Security procedure for subsequent LTM and failure recovery
By forwarding next hop chaining counter values through medium access control signaling, the patent addresses the challenge of secure Layer 1/Layer 2 mobility handovers in wireless communication, ensuring fresh security keys are used for seamless and secure transitions between base stations.
Patent Information
- Application Number
- PCT/EP2025/053421
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-01
- Filing Date
- 2025-02-10
- Publication Date
- 2025-10-09
AI Technical Summary
Existing wireless communication systems face challenges in seamlessly handing over user equipment (UE) between base stations while maintaining security, particularly during Layer 1/Layer 2 triggered mobility (LTM) without radio resource control reconfiguration.
Forwarding next hop chaining counter values to UEs via medium access control layer signaling, allowing for secure key generation procedures during LTM, including indications for intra-access node handover and radio link failure recovery.
Enables secure and seamless handovers by ensuring fresh security keys are used, enhancing security and reducing the need for RRC reconfiguration during LTM, thus maintaining communication integrity.
Smart Images

Figure EP2025053421_09102025_PF_FP_ABST
Abstract
Description
SECURITY PROCEDURE FOR SUBSEQUENT LTM AND FAILURE RECOVERYTECHNICAL FIELD
[0001] Various example embodiments generally relate to the field of wireless communication. Some example embodiments relate to a security procedure for subsequent Layer 1 / Layer 2 triggered mobility (LTM), and further, for failure recovery during LTM procedures.BACKGROUND
[0002] In wireless communications, seamless handover with security provision is desirable. In 5G, handover procedures typically involve a user equipment (UE), base stations such as gNBs, and the access and mobility management function (AMF). When the UE moves from current gNB to another gNB, a handover is triggered during which the UE and gNBs can be configured to conduct mutual authentication and key agreement.SUMMARY
[0003] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0004] Example embodiments of the present disclosure enable forwarding next hop chaining counter values to UEs without using radio resource control reconfiguration. This and other benefits may be achieved by the features of the independent claims. Further example embodiments are provided in the dependent claims, the description, and the drawings.
[0005] According to a first aspect, an apparatus for user equipment is disclosed. The apparatus may comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from a distributed unit of an access node of a serving cell of the user equipment, a next hop chaining counter value for a subsequent Layer 1 / Layer 2 triggered mobility procedure via medium access control layer signalling; and determine a security key generation procedure to be applied for the subsequent Layer 1 / Layer 2 triggered mobility procedure based on the received next hop chaining counter value.
[0006] According to an example embodiment of the first aspect, the next hop chaining counter value is received in at least one of a cell switch command or in a separate message received before a cell switch command from the distributed unit.
[0007] According to an example embodiment of the first aspect, the apparatus is further caused to receive, from the distributed unit of the access node via medium access control layer signalling, an indication whether or not the received next hop chaining counter value is to be used by the user equipment for intra-access node handover; and determine the security key generation procedure for the next intra-access node handover based on the received indication.
[0008] According to an example embodiment of the first aspect, at least one of the cell switch command or the separate message further comprises the indication whether or not to use the received next hop chaining counter value for intra-access node handover.
[0009] According to an example embodiment of the first aspect, the apparatus is further caused to: receive, from the distributed unit of the access node via medium access control layer signalling, an indication to use one of the following in case of a radio link failure recover: a latest security key of the serving cell or a new security key generated for the serving cell; and determine the security key generation procedure based on the received indication for radio link failure recovery.
[0010] According to an example embodiment of the first aspect, at least one of the cell switch command or the separate message further comprises the indication to use one of the latest security key of the serving cell or the new security key generated for the serving cell in case of a radio link failure recovery.
[0011] According to an example embodiment of the first aspect, the medium access control signalling comprises a medium access control, MAC, control element.
[0012] According to an example embodiment of the first aspect, the apparatus is further caused to detect a radio link failure; select a candidate cell for failure recovery based on the detected radio link failure; and initiate the subsequent mobility procedure to the selected candidate cell for failure recovery, wherein a security key for the mobility procedure is updated based on the determined security key generation procedure.
[0013] According to a second aspect, a method is disclosed. The method may comprise: receiving, from a distributed unit of an access node of a serving cell of the user equipment, a next hop chaining counter value for a subsequent Layer 1 / Layer 2 triggered mobility procedure via medium access control layer signalling; and determining a security keygeneration procedure to be applied for the subsequent Layer 1 / Layer 2 triggered mobility procedure based on the received next hop chaining counter value.
[0014] According to an example embodiment of the second aspect, the next hop chaining counter value is received in at least one of a cell switch command or in a separate message received before a cell switch command from the distributed unit.
[0015] According to an example embodiment of the second aspect, the method may comprise receiving, from the distributed unit of the access node via medium access control layer signalling, an indication whether or not the received next hop chaining counter value is to be used by the user equipment for intra-access node handover; and determining the security key generation procedure for the next intra-access node handover based on the received indication.
[0016] According to an example embodiment of the second aspect, at least one of the cell switch command or the separate message further comprises the indication whether or not to use the received next hop chaining counter value for intra-access node handover.
[0017] According to an example embodiment of the second aspect, the method further comprises receiving, from the distributed unit of the access node via medium access control layer signalling, an indication to use one of the following in case of a radio link failure recover: a latest security key of the serving cell or a new security key generated for the serving cell; and determining the security key generation procedure based on the received indication for radio link failure recovery.
[0018] According to an example embodiment of the second aspect, at least one of the cell switch command or the separate message further comprises the indication to use one of the latest security key of the serving cell or the new security key generated for the serving cell in case of a radio link failure recovery.
[0019] According to an example embodiment of the second aspect, the medium access control signalling comprises a medium access control, MAC, control element.
[0020] According to an example embodiment of the second aspect, the method comprises detecting a radio link failure; selecting a candidate cell for failure recovery based on the detected radio link failure; and initiating the subsequent mobility procedure to the selected candidate cell for failure recovery, wherein a security key for the mobility procedure is updated based on the determined security key generation procedure.
[0021] According to a third aspect, an apparatus for distributed unit is disclosed. The apparatus may comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to receive,from a centralized unit of an access node, a message comprising a next hop chaining counter value; update, based on the received next hop chaining counter value, a next hop chaining counter value stored at a distributed unit of the access node associated with a serving cell of the user equipment; and transmit, to the user equipment, the updated next hop chaining counter value via a medium access control layer signalling for a subsequent Layer 1 / Layer 2 triggered mobility procedure.
[0022] According to an example embodiment of the third aspect, the message comprises at least one of a user equipment context setup request or a user equipment context modification request.
[0023] According to an example embodiment of the third aspect, the apparatus is further caused to receive, from the centralized unit of the access node, an indication whether the received next hop chaining counter value is to be used by the user equipment for intra-access node handover; and transmit, to the user equipment, the indication via a medium access control layer signalling.
[0024] According to an example embodiment of the third aspect, the apparatus is caused to receive, from the centralized unit of the access node, an indication for the user equipment to use one of a latest security key of the serving cell or to generate a new security key for the serving cell for radio link failure recovery; and transmit, to the user equipment, the received indication via medium access control signalling
[0025] According to an example embodiment of the third aspect, the medium access control layer signalling comprises a medium access control, MAC, control element.
[0026] According to an example embodiment of the third aspect, the medium access control layer signalling comprises at least one of: a cell switch command; or a separate message before a cell switch command transmitted by the distributed unit.
[0027] According to a fourth aspect, a method is disclosed. The method may comprise receiving, from a centralized unit of an access node, a message comprising a next hop chaining counter value; updating, based on the received next hop chaining counter value, a next hop chaining counter value stored at a distributed unit of the access node associated with a serving cell of the user equipment; and transmitting, to the user equipment, the updated next hop chaining counter value via a medium access control layer signalling for a subsequent Layer 1 / Layer 2 triggered mobility procedure.
[0028] According to an example embodiment of the fourth aspect, the message comprises at least one of a user equipment context setup request or a user equipment context modification request.
[0029] According to an example embodiment of the fourth aspect, the method comprises receiving, from the centralized unit of the access node, an indication whether the received next hop chaining counter value is to be used by the user equipment for intra-access node handover; and transmitting, to the user equipment, the indication via a medium access control layer signalling.
[0030] According to an example embodiment of the fourth aspect, the method comprises receiving, from the centralized unit of the access node, an indication for the user equipment to use one of a latest security key of the serving cell or to generate a new security key for the serving cell for radio link failure recovery; and transmitting, to the user equipment, the received indication via medium access control signalling
[0031] According to an example embodiment of the fourth aspect, the medium access control layer signalling comprises a medium access control, MAC, control element.
[0032] According to an example embodiment of the fourth aspect, the medium access control layer signalling comprises at least one of: a cell switch command; or a separate message before a cell switch command transmitted by the distributed unit.
[0033] According to a fifth aspect, an apparatus for centralized unit is disclosed. The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: determine that a next hop chaining counter value stored at a centralized unit of an access node is updated; and transmit, to a distributed unit of the access node associated with a serving cell of a user equipment, a message comprising the determined next hop chaining counter value to be forwarded by the distributed unit to the user equipment for a subsequent LI / L2 triggered mobility procedure.
[0034] According to an example embodiment of the fifth aspect, the apparatus is further caused to determine whether the next hop chaining counter value is to be used by the user equipment for intra-access node handover; and transmit, to the distributed unit, an indication of whether the next hop chaining counter value is to be used by the user equipment for a next intra-access node handover based on the determination.
[0035] According to an example embodiment of the fifth aspect, the apparatus is caused to determine one of a latest security key of the serving cell or a new security key generated by the user equipment for the serving cell to be used by the user equipment in case of a radio link failure recovery; and transmit, to the distributed unit, an indication for the equipment to use one of the latest security key of the serving cell or to generate the new security key for the serving cell in case of a radio link failure recovery based on the determination.
[0036] According to an example embodiment of the fifth aspect, at least one of the next hop chaining counter value, the indication whether to use the next hop chaining counter for the next intra-access node handover, or the indication to use one of the latest key or the new generated key is transmitted in at least one of a user equipment context setup request message or a user equipment context modification request message.
[0037] According to a sixth aspect, a method is disclosed. The method comprises determining that a next hop chaining counter value stored at a centralized unit of an access node is updated; and transmitting, to a distributed unit of the access node associated with a serving cell of a user equipment, a message comprising the determined next hop chaining counter value to be forwarded by the distributed unit to the user equipment for a subsequent LI / L2 triggered mobility procedure.
[0038] According to an example embodiment of the sixth aspect, method comprises determining whether the next hop chaining counter value is to be used by the user equipment for intra-access node handover; and transmitting, to the distributed unit, an indication of whether the next hop chaining counter value is to be used by the user equipment for a next intra-access node handover based on the determination.
[0039] According to an example embodiment of the sixth aspect, the method comprises determining one of a latest security key of the serving cell or a new security key generated by the user equipment for the serving cell to be used by the user equipment in case of a radio link failure recovery; and transmitting, to the distributed unit, an indication for the equipment to use one of the latest security key of the serving cell or to generate the new security key for the serving cell in case of a radio link failure recovery based on the determination.
[0040] According to an example embodiment of the sixth aspect, at least one of the next hop chaining counter value, the indication whether to use the next hop chaining counter for the next intra-access node handover, or the indication to use one of the latest key or the new generated key is transmitted in at least one of a user equipment context setup request message or a user equipment context modification request message.
[0041] According to a seventh aspect, an apparatus is disclosed. The apparatus may comprise means for performing the method according to the second, fourth, or sixth aspect, or any example embodiment(s) thereof, as provided in the description and / or the claims.
[0042] According to an eight aspect, a computer program, a computer program product, or a (non-transitory) computer-readable medium is disclosed. The computer program, computer program product, or (non-transitory) computer-readable medium may comprise instructions, which when executed by an apparatus, cause the apparatus at least to perform the methodaccording to the second, fourth, or sixth aspect, or any example embodiment(s) thereof, as provided in the description and / or the claims.
[0043] Example embodiments of the present disclosure can thus provide apparatuses, methods, computer programs, computer program products, or computer readable media for improving various aspects of wireless tethering. Any example embodiment may be combined with one or more other example embodiments. These and other aspects of the present disclosure will be apparent from the example embodiment(s) described below. According to some aspects, there is provided the subject matter of the independent claims. Some further aspects are defined in the dependent claims.DESCRIPTION OF THE DRAWINGS
[0044] The accompanying drawings, which are included to provide a further understanding of the example embodiments and constitute a part of this specification, illustrate example embodiments and, together with the description, help to explain the example embodiments. In the drawings:
[0045] FIG. 1 illustrates an example of a communication network;
[0046] FIG. 2 illustrates an example of an apparatus configured to practice one or more example embodiments;
[0047] FIG. 3 illustrates an example of signalling and operations for security procedure for subsequent LTM;
[0048] FIG. 4 illustrates another example of signalling and operations for security procedure for subsequent LTM and failure recovery;
[0049] FIG. 5 illustrates an example of a method for security procedure for subsequent LTM.
[0050] FIG. 6 illustrates an example of another method for security procedure for subsequent LTM.
[0051] Like references are used to designate like parts in the accompanying drawings.DETAILED DESCRIPTION
[0052] Reference will now be made in detail to example embodiments, examples of which are illustrated in the accompanying drawings. The detailed description provided below in connection with the appended drawings is intended as a description of the present examples and is not intended to represent the only forms in which the present example may beconstructed or utilized. The description sets forth the functions of the example and the sequence of steps for constructing and operating the example. However, the same or equivalent functions and sequences may be accomplished by different examples.
[0053] FIG. 1 illustrates an example of a communication network. Communication network 100 may comprise one or more access nodes, such as access nodes 104, 106 and / or 108. Access node(s) 104, 106, 108 may be part of a radio access network (RAN) configured to enable a mobile device, represented throughout the description by UE 102, to access communication services provided by core network (CN) 110. In connection with communication network 100, access node(s) 104, 106, 108 and core network 110 may be collectively referred to as the ‘network’. UE 102 may comprise a user device, a user node, a mobile device, or the like. UE 102 may be configured to communicate with access node(s) 104, 106 and / or 108 over a radio interface, which may be also referred to as an air interface. Access nodes 104, 106, 108 may be also referred to as network devices.
[0054] The radio interface may be configured for example based on the 5G NR (New Radio) standard defined by the 3rdGeneration Partnership Project (3 GPP), or any future standard or technology (e.g., 6G). Access nodes 104, 106, 108 may comprise, for example, 5thgeneration access nodes (gNB). Transmission by an access node to UE 102 may be called downlink (DL) transmission. Transmission by UE 102 to an access node may be called uplink (UL) transmission. UE 102 may be therefore configured to operate as a transmitter for uplink transmissions and as a receiver for downlink transmissions. Access node(s) 104, 106, 108 may be configured to operate as a receiver for uplink transmissions and as a transmitter for downlink transmissions. Communication network 100 may comprise a wireless communication network or a mobile communication network, such as for example a cellular communication network.
[0055] Core network 110 may be implemented with various network functions (NF), including, for example, one or more user plane functions (UPF) and one or more access and mobility management functions (AMF). A UPF may be configured to handle user data part of a communication session. A UPF may thus provide an interconnect point between the radio access network and a data network configured to provide application services to UE 102 via core network 110 and the radio access network. An AMF may be configured to receive connection and session request related data from UE 110 (e.g., via an access node). An AMF may be configured to control connection and mobility management in communication network 100.
[0056] An access node 104, 106, 108 may be configured to communicate with UEs via one or more cells. For example, access node 104 may be configured to serve UEs at cell 112. Access node 106 may be configured to serve UEs at cell 114. Access node 108 may be configured to serve UEs at cell 116. An access node may be configured to serve one or more cells, although only one cell associated with each of the access nodes is depicted in FIG. 1. A cell may be configured to serve UEs at a certain geographical area at a certain radio frequency, or, a range of radio frequencies around a centre frequency of the cell. During a handover process, specific cells may be referred to as a serving cell and a target cell. The serving cell may refer to an access node, and associated cell, that currently serves a particular UE. The UE may be currently connected and communicating with the serving cell. The target cell may refer to an access node, and associated cell, to which the UE is expected to handover during a mobility event, such as a handover triggered by movement or network conditions. Once the handover is completed successfully, the target cell becomes the new serving cell for the UE, and the UE continues its communication with the network through the target cell.
[0057] A UE can be configured to perform measurements on neighbor (target) or serving cells for mobility purposes. The configured measurements can be, for example, L3 (Layer 3) measurements, which enable the network to make a decision about L3 handover, or LI (Layer 1) measurements, which enable the network to make a decision about L1 / L2 (Layer 1 / Layer 2) triggered mobility (LTM). LTM is also known as lower layer triggered mobility. The UE reports the measurements to the network based on a measurement reporting configuration, which may be e.g. periodic or event-triggered. The network can make the handover, or a cell switch, decision based on the reported measurements and command the UE to perform a handover / cell switch to a selected target cell.
[0058] Communication network 100 may be operated based on a protocol stack comprising a plurality of protocol layers. The protocol stack may be arranged based on the open systems interconnection (OSI) model or a layer model of a particular standard such as 3GPP 5GNR. As one example, the protocol stack may comprise a service data adaptation protocol (SDAP) layer, which may receive data from an application layer for transmission. The SDAP layer may be configured to exchange data with the packet data convergence (PDCP) layer. The PDCP layer may be responsible of generation of data bursts comprising one or more data packets, for example based on data obtained from the SDAP layer.
[0059] The PDCP layer may provide data to one or more instances of the radio link control (RLC) layer. Each RLC instance may be associated with corresponding medium access control (MAC) instances of the MAC layer. The MAC layer may provide a mapping betweenlogical channels of upper layer(s) and transport channels of the physical layer, handle multiplexing and demultiplexing of MAC service data units (SDU). Furthermore, the MAC layer may provide error correction functionality based on packet retransmissions, for example according to the hybrid automatic repeat request (HARQ) process. RLC and / or MAC layer may be referred to as Layer 2 (L2). Physically separate transmission legs may be provided by the physical (PHY) layer, also known as the Layer 1 (LI). Corresponding protocol stacks may be applied both at access nodes 104, 106, 108 and UE 102. A UE may be configured to perform mobility measurements based on lower layers of the protocol stack, for example RLC, MAC, and LI. A radio resource control (RRC) layer of the protocol stack may be configured to manage configuration, connection, and release of radio resources. The RRC layer may be also referred to as Layer 3. LI and L3 measurements may comprise parameters related to wireless channel conditions, such as signal strength, signal-to-noise ratio (SNR), channel quality indicators (CQI).
[0060] In a split access node architecture, part of the protocol layers may be implemented at a centralized unit (CU) of an access node, e.g., a gNB-CU, which may be configured to handle upper layers of the protocol stack, for example SDAP and PDCP layers. Furthermore, the centralized unit may be configured to handle radio resource control (RRC) operations. A centralized unit of an access node may be associated with, e.g., configured to control, one or more distributed units (DU) of the access node, e.g., gNB-DU, which may be configured to handle lower layers of the protocol stack, for example RLC, MAC, and LI. Radio unit(s) of the distributed unit(s) may be configured to transmit / receive data to / from UE(s) over the radio interface. A central unit may be referred to as a central node and a distributed unit may be referred to as a distributed node. The gNB-CU and gNB-DU may be connected via a Fl interface. Each DU and each CU may be associated with one or more cells of the gNB. A distributed unit located at a serving cell of the UE may be referred to as a serving DU. A centralized unit located at, or associated with a DU located at, a serving cell may be referred to as a serving CU.
[0061] A gNB may initiate establishment of a context for communication between a UE and the network with an initial UE context setup message. For example, a gNB-CU may initiate the procedure by sending UE context setup request message to a gNB-DU. If the gNB-DU succeeds to establish the UE context, the gNB-DU may reply to the gNB-CU with UE context setup response. If no UE-associated logical Fl -connection exists, the UE- associated logical Fl -connection may be established as part of the procedure.
[0062] For example, the UE context setup message may include PDU session context, the security key, mobility restriction list, UE radio capability, UE security capabilities, and other configured information. The UE context setup message may be transmitted using the Fl Application Protocol (F1AP). The F1AP refers to a protocol for transmitting and receiving data using the Fl interface.
[0063] When the established UE context is to be modified, e.g., establishing, modifying and / or releasing radio resources, a F1AP UE context modification request may be initiated by the gNB-CU to the gNB-DU.
[0064] For secure handover, a key management scheme based on horizontal and vertical key derivation is designed. An access stratum security context may be based on a horizontal key derivation or a vertical key derivation. For both horizontal and vertical key derivation, PCI (physical cell identity) and DL (downlink) frequency may be used. In horizontal key derivation, use of a previous key that has already been used once for key generation may be continued. In vertical key derivation, a key refresh may be performed through use of a new NH (next hop) parameter value. NH is an intermediate key used to derive a session key in vertical key derivation. The vertical key derivation is used to separate key space of each RAN node. The NH value may be provided to the RAN node by the AMF. The vertical keys generated by each RAN node may use a fresh NH value provided by AMF. Thus, the security domain may be detached from the previous RAN node. A main difference between these options (horizontal / vertical key derivation) is that forward security may be only provided by vertical key derivation. In both options, a newly derived intermediate session key, KgNB* may become the new session key after the handover is completed. A key may refer to a security key, such as a session key.
[0065] A UE may be instructed on how to generate the key by indicating the NCC value to the UE after each cell change. The NCC value may be indicated by a gNB in a handover command. However, in case of a LTM dynamic switching via MAC CE cell switch command, candidate cell configurations may be re-used without a new RRC reconfiguration after cell change. In this case, the same NCC value would be used over and over and only horizontal key derivation would be possible. This should be avoided for security reasons to provide different gNBs a new key with a new NH value.
[0066] According to an example embodiment, a serving DU may be configured to transmit a next hop chaining counter (NCC) value to a UE via MAC layer signalling. The definition of the NCC may follow the 3GPP specifications: NCC is a counter related to the NH, i.e. the amount of Key chaining that has been performed, which allows the UE to be synchronisedwith the gNB and to determine whether the next KeNB* needs to be based on the current KeNB or a refreshed NH. The NCC value may be transmitted, for example, in a cell switch command. Alternatively, the NCC value may be transmitted before a cell switch command in a dedicated, separate message, such as in a MAC CE (control element). Hence, the NCC value may be indicated to the UE without a RRC reconfiguration or a handover command. Further, when the NCC is indicated to the UE before a handover / cell switch, the UE is able to perform LTM recovery by using the NCC value in case of a radio link failure, wherein the handover / cell switch command may not be received by the UE.
[0067] In an example embodiment, the NCC value to be forwarded by the DU to the UE may be received by the DU from the CU during at least one of a handover preparation procedure or after a path switch procedure. For example, the CU may be configured to transmit the NCC value to the DU in a DL transfer message. The DL transfer message may comprise, for example, at least one of a UE context setup request or a UE context modification request. The NCC may be transmitted by the CU together with one or more additional indications to be forwarded to the UE. The one or more indications may be related to security key derivation to be performed by the UE. Further, the DU may be configured to forward the received indications to the UE via MAC layer signalling, such as in the MAC CE message comprising the NCC value.
[0068] According to an example embodiment, a UE may be configured to determine a security key generation procedure, e.g. which one of the vertical and horizontal key derivation, to be applied for a subsequent LTM mobility procedure based on a NCC value received from a serving DU via MAC layer signalling. The MAC layer signalling may further comprise one or more indications related to the determination of the security key generation procedures, and the UE may be further configured to determine the security key generation procedure to be applied based on the one or more indications.
[0069] Communication network 100 may comprise other network function(s), network device(s), or protocol(s), in addition, or alternative to, those illustrated in FIG. 1. A network device may be configured to implement functionality of one or more network functions. Even though some embodiments have been described in the context of 5G, it is appreciated that embodiments of the present disclosure are not limited to this example network. Example embodiments may be therefore applied in any present or future communication networks. An apparatus, such as for example UE 102 or access node 104, may comprise, or be configured to implement, e.g., by means of software, one or more of the protocol layers described herein.
[0070] FIG. 2 illustrates an example of an apparatus configured to practice one or more example embodiments. Apparatus 200 may comprise a mobile device such as UE 102, or an access node 104, 106, 108, an access point, a base station, a radio network node, or a split portion thereof (e.g., a centralized unit or distributed unit of an access node), a network device, or in general any apparatus configured to implement functionality described herein. In another embodiment, the apparatus is comprised in the UE 102, access node 104, 106, 108, etc. The apparatus may be, for example, a chipset for the respective entity of the cellular communication network.
[0071] Apparatus 200 may comprise at least one processor 202. The at least one processor 202 may comprise, for example, one or more of various processing devices, such as for example a co-processor, a microprocessor, a controller, a digital signal processor (DSP), a processing circuitry with or without an accompanying DSP, or various other processing devices including integrated circuits such as, for example, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a microcontroller unit (MCU), a hardware accelerator, a special-purpose computer chip, or the like.
[0072] Apparatus 200 may further comprise at least one memory 204. The memory 204 may be configured to store, for example, computer program code or the like, for example operating system software and application software. Memory 204 may comprise one or more volatile memory devices, one or more non-volatile memory devices, and / or a combination thereof. For example, the memory may be embodied as magnetic storage devices (such as hard disk drives, magnetic tapes, etc.), optical magnetic storage devices, or semiconductor memories (such as mask ROM, PROM (programmable ROM), EPROM (erasable PROM), flash ROM, RAM (random access memory), etc.). Memory 204 is provided as an example of a (non-transitory) computer readable medium. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0073] Apparatus 200 may further comprise a communication interface 208 configured to enable apparatus 200 to transmit and / or receive information. Communication interface 208 may comprise an external communication interface, such as for example a radio interface between UE 102 and access node(s) 104, 106, 108, or a communication interface between a centralized unit and distributed unit(s) of an access node (e.g., a Fl interface). Communication interface 208 may comprise one or more radio transmitters or receivers, which may be coupled to one or more antennas or apparatus 200, or be configured to be coupled to one or more antennas external to apparatus 200.
[0074] Apparatus 200 may further comprise other components and / or functions such as a user interface (not shown) comprising at least one input device and / or at least one output device. The input device may take various forms such a keyboard, a touch screen, or one or more embedded control buttons. The output device may for example comprise a display, a speaker, or the like.
[0075] When apparatus 200 is configured to implement some functionality, some component and / or components of apparatus 200, such as for example the at least one processor 202 and / or the at least one memory 204, may be configured to implement this functionality. Furthermore, when the at least one processor 202 is configured to implement some functionality, this functionality may be implemented using program code 206 comprised, for example, in the at least one memory 204.
[0076] The functionality described herein may be performed, at least in part, by one or more computer program product components such as software components. According to an example embodiment, apparatus 200 comprises a processor or processor circuitry, such as for example a microcontroller, configured by the program code 206, when executed, to execute the embodiments of the operations and functionality described herein. Program code 206 is provided as an example of instructions which, when executed by the at least one processor 202, cause performance of apparatus 200.
[0077] Alternatively, or in addition, the functionality described herein can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include field- programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip systems (SOCs), complex programmable logic devices (CPLDs), graphics processing units (GPUs), or the like.
[0078] Apparatus 200 may be configured to perform, or cause performance of, method(s) described herein or comprise means for performing method(s) described herein. In one example, the means comprises the at least one processor 202, the at least one memory 204 including instructions (e.g., program code 206) configured to, when executed by the at least one processor 202, cause apparatus 300 to perform the method(s). In general, computer program instructions may be executed on means providing generic processing functions. Such means may be embedded for example in a personal computer, a smart phone, a network device, or the like. The method(s) may be thus computer-implemented, for example, based on algorithm(s) executable by the generic processing functions, an example of which is the at least one processor 202. The means may comprise transmission or reception means, forexample one or more radio transmitters or receivers, which may be coupled or be configured to be coupled to one or more antennas. Apparatus 200 may comprise, for example, a network device, for example, an access node, an access point, a base station, or a central / distributed unit thereof. Although apparatus 200 is illustrated as a single device, it is appreciated that, wherever applicable, functions of apparatus 200 may be distributed to a plurality of devices.
[0079] FIG. 3 illustrates an example of signalling and operations configured for a security procedure for subsequent LTM. The security procedure may be performed between a UE, such as UE 102, and one or more access nodes, such as access node 104, 106 and / or 108, and CN, depicted by AMF 308. Each access node may comprise a centralized unit and one or more distributed units. A first access node may comprise a centralized unit 302 coupled with a distributed unit 300. A second access node may comprise a centralized unit 306 coupled with a distributed unit 304. The UE 102 may be configured to support multi radio dual connectivity, and the first access node may be, for example, a source master node (MN1). The second access node may be, for example, a target master node (MN2). A master node may be configured to provide control plane connection to the core network.
[0080] During initial access / PDU (packet data unit) session setup, at operation 310, the UE 102 may be registered with the core network (AMF 308) via gNB(s) and a PDU session is established to provide a data path between the UE 102 and the core network.
[0081] At operation 312, a handover preparation procedure may be performed. The handover preparation may be associated to LTM mobility procedure. Further, a serving CU, e.g. CU 302, of the UE 102 may be configured to determine a NCC value. For example, the serving CU 302 may be configured to update the NCC value to a certain value, such as NCC=0. The CU 302 may then share the updated NCC value with LTM candidate target cells for handover. The CU 302 may further inform the UE 102 of configuration of one or multiple LTM candidate target cells, for example, in a RRC reconfiguration message.
[0082] Further, at operation 312, the serving CU 302 may be configured to transmit the NCC value to the serving DU 300 to be forwarded to the UE 102. The NCC value may be transmitted, for example, in a DL transfer message. For example, the NCC value may be transmitted by the CU 302 to the DU 300 via a UE context related message. The UE context related message may be transmitted via UE context setup procedure or UE context modification procedure performed between the CU 302 and the DU 300. The NCC value may be included by the CU 302, for example, in a UE context setup request during establishment of UE context and / or in UE context modification request when changes to theestablished UE context are being made. The UE context related message may be transmitted using a Fl application protocol (F1AP).
[0083] In one example, the serving CU 302 may determine if the UE 102 should use the transmitted NCC value in case of an intra-gNB handover. The serving CU 302 may be configured to transmit an indication whether or not the UE 102 should use the NCC for intra- gNB handover based on the determination. For example, the indication may be included in the UE context setup request or the UE context modification request sent to the DU. In one example, the indication may be included as an indication flag. For example, when the indication flag is configured to true, the UE 102 may be instructed to use vertical key derivation as the selected security key generation procedure for the intra-gNB handover, and when the indication flag is configured to false, the UE 102 may be instructed to use horizontal key derivation as the selected security key generation procedure for the intra-gNB handover, or vice versa.
[0084] In addition, or alternatively, the serving CU 302 may determine if a new key should be used for failure recovery by the UE 102 or if the UE 102 should re-use a latest key in case of a failure recovery. The failure may refer to at least one of a radio link failure or LTM failure, for example, when the UE 102 fails to receive a cell switch command from the serving DU 300. The failure recovery may refer to a procedure during which the UE 102 initiates a handover / cell switch to a configured target cell. The serving CU 302 may be configured to transmit to the serving DU 300 an indication whether the UE 102 should reuse the latest key or generate a new key for failure recovery. For example, the indication may be included in the UE context setup request or the UE context modification request sent to the DU 300.
[0085] For example, a new information element (IE) may be configured to the UE 102 to provide at least one of the intra-gNB handover related indication or the failure recovery related indication. One or more of the indications may be provided to the UE 102 through a MAC CE. In one example, one or more of the indications may be pre-configured during the handover preparation at 312 by one or more target gNBs, for example, through RRC reconfiguration.
[0086] At operation 314, the UE 102 may be configured to transmit a measurement report to the serving DU 300. The UE 102 may be configured to measure neighbor cells and the measurement report may be sent upon detecting that measurement criteria is met. The measurement report may comprise, for example, LI measurements. The neighbor cells may comprise the configured candidate target cells.
[0087] At operation 316, the serving DU 300 may determine to initiate a LTM handover based on the received measurement report. Thereafter, at operation 318, the serving DU 300 may be configured to send a cell switch command to the UE 102. The cell switch command may be transmitted via a MAC CE. The cell switch command may comprise the NCC value received from the CU 302 at 312. Optionally, the cell switch command may further comprise at least one of the indication whether or not the NCC is to be used by the UE for intra-gNB handovers and / or whether the latest or the generated new key of the serving cell is to be used in case of a failure recovery. The serving DU 300 may be configured to forward one or more indications related to security key generation at the UE based on the one or more indications received from the CU 300. The indications may be provided, for example, by including the indication flag to the cell switch command. Alternatively, the DU 300 may be configured to provide the indication by other suitable means, such as including instructions for selection of the security key generation procedure based on one or more conditions (e.g., intra-gNB HO and / or radio link failure recovery). The cell switch command may further comprise an identifier of a target cell for inter-gNB handover to be performed by the UE 102. In one example, configurations for at least one of the indications may be provided in a RRC command configured to the UE. The RRC command may be, for example, a RRC command comprising configuration of one or more LTM candidate target cell(s).
[0088] At operation 320, the serving DU 300 may be configured to send, to the serving CU 302, a notification about a serving cell change.
[0089] At operation 322, the UE 102 may be configured to determine a key generation procedure based on the received cell switch command. The UE 102 may be configured to determine, based on the NCC value received at 318, to perform one of a horizontal key derivation or a vertical key derivation. For example, the UE 102 may compare the received NCC value to a previous NCC value obtained by the UE 102 before the cell switch. Here, the NCC value obtained by the UE during handover preparation may be NCC=0 and the NCC value received in the cell switch command is NCC=0. The UE 102 compares the two NCC values and detects that the NCC values are the same. Hence, the UE 102 may determine to perform horizontal key derivation.
[0090] In an embodiment, the UE 102 may, at operation 322, first determine whether the serving cell change is an inter-gNB handover or an intra-gNB handover. If the serving cell change is the inter-gNB handover, the procedure may proceed as described in the previous paragraph. If the serving cell change is the intra-gNB handover, the UE 102 may, based on the received indication specifying whether or not to use the NCC for the intra-gNB handover,either follow the procedure of the previous paragraph or omit the procedure of the previous paragraph. If the NCC shall not be used for the intra-gNB handover, the UE 102 may simply proceed with the horizontal key derivation. Alternatively, the UE may be configured to, or decide to, re-use existing keys generated for the serving cell earlier. If the NCC shall be used for the intra-gNB handover, the UE 102 may proceed according to the value of the NCC, as described above. Similar procedure may be applied to any serving cell change described herein.
[0091] At operation 324, the UE 102 may be configured to send a RRC reconfiguration complete message to the target cell, which may be the distributed unit 304 of the second access node. The received RRC reconfiguration complete message may be transmitted by the DU 304 to the centralized unit 306 of the second access node. The DU 304 may be further configured to transmit an access notification to the CU 306 at operation 326.
[0092] Thereafter, a path switch procedure may be performed between the CU 306 and AMF 308. At operation 328, the centralized unit may be configured to send a path switch request to the AMF 308. At operation 330, AMF 308 may be configured to respond to the path switch command with an acknowledgement. The acknowledgement may comprise new security configuration. The security configuration may comprise a new NH value and a new NCC value. For example, AMF may have incremented the initial NCC value (NCC=0) by 2, and notify the distributed unit of the updated value NCC=2.
[0093] At operation 332, CU 306 may be configured to generate a security key using the vertical key generation (KNG-RAN*) based on the new security configuration (NH key, NCC). The CU 306 may be configured to notify all other configured CUs (e.g., CU 302) about the new security configuration including the new NH and the updated NCC. The CU 306 may be further configured to perform UE context release at source gNB (first access node).
[0094] At operation 334, the CU 306 (which is now the serving cell after the cell switch) may be configured to indicate the updated NCC value to the DU 304, which is now the new serving DU for the UE 102. The DU 304 may be configured to receive the updated NCC value from the CU 306, for example, via F1AP UE context modification request. The DU 304 may be further configured to receive, from the CU 306, an indication whether or not the NCC value is to be used for intra-gNB HO. Optionally, the DU 304 may be configured to receive, from the CU 306, an indication whether or not the UE 102 should use a latest key of the serving cell or generate a new key for the serving cell in case of a radio link failure recovery. At least one of the indications may be received, for example, in the F1AP UE context modification request together with the NCC value. The one or more indications maybe included, for example, in the form of indication flag(s) in the F1AP UE context modification request.
[0095] At operation 338, the serving DU 304 may be configured to store the NCC received at 334. The serving DU 304 may be further configured to store the one or more indications received from the CU 306. The serving DU 304 may be configured to forward the received NCC and the one or more indications (if any) to the UE 102, for example, by including them to a next cell switch command transmitted to the UE 102.
[0096] At operation 340, the DU 304 may receive a measurement report from the UE 102. The measurement report may comprise, for example, LI measurements of the configured candidate target cells.
[0097] At operation 342, the DU 304 may perform a LTM handover decision based on the received measurement report. Based on the LTM handover decision, the DU 304 may be configured to transmit, to the UE 102, a MAC CE cell switch command comprising the updated NCC value (NCC=2). The cell switch command may further comprise the one or more indications, if received from the CU 306 at 334. The cell switch command may comprise an identifier of a target cell for the cell switch and an indication of an inter-gNB HO to be performed.
[0098] At operation 344, the serving DU 304 may send a serving cell change notification to the serving CU 306.
[0099] At operation 346, the UE 102 may decide for LTM cell change. The UE 102 may be configured to determine the security key generation procedure to be applied based on the NCC value received from the DU 304 at 342. The UE 102 may compare the NCC value received in the latest cell switch command (NCC=2) to the NCC value received in the previous cell switch command (NCC=0). The UE 102 may detect that the NCC value has been incremented, and therefore determine to perform vertical key derivation. At operation 348, the UE 102 may send a RCC reconfiguration complete message to the DU 300 of the first access node by using the new security configuration. The RCC reconfiguration complete message may be forwarded by the DU 300 to the CU 302. The CU 302 may then decode the message by using the new key(s) received at 332.
[0100] Thereafter, a path switch procedure may be performed between the target CU 302 (new serving cell) and AMF 308. At operation 350, the CU 302 may be configured to transmit a path switch request to AMF 308. At operation 352, AMF 308 may respond with a path switch acknowledgment comprising an updated NCC value and a new NH valuegenerated by the AMF 308. For example, the AMF 308 may be configured to increment the previous NCC value by 1, to NCC=3.
[0101] At operation 354, the CU 302 notifies the new security configurations to all other configured CUs (e.g. CU 306) after receiving new security configuration (new NCC and NH key) from AMF 308. The CU 302 may be configured to perform vertical key generation based on the received NCC value, after comparing the updated NCC value (NCC=3) to the previous NCC value (NCC=2). Optionally, CU 302 may perform UE context release at source cell (second access node). The notification send by the CU 302 may comprise the generated key.
[0102] At operation 356, the CU 302 may be configured to indicate the updated NCC value to the DU 300, which is now the new serving DU for the UE 102. The updated NCC value may be indicated, for example, via a F1AP UE context modification request message, or in general via any DL transfer message. The transmitted message may further comprise one or more indications determined by the CU 302 to be forwarded to the UE 102, that is, an indication whether or not the UE should use the NCC value for intra-gNB HO and / or an indication whether the UE should use a latest key of the serving cell or generate a new key for the serving cell in case of a radio link failure recovery. In one example, the indications may be provided by using indication flag(s) included in the message. At operation 358, the DU 300 may be configured to acknowledge reception of the message to the CU 302, for example, with a F1AP UE context modification response message.
[0103] At operation 360, the DU 300 may be configured to store the NCC received at 356. For example, the DU 300 may be configured to update NCC value stored at the DU (NCC=2) based on the received NCC value (NCC=3).
[0104] At operation 362, a measurement report may be received by the DU 300 from the UE 102. The measurement report may comprise new LI measurements.
[0105] At operation 364, the DU 300 performs a LTM handover decision based on the measurement report and sends MAC CE cell switch command to the UE 102 including the updated NCC value stored at DU 300. Optionally, the cell switch command may include an indication, e.g., the indication flag, to indicate if the NCC should be used for intra GNB HO. DU 300 may also optionally include an indication whether the UE should use the latest key of the serving cell or generate a new key for the serving cell for radio link failure recovery. The one or more indications transmitted by the DU 300 may be based on the one or more indications received from the CU 302. The cell switch command may further comprise anidentifier of a target cell and an indication to perform intra-gNB HO. At operation 366, the DU 300 may send a serving cell change notification to the serving CU 302.
[0106] At 368, the UE 102 may decide to perform LTM cell change based on the received cell switch command. The UE 102 may determine security key generation procedure (e.g., vertical / horizontal key derivation) by comparing the NCC received in the cell switch command to a previously stored NCC value. If the cell switch command comprised the indication for whether or not the received NCC value is to be used for intra-gNB HO, the UE 102 may determine the security key generation procedure further based on the indication. At 370, the UE 102 may send a RRC reconfiguration complete message to the DU 300 by using the new security configuration. The CU 302 may then decode the message by using the new keys received at 354.
[0107] The security procedure illustrated in FIG. 3 enables a UE to be notified of the updated NCC values by means of MAC layer signalling by a serving DU. In FIG. 3, the NCC values are included in MAC CE cell switch commands. However, to provide robustness against radio link failures, the NCC value may be also configured to be transmitted before the cell switch command, as illustrated in FIG. 4.
[0108] FIG. 4 illustrates an example of signalling and operations configured for a security procedure for subsequent LTM and failure recovery. The security procedure may be performed between a UE, such as UE 102, and one or more access nodes, such as access node 104, 106 and / or 108, and CN, depicted by AMF 308. Each access node may comprise a centralized unit and one or more distributed units. A first access node may comprise a centralized unit 302 coupled with a distributed unit 300. A second access node may comprise a centralized unit 306 coupled with a distributed unit 304. The first access node may be, for example, a source master node (MN1). The second access node may be, for example, a target master node (MN2).
[0109] Operations 310 and 312 of FIG. 3 and FIG. 4 correspond to each other and are therefore not repeated herein.
[0110] At operation 400, the serving DU 300 may be configured to transmit, to the UE 102, the separate message comprising the NCC value (e.g., NCC=0) received from the serving CU 302. The NCC value may be transmitted via MAC layer signalling. The separate message may comprise, for example, a MAC CE. The separate message may further comprise one or more indications received from the CU 302 to be forwarded to the UE 102. The one or more indications can comprise at least one of the following: an indication to use the NCC value in case of an intra-gNB HO, an indication not to use the NCC value in case of an intra-gNBHO, and indication not to perform security key generation in case of an intra-gNB HO, an indication to use a latest key of a serving cell in case of a radio link failure recovery or an indication to generate a new key for the serving cell in case of a radio link failure recovery. At least one of the received indication or the transmitted indication may be configured to be provided as an indication flag (false / true) included in the respective message. The UE 102 may be preconfigured, or configured by the network, with instructions related to security key generation. The UE 102 may be configured to perform according to the instructions based on the received indication flag.[OHl] At operation 314, the DU 300 receives a LI measurement report from the UE 102. Based on the LI measurement report, DU 300 may perform a decision for LTM HO, at operation 316. After the LTM HO decision, the DU 300 may be configured to transmit a cell switch command to the UE 102. The cell switch command may comprise, for example, an identity of a target cell and / or an indication of an inter-gNB HO to be performed by the UE 102. Because the NCC value was previously sent to the UE 102 in the separate MAC CE message, the cell switch command may not need to comprise the NCC value. At 320, the DU 300 may transmit a notification about the cell change to the serving CU 302.
[0112] At operation 404, the UE 102 may decide for a LTM cell change based on the received cell switch command. The UE 102 may be configured to determine a security key generation to be applied based on the NCC value received at 400. The UE 102 may compare the received NCC value to a previous NCC value obtained by the UE 102, and detect that the NCC values are the same. Because the NCC value has not changed, the UE 102 may determine to perform horizontal key derivation. When the MAC CE message also included the one or more indications, the UE 102 may be configured to further determine the security key generation procedure based on the received indication(s).
[0113] The handover and security procedure may then continue with operations 324, 326, 328, 330, 332 and 334 as already described in FIG. 3, and description of the operations are therefore not repeated herein.
[0114] After the new serving DU 304 has received the updated NCC value from the CU 306 at 334, the DU 304 may be configured to transmit the updated NCC value to the UE 102 in a separate message before a next cell switch command. At operation 406, the DU 304 may be configured to transmit the updated NCC value to the UE 102 via MAC layer signalling, such as in a MAC CE message. For example, the DU 304 may be configured to transmit the NCC value to the UE 102 as soon as the NCC value is received from the CU 306. As described in operation 400, in case the DU 304 also received at least one indication from theCU 306 to be forwarded to the UE 102, the at least one indication may be included in the MAC CE message. After transmission of the MAC CE message to the UE 102, the DU 304 may be configured to transmit a UE context modification response message to the CU 306. However, this is one example, and the MAC CE message may be also configured to be transmitted after the UE context modification response, as long as the MAC CE message is transmitted before the next cell switch command.
[0115] At operation 408, the UE 102 may be configured to store the NCC value and any indication received at 406 for further use.
[0116] At operation 340, the UE 102 may transmit LI measurement report to the DU 304. The DU 304 may then perform a LTM HO decision based on the LI measurement report. However, before a cell switch command is transmitted by the DU 304 to the UE 102, at operation 412, a radio link failure may occur at 410. In this case, the radio link failure may occur so that the UE 102 is not able to receive the cell switch command.
[0117] The UE 102 may be configured to detect the radio link failure event, and initiate LTM recovery at operation 414. At the operation 414, the UE 102 may be configured to decide to perform LTM recovery to a configured LTM candidate target cell. The UE 102 may be configured to select the LTM candidate target cell and determine security key generation procedure based on the NCC value already received in the MAC CE message at 406. The UE 102 may be configured to compare the NCC value in the MAC CE message (NCC=3) to a previously used NCC value (NCC=2) for key derivation, and detect that the received and previously used NCC values are different from each other. Hence, based on the comparison, the UE 102 may determine to perform vertical key derivation by using the received NCC value. If the UE 102 received the at least one indication in the MAC CE message, the UE 102 may be configured to take the indication into consideration when determining the security key generation procedure to be applied. For example, if the selected LTM candidate target cell for recovery is the serving cell / source LTM cell, the UE 102 may be configured to use the old keys or instructed by the network (e.g., based on the received indication for failure recovery). If the selected LTM candidate is the target cell, the UE 102 may use the already generated keys for that target cell, if any, during the LTM execution to the target cell. If the selected LTM candidate cell is any other cell, then UE 102 shall perform new key generation considering if the received NCC is previously used or not, and the indication.
[0118] The UE 102 may then transmit, at operation 414, a RRC reconfiguration message to DU to the selected LTM candidate target cell for recovery.
[0119] Thereafter, a path switch procedure may be performed, and new security configurations may be shared as already described in corresponding operations 350, 352, 354 and 356 in FIG. 3, and are therefore not repeated herein.
[0120] After the NCC value updated by the AMF 308 at operation 352 is received by the DU 300 via the CU 302 at 356, the DU 300 may be configured to forward the updated NCC value (NCC=3) to the UE 102 in the separate MAC CE message configured to be transmitted before a next cell switch command. After the MAC CE message is transmitted by the DU 300 to the UE 102, at operation 418, the DU 300 may be configured to respond to the CU 302 with a UE context response message, at operation 358. The updated NCC received by the UE 102 may stored at the UE 102 to be used for subsequent LTM handover(s).
[0121] FIG. 5 illustrates an example of a method 500 for security procedure. Method 500 may be performed by a mobile device, such as a UE (e.g., UE 102), or by an apparatus configured to control the functioning of the UE, when installed therein.
[0122] At operation 502, the method may comprise receiving, from a distributed unit of an access node of a serving cell of the user equipment, a next hop chaining counter value for a subsequent Layer 1 / Layer 2 triggered mobility procedure via medium access control layer signalling.
[0123] At operation 504, the method may comprise determining a security key generation procedure to be applied for the subsequent Layer 1 / Layer 2 triggered mobility procedure based on the received next hop chaining counter value.
[0124] FIG. 6 illustrates an example of a method 600 for security procedure for a subsequent LTM procedure. Method 600 may be performed by a network device, such as an access node (e.g. gNB 104, 106 and / or gNB 108) or a portion thereof, such as a distributed unit of the access node (e.g., DU 300 and / or DU 304). In one example, the method 600 may be performed by an apparatus configured to control the functioning of the distributed unit, when installed therein.
[0125] At 602, the method may comprise receiving, from a centralized unit of an access node, a message comprising a next hop chaining counter value.
[0126] At 604, the method may comprise updating, based on the received next hop chaining counter value, a next hop chaining counter value stored at the distributed unit of the access node associated with a serving cell of the user equipment.
[0127] At 606, the method may comprise transmitting, to the user equipment, the updated next hop chaining counter value via a medium access control layer signalling for a subsequent Layer 1 / Layer 2 triggered mobility procedure.
[0128] In one example, a method for security procedure for subsequent LTM procedure may be performed by a centralized unit of an access node, e.g. CU 302 and / or CU 306, or an apparatus configured to control the functionality of the centralized unit, when installed therein.
[0129] The method may comprise determining that a next hop chaining counter value stored at a centralized unit of an access node is updated; and transmitting, to a distributed unit of the access node associated with a serving cell of a user equipment, a message comprising the determined next hop chaining counter value to be forwarded by the distributed unit to the user equipment for a subsequent Layer 1 / Layer 2 triggered mobility procedure. The determined next hop chaining value may comprise a value updated by the centralized unit of the access node at a handover preparation procedure or an updated value received from a core network (e.g., AMF) at a path switch procedure.
[0130] The method may further comprise determining whether or not the next hop chaining counter value is to be used by the user equipment for intra-access node handover; and transmitting, to the distributed unit, an indication of whether or not the next hop chaining counter value is to be used by the user equipment for intra-access node handover based on the determination.
[0131] The method may further comprise determining one of a latest security key of the serving cell or a new security key generated by the user equipment for the serving cell to be used by the user equipment in case of a radio link failure recovery; and transmitting, to the distributed unit, an indication for the equipment to use one of the latest security key of the serving cell or to generate the new security key for the serving cell in case of a radio link failure recovery based on the determination.
[0132] The method may further comprise transmitting at least one of the next hop chaining counter value, the indication whether or not to use the next hop chaining counter for intra- access node handover, or the indication to use one of the latest key or the generated new key in at least one of a user equipment context setup request message or a user equipment context modification request message.
[0133] Further features of the methods directly result for example from functionality of UE 102, access node(s) 104, 106 and / or 108, distributed unit(s) 300 and / or 304, or centralized unit(s) 302 and / or 306 as described throughout the description, claims, and drawings, and are therefore not repeated here. An apparatus, for example a mobile device such as UE 102, or an access node, may be configured to perform or cause performance of any aspect of the method(s) described herein. Further, a computer program, a computer program product, ora (non-transitory) computer-readable medium may comprise instructions for causing, when executed by an apparatus, the apparatus to perform any aspect of the method(s) described herein. Further, an apparatus may comprise means for performing any aspect of the method(s) described herein. According to an example embodiment, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform any aspect of the method(s).
[0134] Any range or device value given herein may be extended or altered without losing the effect sought. Also, any embodiment may be combined with another embodiment unless explicitly disallowed.
[0135] Although the subject matter has been described in language specific to structural features and / or acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as examples of implementing the claims and other equivalent features and acts are intended to be within the scope of the claims.
[0136] It will be understood that the benefits and advantages described above may relate to one embodiment or may relate to several embodiments. The embodiments are not limited to those that solve any or all of the stated problems or those that have any or all of the stated benefits and advantages. It will further be understood that reference to 'an' item may refer to one or more of those items.
[0137] The steps or operations of the methods described herein may be carried out in any suitable order, or simultaneously where appropriate. Additionally, individual blocks may be deleted from any of the methods without departing from the scope of the subject matter described herein. Aspects of any of the example embodiments described above may be combined with aspects of any of the other example embodiments described to form further example embodiments without losing the effect sought.
[0138] The term 'comprising' is used herein to mean including the method, blocks, or elements identified, but that such blocks or elements do not comprise an exclusive list and a method or apparatus may contain additional blocks or elements.
[0139] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0140] Although subjects may be referred to as ‘first’ or ‘second’ subjects, this does not necessarily indicate any order or importance of the subjects. Instead, such attributes may be used solely for the purpose of making a difference between subjects.
[0141] As used in this application, the term ‘circuitry’ may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable) :(i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims.
[0142] As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0143] It will be understood that the above description is given by way of example only and that various modifications may be made by those skilled in the art. The above specification, examples and data provide a complete description of the structure and use of exemplary embodiments. Although various embodiments have been described above with a certain degree of particularity, or with reference to one or more individual embodiments, those skilled in the art could make numerous alterations to the disclosed embodiments without departing from scope of this specification.
Claims
CLAIMS1. An apparatus for user equipment, comprising: at least one processor; and at least one memory comprising instructions that, when executed by the at least one processor, cause the apparatus to: receive, from a distributed unit of an access node of a serving cell of the user equipment, a next hop chaining counter value for a subsequent Layer 1 / Layer 2 triggered mobility procedure via medium access control layer signalling; and determine a security key generation procedure to be applied for the subsequent Layer 1 / Layer 2 triggered mobility procedure based on the received next hop chaining counter value.
2. The apparatus of claim 1, wherein the next hop chaining counter value is received in at least one of a cell switch command or in a separate message received before a cell switch command from the distributed unit.
3. The apparatus of any of claim 1 or 2, further caused to: receive, from the distributed unit of the access node via medium access control layer signalling, an indication whether or not the received next hop chaining counter value is to be used by the user equipment for intra-access node handover; and determine the security key generation procedure for the next intra-access node handover based on the received indication.
4. The apparatus according to claim 2 and 3, wherein at least one of the cell switch command or the separate message further comprises the indication whether or not to use the received next hop chaining counter value for intra-access node handover.
5. The apparatus of any of claims 1 to 4, further caused to: receive, from the distributed unit of the access node via medium access control layer signalling, an indication to use one of the following in case of a radio link failure recover: a latest security key of the serving cell or a new security key generated for the serving cell; anddetermine the security key generation procedure based on the received indication for radio link failure recovery.
6. The apparatus according to claim 5 and at least one of claim 2 or claim4, wherein at least one of the cell switch command or the separate message further comprises the indication to use one of the latest security key of the serving cell or the new security key generated for the serving cell in case of a radio link failure recovery.
7. The apparatus of any of claims 1 to 6, wherein the medium access control signalling comprises a medium access control, MAC, control element.
8. The apparatus of any of claims 1 to 7, further caused to: detect a radio link failure; select a candidate cell for failure recovery based on the detected radio link failure; initiate the subsequent mobility procedure to the selected candidate cell for failure recovery, wherein a security key for the mobility procedure is updated based on the determined security key generation procedure.
9. An apparatus for a distributed unit, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from a centralized unit of an access node, a message comprising a next hop chaining counter value; update, based on the received next hop chaining counter value, a next hop chaining counter value stored at a distributed unit of the access node associated with a serving cell of the user equipment; and transmit, to the user equipment, the updated next hop chaining counter value via a medium access control layer signalling for a subsequent Layer 1 / Layer 2 triggered mobility procedure.
10. The apparatus of claim 9, wherein the message comprises at least one of a user equipment context setup request or a user equipment context modification request.
11. The apparatus of any of claims 9 to 10, further caused to: receive, from the centralized unit of the access node, an indication whether the received next hop chaining counter value is to be used by the user equipment for intra-access node handover; and transmit, to the user equipment, the indication via a medium access control layer signalling.
12. The apparatus of any of claims 9 to 11, further caused to: receive, from the centralized unit of the access node, an indication for the user equipment to use one of a latest security key of the serving cell or to generate a new security key for the serving cell for radio link failure recovery; and transmit, to the user equipment, the received indication via medium access control signalling.
13. The apparatus of any of claims 9 to 12, wherein the medium access control layer signalling comprises a medium access control, MAC, control element.
14. The apparatus of claim 13, wherein the medium access control layer signalling comprises at least one of: a cell switch command; or a separate message before a cell switch command transmitted by the distributed unit.
15. A method, comprising: receiving, from a distributed unit of an access node of a serving cell of the user equipment, a next hop chaining counter value for a subsequent Layer 1 / Layer 2 triggered mobility procedure via medium access control layer signalling; and determining a security key generation procedure to be applied for the subsequent Layer 1 / Layer 2 triggered mobility procedure based on the received next hop chaining counter value.
16. A method, comprising:receiving, from a centralized unit of an access node, a message comprising a next hop chaining counter value; updating, based on the received next hop chaining counter value, a next hop chaining counter value stored at a distributed unit of the access node associated with a serving cell of the user equipment; and transmitting, to the user equipment, the updated next hop chaining counter value via a medium access control layer signalling for a subsequent Layer 1 / Layer 2 triggered mobility procedure.
Citation Information
Patent Citations
Transient period operation for l1 / l2 based cell handover
US20210219194A1
Connection Reestablishment Procedure
US20220345970A1