Transfer of security information from centralized unit to distributed unit
The method of transferring security information from a CU to a candidate cell during cell switch enhances robustness and reduces interruption times in wireless communication systems, particularly in conditional handover scenarios, ensuring secure and efficient handover processes.
Patent Information
- Application Number
- PCT/KR2025/006057
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-08
- Filing Date
- 2025-05-07
- Publication Date
- 2025-11-13
AI Technical Summary
Existing wireless communication systems face challenges in ensuring robustness and minimizing interruption time during cell switch procedures, particularly in scenarios involving conditional handovers and L1/L2 triggered mobility, without compromising security updates.
A method and apparatus for transferring security information from a serving centralized unit (CU) to a candidate cell, enabling secure cell switch commands, which includes security information for seamless handover between different CUs, enhancing both robustness and reducing interruption time.
The solution ensures secure and efficient cell switch procedures with reduced interruption times and improved robustness, addressing the limitations of existing conditional mobility and L1/L2 triggered mobility methods.
Smart Images

Figure KR2025006057_13112025_PF_FP_ABST
Abstract
Description
TRANSFER OF SECURITY INFORMATION FROM CENTRALIZED UNIT TO DISTRIBUTED UNIT
[0001] The present disclosure relates to transfer of security information from a Centralized Unit (CU) to a Distributed Unit (DU).
[0002] 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a technology for enabling high-speed packet communications. Many schemes have been proposed for the LTE objective including those that aim to reduce user and provider costs, improve service quality, and expand and improve coverage and system capacity. The 3GPP LTE requires reduced cost per bit, increased service availability, flexible use of a frequency band, a simple structure, an open interface, and adequate power consumption of a terminal as an upper-level requirement.
[0003] 3GPP New Radio (NR) targets a single technical framework addressing all usage scenarios, requirements and deployment scenarios including enhanced Mobile BroadBand (eMBB), massive Machine Type Communications (mMTC), Ultra-Reliable and Low Latency Communications (URLLC), etc. The NR shall be inherently forward compatible. Further, the NR should be able to use any spectrum band ranging at least up to 100 GHz that may be made available for wireless communications even in a more distant future.
[0004] 6G is the successor to 5G cellular technology. 6G networks will be able to use higher frequencies than 5G networks and provide substantially higher capacity and much lower latency. The 6G technology market is expected to facilitate large improvements in the areas of imaging, presence technology and location awareness. Working in conjunction with Artificial Intelligence (AI), the 6G computational infrastructure will be able to identify the best place for computing to occur. This includes decisions about data storage, processing and sharing.
[0005] Layer 3 based mobility has evolved over several releases. Conditional Handover (CHO) and other conditional mobility procedures (Conditional PSCell Addition and Change (CPAC), Subsequent CPAC (SCPAC)) were developed to achieve high robustness by enabling the procedure to be executed without necessitating a signaling exchange with source cell beforehand. L1 / L2 Triggered Mobility (LTM) as introduced in Rel-18 offers short interruption time but not with the same level of robustness as the conditional L3 mobility procedures. In Rel-19, enhancements should be specified so that the system can benefit from both the high robustness and short interruption.
[0006] In an aspect, a method is provided. The method comprises receiving security information related to a candidate cell from a serving centralized unit (CU). The security information is for security update upon cell switch. The method comprises transmitting a cell switch command for the cell switch from the serving cell to the candidate cell, to the wireless device. The cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.
[0007] In another aspect, an apparatus for implementing the above method is provided.
[0008] FIG. 1 shows an example of a communication system to which implementations of the present disclosure are applied.
[0009] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure are applied.
[0010] FIG. 3 shows an example of UE to which implementations of the present disclosure are applied.
[0011] FIG. 4 shows an example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0012] FIG. 5 shows another example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0013] FIGS. 6 and 7 show an example of protocol stacks in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0014] FIG. 8 shows a frame structure in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0015] FIG. 9 shows a data flow example in the 3GPP NR system to which implementations of the present disclosure are applied.
[0016] FIG. 10 shows an example of inter-gNB handover procedures to which implementations of the present disclosure are applied.
[0017] FIG. 11 shows an example of signaling procedure for LTM to which implementations of the present disclosure are applied.
[0018] FIG. 12 shows an example of a method to which implementations of the present disclosure are applied.
[0019] FIG. 13 shows an example of another method to which implementations of the present disclosure are applied.
[0020] FIG. 14 shows an example of transferring security information for inter-CU LTM to which implementations of the present disclosure are applied.
[0021] The following techniques, apparatuses, and systems may be applied to a variety of wireless multiple access systems. Examples of the multiple access systems include a Code Division Multiple Access (CDMA) system, a Frequency Division Multiple Access (FDMA) system, a Time Division Multiple Access (TDMA) system, an Orthogonal Frequency Division Multiple Access (OFDMA) system, a Single Carrier Frequency Division Multiple Access (SC-FDMA) system, and a Multi Carrier Frequency Division Multiple Access (MC-FDMA) system. CDMA may be embodied through radio technology such as Universal Terrestrial Radio Access (UTRA) or CDMA2000. TDMA may be embodied through radio technology such as Global System for Mobile communications (GSM), General Packet Radio Service (GPRS), or Enhanced Data rates for GSM Evolution (EDGE). OFDMA may be embodied through radio technology such as Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, or Evolved UTRA (E-UTRA). UTRA is a part of a Universal Mobile Telecommunications System (UMTS). 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a part of Evolved UMTS (E-UMTS) using E-UTRA. 3GPP LTE employs OFDMA in Downlink (DL) and SC-FDMA in Uplink (UL). Evolution of 3GPP LTE includes LTE-Advanced (LTE-A), LTE-A Pro, 5G New Radio (NR) and / or 6G.
[0022] For convenience of description, implementations of the present disclosure are mainly described in regards to a 3GPP based wireless communication system. However, the technical features of the present disclosure are not limited thereto. For example, although the following detailed description is given based on a mobile communication system corresponding to a 3GPP based wireless communication system, aspects of the present disclosure that are not limited to 3GPP based wireless communication system are applicable to other mobile communication systems.
[0023] For terms and technologies which are not specifically described among the terms of and technologies employed in the present disclosure, the wireless communication standard documents published before the present disclosure may be referenced.
[0024] In the present disclosure, "A or B" may mean "only A", "only B", or "both A and B". In other words, "A or B" in the present disclosure may be interpreted as "A and / or B". For example, "A, B or C" in the present disclosure may mean "only A", "only B", "only C", or "any combination of A, B and C".
[0025] In the present disclosure, slash ( / ) or comma (,) may mean "and / or". For example, "A / B" may mean "A and / or B". Accordingly, "A / B" may mean "only A", "only B", or "both A and B". For example, "A, B, C" may mean "A, B or C".
[0026] In the present disclosure, "at least one of A and B" may mean "only A", "only B" or "both A and B". In addition, the expression "at least one of A or B" or "at least one of A and / or B" in the present disclosure may be interpreted as same as "at least one of A and B".
[0027] In addition, in the present disclosure, "at least one of A, B and C" may mean "only A", "only B", "only C", or "any combination of A, B and C". In addition, "at least one of A, B or C" or "at least one of A, B and / or C" may mean "at least one of A, B and C".
[0028] Also, parentheses used in the present disclosure may mean "for example". In detail, when it is shown as "control information (PDCCH)", "PDCCH" may be proposed as an example of "control information". In other words, "control information" in the present disclosure is not limited to "PDCCH", and "PDCCH" may be proposed as an example of "control information". In addition, even when shown as "control information (i.e., PDCCH)", "PDCCH" may be proposed as an example of "control information".
[0029] Technical features that are separately described in one drawing in the present disclosure may be implemented separately or simultaneously.
[0030] Although not limited thereto, various descriptions, functions, procedures, suggestions, methods and / or operational flowcharts of the present disclosure disclosed herein can be applied to various fields requiring wireless communication and / or connection (e.g., 5G) between devices.
[0031] Hereinafter, the present disclosure will be described in more detail with reference to drawings. The same reference numerals in the following drawings and / or descriptions may refer to the same and / or corresponding hardware blocks, software blocks, and / or functional blocks unless otherwise indicated.
[0032] FIG. 1 shows an example of a communication system to which implementations of the present disclosure are applied.
[0033] The 5G usage scenarios shown in FIG. 1 are only exemplary, and the technical features of the present disclosure can be applied to other 5G usage scenarios which are not shown in FIG. 1.
[0034] Three main requirement categories for 5G include (1) a category of enhanced Mobile BroadBand (eMBB), (2) a category of massive Machine Type Communication (mMTC), and (3) a category of Ultra-Reliable and Low Latency Communications (URLLC).
[0035] Referring to FIG. 1, the communication system 1 includes wireless devices 100a to 100f, Base Stations (BSs) 200, and a network 300. Although FIG. 1 illustrates a 5G network as an example of the network of the communication system 1, the implementations of the present disclosure are not limited to the 5G system, and can be applied to the future communication system beyond the 5G system.
[0036] The BSs 200 and the network 300 may be implemented as wireless devices and a specific wireless device may operate as a BS / network node with respect to other wireless devices.
[0037] The wireless devices 100a to 100f represent devices performing communication using Radio Access Technology (RAT) (e.g., 5G NR or LTE) and may be referred to as communication / radio / 5G devices. The wireless devices 100a to 100f may include, without being limited to, a robot 100a, vehicles 100b-1 and 100b-2, an eXtended Reality (XR) device 100c, a hand-held device 100d, a home appliance 100e, an Internet-of-Things (IoT) device 100f, and an Artificial Intelligence (AI) device / server 400. For example, the vehicles may include a vehicle having a wireless communication function, an autonomous driving vehicle, and a vehicle capable of performing communication between vehicles. The vehicles may include an Unmanned Aerial Vehicle (UAV) (e.g., a drone). The XR device may include an Augmented Reality (AR) / Virtual Reality (VR) / Mixed Reality (MR) device and may be implemented in the form of a Head-Mounted Device (HMD), a Head-Up Display (HUD) mounted in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance device, a digital signage, a vehicle, a robot, etc. The hand-held device may include a smartphone, a smartpad, a wearable device (e.g., a smartwatch or a smartglasses), and a computer (e.g., a notebook). The home appliance may include a TV, a refrigerator, and a washing machine. The IoT device may include a sensor and a smartmeter.
[0038] In the present disclosure, the wireless devices 100a to 100f may be called User Equipments (UEs). A UE may include, for example, a cellular phone, a smartphone, a laptop computer, a digital broadcast terminal, a Personal Digital Assistant (PDA), a Portable Multimedia Player (PMP), a navigation system, a slate Personal Computer (PC), a tablet PC, an ultrabook, a vehicle, a vehicle having an autonomous traveling function, a connected car, an UAV, an AI module, a robot, an AR device, a VR device, an MR device, a hologram device, a public safety device, an MTC device, an IoT device, a medical device, a FinTech device (or a financial device), a security device, a weather / environment device, a device related to a 5G service, or a device related to a fourth industrial revolution field.
[0039] The wireless devices 100a to 100f may be connected to the network 300 via the BSs 200. An AI technology may be applied to the wireless devices 100a to 100f and the wireless devices 100a to 100f may be connected to the AI server 400 via the network 300. The network 300 may be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, and a beyond-5G network. Although the wireless devices 100a to 100f may communicate with each other through the BSs 200 / network 300, the wireless devices 100a to 100f may perform direct communication (e.g., sidelink communication) with each other without passing through the BSs 200 / network 300. For example, the vehicles 100b-1 and 100b-2 may perform direct communication (e.g., Vehicle-to-Vehicle (V2V) / Vehicle-to-everything (V2X) communication). The IoT device (e.g., a sensor) may perform direct communication with other IoT devices (e.g., sensors) or other wireless devices 100a to 100f.
[0040] Wireless communication / connections 150a, 150b and 150c may be established between the wireless devices 100a to 100f and / or between wireless device 100a to 100f and BS 200 and / or between BSs 200. Herein, the wireless communication / connections may be established through various RATs (e.g., 5G NR) such as uplink / downlink communication 150a, sidelink communication (or Device-to-Device (D2D) communication) 150b, inter-base station communication 150c (e.g., relay, Integrated Access and Backhaul (IAB)), etc. The wireless devices 100a to 100f and the BSs 200 / the wireless devices 100a to 100f may transmit / receive radio signals to / from each other through the wireless communication / connections 150a, 150b and 150c. For example, the wireless communication / connections 150a, 150b and 150c may transmit / receive signals through various physical channels. To this end, at least a part of various configuration information configuring processes, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, and resource mapping / de-mapping), and resource allocating processes, for transmitting / receiving radio signals, may be performed based on the various proposals of the present disclosure.
[0041] NR supports multiples numerologies (and / or multiple Sub-Carrier Spacings (SCS)) to support various 5G services. For example, if SCS is 15 kHz, wide area can be supported in traditional cellular bands, and if SCS is 30 kHz / 60 kHz, dense-urban, lower latency, and wider carrier bandwidth can be supported. If SCS is 60 kHz or higher, bandwidths greater than 24.25 GHz can be supported to overcome phase noise.
[0042] The NR frequency band may be defined as two types of frequency range, i.e., Frequency Range 1 (FR1) and Frequency Range 2 (FR2). The numerical value of the frequency range may be changed. For example, the frequency ranges of the two types (FR1 and FR2) may be as shown in Table 1 below. For ease of explanation, in the frequency ranges used in the NR system, FR1 may mean "sub 6 GHz range", FR2 may mean "above 6 GHz range," and may be referred to as millimeter Wave (mmW).
[0043] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1450MHz - 6000MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz
[0044] As mentioned above, the numerical value of the frequency range of the NR system may be changed. For example, FR1 may include a frequency band of 410MHz to 7125MHz as shown in Table 2 below. That is, FR1 may include a frequency band of 6GHz (or 5850, 5900, 5925 MHz, etc.) or more. For example, a frequency band of 6 GHz (or 5850, 5900, 5925 MHz, etc.) or more included in FR1 may include an unlicensed band. Unlicensed bands may be used for a variety of purposes, for example for communication for vehicles (e.g., autonomous driving).
[0045] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1410MHz - 7125MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz
[0046] Here, the radio communication technologies implemented in the wireless devices in the present disclosure may include NarrowBand IoT (NB-IoT) technology for low-power communication as well as LTE, NR and 6G. For example, NB-IoT technology may be an example of Low Power Wide Area Network (LPWAN) technology, may be implemented in specifications such as LTE Cat NB1 and / or LTE Cat NB2, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may communicate based on LTE-M technology. For example, LTE-M technology may be an example of LPWAN technology and be called by various names such as enhanced MTC (eMTC). For example, LTE-M technology may be implemented in at least one of the various specifications, such as 1) LTE Cat 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-bandwidth limited (non-BL), 5) LTE-MTC, 6) LTE Machine Type Communication, and / or 7) LTE M, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may include at least one of ZigBee, Bluetooth, and / or LPWAN which take into account low-power communication, and may not be limited to the above-mentioned names. For example, ZigBee technology may generate Personal Area Networks (PANs) associated with small / low-power digital communication based on various specifications such as IEEE 802.15.4 and may be called various names.
[0047] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure are applied.
[0048] In FIG. 2, The first wireless device 100 and / or the second wireless device 200 may be implemented in various forms according to use cases / services. For example, {the first wireless device 100 and the second wireless device 200} may correspond to at least one of {the wireless device 100a to 100f and the BS 200}, {the wireless device 100a to 100f and the wireless device 100a to 100f} and / or {the BS 200 and the BS 200} of FIG. 1. The first wireless device 100 and / or the second wireless device 200 may be configured by various elements, devices / parts, and / or modules.
[0049] The first wireless device 100 may include at least one transceiver, such as a transceiver 106, at least one processing chip, such as a processing chip 101, and / or one or more antennas 108.
[0050] The processing chip 101 may include at least one processor, such a processor 102, and at least one memory, such as a memory 104. Additional and / or alternatively, the memory 104 may be placed outside of the processing chip 101.
[0051] The processor 102 may control the memory 104 and / or the transceiver 106 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 102 may process information within the memory 104 to generate first information / signals and then transmit radio signals including the first information / signals through the transceiver 106. The processor 102 may receive radio signals including second information / signals through the transceiver 106 and then store information obtained by processing the second information / signals in the memory 104.
[0052] The memory 104 may be operably connectable to the processor 102. The memory 104 may store various types of information and / or instructions. The memory 104 may store a firmware and / or a software code 105 which implements codes, commands, and / or a set of commands that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may implement instructions that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more protocols. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more layers of the radio interface protocol.
[0053] Herein, the processor 102 and the memory 104 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 106 may be connected to the processor 102 and transmit and / or receive radio signals through one or more antennas 108. Each of the transceiver 106 may include a transmitter and / or a receiver. The transceiver 106 may be interchangeably used with Radio Frequency (RF) unit(s). In the present disclosure, the first wireless device 100 may represent a communication modem / circuit / chip.
[0054] The second wireless device 200 may include at least one transceiver, such as a transceiver 206, at least one processing chip, such as a processing chip 201, and / or one or more antennas 208.
[0055] The processing chip 201 may include at least one processor, such a processor 202, and at least one memory, such as a memory 204. Additional and / or alternatively, the memory 204 may be placed outside of the processing chip 201.
[0056] The processor 202 may control the memory 204 and / or the transceiver 206 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 202 may process information within the memory 204 to generate third information / signals and then transmit radio signals including the third information / signals through the transceiver 206. The processor 202 may receive radio signals including fourth information / signals through the transceiver 106 and then store information obtained by processing the fourth information / signals in the memory 204.
[0057] The memory 204 may be operably connectable to the processor 202. The memory 204 may store various types of information and / or instructions. The memory 204 may store a firmware and / or a software code 205 which implements codes, commands, and / or a set of commands that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may implement instructions that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more protocols. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more layers of the radio interface protocol.
[0058] Herein, the processor 202 and the memory 204 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 206 may be connected to the processor 202 and transmit and / or receive radio signals through one or more antennas 208. Each of the transceiver 206 may include a transmitter and / or a receiver. The transceiver 206 may be interchangeably used with RF unit. In the present disclosure, the second wireless device 200 may represent a communication modem / circuit / chip.
[0059] Hereinafter, hardware elements of the wireless devices 100 and 200 will be described more specifically. One or more protocol layers may be implemented by, without being limited to, one or more processors 102 and 202. For example, the one or more processors 102 and 202 may implement one or more layers (e.g., functional layers such as Physical (PHY) layer, Media Access Control (MAC) layer, Radio Link Control (RLC) layer, Packet Data Convergence Protocol (PDCP) layer, Radio Resource Control (RRC) layer, and Service Data Adaptation Protocol (SDAP) layer). The one or more processors 102 and 202 may generate one or more Protocol Data Units (PDUs), one or more Service Data Unit (SDUs), messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The one or more processors 102 and 202 may generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure and provide the generated signals to the one or more transceivers 106 and 206. The one or more processors 102 and 202 may receive the signals (e.g., baseband signals) from the one or more transceivers 106 and 206 and acquire the PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure.
[0060] The one or more processors 102 and 202 may be referred to as controllers, microcontrollers, microprocessors, or microcomputers. The one or more processors 102 and 202 may be implemented by hardware, firmware, software, or a combination thereof. As an example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in the one or more processors 102 and 202. For example, the one or more processors 102 and 202 may be configured by a set of a communication control processor, an Application Processor (AP), an Electronic Control Unit (ECU), a Central Processing Unit (CPU), a Graphic Processing Unit (GPU), and a memory control processor.
[0061] The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 and store various types of data, signals, messages, information, programs, code, instructions, and / or commands. The one or more memories 104 and 204 may be configured by Random Access Memory (RAM), Dynamic RAM (DRAM), Read-Only Memory (ROM), electrically Erasable Programmable Read-Only Memory (EPROM), flash memory, volatile memory, non-volatile memory, hard drive, register, cash memory, computer-readable storage medium, and / or combinations thereof. The one or more memories 104 and 204 may be located at the interior and / or exterior of the one or more processors 102 and 202. The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 through various technologies such as wired or wireless connection.
[0062] The one or more transceivers 106 and 206 may transmit user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, to one or more other devices. The one or more transceivers 106 and 206 may receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, from one or more other devices. For example, the one or more transceivers 106 and 206 may be connected to the one or more processors 102 and 202 and transmit and receive radio signals. For example, the one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may transmit user data, control information, or radio signals to one or more other devices. The one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may receive user data, control information, or radio signals from one or more other devices.
[0063] The one or more transceivers 106 and 206 may be connected to the one or more antennas 108 and 208. Additionally and / or alternatively, the one or more transceivers 106 and 206 may include one or more antennas 108 and 208. The one or more transceivers 106 and 206 may be adapted to transmit and receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, through the one or more antennas 108 and 208. In the present disclosure, the one or more antennas 108 and 208 may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports).
[0064] The one or more transceivers 106 and 206 may convert received user data, control information, radio signals / channels, etc., from RF band signals into baseband signals in order to process received user data, control information, radio signals / channels, etc., using the one or more processors 102 and 202. The one or more transceivers 106 and 206 may convert the user data, control information, radio signals / channels, etc., processed using the one or more processors 102 and 202 from the base band signals into the RF band signals. To this end, the one or more transceivers 106 and 206 may include (analog) oscillators and / or filters. For example, the one or more transceivers 106 and 206 can up-convert OFDM baseband signals to OFDM signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202 and transmit the up-converted OFDM signals at the carrier frequency. The one or more transceivers 106 and 206 may receive OFDM signals at a carrier frequency and down-convert the OFDM signals into OFDM baseband signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202.
[0065] Although not shown in FIG. 2, the wireless devices 100 and 200 may further include additional components. The additional components 140 may be variously configured according to types of the wireless devices 100 and 200. For example, the additional components 140 may include at least one of a power unit / battery, an Input / Output (I / O) device (e.g., audio I / O port, video I / O port), a driving device, and a computing device. The additional components 140 may be coupled to the one or more processors 102 and 202 via various technologies, such as a wired or wireless connection.
[0066] In the implementations of the present disclosure, a UE may operate as a transmitting device in UL and as a receiving device in DL. In the implementations of the present disclosure, a BS may operate as a receiving device in UL and as a transmitting device in DL. Hereinafter, for convenience of description, it is mainly assumed that the first wireless device 100 acts as the UE, and the second wireless device 200 acts as the BS. For example, the processor(s) 102 connected to, mounted on or launched in the first wireless device 100 may be adapted to perform the UE behavior according to an implementation of the present disclosure or control the transceiver(s) 106 to perform the UE behavior according to an implementation of the present disclosure. The processor(s) 202 connected to, mounted on or launched in the second wireless device 200 may be adapted to perform the BS behavior according to an implementation of the present disclosure or control the transceiver(s) 206 to perform the BS behavior according to an implementation of the present disclosure.
[0067] In the present disclosure, a BS is also referred to as a node B (NB), an eNode B (eNB), or a gNB.
[0068] FIG. 3 shows an example of UE to which implementations of the present disclosure are applied.
[0069] Referring to FIG. 3, a UE 100 may correspond to the first wireless device 100 of FIG. 2.
[0070] A UE 100 includes a processor 102, a memory 104, a transceiver 106, one or more antennas 108, a power management module 141, a battery 142, a display 143, a keypad 144, a Subscriber Identification Module (SIM) card 145, a speaker 146, and a microphone 147.
[0071] The processor 102 may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The processor 102 may be adapted to control one or more other components of the UE 100 to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. Layers of the radio interface protocol may be implemented in the processor 102. The processor 102 may include ASIC, other chipset, logic circuit and / or data processing device. The processor 102 may be an application processor. The processor 102 may include at least one of DSP, CPU, GPU, a modem (modulator and demodulator). An example of the processor 102 may be found in SNAPDRAGONTMseries of processors made by Qualcomm®, EXYNOSTMseries of processors made by Samsung®, A series of processors made by Apple®, HELIOTMseries of processors made by MediaTek®, ATOMTMseries of processors made by Intel®or a corresponding next generation processor.
[0072] The memory 104 is operatively coupled with the processor 102 and stores a variety of information to operate the processor 102. The memory 104 may include ROM, RAM, flash memory, memory card, storage medium and / or other storage device. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The modules can be stored in the memory 104 and executed by the processor 102. The memory 104 can be implemented within the processor 102 or external to the processor 102 in which case those can be communicatively coupled to the processor 102 via various means as is known in the art.
[0073] The transceiver 106 is operatively coupled with the processor 102, and transmits and / or receives a radio signal. The transceiver 106 includes a transmitter and a receiver. The transceiver 106 may include baseband circuitry to process radio frequency signals. The transceiver 106 controls the one or more antennas 108 to transmit and / or receive a radio signal.
[0074] The power management module 141 manages power for the processor 102 and / or the transceiver 106. The battery 142 supplies power to the power management module 141.
[0075] The display 143 outputs results processed by the processor 102. The keypad 144 receives inputs to be used by the processor 102. The keypad 144 may be shown on the display 143.
[0076] The SIM card 145 is an integrated circuit that is intended to securely store the International Mobile Subscriber Identity (IMSI) number and its related key, which are used to identify and authenticate subscribers on mobile telephony devices (such as mobile phones and computers). It is also possible to store contact information on many SIM cards.
[0077] The speaker 146 outputs sound-related results processed by the processor 102. The microphone 147 receives sound-related inputs to be used by the processor 102.
[0078] FIG. 4 shows an example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0079] A Next Generation Radio Access Network (NG-RAN) node is either:
[0080] - a gNB, providing NR user plane and control plane protocol terminations towards the UE; or
[0081] - an ng-eNB, providing E-UTRA user plane and control plane protocol terminations towards the UE.
[0082] The gNBs and ng-eNBs are interconnected with each other by means of the Xn interface. The gNBs and ng-eNBs are also connected by means of the NG interfaces to the 5GC, more specifically to the Access and Mobility Management Function (AMF) by means of the NG-C interface and to the User Plane Function (UPF) by means of the NG-U interface.
[0083] FIG. 5 shows another example of NG-RAN architecture to which implementations of the present disclosure are applied.
[0084] A gNB may consist of a gNB-Centralized Unit (CU) and one or more gNB-Distributed Unit(s) (DU(s)). A gNB-CU and a gNB-DU is connected via F1 interface.
[0085] A gNB-CU is a logical node hosting RRC, SDAP and PDCP protocols of the gNB or RRC and PDCP protocols of the en-gNB that controls the operation of one or more gNB-DUs. The gNB-CU terminates the F1 interface connected with the gNB-DU.
[0086] A gNB-DU is a logical node hosting RLC, MAC and Physical (PHY) layers of the gNB or en-gNB, and its operation is partly controlled by gNB-CU. One gNB-DU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the F1 interface connected with the gNB-CU. For Dual Connectivity (DC) operation, the Master gNB (MgNB)-DU designates the gNB-DU of an en-gNB or a gNB acting as master node, and the Secondary gNB (SgNB)-DU designates the gNB-DU of an en-gNB or a gNB acting as secondary node.
[0087] One gNB-DU is connected to only one gNB-CU.
[0088] In case of network sharing with multiple cell Identity (ID) broadcast, each cell ID associated with a subset of Public land Mobile Networks (PLMNs) corresponds to a gNB-DU and the gNB-CU it is connected to, i.e., the corresponding gNB-DUs share the same physical layer cell resources.
[0089] For resiliency, a gNB-DU may be connected to multiple gNB-CUs by appropriate implementation.
[0090] NG, Xn and F1 are logical interfaces.
[0091] FIGS. 6 and 7 show an example of protocol stacks in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0092] In particular, FIG. 6 illustrates an example of a radio interface user plane protocol stack between a UE and a BS and FIG. 7 illustrates an example of a radio interface control plane protocol stack between a UE and a BS. The control plane refers to a path through which control messages used to manage call by a UE and a network are transported. The user plane refers to a path through which data generated in an application layer, for example, voice data or Internet packet data are transported. Referring to FIG. 6, the user plane protocol stack may be divided into Layer 1 (i.e., a PHY layer) and Layer 2. Referring to FIG. 7, the control plane protocol stack may be divided into Layer 1 (i.e., a PHY layer), Layer 2, Layer 3 (e.g., an RRC layer), and a Non-Access Stratum (NAS) layer. Layer 1, Layer 2 and Layer 3 are referred to as an Access Stratum (AS).
[0093] In the 3GPP LTE system, the Layer 2 is split into the following sublayers: MAC, RLC, and PDCP. In the 3GPP NR system, the Layer 2 is split into the following sublayers: MAC, RLC, PDCP and SDAP. The PHY layer offers to the MAC sublayer transport channels, the MAC sublayer offers to the RLC sublayer logical channels, the RLC sublayer offers to the PDCP sublayer RLC channels, the PDCP sublayer offers to the SDAP sublayer radio bearers. The SDAP sublayer offers to 5G core network Quality of Service (QoS) flows.
[0094] In the 3GPP NR system, the main services and functions of the MAC sublayer include: mapping between logical channels and transport channels; multiplexing / de-multiplexing of MAC SDUs belonging to one or different logical channels into / from Transport Blocks (TB) delivered to / from the physical layer on transport channels; scheduling information reporting; error correction through Hybrid Automatic Repeat reQuest (HARQ) (one HARQ entity per cell in case of Carrier Aggregation (CA)); priority handling between UEs by means of dynamic scheduling; priority handling between logical channels of one UE by means of logical channel prioritization; padding. A single MAC entity may support multiple numerologies, transmission timings and cells. Mapping restrictions in logical channel prioritization control which numerology(ies), cell(s), and transmission timing(s) a logical channel can use.
[0095] Different kinds of data transfer services are offered by MAC. To accommodate different kinds of data transfer services, multiple types of logical channels are defined, i.e., each supporting transfer of a particular type of information. Each logical channel type is defined by what type of information is transferred. Logical channels are classified into two groups: control channels and traffic channels. Control channels are used for the transfer of control plane information only, and traffic channels are used for the transfer of user plane information only. Broadcast Control Channel (BCCH) is a downlink logical channel for broadcasting system control information, Paging Control Channel (PCCH) is a downlink logical channel that transfers paging information, system information change notifications and indications of ongoing Public Warning Service (PWS) broadcasts, Common Control Channel (CCCH) is a logical channel for transmitting control information between UEs and network and used for UEs having no RRC connection with the network, and Dedicated Control Channel (DCCH) is a point-to-point bi-directional logical channel that transmits dedicated control information between a UE and the network and used by UEs having an RRC connection. Dedicated Traffic Channel (DTCH) is a point-to-point logical channel, dedicated to one UE, for the transfer of user information. A DTCH can exist in both uplink and downlink. In downlink, the following connections between logical channels and transport channels exist: BCCH can be mapped to Broadcast Channel (BCH); BCCH can be mapped to Downlink Shared Channel (DL-SCH); PCCH can be mapped to Paging Channel (PCH); CCCH can be mapped to DL-SCH; DCCH can be mapped to DL-SCH; and DTCH can be mapped to DL-SCH. In uplink, the following connections between logical channels and transport channels exist: CCCH can be mapped to Uplink Shared Channel (UL-SCH); DCCH can be mapped to UL-SCH; and DTCH can be mapped to UL-SCH.
[0096] The RLC sublayer supports three transmission modes: Transparent Mode (TM), Unacknowledged Mode (UM), and Acknowledged Mode (AM). The RLC configuration is per logical channel with no dependency on numerologies and / or transmission durations. In the 3GPP NR system, the main services and functions of the RLC sublayer depend on the transmission mode and include: transfer of upper layer PDUs; sequence numbering independent of the one in PDCP (UM and AM); error correction through ARQ (AM only); segmentation (AM and UM) and re-segmentation (AM only) of RLC SDUs; reassembly of SDU (AM and UM); duplicate detection (AM only); RLC SDU discard (AM and UM); RLC re-establishment; protocol error detection (AM only).
[0097] In the 3GPP NR system, the main services and functions of the PDCP sublayer for the user plane include: sequence numbering; header compression and decompression using Robust Header Compression (ROHC); transfer of user data; reordering and duplicate detection; in-order delivery; PDCP PDU routing (in case of split bearers); retransmission of PDCP SDUs; ciphering, deciphering and integrity protection; PDCP SDU discard; PDCP re-establishment and data recovery for RLC AM; PDCP status reporting for RLC AM; duplication of PDCP PDUs and duplicate discard indication to lower layers. The main services and functions of the PDCP sublayer for the control plane include: sequence numbering; ciphering, deciphering and integrity protection; transfer of control plane data; reordering and duplicate detection; in-order delivery; duplication of PDCP PDUs and duplicate discard indication to lower layers.
[0098] In the 3GPP NR system, the main services and functions of SDAP include: mapping between a QoS flow and a data radio bearer; marking QoS Flow ID (QFI) in both DL and UL packets. A single protocol entity of SDAP is configured for each individual PDU session.
[0099] In the 3GPP NR system, the main services and functions of the RRC sublayer include: broadcast of system information related to AS and NAS; paging initiated by 5G Core network (5GC) or Next-Generation Radio Access Network (NG-RAN); establishment, maintenance and release of an RRC connection between the UE and NG-RAN; security functions including key management; establishment, configuration, maintenance and release of Signaling Radio Bearers (SRBs) and Data Radio Bearers (DRBs); mobility functions (including: handover and context transfer, UE cell selection and reselection and control of cell selection and reselection, inter-RAT mobility); QoS management functions; UE measurement reporting and control of the reporting; detection of and recovery from radio link failure; NAS message transfer to / from NAS from / to UE.
[0100] FIG. 8 shows a frame structure in a 3GPP based wireless communication system to which implementations of the present disclosure are applied.
[0101] The frame structure shown in FIG. 8 is purely exemplary and the number of subframes, the number of slots, and / or the number of symbols in a frame may be variously changed. In the 3GPP based wireless communication system, OFDM numerologies (e.g., SCS, Transmission Time Interval (TTI) duration) may be differently configured between a plurality of cells aggregated for one UE. For example, if a UE is configured with different SCSs for cells aggregated for the cell, an (absolute time) duration of a time resource (e.g., a subframe, a slot, or a TTI) including the same number of symbols may be different among the aggregated cells. Herein, symbols may include OFDM symbols (or Cyclic Prefix (CP)-OFDM symbols), SC-FDMA symbols (or Discrete Fourier Transform-spread-OFDM (DFT-s-OFDM) symbols).
[0102] Referring to FIG. 8, downlink and uplink transmissions are organized into frames. Each frame has Tf= 10ms duration. Each frame is divided into two half-frames, where each of the half-frames has 5ms duration. Each half-frame consists of 5 subframes, where the duration Tsfper subframe is 1ms. Each subframe is divided into slots and the number of slots in a subframe depends on a subcarrier spacing. Each slot includes 14 or 12 OFDM symbols based on a CP. In a normal CP, each slot includes 14 OFDM symbols and, in an extended CP, each slot includes 12 OFDM symbols. The numerology is based on exponentially scalable subcarrier spacing Δf = 2u*15 kHz.
[0103] Table 3 shows the number of OFDM symbols per slot Nslotsymb, the number of slots per frameNframe,uslot, and the number of slots per subframe Nsubframe,uslotfor the normal CP, according to the subcarrier spacing Δf = 2u*15 kHz.
[0104] uNslotsymbNframe,uslotNsubframe,uslot01410111420221440431480841416016
[0105] Table 4 shows the number of OFDM symbols per slot Nslotsymb, the number of slots per frameNframe,uslot, and the number of slots per subframe Nsubframe,uslotfor the extended CP, according to the subcarrier spacing Δf = 2u*15 kHz.
[0106] uNslotsymbNframe,uslotNsubframe,uslot212404
[0107] A slot includes plural symbols (e.g., 14 or 12 symbols) in the time domain. For each numerology (e.g., subcarrier spacing) and carrier, a resource grid ofNsize,ugrid,x*NRBscsubcarriers andNsubframe,usymbOFDM symbols is defined, starting at Common Resource Block (CRB)Nstart,ugridindicated by higher-layer signaling (e.g., RRC signaling), whereNsize,ugrid,xis the number of Resource Blocks (RBs) in the resource grid and the subscript x is DL for downlink and UL for uplink.NRBscis the number of subcarriers per RB. In the 3GPP based wireless communication system,NRBscis 12 generally. There is one resource grid for a given antenna portp, subcarrier spacing configurationu, and transmission direction (DL or UL). The carrier bandwidthNsize,ugridfor subcarrier spacing configurationuis given by the higher-layer parameter (e.g., RRC parameter). Each element in the resource grid for the antenna portpand the subcarrier spacing configurationuis referred to as a Resource Element (RE) and one complex symbol may be mapped to each RE. Each RE in the resource grid is uniquely identified by an indexkin the frequency domain and an indexlrepresenting a symbol location relative to a reference point in the time domain. In the 3GPP based wireless communication system, an RB is defined by 12 consecutive subcarriers in the frequency domain.
[0108] In the 3GPP NR system, RBs are classified into CRBs and Physical Resource Blocks (PRBs). CRBs are numbered from 0 and upwards in the frequency domain for subcarrier spacing configurationu. The center of subcarrier 0 of CRB 0 for subcarrier spacing configurationucoincides with 'point A' which serves as a common reference point for resource block grids. In the 3GPP NR system, PRBs are defined within a BandWidth Part (BWP) and numbered from 0 toNsizeBWP,i-1, where i is the number of the bandwidth part. The relation between the physical resource block nPRBin the bandwidth part i and the common resource block nCRBis as follows: nPRB= nCRB+NsizeBWP,i, whereNsizeBWP,iis the common resource block where bandwidth part starts relative to CRB 0. The BWP includes a plurality of consecutive RBs. A carrier may include a maximum of N (e.g., 5) BWPs. A UE may be configured with one or more BWPs on a given component carrier. Only one BWP among BWPs configured to the UE can active at a time. The active BWP defines the UE's operating bandwidth within the cell's operating bandwidth.
[0109] In the present disclosure, the term "cell" may refer to a geographic area to which one or more nodes provide a communication system, or refer to radio resources. A "cell" as a geographic area may be understood as coverage within which a node can provide service using a carrier and a "cell" as radio resources (e.g., time-frequency resources) is associated with bandwidth which is a frequency range configured by the carrier. The "cell" associated with the radio resources is defined by a combination of downlink resources and uplink resources, for example, a combination of a DL Component Carrier (CC) and a UL CC. The cell may be configured by downlink resources only, or may be configured by downlink resources and uplink resources. Since DL coverage, which is a range within which the node is capable of transmitting a valid signal, and UL coverage, which is a range within which the node is capable of receiving the valid signal from the UE, depends upon a carrier carrying the signal, the coverage of the node may be associated with coverage of the "cell" of radio resources used by the node. Accordingly, the term "cell" may be used to represent service coverage of the node sometimes, radio resources at other times, or a range that signals using the radio resources can reach with valid strength at other times.
[0110] In CA, two or more CCs are aggregated. A UE may simultaneously receive or transmit on one or multiple CCs depending on its capabilities. CA is supported for both contiguous and non-contiguous CCs. When CA is configured, the UE only has one RRC connection with the network. At RRC connection establishment / re-establishment / handover, one serving cell provides the NAS mobility information, and at RRC connection re-establishment / handover, one serving cell provides the security input. This cell is referred to as the Primary Cell (PCell). The PCell is a cell, operating on the primary frequency, in which the UE either performs the initial connection establishment procedure or initiates the connection re-establishment procedure. Depending on UE capabilities, Secondary Cells (SCells) can be configured to form together with the PCell a set of serving cells. An SCell is a cell providing additional radio resources on top of Special Cell (SpCell). The configured set of serving cells for a UE therefore always consists of one PCell and one or more SCells. For Dual Connectivity (DC) operation, the term SpCell refers to the PCell of the Master Cell Group (MCG) or the Primary SCell (PSCell) of the Secondary Cell Group (SCG). An SpCell supports Physical Uplink Control Channel (PUCCH) transmission and contention-based random access, and is always activated. The MCG is a group of serving cells associated with a master node, comprised of the SpCell (PCell) and optionally one or more SCells. The SCG is the subset of serving cells associated with a secondary node, comprised of the PSCell and zero or more SCells, for a UE configured with DC. For a UE in RRC_CONNECTED not configured with CA / DC, there is only one serving cell comprised of the PCell. For a UE in RRC_CONNECTED configured with CA / DC, the term "serving cells" is used to denote the set of cells comprised of the SpCell(s) and all SCells. In DC, two MAC entities are configured in a UE: one for the MCG and one for the SCG.
[0111] FIG. 9 shows a data flow example in the 3GPP NR system to which implementations of the present disclosure are applied.
[0112] Referring to FIG. 9, "RB" denotes a radio bearer, and "H" denotes a header. Radio bearers are categorized into two groups: DRBs for user plane data and SRBs for control plane data. The MAC PDU is transmitted / received using radio resources through the PHY layer to / from an external device. The MAC PDU arrives to the PHY layer in the form of a transport block.
[0113] In the PHY layer, the uplink transport channels UL-SCH and Random Access Channel (RACH) are mapped to their physical channels Physical Uplink Shared Channel (PUSCH) and Physical Random Access Channel (PRACH), respectively, and the downlink transport channels DL-SCH, BCH and PCH are mapped to Physical Downlink Shared Channel (PDSCH), Physical Broadcast Channel (PBCH) and PDSCH, respectively. In the PHY layer, Uplink Control Information (UCI) is mapped to PUCCH, and Downlink Control Information (DCI) is mapped to Physical Downlink Control Channel (PDCCH). A MAC PDU related to UL-SCH is transmitted by a UE via a PUSCH based on an UL grant, and a MAC PDU related to DL-SCH is transmitted by a BS via a PDSCH based on a DL assignment.
[0114] Network controlled mobility applies to UEs in RRC_CONNECTED and is categorized into two types of mobility: cell level mobility and beam level mobility. Beam level mobility includes intra-cell beam level mobility and inter-cell beam level mobility.
[0115] Cell level mobility requires explicit RRC signaling to be triggered, i.e., handover.
[0116] FIG. 10 shows an example of inter-gNB handover procedures to which implementations of the present disclosure are applied.
[0117] For inter-gNB handover, the signaling procedures consist of at least the following elemental components described in FIG. 10.
[0118] 1. Step 1: The source gNB initiates handover and issues a HANDOVER REQUEST over the Xn interface.
[0119] 2. Step 2: The target gNB performs admission control and provides the new RRC configuration as part of the HANDOVER REQUEST ACKNOWLEDGE.
[0120] 3. Step 3: The source gNB provides the RRC configuration to the UE by forwarding theRRCReconfigurationmessage received in the HANDOVER REQUEST ACKNOWLEDGE. TheRRCReconfigurationmessage includes at least cell ID and all information required to access the target cell so that the UE can access the target cell without reading system information. For some cases, the information required for contention-based and contention-free random access can be included in theRRCReconfigurationmessage. The access information to the target cell may include beam specific information, if any.
[0121] 4. Step 4: The UE moves the RRC connection to the target gNB and replies with theRRCReconfigurationComplete.
[0122] User data may also be sent in step 4 if the grant allows.
[0123] Beam level mobility does not require explicit RRC signaling to be triggered. Beam level mobility can be within a cell, or between cells, the latter is referred to as Inter-Cell Beam Management (ICBM). For ICBM, a UE can receive or transmit UE dedicated channels / signals via a Transmission / Reception Point (TRP) associated with a Physical Cell ID (PCI) different from the PCI of a serving cell, while non-UE-dedicated channels / signals can only be received via a TRP associated with a PCI of the serving cell. The gNB provides via RRC signaling the UE with measurement configuration containing configurations of Synchronization Signal Block (SSB) / Channel State Information (CSI) resources and resource sets, reports and trigger states for triggering channel and interference measurements and reports. In case of ICBM, a measurement configuration includes SSB resources associated with PCIs different from the PCI of a serving cell. Beam level mobility is then dealt with at lower layers by means of physical layer and MAC layer control signaling, and RRC is not required to know which beam is being used at a given point in time.
[0124] SSB-based beam level mobility is based on the SSB associated to the initial DL BWP and can only be configured for the initial DL BWPs and for DL BWPs containing the SSB associated to the initial DL BWP. For other DL BWPs, beam level mobility can only be performed based on CSI-Reference Signal (RS).
[0125] A Conditional Handover (CHO) is defined as a handover that is executed by the UE when one or more handover execution conditions are met. The UE starts evaluating the execution condition(s) upon receiving the CHO configuration, and stops evaluating the execution condition(s) once a handover is executed.
[0126] The following principles apply to CHO:
[0127] - The CHO configuration contains the configuration of CHO candidate cell(s) generated by the candidate gNB(s) and execution condition(s) generated by the source gNB.
[0128] - An execution condition may consist of one or two trigger condition(s) (CHO events A3 / ). Only single RS type is supported and at most two different trigger quantities (e.g., Reference Signal Received Power (RSRP) and Reference Signal Received Quality (RSRQ), RSRP and Signal-to-Interference plus Noise Ratio (SINR), etc.) can be configured simultaneously for the evaluation of CHO execution condition of a single candidate cell.
[0129] - Before any CHO execution condition is satisfied, upon reception of HO command (without CHO configuration), the UE executes the HO procedure, regardless of any previously received CHO configuration.
[0130] - While executing CHO, i.e., from the time when the UE starts synchronization with target cell, the UE does not monitor source cell.
[0131] L1 / L2 Triggered Mobility (LTM) is a procedure in which a gNB receives L1 measurement report(s) from a UE, and on their basis the gNB changes UE's serving cell by a cell switch command signaled via a MAC CE. The cell switch command indicates an LTM candidate cell configuration that the gNB previously prepared and provided to the UE through RRC signaling. Then the UE switches to the target cell according to the cell switch command. The LTM procedure can be used to reduce the mobility latency.
[0132] When configured by the network, it is possible to activate Transmission Configuration Index (TCI) states of one or multiple cells that are different from the current serving cell. For instance, the TCI states of the LTM candidate cells can be activated in advance before any of those cells become the serving cell. This allows the UE to be DL synchronized with those cells, thereby facilitating a faster cell switch to one of those cells when cell switch is triggered.
[0133] When configured by the network, it is possible to initiate UL Timing Advance (TA) acquisition procedure to one or multiple cells that are different from the current serving cell. For instance, the network may request the UE to perform early TA acquisition of a candidate cell before a cell switch. The early TA acquisition is triggered by PDCCH order or realized through UE-based TA measurement. In the former case, the gNB to which the candidate cell belongs calculates the TA value and sends it to the gNB to which the serving cell belongs. The serving cell sends the TA value in the LTM cell switch command MAC CE when triggering LTM cell switch. In the latter case, the UE applies the TA value measured by itself and performs RACH-less LTM upon receiving the cell switch command.
[0134] If UE-based TA measurement is configured, the UE performs RACH-less LTM upon receiving the cell switch command. Otherwise, the UE determines whether to access the target cell with the RA procedure depending on whether a TA value is provided in the cell switch command. For RACH-less LTM, the UE accesses the target cell via a configured grant provided in the LTM candidate cell configuration and selects the configured grant occasion associated with the beam indicated in the cell switch command. If the LTM candidate cell configuration does not include a configured grant, the UE may monitor PDCCH for dynamic scheduling from the target cell upon LTM cell switch. Before RACH-less LTM procedure completion, the UE may not trigger random access procedure if it does not have a valid PUCCH resource for triggered Scheduling Requests (SRs).
[0135] The following principles apply to LTM:
[0136] - The UE does not update its security key after an intra-gNB LTM cell switch.
[0137] - Subsequent LTM is supported.
[0138] LTM supports both intra-gNB-Distributed Unit (DU) and intra-gNB-Centralized Unit (CU) inter-gNB-DU mobility. LTM supports both intra-frequency and inter-frequency mobility, including mobility to inter-frequency cell that is not a current serving cell. The following scenarios are supported:
[0139] - PCell change in non-CA scenario and non-DC scenario,
[0140] - PCell change in CA scenario,
[0141] - DC scenario, MCG PCell change and SCG PSCell change without MN involvement case (i.e., intra-SN PSCell change).
[0142] While the UE has stored LTM candidate cell configurations, the UE can also execute any L3 handover command sent by the network.
[0143] FIG. 11 shows an example of signaling procedure for LTM to which implementations of the present disclosure are applied.
[0144] Cell switch command is conveyed in a MAC Control Element (CE), which contains the necessary information to perform the LTM cell switch.
[0145] Subsequent LTM is done by repeating the early synchronization, LTM cell switch execution, and LTM cell switch completion steps without releasing other LTM candidate cell configurations after each LTM cell switch completion.
[0146] The signaling procedure for LTM is as follows.
[0147] 1. Step 1: The UE sends aMeasurementReportmessage to the gNB. The gNB decides to configure LTM and initiates candidate cell(s) preparation.
[0148] 2. Step 2: The gNB transmits anRRCReconfigurationmessage to the UE including the LTM candidate cell configurations of one or multiple candidate cells.
[0149] 3. Step 3: The UE stores the LTM candidate cell configurations and transmits anRRCReconfigurationCompletemessage to the gNB.
[0150] 4a. Step 4a: The UE may perform DL synchronization with the candidate cell(s) before receiving the cell switch command.
[0151] 4b. Step 4b: When UE-based TA measurement is configured, the UE may acquire the TA value(s) of the candidate cell(s) by measurement. Otherwise, the UE may perform early TA acquisition with the candidate cell(s) as requested by the network before receiving the cell switch command. This may be done via Contention-Free Random Access (CFRA) triggered by a PDCCH order from the source cell, following which the UE may send preamble towards the indicated candidate cell. In order to minimize the data interruption of the source cell due to CFRA towards the candidate cell(s), the UE may not receive random access response from the network for the purpose of TA value acquisition and the TA value of the candidate cell is indicated in the cell switch command. The UE may not maintain the TA timer for the candidate cell and relies on network implementation to guarantee the TA validity.
[0152] 5. Step 5: The UE performs L1 measurements on the configured candidate cell(s) and transmits L1 measurement reports to the gNB. L1 measurement should be performed as long as RRC reconfiguration (step 2) is applicable.
[0153] 6. Step 6: The gNB decides to execute cell switch to a target cell and transmits a MAC CE triggering cell switch by including the candidate configuration index of the target cell. The UE switches to the target cell and applies the configuration indicated by candidate configuration index.
[0154] 7. Step 7: The UE may perform the random access procedure towards the target cell, if the UE does not have valid TA of the target cell. The UE may perform CFRA if the LTM cell switch command MAC CE contains information for CFRA.
[0155] 8. Step 8: The UE completes the LTM cell switch procedure by sendingRRCReconfigurationCompletemessage to target cell. If the UE has performed a random access procedure in step 7, the UE considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed. For RACH-less LTM, the UE considers that LTM cell switch execution is successfully completed when the UE determines that the network has successfully received its first UL data. The UE determines successful reception of its first UL data by receiving a PDCCH addressing the UE's Cell Radio Network Temporary Identity (C-RNTI) in the target cell, which schedules a new transmission following the first UL data. The PDCCH carries either a DL assignment or an UL grant addressing the same HARQ process as the first UL data.
[0156] The steps 4-8 can be performed multiple times for subsequent LTM using the LTM candidate cell configuration(s) provided in step 2.
[0157] Security handling in mobility is described.
[0158] Whenever an initial AS security context needs to be established between UE and gNB / ng-eNB, Access and mobility Management Function (AMF) and the UE may derive a KgNBand a Next Hop parameter (NH). The KgNBand the NH are derived from the KAMF. A NH Chaining Counter (NCC) is associated with each KgNBand NH parameter. Every KgNBis associated with the NCC corresponding to the NH value from which it was derived. At initial setup, the KgNBis derived directly from KAMF, and is then considered to be associated with a virtual NH parameter with NCC value equal to zero. At initial setup, the derived NH value is associated with the NCC value one.
[0159] The AMF may not send the NH value to gNB / ng-eNB at the initial connection setup. The gNB / ng-eNB may initialize the NCC value to zero after receiving NGAP Initial Context Setup Request message.
[0160] The UE and the gNB / ng-eNB use the KgNBto secure the communication between each other. On handovers and at transitions from RRC_INACTIVE to RRC_CONNECTED states, the basis for the KgNBthat will be used between the UE and the target gNB / ng-eNB, called KNG-RAN*, is derived from either the currently active KgNBor from the NH parameter. If KNG-RAN* is derived from the currently active KgNB, this is referred to as a horizontal key derivation and if the KNG-RAN* is derived from the NH parameter, the derivation is referred to as a vertical key derivation.
[0161] As NH parameters are only computable by the UE and the AMF, it is arranged so that NH parameters are provided to gNB / ng-eNBs from the AMF in such a way that forward security can be achieved.
[0162] On handovers with vertical key derivation, the NH is further bound to the target PCI and its frequency Absolute Radio-Frequency Channel Number (ARFCN)-DL before it is taken into use as the KgNBin the target gNB / ng-eNB. On handovers with horizontal key derivation, the currently active KgNBis further bound to the target PCI and its frequency ARFCN-DL before it is taken into use as the KgNBin the target gNB / ng-eNB.
[0163] In intra-gNB-CU handover and intra-ng-eNB handover, the gNB may have a policy deciding at which intra-gNB-CU handovers the KgNBcan be retained and at which a new KgNBneeds to be derived. At an intra-gNB-CU handover, the gNB may indicate to the UE whether to change or retain the current KgNBin the HO Command message. Retaining the current KgNBmay only be done during intra-gNB-CU handover.
[0164] If the current KgNBis to be changed, the gNB / ng-eNB and the UE may derive a KNG-RAN* using target PCI, its frequency ARFCN-DL / E-UTRAN ARFCN (EARFCN)-DL, and either NH or the current KgNBdepending on the following criteria: the gNB may use the NH for deriving KNG-RAN* if an unused {NH, NCC} pair is available in the gNB (this is referred to as a vertical key derivation), otherwise if no unused {NH, NCC} pair is available in the gNB, the gNB may derive KNG-RAN* from the current KgNB(this is referred to as a horizontal key derivation). The gNB may send the NCC used for the KNG-RAN* derivation to UE in HO Command message. The gNB / ng-eNB and the UE may use the KNG-RAN* as the KgNB, after handover.
[0165] If the current KgNBis to be retained, the gNB and the UE may continue using the current KgNB, after handover.
[0166] This may also be applicable when gNB is implemented as a single unit, i.e., when the gNB is not split into CU and DU.
[0167] In Xn handover, the source gNB / ng-eNB may perform a vertical key derivation in case it has an unused {NH, NCC} pair. The source gNB / ng-eNB may first compute KNG-RAN* from target PCI, its frequency ARFCN-DL / EARFCN-DL, and either from currently active KgNBin case of horizontal key derivation or from the NH in case of vertical key derivation.
[0168] Next, the source gNB / ng-eNB may forward the {KNG-RAN*, NCC} pair to the target gNB / ng-eNB. The target gNB / ng-eNB may use the received KNG-RAN* directly as KgNBto be used with the UE. The target gNB / ng-eNB may associate the NCC value received from source gNB / ng-eNB with the KgNB. The target gNB / ng-eNB may include the received NCC into the prepared HO Command message, which is sent back to the source gNB / ng-eNB in a transparent container and forwarded to the UE by source gNB / ng-eNB.
[0169] When the target gNB / ng-eNB has completed the handover signaling with the UE, it may send a NGAP PATH SWITCH REQUEST message to the AMF. Upon reception of the NGAP PATH SWITCH REQUEST, the AMF may increase its locally kept NCC value by one and compute a new fresh NH from its stored data using the function. The AMF may use the KAMFfrom the currently active 5G NAS security context for the computation of the new fresh NH. The AMF may then send the newly computed {NH, NCC} pair to the target gNB / ng-eNB in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The target gNB / ng-eNB may store the received {NH, NCC} pair for further handovers and remove other existing unused stored {NH, NCC} pairs if any.
[0170] If the AMF had activated a new 5G NAS security context with a new KAMF, different from the 5G NAS security context on which the currently active 5G AS security context is based, but has not yet successfully performed a UE Context Modification procedure, the sent NGAP PATH SWITCH REQUEST ACKNOWLEDGE message may in addition contain a New Security Context Indicator (NSCI). The AMF may in this case derive a new initial KgNBfrom the new KAMFand the uplink NAS COUNT in the most recent NAS Security Mode Complete message. The AMF may associate the derived new initial KgNBwith a new NCC value equal to zero. Then, the AMF may use {the derived new initial KgNB, the new NCC value initialized to zero} pair as the newly computed {NH, NCC} pair to be sent in the NGAP PATH SWITCH REQUEST ACKNOWLEDGE message. The gNB / ng-eNB may in this case set the value ofkeySetChangeIndicatorfield to true in further handovers. The gNB / ng-eNB should in this case perform an intra-gNB-CU / intra-ng-eNB handover immediately.
[0171] The key derivation mechanism described above may also be applicable to CHO.
[0172] The UE behavior is the same regardless if the handover is intra-gNB-CU, intra ng-eNB, Xn, or N2 with the exception that during intra-gNB-CU handover, the UE may retain the same key based on an indication from the gNB. The UE behavior is also same in case of CHO, i.e., the UE shall use the parameters of the selected target cell in KNG-RAN* derivations.
[0173] If the UE also receives a NAS Container (NASC) in the HO Command message, the UE may update its NAS security context as follows:
[0174] 1> The UE may verify the freshness of the downlink NAS COUNT in the NASC.
[0175] 1> If the NASC indicates a new KAMFhas been calculated (i.e., K_AMF_change_flag is one),
[0176] 2> The UE may compute the horizontally derived KAMFusing the KAMFfrom the current 5G NAS security context identified by the ngKSI included in the NASC and the downlink NAS COUNT in the NASC.
[0177] 2> The UE may assign the ngKSI included in the NASC to the ngKSI of the new derived KAMF. The UE may further configure NAS security based on the horizontally derived KAMFand the selected NAS security algorithms in the NASC.
[0178] 2> The UE may further verify the NAS MAC in the NASC and if the verification is successful, the UE may further set the NAS COUNTs to zero.
[0179] 1> If KAMFchange is not indicated,
[0180] 2> If the verification is successful, the UE may configure the NAS security based on the parameters included in the NASC but may not set the NAS COUNTs to zero.
[0181] 2> The UE may verify the NAS MAC in the NASC.
[0182] 2> The UE may further set the downlink NAS COUNT value of the currently active NAS security context to the received downlink NAS COUNT value in the NASC.
[0183] If verification of the NASC fails, the UE may abort the handover procedure. Furthermore, the UE may discard the new NAS security context if it was derived and continue to use the existing NAS and AS security contexts.
[0184] The UE may use the KNG-RAN* as the KgNBwhen communicating with the target gNB and as the KeNBwhen communicating with the target ng-eNB.
[0185] The S-KeNBthat is used for dual connectivity between base stations is also used as the root for the security context at the secondary base station (e.g., Secondary gNB (SgNB)). When used in the contexts of dual connectivity with an SgNB, the key may be called an S-KgNB, i.e., the master base station (e.g., Master eNB (MeNB) and / or Master gNB (MgNB)) generates and forwards an S-KgNBto the SgNB during the SgNB addition procedure or SgNB mprocedure requiring key update.
[0186] Similarly, the MeNB / MgNB handles the SCG counter due to interactions with a SgNB for interactions with SeNBs, i.e., this is a single shared SCG counter for SeNBs and SgNBs and provides the same value of SCG counter used to the UE and ensure that fresh radio bearer identities are used or the S-KgNBis refreshed.
[0187] When the SgNB receives an S-KgNBin a SgNB addition / modification procedure, the SgNB may derive and store KSgNB-UP-encand KSgNB-UP-int, as well as KSgNB-RRC-intand KSgNB-RRC-encif an SRB is to be added from the received S-KgNB. These freshly derived keys are then used to protect all the radio bearer(s) that use the PDCP of the SgNB. Any previous such keys may be deleted. If all the keys were derived, then the S-KgNBmay be deleted.
[0188] If the UE receives a new SCG counter in SgNB addition / modification procedure, then the UE may derive a new S-KgNBfrom this SCG counter and use KSgNB-UP-enc, KSgNB-UP-int, KSgNB-RRC-intand KSgNB-RRC-encderived from the new S-KgNB, as the keys to protect all the radio bearer(s) using the PDCP of the SgNB. If all the keys were derived, then the S-KgNBmay be deleted in the UE.
[0189] When the SgNB release procedure releases the last radio bearer on the SgNB, the SgNB and the UE may delete the KSgNB-UPenc,KSgNB-UP-int,KSgNB-RRC-intand KSgNB-RRC-enc. The SgNB and UE may also delete the S-KgNB, if it was not deleted earlier.
[0190] The UE and MeNB / MgNB may derive the security key S-KgNBof the target SgNB. KSgNB-UP-enc, KSgNB-UP-int,KSgNB-RRC-intand KSgNB-RRC-encare derived from the S-KgNBboth at the SgNB side and the UE side.
[0191] The system supports update of the S-KgNB. The MeNB / MgNB may update the S-KgNBfor any reason by using the S-KgNBupdate procedure. The SgNB may request the MeNB / MgNB to update the S-KgNBover the X2-C, when uplink or downlink PDCP COUNTs are about to wrap around for any of the SgNB terminated DRBs or SgNB terminated SRB.
[0192] If the MeNB / MgNB re-keys its currently active KeNBin an AS security context, the MeNB / MgNB may update any S-KgNBassociated with that AS security context. This retains the two-hop security property for X2-handovers.
[0193] If the MeNB / MgNB receives a request for S-KgNBupdate from the SgNB or decides on its own to perform S-KgNBupdate, the MeNB / MgNB may compute a fresh S-KgNBand increment the SCG counter. Thenthe MeNB / MgNB may performa SgNB modification procedure to deliver the fresh S-KgNBto the SgNB. The MeNB / MgNB may provide the value of the SCG counter used in the derivation of the S-KgNBto the UE in an integrity protected RRC procedure. The UE may derive the S-KgNB.
[0194] Whenever the UE or SgNB start using a fresh S-KgNB, they may re-calculate KSgNB-UP-int, KSgNB-UP-enc, KSgNB-RRC-intand KSgNB-RRC-encfrom the fresh S-KgNB.
[0195] Scenarios considered in LTM have been limited to intra-CU case only, i.e., serving cell change within cells under a single CU. For NR mobility enhancement, support for inter-CU LTM has been studied. Specifically, it has been studied to support for subsequent LTM mobility procedures aiming to avoid RRC configuration between cell switches as per current LTM mechanism. In other words, inter-CU mobility should support initial and subsequent serving cell changes based on a single mobility configuration (i.e., no RRC reconfiguration between cell switches).
[0196] In subsequent mobility supported by inter-CU LTM, any cell among candidate cells may become the new source cell. Inter-CU LTM may require security update based on pre-configuration whenever changing CU. However, it may be impossible for the network to provide security configuration in the reference configuration or the candidate cell configuration. This is because the source gNB key may be required for new gNB key derivation and avoiding security updates to the same cell with the same security key according to the current UE security requirements.
[0197] For Subsequent Conditional PSCell Addition / Change (SCPAC), similar security handling problem has been discussed for inter-SN SCPAC. To address the problem, it has been agreed that the UE may receive one or more lists of multiple sk-counter values necessary for security update and each list may be configured per-node (i.e., per CU). That is, during subsequent inter-SN mobility (e.g., inter-SN SCPAC), the UE may select one sk-counter value from the multiple sk-counter values in the list corresponding to the node and perform the security update accordingly.
[0198] Accordingly, it may be discussed whether the UE can perform security update procedure in the inter-CU LTM by applying the similar principle of the multiple sk-counter values used in inter-SN SCPAC.
[0199] A cell switch command for inter-CU LTM (e.g., LTM cell switch command MAC CE) may contain information for security update. This is because if the MAC CE does not contain information for security update, RRC reconfiguration may be required for each inter-CU LTM cell switch which causes interruption.
[0200] For example, new information included in the LTM cell switch command MAC CE may be used to deliver the security information. Whether the UE uses horizontal derivation or vertical derivation may be determined based on this new information included in the LTM cell switch command MAC CE (which is currently, neither integrity protected nor ciphered). For example, an NCC value to be used at inter-CU LTM execution may be included as the new information for security update in the LTM cell switch command MAC CE. For example, the UE may be preconfigured with a list of NCC values in a ciphered and integrity protected RRC message, and the index of an NCC value in the list may be included as the new information for security update in the LTM cell switch command MAC CE.
[0201] Meanwhile, LTM cell switch command MAC CE is generated by the DU that the serving cell belongs to (e.g., serving DU), while security information is generated by the serving CU. However, currently, there is no signaling between the serving CU and the serving DU to transfer security information from the serving CU to the serving DU. Consequently, there is no way for the serving DU to include the security information into the LTM cell switch command MAC CE.
[0202] According to implementations of the present disclosure, the serving CU and the serving DU may exchange security information in order for the serving DU to include the security information into the cell switch command (e.g., LTM cell switch command MAC CE). The serving DU may request the security information of one or more candidate cells if the candidate cells belong to another CU (e.g., CU different from the serving CU). The serving CU may transmit the security information of participating CUs in advance (e.g., prior to the cell switch) to the serving DU. The serving DU may include the security information of a candidate target cell into the cell switch command if the candidate target cell belongs to another CU, or as requested by the serving CU. That is, the serving DU may include the security information of a candidate target cell into the cell switch command in case of inter-CU LTM. the serving DU may not include the security information of a candidate target cell into the cell switch command in case of intra-CU LTM.
[0203] According to implementations of the present disclosure, when the UE receives a cell switch command, which is not encrypted, for cell switch from a source cell to a target cell in LTM, the UE may check if security information is included in the cell switch command. The security information may include a security key that the UE applies upon cell switch. The security information may include an indicator (e.g., index) indicating a security key included in a list of security keys in the pre-configuration for cell switch. The security information may include a number used for deriving the security key for cell switch, where a function / equation for deriving a security key based on the number can be configured for the UE. Based on the security information, the UE may determine how the UE updates security for data transmission between the UE and the target cell.
[0204] When the security information includes a security key that the UE applies upon cell switch, if the UE receives the security key in the cell switch command, the UE may update security based on the security key included in the cell switch command. Otherwise, if the UE does not receive the security key in the cell switch command, the UE may regard the source gNB key is the security key for the security update and update security using the source gNB key.
[0205] When the security information includes an indicator (e.g., index) indicating a security key included in a list of security keys in the pre-configuration for cell switch, if the UE receives the index value in the cell switch command, the UE may select a security key corresponding to the index value among the security key list, which has been configured before the reception of the cell switch command. Upon selection of the security key, the UE may update security using the selected security key. Otherwise, if the UE does not receive the index value in the cell switch command, the UE may regard the source gNB key is the security key for the security update and update security using the source gNB key.
[0206] When the security information includes a number used for deriving the security key for cell switch, where a function / equation for deriving a security key based on the number can be configured for the UE, if the UE receives the number for security key derivation in the cell switch command, the UE may derive the security key based on the preconfigured equation / function and the number. Upon deriving the security key, the UE may update security using the derived security key. Otherwise, if the UE does not receive the number for deriving security key in the cell switch command, the UE may regard the source gNB key is the security key for the security update and update security using the source gNB key.
[0207] After the security update, the UE may send a complete message, which is encrypted by the updated security, to the target cell.
[0208] According to implementations of the present disclosure, before reception of the cell switch command, the UE may receive a pre-configuration for a cell switch in LTM. The pre-configuration may include at least one of the followings.
[0209] - Reference configuration: cell configuration used commonly for all candidate cells when performing cell switch;
[0210] - Candidate cell configuration: cell configuration dedicated to a corresponding candidate cell when performing cell switch;
[0211] - Security key lists: one or more lists for each node used for security update when performing cell switch. Each list may consist of one or more security keys for the corresponding node. Each security key may include at least one of a gNB key (e.g., KgNB) or an input parameter for security key derivation, such as NCC value or sk-counter (SCG counter) value. For discriminating the security key lists, each security key list may contain a group identity. The security key list may contain the same security key multiple times, e.g., {1,2,4,0,5,1,0,7,4,3,1,2,5,5,3,4,5,6}.
[0212] - Equation / function for deriving security key: the security key value (e.g., NCC) may be derived by substituting an arbitrary number into the equation. For example, if the equation is f(x) = x mod 8, then the security key value may be derived between 0 and 7 with any integer x.
[0213] - Current group identity for the source cell: to discriminate whether upcoming cell switch is for inter-node mobility (e.g., inter-CU LTM) or not (e.g., intra-CU LTM). The UE may update this current group identity after each cell switch is successfully complete.
[0214] According to implementations of the present disclosure, for MN mobility (i.e., the UE performs handover for PCell change and reconfiguration with sync is included in RRC reconfiguration message for MCG), the UE may receive one or more NCC values as the multiple security keys in the pre-configuration. Then, when initiating the cell switch, the UE may determine if horizontal derivation or vertical derivation is used for a target gNB key derivation based on whether the cell switch command includes the security information or not.
[0215] If the UE receives the security information in the cell switch command for MN mobility, the UE may select an NCC value associated with the security information from among the one or more NCC values in the pre-configuration and the UE may perform security update based on vertical derivation using the selected NCC value to derive new gNB key for the target cell. If the selected NCC value is lower than the previously selected NCC value or the same as the previously selected NCC value, which was used for the current gNB key of the source cell, the UE may perform security update based on horizontal derivation using the current gNB key of the source cell to derive new gNB key for the target cell.
[0216] Else if the UE doe not receive the security information in the cell switch command for MN mobility, the UE may perform security update based on horizontal derivation using the current gNB key of the source cell to derive a new gNB key for the target cell.
[0217] According to implementations of the present disclosure, for SN mobility (i.e., the UE performs handover for PSCell change and reconfiguration with sync is included in RRC reconfiguration message for SCG), the UE may receive one or more sk-counter values as the multiple security keys in the pre-configuration. Then, when initiating the cell switch, the UE may determine whether to perform security update for SCG based on whether the cell switch command includes the security information or not.
[0218] If the UE receives the security information in the cell switch command for the SN mobility, the UE may select a sk-counter value associated with the security information from among one or more sk-counter values in the pre-configuration and the UE may perform SgNB key derivation using the selected sk-counter and the current MgNB key.
[0219] Else if the UE does not receive the security information in the cell switch command for the SN mobility, the UE may consider that the security update is not needed for the cell switch.
[0220] According to implementations of the present disclosure, the UE may further check if the cell switch is for inter-node mobility (e.g., inter-CU LTM) or intra-node mobility (e.g., intra-CU LTM). To determine whether the cell switch is for inter-node mobility or not, the UE may compare the current group identity of the source cell with the group identity of the target cell which may be provided in the pre-configuration. Based on the checking, if the cell switch is for inter-node mobility, the UE may decide to the security update based on presence of the security information in the cell switch command, as mentioned above. Otherwise, if the cell switch is for intra-node mobility, the UE may skip the security update even though the security information is included in the cell switch command.
[0221] The following drawings are created to explain specific embodiments of the present disclosure. The names of the specific devices or the names of the specific signals / messages / fields shown in the drawings are provided by way of example, and thus the technical features of the present disclosure are not limited to the specific names used in the following drawings.
[0222] An embodiment of the present disclosure related to a specific drawing described below may be combined with various embodiments of the present disclosure related to other drawings, and some descriptions, functions, procedures, proposals, methods and / or operations of the embodiment may be omitted.
[0223] FIG. 12 shows an example of a method to which implementations of the present disclosure are applied.
[0224] In step S1200, the method comprises transmitting a configuration related to one or more candidate cells for subsequent mobility to a wireless device.
[0225] In step S1210, the method comprises receiving a measurement report of a candidate cell from the wireless device.
[0226] In step S1220, the method comprises receiving security information related to the candidate cell from a serving CU. The security information is for security update upon cell switch.
[0227] In step S1230, the method comprises transmitting a cell switch command for the cell switch from the serving cell to the candidate cell, to the wireless device. The cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.
[0228] In some implementations, the security information may include an NCC value. Additionally and / or alternatively, the security information may include an index value for the security update.
[0229] In some implementations, the method may further comprise transmitting a request for the security information to the serving CU.
[0230] In some implementations, whether the candidate cell belongs to the CU different from the serving CU may be determined based on a group identity. For example, it may be determined that whether the candidate cell belongs to the CU different from the serving CU based on a current group identity for the serving cell being different from a group identity for the candidate cell.
[0231] In some implementations, the subsequent mobility may relate to LTM.
[0232] In some implementations, the configuration may include at least one of a reference configuration, one or more candidate cell configurations for the one or more candidate cells, one or more security key lists, an equation or function for deriving a security key or a current group identity for the serving cell.
[0233] In some implementations, the method may be performed by a serving DU. The serving CU and the serving DU may belong to a serving base station.
[0234] Furthermore, the method described above in FIG. 12 may be performed by a serving DU in a base station. The serving DU in the base station may be implemented by the second wireless device 200 shown in FIG. 2.
[0235] The serving DU in the base station comprises at least one transceiver, at least one processor, and at least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method described in FIG. 12.
[0236] More specifically, the serving DU transmits, via the at least one transceiver, a configuration related to one or more candidate cells for subsequent mobility to a wireless device.
[0237] The serving DU receives, via the at least one transceiver, a measurement report of a candidate cell from the wireless device.
[0238] The serving DU receives, via the at least one transceiver, security information related to the candidate cell from a serving CU. The security information is for security update upon cell switch.
[0239] The serving DU transmits, via the at least one transceiver, a cell switch command for the cell switch from the serving cell to the candidate cell, to the wireless device. The cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.
[0240] In some implementations, the security information may include an NCC value. Additionally and / or alternatively, the security information may include an index value for the security update.
[0241] In some implementations, the serving DU may transmit a request for the security information to the serving CU.
[0242] In some implementations, whether the candidate cell belongs to the CU different from the serving CU may be determined based on a group identity. For example, it may be determined that whether the candidate cell belongs to the CU different from the serving CU based on a current group identity for the serving cell being different from a group identity for the candidate cell.
[0243] In some implementations, the subsequent mobility may relate to LTM.
[0244] In some implementations, the configuration may include at least one of a reference configuration, one or more candidate cell configurations for the one or more candidate cells, one or more security key lists, an equation or function for deriving a security key or a current group identity for the serving cell.
[0245] FIG. 13 shows an example of another method to which implementations of the present disclosure are applied.
[0246] In step S1300, the method comprises receiving a configuration related to one or more candidate cells for subsequent mobility from a serving DU.
[0247] In step S1310, the method comprises transmitting a measurement report of a candidate cell to the serving DU.
[0248] In step S1320, the method comprises receiving a cell switch command for cell switch from a serving cell to the candidate cell, from the serving DU. Security information related to the candidate cell is delivered from a serving CU to the serving DU. The cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.
[0249] In some implementations, the method may be performed by a wireless device in communication with at least one of a mobile device, a network, and / or autonomous vehicles other than the wireless device.
[0250] Furthermore, the method described above in FIG. 13 may be performed by a wireless device. The wireless device may be implemented by the first wireless device 100 shown in FIG. 2 and / or the UE 100 shown in FIG. 3.
[0251] The wireless device comprises at least one transceiver, at least one processor, and at least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method described in FIG. 13.
[0252] More specifically, the wireless device receives, via the at least one transceiver, a configuration related to one or more candidate cells for subsequent mobility from a serving DU.
[0253] The wireless device transmits, via the at least one transceiver, a measurement report of a candidate cell to the serving DU.
[0254] The wireless device receives, via the at least one transceiver, a cell switch command for cell switch from a serving cell to the candidate cell, from the serving DU. Security information related to the candidate cell is delivered from a serving CU to the serving DU. The cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.
[0255] Furthermore, the method described above in FIG. 13 may be performed by control of a processing apparatus adapted to control a wireless device. The processing apparatus may be implemented by the processor 102 included in the first wireless device 100 shown in FIG. 2 and / or the processor 102 included in the UE 100 shown in FIG. 3.
[0256] The processing apparatus adapted to control the wireless device comprises at least one processor, and at least one memory operably connectable to the at least one processor. The at least one processor is adapted to perform the method described in FIG. 13.
[0257] Furthermore, the method described above in FIG. 13 may be performed by a software code 105 stored in the memory 104 included in the first wireless device 100 shown in FIG. 2.
[0258] The technical features of the present disclosure may be embodied directly in hardware, in a software executed by a processor, or in a combination of the two. For example, a method performed by a wireless device in a wireless communication may be implemented in hardware, software, firmware, or any combination thereof. For example, a software may reside in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, a removable disk, a CD-ROM, or any other storage medium.
[0259] Some example of storage medium may be coupled to the processor such that the processor can read information from the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. For other example, the processor and the storage medium may reside as discrete components.
[0260] The computer-readable medium may include a tangible and non-transitory computer-readable storage medium.
[0261] For example, non-transitory computer-readable media may include RAM such as Synchronous DRAM (SDRAM), ROM, Non-Volatile RAM (NVRAM), EEPROM, flash memory, magnetic or optical data storage media, or any other medium that can be used to store instructions or data structures. Non-transitory computer-readable media may also include combinations of the above.
[0262] In addition, the method described herein may be realized at least in part by a computer-readable communication medium that carries or communicates code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer.
[0263] According to some implementations of the present disclosure, a non-transitory Computer-Readable Medium (CRM) stores instructions that, based on being executed by at least one processor, perform the method described in FIG. 13.
[0264] Regarding transfer of security information from the CU to the DU describe above, transferring the security information (e.g., NCC value) from the CU to the DU may not occur during the initial preparation phase, as the NCC value required for initial execution is already included in the initial RRC reconfiguration configuring LTM to the UE. The UE is already configured with the correct NCC value to use for initial execution.
[0265] After the first inter-CU LTM execution, the new serving CU may receive a new {NH, NCC} pair from the AMF during path switch. The serving CU then may transfer the new NCC value to the serving DU, so that DU can deliver it to the UE via MAC CE for subsequent LTM. At this stage, the UE context has already been established in the serving DU, and the NCC value needs to be stored within this UE context until it is delivered to the UE.
[0266] Therefore, the UE Context Modification Request message may be used to transfer the security information from the serving CU to the serving DU. The UE Context Modification Request message is initiated by the gNB-CU. If theLTM Security InformationIE is included in the UE Context Modification Request message, the gNB-DU shall, if supported, store it and take it into account for supporting the UE's AS security continuation during an inter-CU LTM cell switch.
[0267] Table 5 shows an example of theLTM Security InformationIE. TheLTM Security InformationIE contains the security related information for LTM candidate cell(s) to support the UE in generating the key material for AS security during an inter-CU LTM cell switch.
[0268] IE / Group NamePresenceRangeIE type and referenceSemantics descriptionNext Hop Chaining CountMINTEGER (0..7)Next Hop Chaining Count (NCC)
[0269] Various examples according to implementations of the present disclosure are described below. In the example described below, some steps may be omitted and / or order of steps may change.
[0270] 1. Example 1: transferring security information for inter-CU LTM
[0271] FIG. 14 shows an example of transferring security information for inter-CU LTM to which implementations of the present disclosure are applied.
[0272] In step S1400, cell 0 (i.e., current serving cell) may configure the UE with LTM. Cell 0 belongs to DU#0 and correspondingly CU#0. CU#0 may transmit an LTM configuration to the UE. Cell 1 may be configured as LTM candidate cell in the LTM configuration. Cell 1 belongs to DU#1 and correspondingly CU#1.
[0273] In step S1410, DU#0 may receive the L1 measurement report of cell #1 from the UE.
[0274] In step S1420, CU#0 may transmit to DU#0 the security information for security key update for the cell switch from cell 0 to cell 1.
[0275] Step S1410 and S1420 may be performed with different order (e.g., step S1420 is performed first, and then step S1410 is performed).
[0276] Before step S1420, DU#0 may request to CU#0 the security information for security key update for the cell switch from cell 0 to cell 1 (i.e. CU#0 to CU#1). CU#0 may transmit to DU#0 the security information for security key update in step S1420, in response to the request.
[0277] In step S1430, DU#0 may generate the LTM cell switch command indicating the cell switch toward cell #1. The LTM cell switch command may include the security information based on the cell switch from cell 0 to cell 1 (i.e., inter-CU LTM). DU#0 may send the LTM cell switch command to the UE.
[0278] In step S1440, the UE performs LTM cell switch towards cell 1 with DU#1.
[0279] 2. Example 2: Security update in subsequent inter MN LTM, in case that the security information is a security key that the UE applies upon cell switch
[0280] (0) Preparation for LTM
[0281] - Step 1: The UE may receive an LTM configuration from cell 0. Cell 0 may configure three candidate cell configurations for LTM candidate cells (e.g., cell 1, cell 2, and cell 3). The LTM configuration may include L1 measurement configuration for beams related to each of LTM candidate cells and / or candidate cell configurations for each of LTM candidate cells.
[0282] - Step 2: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and report the L1 measurement results to the network.
[0283] (2) Mobility from cell 0 to cell 1
[0284] - Step 3: The UE may receive LTM cell switch command for mobility from cell 0 to cell 1 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 1 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes a security key for security update. It is assumed that a security key 2 is included in the LTM cell switch command.
[0285] - Step 4: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 0 and cell 1. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 1.
[0286] - Step 5: The UE may update security information based on the security key 2. For example, the UE selects an NCC value 2 for security update. After selection of the NCC value 2, the UE may perform vertical derivation using the selected NCC value 2 to derive new gNB key for cell 1.
[0287] - Step 6: After the vertical derivation, the UE may perform security update for cell 1 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 1.
[0288] - Step 7: The UE may succeed to access cell 1. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 1.
[0289] - Step 8: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0290] (2) Mobility from cell 1 to cell 3
[0291] - Step 9: The UE may receive LTM cell switch command for mobility from cell 1 to cell 3 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 3 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes a security key for security update. It is assumed that a security key 6 is included in the LTM cell switch command.
[0292] - Step 10: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 1 and cell 3. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 3.
[0293] - Step 11: The UE may update security information based on the security key 6. For example, the UE selects an NCC value 6 for security update. After selection of the NCC value 6, the UE may perform vertical derivation using the selected NCC value 6 to derive new gNB key for cell 3.
[0294] - Step 12: After the vertical derivation, the UE may perform security update for cell 3 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 3.
[0295] - Step 13: The UE may succeed to access cell 3. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 3.
[0296] - Step 14: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0297] 3. Example 3: Security update in subsequent inter MN LTM, in case that the security information is an indicator (e.g., index) indicating a security key included in a list of security keys in the pre-configuration for cell switch
[0298] (0) Preparation for LTM
[0299] - Step 1: The UE may receive an LTM configuration from cell 0. Cell 0 may configure three candidate cell configurations for LTM candidate cells (e.g., cell 1, cell 2, and cell 3). The LTM configuration may include L1 measurement configuration for beams related to each of LTM candidate cells and / or candidate cell configurations for each of LTM candidate cells.
[0300] In addition, the LTM configuration may include multiple lists of security keys (e.g., a first list for cell 1, a second list for cell 2, a third list for cell 3) for security update when performing the subsequent LTM. Each list may include one or more security keys which may be an NCC value, and group identity. For example, the first list for cell 1 may include NCC value {2, 3, 4} and group identity 1, the second list for cell 2 may include NCC value {3, 4, 5} and group identity 2, and the third list for cell 3 may include NCC value {5, 6, 7} and group identity 3. The LTM configuration may also include group identity 0 for the current cell 0.
[0301] - Step 2: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and report the L1 measurement results to the network.
[0302] (2) Mobility from cell 0 to cell 1
[0303] - Step 3: The UE may receive LTM cell switch command for mobility from cell 0 to cell 1 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 1 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes security information (e.g., an index value) for security update. It is assumed that an index value of 2 is included in the LTM cell switch command.
[0304] - Step 4: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 0 and cell 1. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 1.
[0305] - Step 5: The UE may update security information based on the index value of 2. For example, the UE selects the second NCC value in the first list for cell 1 (i.e., NCC value 3) for security update. After selection of the NCC value 3, the UE may perform vertical derivation using the selected NCC value 3 to derive new gNB key for cell 1.
[0306] - Step 6: After the vertical derivation, the UE may perform security update for cell 1 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 1.
[0307] - Step 7: The UE may succeed to access cell 1. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 1.
[0308] - Step 8: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0309] (2) Mobility from cell 1 to cell 3
[0310] - Step 9: The UE may receive LTM cell switch command for mobility from cell 1 to cell 3 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 3 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes security information (e.g., an index value) for security update. It is assumed that an index value of 2 is included in the LTM cell switch command.
[0311] - Step 10: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 1 and cell 3. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 3.
[0312] - Step 11: The UE may update security information based on the index value of 2. For example, the UE selects the second NCC value in the third list for cell 3 (i.e., NCC value 6) for security update. After selection of the NCC value 3, the UE may perform vertical derivation using the selected NCC value 6 to derive new gNB key for cell 1.
[0313] - Step 12: After the vertical derivation, the UE may perform security update for cell 3 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 3.
[0314] - Step 13: The UE may succeed to access cell 3. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 3.
[0315] - Step 14: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0316] (3) Mobility from cell 3 to cell 1
[0317] - Step 15: The UE may receive LTM cell switch command for mobility from cell 3 to cell 1 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 1 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes security information (e.g., an index value) for security update. It is assumed that an index value of 2 is included in the LTM cell switch command.
[0318] - Step 16: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 3 and cell 1. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 1.
[0319] - Step 17: However, the UE may decide not to perform the vertical derivation because, based on the index value of 2, the selected NCC value (i.e., NCC value 2) is same as the previous selected NCC value for cell 1. Instead, the UE may decide to perform horizontal derivation based on the current gNB key for cell 3.
[0320] - Step 18: After the horizontal derivation, the UE may perform security update for cell 1 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 1.
[0321] - Step 19: The UE may succeed to access cell 1. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 1.
[0322] - Step 20: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0323] (4) Mobility from cell 1 to cell 2
[0324] - Step 21: The UE may receive LTM cell switch command for mobility from cell 1 to cell 2 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 2 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes security information (e.g., an index value) for security update. It is assumed that there is no index value information in the LTM cell switch command.
[0325] - Step 22: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 1 and cell 2. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 2.
[0326] - Step 23: However, the UE may decide not to perform the vertical derivation because there is no index value information in the LTM cell switch command. Instead, the UE may decide to perform horizontal derivation based on the current gNB key for cell 1.
[0327] - Step 24: After the horizontal derivation, the UE may perform security update for cell 2 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 2.
[0328] - Step 25: The UE may succeed to access cell 2. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 2.
[0329] - Step 26: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0330] 4. Example 4: Security update in subsequent inter MN LTM, in case that the security information is a number used for deriving the security key for cell switch
[0331] (0) Preparation for LTM
[0332] - Step 1: The UE may receive an LTM configuration from cell 0. Cell 0 may configure three candidate cell configurations for LTM candidate cells (e.g., cell 1, cell 2, and cell 3). The LTM configuration may include L1 measurement configuration for beams related to each of LTM candidate cells and / or candidate cell configurations for each of LTM candidate cells.
[0333] In addition, the LTM configuration may include parameters of equation or function for deriving security key, e.g., 8 as modular basis.
[0334] - Step 2: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and report the L1 measurement results to the network.
[0335] (2) Mobility from cell 0 to cell 1
[0336] - Step 3: The UE may receive LTM cell switch command for mobility from cell 0 to cell 1 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 1 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes a number for deriving security key for security update. It is assumed that 'number: 2234' is included in the LTM switch command.
[0337] - Step 4: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 0 and cell 1. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 1.
[0338] - Step 5: The UE may update security information based on the 'number: 2234'. For example, the UE selects an NCC value 2 by '2234 mod 8 = 2' for security update. After selection of the NCC value 2, the UE may perform vertical derivation using the selected NCC value 2 to derive new gNB key for cell 1.
[0339] - Step 6: After the vertical derivation, the UE may perform security update for cell 1 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 1.
[0340] - Step 7: The UE may succeed to access cell 1. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 1.
[0341] - Step 8: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0342] (2) Mobility from cell 1 to cell 3
[0343] - Step 9: The UE may receive LTM cell switch command for mobility from cell 1 to cell 3 via lower layer signaling, which is not encrypted. The UE may apply a corresponding cell configuration for cell 3 (e.g., RRC Reconfiguration message) and try to access with synchronization. The UE may also check if the LTM cell switch command includes a security key for security update. It is assumed that 'number: 806' is included in the LTM switch command.
[0344] - Step 10: The UE may check if the LTM cell switch command is for inter-node mobility by comparing group identities for cell 1 and cell 3. After checking, the UE may confirm that the LTM cell switch command is for the inter-node mobility and decide to perform the security update for cell 3.
[0345] - Step 5: The UE may update security information based on the 'number: 806'. For example, the UE selects an NCC value 2 by '806 mod 8 = 6' for security update. After selection of the NCC value 6, the UE may perform vertical derivation using the selected NCC value 6 to derive new gNB key for cell 3.
[0346] - Step 12: After the vertical derivation, the UE may perform security update for cell 3 with the new gNB key. And, the UE may send LTM cell switch complete message (e.g., RRC Reconfiguration complete message), which encrypted by the new gNB key, to cell 3.
[0347] - Step 13: The UE may succeed to access cell 3. The UE may be successfully completed to send the complete message. The UE may update the group identity for the current cell as 3.
[0348] - Step 14: The UE may perform L1 measurement based on the received L1 measurement configuration for each candidate cell and reports the L1 measurement results to the network.
[0349] The present disclosure may have various advantageous effects.
[0350] For example, by transferring security information from the CU to the DU, subsequent inter-CU LTM can be performed without RRC reconfiguration. As a result, mobility interruptions can be reduced.
[0351] Advantageous effects which can be obtained through specific embodiments of the present disclosure are not limited to the advantageous effects listed above. For example, there may be a variety of technical effects that a person having ordinary skill in the related art can understand and / or derive from the present disclosure. Accordingly, the specific effects of the present disclosure are not limited to those explicitly described herein, but may include various effects that may be understood or derived from the technical features of the present disclosure.
[0352] Claims in the present disclosure can be combined in a various way. For instance, technical features in method claims of the present disclosure can be combined to be implemented or performed in an apparatus, and technical features in apparatus claims can be combined to be implemented or performed in a method. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in an apparatus. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in a method. Other implementations are within the scope of the following claims.
Claims
1.A method comprising:transmitting a configuration related to one or more candidate cells for subsequent mobility to a wireless device;receiving a measurement report of a candidate cell from the wireless device;receiving security information related to the candidate cell from a serving centralized unit (CU),wherein the security information is for security update upon cell switch; andtransmitting a cell switch command for the cell switch from the serving cell to the candidate cell, to the wireless device,wherein the cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.2.The method of claim 1, wherein the security information includes a Next hop Chaining Counter (NCC) value.3.The method of claim 1 or 2, wherein the security information includes an index value for the security update.4.The method of any claims 1 to 3, wherein the method further comprises transmitting a request for the security information to the serving CU.5.The method of any claims 1 to 4, wherein whether the candidate cell belongs to the CU different from the serving CU is determined based on a group identity.6.The method of claim 5, wherein it is determined that whether the candidate cell belongs to the CU different from the serving CU based on a current group identity for the serving cell being different from a group identity for the candidate cell.7.The method of any claims 1 to 6, wherein the subsequent mobility relates to a L1 / L2 Triggered Mobility (LTM).8.The method of any claims 1 to 7, wherein the configuration includes at least one of a reference configuration, one or more candidate cell configurations for the one or more candidate cells, one or more security key lists, an equation or function for deriving a security key or a current group identity for the serving cell.9.The method of any claims 1 to 8, wherein the method is performed by a serving distributed unit (DU).10.The method of claim 9, wherein the serving CU and the serving DU belongs to a serving base station.11.A serving distributed unit (DU) comprising:at least one transceiver;at least one processor; andat least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method of claims 1 to 10.12.A method comprising:receiving a configuration related to one or more candidate cells for subsequent mobility from a serving distributed unit (DU);transmitting a measurement report of a candidate cell to the serving DU; andreceiving a cell switch command for cell switch from a serving cell to the candidate cell, from the serving DU,wherein security information related to the candidate cell is delivered from a serving centralized unit (CU) to the serving DU, andwherein the cell switch command includes the security information related to the candidate cell based on the candidate cell belonging to a CU different from the serving CU.13.The method of claim 12, wherein the method is performed by a wireless device in communication with at least one of a mobile device, a network, and / or autonomous vehicles other than the wireless device.14.A wireless device comprising:at least one transceiver;at least one processor; andat least one memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform the method of any claims 12 to 13.15.A processing apparatus adapted to control a wireless device comprising:at least one processor; andat least one memory operably connectable to the at least one processor,wherein the at least one processor is adapted to perform the method of any claims 12 to 13.16.A non-transitory Computer Readable Medium (CRM) storing instructions that, based on being executed by at least one processor, perform the method of any claims 12 to 13.
Citation Information
Patent Citations
Security handling for subsequent mobility
WO2024071878A1
Cited By
Inapplicable configuration handling in wireless communications
US20260173085A1