Method, apparatus and computer program

The method addresses the challenge of intermittent connectivity in NTNs by determining security keys and managing access stratum security contexts for secure radio resource control resumption in UEs, enhancing connectivity in incomplete satellite constellations.

WO2025233042A1PCT designated stage Publication Date: 2025-11-13NOKIA TECHNOLOGIES OY
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/057173
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-10
Filing Date
2025-03-17
Publication Date
2025-11-13

AI Technical Summary

Technical Problem

In Non-Terrestrial Networks (NTNs) with incomplete satellite constellations, there are challenges with discontinuous satellite connectivity to User Equipment (UEs) and ground stations, leading to intermittent coverage and the need for store-and-forward operations, which complicate security key management and access stratum security context updates.

Method used

A method and apparatus for determining a security key using the identity and channel number of a target satellite, updating the access stratum security context, and managing message authentication codes to ensure secure connectivity during radio resource control suspension and resumption in NTN scenarios.

Benefits of technology

Ensures secure and efficient radio resource control connection resumption in NTNs with discontinuous connectivity by providing a robust security framework for UEs, even in situations with intermittent satellite coverage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025057173_13112025_PF_FP_ABST
    Figure EP2025057173_13112025_PF_FP_ABST
Patent Text Reader

Abstract

An apparatus comprising: means for receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; means for determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for determining an updated access stratum security context for the user equipment using the security key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD, APPARATUS AND COMPUTER PROGRAM

[0002] TECHNICAL FIELD

[0003] Various example embodiments of this disclosure relate to a method, apparatus, and computer program for a communications network. Some examples relate to a method, apparatus, and computer program for security principles in Non-Terrestrial Networks (NTNs).

[0004] BACKGROUND

[0005] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0006] Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 4G (4thGeneration), 5G (5th Generation) standards provided by 3GPP.

[0007] SUMMARY

[0008] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.

[0009] According to a first aspect there is provided an apparatus comprising: means for receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; means for determining a security key for the user equipment using the identity and the channel number; means for updating an access stratum security context using the determined security key; means for sending the updated access stratum security context to the target satellite.

[0010] According to some examples, the channel number of the physical cell comprises a E-UTRA Absolute Radio Frequency Channel Number. According to some examples, the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.

[0011] According to some examples, the apparatus comprises: means for determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; means for determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.

[0012] .According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.

[0013] According to some examples, the apparatus comprises: means for determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.

[0014] According to some examples, the apparatus comprises: means for generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; means for sending the list to the target satellite.

[0015] According to some examples, the MAC comprises a shortResumeMAC-l.

[0016] According to some examples, the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.

[0017] According to some examples, the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.

[0018] According to some examples, the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node. According to some examples, the apparatus comprises: means for sending, to the target satellite, an indication that the access stratum security context has been updated.

[0019] According to a second aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.

[0020] According to some examples, the channel number of the physical cell comprises a E-LITRA Absolute Radio Frequency Channel Number.

[0021] According to some examples, the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.

[0022] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.

[0023] .According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.

[0024] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.

[0025] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; sending the list to the target satellite.

[0026] According to some examples, the MAC comprises a shortResumeMAC-l.

[0027] According to some examples, the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.

[0028] According to some examples, the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.

[0029] According to some examples, the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node.

[0030] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: sending, to the target satellite, an indication that the access stratum security context has been updated.

[0031] According to a third aspect there is provided a method comprising: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.

[0032] According to some examples, the channel number of the physical cell comprises a E-LITRA Absolute Radio Frequency Channel Number.

[0033] According to some examples, the channel number of the physical cell identifies at least one of: a frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode.

[0034] According to some examples, the method comprises: determining that a serving satellite for the user equipment has lost connectivity with a core network of the apparatus; determining the target satellite as the next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state after the serving satellite has lost connectivity with the core network of the apparatus and before the target satellite has connectivity with the core network.

[0035] .According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.

[0036] According to some examples, the method comprises: determining that the identity of the physical cell of the target satellite and the serving satellite are the same, and in response, determining the security key using a target base station identifier of the target satellite or using any unique identifier of the next satellite after the target satellite that will have connectivity with the core network.

[0037] According to some examples, the method comprises: generating a message authentication code, MAC, for each UE and per non-terrestrial network cell hosted by the target satellite to provide a list of one or more MACs; sending the list to the target satellite.

[0038] According to some examples, the MAC comprises a shortResumeMAC-l.

[0039] According to some examples, the identity of the physical cell of the target satellite and the channel number of the target physical cell are received over a feeder link between the target satellite and the apparatus.

[0040] According to some examples, the feeder link comprises a 3GPP standardized (e.g. S1 interface) or proprietary interface between a base station onboard the target satellite and a core network.

[0041] According to some examples, the apparatus comprises: a core network node; a non-terrestrial network gateway node; or a proxy node.

[0042] According to some examples, the method comprises sending, to the target satellite, an indication that the access stratum security context has been updated.

[0043] According to a fourth aspect there is provided a computer readable medium comprising instructions which, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.

[0044] According to a fifth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by a user equipment, cause the user equipment to perform at least the following: receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell; determining a security key for the user equipment using the identity and the channel number; updating an access stratum security context using the determined security key; sending the updated access stratum security context to the target satellite.

[0045] According to a sixth aspect there is provided an apparatus comprising: means for sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.

[0046] According to some examples, the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

[0047] According to some examples, the apparatus comprises: means for receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.

[0048] According to some examples, the apparatus comprises: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; means for determining that the first MAC is in the list received from the network node and then authenticating the first MAC; means for resuming the radio resource control connection with the network of the apparatus.

[0049] According to some examples, the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus. According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.

[0050] According to some examples, a satellite comprises the apparatus.

[0051] According to some examples, the apparatus comprises: means for determining at least one further access stratum integrity and encryption key using the security key.

[0052] According to some examples, the apparatus comprises: means for receiving, from the network node, an indication that the updated access stratum security context has been updated.

[0053] According to a seventh aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.

[0054] According to some examples, the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

[0055] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.

[0056] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; determining that the first MAC is in the list received from the network node and then authenticating the first MAC; resuming the radio resource control connection with the network of the apparatus. According to some examples, the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.

[0057] According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.

[0058] According to some examples, a satellite comprises the apparatus.

[0059] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining at least one further access stratum integrity and encryption key using the security key.

[0060] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the network node, an indication that the updated access stratum security context has been updated.

[0061] According to an eighth aspect there is provided a method comprising: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.

[0062] According to some examples, the user equipment is in a radio resource control suspended state after a serving satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

[0063] According to some examples, the method comprises: receiving, from the network node, a list comprising a message authentication code, MAC, for each user equipment per non-terrestrial network cell hosted by the apparatus.

[0064] According to some examples, the method comprises: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first MAC; determining that the first MAC is in the list received from the network node and then authenticating the first MAC; resuming the radio resource control connection with the network of the apparatus. According to some examples, the identity of the physical cell of the apparatus and the channel number of the target physical cell is sent over a feeder link between the target satellite and the apparatus.

[0065] According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.

[0066] According to some examples, a satellite comprises the apparatus.

[0067] According to some examples, the method comprises: determining at least one further access stratum integrity and encryption key using the security key.

[0068] According to some examples, the method comprises: receiving, from the network node, an indication that the updated access stratum security context has been updated.

[0069] According to a ninth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.

[0070] According to a tenth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.

[0071] According to an eleventh aspect, there is provided a user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0072] According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the user equipment comprises: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the determined security key.

[0073] According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, the user equipment comprising: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the determined security key

[0074] According to a twelfth aspect, there is provided a user equipment comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0075] According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the determined security key.

[0076] According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the instructions, when executed by the at least one processor, cause the apparatus to perform: cause the apparatus at least to perform: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the determined security key. According to an thirteenth aspect, there is provided a method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0077] According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the method comprises: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the determined security key.

[0078] According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the method comprises: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the determined security key.

[0079] According to a fourteenth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0080] According to a fifteenth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0081] According to sixteenth aspect, there is provided an apparatus comprising: means for receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; means for determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for determining an updated access stratum security context for the user equipment using the security key.

[0082] According to some examples, the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

[0083] According to some examples, the apparatus comprises: means for determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.

[0084] According to some examples, the apparatus comprises: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; means for determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; means for resuming the radio resource control connection with the user equipment.

[0085] According to some examples, the message authentication code comprises a shortResumeMAC-l .

[0086] According to some examples, the apparatus comprises: means for determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.

[0087] According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.

[0088] According to some examples, a satellite comprises the apparatus.

[0089] According to some examples, the apparatus comprises: means for determining at least one further access stratum integrity and encryption key using the security key.

[0090] According to a seventeenth aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.

[0091] According to some examples, the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

[0092] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.

[0093] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; resuming the radio resource control connection with the user equipment.

[0094] According to some examples, the message authentication code comprises a shortResumeMAC-l .

[0095] According to some examples, the instructions, when executed by the at least one processor, cause the apparatus to perform: determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.

[0096] According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.

[0097] According to some examples, a satellite comprises the apparatus. According to a eighteenth aspect, there is provided a method comprising: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.

[0098] According to some examples, the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

[0099] According to some examples, the method comprises determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.

[0100] According to some examples, the method comprises: receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; resuming the radio resource control connection with the user equipment.

[0101] According to some examples, the message authentication code comprises a shortResumeMAC-l .

[0102] According to some examples, the method comprises: determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.

[0103] According to some examples, the network node comprises at least one of: a core network node; a non-terrestrial network gateway node; a proxy node.

[0104] According to some examples, a satellite comprises the apparatus that performs the method. According to a nineteenth aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.

[0105] According to a twentieth aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; determining an updated access stratum security context for the user equipment using the security key.

[0106] According to a further aspect, there is provided an apparatus comprising: means for determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; means for sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

[0107] According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.

[0108] According to some examples, the apparatus comprises one of: a core network node; a nonterrestrial network gateway node; a proxy node.

[0109] According to a further aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

[0110] According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.

[0111] According to some examples, the apparatus comprises one of: a core network node; a nonterrestrial network gateway node; a proxy node.

[0112] According to a further aspect, there is provided a method comprising: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

[0113] According to some examples, the target satellite is determined as the next satellite using satellite ephemeris.

[0114] According to some examples, the method if performed by one of: a core network node; a nonterrestrial network gateway node; a proxy node.

[0115] According to a further aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

[0116] According to a further aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated. According to a further aspect, there is provided a user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0117] According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the user equipment comprises: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the security key.

[0118] According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the user equipment comprises: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the security key

[0119] According to a further aspect, there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0120] According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the security key.

[0121] According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the instructions, when executed by the at least one processor, cause the apparatus to perform: determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the security key.

[0122] According to a further aspect, there is provided a method comprising: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0123] According to some examples, the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, and method comprises: determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; connecting to the target satellite using the security key.

[0124] According to some examples, the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, and the method comprises determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; connecting to the target satellite using the security key

[0125] According to a further aspect there is provided a computer readable medium comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed

[0126] According to a further aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed. According to an aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.

[0127] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.

[0128] According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods.

[0129] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.

[0130] In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above.

[0131] DESCRIPTION OF FIGURES

[0132] Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying Figures in which:

[0133] FIG. 1 shows a representation of a communication network comprising a 5thgeneration communication system and a data network;

[0134] FIG. 2 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario;

[0135] FIG. 3 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario with security key computation at a network node;

[0136] FIG. 4 shows an example signal flow diagram for an example NTN Store and Forward (S&F) scenario with security key computation at a next serving target satellite;

[0137] FIG. 5 shows an example method performed by a network node;

[0138] FIG. 6 shows an example method performed by a target satellite;

[0139] FIG. 7 shows an example method performed by a User Equipment (UE);

[0140] FIG. 8 shows an example method performed by a network node;

[0141] FIG. 9 shows an example method performed by a target satellite; FIG. 10 shows an example method performed by a User Equipment (UE);

[0142] FIG. 11 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments;

[0143] FIG. 12 shows a representation of an apparatus (e.g., a UE) according to some example embodiments; and

[0144] FIG. 13 shows a schematic representation of a non-volatile memory medium storing instructions which when executed by a processor allow a processor to perform one or more of the steps of the methods disclosed herein.

[0145] DETAILED DESCRIPTION

[0146] Some examples described herein relate to a security framework for NTN S&F scenarios.

[0147] NTNs are wireless communication systems where at least part of the network is located above the Earth's surface. NTNs may involve satellites at low Earth orbit (LEO), medium Earth orbit (MEO) and geostationary orbit (GEO), high-altitude platforms (HAPS) and drones. Due to the high cost of satellite launch and operation, NTNs comprising satellite networks with incomplete satellite constellations are foreseen. Such satellite networks are often cost-efficient to launch and operate and can be useful for applications that are not time-critical (e.g., Internet of Things (loT) NTN having sparse LEO or MEO constellations and a limited number of ground stations). Satellite networks with incomplete satellite connections may have discontinuous satellite connectivity with User Equipment’s (UEs) and / or may have discontinuous connectivity to a ground station (e.g., ground station connectivity) due to coverage gaps that are caused by satellites that are missing from a full satellite constellation or due to a lack of ground station connectivity at some locations. A satellite network with an incomplete satellite constellation cannot be guaranteed to have ground station connectivity via a feeder link to the ground station at all times, and also cannot be guaranteed to provide continuous coverage to a UE in the satellite network (instead, only intermittent coverage may be available). A satellite may be able to establish a connection to a ground station (“a ground station connection”) for sending Control Plane (CP) data and / or signalling at certain points in the satellite’s orbit, and may not be able to establish a ground station connection at other points. Similarly, the satellite may be able to establish a connection for sending CP data and / or signalling to a UE at certain points in the satellite’s orbit, and may not be able to establish such a connection at other points. Consequently, in some situations a satellite may have either ground station connectivity (e.g., connectivity to a ground station via a feeder link) or satellite connectivity (e.g., connectivity to a UE via a satellite link), but not both at the same time. In NTNs with discontinuous satellite connectivity with UEs or a ground station, using a store- and-forward operation in the NTN can be useful. When a store-and-forward operations is used in a network, downlink CP data and / or signalling can be uploaded by a ground station to the satellite, buffered at the satellite and then transferred to a UE when the satellite has travelled further on its orbit to a point where a connection to the UE can be established. This enables the next hop to the UE for the stored payload. Uplink CP data and / or signalling can be similarly buffered at the satellite when a store-and-forward operation is used in a NTN, such that the CP data and / or signalling is sent by a UE to the satellite, buffered at the satellite and then later transferred to a ground station once the satellite has travelled further on its orbit to a point where a ground station connection to the ground station can be established. This enables the next hop to the ground station for the stored payload. A ground station connection between a ground station and a satellite may be considered to be established on a “feeder link”. When a satellite does not have a ground station connection, the satellite will have discontinuous connectivity to the core network (CN).

[0148] Store and Forward (S&F) operations allow a satellite to provide service to NTN devices even when the satellite is not connected to the NTN Gateway (GW) on the ground. A typical S&F scenario may involve a non-simultaneous connection between UE and satellite comprising a base station as regenerative payload (also called Access link) and satellite comprising a base station as regenerative payload and the CN on the ground (on the feeder link).

[0149] In the following various example embodiments are explained with reference to communication devices (e.g., UEs) that are capable of communication with a communications network (e.g., a 5G or 6G network). Before explaining in detail the embodiments of the methods, apparatuses, and computer programs of the present disclosure, a communication network comprising a 5thgeneration communication system (5GS), a radio access network and a core network (5GC) thereof, are briefly explained with reference to FIG. 1.

[0150] FIG. 1 shows a schematic representation of a communication network comprising a cellular or mobile communication system (e.g., a 5G communication system (5GS), and data network. The 5GS may comprise a radio access network such as a 5G radio access network (5G-RAN) or next generation radio access network (NG-RAN), a 5G core network (5GC). An application function may be deployed in the 5GS (e.g., hosted on an apparatus of the 5GC) and hence are generally referred to as a trusted application function or an AF may be deployed or hosted on one or more application servers of the data network and communicate with 5GC via a network exposure function of the 5GC as described in further detailed below. An application functions deployed or hosted on one or more application servers of the data network is generally referred to as an untrusted application function. The 5GS is configured to establish data sessions (e.g., PDU sessions) to provide a data connection between a UE and a data network via the access network and the 5GC (e.g., a UPF of the 5GC). The data sessions may be used to provide services to the UE.

[0151] FIG. 2 shows a method flow diagram for an example NTN S&F scenario where an RRC connection for UE 200 can be suspended and resumed.

[0152] At 201, UE 200 is in an connected RRC state (RRC_CONNECTED) and / or a Connection Management connected state (CM-CONNECTED). At 203, a proxy gateway (P-GW) 208 sends downlink (DL) data to a serving base station on board satellite 1 204. The base station may comprise an eNB or gNB. Satellite 204 may comprise a Non-Geo Synchronous Orbit (NGSO) satellite 1 204. At 205a, serving satellite 1 204 suspends the context of UE 200 by sending an RRC Connection Suspend request to MME 206. This can be performed before serving satellite 1 204 loses feeder link connectivity. In some examples, the request sent at 205a may be sent using S1 Application Protocol (S1-AP).

[0153] At 205b, MME 206 responds to the message sent at 205a. The response may indicate that the UE context has been suspended. Optionally, an indication of a Next Hop (NH) satellite and corresponding Nokia Converged Charging (NCC) value may be provided at 205b. This can be stored at 207 at the serving satellite 204. At 209 the serving satellite 1 204 indicates to UE 200 that the RRC connection has been suspended, and will send an identifier for resuming the RRC connection (Resume ID) and a NCC value. The NCC value may be the new value received at 205b, or may be an existing value received prior to 205b. At 211 , the serving satellite 1 204 stores the Resume ID and the UE context. The UE context included an Access Stratum (AS) security.

[0154] At 213, if a new NH value and NCC value were received at 205b from MME 206, serving satellite 1 204 may keep key KRRCint and delete other AS keys such as KeNB, KRRCenc, KUPenc. If a new NH and new NCC value were not received at 205b, serving satellite 1 204 may keep all AS keys.

[0155] At 215, UE 200 stores the Resume ID received at 209 with the UE context. The UE context may include the AS security context. UE 200 may also store the NCC value to be used in the next resumption of RRC connectivity.

[0156] At 217, UE 200 is in an RRC inactive (RRCJNACTIVE) and CM-CONNECTED state. At 219, the UE context of UE 200 is sent to network node 206. Although the example of FIG. 2 shows an MME as network node 206, other CN nodes may be used, or a NTN gateway (NTN GW) or a proxy node. At 221 , serving satellite 1 204 loses connectivity with the CN (or NTN GW) on the ground.

[0157] At 223, the network node 206 (or in some examples, one or more other CN entities) identifies a next target satellite 4 202 that may have connectivity with network node 206. This may be done using know satellite paths and the current time in the schedule (satellite ephemeris information), for example. At 225, network node 206 sends the UE context to the next serving satellite 4 202.

[0158] At 227, UE 200 determines that there is Uplink (UL) data to send. At 229, UE 200 sends to target satellite 4 204 a request to resume the RRC configuration (RRCResumeRequest). The request may comprise a resume ID and a message authentication code (e.g., ShortResumeMAC-l). When the UE decides at 227 to resume the RRC connection and triggers the RRCResumeRequest including the Resume ID and the ShortResumeMAC-l toward the target satellite 4 202 (e.g., an comprising eNB or gNB), the target satellite 4 202 extracts the Resume ID and ShortResumeMAC-l from the RRCResumeRequest.

[0159] The target satellite 4 202 may then contact the cell at the source satellite 1 204 based on the information in the Resume ID by sending a Retrieve UE Context Request message (e.g., on an X2 interface), the message including the Resume ID, the ShortResumeMAC-l and Cell-ID of target cell, in order to retrieve the UE context (including the AS security context). The source satellite 1 204 retrieves the stored UE context including the AS security context from its database identified by the Resume ID and the source eNB calculates and verifies the ShortResumeMAC-l. If the check of the ShortResumeMAC-l is successful, then the source eNB shall derive a new KeNB*, based on the target Physical Cell ID (PCI) and target Evolved Universal Mobile Telecommunications System Terrestrial Radio Access Network (E-UTRAN) Absolute Radio Frequency Channel Number Downlink frequency (EARFCN-DL). If source satellite 1 204 received a new {NH, NCC} pair from MME 206 at 205b, then that pair shall be used, and the new NH shall be used in the new KeNB* derivation. The source satellite 1 204 responds with a Retrieve UE Context Response message to the target satellite 4 202 (e.g., on an X2 interface) including the UE context that is updated with AS security context using the new key. The AS security context sent to the target satellite eNB shall include a new derived security key (KeNB*), the NCC associated to the KeNB*. However, in a S&F scenario, the UE context of RRCJNACTIVE state UEs is forwarded by the last serving satellite 1 204 to network node 206 (e.g., CN node or the NTN GW node) before the last serving satellite 1 204 loses connectivity with network node 206. When network node 206 identifies the next serving target satellite that shall have connectivity to network node 206, network node 206 forwards the stored UE contexts blindly to the target satellite (without updating AS security context). As a result, an attempt by the RRCJNACTIVE state UE 200 to resume the connection at the target satellite will fail, as the AS security in the UE context is not updated with a new security key relevant to target satellite 4 202.

[0160] In other words, a S&F scenario, when a network node (e.g., a CN node, proxy node or an NTN GW node) forwards the UE context of RRC NACTIVE state UE(s) to a target satellite, unless the AS security context that is part of UE context is updated with new security key derived using security parameters relevant to the next serving target satellite, either by the CN node before forwarding or by the target node on receiving, the UE context is not valid for a successful connection resume at the target satellite. Such a failure is shown at 231 , where the RRC connection is released, and 233 where the connection resume fails.

[0161] FIG. 3 and FIG. 4 show two different methods for S&F scenarios to enable either the network node (FIG. 3) or target satellite node (FIG. 4) to compute a new security key and update the AS security context. This prevents the connection resume in NTN S&F scenarios failing as in FIG. 2, where the connection resume for a UE fails due to an outdated AS security context that is not updated using a new security key derived using input parameters relevant to the target satellite for the UE.

[0162] 201 to 221 may occur before the method of FIG. 3. The method of FIG. 3 then takes place instead of 223 to 233. Entities 200 to 208 correspond to entities 300 to 308. 201 to 221 may also occur before the method of FIG. 4. The method of FIG. 4 then takes place instead of 223 to 233. Entities 200 to 208 correspond to entities 400 to 408.

[0163] In FIG. 3, network node 306 (e.g., a CN node, NTN GW node or proxy node) that has stored UE context(s) of one or more RRCJNACTIVE UEs (this may have been received over an S1 interface from source (last serving) satellite 1 304) computes a new security key using an identified next serving satellite 4 302’s security parameters. Network node 306 then updates the AS security context of UE 300 before pushing the updated AS security context to the next serving target satellite 4 302 (e.g., via an S1 interface) that has connectivity with network node 306. This enables successful connection resume at the next serving target satellite. At 323, similarly to 223, network node 306 determines a next serving satellite for UE 300 as target satellite 4 302. At 325, network node 306 retrieves, from target satellite 4 302, a target cell PCI of target satellite 4 302 and channel number (e.g., EARFCN-DL). This may be retried over an S1 interface or a proprietary interface, for example. Based on the number of NTN cells hosted by target satellite 4302, target satellite 4 302 may provide a list of target cell PCIs and target EARFCN-DL associated with the target NTN cells. In examples where UE context(s) are stored at network node 306, network node 306 may retrieve a target satellite 1 304 and target EARFCN-DL via a proprietary interface (e.g., Stream Control Transmission Protocol (STCP), Next Generation Application Protocol (NGAP) or Operations & Management (O&M)).

[0164] At 327a, network node 306 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 302. The new security key may be determined using a PCI of target satellite node 4 302 and a channel number of a physical cell of the target satellite node 4 302 (e.g., EARFCN-DL). The channel number may identify at least one of: frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode. In the case where an NTN target cell 302 PCI same as the last serving NTN cell 304 PCI, an additional parameter (e.g. target eNB Id or next serving target satellite Id or any other unique parameter) may be used to compute the new security key. The additional parameter is also used by UE 300 to compute the same key (see below). The network node may compute the new key (KeNB*) using any suitable key derivation function, such as the “A.5 KeNB* derivation function” in 3GPP TS33.401.

[0165] At 327b, based on the number of NTN cells hosted by target satellite 4 302 (or on a list of target cells received form the target satellite at network node 306), an equivalent list of message authentication codes (e.g., shortResumeMAC-l’s) are generated by network node 306, where each message authentication code can be associated with a UE context. Target satellite 4 302 can implicitly authenticate the UE by validating the message authentication code(s).

[0166] It should be noted that at 327a and 327b, if there is a new NH value available for YE 300 at network node 306, this may be used in determining KeNB*. After 327a and 327b, network node 306 updates the AS security context within each stored UE context using the newly computed security key (KeNB*), and at 329 sends the UE context(s) to the next serving target satellite 4 302. The updated UE context(s) include a UE context of UE 300. The updated UE context(s) include updated AS security context determined using the new key (KeNB*), NCC value associated with the KeNB* and a list of one or more message authentication code(s) (e.g., shortResumeMAC-l’s) associated with each UE context. The message sent at 329 may comprise an indication that the AS security context has been updated.

[0167] At 331 , the updated UE context is stored at target satellite 4 302. At 333, target satellite 4 302 derives new AS keys (e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)) using the new key KeNB*.

[0168] At 335, UE 300 has UL data to send. At 337, UE 300 attempts to resume the RRC connection by sending an RRC resume request (RRCResumeRequest) including a Resume ID and a message authentication code (e.g., shortResumeMAC-l). At 339, target satellite 4 302 can then retrieve the UE context using the Resume ID and authenticate the UE context by comparing the shortResumeMAC-l received from UE 300 with the list of shortResumeMAC- I’s received from network node 306 with the UE context, which is referred to herein as (implicit) authentication.

[0169] At 341 , upon successful authentication, target satellite 4 302 triggers resumption of the RRC connection (RRCResume). The RRCResume message may be sent towards UE 300 and include an NCC value, if an NCC value was previously received from network node 306 (e.g., in an S1-AP UE Context Suspend Response message, similar to 205b). The RRCResume message may additionally include an eNB ID, gNB ID or satellite ID of the target satellite (or other unique identifier of the target satellite or next satellite after the target satellite). This can be used by UE 300 as an additional parameter for security key competition in the case that the target cell PCI is same as the last serving cell.

[0170] The NCC value in RRCResume can be used by UE 300 at 343 to compare it with the NCC store at UE 300; if it is the same, then UE 300 derives the security key (KeNB*) at 345; otherwise, UE 300 can synchronize the locally kept NH and then compute the security key (KeNB*) at 345. At 345, UE 300 may use an optional parameter (satellite ID, eNB ID or any other unique identifier of target satellite 4 302) as an input parameter for new key computation, wherein the optional parameter is included in the RRCResume message sent at 341.

[0171] At 347, UE 300 is in an RRC connected an CM-connected state, and can send a message indicating that the RRC resumption is complete (RRCResumeComplete) to network node 306. A path switch request is sent from target satellite 4 302 to network node 306 at 351 and network node 306 responds at 353. At 355, DL data may be sent from P-GW 306 to satellite 4 302 (now a serving satellite for UE 300). Using the above method, UE 300 and target satellite 4 302 will have the same key KeNB*, so that the interface between them can be protected.

[0172] In FIG. 4, a network node 406 (e.g., a CN node, NTN GW node or a Proxy node) that has stored the UE context of RRCJNACTIVE state UEs, pushed by the last serving satellite 404 (e.g., via an S1 interface), and blindly transfers the stored UE contexts to the next serving target satellite 402 (e.g., via an S1 interface) that will have CN (or NTN GW) connectivity, without updating the AS security context. An indication that the AS security context has not been updated may be included. The next serving target satellite 4402, upon receiving the UE context of RRCJNACTIVE state UEs, computes the new security key using relevant target satellite specific security parameters and updates the AS security context in each of the UE context(s). This enables successful connection resume at the next serving target satellite 402.

[0173] At 423, similarly to 223, Network node 406 determines a next serving satellite for UE 400 as target satellite 4 402. At 461 , network node 406 node pushes (or forwards) the stored UE context of all the Inactive state UEs to the next serving target satellite as was received from last serving satellite 1 404 (without generating the new security key or updating the AS security context as in FIG. 3).

[0174] At 463, target satellite 4402 computes a new security key (KeNB*) using security parameter(s) related to target satellite node 4 402. The new security key may be determined using a PCI of target satellite node 4 402 and a channel number of a physical cell of the target satellite node 4 402 (e.g., EARFCN-DL). The channel number may identify at least one of: frequency of the physical cell; a bandwidth of the physical cell; a channel duplex mode. In the case where an NTN target cell 402 PCI same as the last serving NTN cell 404 PCI, an additional parameter (e.g. target eNB Id or next serving target satellite Id or any other unique parameter) may be used to compute the new security key. The additional parameter is also used by UE 400 to compute the same key (see below). The network node may compute the new key (KeNB*) using any suitable key derivation function, such as the “A.5 KeNB* derivation function” in 3GPP TS33.401.

[0175] At 465, target satellite 4 402 derives new AS keys (e.g., RRC integrity key, RRC encryption key, User Plane (UP) key(s)) using the new key KeNB*.

[0176] At 467, UE 400 has UL data to send. At 469, UE 400 attempts to resume the RRC connection by sending an RRC resume request (RRCResumeRequest) including a Resume ID and a message authentication code (e.g., shortResumeMAC-l). At 471 , target satellite 4 402 can then retrieve the UE context using the Resume ID and authenticate the UE context by comparing the shortResumeMAC-l received from UE 400 with the list of shortResumeMAC- I’s received from network node 406 with the UE context, which is referred to herein as (implicit) authentication.

[0177] At 473, upon successful authentication, target satellite 4 402 triggers resumption of the RRC connection (RRCResume). The RRCResume message may be sent towards UE 400 and include an NCC value, if an NCC value was previously received from network node 406 (e.g., in an S1-AP UE Context Suspend Response message, similar to 205b). The RRCResume message may additionally include an eNB ID, gNB ID or satellite ID of the target satellite (or other unique identifier of the target satellite or next satellite after the target satellite). This can be used by UE 400 as an additional parameter for security key competition in the case that the target cell PCI is same as the last serving cell.

[0178] The NCC value in RRCResume can be used by UE 400 at 475 to compare it with the NCC stored at UE 400; if it is the same, then UE 400 derives the security key (KeNB*) at 477; otherwise, UE 400 can synchronize the locally kept NH and then compute the security key (KeNB*) at 477. At 477, UE 400 may use an optional parameter (satellite ID, eNB ID or any other unique identifier of target satellite 4402) as an input parameter for new key computation, wherein the optional parameter is included in the RRCResume message sent at 473.

[0179] At 479, UE 400 is in an RRC connected an CM-connected state, and at 481 can send a message indicating that the RRC resumption is complete (RRCResumeComplete) to network node 406. A path switch request is sent from target satellite 4402 to network node 406 at 483 and network node 406 responds at 485. At 487, DL data may be sent from P-GW 406 to satellite 4 404 (now a serving satellite for UE 400).

[0180] Using the above method, UE 300 and target satellite 4 302 will have the same key KeNB*, so that the interface between them can be protected.

[0181] FIG. 5 shows an example method flow. The method may be performed by a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.

[0182] At 500, the method comprises receiving, from a target satellite for a user equipment, an identity of a physical cell of the target satellite and a channel number of the physical cell. At 502, the method comprises determining a security key for the user equipment using the identity and the channel number.

[0183] At 504, the method comprises updating an access stratum security context using the determined security key.

[0184] At 506, the method comprises sending the updated access stratum security context to the target satellite.

[0185] FIG. 6 shows an example method flow. The method may be performed by an apparatus at a target satellite, for example target base station 302 or 402.

[0186] At 600, the method comprises sending, to a network node, an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus.

[0187] At 602, the method comprises receiving, from the network node, an updated access stratum security context for a user equipment, wherein a security key is determined using the identity and the channel number, and wherein the updated access stratum security context comprises an access stratum security context updated using the security key.

[0188] FIG. 7 shows an example method flow. The method may be performed by a UE such as UE 300 or 400, for example.

[0189] At 700, the method comprises sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code, MAC.

[0190] At 702, the method comprises receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0191] FIG. 8 shows an example method flow. The method may be performed by an apparatus at a target satellite, for example target base station 302 or 402.

[0192] At 800, the method comprises receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite. At 802, the method comprises determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus.

[0193] At 804, the method comprises determining an updated access stratum security context for the user equipment using the security key.

[0194] FIG. 9 shows an example method flow. The method may be performed by a network node such as a CN node, network node 306 or 406, an NTN GW node or a proxy node, for example.

[0195] At 900, the method comprises for determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state.

[0196] At 902, the method comprises sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

[0197] FIG. 10 shows an example method flow. The method may be performed by a user equipment such as UE 300 or 400, for example.

[0198] At 1000, the method comprises sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code.

[0199] At 1002, the method comprises receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

[0200] FIG. 11 illustrates an example of an apparatus 1100 that may implement or comprise at least a core network entity or AF of the communication network illustrated in FIG. 1. The apparatus 1100 may comprise at least one random access memory (RAM) 1111a, at least on read only memory (ROM) 1111 b, at least one processor 1112, 1113 and a network interface 1114. The at least one processor 1112, 813 may be coupled to the RAM 1111a and the ROM 1111 b. The at least one processor 1112, 1113 may be configured to execute an appropriate software code 1115. Execution of the software code 1115 (or execution of instructions of the software code 1115. The software code 1115 may be stored in the ROM 1111 b. The apparatus 1100 may be interconnected with another apparatus 1100 for controlling other network functions of the 5GC, for example. In some embodiments, one or more network functions of the 5GC is deployed or hosted on an apparatus 1100. In alternative embodiments, the apparatus may include software code of additional network functions of the core network of the communication network. The apparatus 1100 may comprise a computing device (e.g., a server), a computing system, such as a distributed computing system, or a virtual machine provided by a cloud computing system. In some examples, the apparatus 1100 may comprise a cloud computing system (e.g., a cloud core network), and other network functions of the core network shown in FIG. 1.

[0201] FIG. 2 illustrates an example of a communication device 1200, such as the terminal illustrated on FIG. 1 . The communication device 1200 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 1200 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 1200 may comprise a transceiver for transmitting and / or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.

[0202] The communication device 1200 may receive wireless signals (e.g., radio signals) over an air or radio interface 1207 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In FIG. 12, a transceiver is designated schematically by block 1206. The transceiver 1206 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi output (MIMO) antenna.

[0203] The communication device 1200 may be provided with at least one processor 1201 , at least one memory ROM 1202a, at least one RAM 1202b and other possible components 1203 for use in software and hardware aided execution of tasks it is configured to perform, including control of access to and communications with radio access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices. The at least one processor 901 is coupled to the RAM 1202b and the ROM 1202a. The at least one processor 901 may be configured to execute an appropriate software code 1208 (e.g., the at least one processor may execute instructions of the software code 1208). The execution of the software code 908 may for example allow the communication device to perform one or more operations, including the operations described herein. The software code 1208 may be stored in the ROM 1202a.

[0204] The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. The circuit board, chipsets or system on chip is denoted by reference 1204. The communication device 1200 may optionally have a user interface such as key pad 1205, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of communication device.

[0205] FIG. 13 shows a schematic representation of non-volatile memory media 1300a (e.g. computer disc (CD) or digital versatile disc (DVD)) and 1300b (e.g. universal serial bus (USB) memory stick) storing instructions and / or parameters 1302 which when executed by a processor allow the processor to perform one or more of the steps of any method flow described herein.

[0206] It is understood that references in the above to various network functions (e.g., to an MME, proxy node, NTN GW node, target satellite, etc.) may comprise apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus comprising a network function may comprise a virtual network function instance of that network function.

[0207] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.

[0208] It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein. It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.

[0209] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0210] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0211] As used herein, the term “circuitry” may refer to one or more or all of the following:

[0212] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and

[0213] (b) combinations of hardware circuits and software, such as (as applicable):

[0214] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and

[0215] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and

[0216] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.”

[0217] This definition of circuitry applies to all uses of the term “means” herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0218] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computerexecutable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.

[0219] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.

[0220] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e. , tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0221] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

[0222] Various example embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate. The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments and features thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.

[0223] The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of the disclosure as set forth in the claims. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.

Claims

Claims1. An apparatus comprising: means for receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; means for determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of the apparatus; means for determining an updated access stratum security context for the user equipment using the security key.

2. The apparatus according to claim 1 , wherein the user equipment is in a radio resource control suspended state after the source satellite has lost connectivity with the network node and before the apparatus has connectivity with the user equipment.

3. The apparatus according to claim 1 or claim 2, the apparatus comprising: means for determining a list comprising a message authentication code for each user equipment per non-terrestrial network cell hosted by the apparatus.

4. The apparatus according to claim 3, the apparatus comprising: means for receiving, from the user equipment, a request to resume a radio resource control connection with the network of the apparatus, the request comprising a first message authentication code; means for determining that the first message authentication code is in the list received from the network node and then authenticating the first message authentication code; means for resuming the radio resource control connection with the user equipment.

5. The apparatus according to any preceding claim, the apparatus comprising: means for determining that the identity of the physical cell of the apparatus and the source satellite are the same, and in response, determining the security key using a base station identifier of the apparatus or using any unique identifier of the next satellite after the apparatus that will have connectivity with the core network.

6. The apparatus according to any preceding claim, wherein a satellite comprises the apparatus.

7. The apparatus according to any of claims 1 to 6, the apparatus comprising:means for determining at least one further access stratum integrity and encryption key using the security key.

8. A method comprising: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of an apparatus; determining an updated access stratum security context for the user equipment using the security key.

9. A computer program comprising instructions stored thereon for performing at least the following: receiving, from a network node, an access stratum security context for a user equipment and an indication that the access stratum security context has not been updated after the user equipment was connected to a source satellite; determining a security key for the user equipment using an identity of a physical cell of the apparatus and a channel number of the physical cell of an apparatus; determining an updated access stratum security context for the user equipment using the security key.

10. An apparatus comprising: means for determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; means for sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.11 . The apparatus according to claim 10, wherein the apparatus comprises one of: a core network node; a non-terrestrial network gateway node; a proxy node.

12. A method comprising:determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

13. A computer program comprising instructions stored thereon for performing at least the following: determining a target satellite for a user equipment as a next satellite that will have connectivity with a core network, wherein the user equipment is in a radio resource control suspended state; sending, to the target satellite, an access stratum security context for the user equipment and an indication that the access stratum security context has not been updated.

14. A user equipment comprising: means for sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; means for receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

15. The user equipment according to claim 14, wherein the response comprises an identity of a physical cell of the target satellite and a channel number of the target physical cell, the user equipment comprising: means for determining a security key from the identity of the physical cell of the target satellite and the channel number of the target physical cell; means for connecting to the target satellite using the security key.

16. The user equipment according to claim 15, wherein the identity of the physical cell of the target satellite and an identity of a physical cell of a source satellite for the user equipment are the same, and the response comprises an identifier of a target cell of the target satellite or an identifier of the target satellite, the user equipment comprising: means for determining a security key from the identifier of the physical cell of the target satellite or the identifier of the target satellite; means for connecting to the target satellite using the security key.

17. A method comprising:sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

18. A computer program comprising instructions stored thereon for performing at least the following: sending, to a target satellite, a request to resume a radio resource control connection with a network of the target satellite, the request comprising a message authentication code; receiving a response from the target satellite indicating that the radio resource control connection can be resumed.

Citation Information

Patent Citations

  • Communication method and device

    CN115175181A

  • Mobile communication method

    EP2271145A1

  • System and Method for Communicating with Provisioned Security Protection

    US20190124506A1

  • Information transmission method and apparatus, and communication device

    US20200351977A1

  • Apparatus, method, and computer program

    WO2024026640A1