Security handling and reporting while subsequent mobility failure
The method and apparatus address mobility failure robustness and signaling interruptions in 3GPP systems by enabling security updates and key transmission during cell switch failures, enhancing system reliability and reducing interruptions.
Patent Information
- Application Number
- PCT/KR2025/004569
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-11
- Filing Date
- 2025-04-04
- Publication Date
- 2025-10-16
AI Technical Summary
Existing mobility failure in 3GPP LTE and NR systems during cell switch operations lacks robustness and involves significant signaling interruptions, necessitating improved security handling and reporting mechanisms.
A method and apparatus for receiving security information during cell switch failures, enabling security updates and key transmission to a target cell, enhancing robustness and reducing interruption times.
The solution provides enhanced robustness and reduced signaling interruptions during cell switch failures by implementing security updates and key transmission, improving the reliability of mobility procedures in 3GPP systems.
Smart Images

Figure KR2025004569_16102025_PF_FP_ABST
Abstract
Description
SECURITY HANDLING AND REPORTING WHILE SUBSEQUENT MOBILITY FAILURE
[0001] The present disclosure relates to security handling and reporting while subsequent mobility failure.
[0002] 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a technology for enabling high-speed packet communications. Many schemes have been proposed for the LTE objective including those that aim to reduce user and provider costs, improve service quality, and expand and improve coverage and system capacity. The 3GPP LTE requires reduced cost per bit, increased service availability, flexible use of a frequency band, a simple structure, an open interface, and adequate power consumption of a terminal as an upper-level requirement.
[0003] 3GPP New Radio (NR) targets a single technical framework addressing all usage scenarios, requirements and deployment scenarios including enhanced Mobile BroadBand (eMBB), massive Machine Type Communications (mMTC), Ultra-Reliable and Low Latency Communications (URLLC), etc. The NR shall be inherently forward compatible. Further, the NR should be able to use any spectrum band ranging at least up to 100 GHz that may be made available for wireless communications even in a more distant future.
[0004] 6G is the successor to 5G cellular technology. 6G networks will be able to use higher frequencies than 5G networks and provide substantially higher capacity and much lower latency. The 6G technology market is expected to facilitate large improvements in the areas of imaging, presence technology and location awareness. Working in conjunction with Artificial Intelligence (AI), the 6G computational infrastructure will be able to identify the best place for computing to occur. This includes decisions about data storage, processing and sharing.
[0005] Layer 3 based mobility has evolved over several releases. Conditional Handover (CHO) and other conditional mobility procedures (Conditional PSCell Addition and Change (CPAC), Subsequent CPAC (SCPAC)) were developed to achieve high robustness by enabling the procedure to be executed without necessitating a signaling exchange with source cell beforehand. L1 / L2 Triggered Mobility (LTM) as introduced in Rel-18 offers short interruption time but not with the same level of robustness as the conditional L3 mobility procedures. In Rel-19, enhancements should be specified so that the system can benefit from both the high robustness and short interruption.
[0006] In an aspect, a method is provided. The method comprises receiving a cell switch command including security information from a source cell. The method further comprises, based on a selected cell, due to a cell selection upon detection of a failure of a cell switch from the source cell to a target cell, being the target cell, performing security update for the target cell based on the security information.
[0007] In another aspect, a method is provided. The method comprises, based on a selected cell, due to a cell selection upon detection of a failure of a cell switch from the source cell to a target cell, being the target cell, transmitting a security key related to the failure of the cell switch to a network.
[0008] In another aspect, an apparatus for implementing the above method is provided.
[0009] FIG. 1 shows an example of a communication system to which implementations of the present disclosure are applied.
[0010] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure are applied.
[0011] FIG. 3 shows an example of UE to which implementations of the present disclosure are applied.
[0012] FIGS. 4 and 5 show an example of protocol stacks in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0013] FIG. 6 shows a frame structure in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0014] FIG. 7 shows a data flow example in the 3GPP NR system to which implementations of the present disclosure are applied.
[0015] FIG. 8 shows an example of inter-gNB handover procedures to which implementations of the present disclosure are applied.
[0016] FIG. 9 shows an example of signaling procedure for LTM to which implementations of the present disclosure are applied.
[0017] FIG. 10 shows an example of a method to which implementations of the present disclosure are applied.
[0018] FIG. 11 shows an example of another method to which implementations of the present disclosure are applied.
[0019] FIG. 12 shows an example of another method to which implementations of the present disclosure are applied.
[0020] The following techniques, apparatuses, and systems may be applied to a variety of wireless multiple access systems. Examples of the multiple access systems include a Code Division Multiple Access (CDMA) system, a Frequency Division Multiple Access (FDMA) system, a Time Division Multiple Access (TDMA) system, an Orthogonal Frequency Division Multiple Access (OFDMA) system, a Single Carrier Frequency Division Multiple Access (SC-FDMA) system, and a Multi Carrier Frequency Division Multiple Access (MC-FDMA) system. CDMA may be embodied through radio technology such as Universal Terrestrial Radio Access (UTRA) or CDMA2000. TDMA may be embodied through radio technology such as Global System for Mobile communications (GSM), General Packet Radio Service (GPRS), or Enhanced Data rates for GSM Evolution (EDGE). OFDMA may be embodied through radio technology such as Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, or Evolved UTRA (E-UTRA). UTRA is a part of a Universal Mobile Telecommunications System (UMTS). 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a part of Evolved UMTS (E-UMTS) using E-UTRA. 3GPP LTE employs OFDMA in Downlink (DL) and SC-FDMA in Uplink (UL). Evolution of 3GPP LTE includes LTE-Advanced (LTE-A), LTE-A Pro, 5G New Radio (NR) and / or 6G.
[0021] For convenience of description, implementations of the present disclosure are mainly described in regards to a 3GPP based wireless communication system. However, the technical features of the present disclosure are not limited thereto. For example, although the following detailed description is given based on a mobile communication system corresponding to a 3GPP based wireless communication system, aspects of the present disclosure that are not limited to 3GPP based wireless communication system are applicable to other mobile communication systems.
[0022] For terms and technologies which are not specifically described among the terms of and technologies employed in the present disclosure, the wireless communication standard documents published before the present disclosure may be referenced.
[0023] In the present disclosure, "A or B" may mean "only A", "only B", or "both A and B". In other words, "A or B" in the present disclosure may be interpreted as "A and / or B". For example, "A, B or C" in the present disclosure may mean "only A", "only B", "only C", or "any combination of A, B and C".
[0024] In the present disclosure, slash ( / ) or comma (,) may mean "and / or". For example, "A / B" may mean "A and / or B". Accordingly, "A / B" may mean "only A", "only B", or "both A and B". For example, "A, B, C" may mean "A, B or C".
[0025] In the present disclosure, "at least one of A and B" may mean "only A", "only B" or "both A and B". In addition, the expression "at least one of A or B" or "at least one of A and / or B" in the present disclosure may be interpreted as same as "at least one of A and B".
[0026] In addition, in the present disclosure, "at least one of A, B and C" may mean "only A", "only B", "only C", or "any combination of A, B and C". In addition, "at least one of A, B or C" or "at least one of A, B and / or C" may mean "at least one of A, B and C".
[0027] Also, parentheses used in the present disclosure may mean "for example". In detail, when it is shown as "control information (PDCCH)", "PDCCH" may be proposed as an example of "control information". In other words, "control information" in the present disclosure is not limited to "PDCCH", and "PDCCH" may be proposed as an example of "control information". In addition, even when shown as "control information (i.e., PDCCH)", "PDCCH" may be proposed as an example of "control information".
[0028] Technical features that are separately described in one drawing in the present disclosure may be implemented separately or simultaneously.
[0029] Although not limited thereto, various descriptions, functions, procedures, suggestions, methods and / or operational flowcharts of the present disclosure disclosed herein can be applied to various fields requiring wireless communication and / or connection (e.g., 5G) between devices.
[0030] Hereinafter, the present disclosure will be described in more detail with reference to drawings. The same reference numerals in the following drawings and / or descriptions may refer to the same and / or corresponding hardware blocks, software blocks, and / or functional blocks unless otherwise indicated.
[0031] FIG. 1 shows an example of a communication system to which implementations of the present disclosure are applied.
[0032] The 5G usage scenarios shown in FIG. 1 are only exemplary, and the technical features of the present disclosure can be applied to other 5G usage scenarios which are not shown in FIG. 1.
[0033] Three main requirement categories for 5G include (1) a category of enhanced Mobile BroadBand (eMBB), (2) a category of massive Machine Type Communication (mMTC), and (3) a category of Ultra-Reliable and Low Latency Communications (URLLC).
[0034] Referring to FIG. 1, the communication system 1 includes wireless devices 100a to 100f, Base Stations (BSs) 200, and a network 300. Although FIG. 1 illustrates a 5G network as an example of the network of the communication system 1, the implementations of the present disclosure are not limited to the 5G system, and can be applied to the future communication system beyond the 5G system.
[0035] The BSs 200 and the network 300 may be implemented as wireless devices and a specific wireless device may operate as a BS / network node with respect to other wireless devices.
[0036] The wireless devices 100a to 100f represent devices performing communication using Radio Access Technology (RAT) (e.g., 5G NR or LTE) and may be referred to as communication / radio / 5G devices. The wireless devices 100a to 100f may include, without being limited to, a robot 100a, vehicles 100b-1 and 100b-2, an eXtended Reality (XR) device 100c, a hand-held device 100d, a home appliance 100e, an Internet-of-Things (IoT) device 100f, and an Artificial Intelligence (AI) device / server 400. For example, the vehicles may include a vehicle having a wireless communication function, an autonomous driving vehicle, and a vehicle capable of performing communication between vehicles. The vehicles may include an Unmanned Aerial Vehicle (UAV) (e.g., a drone). The XR device may include an Augmented Reality (AR) / Virtual Reality (VR) / Mixed Reality (MR) device and may be implemented in the form of a Head-Mounted Device (HMD), a Head-Up Display (HUD) mounted in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance device, a digital signage, a vehicle, a robot, etc. The hand-held device may include a smartphone, a smartpad, a wearable device (e.g., a smartwatch or a smartglasses), and a computer (e.g., a notebook). The home appliance may include a TV, a refrigerator, and a washing machine. The IoT device may include a sensor and a smartmeter.
[0037] In the present disclosure, the wireless devices 100a to 100f may be called User Equipments (UEs). A UE may include, for example, a cellular phone, a smartphone, a laptop computer, a digital broadcast terminal, a Personal Digital Assistant (PDA), a Portable Multimedia Player (PMP), a navigation system, a slate Personal Computer (PC), a tablet PC, an ultrabook, a vehicle, a vehicle having an autonomous traveling function, a connected car, an UAV, an AI module, a robot, an AR device, a VR device, an MR device, a hologram device, a public safety device, an MTC device, an IoT device, a medical device, a FinTech device (or a financial device), a security device, a weather / environment device, a device related to a 5G service, or a device related to a fourth industrial revolution field.
[0038] The wireless devices 100a to 100f may be connected to the network 300 via the BSs 200. An AI technology may be applied to the wireless devices 100a to 100f and the wireless devices 100a to 100f may be connected to the AI server 400 via the network 300. The network 300 may be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, and a beyond-5G network. Although the wireless devices 100a to 100f may communicate with each other through the BSs 200 / network 300, the wireless devices 100a to 100f may perform direct communication (e.g., sidelink communication) with each other without passing through the BSs 200 / network 300. For example, the vehicles 100b-1 and 100b-2 may perform direct communication (e.g., Vehicle-to-Vehicle (V2V) / Vehicle-to-everything (V2X) communication). The IoT device (e.g., a sensor) may perform direct communication with other IoT devices (e.g., sensors) or other wireless devices 100a to 100f.
[0039] Wireless communication / connections 150a, 150b and 150c may be established between the wireless devices 100a to 100f and / or between wireless device 100a to 100f and BS 200 and / or between BSs 200. Herein, the wireless communication / connections may be established through various RATs (e.g., 5G NR) such as uplink / downlink communication 150a, sidelink communication (or Device-to-Device (D2D) communication) 150b, inter-base station communication 150c (e.g., relay, Integrated Access and Backhaul (IAB)), etc. The wireless devices 100a to 100f and the BSs 200 / the wireless devices 100a to 100f may transmit / receive radio signals to / from each other through the wireless communication / connections 150a, 150b and 150c. For example, the wireless communication / connections 150a, 150b and 150c may transmit / receive signals through various physical channels. To this end, at least a part of various configuration information configuring processes, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, and resource mapping / de-mapping), and resource allocating processes, for transmitting / receiving radio signals, may be performed based on the various proposals of the present disclosure.
[0040] NR supports multiples numerologies (and / or multiple Sub-Carrier Spacings (SCS)) to support various 5G services. For example, if SCS is 15 kHz, wide area can be supported in traditional cellular bands, and if SCS is 30 kHz / 60 kHz, dense-urban, lower latency, and wider carrier bandwidth can be supported. If SCS is 60 kHz or higher, bandwidths greater than 24.25 GHz can be supported to overcome phase noise.
[0041] The NR frequency band may be defined as two types of frequency range, i.e., Frequency Range 1 (FR1) and Frequency Range 2 (FR2). The numerical value of the frequency range may be changed. For example, the frequency ranges of the two types (FR1 and FR2) may be as shown in Table 1 below. For ease of explanation, in the frequency ranges used in the NR system, FR1 may mean "sub 6 GHz range", FR2 may mean "above 6 GHz range," and may be referred to as millimeter Wave (mmW).
[0042] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1450MHz - 6000MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz
[0043] As mentioned above, the numerical value of the frequency range of the NR system may be changed. For example, FR1 may include a frequency band of 410MHz to 7125MHz as shown in Table 2 below. That is, FR1 may include a frequency band of 6GHz (or 5850, 5900, 5925 MHz, etc.) or more. For example, a frequency band of 6 GHz (or 5850, 5900, 5925 MHz, etc.) or more included in FR1 may include an unlicensed band. Unlicensed bands may be used for a variety of purposes, for example for communication for vehicles (e.g., autonomous driving).
[0044] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1410MHz - 7125MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz
[0045] Here, the radio communication technologies implemented in the wireless devices in the present disclosure may include NarrowBand IoT (NB-IoT) technology for low-power communication as well as LTE, NR and 6G. For example, NB-IoT technology may be an example of Low Power Wide Area Network (LPWAN) technology, may be implemented in specifications such as LTE Cat NB1 and / or LTE Cat NB2, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may communicate based on LTE-M technology. For example, LTE-M technology may be an example of LPWAN technology and be called by various names such as enhanced MTC (eMTC). For example, LTE-M technology may be implemented in at least one of the various specifications, such as 1) LTE Cat 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-bandwidth limited (non-BL), 5) LTE-MTC, 6) LTE Machine Type Communication, and / or 7) LTE M, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may include at least one of ZigBee, Bluetooth, and / or LPWAN which take into account low-power communication, and may not be limited to the above-mentioned names. For example, ZigBee technology may generate Personal Area Networks (PANs) associated with small / low-power digital communication based on various specifications such as IEEE 802.15.4 and may be called various names.
[0046] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure are applied.
[0047] In FIG. 2, The first wireless device 100 and / or the second wireless device 200 may be implemented in various forms according to use cases / services. For example, {the first wireless device 100 and the second wireless device 200} may correspond to at least one of {the wireless device 100a to 100f and the BS 200}, {the wireless device 100a to 100f and the wireless device 100a to 100f} and / or {the BS 200 and the BS 200} of FIG. 1. The first wireless device 100 and / or the second wireless device 200 may be configured by various elements, devices / parts, and / or modules.
[0048] The first wireless device 100 may include at least one transceiver, such as a transceiver 106, at least one processing chip, such as a processing chip 101, and / or one or more antennas 108.
[0049] The processing chip 101 may include at least one processor, such a processor 102, and at least one memory, such as a memory 104. Additional and / or alternatively, the memory 104 may be placed outside of the processing chip 101.
[0050] The processor 102 may control the memory 104 and / or the transceiver 106 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 102 may process information within the memory 104 to generate first information / signals and then transmit radio signals including the first information / signals through the transceiver 106. The processor 102 may receive radio signals including second information / signals through the transceiver 106 and then store information obtained by processing the second information / signals in the memory 104.
[0051] The memory 104 may be operably connectable to the processor 102. The memory 104 may store various types of information and / or instructions. The memory 104 may store a firmware and / or a software code 105 which implements codes, commands, and / or a set of commands that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may implement instructions that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more protocols. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more layers of the radio interface protocol.
[0052] Herein, the processor 102 and the memory 104 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 106 may be connected to the processor 102 and transmit and / or receive radio signals through one or more antennas 108. Each of the transceiver 106 may include a transmitter and / or a receiver. The transceiver 106 may be interchangeably used with Radio Frequency (RF) unit(s). In the present disclosure, the first wireless device 100 may represent a communication modem / circuit / chip.
[0053] The second wireless device 200 may include at least one transceiver, such as a transceiver 206, at least one processing chip, such as a processing chip 201, and / or one or more antennas 208.
[0054] The processing chip 201 may include at least one processor, such a processor 202, and at least one memory, such as a memory 204. Additional and / or alternatively, the memory 204 may be placed outside of the processing chip 201.
[0055] The processor 202 may control the memory 204 and / or the transceiver 206 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 202 may process information within the memory 204 to generate third information / signals and then transmit radio signals including the third information / signals through the transceiver 206. The processor 202 may receive radio signals including fourth information / signals through the transceiver 106 and then store information obtained by processing the fourth information / signals in the memory 204.
[0056] The memory 204 may be operably connectable to the processor 202. The memory 204 may store various types of information and / or instructions. The memory 204 may store a firmware and / or a software code 205 which implements codes, commands, and / or a set of commands that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may implement instructions that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more protocols. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more layers of the radio interface protocol.
[0057] Herein, the processor 202 and the memory 204 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 206 may be connected to the processor 202 and transmit and / or receive radio signals through one or more antennas 208. Each of the transceiver 206 may include a transmitter and / or a receiver. The transceiver 206 may be interchangeably used with RF unit. In the present disclosure, the second wireless device 200 may represent a communication modem / circuit / chip.
[0058] Hereinafter, hardware elements of the wireless devices 100 and 200 will be described more specifically. One or more protocol layers may be implemented by, without being limited to, one or more processors 102 and 202. For example, the one or more processors 102 and 202 may implement one or more layers (e.g., functional layers such as Physical (PHY) layer, Media Access Control (MAC) layer, Radio Link Control (RLC) layer, Packet Data Convergence Protocol (PDCP) layer, Radio Resource Control (RRC) layer, and Service Data Adaptation Protocol (SDAP) layer). The one or more processors 102 and 202 may generate one or more Protocol Data Units (PDUs), one or more Service Data Unit (SDUs), messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The one or more processors 102 and 202 may generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure and provide the generated signals to the one or more transceivers 106 and 206. The one or more processors 102 and 202 may receive the signals (e.g., baseband signals) from the one or more transceivers 106 and 206 and acquire the PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure.
[0059] The one or more processors 102 and 202 may be referred to as controllers, microcontrollers, microprocessors, or microcomputers. The one or more processors 102 and 202 may be implemented by hardware, firmware, software, or a combination thereof. As an example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in the one or more processors 102 and 202. For example, the one or more processors 102 and 202 may be configured by a set of a communication control processor, an Application Processor (AP), an Electronic Control Unit (ECU), a Central Processing Unit (CPU), a Graphic Processing Unit (GPU), and a memory control processor.
[0060] The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 and store various types of data, signals, messages, information, programs, code, instructions, and / or commands. The one or more memories 104 and 204 may be configured by Random Access Memory (RAM), Dynamic RAM (DRAM), Read-Only Memory (ROM), electrically Erasable Programmable Read-Only Memory (EPROM), flash memory, volatile memory, non-volatile memory, hard drive, register, cash memory, computer-readable storage medium, and / or combinations thereof. The one or more memories 104 and 204 may be located at the interior and / or exterior of the one or more processors 102 and 202. The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 through various technologies such as wired or wireless connection.
[0061] The one or more transceivers 106 and 206 may transmit user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, to one or more other devices. The one or more transceivers 106 and 206 may receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, from one or more other devices. For example, the one or more transceivers 106 and 206 may be connected to the one or more processors 102 and 202 and transmit and receive radio signals. For example, the one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may transmit user data, control information, or radio signals to one or more other devices. The one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may receive user data, control information, or radio signals from one or more other devices.
[0062] The one or more transceivers 106 and 206 may be connected to the one or more antennas 108 and 208. Additionally and / or alternatively, the one or more transceivers 106 and 206 may include one or more antennas 108 and 208. The one or more transceivers 106 and 206 may be adapted to transmit and receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, through the one or more antennas 108 and 208. In the present disclosure, the one or more antennas 108 and 208 may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports).
[0063] The one or more transceivers 106 and 206 may convert received user data, control information, radio signals / channels, etc., from RF band signals into baseband signals in order to process received user data, control information, radio signals / channels, etc., using the one or more processors 102 and 202. The one or more transceivers 106 and 206 may convert the user data, control information, radio signals / channels, etc., processed using the one or more processors 102 and 202 from the base band signals into the RF band signals. To this end, the one or more transceivers 106 and 206 may include (analog) oscillators and / or filters. For example, the one or more transceivers 106 and 206 can up-convert OFDM baseband signals to OFDM signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202 and transmit the up-converted OFDM signals at the carrier frequency. The one or more transceivers 106 and 206 may receive OFDM signals at a carrier frequency and down-convert the OFDM signals into OFDM baseband signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202.
[0064] Although not shown in FIG. 2, the wireless devices 100 and 200 may further include additional components. The additional components 140 may be variously configured according to types of the wireless devices 100 and 200. For example, the additional components 140 may include at least one of a power unit / battery, an Input / Output (I / O) device (e.g., audio I / O port, video I / O port), a driving device, and a computing device. The additional components 140 may be coupled to the one or more processors 102 and 202 via various technologies, such as a wired or wireless connection.
[0065] In the implementations of the present disclosure, a UE may operate as a transmitting device in UL and as a receiving device in DL. In the implementations of the present disclosure, a BS may operate as a receiving device in UL and as a transmitting device in DL. Hereinafter, for convenience of description, it is mainly assumed that the first wireless device 100 acts as the UE, and the second wireless device 200 acts as the BS. For example, the processor(s) 102 connected to, mounted on or launched in the first wireless device 100 may be adapted to perform the UE behavior according to an implementation of the present disclosure or control the transceiver(s) 106 to perform the UE behavior according to an implementation of the present disclosure. The processor(s) 202 connected to, mounted on or launched in the second wireless device 200 may be adapted to perform the BS behavior according to an implementation of the present disclosure or control the transceiver(s) 206 to perform the BS behavior according to an implementation of the present disclosure.
[0066] In the present disclosure, a BS is also referred to as a node B (NB), an eNode B (eNB), or a gNB.
[0067] FIG. 3 shows an example of UE to which implementations of the present disclosure are applied.
[0068] Referring to FIG. 3, a UE 100 may correspond to the first wireless device 100 of FIG. 2.
[0069] A UE 100 includes a processor 102, a memory 104, a transceiver 106, one or more antennas 108, a power management module 141, a battery 142, a display 143, a keypad 144, a Subscriber Identification Module (SIM) card 145, a speaker 146, and a microphone 147.
[0070] The processor 102 may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The processor 102 may be adapted to control one or more other components of the UE 100 to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. Layers of the radio interface protocol may be implemented in the processor 102. The processor 102 may include ASIC, other chipset, logic circuit and / or data processing device. The processor 102 may be an application processor. The processor 102 may include at least one of DSP, CPU, GPU, a modem (modulator and demodulator). An example of the processor 102 may be found in SNAPDRAGONTMseries of processors made by Qualcomm®, EXYNOSTMseries of processors made by Samsung®, A series of processors made by Apple®, HELIOTMseries of processors made by MediaTek®, ATOMTMseries of processors made by Intel®or a corresponding next generation processor.
[0071] The memory 104 is operatively coupled with the processor 102 and stores a variety of information to operate the processor 102. The memory 104 may include ROM, RAM, flash memory, memory card, storage medium and / or other storage device. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The modules can be stored in the memory 104 and executed by the processor 102. The memory 104 can be implemented within the processor 102 or external to the processor 102 in which case those can be communicatively coupled to the processor 102 via various means as is known in the art.
[0072] The transceiver 106 is operatively coupled with the processor 102, and transmits and / or receives a radio signal. The transceiver 106 includes a transmitter and a receiver. The transceiver 106 may include baseband circuitry to process radio frequency signals. The transceiver 106 controls the one or more antennas 108 to transmit and / or receive a radio signal.
[0073] The power management module 141 manages power for the processor 102 and / or the transceiver 106. The battery 142 supplies power to the power management module 141.
[0074] The display 143 outputs results processed by the processor 102. The keypad 144 receives inputs to be used by the processor 102. The keypad 144 may be shown on the display 143.
[0075] The SIM card 145 is an integrated circuit that is intended to securely store the International Mobile Subscriber Identity (IMSI) number and its related key, which are used to identify and authenticate subscribers on mobile telephony devices (such as mobile phones and computers). It is also possible to store contact information on many SIM cards.
[0076] The speaker 146 outputs sound-related results processed by the processor 102. The microphone 147 receives sound-related inputs to be used by the processor 102.
[0077] FIGS. 4 and 5 show an example of protocol stacks in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0078] In particular, FIG. 4 illustrates an example of a radio interface user plane protocol stack between a UE and a BS and FIG. 5 illustrates an example of a radio interface control plane protocol stack between a UE and a BS. The control plane refers to a path through which control messages used to manage call by a UE and a network are transported. The user plane refers to a path through which data generated in an application layer, for example, voice data or Internet packet data are transported. Referring to FIG. 4, the user plane protocol stack may be divided into Layer 1 (i.e., a PHY layer) and Layer 2. Referring to FIG. 5, the control plane protocol stack may be divided into Layer 1 (i.e., a PHY layer), Layer 2, Layer 3 (e.g., an RRC layer), and a Non-Access Stratum (NAS) layer. Layer 1, Layer 2 and Layer 3 are referred to as an Access Stratum (AS).
[0079] In the 3GPP LTE system, the Layer 2 is split into the following sublayers: MAC, RLC, and PDCP. In the 3GPP NR system, the Layer 2 is split into the following sublayers: MAC, RLC, PDCP and SDAP. The PHY layer offers to the MAC sublayer transport channels, the MAC sublayer offers to the RLC sublayer logical channels, the RLC sublayer offers to the PDCP sublayer RLC channels, the PDCP sublayer offers to the SDAP sublayer radio bearers. The SDAP sublayer offers to 5G core network Quality of Service (QoS) flows.
[0080] In the 3GPP NR system, the main services and functions of the MAC sublayer include: mapping between logical channels and transport channels; multiplexing / de-multiplexing of MAC SDUs belonging to one or different logical channels into / from Transport Blocks (TB) delivered to / from the physical layer on transport channels; scheduling information reporting; error correction through Hybrid Automatic Repeat reQuest (HARQ) (one HARQ entity per cell in case of Carrier Aggregation (CA)); priority handling between UEs by means of dynamic scheduling; priority handling between logical channels of one UE by means of logical channel prioritization; padding. A single MAC entity may support multiple numerologies, transmission timings and cells. Mapping restrictions in logical channel prioritization control which numerology(ies), cell(s), and transmission timing(s) a logical channel can use.
[0081] Different kinds of data transfer services are offered by MAC. To accommodate different kinds of data transfer services, multiple types of logical channels are defined, i.e., each supporting transfer of a particular type of information. Each logical channel type is defined by what type of information is transferred. Logical channels are classified into two groups: control channels and traffic channels. Control channels are used for the transfer of control plane information only, and traffic channels are used for the transfer of user plane information only. Broadcast Control Channel (BCCH) is a downlink logical channel for broadcasting system control information, Paging Control Channel (PCCH) is a downlink logical channel that transfers paging information, system information change notifications and indications of ongoing Public Warning Service (PWS) broadcasts, Common Control Channel (CCCH) is a logical channel for transmitting control information between UEs and network and used for UEs having no RRC connection with the network, and Dedicated Control Channel (DCCH) is a point-to-point bi-directional logical channel that transmits dedicated control information between a UE and the network and used by UEs having an RRC connection. Dedicated Traffic Channel (DTCH) is a point-to-point logical channel, dedicated to one UE, for the transfer of user information. A DTCH can exist in both uplink and downlink. In downlink, the following connections between logical channels and transport channels exist: BCCH can be mapped to Broadcast Channel (BCH); BCCH can be mapped to Downlink Shared Channel (DL-SCH); PCCH can be mapped to Paging Channel (PCH); CCCH can be mapped to DL-SCH; DCCH can be mapped to DL-SCH; and DTCH can be mapped to DL-SCH. In uplink, the following connections between logical channels and transport channels exist: CCCH can be mapped to Uplink Shared Channel (UL-SCH); DCCH can be mapped to UL-SCH; and DTCH can be mapped to UL-SCH.
[0082] The RLC sublayer supports three transmission modes: Transparent Mode (TM), Unacknowledged Mode (UM), and Acknowledged Mode (AM). The RLC configuration is per logical channel with no dependency on numerologies and / or transmission durations. In the 3GPP NR system, the main services and functions of the RLC sublayer depend on the transmission mode and include: transfer of upper layer PDUs; sequence numbering independent of the one in PDCP (UM and AM); error correction through ARQ (AM only); segmentation (AM and UM) and re-segmentation (AM only) of RLC SDUs; reassembly of SDU (AM and UM); duplicate detection (AM only); RLC SDU discard (AM and UM); RLC re-establishment; protocol error detection (AM only).
[0083] In the 3GPP NR system, the main services and functions of the PDCP sublayer for the user plane include: sequence numbering; header compression and decompression using Robust Header Compression (ROHC); transfer of user data; reordering and duplicate detection; in-order delivery; PDCP PDU routing (in case of split bearers); retransmission of PDCP SDUs; ciphering, deciphering and integrity protection; PDCP SDU discard; PDCP re-establishment and data recovery for RLC AM; PDCP status reporting for RLC AM; duplication of PDCP PDUs and duplicate discard indication to lower layers. The main services and functions of the PDCP sublayer for the control plane include: sequence numbering; ciphering, deciphering and integrity protection; transfer of control plane data; reordering and duplicate detection; in-order delivery; duplication of PDCP PDUs and duplicate discard indication to lower layers.
[0084] In the 3GPP NR system, the main services and functions of SDAP include: mapping between a QoS flow and a data radio bearer; marking QoS Flow ID (QFI) in both DL and UL packets. A single protocol entity of SDAP is configured for each individual PDU session.
[0085] In the 3GPP NR system, the main services and functions of the RRC sublayer include: broadcast of system information related to AS and NAS; paging initiated by 5G Core network (5GC) or Next-Generation Radio Access Network (NG-RAN); establishment, maintenance and release of an RRC connection between the UE and NG-RAN; security functions including key management; establishment, configuration, maintenance and release of Signaling Radio Bearers (SRBs) and Data Radio Bearers (DRBs); mobility functions (including: handover and context transfer, UE cell selection and reselection and control of cell selection and reselection, inter-RAT mobility); QoS management functions; UE measurement reporting and control of the reporting; detection of and recovery from radio link failure; NAS message transfer to / from NAS from / to UE.
[0086] FIG. 6 shows a frame structure in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0087] The frame structure shown in FIG. 6 is purely exemplary and the number of subframes, the number of slots, and / or the number of symbols in a frame may be variously changed. In the 3GPP based wireless communication system, OFDM numerologies (e.g., SCS, Transmission Time Interval (TTI) duration) may be differently configured between a plurality of cells aggregated for one UE. For example, if a UE is configured with different SCSs for cells aggregated for the cell, an (absolute time) duration of a time resource (e.g., a subframe, a slot, or a TTI) including the same number of symbols may be different among the aggregated cells. Herein, symbols may include OFDM symbols (or Cyclic Prefix (CP)-OFDM symbols), SC-FDMA symbols (or Discrete Fourier Transform-spread-OFDM (DFT-s-OFDM) symbols).
[0088] Referring to FIG. 6, downlink and uplink transmissions are organized into frames. Each frame has Tf= 10ms duration. Each frame is divided into two half-frames, where each of the half-frames has 5ms duration. Each half-frame consists of 5 subframes, where the duration Tsfper subframe is 1ms. Each subframe is divided into slots and the number of slots in a subframe depends on a subcarrier spacing. Each slot includes 14 or 12 OFDM symbols based on a CP. In a normal CP, each slot includes 14 OFDM symbols and, in an extended CP, each slot includes 12 OFDM symbols. The numerology is based on exponentially scalable subcarrier spacing Δf = 2u*15 kHz.
[0089] Table 3 shows the number of OFDM symbols per slot Nslotsymb, the number of slots per frameNframe,uslot, and the number of slots per subframe Nsubframe,uslotfor the normal CP, according to the subcarrier spacing Δf = 2u*15 kHz.
[0090] uNslotsymbNframe,uslotNsubframe,uslot01410111420221440431480841416016
[0091] Table 4 shows the number of OFDM symbols per slot Nslotsymb, the number of slots per frameNframe,uslot, and the number of slots per subframe Nsubframe,uslotfor the extended CP, according to the subcarrier spacing Δf = 2u*15 kHz.
[0092] uNslotsymbNframe,uslotNsubframe,uslot212404
[0093] A slot includes plural symbols (e.g., 14 or 12 symbols) in the time domain. For each numerology (e.g., subcarrier spacing) and carrier, a resource grid ofNsize,ugrid,x*NRBscsubcarriers andNsubframe,usymbOFDM symbols is defined, starting at Common Resource Block (CRB)Nstart,ugridindicated by higher-layer signaling (e.g., RRC signaling), whereNsize,ugrid,xis the number of Resource Blocks (RBs) in the resource grid and the subscript x is DL for downlink and UL for uplink.NRBscis the number of subcarriers per RB. In the 3GPP based wireless communication system,NRBscis 12 generally. There is one resource grid for a given antenna portp, subcarrier spacing configurationu, and transmission direction (DL or UL). The carrier bandwidthNsize,ugridfor subcarrier spacing configurationuis given by the higher-layer parameter (e.g., RRC parameter). Each element in the resource grid for the antenna portpand the subcarrier spacing configurationuis referred to as a Resource Element (RE) and one complex symbol may be mapped to each RE. Each RE in the resource grid is uniquely identified by an indexkin the frequency domain and an indexlrepresenting a symbol location relative to a reference point in the time domain. In the 3GPP based wireless communication system, an RB is defined by 12 consecutive subcarriers in the frequency domain.
[0094] In the 3GPP NR system, RBs are classified into CRBs and Physical Resource Blocks (PRBs). CRBs are numbered from 0 and upwards in the frequency domain for subcarrier spacing configurationu. The center of subcarrier 0 of CRB 0 for subcarrier spacing configurationucoincides with 'point A' which serves as a common reference point for resource block grids. In the 3GPP NR system, PRBs are defined within a BandWidth Part (BWP) and numbered from 0 toNsizeBWP,i-1, where i is the number of the bandwidth part. The relation between the physical resource block nPRBin the bandwidth part i and the common resource block nCRBis as follows: nPRB= nCRB+NsizeBWP,i, whereNsizeBWP,iis the common resource block where bandwidth part starts relative to CRB 0. The BWP includes a plurality of consecutive RBs. A carrier may include a maximum of N (e.g., 5) BWPs. A UE may be configured with one or more BWPs on a given component carrier. Only one BWP among BWPs configured to the UE can active at a time. The active BWP defines the UE's operating bandwidth within the cell's operating bandwidth.
[0095] In the present disclosure, the term "cell" may refer to a geographic area to which one or more nodes provide a communication system, or refer to radio resources. A "cell" as a geographic area may be understood as coverage within which a node can provide service using a carrier and a "cell" as radio resources (e.g., time-frequency resources) is associated with bandwidth which is a frequency range configured by the carrier. The "cell" associated with the radio resources is defined by a combination of downlink resources and uplink resources, for example, a combination of a DL Component Carrier (CC) and a UL CC. The cell may be configured by downlink resources only, or may be configured by downlink resources and uplink resources. Since DL coverage, which is a range within which the node is capable of transmitting a valid signal, and UL coverage, which is a range within which the node is capable of receiving the valid signal from the UE, depends upon a carrier carrying the signal, the coverage of the node may be associated with coverage of the "cell" of radio resources used by the node. Accordingly, the term "cell" may be used to represent service coverage of the node sometimes, radio resources at other times, or a range that signals using the radio resources can reach with valid strength at other times.
[0096] In CA, two or more CCs are aggregated. A UE may simultaneously receive or transmit on one or multiple CCs depending on its capabilities. CA is supported for both contiguous and non-contiguous CCs. When CA is configured, the UE only has one RRC connection with the network. At RRC connection establishment / re-establishment / handover, one serving cell provides the NAS mobility information, and at RRC connection re-establishment / handover, one serving cell provides the security input. This cell is referred to as the Primary Cell (PCell). The PCell is a cell, operating on the primary frequency, in which the UE either performs the initial connection establishment procedure or initiates the connection re-establishment procedure. Depending on UE capabilities, Secondary Cells (SCells) can be configured to form together with the PCell a set of serving cells. An SCell is a cell providing additional radio resources on top of Special Cell (SpCell). The configured set of serving cells for a UE therefore always consists of one PCell and one or more SCells. For Dual Connectivity (DC) operation, the term SpCell refers to the PCell of the Master Cell Group (MCG) or the Primary SCell (PSCell) of the Secondary Cell Group (SCG). An SpCell supports Physical Uplink Control Channel (PUCCH) transmission and contention-based random access, and is always activated. The MCG is a group of serving cells associated with a master node, comprised of the SpCell (PCell) and optionally one or more SCells. The SCG is the subset of serving cells associated with a secondary node, comprised of the PSCell and zero or more SCells, for a UE configured with DC. For a UE in RRC_CONNECTED not configured with CA / DC, there is only one serving cell comprised of the PCell. For a UE in RRC_CONNECTED configured with CA / DC, the term "serving cells" is used to denote the set of cells comprised of the SpCell(s) and all SCells. In DC, two MAC entities are configured in a UE: one for the MCG and one for the SCG.
[0097] FIG. 7 shows a data flow example in the 3GPP NR system to which implementations of the present disclosure are applied.
[0098] Referring to FIG. 7, "RB" denotes a radio bearer, and "H" denotes a header. Radio bearers are categorized into two groups: DRBs for user plane data and SRBs for control plane data. The MAC PDU is transmitted / received using radio resources through the PHY layer to / from an external device. The MAC PDU arrives to the PHY layer in the form of a transport block.
[0099] In the PHY layer, the uplink transport channels UL-SCH and Random Access Channel (RACH) are mapped to their physical channels Physical Uplink Shared Channel (PUSCH) and Physical Random Access Channel (PRACH), respectively, and the downlink transport channels DL-SCH, BCH and PCH are mapped to Physical Downlink Shared Channel (PDSCH), Physical Broadcast Channel (PBCH) and PDSCH, respectively. In the PHY layer, Uplink Control Information (UCI) is mapped to PUCCH, and Downlink Control Information (DCI) is mapped to Physical Downlink Control Channel (PDCCH). A MAC PDU related to UL-SCH is transmitted by a UE via a PUSCH based on an UL grant, and a MAC PDU related to DL-SCH is transmitted by a BS via a PDSCH based on a DL assignment.
[0100] Network controlled mobility applies to UEs in RRC_CONNECTED and is categorized into two types of mobility: cell level mobility and beam level mobility. Beam level mobility includes intra-cell beam level mobility and inter-cell beam level mobility.
[0101] Cell level mobility requires explicit RRC signaling to be triggered, i.e., handover.
[0102] FIG. 8 shows an example of inter-gNB handover procedures to which implementations of the present disclosure are applied.
[0103] For inter-gNB handover, the signaling procedures consist of at least the following elemental components described in FIG. 8.
[0104] 1. Step 1: The source gNB initiates handover and issues a HANDOVER REQUEST over the Xn interface.
[0105] 2. Step 2: The target gNB performs admission control and provides the new RRC configuration as part of the HANDOVER REQUEST ACKNOWLEDGE.
[0106] 3. Step 3: The source gNB provides the RRC configuration to the UE by forwarding theRRCReconfigurationmessage received in the HANDOVER REQUEST ACKNOWLEDGE. TheRRCReconfigurationmessage includes at least cell ID and all information required to access the target cell so that the UE can access the target cell without reading system information. For some cases, the information required for contention-based and contention-free random access can be included in theRRCReconfigurationmessage. The access information to the target cell may include beam specific information, if any.
[0107] 4. Step 4: The UE moves the RRC connection to the target gNB and replies with theRRCReconfigurationComplete.
[0108] User data may also be sent in step 4 if the grant allows.
[0109] Beam level mobility does not require explicit RRC signaling to be triggered. Beam level mobility can be within a cell, or between cells, the latter is referred to as Inter-Cell Beam Management (ICBM). For ICBM, a UE can receive or transmit UE dedicated channels / signals via a Transmission / Reception Point (TRP) associated with a Physical Cell ID (PCI) different from the PCI of a serving cell, while non-UE-dedicated channels / signals can only be received via a TRP associated with a PCI of the serving cell. The gNB provides via RRC signaling the UE with measurement configuration containing configurations of Synchronization Signal Block (SSB) / Channel State Information (CSI) resources and resource sets, reports and trigger states for triggering channel and interference measurements and reports. In case of ICBM, a measurement configuration includes SSB resources associated with PCIs different from the PCI of a serving cell. Beam level mobility is then dealt with at lower layers by means of physical layer and MAC layer control signaling, and RRC is not required to know which beam is being used at a given point in time.
[0110] SSB-based beam level mobility is based on the SSB associated to the initial DL BWP and can only be configured for the initial DL BWPs and for DL BWPs containing the SSB associated to the initial DL BWP. For other DL BWPs, beam level mobility can only be performed based on CSI-Reference Signal (RS).
[0111] A Conditional Handover (CHO) is defined as a handover that is executed by the UE when one or more handover execution conditions are met. The UE starts evaluating the execution condition(s) upon receiving the CHO configuration, and stops evaluating the execution condition(s) once a handover is executed.
[0112] The following principles apply to CHO:
[0113] - The CHO configuration contains the configuration of CHO candidate cell(s) generated by the candidate gNB(s) and execution condition(s) generated by the source gNB.
[0114] - An execution condition may consist of one or two trigger condition(s) (CHO events A3 / ). Only single RS type is supported and at most two different trigger quantities (e.g., Reference Signal Received Power (RSRP) and Reference Signal Received Quality (RSRQ), RSRP and Signal-to-Interference plus Noise Ratio (SINR), etc.) can be configured simultaneously for the evaluation of CHO execution condition of a single candidate cell.
[0115] - Before any CHO execution condition is satisfied, upon reception of HO command (without CHO configuration), the UE executes the HO procedure, regardless of any previously received CHO configuration.
[0116] - While executing CHO, i.e., from the time when the UE starts synchronization with target cell, the UE does not monitor source cell.
[0117] L1 / L2 Triggered Mobility (LTM) is a procedure in which a gNB receives L1 measurement report(s) from a UE, and on their basis the gNB changes UE's serving cell by a cell switch command signaled via a MAC CE. The cell switch command indicates an LTM candidate cell configuration that the gNB previously prepared and provided to the UE through RRC signaling. Then the UE switches to the target cell according to the cell switch command. The LTM procedure can be used to reduce the mobility latency.
[0118] When configured by the network, it is possible to activate Transmission Configuration Index (TCI) states of one or multiple cells that are different from the current serving cell. For instance, the TCI states of the LTM candidate cells can be activated in advance before any of those cells become the serving cell. This allows the UE to be DL synchronized with those cells, thereby facilitating a faster cell switch to one of those cells when cell switch is triggered.
[0119] When configured by the network, it is possible to initiate UL Timing Advance (TA) acquisition procedure to one or multiple cells that are different from the current serving cell. For instance, the network may request the UE to perform early TA acquisition of a candidate cell before a cell switch. The early TA acquisition is triggered by PDCCH order or realized through UE-based TA measurement. In the former case, the gNB to which the candidate cell belongs calculates the TA value and sends it to the gNB to which the serving cell belongs. The serving cell sends the TA value in the LTM cell switch command MAC CE when triggering LTM cell switch. In the latter case, the UE applies the TA value measured by itself and performs RACH-less LTM upon receiving the cell switch command.
[0120] If UE-based TA measurement is configured, the UE performs RACH-less LTM upon receiving the cell switch command. Otherwise, the UE determines whether to access the target cell with the RA procedure depending on whether a TA value is provided in the cell switch command. For RACH-less LTM, the UE accesses the target cell via a configured grant provided in the LTM candidate cell configuration and selects the configured grant occasion associated with the beam indicated in the cell switch command. If the LTM candidate cell configuration does not include a configured grant, the UE may monitor PDCCH for dynamic scheduling from the target cell upon LTM cell switch. Before RACH-less LTM procedure completion, the UE may not trigger random access procedure if it does not have a valid PUCCH resource for triggered Scheduling Requests (SRs).
[0121] The following principles apply to LTM:
[0122] - The UE does not update its security key after an intra-gNB LTM cell switch.
[0123] - Subsequent LTM is supported.
[0124] LTM supports both intra-gNB-Distributed Unit (DU) and intra-gNB-Centralized Unit (CU) inter-gNB-DU mobility. LTM supports both intra-frequency and inter-frequency mobility, including mobility to inter-frequency cell that is not a current serving cell. The following scenarios are supported:
[0125] - PCell change in non-CA scenario and non-DC scenario,
[0126] - PCell change in CA scenario,
[0127] - DC scenario, MCG PCell change and SCG PSCell change without MN involvement case (i.e., intra-SN PSCell change).
[0128] While the UE has stored LTM candidate cell configurations, the UE can also execute any L3 handover command sent by the network.
[0129] FIG. 9 shows an example of signaling procedure for LTM to which implementations of the present disclosure are applied.
[0130] Cell switch command is conveyed in a MAC Control Element (CE), which contains the necessary information to perform the LTM cell switch.
[0131] Subsequent LTM is done by repeating the early synchronization, LTM cell switch execution, and LTM cell switch completion steps without releasing other LTM candidate cell configurations after each LTM cell switch completion.
[0132] The signaling procedure for LTM is as follows.
[0133] 1. Step 1: The UE sends aMeasurementReportmessage to the gNB. The gNB decides to configure LTM and initiates candidate cell(s) preparation.
[0134] 2. Step 2: The gNB transmits anRRCReconfigurationmessage to the UE including the LTM candidate cell configurations of one or multiple candidate cells.
[0135] 3. Step 3: The UE stores the LTM candidate cell configurations and transmits anRRCReconfigurationCompletemessage to the gNB.
[0136] 4a. Step 4a: The UE may perform DL synchronization with the candidate cell(s) before receiving the cell switch command.
[0137] 4b. Step 4b: When UE-based TA measurement is configured, the UE may acquire the TA value(s) of the candidate cell(s) by measurement. Otherwise, the UE may perform early TA acquisition with the candidate cell(s) as requested by the network before receiving the cell switch command. This may be done via Contention-Free Random Access (CFRA) triggered by a PDCCH order from the source cell, following which the UE may send preamble towards the indicated candidate cell. In order to minimize the data interruption of the source cell due to CFRA towards the candidate cell(s), the UE may not receive random access response from the network for the purpose of TA value acquisition and the TA value of the candidate cell is indicated in the cell switch command. The UE may not maintain the TA timer for the candidate cell and relies on network implementation to guarantee the TA validity.
[0138] 5. Step 5: The UE performs L1 measurements on the configured candidate cell(s) and transmits L1 measurement reports to the gNB. L1 measurement should be performed as long as RRC reconfiguration (step 2) is applicable.
[0139] 6. Step 6: The gNB decides to execute cell switch to a target cell and transmits a MAC CE triggering cell switch by including the candidate configuration index of the target cell. The UE switches to the target cell and applies the configuration indicated by candidate configuration index.
[0140] 7. Step 7: The UE may perform the random access procedure towards the target cell, if the UE does not have valid TA of the target cell. The UE may perform CFRA if the LTM cell switch command MAC CE contains information for CFRA.
[0141] 8. Step 8: The UE completes the LTM cell switch procedure by sendingRRCReconfigurationCompletemessage to target cell. If the UE has performed a random access procedure in step 7, the UE considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM, the UE considers that LTM cell switch execution is successfully completed when the UE determines that the network has successfully received its first UL data. The UE determines successful reception of its first UL data by receiving a PDCCH addressing the UE's Cell Radio Network Temporary Identity (C-RNTI) in the target cell, which schedules a new transmission following the first UL data. The PDCCH carries either a DL assignment or an UL grant addressing the same HARQ process as the first UL data.
[0142] The steps 4-8 can be performed multiple times for subsequent LTM using the LTM candidate cell configuration(s) provided in step 2.
[0143] Security handling in mobility is described.
[0144] Whenever an initial AS security context needs to be established between UE and gNB / ng-eNB, Access and mobility Management Function (AMF) and the UE may derive a KgNBand a Next Hop parameter (NH). The KgNBand the NH are derived from the KAMF. A NH Chaining Counter (NCC) is associated with each KgNBand NH parameter. Every KgNBis associated with the NCC corresponding to the NH value from which it was derived. At initial setup, the KgNBis derived directly from KAMF, and is then considered to be associated with a virtual NH parameter with NCC value equal to zero. At initial setup, the derived NH value is associated with the NCC value one.
[0145] The AMF may not send the NH value to gNB / ng-eNB at the initial connection setup. The gNB / ng-eNB may initialize the NCC value to zero after receiving NGAP Initial Context Setup Request message.
[0146] The UE and the gNB / ng-eNB use the KgNBto secure the communication between each other. On handovers and at transitions from RRC_INACTIVE to RRC_CONNECTED states, the basis for the KgNBthat will be used between the UE and the target gNB / ng-eNB, called KNG-RAN*, is derived from either the currently active KgNBor from the NH parameter. If KNG-RAN* is derived from the currently active KgNB, this is referred to as a horizontal key derivation and if the KNG-RAN* is derived from the NH parameter, the derivation is referred to as a vertical key derivation.
[0147] As NH parameters are only computable by the UE and the AMF, it is arranged so that NH parameters are provided to gNB / ng-eNBs from the AMF in such a way that forward security can be achieved.
[0148] On handovers with vertical key derivation, the NH is further bound to the target PCI and its frequency Absolute Radio-Frequency Channel Number (ARFCN)-DL before it is taken into use as the KgNBin the target gNB / ng-eNB. On handovers with horizontal key derivation, the currently active KgNBis further bound to the target PCI and its frequency ARFCN-DL before it is taken into use as the KgNBin the target gNB / ng-eNB.
[0149] In intra-gNB-CU handover and intra-ng-eNB handover, the gNB may have a policy deciding at which intra-gNB-CU handovers the KgNBcan be retained and at which a new KgNBneeds to be derived. At an intra-gNB-CU handover, the gNB may indicate to the UE whether to change or retain the current KgNBin the HO Command message. Retaining the current KgNBmay only be done during intra-gNB-CU handover.
[0150] If the current KgNBis to be changed, the gNB / ng-eNB and the UE may derive a KNG-RAN* using target PCI, its frequency ARFCN-DL / E-UTRAN ARFCN (EARFCN)-DL, and either NH or the current KgNBdepending on the following criteria: the gNB may use the NH for deriving KNG-RAN* if an unused {NH, NCC} pair is available in the gNB (this is referred to as a vertical key derivation), otherwise if no unused {NH, NCC} pair is available in the gNB, the gNB may derive KNG-RAN* from the current KgNB(this is referred to as a horizontal key derivation). The gNB may send the NCC used for the KNG-RAN* derivation to UE in HO Command message. The gNB / ng-eNB and the UE may use the KNG-RAN* as the KgNB, after handover.
[0151] If the current KgNBis to be retained, the gNB and the UE may continue using the current KgNB, after handover.
[0152] This may also be applicable when gNB is implemented as a single unit, i.e., when the gNB is not split into CU and DU.
[0153] In Xn handover, the source gNB / ng-eNB may perform a vertical key derivation in case it has an unused {NH, NCC} pair. The source gNB / ng-eNB may first compute KNG-RAN* from target PCI, its frequency ARFCN-DL / EARFCN-DL, and either from currently active KgNBin case of horizontal key derivation or from the NH in case of vertical key derivation.
[0154] Next, the source gNB / ng-eNB may forward the {KNG-RAN*, NCC} pair to the target gNB / ng-eNB. The target gNB / ng-eNB may use the received KNG-RAN* directly as KgNBto be used with the UE. The target gNB / ng-eNB may associate the NCC value received from source gNB / ng-eNB with the KgNB. The target gNB / ng-eNB may include the received NCC into the prepared HO Command message, which is sent back to the source gNB / ng-eNB in a transparent container and forwarded to the UE by source gNB / ng-eNB.
[0155] When the target gNB / ng-eNB has completed the handover signaling with the UE, it may send a NGAP PATH SWITCH REQUEST message to the AMF. Upon reception of the NGAP PATH SWITCH REQUEST, the AMF may increase its locally kept NCC value by one and compute a new fresh NH from its stored data using the function. The AMF may use the KAMFfrom the currently active 5G NAS security context for the computation of the new fresh NH. The AMF may then send the newly computed {NH, NCC} pair to the target gNB / ng-eNB in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The target gNB / ng-eNB may store the received {NH, NCC} pair for further handovers and remove other existing unused stored {NH, NCC} pairs if any.
[0156] If the AMF had activated a new 5G NAS security context with a new KAMF, different from the 5G NAS security context on which the currently active 5G AS security context is based, but has not yet successfully performed a UE Context Modification procedure, the sent NGAP PATH SWITCH REQUEST ACKNOWLEDGE message may in addition contain a New Security Context Indicator (NSCI). The AMF may in this case derive a new initial KgNBfrom the new KAMFand the uplink NAS COUNT in the most recent NAS Security Mode Complete message. The AMF may associate the derived new initial KgNBwith a new NCC value equal to zero. Then, the AMF may use {the derived new initial KgNB, the new NCC value initialized to zero} pair as the newly computed {NH, NCC} pair to be sent in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The gNB / ng-eNB may in this case set the value ofkeySetChangeIndicatorfield to true in further handovers. The gNB / ng-eNB should in this case perform an intra-gNB-CU / intra-ng-eNB handover immediately.
[0157] The key derivation mechanism described above may also be applicable to CHO.
[0158] The UE behavior is the same regardless if the handover is intra-gNB-CU, intra ng-eNB, Xn, or N2 with the exception that during intra-gNB-CU handover, the UE may retain the same key based on an indication from the gNB. The UE behavior is also same in case of CHO, i.e., the UE shall use the parameters of the selected target cell in KNG-RAN* derivations.
[0159] If the UE also receives a NAS Container (NASC) in the HO Command message, the UE may update its NAS security context as follows:
[0160] 1> The UE may verify the freshness of the downlink NAS COUNT in the NASC.
[0161] 1> If the NASC indicates a new KAMFhas been calculated (i.e., K_AMF_change_flag is one),
[0162] 2> The UE may compute the horizontally derived KAMFusing the KAMFfrom the current 5G NAS security context identified by the ngKSI included in the NASC and the downlink NAS COUNT in the NASC.
[0163] 2> The UE may assign the ngKSI included in the NASC to the ngKSI of the new derived KAMF. The UE may further configure NAS security based on the horizontally derived KAMFand the selected NAS security algorithms in the NASC.
[0164] 2> The UE may further verify the NAS MAC in the NASC and if the verification is successful, the UE may further set the NAS COUNTs to zero.
[0165] 1> If KAMFchange is not indicated,
[0166] 2> If the verification is successful, the UE may configure the NAS security based on the parameters included in the NASC but may not set the NAS COUNTs to zero.
[0167] 2> The UE may verify the NAS MAC in the NASC.
[0168] 2> The UE may further set the downlink NAS COUNT value of the currently active NAS security context to the received downlink NAS COUNT value in the NASC.
[0169] If verification of the NASC fails, the UE may abort the handover procedure. Furthermore, the UE may discard the new NAS security context if it was derived and continue to use the existing NAS and AS security contexts.
[0170] The UE may use the KNG-RAN* as the KgNBwhen communicating with the target gNB and as the KeNBwhen communicating with the target ng-eNB.
[0171] The S-KeNBthat is used for dual connectivity between base stations is also used as the root for the security context at the secondary base station (e.g., Secondary gNB (SgNB)). When used in the contexts of dual connectivity with an SgNB, the key may be called an S-KgNB, i.e., the master base station (e.g., Master eNB (MeNB) and / or Master gNB (MgNB)) generates and forwards an S-KgNBto the SgNB during the SgNB addition procedure or SgNB mprocedure requiring key update.
[0172] Similarly, the MeNB / MgNB handles the SCG counter due to interactions with a SgNB for interactions with SeNBs, i.e., this is a single shared SCG counter for SeNBs and SgNBs and provides the same value of SCG counter used to the UE and ensure that fresh radio bearer identities are used or the S-KgNBis refreshed.
[0173] When the SgNB receives an S-KgNBin a SgNB addition / modification procedure, the SgNB may derive and store KSgNB-UP-encand KSgNB-UP-int, as well as KSgNB-RRC-intand KSgNB-RRC-encif an SRB is to be added from the received S-KgNB. These freshly derived keys are then used to protect all the radio bearer(s) that use the PDCP of the SgNB. Any previous such keys may be deleted. If all the keys were derived, then the S-KgNBmay be deleted.
[0174] If the UE receives a new SCG counter in SgNB addition / modification procedure, then the UE may derive a new S-KgNBfrom this SCG counter and use KSgNB-UP-enc, KSgNB-UP-int, KSgNB-RRC-intand KSgNB-RRC-encderived from the new S-KgNB, as the keys to protect all the radio bearer(s) using the PDCP of the SgNB. If all the keys were derived, then the S-KgNBmay be deleted in the UE.
[0175] When the SgNB release procedure releases the last radio bearer on the SgNB, the SgNB and the UE may delete the KSgNB-UPenc,KSgNB-UP-int,KSgNB-RRC-intand KSgNB-RRC-enc. The SgNB and UE may also delete the S-KgNB, if it was not deleted earlier.
[0176] The UE and MeNB / MgNB may derive the security key S-KgNBof the target SgNB. KSgNB-UP-enc, KSgNB-UP-int,KSgNB-RRC-intand KSgNB-RRC-encare derived from the S-KgNBboth at the SgNB side and the UE side.
[0177] The system supports update of the S-KgNB. The MeNB / MgNB may update the S-KgNBfor any reason by using the S-KgNBupdate procedure. The SgNB may request the MeNB / MgNB to update the S-KgNBover the X2-C, when uplink or downlink PDCP COUNTs are about to wrap around for any of the SgNB terminated DRBs or SgNB terminated SRB.
[0178] If the MeNB / MgNB re-keys its currently active KeNBin an AS security context, the MeNB / MgNB may update any S-KgNBassociated with that AS security context. This retains the two-hop security property for X2-handovers.
[0179] If the MeNB / MgNB receives a request for S-KgNBupdate from the SgNB or decides on its own to perform S-KgNBupdate, the MeNB / MgNB may compute a fresh S-KgNBand increment the SCG counter. Thenthe MeNB / MgNB may performa SgNB modification procedure to deliver the fresh S-KgNBto the SgNB. The MeNB / MgNB may provide the value of the SCG counter used in the derivation of the S-KgNBto the UE in an integrity protected RRC procedure. The UE may derive the S-KgNB.
[0180] Whenever the UE or SgNB start using a fresh S-KgNB, they may re-calculate KSgNB-UP-int, KSgNB-UP-enc, KSgNB-RRC-intand KSgNB-RRC-encfrom the fresh S-KgNB.
[0181] Scenarios considered in LTM have been limited to intra-CU case only, i.e., serving cell change within cells under a single CU. For NR mobility enhancement, support for inter-CU LTM has been studied. Specifically, it has been studied to support for subsequent LTM mobility procedures aiming to avoid RRC configuration between cell switches as per current LTM mechanism. In other words, inter-CU mobility should support initial and subsequent serving cell changes based on a single mobility configuration (i.e., no RRC reconfiguration between cell switches). Since the subsequent mobility (e.g., LTM and / or Subsequent Conditional PSCell Addition and Change (SCPAC)) should be able to support continuous mobilities based on the pre-configuration without additional reconfiguration from the network, the UE may receive multiple security key values required when performing inter-MN subsequent mobility.
[0182] However, when performing the inter-MN subsequent mobility, security mismatch problems may occur between the network and the UE. This is because, if a mobility failure is declared during the inter-MN subsequent mobility such as CHO and LTM, the UE can initiate the UE-based failure recovery procedure.
[0183] If the UE has received the multiple security key values for the inter-MN subsequent mobility (and in fact, the mobility failure may occur due to a security problem), the UE may revert back to the source cell configuration from applying the target cell configuration, and then the UE may initiate the UE-based failure recovery. In this process, the security information updated along with the target cell configuration should be considered invalid. However, there is currently no defined UE operation for this case, so the network cannot know this, resulting in a security mismatch.
[0184] As a result, the network may misunderstand that there is still a usable security key value from among the multiple security key values for inter-MN subsequent mobility, but actually, the UE may not have a valid security key value. This may lead to connection re-establishment procedure due to a security mismatch problem in which data interruption may cause.
[0185] According to implementations of the present disclosure, while performing subsequent mobility, upon declaration and / or detection of subsequent mobility failure, the UE may consider a security key value that was intended to be applied to a target cell as an invalid value. The UE may initiate a cell selection procedure for a UE-based failure recovery. If a selected new cell is applicable to perform the UE-based failure recovery, the UE may re-initiate the subsequent mobility with a new security key value. When the re-initiated subsequent mobility is successfully completed, the UE may notify the network that the security key value that was intended to be applied to the target cell has been considered invalid by the UE based on the subsequent mobility failure.
[0186] According to implementations of the present disclosure, for the subsequent mobility, the network may provide security information including one or more lists of multiple security key values as a pre-configuration. The one or more lists of multiple security key values may be intended to allow the UE to update security without receiving configuration from the network whenever performing the subsequent mobility (e.g., no RRC reconfiguration between cell switches). The one or more lists of multiple security key values may be used for security update only when the UE performs the subsequent mobility between inter-nodes (e.g., inter-CU mobility). The one or more lists of multiple security key values may not be used for security update when the UE performs the subsequent mobility between intra nodes (e.g., intra-CU mobility). Also, the security information may include one or more lists of multiple security key values for multiple nodes for security update, and when performing the subsequent mobility, the UE may select one list of multiple security key values for the corresponding node from among the one or more lists of multiple security key values for multiple nodes.
[0187] According to implementations of the present disclosure, for the selection of a security key value from the selected list of multiple security key values, the UE may select one security key value sequentially (e.g., select the first or the last value from the corresponding list) or randomly. After the security update, the UE may report the updated security information to the network when the subsequent mobility is completed. The report may include the selected security key value and / or derived gNB key. The UE may also regard the used security key value for the source cell as invalid and may remove (and / or exclude) the used security key value from the lists of multiple security key values if the used security key value is still included.
[0188] Otherwise, the network may indicate a security key value from the one or more lists of multiple security key values if the network commands the subsequent mobility to the UE via RRC signaling or lower layer signaling (e.g., MAC CE). In this case, the network may indicate the security key value as an index value in the subsequent mobility command or the network may just indicate the security key value in the subsequent mobility command.
[0189] According to implementations of the present disclosure, for the pre-configuration, the network may also provide one or more candidate cell information / configuration to apply when performing the subsequent mobility. Additionally and / or alternatively, the network may include one or more execution conditions corresponding to and / or associated with each candidate cell. If the UE receives the one or more execution conditions for the subsequent mobility, the UE may start evaluation of the execution condition and the UE may apply corresponding candidate cell information / configuration for the subsequent mobility only when at least one corresponding execution condition is met.
[0190] According to implementations of the present disclosure, for the UE-based failure recovery, the network may provide indication / information to allow the UE-based failure recovery for the subsequent mobility failure before performing the subsequent mobility. If the network allows, the UE may initiate additional subsequent mobility once more based on the pre-configuration for the subsequent mobility after a subsequent mobility has failed. More specifically, upon declaration / detection of the subsequent mobility failure, the UE may perform the cell selection procedure and if a newly selected cell is one of the candidate cells for the subsequent mobility, the UE may try additional subsequent mobility towards the newly selected cell for the UE-based failure recovery, instead of performing RRC connection re-establishment procedure.
[0191] According to implementations of the present disclosure, when performing the UE-based failure recovery, the UE may use the security key value of the source cell for the security update for the newly selected cell from the cell selection procedure. For example, in case of MN mobility, the UE may always perform security update using the security key value of the source cell (e.g., horizontal derivation based on the source key KgNB) for the security update of the newly selected cell from the UE-based failure recovery.
[0192] Otherwise, the network may provide security information (e.g., NCC value) for one or more candidate cells in the subsequent mobility command for the UE-based failure recovery. If security information for the UE-based failure recovery is provided in the subsequent mobility command, the UE may check first whether the newly selected cell for the UE-based failure recovery is applicable to use the security information for the UE-based failure recovery. If the newly selected is applicable to use the security information, the UE may perform security update (e.g., vertical derivation) for the newly selected cell based on the provided security information. If the newly selected is not applicable to use the security information, the UE may perform security update (e.g., horizontal derivation) for the newly selected cell based on the security key value of the source cell.
[0193] If the network does not provide the security information for the UE-based failure recovery, the UE may just use sequentially next unused security key value in the selected list of multiple security key values from the pre-configuration, if the newly selected cell for the UE-based failure recovery should use the same security key list which was used at the subsequent mobility failure.
[0194] According to implementations of the present disclosure, when notifying the network of the updated security information after the UE-based failure recovery is successfully completed, the UE may send updated security information and / or invalid security information. The updated security information may include a newly selected security key value for a candidate cell that has been selected from the UE-based failure recovery procedure. The invalid security information may include a security key value for another candidate cell for which subsequent mobility has failed before performing the UE-based failure recovery. Upon and / or after notification, the UE may remove (and / or exclude) the security key value for the invalid security information from the one or more lists of multiple security key values if the used security key is still included. The order of notifying and removal of the security key value may vary, so the UE may remove (and / or exclude) first and then notify it to the network.
[0195] The following drawings are created to explain specific embodiments of the present disclosure. The names of the specific devices or the names of the specific signals / messages / fields shown in the drawings are provided by way of example, and thus the technical features of the present disclosure are not limited to the specific names used in the following drawings.
[0196] An embodiment of the present disclosure related to a specific drawing described below may be combined with various embodiments of the present disclosure related to other drawings, and some descriptions, functions, procedures, proposals, methods and / or operations of the embodiment may be omitted.
[0197] The various embodiments of the present disclosure may be combined with each other, and some descriptions, functions, procedures, proposals, methods and / or operations of the various embodiments may be omitted.
[0198] FIG. 10 shows an example of a method to which implementations of the present disclosure are applied.
[0199] In step S1000, the method comprises receiving a cell switch command from a source cell. The cell switch command includes security information.
[0200] In some implementations, the security information may include an NCC value for the target cell.
[0201] In step S1010, the method comprises initiating a cell switch based on the cell switch command.
[0202] In step S1020, the method comprises performing a cell selection upon detecting a failure of the cell switch.
[0203] In step S1030, based on a selected cell being a target cell among one or more candidate target cells of subsequent mobility, the method comprises applying a configuration of the target cell.
[0204] For example, if the cell selection is triggered by detecting the failure of the cell switch, and if the selected cell is a target cell among one or more candidate target cells of subsequent mobility, the wireless device may perform UE-based failure recovery towards the target cell, e.g., apply the configuration of the target cell.
[0205] In step S1040, the method comprises performing security update for the target cell based on the security information.
[0206] In some implementations, the method may further comprise whether the selected cell is applicable to use the security information for UE-based failure recovery. The security update may correspond to a vertical derivation based on the selected cell being applicable to use the security information for the UE-based failure recovery.
[0207] Otherwise, the security update may correspond to a horizontal derivation based on the selected cell not being applicable to use the security information for the UE-based failure recovery. In this case, the security update may be performed based a security key of the source cell, instead of the security information (e.g., NCC value) included in the cell switch command.
[0208] In some implementations, the one or more candidate target cells may be configured based on a candidate target cell configuration for each of the one or more candidate target cells.
[0209] FIG. 11 shows an example of another method to which implementations of the present disclosure are applied.
[0210] In step S1100, the method comprises initiating a cell switch based on a cell switch command.
[0211] In some implementations, the method may further comprise receiving a pre-configuration including one or more lists of security key values from the network. The one or more lists of security key values may be intended to allow a wireless device to perform security update without receiving a configuration from the network whenever performing a subsequent mobility. The one or more lists of security key values may be used for security update only when a subsequent mobility between inter-nodes is performed.
[0212] In some implementations, the method may further comprise selecting one list from among the one or more lists of security key values for a target node serving the target cell.
[0213] In some implementations, the method may further comprise selecting a security key value from among the one or more lists of security key values.
[0214] In some implementations, the pre-configuration may include one or more candidate cell configurations to apply for a subsequent mobility, and each of the one or more candidate cell configuration may include one or more execution conditions.
[0215] In step S1110, the method performing a cell selection upon detecting a failure of the cell switch.
[0216] In step S1120, based on a selected cell being a target cell among one or more candidate target cells of subsequent mobility, the method comprises applying a configuration of the target cell.
[0217] In some implementations, selecting of the security key value may include selecting the first security key value. The failure of the cell switch may include a subsequent mobility failure with the first security key value.
[0218] In some implementations, selecting of the security key value may include selecting a second security key value.
[0219] For example, the subsequent mobility with the first security key value may fail. Upon detecting the failure of the subsequent mobility with the first security key value, the cell selection may be triggered. If the selected cell is a target cell which is one of candidate cells for the subsequent mobility, the wireless device may initiate a UE-based failure recovery with the second security key value. The UE-based failure recovery may include applying of the configuration of the target cell and / or performing security update based on the second security key value.
[0220] In step S1130, the method comprises transmitting a first security key value related to the failure of the cell switch to a network.
[0221] In some implementations, the method may further comprise considering the first security key value related to the failure of the cell switch as an invalid security key value.
[0222] In some implementations, the first security key value may be transmitted after the UE-based failure recovery is completed.
[0223] In some implementations, the method further may comprise transmitting updated security information to the network. The updated security information may be encrypted based on the second security key value. The updated security information may include at least one of the second security kay value and / or a derived gNB key.
[0224] In some implementations, the method further may comprise considering a used security key value as invalid and removing the used security key value from the one or more lists of security key values.
[0225] In implementations of the present disclosure described in FIG. 10 and / or FIG. 11, the cell switch may be related to a subsequent mobility. The subsequent mobility may be related to LTM and / or CHO. The subsequent mobility may be related to a mobility between inter-nodes.
[0226] In implementations of the present disclosure described in FIG. 10 and / or FIG. 11, the method may be performed by a wireless device in communication with at least one of a mobile device, a network, and / or autonomous vehicles other than the wireless device.
[0227] Furthermore, the method described above in FIG. 10 and / or FIG. 11 may be performed by a wireless device. The wireless device may be implemented by the first wireless device 100 shown in FIG. 2 and / or the UE 100 shown in FIG. 3.
[0228] The wireless device comprises at least one transceiver, at least one processor, and at least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method described in FIG. 10 and / or FIG. 11.
[0229] Furthermore, the method described above in FIG. 10 and / or FIG. 11 may be performed by control of a processing apparatus adapted to control a wireless device. The processing apparatus may be implemented by the processor 102 included in the first wireless device 100 shown in FIG. 2 and / or the processor 102 included in the UE 100 shown in FIG. 3.
[0230] The processing apparatus adapted to control the wireless device comprises at least one processor, and at least one memory operably connectable to the at least one processor. The at least one processor is adapted to perform the method described in FIG. FIG. 10 and / or FIG. 11.
[0231] Furthermore, the method described above in FIG. 10 and / or FIG. 11 may be performed by a software code 105 stored in the memory 104 included in the first wireless device 100 shown in FIG. 2.
[0232] The technical features of the present disclosure may be embodied directly in hardware, in a software executed by a processor, or in a combination of the two. For example, a method performed by a wireless device in a wireless communication may be implemented in hardware, software, firmware, or any combination thereof. For example, a software may reside in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, a removable disk, a CD-ROM, or any other storage medium.
[0233] Some example of storage medium may be coupled to the processor such that the processor can read information from the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. For other example, the processor and the storage medium may reside as discrete components.
[0234] The computer-readable medium may include a tangible and non-transitory computer-readable storage medium.
[0235] For example, non-transitory computer-readable media may include RAM such as Synchronous DRAM (SDRAM), ROM, Non-Volatile RAM (NVRAM), EEPROM, flash memory, magnetic or optical data storage media, or any other medium that can be used to store instructions or data structures. Non-transitory computer-readable media may also include combinations of the above.
[0236] In addition, the method described herein may be realized at least in part by a computer-readable communication medium that carries or communicates code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer.
[0237] According to some implementations of the present disclosure, a non-transitory Computer-Readable Medium (CRM) stores instructions that, based on being executed by at least one processor, perform the method described in FIG. 10 and / or FIG. 11.
[0238] FIG. 12 shows an example of another method to which implementations of the present disclosure are applied.
[0239] In step S1200, based on a selected cell, due to a cell selection upon a failure of a cell switch, being a target cell among one or more candidate target cells of subsequent mobility, the method comprises receiving a security key related to the failure of the cell switch from a wireless device.
[0240] Furthermore, the method described above in FIG. 12 may be performed by a base station. The base station may be implemented by the second wireless device 200 shown in FIG. 2.
[0241] The base station comprises at least one transceiver, at least one processor, and at least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method described in FIG. 12.
[0242] Examples of the UE operation according to implementations of the present disclosure is described below. In the example described below, some steps may be omitted and / or order of steps may change.
[0243] (1) Example 1: Security handling in subsequent inter-MN CHO failure
[0244] - Step 1: The UE may receive a CHO configuration for subsequent CHO from cell 0. The CHO configuration may configure three cell configurations for CHO candidate cells (e.g., cell 1, cell 2, and cell 3). The CHO configuration may include candidate cell configurations for candidate cells (e.g., cell 1, cell 2, and cell 3) and execution conditions for each candidate cell. In addition, the CHO configuration may include three lists of multiple security key values (first list for cell 1, second list for cell 2, and third list for cell 3) for security update when performing the subsequent CHO.
[0245] - Step 2: The UE may start evaluation for the execution conditions for the subsequent CHO towards cell 1, cell2, and / or cell 3.
[0246] - Step 3: The UE may initiate the subsequent CHO from cell 0 to cell 1 when the related execution condition is met. The UE may start a mobility timer, e.g., T304. The UE may apply a corresponding cell configuration for cell 1 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also update security information based on the first list. The UE may select a first security key value in the first list.
[0247] - Step 4: The UE may not succeed to access cell 1. The UE may declare / detect a mobility failure upon the expiry of mobility timer. The UE may revert back the current configuration to the used configuration for the source cell, i.e., cell 0 with security configuration. As a result, the UE may regard the updated security information (e.g., the first security key value in the first list) as invalid. After that, the UE may perform cell selection procedure to find a new cell instead of cell 1.
[0248] - Step 5: The UE may select cell 3 as the result of the cell selection procedure. The UE may confirm that cell 3 is in the candidate cell list for the subsequent CHO. The UE may initiate additional subsequent CHO from cell 0 to cell 3 for the UE-based failure recovery. The UE may start a mobility timer, e.g., T304 again. The UE may apply a corresponding cell configuration for cell 3 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also update security information based on the third list. The UE may select the first security key value in the third list.
[0249] - Step 6: The UE may succeed to access cell 3. The UE may be successfully completed to send mobility complete message (e.g., RRC Reconfiguration complete message). The mobility complete message may include updated security information and invalid security information. The update security information may include the security key value for cell 3 (e.g., the first security key value in the third list). The invalid security information may include the security key value for cell 1 (e.g., the first security key value in the first list). Upon or after sending the mobility complete message, the UE may remove invalid security information from the list so that the UE can choose a new first security key value in the first list later.
[0250] - Step 7: After the reception of the mobility complete message, the network may identify that the first security key value in the first list is no longer applicable for the subsequent mobility. The network may provide a reconfiguration message for update of the lists of multiple security key values.
[0251] (2) Example 2: Security handling in subsequent inter-MN LTM failure
[0252] - Step 1: The UE may receive a LTM configuration for subsequent LTM from cell 0. The LTM configuration may configure three cell configurations for LTM candidate cells (e.g., cell 1, cell 2, and cell 3). The LTM configuration may include candidate cell configurations for candidate cells (e.g., cell 1, cell 2, and cell 3) and L1 measurement configuration for beams related to LTM candidate cells (e.g., cell 1, cell 2, and cell 3). In addition, the LTGM configuration may include three lists of multiple security key values (first list for cell 1, second list for cell 2, and third list for cell 3) for security update when performing the subsequent LTM.
[0253] - Step 2: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and report the L1 measurement results to the network.
[0254] - Step 3: The UE may receive cell switch command from cell 0 via lower layer signaling for LTM from cell 0 to cell 1. The UE may apply a corresponding cell configuration for cell 1 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also update security information based on the first list. The UE may select a first security key in the first list.
[0255] - Step 4: The UE may not succeed to access cell 1. The UE may declare / detect a mobility failure upon the expiry of mobility timer. The UE may revert back the current configuration to the used configuration for the source cell, i.e., cell 0 with security configuration. As a result, the UE may regard the updated security information (e.g., the first security key value in the first list) as invalid. After that, the UE may perform cell selection procedure to find a new cell instead of cell 1.
[0256] - Step 5: The UE may select cell 3 as the result of the cell selection procedure. The UE may confirm that cell 3 is in the candidate cell list for the subsequent LTM. The UE may initiate additional subsequent LTM from cell 0 to cell 3 for the UE-based failure recovery. The UE may start a mobility timer, e.g., T304 again. The UE may apply a corresponding cell configuration for cell 3 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also update security information based on the third list. The UE may select the first security key value in the third list.
[0257] - Step 6: The UE may succeed to access cell 3. The UE may be successfully completed to send mobility complete message (e.g., RRC Reconfiguration complete message). The mobility complete message may include updated security information and invalid security information. The update security information may include the security key value for cell 3 (e.g., the first security key value in the third list). The invalid security information may include the security key value for cell 1 (e.g., the first security key value in the first list). Upon or after sending the mobility complete message, the UE may remove invalid security information from the list so that the UE can choose a new first security key value in the first list later.
[0258] - Step 7: After the reception of the mobility complete message, the network may identify that the first security key value in the first list is no longer applicable for the subsequent mobility. The network may provide a reconfiguration message for update of the lists of multiple security key values.
[0259] In the present disclosure, the UE-based failure recovery upon detection failure of the cell switch involving the cell selection and performing subsequent mobility towards a target cell may be performed as follows.
[0260] upon selecting a suitable NR cell while T311 is running, the UE may:
[0261] 1> ensure having valid and up to date essential system information;
[0262] 1> stop timer T311;
[0263] 1> if T390 is running:
[0264] 2> stop timer T390 for all access categories;
[0265] 1> stop the relay (re)selection procedure, if ongoing;
[0266] 1> if the cell selection is triggered by detecting radio link failure of the MCG or re-configuration with sync failure of the MCG or mobility from NR failure, and
[0267] 1> ifattemptCondReconfigis configured; and
[0268] 1> if the selected cell is not configured withCondEventT1, or the selected cell is configured withCondEventT1and leaving condition has not been fulfilled; and
[0269] 1> if the selected cell is one of the candidate cells for which thereconfigurationWithSyncis included in themasterCellGroupin the MCGVarConditionalReconfig:
[0270] 2> if the UE supportsRLF-Reportfor conditional handover, set thechoCellIdin theVarRLF-Reportto the global cell identity, if available, otherwise to the physical cell identity and carrier frequency of the selected cell;
[0271] 2> apply the storedcondRRCReconfigassociated to the selected cell and perform applyingRRCReconfigurationmessage;
[0272] 1> if the cell selection is triggered by detecting radio link failure of the MCG or re-configuration with sync failure of the MCG or mobility from NR failure; and
[0273] 1> ifattemptLTM-Switchis configured; and
[0274] 1> if the selected cell is one of the LTM candidate cells in theLTM-CandidateIE withinVarLTM-Configassociated with the MCG:
[0275] 2> perform the LTM cell switch procedure for the selected LTM candidate cell according to the actions specified below.
[0276] For LTM cell switch execution, upon the indication by lower layers that an LTM cell switch procedure is triggered, or upon performing LTM cell switch following cell selection performed while timer T311 was running, the UE may:
[0277] 1> release / clear all current dedicated radio configuration associated with the cell group for which the LTM cell switch procedure is triggered except for the following:
[0278] 2> if the LTM cell switch is triggered on the MCG:
[0279] - the MCG C-RNTI;
[0280] - the AS security configurations associated with the master key;
[0281] - for each SRB / DRB in current UE configuration which is using the master key:
[0282] - keep the associated PDCP and SDAP entities, their state variables, buffers and timers;
[0283] - release all fields related to the SRB / DRB configuration except forsrb-Identityanddrb-Identity;
[0284] 2> else, if the LTM cell switch is triggered on the SCG:
[0285] - the AS security configurations associated with the secondary key;
[0286] - for each SRB / DRB in current UE configuration which is using the secondary key:
[0287] - keep the associated PDCP and SDAP entities, their state variables, buffers and timers;
[0288] - release all fields related to the SRB / DRB configuration except forsrb-Identityanddrb-Identity;
[0289] - thelogicalChannelIdentityandlogicalChannelIdentityExtof RLC bearers configured inRLC-BearerConfigand the associated RLC entities, their state variables, buffers, and timers;
[0290] - the UE variablesVarLTM-Config,VarLTM-ServingCellNoResetID, andVarLTM-ServingCellUE-MeasuredTA-ID.
[0291] 1> release / clear all current common radio configuration associated with the cell group for which the LTM cell switch procedure is triggered;
[0292] 1> use the default values for timers T310, T311 and constants N310, N311 associate to cell group for which the LTM cell switch procedure is triggered;
[0293] 1> apply the default L1 parameter values as specified in corresponding physical layer specifications;
[0294] 1> if the value of fieldltm-NoResetIDcontained within theLTM-CandidateIE inVarLTM-Configindicated by lower layers or for the selected cell 3 is equal to the value ofltm-ServingCellNoResetIDwithinVarLTM-ServingCellNoResetID:
[0295] 2> continue using the current RLC entity in the LTM candidate configuration indicated by lower layers;
[0296] 1> else:
[0297] 2> for eachlogicalChannelIdandlogicalChannelIdExtthat is part of the current UE configuration for the cell group for which the LTM cell switch procedure is triggered:
[0298] 3> re-establish the corresponding RLC entity;
[0299] 2> for eachdrb-Identityvalue that is part of the current UE configuration:
[0300] 3> trigger the PDCP entity of this DRB to perform data recovery;
[0301] 2> replace the value ofltm-ServingCellNoResetIDinVarLTM-ServingCellNoResetIDwith the value ofltm-NoResetIDin the LTM-Candidate inVarLTM-Configindicated by lower layers or for the selected cell;
[0302] 1> if the value ofltm-UE-MeasuredTA-IDcontained within theLTM-CandidateIE inVarLTM-Configindicated by lower layers or for the selected cell is equal to the value ofltm-ServingCellUE-MeasuredTA-IDwithinVarLTM-ServingCellUE-MeasuredTA-ID:
[0303] 2> inform lower layers that UE should perform UE-based TA measurements;
[0304] 2> replace the value ofltm-ServingCellUE-MeasuredTA-IDinVarLTM-ServingCellUE-MeasuredTA-IDwith the value received withinltm-UE-MeasuredTA-ID;
[0305] 1> else:
[0306] 2> replace the value ofltm-ServingCellUE-MeasuredTA-IDinVarLTM-ServingCellUE-MeasuredTA-IDwith the value ofltm-UE-MeasuredTA-IDin theLTM-CandidateinVarLTM-Configindicated by lower layers or for the selected cell;
[0307] 1> continue using the current PDCP entity in the LTM candidate configuration indicated by lower layers;
[0308] 1> ifltm-ConfigCompleteis not included within theLTM-CandidateIE inVarLTM-Configindicated by lower layers or for the selected cell:
[0309] 2> considerltm-ReferenceConfigurationinVarLTM-Config, associated with the cell group for which the LTM cell switch procedure is triggered, to be the current UE configuration;
[0310] 1> if the LTM cell switch is triggered by an indication from lower layers:
[0311] 2> apply the LTM configuration inltm-CandidateConfigwithinLTM-CandidateIE inVarLTM-Configidentified by the LTM candidate configuration identity as received from lower layers;
[0312] 1> else (LTM cell switch triggered upon cell selection performed while timer T311 was running):
[0313] 2> apply the LTM configuration inltm-CandidateConfigwithinLTM-CandidateIE inVarLTM-Configrelated to the LTM candidate configuration identity for the selected cell;
[0314] 2> perform LTM configuration release procedure for the MCG.
[0315] The present disclosure may have various advantageous effects.
[0316] For example, a mismatch can be prevented in multiple security key handling between the network and the UE.
[0317] For example, the network can perform proper security handling to prevent RRC connection re-establishment due to applying an invalid security key value in subsequent mobility.
[0318] Advantageous effects which can be obtained through specific embodiments of the present disclosure are not limited to the advantageous effects listed above. For example, there may be a variety of technical effects that a person having ordinary skill in the related art can understand and / or derive from the present disclosure. Accordingly, the specific effects of the present disclosure are not limited to those explicitly described herein, but may include various effects that may be understood or derived from the technical features of the present disclosure.
[0319] Claims in the present disclosure can be combined in a various way. For instance, technical features in method claims of the present disclosure can be combined to be implemented or performed in an apparatus, and technical features in apparatus claims can be combined to be implemented or performed in a method. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in an apparatus. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in a method. Other implementations are within the scope of the following claims.
Claims
1.A method comprising:receiving a cell switch command from a source cell,wherein the cell switch command includes security information;initiating a cell switch based on the cell switch command;performing a cell selection upon detecting a failure of the cell switch;based on a selected cell being a target cell among one or more candidate target cells of subsequent mobility, applying a configuration of the target cell; andperforming security update for the target cell based on the security information.2.The method of claim 1, wherein the security information includes a Next Hop Chaining Counter (NCC) value for the target cell.3.The method of claim 1 or 2, wherein the method further comprises whether the selected cell is applicable to use the security information for a user equipment (UE)-based failure recovery.4.The method of claim 3, wherein the security update corresponds to a vertical derivation based on the selected cell being applicable to use the security information for the UE-based failure recovery.5.The method of claim 3, wherein the security update corresponds to a horizontal derivation based on the selected cell not being applicable to use the security information for the UE-based failure recovery, andwherein the security update is performed based a security key of the source cell.6.The method of any claims 1 to 5, wherein the one or more candidate target cells are configured based on a candidate target cell configuration for each of the one or more candidate target cells.7.The method of any claims 1 to 6, wherein the subsequent mobility is related to a L1 / L2 triggered mobility (LTM) and / or conditional handover (CHO).8.The method of any claims 1 to 7, wherein the subsequent mobility is related to a mobility between inter-nodes.9.The method of any claims 1 to 8, wherein the method is performed by a wireless device in communication with at least one of a mobile device, a network, and / or autonomous vehicles other than the wireless device.10.A wireless device comprising:at least one transceiver;at least one processor; andat least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method of any claims 1 to 8.11.A processing apparatus adapted to control a wireless device comprising:at least one processor; andat least one memory operably connectable to the at least one processor,wherein the at least one processor is adapted to perform the method of any claims 1 to 9.12.A non-transitory Computer Readable Medium (CRM) storing instructions that, based on being executed by at least one processor, perform the method of any claims 1 to 9.13.A method comprising:initiating a cell switch based on a cell switch command;performing a cell selection upon detecting a failure of the cell switch;based on a selected cell being a target cell among one or more candidate target cells of subsequent mobility, applying a configuration of the target cell; andtransmitting a first security key value related to the failure of the cell switch to a network.14.The method of claim 13, wherein the method further comprises considering the first security key value related to the failure of the cell switch as an invalid security key value.15.The method of claim 13 or 14, wherein the method further comprises receiving a pre-configuration including one or more lists of security key values from the network.16.The method of claim 15, wherein the one or more lists of security key values is intended to allow a wireless device to perform security update without receiving a configuration from the network whenever performing a subsequent mobility.17.The method of claim 15 or 16, wherein the one or more lists of security key values is used for security update only when a subsequent mobility between inter-nodes is performed.18.The method of any claims 15 to 17, wherein the method further comprises selecting one list from among the one or more lists of security key values for a target node serving the target cell.19.The method of any claims 15 to 18, wherein the method further comprises selecting a security key value from among the one or more lists of security key values.20.The method of claim 19, wherein selecting of the security key value includes selecting the first security key value, andwherein the failure of the cell switch includes a subsequent mobility failure with the first security key value.21.The method of claim 20, wherein selecting of the security key value includes selecting a second security key value.22.The method of claim 21, wherein the method further comprises initiating a UE-based failure recovery with the second security key value, andwherein the UE-based failure recovery includes applying of the configuration of the target cell and performing security update based on the second security key value.23.The method of claim 19, wherein the first security key value is transmitted after the UE-based failure recovery is completed.24.The method of claim 19 or 20, wherein the method further comprises transmitting updated security information to the network.25.The method of claim 24, wherein the updated security information is encrypted based on the second security key value.26.The method of claim 24 or 25, wherein the updated security information includes at least one of the second security kay value and / or a derived gNB key.27.The method of any claims 15 to 26, wherein the method further comprises considering a used security key value as invalid and removing the used security key value from the one or more lists of security key values.28.The method of any claims 15 to 27, wherein the pre-configuration includes one or more candidate cell configurations to apply for a subsequent mobility, andwherein each of the one or more candidate cell configuration includes one or more execution conditions.29.A method comprising:based on a selected cell, due to a cell selection upon a failure of a cell switch from a source cell to a target cell, being a target cell among one or more candidate target cells of subsequent mobility, receiving a security key related to the failure of the cell switch from a wireless device.30.A base station comprising:at least one transceiver;at least one processor; andat least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method of claim 29.
Citation Information
Patent Citations
Communication method and device
CN116939735A
Method, Apparatus and System for Processing Security Key when Reestablishing Radio Resource Control (RRC) Connection
US20120129499A1
Release of configurations for conditional handovers based on security configurations
US20220330125A1
Mobility features for next generation cellular networks
US20230388871A1
Secondary cell group configuration retention or release
WO2024072796A1