particular feature, structure, or characteristic, but not every possible implementation of the present application necessarily includes the particular feature, structure, or characteristic. Further, repeated use of the phrase “In some implementations,” or “in an example implementation,” “an implementation,” do not necessarily refer to the same implementation, although they may. Moreover, any use of phrases like “implementations” in connection with “the present application” are never meant to characterize that all implementations of the present application must include the particular feature, structure, or characteristic, and should instead be understood to mean “at least some implementations of the present application” includes the stated particular feature, structure, or characteristic. The term “coupled” is defined as connected, whether directly or indirectly through intervening components, and is not necessarily limited to physical connections. The term “comprising,” when utilized, means “including, but not necessarily limited to”; it specifically indicates open-ended inclusion or membership in the so-described combination, group, series, and the equivalent.
[0028] The expression “at least one of A, B and C” or “at least one of the following: A, B and C” means “only A, or only B, or only C, or any combination of A, B and C.” The terms “system” and “network” may be used interchangeably. The term “and / or” is only an association relationship for describing associated objects and represents that three relationships may exist such that A and / or B may indicate that A exists alone, A and B exist at the same time, or B exists alone. The character “ / ” generally represents that the associated objects are in an “or” relationship.
[0029] For the purposes of explanation and non-limitation, specific details, such as functional entities, techniques, protocols, and standards, are set forth for providing an understanding of the disclosed technology. In other examples, detailed disclosure of well-known methods, technologies, systems, and architectures are omitted so as not to obscure the present disclosure with unnecessary details.
[0030] Persons skilled in the art will immediately recognize that any network function(s) or algorithm(s) disclosed may be implemented by hardware, software, or a combination of software and hardware. Disclosed functions may correspond to modules which may be software, hardware, firmware, or any combination thereof.
[0031] A software implementation may include computer executable instructions stored on a computer-readable medium, such as memory or other type of storage devices. One or more microprocessors or general-purpose computers with communication processing capability may be programmed with corresponding executable instructions and perform the disclosed network function(s) or algorithm(s).
[0032] The microprocessors or general-purpose computers may include Application-Specific Integrated Circuits (ASICs), programmable logic arrays, and / or one or more Digital Signal Processor (DSPs). Although some of the disclosed implementations are oriented to software installed and executing on computer hardware, alternative implementations implemented as firmware, as hardware, or as a combination of hardware and software are well within the scope of the present disclosure. The computer-readable medium includes but is not limited to Random Access Memory (RAM), Read Only Memory (ROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), flash memory, Compact Disc Read-Only Memory (CD-ROM), magnetic cassettes, magnetic tape, magnetic disk storage, or any other equivalent medium capable of storing computer-readable instructions.
[0033] A radio communication network architecture such as a Long-Term Evolution (LTE) system, an LTE-Advanced (LTE-A) system, an LTE-Advanced Pro system, or a 5G NR Radio Access Network (RAN) typically includes at least one base station (BS), at least one UE, and one or more optional network elements that provide connection within a network. The UE communicates with the network such as a Core Network (CN), an Evolved Packet Core (EPC) network, an Evolved Universal Terrestrial RAN (E-UTRAN), a 5G Core (5GC), or an internet via a RAN established by one or more BSs.
[0034] A UE may include, but is not limited to, a mobile station, a mobile terminal or device, or a user communication radio terminal. The UE may be a portable radio equipment that includes, but is not limited to, a mobile phone, a tablet, a wearable device, a sensor, a vehicle, or a Personal Digital Assistant (PDA) with wireless communication capability. The UE is configured to receive and transmit signals over an air interface to one or more cells in a RAN.
[0035] The BS may be configured to provide communication services according to at least a Radio Access Technology (RAT) such as Worldwide Interoperability for Microwave Access (WiMAX), Global System for Mobile communications (GSM) that is often referred to as 2G, GSM Enhanced Data rates for GSM Evolution (EDGE) RAN (GERAN), General Packet Radio Service (GPRS), Universal Mobile Telecommunication System (UMTS) that is often referred to as 3G based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), LTE, LTE-A, evolved LTE (eLTE) that is LTE connected to 5GC, NR (often referred to as 5G), and / or LTE-A Pro. However, the scope of the present disclosure is not limited to these protocols.
[0036] The BS may include, but is not limited to, a node B (NB) in the UMTS, an evolved node B (eNB) in LTE or LTE-A, a radio network controller (RNC) in UMTS, a BS controller (BSC) in the GSM / GERAN, an ng-eNB in an Evolved Universal Terrestrial Radio Access (E-UTRA) BS in connection with 5GC, a next generation Node B (gNB) in the 5G-RAN, or any other apparatus capable of controlling radio communication and managing radio resources within a cell. The BS may serve one or more UEs via a radio interface. Although the gNB is used as an example in some implementations within the present disclosure, it should be noted that the disclosed implementations may also be applied to other types of base stations.
[0037] The BS may be operable to provide radio coverage to a specific geographical area using multiple cells forming the RAN. The BS may support the operations of the cells. Each cell may be operable to provide services to at least one UE within its radio coverage.
[0038] Each cell (may often referred to as a serving cell) may provide services to one or more UEs within the cell’s radio coverage, such that each cell schedules the DL (and optionally UL resources) to at least one UE within its radio coverage for DL (and optionally UL packet transmissions from the UE). The BS may communicate with one or more UEs in the radio communication system via the cells.
[0039] A cell may allocate sidelink (SL) resources for supporting the Proximity Services (ProSe) or Vehicle to Everything (V2X) services. Each cell may have overlapped coverage areas with other cells.
[0040] In Multi-RAT Dual Connectivity (MR-DC) cases, the primary cell of a Master Cell Group (MCG) or a Secondary Cell Group (SCG) may be referred to as a Special Cell (SpCell). A Primary Cell (PCell) may include the SpCell of an MCG. A Primary SCG Cell (PSCell) may include the SpCell of an SCG. MCG may include a group of serving cells associated with the Master Node (MN), including the SpCell and optionally one or more Secondary Cells (SCells). An SCG may include a group of serving cells associated with the Secondary Node (SN), including the SpCell and optionally one or more SCells.
[0041] As discussed above, the frame structure for NR may support flexible configurations for accommodating various next generation (e.g., 5G) communication requirements, such as Enhanced Mobile Broadband (eMBB), Massive Machine Type Communication (mMTC), and Ultra-Reliable and Low-Latency Communication (URLLC), while fulfilling high reliability, high data rate, and low latency requirements. The Orthogonal Frequency-Division Multiplexing (OFDM) technology in the 3GPP may serve as a baseline for an NR waveform. The scalable OFDM numerology, such as adaptive sub-carrier spacing, channel bandwidth, and Cyclic Prefix (CP), may also be used.
[0042] Two coding schemes may be considered for NR, specifically, Low-Density Parity-Check (LDPC) code and Polar Code. The coding scheme adaption may be configured based on channel conditions and / or service applications.
[0043] At least the DL transmission data, a guard period, and UL transmission data should be included in a transmission time interval (TTI) of a single NR frame. The respective portions of the DL transmission data, the guard period, and the UL transmission data should also be configurable based on, for example, the network dynamics of NR. SL resources may also be provided in an NR frame to support ProSe services or V2X services.
[0044] Any two or more than two of the following paragraphs, (sub)-bullets, points, actions, behaviors, terms, or claims described in the present disclosure may be combined logically, reasonably, and properly to form a specific method.
[0045] Any sentence, paragraph, (sub)-bullet, point, action, behaviors, terms, or claims described in the present disclosure may be implemented independently and separately to form a specific method.
[0046] Dependency, e.g., “based on”, “more specifically”, “preferably”, “in one embodiment”, “in some implementations”, etc., in the present disclosure is just one possible example which would not restrict the specific method.
[0047] In some implementations, all the designs / embodiment / implementations introduced within this disclosure are not limited to be applied for dealing with the problems discussed within this disclosure. For example, the described embodiments may be applied to solve other problems that exist in the RAN of wireless communication systems. In some implementations, all of the numbers listed within the designs / embodiment / implementations introduced within this disclosure are just examples and for illustration, for example, of how the described methods are executed.
[0048] Examples of some selected terms in the present disclosure are provided as follows.
[0049] The network (NW), cell, camped cell, serving cell, base station, gNB, eNB, and ng-eNB may be interchangeably in the present disclosure. In some implementations, some of these items may refer to the same network entity.
[0050] The RAT may include, but not limited to, NR, LTE, E-UTRA connected to 5GC, LTE connected to 5GC, E-UTRA connected to EPC, and LTE connected to EPC. The proposed mechanism may be applied for UEs in public networks or in private networks, such as non-public network (NPN), standalone NPN (SNPN), and public network integrated NPN (PNI-NPN).
[0051] The proposed mechanism may be used for licensed frequency and / or unlicensed frequency. In addition, the proposed mechanism of conditional configuration selection may be applied to cases in which a UE experiences a radio link failure when configured with conditional configurations.
[0052] System information (SI) may refer to MIB, SIB1, and other SI. Minimum SI may include MIB and SIB1. Other SI may refer to SIB3, SIB4, SIB5, and other SIB(s).
[0053] Dedicated signaling may refer to (but not limited to) RRC message(s). For example, RRC (Connection) Setup Request message, RRC (Connection) Setup message, RRC (Connection) Setup Complete message, RRC (Connection) Reconfiguration message, RRC Connection Reconfiguration message including the mobility control information, RRC Connection Reconfiguration message without the mobility control information inside, RRC Reconfiguration message including the configuration with sync, RRC Reconfiguration message without the configuration with sync inside, RRC (Connection) Reconfiguration Complete message, RRC (Connection) Resume Request message, RRC (Connection) Resume message, RRC (Connection) Resume Complete message, RRC (Connection) Reestablishment Request message, RRC (Connection) Reestablishment message, RRC (Connection) Reestablishment Complete message, RRC (Connection) Reject message, RRC (Connection) Release message, RRC System Information Request message, UE Assistance Information message, UE Capability Enquiry message, and UE Capability Information message.
[0054] The RRC_CONNECTED UE, RRC_INACTIVE UE, and RRC_IDLE UE may apply the proposed implementations.
[0055] The source cell may be a suitable cell or an acceptable cell.
[0056] A suitable cell is a cell on which a UE may camp. The UE may consider a cell as suitable if the following conditions are fulfilled: (1) The cell is part of either the selected PLMN or the registered PLMN or PLMN of the Equivalent PLMN list, and (2) The cell criteria of the cell are fulfilled. Furthermore, according to the latest information provided by NAS, the suitable cell is not barred. The suitable cell is part of at least one TA that is not part of the list of “Forbidden Tracking Areas”, which belongs to a PLMN that fulfils the condition (1).
[0057] An acceptable cell is a cell on which the UE may camp to obtain limited service, such as originating emergency calls and receiving ETWS and CMAS notifications. An acceptable cell may fulfil the following requirements, which is the minimum set of requirements to initiate an emergency call and to receive ETWS and CMAS notification in an NR network: (1) the cell is not barred, and / or (2) the cell selection criteria are fulfilled.
[0058] Primary Cell (PCell): The MCG cell, operating on the primary frequency, in which the UE either performs the initial connection establishment procedure or initiates the connection re-establishment procedure may be referred to as a primary cell.
[0059] Primary SCG (PSCell): For dual connectivity operation, the SCG cell in which the UE performs random access when performing the Reconfiguration with Sync procedure.
[0060] Serving Cell: For a UE in the RRC_CONNECTED state, that is not configured with CA / DC, there is only one serving cell which is a primary cell. For a UE in the RRC_CONNECTED state, that is configured with CA / DC, the term ‘serving cells’ is used to denote a set of cells including the Special Cell(s) and all secondary cells. The serving cell may include a PCell, a PSCell, or an SCell.
[0061] Secondary Cell: For a UE configured with CA, a cell that provides additional radio resources on top of the special cell may be referred to as a secondary cell.
[0062] Special Cell (SpCell): For a Dual Connectivity operation, the term Special Cell may include the PCell of the MCG or the PSCell of the SCG depending on whether the MAC entity is associated with the MCG or the SCG, respectively. Otherwise, the term Special Cell may include the PCell.
[0063] Master Cell Group (MCG): In MR-DC, a group of serving cells associated with the master node, including the SpCell (e.g., PCell) and optionally one or more SCells.
[0064] Master node: In MR-DC, the radio access node that provides the control plane connection to the core network. It may be a Master eNB (in EN-DC), a Master ng-eNB (in NGEN-DC), or a Master gNB (in NR-DC and NE-DC).
[0065] Secondary Cell Group (SCG): In MR-DC, a group of serving cells associated with the secondary node, including the SpCell (e.g., PSCell) and optionally one or more SCells.
[0066] Secondary node: In MR-DC, the radio access node, with no control plane connection to the core network, providing additional resources to the UE. It may be an en-gNB (in EN-DC), a Secondary ng-eNB (in NE-DC), or a Secondary gNB (in NR-DC and NGEN-DC).
[0067] Source node: The node from which the UE receives a CSC. The source node may be interpreted as a source MN, a source SN, a source PCell, a source PSCell, or a source gNB.
[0068] Source cell: The cell from which the UE receives a CSC. The source cell may be interpreted as a source PCell, or a source PSCell.
[0069] Candidate node: The node that is associated with the LTM candidate configuration stored by the UE. The candidate node may be interpreted as a candidate MN, a candidate SN, a candidate PCell, a candidate PSCell, or a candidate gNB.
[0070] Candidate cell: The cell that is associated with the LTM candidate configuration stored by the UE. The candidate cell may be interpreted as a candidate PCell, or a candidate PSCell.
[0071] Target node: The node that is associated with the LTM candidate configuration ID in the CSC received by the UE. The target node may be interpreted as a target MN, a target SN, a target PCell, a target PSCell, or a target gNB.
[0072] Target cell: The cell that is associated with the LTM candidate configuration ID in the CSC received by the UE. The target cell may be interpreted as a target PCell, or a target PSCell.
[0073] In the present disclosure, the system information may be associated with the serving cell and / or the candidate / target cell.
[0074] In the wireless cellular network, mobile devices (e.g., UE) may move from the coverage area of one cell to another cell. To avoid the connection interruption and ensure the service continuity, a handover procedure may be applied for the mobile devices when the handover procedure is triggered under certain conditions, e.g., when the signal quality of the source cell becomes poorer than a threshold for a period.
[0075] A handover procedure may be triggered by Layer 3 (L3) measurements and completed through RRC signaling, which triggers Reconfiguration with Synchronization to change the PCell and PSCell, as well as to release and add SCells. In addition, a conditional handover (CHO) may enhance robustness by allowing the mobile device to receive the target cell configuration in advance, for example, when the signal quality between the mobile device and the source cell is stable. Dual Active Protocol Stack (DAPS) handover may reduce the interruption time because the mobile device may maintain two protocol stacks for simultaneous connections with the source cell and the target cell during handover. For example, one protocol stack is associated with the source cell and the other one is associated with the target cell. These handover procedures, including the conditional handover and the DAPS handover, may require a complete Layer 2 (L2) reset and Layer 1 (L1) reset. L2 may refer to the Medium Access Control (MAC) layer, Radio Link Control (RLC) layer, and Packet Data Convergence Protocol (PDCP) layer, and L1 may refer to the Physical (PHY) layer. Complete L1 / L2 reset may result in longer latency, larger overhead and longer interruption time than beam switch mobility. Thus, L1 / L2 triggered mobility (LTM) has been proposed to enable a serving cell change via L1 / L2 signaling, which may reduce the latency, overhead and interruption time during the handover procedures.
[0076] In some implementations, the LTM supports scenarios where the mobility happens in cells belonging to the same central unit (CU). That is, intra-CU mobility may be supported for the LTM. To support inter-CU LTM, the security key handling may be essential because the UE is required to perform security counter update and derive the security key according to the updated security counter every time when the UE is connected to a different CU. In some implementations, the security counter value may be included in an RRC configuration (e.g., the RRCReconfiguration IE) in the LTM candidate configuration (e.g., the LTM-Candidate IE). However, this solution may not be applicable to inter-CU subsequent LTM since the UE needs to use a different security counter when switching out of and then back to the same CU. Therefore, it is important to explore security counter handling to support the inter-CU subsequent LTM effectively.
[0077] Inter-CU LTM Scenarios
[0078] The following scenarios may be considered in the present disclosure. A network may include multiple cells, and a UE may or may not support the MR-DC configuration. That is, the UE may receive services from at least two RAN nodes or from only one RAN node. The RAN node may be an evolved node B (eNB) or a next generation node B (gNB). The at least two RAN nodes may include an MN associated with an MCG and at least one SN associated with an SCG. The UE may be equipped with multiple receivers and transmitters, and the UE may be capable of supporting the MR-DC dedicated configurations. The network, having the information that the UE is capable of supporting the MR-DC, may configure the UE with the MR-DC configuration (e.g., the SCG configuration), which may be encapsulated in an RRC Reconfiguration message and transmitted from the serving RAN node to the UE.
[0079] If the UE is not configured and not operating with MR-DC, the network may transmit a MAC CE to the UE to trigger the LTM execution. In the present disclosure, the MAC CE triggering the LTM execution may be referred as a cell switch command (CSC), an LTM CSC, or an LTM CSC MAC CE.
[0080] If the UE is configured and operating with MR-DC, the network may utilize radio resources provided by two distinct schedulers, located in two different RAN nodes. The UE may maintain the control and user plane connection to the PCell in the MCG and to the PSCell in the SCG. In this case, the network may transmit a CSC via PCell to the UE to trigger the MCG LTM execution, or the network may transmit a CSC via PSCell to the UE to trigger the SCG LTM execution.
[0081] Inter-CU LTM Preparation
[0082] In some implementations, a source node may send an inter-node signaling (e.g., XnAP signaling or inter-node RRC signaling) to a candidate node. In some implementations, the inter-node signaling may include an integer indicating the maximum number of LTM candidate configurations that the candidate node may prepare.
[0083] In some implementations, a candidate node may send an inter-node signaling (e.g., XnAP signaling or inter-node RRC signaling) to a source node. Implementations regarding the inter-node signaling from the candidate node to the source node are disclosed below.
[0084] In some implementations, the inter-node signaling may include a list of LTM candidate configurations. In some implementations, an LTM candidate configuration may be associated with a candidate cell. In some implementations, an LTM candidate configuration may include at least one of the following: an LTM candidate configuration ID for identification, an RRC configuration (e.g., the RRCReconfiguration IE) that the UE may apply upon receiving a CSC, a random access channel (RACH) configuration for the UE to perform early uplink synchronization before receiving a CSC, a list of TCI states for the UE to perform early beam activation before receiving a CSC, an indicator for the UE to determine whether to re-establish the RLC entity or not, an indicator for the UE to determine whether to implement PDCP data recovery or PDCP re-establishment during the LTM execution procedure, and an indicator for the UE to determine whether to perform UE-based TA measurement before receiving a CSC.
[0085] In some implementations, the inter-node signaling may include a list of TCI state configurations for the UE to perform early beam activation before receiving a CSC. In some implementations, each TCI state configuration in the list may correspond to one of the LTM candidate configurations. For example, the first entry of the TCI state configuration list may correspond to the first entry of the LTM candidate configuration list, and the second entry of the TCI state configuration list may correspond to the second entry of the LTM candidate configuration list, and so on. The number of the TCI state configurations in the TCI state configuration list may be equal to the number of the LTM candidate configurations in the LTM candidate configuration list. In some implementations, if a particular TCI state configuration is missing, the source node may send another inter-CU message to the candidate node. In some implementations, if a particular TCI state configuration is missing, the source node may assume that the UE assumes there is no pre-configuration for the corresponding LTM candidate. In some implementations, if a particular TCI state configuration is missing, the UE may assume that a reference beam and / or TCI state may be applied, where the reference beam / TCI state may be a default setting or the most recently used one under current source node.
[0086] In some implementations, the inter-node signaling may include a list of indicators for the UE to determine whether to re-establish the RLC entity during the LTM execution procedure. In some implementations, each indicator in the list may correspond to one of the LTM candidate configurations. For example, the first entry of the indicator list may correspond to the first entry of the LTM candidate configuration list, and the second entry of the indicator list may correspond to the second entry of the LTM candidate configuration list, and so on. The number of the indicators in the indicator list may be equal to the number of the LTM candidate configurations in the LTM candidate configuration list.
[0087] In some implementations, each indicator may include a Boolean indicator to indicate to the UE whether to re-establish the RLC entity. In some implementations, the UE may re-establish the RLC entity when the Boolean indicator is present or set to ‘true’; the UE may not re-establish the RLC entity when the Boolean indicator is absent or set to ‘false’.
[0088] In some implementations, each indicator may include an integer ranging from 1 to the number of LTM configurations associated with the candidate node. In some implementations, the UE may re-establish the RLC entity when the value of the indicator is not equal to the value of a stored RLC-reestablishment indicator; the UE may not re-establish the RLC entity when the value of the indicator is equal to the value of a stored RLC-reestablishment indicator.
[0089] In some implementations, the inter-node signaling may include a list of indicators for the UE to determine whether to perform UE-based TA measurement before receiving a CSC. In some implementations, each indicator in the list may correspond to one of the LTM candidate configurations. For example, the first entry of the indicator list may correspond to the first entry of the LTM candidate configuration list, and the second entry of the indicator list may correspond to the second entry of the LTM candidate configuration list, and so on. The number of the indicators in the indicator list may be equal to the number of the LTM candidate configurations in the LTM candidate configuration list.
[0090] In some implementations, each indicator (e.g., a Boolean indicator) in the inter-node signaling may be provided for the UE to determine whether to perform UE-based TA measurement before receiving a CSC. In some implementations, if the indicator is present or set to ‘true’, the UE may determine to perform the UE-based TA measurement towards the candidate cell associated with the LTM candidate configuration corresponding to the indicator before receiving the CSC. In some implementations, if the indicator is absent or set to ‘false’, the UE may determine not to perform the UE-based TA measurement towards the candidate cell associated with the LTM candidate configuration corresponding to the indicator before receiving the CSC.
[0091] In some implementations, each indicator may include an integer ranging from 1 to the number of LTM configurations associated with the candidate node. In some implementations, before receiving the CSC, the UE may perform the UE-based TA measurement towards a candidate cell when the value of the indicator associated with the candidate cell is equal to the value of a stored UE-based TA measurement indicator; the UE may not perform the UE-based TA measurement towards a candidate cell when the value of the indicator associated with the candidate cell is not equal to the value of a stored UE-based TA measurement indicator.
[0092] In some implementations, the inter-node signaling may include a list of security counters (e.g., the nextHoppingChainCount and / or SK-Counter(s) in the 3GPP technical specifications) that the UE may use for security counter update and security key update during the LTM execution procedure. The nextHoppingChainCount may be referred to as the master key. The SK-Counter may be referred to as the secondary key.
[0093] In some implementations, a source node may send an inter-node signaling (e.g., XnAP signaling or inter-node RRC signaling) to a candidate node. Implementations regarding the inter-node signaling from the source node to the candidate node are disclosed below.
[0094] In some implementations, the inter-node signaling may include a list of tuples, where each tuple may include a security counter set ID and a cell ID. In some implementations, the security counter set ID may indicate an ID associated with a specific set of security counters, and the cell ID may indicate an ID of a specific cell.
[0095] In some implementations, the inter-node signaling may include a list of tuples, where each tuple may include a security counter set ID and a list of cell IDs. In some implementations, the security counter set ID may indicate an ID associated with a specific set of security counters, and the cell ID may indicate an ID of a specific cell.
[0096] In some implementations, the inter-node signaling may include a list of tuples, where each tuple may include a security counter set ID and an LTM candidate configuration ID. In some implementations, the security counter set ID may indicate an ID associated with a specific set of security counters, and the LTM candidate configuration ID may indicate an ID of a specific LTM candidate configuration.
[0097] In some implementations, the inter-node signaling may include a list of tuples, where each tuple may include a security counter set ID and a list of LTM candidate configuration IDs. In some implementations, the security counter set ID may indicate an ID associated with a specific set of security counters, and the LTM candidate configuration ID may indicate an ID of a specific LTM candidate configuration.
[0098] Inter-CU LTM Configuration
[0099] In some implementations, the source node may transmit an LTM-related configuration to the UE via RRC signaling (e.g., an RRCReconfiguration message). Implementations regarding the RRC signaling from the source node to the UE are disclosed below.
[0100] In some implementations, the RRC signaling may include multiple LTM candidate configurations. In some implementations, an LTM candidate configuration may include at least one of the following: an LTM candidate configuration ID for the UE to identify, an RRC configuration (e.g., the RRCReconfiguration IE) for the UE to apply upon receiving a CSC, a list of TCI state configurations for the UE to apply early beam activation before receiving a CSC, an indicator for the UE to determine whether to re-establish the RLC entity during the LTM execution, an indicator for the UE to determine whether to perform UE-based TA measurement before receiving a CSC, and a security counter set ID for the UE to determine whether to perform security counter update and from which security counter set the UE selects a security counter during the LTM execution procedure. The indicator for the UE to determine whether to re-establish the RLC entity during the LTM execution and the indicator for the UE to determine whether to perform the UE-based TA measurement before receiving the CSC may be configured on a per-LTM-candidate-configuration basis. For example, different LTM candidate configurations may include different values of these indicators.
[0101] In some implementations, each indicator may include a Boolean indicator to indicate to the UE whether to re-establish the RLC entity. In some implementations, the UE may re-establish the RLC entity when the Boolean indicator is present or set to ‘true’; the UE may not re-establish the RLC entity when the Boolean indicator is absent or set to ‘false’.
[0102] In some implementations, each indicator may include an integer ranging from 1 to the number of LTM configurations associated with the candidate node. In some implementations, the UE may re-establish the RLC entity when the value of the indicator is not equal to the value of a stored RLC-reestablishment indicator; the UE may not re-establish the RLC entity when the value of the indicator is equal to the value of a stored RLC-reestablishment indicator.
[0103] In some implementations, each indicator may include a Boolean indicator to indicate to the UE whether to perform UE-based TA measurement towards the candidate cell associated with the LTM candidate configuration corresponding to the indicator before receiving a CSC. In some implementations, the UE may determine to perform the UE-based TA measurement towards the candidate cell associated with the LTM candidate configuration corresponding to the indicator before receiving the CSC when the Boolean indicator is present or set to be ‘true’; the UE may determine not to perform the UE-based TA measurement towards the candidate cell associated with the LTM candidate configuration corresponding to the indicator before receiving the CSC when the Boolean indicator is absent or set to ‘false’.
[0104] In some implementations, each indicator may include an integer ranging from 1 to the number of LTM configurations associated with the candidate node. In some implementations, before receiving the CSC, the UE may perform the UE-based TA measurement towards a candidate cell when the value of the indicator associated with the candidate cell is equal to the value of a stored UE-based TA measurement indicator; the UE may not perform the UE-based TA measurement towards a candidate cell when the value of the indicator associated with the candidate cell is not equal to the value of a stored UE-based TA measurement indicator.
[0105] In some implementations, the RRC signaling may include a list of tuples, where each tuple may include a security counter set ID and a list of security counter values (e.g., multiple counter values), enabling the UE to add and / or modify the security counter configuration.
[0106] In some implementations, the security counter set ID may indicate an ID associated with a set of security counter values, which may be included in the same tuple as the security counter set ID.
[0107] In some implementations, the security counter values associated with the same security counter set ID may be consecutive integers. In some implementations, the security counter values associated with the same security counter set ID may not be consecutive integers.
[0108] In some implementations, the security counter values associated with different security counter set IDs may be different.
[0109] In some implementations, the security counter values may be mutually exclusive within a security counter set, but the same counter value may be reused in different security counter sets, each associated with a corresponding set ID.
[0110] In some implementations, the security counter values may be determined based on the security counter set and / or the number of counter values in a counter set. The maximum number of counter values may be the same across all security counter sets. However, the number of counter values within each security counter set may be different.
[0111] In some implementations, the RRC signaling may include a list of security counter set IDs, allowing the UE to release the security counter configuration. In some implementations, a security counter set ID in the list may instruct the UE to release all the stored security counter values associated with the security counter set ID.
[0112] In some implementations, the RRC signaling may include a list of tuples, where each tuple may include a security counter set ID and a list of security counter values, allowing the UE to release the security counter configuration. In some implementations, a security counter set ID may indicate an ID corresponding to a security counter set ID stored by the UE. In some implementations, the received security counter values may indicate the security counter values to be released from those stored by the UE.
[0113] In some implementations, upon receiving the LTM-related configuration via RRC signaling (e.g., the RRCReconfiguration message) from the source node, the UE may apply and / or store the LTM-related configuration.
[0114] In some implementations, if the RRC signaling contains a list of tuples, each including a security counter set ID and a list of security counter values, the UE may release all the stored tuples and store all the tuples received in the RRC signaling.
[0115] In some implementations, if the RRC signaling contains a list of tuples, each including a security counter set ID and a list of security counter values, the UE may check, for each entry in the received list of tuples, whether there is a stored tuple with a security counter set ID that matches the security counter set ID of the entry.
[0116] In some implementations, if there is a stored tuple with a security counter set ID that matches the security counter set ID of the entry, the UE may release the stored tuple and store the tuple received in the RRC signaling. In some implementations, the UE may initialize the stored index associated with the security counter set ID by setting the stored index to 1. In some implementations, the UE may initialize the stored used security counter list associated with the security counter set ID by removing all the entries in the stored used security counter list.
[0117] In some implementations, if there is no stored tuple with a security counter set ID that matches the security counter set ID of the entry, the UE may store the tuple received in the RRC signaling. In some implementations, the UE may initialize the stored index associated with the security counter set ID by setting the stored index to 1. In some implementations, the UE may initialize the stored used security counter list associated with the security counter set ID by removing all the entries in the stored used security counter list.
[0118] In some implementations, if the RRC signaling includes a list of security counter set IDs (e.g., the ltm-counterToReleaseList IE), the UE may release the stored tuples with a security counter set ID that is in the received list. In some implementations, the UE may release the stored index associated with the security counter set ID when the UE receives the RRC signaling including the list of security counter set IDs. In some implementations, the UE may release the stored used security counter list associated with the security counter set ID when the UE receives the RRC signaling including the list of security counter set IDs.
[0119] In the present disclosure, the term “security counter set” may refer to a set of security counter values associated with the same security counter set ID.
[0120] Inter-CU LTM Execution
[0121] In some implementations, the source node may determine an LTM cell switch, and the source node may transmit one or more CSC(s) to the UE.
[0122] In some implementations, the CSC may include at least one of the following: a field indicating whether contention-free RA (CFRA) related information exists in the CSC, a field indicating whether normal uplink (NUL) or supplementary uplink (SUL) is used, a field indicating an LTM candidate configuration ID that the UE may apply for the LTM execution, a field indicating a TA value, a field indicating the downlink / joint / uplink TCI state ID, a field indicating a security counter set ID, and a field indicating the CFRA-related information (e.g., preamble index, SS / PBCH index, and PRACH mask index).
[0123] In some implementations, the CSC may include at least one of the following: a field indicating whether CFRA related information exists in the CSC, a field indicating whether NUL or SUL is used, a field indicating an LTM candidate configuration ID that the UE may apply for the LTM execution, a field indicating a TA value, a field indicating the downlink / joint / uplink TCI state ID, a field indicating one or more security counter values, and a field indicating the CFRA-related information (e.g., preamble index, SS / PBCH index, and PRACH mask index).
[0124] In some implementations, the CSC may include at least one of the following: a field indicating whether CFRA related information exists in the CSC, a field indicating whether NUL or SUL is used, a field indicating an LTM candidate configuration ID that the UE may apply for the LTM execution, a field indicating a TA value, a field indicating the downlink / joint / uplink TCI state ID, a field indicating one or more indices of security counters, and a field indicating the CFRA-related information (e.g., preamble index, SS / PBCH index, and PRACH mask index).
[0125] In some implementations, the CSC may include at least one of the following: a field indicating whether CFRA related information exists in the CSC, a field indicating whether NUL or SUL is used, a field indicating an LTM candidate configuration ID that the UE may apply for the LTM execution, a field indicating a TA value, a field indicating the downlink / joint / uplink TCI state ID, a field indicating a differential of security counter value, and a field indicating the CFRA-related information (e.g., preamble index, SS / PBCH index, and PRACH mask index). In some implementations, the CSC may instruct the UE to combine its stored security counter value with the differential of security counter value received in the CSC (e.g., by adding or subtracting the differential of security counter value from the stored security counter value) to obtain a new security counter value to be applied for the target cell.
[0126] In some implementations, the CSC may additionally include a field indicating whether the LTM cell switch is an inter-CU LTM. In some implementations, the field with a value of 1 may indicate an inter-CU LTM, while the field with a value of 0 may indicate an intra-CU LTM. In some implementations, the field with a value of 1 may indicate the intra-CU LTM, while the field with a value of 0 may indicate the inter-CU LTM. In some implementations, the field with a value of ‘T’ (true) may correspond to the inter-CU LTM.
[0127] In some implementations, upon receiving the CSC from the source node, the UE may start the LTM execution procedure. In some implementations, the UE may perform PDCP re-establishment upon identifying an inter-CU LTM.
[0128] In some implementations, the serving RAN may configure the security counter set, which provides the mapping relationship between the security counter set ID (e.g., the securityCellSetID) and the security counter value (e.g., the sk-Counter), in the LTM configuration or conditional reconfiguration. Table 1 below illustrates an example configuration for the security counter set, according to an example implementation of the present disclosure.
[0129] In some implementations, if the CSC includes a field indicating a security counter set ID, the UE may first check whether the stored security counter set ID is equal to the security counter set ID in the received CSC.
[0130] In some implementations, if the stored security counter set ID is equal to the security counter set ID in the received CSC, the UE may consider the LTM as an intra-CU LTM and refrain from performing a security counter update during the LTM execution procedure. If the security counter set ID is absent, the UE may also consider the LTM as an intra-CU LTM.
[0131] In some implementations, if the stored security counter set ID is not equal to the security counter set ID in the received CSC, the UE may consider the LTM as an inter-CU LTM and perform the security counter update during the LTM execution procedure. In some implementations, the UE may select a security counter value from a security counter set associated with the security counter set ID in the received CSC.
[0132] In some implementations, the UE may select the first value from the stored security counter set as the security counter value to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in an RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. In some implementations, the first value selected during this procedure may be removed from the stored security counter set. An updated security set may be generated accordingly, and the updated security counter set may be reused in subsequent LTM implementations.
[0133] In some implementations, the UE may randomly select a value from the stored security counter set as the security counter value to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. In some implementations, the security counter value selected during this procedure may be removed from the stored security counter set.
[0134] In some implementations, the UE may randomly select a value from the stored security counter set, where the selected value is not present in the stored used security counter list associated with the security counter set ID received in the CSC. The UE then may use the selected value as the security counter value in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. In some implementations, the security counter value selected during this procedure may be removed from the stored security counter set.
[0135] In some implementations, the UE may select a value from the stored security counter set based on the stored index associated with the security counter set ID received in the CSC. The UE then may use the selected value as the security counter value in the target node and store the selected security counter value. In some implementations, upon selecting the security counter value, the UE may increase the value of the stored index associated with the security counter set ID by 1. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. In some implementations, the security counter value selected during this procedure may be removed from the stored security counter set.
[0136] In some implementations, it may be up to the UE implementation to select the security counter value corresponding to a security counter set ID indicated in the received CSC. For instance, if the UE determines that a counter value within the counter set may not be appropriate, the UE may select an alternative value outside of the set and indicate this via the RRCReconfigurationComplete message. However, this may introduce additional interruption time due to security information exchange between nodes. To avoid this latency, the UE may select a value from within the indicated set.
[0137] In some implementations, the security counter value in the received security set may not be equal to the security counter value in the stored security set.
[0138] In some implementations, if the CSC includes a field indicating a security counter value, the UE may consider the security counter value in the received CSC as the security counter to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. The UE may implement the security update procedure by using the security counter value indicated by the CSC directly. In some implementations, the indicated security counter value may be removed from the stored security counter set after the security update procedure.
[0139] In some implementations, if the CSC includes a field indicating more than one security counter values, the UE may randomly select a counter value form the security counter values indicated in the received CSC. The UE then may use the selected security counter value in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. The UE may implement the security update procedure by using the security counter value indicated by the CSC directly. In some implementations, the indicated security counter value may be removed from the stored security counter set after the security update procedure.
[0140] In some implementations, if the CSC includes a field indicating a security counter value and the value of the field is not equal to a predefined or specific value (e.g., all ‘0’ or all ‘1’), the UE may consider the security counter value in the received CSC as the security counter to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0141] In some implementations, if the CSC includes a field indicating a security counter value and the value of the field is equal to a predefined or specific value (e.g., all ‘0’ or all ‘1’), the UE may consider the LTM as an intra-CU LTM and refrain from performing the security counter update during the LTM execution procedure. In some implementations, the UE may continuously use the security key that is currently used by the UE if the CSC includes a security counter value.
[0142] In some implementations, if the CSC includes a field indicating an index (e.g., an index value K) of a security counter in the security counter set, the UE may consider the value of the K-th entry of the security counter set, corresponding to the security counter set ID associated with the LTM candidate configuration ID in the received CSC, as the security counter to be used in the target node and store the selected security counter value. The value of K may be derived from the field indicating the index of security counter in the received CSC. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0143] In some implementations, if the CSC includes a field indicating multiple indices of security counters in the security counter set, the UE may randomly select one of the indices (e.g., index value K) from the indices indicated in the received CSC. Then the UE may consider the value of the K-th entry of the security counter set, corresponding to the security counter set ID associated with the LTM candidate configuration ID in the received CSC, as the security counter to be used in the target node and store the selected security counter value. The value of K may be derived from the field indicating the index of security counter in the received CSC. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0144] In some implementations, if the CSC includes a field indicating an index of a security counter and the value of the field is not equal to a predefined or specific value (e.g., all ‘0’ or all ‘1’), the UE may consider the value of the K-th entry of the security counter set, corresponding to the security counter set ID associated with the LTM candidate configuration ID in the received CSC, as the security counter to be used in the target node and store the selected security counter value. The value of K may be derived from the field indicating the index of security counter in the received CSC. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0145] In some implementations, if the CSC includes a field indicating an index of a security counter and the value of the field is equal to a predefined or specific value (e.g., all ‘0’ or all ‘1’), the UE may consider the LTM as an intra-CU LTM and refrain from performing security counter update during the LTM execution procedure.
[0146] In some implementations, if the CSC includes a field indicating a differential of security counter value, the UE may add or subtract the differential of security counter value from the stored security counter value to obtain the security counter value. The UE then may use the security counter value in the target node and store the security counter value. In some implementations, the UE may include the security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure. In some implementations, the CSC may further indicate a reference index of security (e.g., the index-K in the security counter set as a reference of security counter value) and a differential value for the UE to generate an updated security counter value. In addition, the UE may implement the security update procedure based on the updated security counter value. In some implementations, the reference security counter value may be provided in the security counter set.
[0147] In some implementations, the reference security counter value may be removed after the security update procedure. In some implementations, the reference security counter value may not be removed after the security update procedure.
[0148] In some implementations, if the CSC includes a field (e.g., with a 1-bit value of ‘0’ or ‘1’) indicating that the LTM is an inter-CU LTM, the UE may determine that the LTM is an inter-CU LTM. In some implementations, the UE may consider the stored security counter set with a security set ID that is associated with the LTM candidate configuration ID in the received CSC as the security counter set to be applied. The UE may select a security counter value from the considered security counter set. In some implementations, the UE may perform PDCP re-establishment and RLC re-establishment procedures. In some implementations, the LTM candidate configuration may include a security counter set and / or a security counter set ID.
[0149] In some implementations, the UE may select the first value from the stored security counter set as the security counter value to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0150] In some implementations, the UE may randomly select a value from the stored security counter set as the security counter value to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0151] In some implementations, the UE may randomly select a value from the stored security counter set, where the selected value is not present in the stored used security counter list associated with the security counter set ID corresponding to the LTM candidate configuration ID received in the CSC. The UE then may use the selected value as the security counter value in the target node and store the security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0152] In some implementations, the UE may select a value from the stored security counter set based on the stored index associated with the security counter set ID corresponding to the LTM candidate configuration ID received in the CSC. The UE then may use the selected value as the security counter value in the target node and store the selected security counter value. In some implementations, upon selecting the security counter value, the UE may increase the value of the stored index associated with the security counter set ID by 1. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0153] In some implementations, the UE may implement the security update procedure by using the security counter value indicated by the CSC directly or selected by the UE itself. In some implementations, the indicated security counter value may be removed from the stored security counter set (e.g., after the security update procedure).
[0154] In some implementations, the UE may check whether the stored security counter set ID is equal to the security counter set ID associated with the LTM candidate configuration ID received in the CSC.
[0155] In some implementations, if the stored security counter set ID is equal to the security counter set ID associated with the LTM candidate configuration ID in the received CSC, the UE may consider the LTM as an intra-CU LTM and does not perform security counter update during the LTM execution procedure.
[0156] In some implementations, if the stored security counter set ID is not equal to the security counter set ID associated with the LTM candidate configuration ID in the received CSC, the UE may consider the LTM as an inter-CU LTM and perform the security counter update during the LTM execution procedure. In some implementations, the UE may select a security counter value from the security counter set corresponding to the security counter set ID associated with the LTM candidate configuration ID in the received CSC.
[0157] In some implementations, the UE may select the first value from the stored security counter set as the security counter value to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0158] In some implementations, the UE may randomly select a value from the stored security counter set as the security counter value to be used in the target node and store the selected security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0159] In some implementations, the UE may randomly select a value from the stored security counter set, where the selected value is not present in the stored used security counter list associated with the security counter set ID associated with the LTM candidate configuration ID received in the CSC. The UE may then use the selected value as the security counter value in the target node and store the security counter value. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0160] In some implementations, the UE may select a value from the stored security counter set based on the stored index associated with the security counter set ID associated with the LTM candidate configuration ID received in the CSC. The UE then may use the selected value as the security counter value in the target node and store the selected security counter value. In some implementations, upon selecting the security counter value, the UE may increase the value of the stored index associated with the security counter set ID by 1. In some implementations, the UE may include the selected security counter value in the RRCReconfigurationComplete message, which may be transmitted at the end of the LTM execution procedure.
[0161] In some implementations, upon selecting a new security counter value during the LTM execution, the UE may release the stored security counter value from the corresponding stored security counter set, release the stored security counter value, and store the selected security counter value.
[0162] In some implementations, upon selecting a new security counter value during the LTM execution, the UE may store the selected security counter value in the used security counter list associated with the security counter set ID in the received CSC and store the selected security counter value.
[0163] In some implementations, upon selecting a new security counter value during the LTM execution, the UE may store the selected security counter value and release the selected security counter value from the corresponding stored security counter set.
[0164] In some implementations, the UE may implement the security update procedure by using the security counter value indicated by the CSC directly or selected by the UE itself. In some implementations, the indicated security counter value may be removed from the stored security counter set (e.g., after the security update procedure).
[0165] FIG. 1 is a flowchart illustrating a method / process 100 performed by a UE for performing an LTM operation, according to an example implementation of the present disclosure. In the action 102, the process 100 may start by receiving, from a source cell, a first LTM configuration indicating a first target cell and a counter set including multiple counter values. In some implementations, the first LTM configuration may be received via an RRC configuration (e.g., the RRCReconfiguration message).
[0166] In some implementations, an LTM configuration may specify a counter set ID, while the counter values corresponding to the counter set ID may be provided in a separate configuration. The UE may be configured with a first and a second LTM configuration, each associated with a first and a second counter set ID, respectively. Additionally, the UE may be configured with a first and a second counter set configuration, which specify the counter values for the first and second counter set IDs, respectively.
[0167] In the action 104, the process 100 may receive, from the source cell, an LTM CSC indicating the first target cell and a counter index. In some implementations, the LTM CSC may be received via a MAC CE (e.g., the LTM CSC MAC CE). In some implementations, the LTM CSC may include a candidate LTM configuration ID (e.g., for indicating the first target cell), a counter index, a TA command, and a TCI state ID. The LTM CSC MAC CE may instruct the UE to switch from the source cell to the first target cell according to the parameters provided in the LTM CSC MAC CE.
[0168] In the action 106, the process 100 may determine a target counter value based on the counter set and the counter index. In some implementations, the process 100 may select the target counter value from the counter values corresponding to the counter index in response to determining that the counter index is not equal to a predefined value. The process 100 may set the target counter value to a current counter value currently used by the UE in response to determining that the counter index is equal to the predefined value. The predefined value may be 0 or other integer values. For example, the predefined value may correspond to a bit string in which all bits are set to ‘0’ or all bits are set to ‘1’.
[0169] In the action 108, the process 100 may switch from the source cell to the first target cell in response to receiving the LTM CSC. In some implementations, the source cell may belong to a first CU, and the first target cell may belong to a second CU different from the first CU. The LTM operation performed by the UE may be an inter-CU LTM.
[0170] In some implementations, the process 100 may further receive, from the source cell, a second LTM configuration indicating a second target cell and the counter set. The first target cell and the second target cell may both belong to the second CU. The counter set may be common to the first target cell and the second target cell. The counter set indicated in the second LTM configuration may be identical to that indicated in the first LTM configuration. In other words, candidate cells associated with the same CU may be grouped and share the same set of counters. As such, the UE may be preconfigured with a counter (or key) group set on a per-CU basis.
[0171] In the action 110, in response to determining that the counter index is not equal to the predefined value, the process 100 may perform a security update procedure in the first target cell using a security key that is derived from the target counter value. The predefined value may be 0 or other integer values. For example, the UE may refrain from changing the counter value currently used when the counter index received in the LTM CSC is equal to 0. In some implementations, the LTM CSC including a counter index equal to 0 may instruct the UE to perform an intra-CU LTM procedure, where the security update procedure may not be required. The process 100 may then end.
[0172] In some implementations, the process 100 may further transmit, to the first target cell, a reconfiguration complete message indicating the target counter value. For example, the UE may include the target counter value in the RRCReconfigurationComplete message. As such, the NW may identify the target counter value used by the UE.
[0173] The steps / actions shown in FIG. 1 should not be construed as necessarily order dependent. The order in which the process is described is not intended to be construed as a limitation. Moreover, some of the actions shown in FIG. 1 may be omitted in some implementations and one or more actions shown in FIG. 1 may be combined.
[0174] The technical problem addressed by the method illustrated in FIG. 1 is how to perform an LTM operation, particularly how to achieve a security update procedure during an inter-CU LTM operation. In the proposed method above, the UE may be preconfigured with candidate counter values. The UE may initiate an LTM procedure (e.g., an inter-CU LTM) upon receiving an LTM CSC providing a counter index. The UE may select a target counter value based on the counter index provided in the LTM CSC. This method may allow the UE to update its security key using a counter-based mechanism without requiring L3 signaling. By deriving the security key from a target counter value, the UE may seamlessly perform the security update in the new target cell, reducing signaling overhead and improving mobility efficiency. This method may enhance overall network performance, particularly in scenarios with frequent inter-CU mobility transitions.
[0175] FIG. 2 is a flowchart illustrating a method / process 200 performed by a BS for configuring an LTM operation, according to an example implementation of the present disclosure. In the action 202, the process 200 may start by transmitting, via a source cell to the UE, a first LTM configuration indicating a first target cell and a counter set including multiple counter values. In the action 204, the process 200 may and transmit, via the source cell to the UE, an LTM CSC indicating the first target cell and a counter index. The UE may determine a target counter value based on the counter set and the counter index. The UE may switch from the source cell to the first target cell in response to receiving the LTM CSC. In response to determining that the counter index is not equal to a predefined value, the UE may perform a security update procedure in the first target cell using a security key that is derived from the target counter value. The process 200 may then end. The method illustrated in FIG. 2 is similar to that in FIG. 1, except that it is described from the perspective of the BS (instead of the UE).
[0176] FIG. 3 is a block diagram illustrating a node 300 for wireless communication in accordance with various aspects of the present disclosure. As illustrated in FIG. 3, a node 300 may include a transceiver 320, a processor 328, a memory 334, one or more presentation components 338, and at least one antenna 336. The node 300 may also include a radio frequency (RF) spectrum band module, a BS communications module, a network communications module, and a system communications management module, Input / Output (I / O) ports, I / O components, and a power supply (not illustrated in FIG. 3).
[0177] Each of the components may directly or indirectly communicate with each other over one or more buses 340. The node 300 may be a UE or a BS that performs various functions disclosed with reference to FIGS. 1 through 2.
[0178] The transceiver 320 has a transmitter 322 (e.g., transmitting / transmission circuitry) and a receiver 324 (e.g., receiving / reception circuitry) and may be configured to transmit and / or receive time and / or frequency resource partitioning information. The transceiver 320 may be configured to transmit in different types of subframes and slots including, but not limited to, usable, non-usable, and flexibly usable subframes and slot formats. The transceiver 320 may be configured to receive data and control channels.
[0179] The node 300 may include a variety of computer-readable media. Computer-readable media may be any available media that may be accessed by the node 300 and include volatile (and / or non-volatile) media and removable (and / or non-removable) media.
[0180] The computer-readable media may include computer-storage media and communication media. Computer-storage media may include both volatile (and / or non-volatile media), and removable (and / or non-removable) media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules, or data.
[0181] Computer-storage media may include RAM, ROM, EPROM, EEPROM, flash memory (or other memory technology), CD-ROM, Digital Versatile Disks (DVD) (or other optical disk storage), magnetic cassettes, magnetic tape, magnetic disk storage (or other magnetic storage devices), etc. Computer-storage media may not include a propagated data signal. Communication media may typically embody computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave, or other transport mechanisms and include any information delivery media.
[0182] The term “modulated data signal” may mean a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal. Communication media may include wired media, such as a wired network or direct-wired connection, and wireless media, such as acoustic, RF, infrared, and other wireless media. Combinations of any of the above listed components should also be included within the scope of computer-readable media.
[0183] The memory 334 may include computer-storage media in the form of volatile and / or non-volatile memory. The memory 334 may be removable, non-removable, or a combination thereof. Example memory may include solid-state memory, hard drives, optical-disc drives, etc. As illustrated in FIG. 3, the memory 334 may store a computer-readable and / or computer-executable instructions 332 (e.g., software codes) that are configured to, when executed, cause the processor 328 to perform various functions disclosed herein, for example, with reference to FIGS. 1 through 2. Alternatively, the instructions 332 may not be directly executable by the processor 328 but may be configured to cause the node 300 (e.g., when compiled and executed) to perform various functions disclosed herein.
[0184] The processor 328 (e.g., having processing circuitry) may include an intelligent hardware device, e.g., a Central Processing Unit (CPU), a microcontroller, an ASIC, etc. The processor 328 may include memory. The processor 328 may process the data 330 and the instructions 332 received from the memory 334, and information transmitted and received via the transceiver 320, the baseband communications module, and / or the network communications module. The processor 328 may also process information to send to the transceiver 320 for transmission via the antenna 336 to the network communications module for transmission to a CN.
[0185] One or more presentation components 338 may present data indications to a person or another device. Examples of presentation components 338 may include a display device, a speaker, a printing component, a vibrating component, etc.
[0186] In view of the present disclosure, it is obvious that various techniques may be used for implementing the disclosed concepts without departing from the scope of those concepts. Moreover, while the concepts have been disclosed with specific reference to certain implementations, a person of ordinary skill in the art may recognize that changes may be made in form and detail without departing from the scope of those concepts. As such, the disclosed implementations are to be considered in all respects as illustrative and not restrictive. It should also be understood that the present disclosure is not limited to the particular implementations disclosed and many rearrangements, modifications, and substitutions are possible without departing from the scope of the present disclosure.
Claims
1. A User Equipment (UE) for performing a Layer1 / Layer2 Triggered Mobility (LTM) operation, the UE comprising: at least one processor; and at least one non-transitory computer-readable medium coupled to the at least one processor and storing one or more computer-executable instructions that, when executed by the at least one processor, cause the UE to: receive, from a source cell, a first LTM configuration indicating a first target cell and a counter set comprising a plurality of counter values; receive, from the source cell, an LTM cell switch command (CSC) indicating the first target cell and a counter index; determine a target counter value based on the counter set and the counter index; switch from the source cell to the first target cell in response to receiving the LTM CSC; and in response to determining that the counter index is not equal to a predefined value, perform a security update procedure in the first target cell using a security key that is derived from the target counter value.
2. The UE of claim 1, wherein: receiving the first LTM configuration comprises receiving the first LTM configuration via a Radio Resource Control (RRC) configuration, and receiving the LTM CSC comprises receiving the LTM CSC via a Medium Access Control (MAC) Control Element (CE).
3. The UE of claim 1 wherein the one or more computer-executable instructions, when executed by the at least one processor, further cause the UE to: transmit, to the first target cell, a reconfiguration complete message indicating the target counter value.
4. The UE of claim 1 wherein: the source cell belongs to a first central unit (CU), and the first target cell belongs to a second CU different from the first CU.
5. The UE of claim 4, wherein the one or more computer-executable instructions, when executed by the at least one processor, further cause the UE to: receive, from the source cell, a second LTM configuration indicating a second target cell and the counter set, wherein: the first target cell and the second target cell both belong to the second CU, and the counter set is common to the first target cell and the second target cell.
6. The UE of claim 1, wherein determining the target counter value based on the counter set and the counter index comprises: in response to determining that the counter index is not equal to the predefined value, selecting the target counter value from the plurality of counter values corresponding to the counter index; and in response to determining that the counter index is equal to the predefined value, setting the target counter value to a current counter value currently used by the UE.
7. The UE of claim 1, wherein the predefined value is 0.
8. A Base Station (BS) for configuring a Layer1 / Layer2 Triggered Mobility (LTM) operation, the BS comprising: at least one processor; and at least one non-transitory computer-readable medium coupled to the at least one processor and storing one or more computer-executable instructions that, when executed by the at least one processor, cause the BS to: transmit, via a source cell to the UE, a first LTM configuration indicating a first target cell and a counter set comprising a plurality of counter values; and transmit, via the source cell to the UE, an LTM cell switch command (CSC) indicating the first target cell and a counter index, wherein the UE: determines a target counter value based on the counter set and the counter index; switches from the source cell to the first target cell in response to receiving the LTM CSC; and in response to determining that the counter index is not equal to a predefined value, performs a security update procedure in the first target cell using a security key that is derived from the target counter value.
9. The BS of claim 8, wherein: transmitting the first LTM configuration comprises transmitting the first LTM configuration via a Radio Resource Control (RRC) configuration, and transmitting the LTM CSC comprises transmitting the LTM CSC via a Medium Access Control (MAC) Control Element (CE).
10. The BS of claim 8, wherein the UE further transmits, to the first target cell, a reconfiguration complete message indicating the target counter value.
11. The BS of claim 8, wherein: the source cell belongs to a first central unit (CU), and the first target cell belongs to a second CU different from the first CU.
12. The BS of claim 11, wherein the one or more computer-executable instructions, when executed by the at least one processor, further cause the BS to: transmit, via the source cell to the UE, a second LTM configuration indicating a second target cell and the counter set, wherein: the first target cell and the second target cell both belong to the second CU, and the counter set is common to the first target cell and the second target cell.
13. The BS of claim 8, wherein: the UE selects the target counter value from the plurality of counter values corresponding to the counter index in response to determining that the counter index is not equal to the predefined value; and the UE sets the target counter value to a current counter value currently used by the UE in response to determining that the counter index is equal to the predefined value.
14. The BS of claim 8, wherein the predefined value is 0.
15. A method performed by a User Equipment (UE) for performing a Layer1 / Layer2 Triggered Mobility (LTM) operation, the method comprising: receiving, from a source cell, a first LTM configuration indicating a first target cell and a counter set comprising a plurality of counter values; receiving, from the source cell, an LTM cell switch command (CSC) indicating the first target cell and a counter index; determining a target counter value based on the counter set and the counter index; switching from the source cell to the first target cell in response to receiving the LTM CSC; and in response to determining that the counter index is not equal to a predefined value, performing a security update procedure in the first target cell using a security key that is derived from the target counter value.