Security information reporting

The method of security information reporting through conditional reconfigurations and key updates in wireless communication systems addresses key management challenges, enhancing security and reducing RRC connection failures.

WO2026010434A1PCT designated stage Publication Date: 2026-01-08LG ELECTRONICS INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/009625
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-05
Filing Date
2025-07-04
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Existing security mechanisms in wireless communication systems, such as 3GPP LTE and NR, face challenges in optimizing security key updates during mobility, leading to potential RRC connection failures due to security key mismatches.

Method used

A method and apparatus for security information reporting in wireless communication systems, involving conditional reconfigurations and security key updates, where a user equipment (UE) and network node exchange lists of configured security keys and perform key updates based on fulfillment of execution conditions, enabling optimized security key management during mobility.

Benefits of technology

Prevents security key mismatch issues, thereby reducing the likelihood of RRC connection failures by ensuring timely and optimized security key updates during mobility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025009625_08012026_PF_FP_ABST
    Figure KR2025009625_08012026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure is related to security information reporting in wireless communications. According to an embodiment of the present disclosure, a method performed by a user equipment (UE) configured to operate in a wireless communication system comprises: receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys; initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and transmitting security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.
Need to check novelty before this filing date? Find Prior Art

Description

SECURITY INFORMATION REPORTING

[0001] The present disclosure is related to security information reporting in wireless communications.

[0002] 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a technology for enabling high-speed packet communications. Many schemes have been proposed for the LTE objective including those that aim to reduce user and provider costs, improve service quality, and expand and improve coverage and system capacity. The 3GPP LTE requires reduced cost per bit, increased service availability, flexible use of a frequency band, a simple structure, an open interface, and adequate power consumption of a terminal as an upper-level requirement.

[0003] Work has started in International Telecommunication Union (ITU) and 3GPP to develop requirements and specifications for New Radio (NR) systems. 3GPP has to identify and develop the technology components needed for successfully standardizing the new RAT timely satisfying both the urgent market needs, and the more long-term requirements set forth by the ITU Radio communication sector (ITU-R) International Mobile Telecommunications (IMT)-2020 process. Further, the NR should be able to use any spectrum band ranging at least up to 100 GHz that may be made available for wireless communications even in a more distant future.

[0004] The NR targets a single technical framework addressing all usage scenarios, requirements and deployment scenarios including enhanced Mobile BroadBand (eMBB), massive Machine Type Communications (mMTC), Ultra-Reliable and Low Latency Communications (URLLC), etc. The NR shall be inherently forward compatible.

[0005] In communication systems, a security architecture is defined to protect user data and signaling messages exchanged between a User Equipment (UE) and a network. This security framework includes two primary layers: the Non-Access Stratum (NAS) layer and the Access Stratum (AS) layer. The AS security, which is applied to messages exchanged between the UE and the radio access network (RAN), is established after successful authentication and key agreement procedures.

[0006] AS security involves the derivation and application of encryption and integrity protection keys. Upon the completion of the NAS security setup, the network initiates the AS security setup by deriving AS-specific keys (KeNB or KgNB) from the master key (KASME or KAMF) through a key derivation function (KDF). These keys are then used to derive ciphering and integrity keys (e.g., KRRCenc, KRRCint, KUPenc) which are applied to the Radio Resource Control (RRC) messages and user plane data.

[0007] AS security provides both confidentiality and integrity protection for signaling messages and, optionally, for user plane data. The activation and configuration of AS security are typically handled during the RRC connection setup or reconfiguration procedures. Security algorithms for encryption and integrity are negotiated between the UE and the network and are based on capabilities and operator policies.

[0008] While AS security mechanisms provide essential protections, several issues remain to be addressed.

[0009] An aspect of the present disclosure is to provide method and apparatus for security information reporting in a wireless communication system.

[0010] According to an embodiment of the present disclosure, a method performed by a user equipment (UE) configured to operate in a wireless communication system comprises: receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys; initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and transmitting security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0011] According to an embodiment of the present disclosure, a method performed by a network node configured to operate in a wireless communication system comprises: transmitting, to a user equipment (UE), a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys, wherein the UE is configured to perform operations comprising: initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; and performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and receiving, from the UE, security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0012] According to various embodiments, apparatuses to implement the above methods are provided.

[0013] The present disclosure may have various advantageous effects.

[0014] For example, by logging security information related to security key usage whenever performing subsequent mobility, the UE and the network can optimize the security information / configuration of the subsequent mobility and the update timing of the security information / configuration so that further security key mismatch problems which can cause RRC connection failure can be prevented.

[0015] Advantageous effects which can be obtained through specific embodiments of the present disclosure are not limited to the advantageous effects listed above. For example, there may be a variety of technical effects that a person having ordinary skill in the related art can understand and / or derive from the present disclosure. Accordingly, the specific effects of the present disclosure are not limited to those explicitly described herein, but may include various effects that may be understood or derived from the technical features of the present disclosure.

[0016] FIG. 1 shows an example of a communication system to which implementations of the present disclosure is applied.

[0017] FIG. 2 shows an example of wireless devices to which implementations of the present disclosure is applied.

[0018] FIG. 3 shows an example of UE to which implementations of the present disclosure is applied.

[0019] FIGs. 4 and 5 show an example of protocol stacks in a 3GPP based wireless communication system to which implementations of the present disclosure is applied.

[0020] FIG. 6 shows a frame structure in a 3GPP based wireless communication system to which implementations of the present disclosure is applied.

[0021] FIG. 7 shows a data flow example in the 3GPP NR system to which implementations of the present disclosure is applied.

[0022] FIG. 8 shows an example of a conditional mobility procedure according to an embodiment of the present disclosure.

[0023] FIG. 9 shows an example of a method performed by a UE for security information reporting according to an embodiment of the present disclosure.

[0024] FIG. 10 shows an example of a signal flow between UE and network for security information reporting according to an embodiment of the present disclosure.

[0025] FIG. 11 shows an example of a method for logging security information when a subsequent mobility succeeds according to an embodiment of the present disclosure.

[0026] FIG. 12 shows an example of a method for logging security information when a subsequent mobility fails according to an embodiment of the present disclosure.

[0027] The following techniques, apparatuses, and systems may be applied to a variety of wireless multiple access systems. Examples of the multiple access systems include a Code Division Multiple Access (CDMA) system, a Frequency Division Multiple Access (FDMA) system, a Time Division Multiple Access (TDMA) system, an Orthogonal Frequency Division Multiple Access (OFDMA) system, a Single Carrier Frequency Division Multiple Access (SC-FDMA) system, and a Multi Carrier Frequency Division Multiple Access (MC-FDMA) system. CDMA may be embodied through radio technology such as Universal Terrestrial Radio Access (UTRA) or CDMA2000. TDMA may be embodied through radio technology such as Global System for Mobile communications (GSM), General Packet Radio Service (GPRS), or Enhanced Data rates for GSM Evolution (EDGE). OFDMA may be embodied through radio technology such as Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, or Evolved UTRA (E-UTRA). UTRA is a part of a Universal Mobile Telecommunications System (UMTS). 3rd Generation Partnership Project (3GPP) Long-Term Evolution (LTE) is a part of Evolved UMTS (E-UMTS) using E-UTRA. 3GPP LTE employs OFDMA in downlink (DL) and SC-FDMA in uplink (UL). Evolution of 3GPP LTE includes LTE-Advanced (LTE-A), LTE-A Pro, and / or 5G New Radio (NR).

[0028] For convenience of description, implementations of the present disclosure are mainly described in regards to a 3GPP based wireless communication system. However, the technical features of the present disclosure are not limited thereto. For example, although the following detailed description is given based on a mobile communication system corresponding to a 3GPP based wireless communication system, aspects of the present disclosure that are not limited to 3GPP based wireless communication system are applicable to other mobile communication systems.

[0029] For terms and technologies which are not specifically described among the terms of and technologies employed in the present disclosure, the wireless communication standard documents published before the present disclosure may be referenced.

[0030] In the present disclosure, "A or B" may mean "only A", "only B", or "both A and B". In other words, "A or B" in the present disclosure may be interpreted as "A and / or B". For example, "A, B or C" in the present disclosure may mean "only A", "only B", "only C", or "any combination of A, B and C".

[0031] In the present disclosure, slash ( / ) or comma (,) may mean "and / or". For example, "A / B" may mean "A and / or B". Accordingly, "A / B" may mean "only A", "only B", or "both A and B". For example, "A, B, C" may mean "A, B or C".

[0032] In the present disclosure, "at least one of A and B" may mean "only A", "only B" or "both A and B". In addition, the expression "at least one of A or B" or "at least one of A and / or B" in the present disclosure may be interpreted as same as "at least one of A and B".

[0033] In addition, in the present disclosure, "at least one of A, B and C" may mean "only A", "only B", "only C", or "any combination of A, B and C". In addition, "at least one of A, B or C" or "at least one of A, B and / or C" may mean "at least one of A, B and C".

[0034] Also, parentheses used in the present disclosure may mean "for example". In detail, when it is shown as "control information (PDCCH)", "PDCCH" may be proposed as an example of "control information". In other words, "control information" in the present disclosure is not limited to "PDCCH", and "PDCCH" may be proposed as an example of "control information". In addition, even when shown as "control information (i.e., PDCCH)", "PDCCH" may be proposed as an example of "control information".

[0035] Technical features that are separately described in one drawing in the present disclosure may be implemented separately or simultaneously.

[0036] Although not limited thereto, various descriptions, functions, procedures, suggestions, methods and / or operational flowcharts of the present disclosure disclosed herein can be applied to various fields requiring wireless communication and / or connection (e.g., 5G) between devices.

[0037] Hereinafter, the present disclosure will be described in more detail with reference to drawings. The same reference numerals in the following drawings and / or descriptions may refer to the same and / or corresponding hardware blocks, software blocks, and / or functional blocks unless otherwise indicated.

[0038] FIG. 1 shows an example of a communication system to which implementations of the present disclosure is applied.

[0039] The 5G usage scenarios shown in FIG. 1 are only exemplary, and the technical features of the present disclosure can be applied to other 5G usage scenarios which are not shown in FIG. 1.

[0040] Three main requirement categories for 5G include (1) a category of enhanced Mobile BroadBand (eMBB), (2) a category of massive Machine Type Communication (mMTC), and (3) a category of Ultra-Reliable and Low Latency Communications (URLLC).

[0041] Referring to FIG. 1, the communication system 1 includes wireless devices 100a to 100f, Base Stations (BSs) 200, and a network 300. Although FIG. 1 illustrates a 5G network as an example of the network of the communication system 1, the implementations of the present disclosure are not limited to the 5G system, and can be applied to the future communication system beyond the 5G system.

[0042] The BSs 200 and the network 300 may be implemented as wireless devices and a specific wireless device may operate as a BS / network node with respect to other wireless devices.

[0043] The wireless devices 100a to 100f represent devices performing communication using Radio Access Technology (RAT) (e.g., 5G NR or LTE) and may be referred to as communication / radio / 5G devices. The wireless devices 100a to 100f may include, without being limited to, a robot 100a, vehicles 100b-1 and 100b-2, an eXtended Reality (XR) device 100c, a hand-held device 100d, a home appliance 100e, an Internet-of-Things (IoT) device 100f, and an Artificial Intelligence (AI) device / server 400. For example, the vehicles may include a vehicle having a wireless communication function, an autonomous driving vehicle, and a vehicle capable of performing communication between vehicles. The vehicles may include an Unmanned Aerial Vehicle (UAV) (e.g., a drone). The XR device may include an Augmented Reality (AR) / Virtual Reality (VR) / Mixed Reality (MR) device and may be implemented in the form of a Head-Mounted Device (HMD), a Head-Up Display (HUD) mounted in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance device, a digital signage, a vehicle, a robot, etc. The hand-held device may include a smartphone, a smartpad, a wearable device (e.g., a smartwatch or a smartglasses), and a computer (e.g., a notebook). The home appliance may include a TV, a refrigerator, and a washing machine. The IoT device may include a sensor and a smartmeter.

[0044] In the present disclosure, the wireless devices 100a to 100f may be called User Equipments (UEs). A UE may include, for example, a cellular phone, a smartphone, a laptop computer, a digital broadcast terminal, a Personal Digital Assistant (PDA), a Portable Multimedia Player (PMP), a navigation system, a slate Personal Computer (PC), a tablet PC, an ultrabook, a vehicle, a vehicle having an autonomous traveling function, a connected car, an UAV, an AI module, a robot, an AR device, a VR device, an MR device, a hologram device, a public safety device, an MTC device, an IoT device, a medical device, a FinTech device (or a financial device), a security device, a weather / environment device, a device related to a 5G service, or a device related to a fourth industrial revolution field.

[0045] The wireless devices 100a to 100f may be connected to the network 300 via the BSs 200. An AI technology may be applied to the wireless devices 100a to 100f and the wireless devices 100a to 100f may be connected to the AI server 400 via the network 300. The network 300 may be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, and a beyond-5G network. Although the wireless devices 100a to 100f may communicate with each other through the BSs 200 / network 300, the wireless devices 100a to 100f may perform direct communication (e.g., sidelink communication) with each other without passing through the BSs 200 / network 300. For example, the vehicles 100b-1 and 100b-2 may perform direct communication (e.g., Vehicle-to-Vehicle (V2V) / Vehicle-to-everything (V2X) communication). The IoT device (e.g., a sensor) may perform direct communication with other IoT devices (e.g., sensors) or other wireless devices 100a to 100f.

[0046] Wireless communication / connections 150a, 150b and 150c may be established between the wireless devices 100a to 100f and / or between wireless device 100a to 100f and BS 200 and / or between BSs 200. Herein, the wireless communication / connections may be established through various RATs (e.g., 5G NR) such as uplink / downlink communication 150a, sidelink communication (or Device-to-Device (D2D) communication) 150b, inter-base station communication 150c (e.g., relay, Integrated Access and Backhaul (IAB)), etc. The wireless devices 100a to 100f and the BSs 200 / the wireless devices 100a to 100f may transmit / receive radio signals to / from each other through the wireless communication / connections 150a, 150b and 150c. For example, the wireless communication / connections 150a, 150b and 150c may transmit / receive signals through various physical channels. To this end, at least a part of various configuration information configuring processes, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, and resource mapping / de-mapping), and resource allocating processes, for transmitting / receiving radio signals, may be performed based on the various proposals of the present disclosure.

[0047] NR supports multiples numerologies (and / or multiple Sub-Carrier Spacings (SCS)) to support various 5G services. For example, if SCS is 15 kHz, wide area can be supported in traditional cellular bands, and if SCS is 30 kHz / 60 kHz, dense-urban, lower latency, and wider carrier bandwidth can be supported. If SCS is 60 kHz or higher, bandwidths greater than 24.25 GHz can be supported to overcome phase noise.

[0048] The NR frequency band may be defined as two types of frequency range, i.e., Frequency Range 1 (FR1) and Frequency Range 2 (FR2). The numerical value of the frequency range may be changed. For example, the frequency ranges of the two types (FR1 and FR2) may be as shown in Table 1 below. For ease of explanation, in the frequency ranges used in the NR system, FR1 may mean "sub 6 GHz range", FR2 may mean "above 6 GHz range," and may be referred to as millimeter Wave (mmW).

[0049] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1450MHz - 6000MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz

[0050] As mentioned above, the numerical value of the frequency range of the NR system may be changed. For example, FR1 may include a frequency band of 410MHz to 7125MHz as shown in Table 2 below. That is, FR1 may include a frequency band of 6GHz (or 5850, 5900, 5925 MHz, etc.) or more. For example, a frequency band of 6 GHz (or 5850, 5900, 5925 MHz, etc.) or more included in FR1 may include an unlicensed band. Unlicensed bands may be used for a variety of purposes, for example for communication for vehicles (e.g., autonomous driving).

[0051] Frequency Range designationCorresponding frequency rangeSubcarrier SpacingFR1410MHz - 7125MHz15, 30, 60kHzFR224250MHz - 52600MHz60, 120, 240kHz

[0052] Here, the radio communication technologies implemented in the wireless devices in the present disclosure may include NarrowBand IoT (NB-IoT) technology for low-power communication as well as LTE, NR and 6G. For example, NB-IoT technology may be an example of Low Power Wide Area Network (LPWAN) technology, may be implemented in specifications such as LTE Cat NB1 and / or LTE Cat NB2, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may communicate based on LTE-M technology. For example, LTE-M technology may be an example of LPWAN technology and be called by various names such as enhanced MTC (eMTC). For example, LTE-M technology may be implemented in at least one of the various specifications, such as 1) LTE Cat 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-bandwidth limited (non-BL), 5) LTE-MTC, 6) LTE Machine Type Communication, and / or 7) LTE M, and may not be limited to the above-mentioned names. Additionally and / or alternatively, the radio communication technologies implemented in the wireless devices in the present disclosure may include at least one of ZigBee, Bluetooth, and / or LPWAN which take into account low-power communication, and may not be limited to the above-mentioned names. For example, ZigBee technology may generate Personal Area Networks (PANs) associated with small / low-power digital communication based on various specifications such as IEEE 802.15.4 and may be called various names.FIG. 2 shows an example of wireless devices to which implementations of the present disclosure is applied.

[0053] In FIG. 2, The first wireless device 100 and / or the second wireless device 200 may be implemented in various forms according to use cases / services. For example, {the first wireless device 100 and the second wireless device 200} may correspond to at least one of {the wireless device 100a to 100f and the BS 200}, {the wireless device 100a to 100f and the wireless device 100a to 100f} and / or {the BS 200 and the BS 200} of FIG. 1. The first wireless device 100 and / or the second wireless device 200 may be configured by various elements, devices / parts, and / or modules.

[0054] The first wireless device 100 may include at least one transceiver, such as a transceiver 106, at least one processing chip, such as a processing chip 101, and / or one or more antennas 108.

[0055] The processing chip 101 may include at least one processor, such a processor 102, and at least one memory, such as a memory 104. Additional and / or alternatively, the memory 104 may be placed outside of the processing chip 101.

[0056] The processor 102 may control the memory 104 and / or the transceiver 106 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 102 may process information within the memory 104 to generate first information / signals and then transmit radio signals including the first information / signals through the transceiver 106. The processor 102 may receive radio signals including second information / signals through the transceiver 106 and then store information obtained by processing the second information / signals in the memory 104.

[0057] The memory 104 may be operably connectable to the processor 102. The memory 104 may store various types of information and / or instructions. The memory 104 may store a firmware and / or a software code 105 which implements codes, commands, and / or a set of commands that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may implement instructions that, when executed by the processor 102, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more protocols. For example, the firmware and / or the software code 105 may control the processor 102 to perform one or more layers of the radio interface protocol.

[0058] Herein, the processor 102 and the memory 104 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 106 may be connected to the processor 102 and transmit and / or receive radio signals through one or more antennas 108. Each of the transceiver 106 may include a transmitter and / or a receiver. The transceiver 106 may be interchangeably used with Radio Frequency (RF) unit(s). In the present disclosure, the first wireless device 100 may represent a communication modem / circuit / chip.

[0059] The second wireless device 200 may include at least one transceiver, such as a transceiver 206, at least one processing chip, such as a processing chip 201, and / or one or more antennas 208.

[0060] The processing chip 201 may include at least one processor, such a processor 202, and at least one memory, such as a memory 204. Additional and / or alternatively, the memory 204 may be placed outside of the processing chip 201.

[0061] The processor 202 may control the memory 204 and / or the transceiver 206 and may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts described in the present disclosure. For example, the processor 202 may process information within the memory 204 to generate third information / signals and then transmit radio signals including the third information / signals through the transceiver 206. The processor 202 may receive radio signals including fourth information / signals through the transceiver 106 and then store information obtained by processing the fourth information / signals in the memory 204.

[0062] The memory 204 may be operably connectable to the processor 202. The memory 204 may store various types of information and / or instructions. The memory 204 may store a firmware and / or a software code 205 which implements codes, commands, and / or a set of commands that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may implement instructions that, when executed by the processor 202, perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more protocols. For example, the firmware and / or the software code 205 may control the processor 202 to perform one or more layers of the radio interface protocol.

[0063] Herein, the processor 202 and the memory 204 may be a part of a communication modem / circuit / chip designed to implement RAT (e.g., LTE or NR). The transceiver 206 may be connected to the processor 202 and transmit and / or receive radio signals through one or more antennas 208. Each of the transceiver 206 may include a transmitter and / or a receiver. The transceiver 206 may be interchangeably used with RF unit. In the present disclosure, the second wireless device 200 may represent a communication modem / circuit / chip.

[0064] Hereinafter, hardware elements of the wireless devices 100 and 200 will be described more specifically. One or more protocol layers may be implemented by, without being limited to, one or more processors 102 and 202. For example, the one or more processors 102 and 202 may implement one or more layers (e.g., functional layers such as Physical (PHY) layer, Media Access Control (MAC) layer, Radio Link Control (RLC) layer, Packet Data Convergence Protocol (PDCP) layer, Radio Resource Control (RRC) layer, and Service Data Adaptation Protocol (SDAP) layer). The one or more processors 102 and 202 may generate one or more Protocol Data Units (PDUs), one or more Service Data Unit (SDUs), messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The one or more processors 102 and 202 may generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure and provide the generated signals to the one or more transceivers 106 and 206. The one or more processors 102 and 202 may receive the signals (e.g., baseband signals) from the one or more transceivers 106 and 206 and acquire the PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure.

[0065] The one or more processors 102 and 202 may be referred to as controllers, microcontrollers, microprocessors, or microcomputers. The one or more processors 102 and 202 may be implemented by hardware, firmware, software, or a combination thereof. As an example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in the one or more processors 102 and 202. For example, the one or more processors 102 and 202 may be configured by a set of a communication control processor, an Application Processor (AP), an Electronic Control Unit (ECU), a Central Processing Unit (CPU), a Graphic Processing Unit (GPU), and a memory control processor.

[0066] The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 and store various types of data, signals, messages, information, programs, code, instructions, and / or commands. The one or more memories 104 and 204 may be configured by Random Access Memory (RAM), Dynamic RAM (DRAM), Read-Only Memory (ROM), electrically Erasable Programmable Read-Only Memory (EPROM), flash memory, volatile memory, non-volatile memory, hard drive, register, cash memory, computer-readable storage medium, and / or combinations thereof. The one or more memories 104 and 204 may be located at the interior and / or exterior of the one or more processors 102 and 202. The one or more memories 104 and 204 may be connected to the one or more processors 102 and 202 through various technologies such as wired or wireless connection.

[0067] The one or more transceivers 106 and 206 may transmit user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, to one or more other devices. The one or more transceivers 106 and 206 may receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, from one or more other devices. For example, the one or more transceivers 106 and 206 may be connected to the one or more processors 102 and 202 and transmit and receive radio signals. For example, the one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may transmit user data, control information, or radio signals to one or more other devices. The one or more processors 102 and 202 may perform control so that the one or more transceivers 106 and 206 may receive user data, control information, or radio signals from one or more other devices.

[0068] The one or more transceivers 106 and 206 may be connected to the one or more antennas 108 and 208. Additionally and / or alternatively, the one or more transceivers 106 and 206 may include one or more antennas 108 and 208. The one or more transceivers 106 and 206 may be adapted to transmit and receive user data, control information, and / or radio signals / channels, mentioned in the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure, through the one or more antennas 108 and 208. In the present disclosure, the one or more antennas 108 and 208 may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports).

[0069] The one or more transceivers 106 and 206 may convert received user data, control information, radio signals / channels, etc., from RF band signals into baseband signals in order to process received user data, control information, radio signals / channels, etc., using the one or more processors 102 and 202. The one or more transceivers 106 and 206 may convert the user data, control information, radio signals / channels, etc., processed using the one or more processors 102 and 202 from the base band signals into the RF band signals. To this end, the one or more transceivers 106 and 206 may include (analog) oscillators and / or filters. For example, the one or more transceivers 106 and 206 can up-convert OFDM baseband signals to OFDM signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202 and transmit the up-converted OFDM signals at the carrier frequency. The one or more transceivers 106 and 206 may receive OFDM signals at a carrier frequency and down-convert the OFDM signals into OFDM baseband signals by their (analog) oscillators and / or filters under the control of the one or more processors 102 and 202.

[0070] Although not shown in FIG. 2, the wireless devices 100 and 200 may further include additional components. The additional components 140 may be variously configured according to types of the wireless devices 100 and 200. For example, the additional components 140 may include at least one of a power unit / battery, an Input / Output (I / O) device (e.g., audio I / O port, video I / O port), a driving device, and a computing device. The additional components 140 may be coupled to the one or more processors 102 and 202 via various technologies, such as a wired or wireless connection.

[0071] In the implementations of the present disclosure, a UE may operate as a transmitting device in Uplink (UL) and as a receiving device in Downlink (DL). In the implementations of the present disclosure, a BS may operate as a receiving device in UL and as a transmitting device in DL. Hereinafter, for convenience of description, it is mainly assumed that the first wireless device 100 acts as the UE, and the second wireless device 200 acts as the BS. For example, the processor(s) 102 connected to, mounted on or launched in the first wireless device 100 may be adapted to perform the UE behavior according to an implementation of the present disclosure or control the transceiver(s) 106 to perform the UE behavior according to an implementation of the present disclosure. The processor(s) 202 connected to, mounted on or launched in the second wireless device 200 may be adapted to perform the BS behavior according to an implementation of the present disclosure or control the transceiver(s) 206 to perform the BS behavior according to an implementation of the present disclosure.

[0072] In the present disclosure, a BS is also referred to as a node B (NB), an eNode B (eNB), or a gNB.

[0073] FIG. 3 shows an example of UE to which implementations of the present disclosure is applied.

[0074] Referring to FIG. 3, a UE 100 may correspond to the first wireless device 100 of FIG. 2.

[0075] A UE 100 includes a processor 102, a memory 104, a transceiver 106, one or more antennas 108, a power management module 141, a battery 142, a display 143, a keypad 144, a Subscriber Identification Module (SIM) card 145, a speaker 146, and a microphone 147.

[0076] The processor 102 may be adapted to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The processor 102 may be adapted to control one or more other components of the UE 100 to implement the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. Layers of the radio interface protocol may be implemented in the processor 102. The processor 102 may include ASIC, other chipset, logic circuit and / or data processing device. The processor 102 may be an application processor. The processor 102 may include at least one of DSP, CPU, GPU, a modem (modulator and demodulator). An example of the processor 102 may be found in SNAPDRAGONTMseries of processors made by Qualcomm®, EXYNOSTMseries of processors made by Samsung®, A series of processors made by Apple®, HELIOTMseries of processors made by MediaTek®, ATOMTMseries of processors made by Intel®or a corresponding next generation processor.

[0077] The memory 104 is operatively coupled with the processor 102 and stores a variety of information to operate the processor 102. The memory 104 may include ROM, RAM, flash memory, memory card, storage medium and / or other storage device. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, suggestions, methods and / or operational flowcharts disclosed in the present disclosure. The modules can be stored in the memory 104 and executed by the processor 102. The memory 104 can be implemented within the processor 102 or external to the processor 102 in which case those can be communicatively coupled to the processor 102 via various means as is known in the art.

[0078] The transceiver 106 is operatively coupled with the processor 102, and transmits and / or receives a radio signal. The transceiver 106 includes a transmitter and a receiver. The transceiver 106 may include baseband circuitry to process radio frequency signals. The transceiver 106 controls the one or more antennas 108 to transmit and / or receive a radio signal.

[0079] The power management module 141 manages power for the processor 102 and / or the transceiver 106. The battery 142 supplies power to the power management module 141.

[0080] The display 143 outputs results processed by the processor 102. The keypad 144 receives inputs to be used by the processor 102. The keypad 144 may be shown on the display 143.

[0081] The SIM card 145 is an integrated circuit that is intended to securely store the International Mobile Subscriber Identity (IMSI) number and its related key, which are used to identify and authenticate subscribers on mobile telephony devices (such as mobile phones and computers). It is also possible to store contact information on many SIM cards.

[0082] The speaker 146 outputs sound-related results processed by the processor 102. The microphone 147 receives sound-related inputs to be used by the processor 102.

[0083] FIGs. 4 and 5 show an example of protocol stacks in a 3GPP based wireless communication system to which implementations of the present disclosure is applied.

[0084] In particular, FIG. 4 illustrates an example of a radio interface user plane protocol stack between a UE and a BS and FIG. 5 illustrates an example of a radio interface control plane protocol stack between a UE and a BS. The control plane refers to a path through which control messages used to manage call by a UE and a network are transported. The user plane refers to a path through which data generated in an application layer, for example, voice data or Internet packet data are transported. Referring to FIG. 4, the user plane protocol stack may be divided into Layer 1 (L1, for example PHY layer) and Layer 2 (L2, for example MAC / RLC / PDCP layer). Referring to FIG. 5, the control plane protocol stack may be divided into Layer 1 (L1, for example PHY layer), Layer 2 (L2, for example MAC / RLC / PDCP layer), Layer 3 (L3, for example an RRC layer), and a non-access stratum (NAS) layer. Layer 1, Layer 2 and Layer 3 are referred to as an access stratum (AS).

[0085] In the 3GPP LTE system, the Layer 2 is split into the following sublayers: MAC, RLC, and PDCP. In the 3GPP NR system, the Layer 2 is split into the following sublayers: MAC, RLC, PDCP and SDAP. The PHY layer offers to the MAC sublayer transport channels, the MAC sublayer offers to the RLC sublayer logical channels, the RLC sublayer offers to the PDCP sublayer RLC channels, the PDCP sublayer offers to the SDAP sublayer radio bearers. The SDAP sublayer offers to 5G core network quality of service (QoS) flows.

[0086] In the 3GPP NR system, the main services and functions of the MAC sublayer include: mapping between logical channels and transport channels; multiplexing / de-multiplexing of MAC SDUs belonging to one or different logical channels into / from transport blocks (TB) delivered to / from the physical layer on transport channels; scheduling information reporting; error correction through hybrid automatic repeat request (HARQ) (one HARQ entity per cell in case of carrier aggregation (CA)); priority handling between UEs by means of dynamic scheduling; priority handling between logical channels of one UE by means of logical channel prioritization; padding. A single MAC entity may support multiple numerologies, transmission timings and cells. Mapping restrictions in logical channel prioritization control which numerology(ies), cell(s), and transmission timing(s) a logical channel can use.

[0087] Different kinds of data transfer services are offered by MAC. To accommodate different kinds of data transfer services, multiple types of logical channels are defined, i.e., each supporting transfer of a particular type of information. Each logical channel type is defined by what type of information is transferred. Logical channels are classified into two groups: control channels and traffic channels. Control channels are used for the transfer of control plane information only, and traffic channels are used for the transfer of user plane information only. Broadcast control channel (BCCH) is a downlink logical channel for broadcasting system control information, paging control channel (PCCH) is a downlink logical channel that transfers paging information, system information change notifications and indications of ongoing public warning service (PWS) broadcasts, common control channel (CCCH) is a logical channel for transmitting control information between UEs and network and used for UEs having no RRC connection with the network, and dedicated control channel (DCCH) is a point-to-point bi-directional logical channel that transmits dedicated control information between a UE and the network and used by UEs having an RRC connection. Dedicated traffic channel (DTCH) is a point-to-point logical channel, dedicated to one UE, for the transfer of user information. A DTCH can exist in both uplink and downlink. In downlink, the following connections between logical channels and transport channels exist: BCCH can be mapped to broadcast channel (BCH); BCCH can be mapped to downlink shared channel (DL-SCH); PCCH can be mapped to paging channel (PCH); CCCH can be mapped to DL-SCH; DCCH can be mapped to DL-SCH; and DTCH can be mapped to DL-SCH. In uplink, the following connections between logical channels and transport channels exist: CCCH can be mapped to uplink shared channel (UL-SCH); DCCH can be mapped to UL-SCH; and DTCH can be mapped to UL-SCH.

[0088] The RLC sublayer supports three transmission modes: transparent mode (TM), unacknowledged mode (UM), and acknowledged node (AM). The RLC configuration is per logical channel with no dependency on numerologies and / or transmission durations. In the 3GPP NR system, the main services and functions of the RLC sublayer depend on the transmission mode and include: transfer of upper layer PDUs; sequence numbering independent of the one in PDCP (UM and AM); error correction through ARQ (AM only); segmentation (AM and UM) and re-segmentation (AM only) of RLC SDUs; reassembly of SDU (AM and UM); duplicate detection (AM only); RLC SDU discard (AM and UM); RLC re-establishment; protocol error detection (AM only).

[0089] In the 3GPP NR system, the main services and functions of the PDCP sublayer for the user plane include: sequence numbering; header compression and decompression using robust header compression (ROHC); transfer of user data; reordering and duplicate detection; in-order delivery; PDCP PDU routing (in case of split bearers); retransmission of PDCP SDUs; ciphering, deciphering and integrity protection; PDCP SDU discard; PDCP re-establishment and data recovery for RLC AM; PDCP status reporting for RLC AM; duplication of PDCP PDUs and duplicate discard indication to lower layers. The main services and functions of the PDCP sublayer for the control plane include: sequence numbering; ciphering, deciphering and integrity protection; transfer of control plane data; reordering and duplicate detection; in-order delivery; duplication of PDCP PDUs and duplicate discard indication to lower layers.

[0090] In the 3GPP NR system, the main services and functions of SDAP include: mapping between a QoS flow and a data radio bearer; marking QoS flow ID (QFI) in both DL and UL packets. A single protocol entity of SDAP is configured for each individual PDU session.

[0091] In the 3GPP NR system, the main services and functions of the RRC sublayer include: broadcast of system information related to AS and NAS; paging initiated by 5GC or NG-RAN; establishment, maintenance and release of an RRC connection between the UE and NG-RAN; security functions including key management; establishment, configuration, maintenance and release of signaling radio bearers (SRBs) and data radio bearers (DRBs); mobility functions (including: handover and context transfer, UE cell selection and reselection and control of cell selection and reselection, inter-RAT mobility); QoS management functions; UE measurement reporting and control of the reporting; detection of and recovery from radio link failure; NAS message transfer to / from NAS from / to UE.

[0092] FIG. 6 shows a frame structure in a 3GPP based wireless communication system to which implementations of the present disclosure is applied.

[0093] The frame structure shown in FIG. 6 is purely exemplary and the number of subframes, the number of slots, and / or the number of symbols in a frame may be variously changed. In the 3GPP based wireless communication system, OFDM numerologies (e.g., subcarrier spacing (SCS), transmission time interval (TTI) duration) may be differently configured between a plurality of cells aggregated for one UE. For example, if a UE is configured with different SCSs for cells aggregated for the cell, an (absolute time) duration of a time resource (e.g., a subframe, a slot, or a TTI) including the same number of symbols may be different among the aggregated cells. Herein, symbols may include OFDM symbols (or CP-OFDM symbols), SC-FDMA symbols (or discrete Fourier transform-spread-OFDM (DFT-s-OFDM) symbols).

[0094] Referring to FIG. 6, downlink and uplink transmissions are organized into frames. Each frame has Tf= 10ms duration. Each frame is divided into two half-frames, where each of the half-frames has 5ms duration. Each half-frame consists of 5 subframes, where the duration Tsfper subframe is 1ms. Each subframe is divided into slots and the number of slots in a subframe depends on a subcarrier spacing. Each slot includes 14 or 12 OFDM symbols based on a cyclic prefix (CP). In a normal CP, each slot includes 14 OFDM symbols and, in an extended CP, each slot includes 12 OFDM symbols. The numerology is based on exponentially scalable subcarrier spacing βf = 2u*15 kHz.

[0095] Table 3 shows the number of OFDM symbols per slot Nslotsymb, the number of slots per frameNframe,uslot, and the number of slots per subframe Nsubframe,uslotfor the normal CP, according to the subcarrier spacing βf = 2u*15 kHz.

[0096] uNslotsymbNframe,uslotNsubframe,uslot01410111420221440431480841416016

[0097] Table 4 shows the number of OFDM symbols per slot Nslotsymb, the number of slots per frameNframe,uslot, and the number of slots per subframe Nsubframe,uslotfor the extended CP, according to the subcarrier spacing βf = 2u*15 kHz.

[0098] uNslotsymbNframe,uslotNsubframe,uslot212404

[0099] A slot includes plural symbols (e.g., 14 or 12 symbols) in the time domain. For each numerology (e.g., subcarrier spacing) and carrier, a resource grid ofNsize,ugrid,x*NRBscsubcarriers andNsubframe,usymbOFDM symbols is defined, starting at common resource block (CRB)Nstart,ugridindicated by higher-layer signaling (e.g., RRC signaling), whereNsize,ugrid,xis the number of resource blocks (RBs) in the resource grid and the subscript x is DL for downlink and UL for uplink.NRBscis the number of subcarriers per RB. In the 3GPP based wireless communication system,NRBscis 12 generally. There is one resource grid for a given antenna portp, subcarrier spacing configurationu, and transmission direction (DL or UL). The carrier bandwidthNsize,ugridfor subcarrier spacing configurationuis given by the higher-layer parameter (e.g., RRC parameter). Each element in the resource grid for the antenna portpand the subcarrier spacing configurationuis referred to as a resource element (RE) and one complex symbol may be mapped to each RE. Each RE in the resource grid is uniquely identified by an indexkin the frequency domain and an indexlrepresenting a symbol location relative to a reference point in the time domain. In the 3GPP based wireless communication system, an RB is defined by 12 consecutive subcarriers in the frequency domain. As shown in FIG. 6, as SCS doubles, the slot length and symbol length are halved. For example, when SCS is 15kHz, the slot length is 1ms, which is the same as the subframe length. When SCS is 30kHz, the slot length is 0.5ms (=500us), and the symbol length is half of that when the SCS is 15kHz. When SCS is 60kHz, the slot length is 0.25ms (=250us), and the symbol length is half of that when the SCS is 30kHz. When SCS is 120kHz, the slot length is 0.125ms (=125us), and the symbol length is half of that when the SCS is 60kHz. When SCS is 240kHz, the slot length is 0.0625ms (=62.5us), and the symbol length is half of that when the SCS is 120kHz.

[0100] In the 3GPP NR system, RBs are classified into CRBs and physical resource blocks (PRBs). CRBs are numbered from 0 and upwards in the frequency domain for subcarrier spacing configurationu. The center of subcarrier 0 of CRB 0 for subcarrier spacing configurationucoincides with 'point A' which serves as a common reference point for resource block grids. In the 3GPP NR system, PRBs are defined within a bandwidth part (BWP) and numbered from 0 toNsizeBWP,i-1, where i is the number of the bandwidth part. The relation between the physical resource block nPRBin the bandwidth part i and the common resource block nCRBis as follows: nPRB= nCRB+NsizeBWP,i, whereNsizeBWP,iis the common resource block where bandwidth part starts relative to CRB 0. The BWP includes a plurality of consecutive RBs. A carrier may include a maximum of N (e.g., 5) BWPs. A UE may be configured with one or more BWPs on a given component carrier. Only one BWP among BWPs configured to the UE can active at a time. The active BWP defines the UE's operating bandwidth within the cell's operating bandwidth.

[0101] In the present disclosure, the term "cell" may refer to a geographic area to which one or more nodes provide a communication system, or refer to radio resources. A "cell" as a geographic area may be understood as coverage within which a node can provide service using a carrier and a "cell" as radio resources (e.g., time-frequency resources) is associated with bandwidth which is a frequency range configured by the carrier. The "cell" associated with the radio resources is defined by a combination of downlink resources and uplink resources, for example, a combination of a DL component carrier (CC) and a UL CC. The cell may be configured by downlink resources only, or may be configured by downlink resources and uplink resources. Since DL coverage, which is a range within which the node is capable of transmitting a valid signal, and UL coverage, which is a range within which the node is capable of receiving the valid signal from the UE, depends upon a carrier carrying the signal, the coverage of the node may be associated with coverage of the "cell" of radio resources used by the node. Accordingly, the term "cell" may be used to represent service coverage of the node sometimes, radio resources at other times, or a range that signals using the radio resources can reach with valid strength at other times.

[0102] In CA, two or more CCs are aggregated. A UE may simultaneously receive or transmit on one or multiple CCs depending on its capabilities. CA is supported for both contiguous and non-contiguous CCs. When CA is configured, the UE only has one RRC connection with the network. At RRC connection establishment / re-establishment / handover, one serving cell provides the NAS mobility information, and at RRC connection re-establishment / handover, one serving cell provides the security input. This cell is referred to as the primary cell (PCell). The PCell is a cell, operating on the primary frequency, in which the UE either performs the initial connection establishment procedure or initiates the connection re-establishment procedure. Depending on UE capabilities, secondary cells (SCells) can be configured to form together with the PCell a set of serving cells. An SCell is a cell providing additional radio resources on top of special cell (SpCell). The configured set of serving cells for a UE therefore always consists of one PCell and one or more SCells. For dual connectivity (DC) operation, the term SpCell refers to the PCell of the master cell group (MCG) or the primary SCell (PSCell) of the secondary cell group (SCG). An SpCell supports PUCCH transmission and contention-based random access, and is always activated. The MCG is a group of serving cells associated with a master node, comprised of the SpCell (PCell) and optionally one or more SCells. The SCG is the subset of serving cells associated with a secondary node, comprised of the PSCell and zero or more SCells, for a UE configured with DC. For a UE in RRC_CONNECTED not configured with CA / DC, there is only one serving cell comprised of the PCell. For a UE in RRC_CONNECTED configured with CA / DC, the term "serving cells" is used to denote the set of cells comprised of the SpCell(s) and all SCells. In DC, two MAC entities are configured in a UE: one for the MCG and one for the SCG.

[0103] FIG. 7 shows a data flow example in the 3GPP NR system to which implementations of the present disclosure is applied.

[0104] Referring to FIG. 7, "RB" denotes a radio bearer, and "H" denotes a header. Radio bearers are categorized into two groups: DRBs for user plane data and SRBs for control plane data. The MAC PDU is transmitted / received using radio resources through the PHY layer to / from an external device. The MAC PDU arrives to the PHY layer in the form of a transport block.

[0105] In the PHY layer, the uplink transport channels UL-SCH and random access channel (RACH) are mapped to their physical channels physical uplink shared channel (PUSCH) and physical random access channel (PRACH), respectively, and the downlink transport channels DL-SCH, BCH and PCH are mapped to physical downlink shared channel (PDSCH), physical broadcast channel (PBCH) and PDSCH, respectively. In the PHY layer, uplink control information (UCI) is mapped to physical uplink control channel (PUCCH), and downlink control information (DCI) is mapped to physical downlink control channel (PDCCH). A MAC PDU related to UL-SCH is transmitted by a UE via a PUSCH based on an UL grant, and a MAC PDU related to DL-SCH is transmitted by a BS via a PDSCH based on a DL assignment.

[0106] Hereinafter, a description will be given of AS security.

[0107] AS security comprises of the integrity protection and ciphering of RRC signalling (SRBs) and user data (DRBs).

[0108] RRC handles the configuration of the AS security parameters which are part of the AS configuration: the integrity protection algorithm, the ciphering algorithm, if integrity protection and / or ciphering is enabled for a DRB and two parameters, namely thekeySetChangeIndicatorand thenextHopChainingCount, which are used by the UE to determine the AS security keys upon reconfiguration with sync (with key change), connection re-establishment and / or connection resume.

[0109] The integrity protection algorithm is common for SRB1, SRB2, SRB3 (if configured), SRB4 (if configured), SRB5 (if configured) and DRBs configured with integrity protection, with the samekeyToUsevalue. The ciphering algorithm is common for SRB1, SRB2, SRB3 (if configured), SRB4 (if configured), SRB5 (if configured) and DRBs configured with the samekeyToUsevalue. Neither integrity protection nor ciphering applies for SRB0.

[0110] All DRBs related to the same PDU session have the same enable / disable setting for ciphering and the same enable / disable setting for integrity protection.

[0111] RRC integrity protection and ciphering are always activated together, i.e. in one message / procedure. RRC integrity protection and ciphering for SRBs are never de-activated. However, it is possible to switch to a 'NULL' ciphering algorithm (nea0).

[0112] The 'NULL' integrity protection algorithm (nia0) is used only for SRBs and for the UE in limited service mode, and when used for SRBs, integrity protection is disabled for DRBs. In case the 'NULL' integrity protection algorithm is used, 'NULL' ciphering algorithm is also used.

[0113] Lower layers discard RRC messages for which the integrity protection check has failed and indicate the integrity protection verification check failure to RRC.

[0114] The AS applies four different security keys: one for the integrity protection of RRC signalling (KRRCint), one for the ciphering of RRC signalling (KRRCenc), one for integrity protection of user data (KUPint) and one for the ciphering of user data (KUPenc). All four AS keys are derived from the KgNB key. The KgNB key is based on the KAMF key, which is handled by upper layers.

[0115] The integrity protection and ciphering algorithms can only be changed with reconfiguration with sync. The AS keys (KgNB, KRRCint, KRRCenc, KUPint and KUPenc) change upon reconfiguration with sync (ifmasterKeyUpdateis included), and upon connection re-establishment and connection resume.

[0116] For each radio bearer an independent counter (COUNT) is maintained for each direction.

[0117] For each radio bearer, theCOUNTis used as input for ciphering and integrity protection.

[0118] It is not allowed to use the sameCOUNTvalue more than once for a given security key. The network is responsible for avoiding reuse of theCOUNTwith the same RB identity and with the same key, e.g. due to the transfer of large volumes of data, release and establishment of new RBs, and multiple termination point changes for RLC-UM bearers and multiple termination point changes for RLC-AM bearer with SN terminated PDCP re-establishment (COUNT reset) due to SN only full configuration whilst the key stream inputs (i.e. bearer ID, security key) at MN have not been updated. In order to avoid such re-use, the network may e.g. use different RB identities for RB establishments, change the AS security key, or an RRC_CONNECTED to RRC_IDLE / RRC_INACTIVE and then to RRC_CONNECTED transition.

[0119] In order to limit the signalling overhead, individual messages / packets include a short sequence number (PDCP SN). In addition, an overflow counter mechanism is used: the hyper frame number (HFN). The HFN needs to be synchronized between the UE and the network.

[0120] For each SRB, the value provided by RRC to lower layers to derive the 5-bit BEARER parameter used as input for ciphering and for integrity protection is the value of the correspondingsrb-Identitywith the MSBs padded with zeroes.

[0121] For a UE provided with ansk-counter,keyToUseindicates whether the UE uses the master key (KgNB) or the secondary key (S-KeNB or S-KgNB) for a particular DRB. The secondary key is derived from the master key andsk-Counter. Whenever there is a need to refresh the secondary key, e.g. upon change of MN with KgNB change or to avoid COUNT reuse, the security key update is used. When the UE is in NR-DC, the network may provide a UE configured with an SCG with ansk-Countereven when no DRB is setup using the secondary key (S-KgNB) in order to allow the configuration of SRB3. The network can also provide the UE with ansk-Counter, even if no SCG is configured, when using SN terminated MCG bearers.

[0122] Hereinafter, a description will be given of mobility.

[0123] The mobility may comprise PCell change, PSCell change (or, secondary node (SN) change), and / or PSCell addition (or, SN addition).

[0124] In the present disclosure, the term "handover (HO)" may mean PCell change, or may be a broad concept that includes not only PCell change but also PSCell change / addition.

[0125] In the present disclosure, the terms "handover" and "mobility" can be used interchangeably.

[0126] In the present disclosure, the description regarding handover can also be applied to other mobility procedures (e.g., PSCell change / addition).

[0127] There may be at least two types of mobility: network-controlled mobility (or, legacy mobility) and UE-based mobility (or, conditional mobility).

[0128] The network-controlled mobility (or, legacy mobility) is a mobility where the network determines a target cell for mobility, and configures UE with the target cell. The network may transmit, to the UE, anRRCReconfigurationmessage comprising a configuration of the target cell. The UE may execute a mobility to the target cell and / or apply the configuration of the target cell, upon receiving the configuration of the target cell.

[0129] The UE-based mobility (or, conditional mobility) is a mobility where the network configures the UE with a plurality of candidate cells, and the UE determines a target cell which satisfies a mobility execution condition among the plurality of candidate cells. The conditional mobility may comprise at least one of a conditional PCell change / conditional handover (CHO) or a conditional PSCell mobility. The conditional PSCell mobility may comprise conditional PSCell addition / change (CPAC), including conditional PSCell addition (CPA) and / or conditional PSCell change (CPC). The network may transmit, to the UE, anRRCReconfigurationmessage comprisingConditionalReconfigurationinformation element (IE)(or, conditional mobility configuration), which comprises a list of candidate configurations for conditional mobility related to the plurality of candidate cells. A candidate configuration for conditional mobility may comprise an identifier of the candidate configuration, a mobility execution condition for the related candidate cell, and a configuration of the related candidate cell. The UE may evaluate the mobility execution conditions for the plurality of candidate cells, and when a mobility execution condition for a candidate cell is satisfied, the UE may consider the candidate cell as a target cell, and execute a mobility to the target cell and / or apply the configuration of the target cell.

[0130] According to various embodiments, the mobility execution condition may be satisfied / met when an entry condition (or, entering condition) for the mobility execution condition is satisfied / met for at least a time-to-trigger (TTT) for the mobility execution condition. The entry condition / entering condition may mean that the mobility execution condition is initially met. Once the entry condition is met, the mobility execution condition will be considered to be met if the entry condition is met for time duration TTT continuously.

[0131] In the present disclosure, subsequent mobility (e.g., subsequent CHO, subsequent CPAC (SCPAC)) is described. The subsequent mobility may refer to a mobility that is done by repeating a mobility execution / completion after each mobility execution / completion based on a corresponding candidate configuration without releasing other candidate configurations. That is, the subsequent mobility may refer to a mobility that is performed without reconfiguration and / or re-initialization on the mobility preparation from a network after a previous mobility. For example, when a UE has received a plurality of candidate configurations, after the UE performs a mobility based on a corresponding candidate configuration, the UE does not release other candidate configurations, and may perform a subsequent mobility based on a corresponding candidate configuration among the already received plurality of candidate configurations without reconfiguration and / or re-initialization on the mobility preparation from the network (or, without receiving new candidate configurations from the network). This results in a reduction of the signalling overhead and / or interrupting time for mobility.

[0132] FIG. 8 shows an example of a conditional mobility procedure according to an embodiment of the present disclosure.

[0133] In FIG. 8:

[0134] - the serving BS may be related to a PCell, which may be a source PCell for CHO;

[0135] - the serving BS may be an MN associated with an SN in DC, where the SN may be related to a source PSCell for CPC; and

[0136] - the target cell may be a target PCell for CHO, or a target PSCell for CPA / CPC.

[0137] Referring to FIG. 8, in step S801, UE may receive, from the serving BS, anRRCReconfigurationmessage comprising a conditional reconfiguration information element (IE) (i.e.,CondidtionalReconfiguration). The conditional reconfiguration IE may comprise a list of candidate configurations for conditional mobility related to candidate cells including the target cell. Each candidate configuration in the list may be related to the corresponding candidate cell, and comprises i) an identifier of the corresponding candidate configuration (i.e.,condReconfigId), ii) one or more execution conditions for the related candidate cell (i.e.,condExecutionCond), and / or iii) RRC reconfiguration for the related candidate cell (i.e.,condRRCReconfig) including a configuration of the related candidate cell. The one or more execution conditions may comprise CHO execution condition(s), CPA execution condition(s), and / or CPC execution condition(s).

[0138] The IEs in theConditionalReconfigurationare shown in table 5:

[0139] ConditionalReconfiguration-r16 ::= SEQUENCE {attemptCondReconfig-r16 ENUMERATED {true} OPTIONAL, -- Cond CHOcondReconfigToRemoveList-r16 CondReconfigToRemoveList-r16 OPTIONAL, -- Need NcondReconfigToAddModList-r16 CondReconfigToAddModList-r16 OPTIONAL, -- Need N...,[[scpac-ReferenceConfiguration-r18 SetupRelease {ReferenceConfiguration-r18} OPTIONAL, -- Need MservingSecurityCellSetId-r18 SecurityCellSetId-r18 OPTIONAL, -- Need Msk-CounterConfiguration-r18 SK-CounterConfiguration-r18 OPTIONAL -- Need M]]}CondReconfigToRemoveList-r16 ::= SEQUENCE (SIZE (1.. maxNrofCondCells-r16)) OF CondReconfigId-r16SK-CounterConfiguration-r18 ::= SEQUENCE {sk-CounterConfigToReleaseList-r18 SEQUENCE (SIZE (1..maxSecurityCellSet-r18)) OF SecurityCellSetId-r18 OPTIONAL, -- Need Nsk-CounterConfigToAddModList-r18 SEQUENCE (SIZE (1..maxSecurityCellSet-r18)) OF SK-CounterConfig-r18 OPTIONAL -- Need N}SK-CounterConfig-r18 ::= SEQUENCE {securityCellSetId-r18 SecurityCellSetId-r18,sk-CounterList-r18 SEQUENCE (SIZE (1..maxSK-Counter-r18)) OF SK-Counter}SecurityCellSetId-r18 ::= INTEGER (1.. maxSecurityCellSet-r18)

[0140] In table 5:-attemptCondReconfig: if present, the UE shall perform conditional reconfiguration if selected cell is a target candidate cell and it is the first cell selection after failure;

[0141] -condReconfigToAddModList: list of the configuration of candidate SpCells to be added or modified for CHO, CPA or CPC;

[0142] -condReconfigToRemoveList: list of the configuration of candidate SpCells to be removed;

[0143] -scpac-ReferenceConfiguration: includes the reference configuration for the candidate supporting subsequent CPAC;

[0144] -servingSecurityCellSetId: this field identifies the security cell set for serving PSCell. The network does not provide this field for the conditional reconfiguration(s) generated by the SN; and

[0145] -sk-counterConfiguration: includes a list ofsk-Counterfrom which the UE should selectthe sk-counterused to derive S-KgNB for inter-SN subsequent CPAC. The network does not provide this field for the conditional reconfiguration(s) generated by the SN.

[0146] The IEs in thecondReconfigToAddModListare shown in table 6:

[0147] CondReconfigToAddModList-r16 ::= SEQUENCE (SIZE (1.. maxNrofCondCells-r16)) OF CondReconfigToAddMod-r16CondReconfigToAddMod-r16 ::= SEQUENCE {condReconfigId-r16 CondReconfigId-r16,condExecutionCond-r16 SEQUENCE (SIZE (1..2)) OF MeasId OPTIONAL, -- Need McondRRCReconfig-r16 OCTET STRING (CONTAINING RRCReconfiguration) OPTIONAL, -- Cond condReconfigAdd...,[[condExecutionCondSCG-r17 OCTET STRING (CONTAINING CondReconfigExecCondSCG-r17) OPTIONAL -- Need M]],[[condExecutionCondPSCell-r18 SEQUENCE (SIZE (1..2)) OF MeasId OPTIONAL, -- Cond condReconfigCHO-WithSCGsubsequentCondReconfig-r18 SubsequentCondReconfig-r18 OPTIONAL, -- Need MsecurityCellSetId-r18 SecurityCellSetId-r18 OPTIONAL, -- Need Mscpac-ConfigComplete-r18 ENUMERATED {true} OPTIONAL -- Cond CPAC]]}CondReconfigExecCondSCG-r17 ::= SEQUENCE (SIZE (1..2)) OF MeasIdSubsequentCondReconfig-r18 ::= SEQUENCE {condExecutionCondToReleaseList-r18 CondExecutionCondToReleaseList-r18 condExecutionCondToAddModList-r18 CondExecutionCondToAddModList-r18 ...OPTIONAL, -- Need NOPTIONAL, -- Need N}CondExecutionCondToAddModList-r18 ::= SEQUENCE (SIZE (1.. maxNrofCondCells-r16)) OF CondExecutionCondToAddMod-r18CondExecutionCondToAddMod-r18 ::= SEQUENCE {subsequentCondReconfigId-r18 CondReconfigId-r16,subsequentCondExecutionCond-r18 SEQUENCE (SIZE (1..2)) OF MeasId OPTIONAL, -- Need MsubsequentCondExecutionCondSCG-r18 OCTET STRING (CONTAINING CondReconfigExecCondSCG-r17) OPTIONAL, -- Need M...}CondExecutionCondToReleaseList-r18 ::= SEQUENCE (SIZE (1.. maxNrofCondCells-r16)) OF CondReconfigId-r16

[0148] In table 6:-condExecutionCond: the execution condition that needs to be fulfilled in order to trigger the execution of a conditional reconfiguration for CHO, CPA, intra-SN CPC without MN involvement, MN initiated inter-SN CPC, MN initiated subsequent CPAC, or SN initiated intra-SN subsequent CPAC without MN involvement. When configuring 2 triggering events (MeasIds) for a candidate cell, the network ensures that both refer to the samemeasObject. The network configures at most one fromcondEventD1,condEventD2orcondEventT1for the same candidate cell. For CPA, MN-initiated inter-SN CPC, and for MN initiated subsequent CPAC, the network only indicatesMeasId(s) associated withcondEventA4. For intra-SN CPC and for SN initiated intra-SN subsequent CPAC without MN involvement, the network only indicatesMeasId(s) associated withcondEventA3orcondEventA5;

[0149] -condExecutionCondPSCell: the execution condition that needs to be fulfilled for the associated PSCell in order to trigger the execution of a conditional reconfiguration for CHO with candidate SCG(s). TheMeasIdsrefer to themeasConfigassociated with the MCG. When configuring 2 triggering events (MeasIds) for a candidate cell, network ensures that both refer to the samemeasObject. The network only indicatesMeasId(s) associated withcondEventA4;

[0150] -condExecutionCondSCG: contains execution condition that needs to be fulfilled in order to trigger the execution of a conditional reconfiguration for SN initiated inter-SN CPC, SN initiated inter-SN subsequent CPAC, or SN initiated intra-SN subsequent CPAC with MN involvement. TheMeasIds refer to themeasConfigassociated with the SCG. When configuring 2 triggering events (MeasIds) for a candidate cell, network ensures that both refer to the samemeasObject. For eachcondReconfigId, the network always configures eithercondExecutionCondorcondExecutionCondSCG(not both). The network only indicatesMeasId(s) associated withcondEventA3orcondEventA5;

[0151] -condRRCReconfig: theRRCReconfigurationmessage to be applied when the condition(s) are fulfilled. TheRRCReconfigurationmessage contained incondRRCReconfigcannot contain the fieldconditionalReconfigurationor the fielddaps-Config;

[0152] -securityCellSetId: this field is used to determine whether the UE should perform security update when conditional reconfiguration containingsubsequentCondReconfigis executed. If the fieldservingSecurityCellSetIdis configured inconditionalReconfiguration, this field is configured for all the candidate configurations for subsequent CPAC;

[0153] -subsequentCondReconfig: contains the execution conditions that need to be fulfilled in order to trigger the execution of a subsequent CPAC. If the field is configured, the configuration of candidate PSCells for subsequent CPAC is supported. The subsequent execution condition is used for conditional reconfiguration evaluation for other candidate cells when theRRCReconfigurationmessage contained incondRRCReconfighas been applied;

[0154] -subsequentCondExecutionCond: the execution condition that needs to be fulfilled in order to trigger the subsequent execution of a conditional reconfiguration for SN initiated intra-SN subsequent CPAC without MN involvement. When configuring 2 triggering events (MeasIds) for a candidate cell, the network ensures that both refer to the samemeasObject. The network only indicatesMeasId(s) associated withcondEventA3orcondEventA5; and

[0155] -subsequentCondExecutionCondSCG: contains execution condition that needs to be fulfilled in order to trigger the subsequent execution of a conditional reconfiguration for SN initiated inter-SN subsequent CPAC, SN initiated intra-SN subsequent CPAC with MN involvement, or MN initiated subsequent CPAC. TheMeasIds refer to themeasConfigassociated with the SCG. When configuring 2 triggering events (MeasIds) for a candidate cell, network ensures that both refer to the samemeasObject. The network only indicatesMeasId(s) associated withcondEventA3orcondEventA5.

[0156] In step S803, the UE may start evaluating the one or more execution conditions for the candidate cells.

[0157] In step S805, if the target cell satisfies the corresponding execution condition(s), the UE may execute the conditional mobility towards the target cell and / or apply the RRC reconfiguration for the target cell including a configuration of the target cell. When / upon executing the conditional mobility and / or applying the RRC reconfiguration (e.g.,RRCReconfigurationincludingReconfigurationWithSync) for the target cell, the UE may start a timer (e.g., T304 timer). The timer value of the T304 timer (i.e., T304 timer value) for the target cell may be included in theReconfigurationWithSyncinRRCReconfigurationfor the target cell.

[0158] While the timer is running, the UE may perform DL synchronization and / or UL synchronization (e.g., random access) towards the target cell. The UE may skip the random access towards the target cell if timing advance (TA) information for the target cell is available.

[0159] In step S807, the UE, serving BS and / or BS related to the target cell may perform actions related to conditional mobility completion. For example, upon successful completion of the random access on the corresponding target cell, the UE may stop the timer (e.g., T304 timer).

[0160] Hereinafter, detailed procedure of the conditional reconfiguration / mobility is described.

[0161] The network configures the UE with one or more candidate target SpCells in the conditional reconfiguration. The UE evaluates the condition of each configured candidate target SpCell. The UE applies the conditional reconfiguration associated with one of the target SpCells which fulfils associated execution condition.

[0162] The network can also configure the UE with one or more candidate target PCells associated with one or more candidate target PSCells. The UE evaluates the conditions for the candidate target PCells and the associated candidate target PSCells in parallel and applies a target configuration that include PCell and PSCell for which the associated execution conditions are fulfilled. If there are multiple candidate PSCells associated with one candidate target PCell, the network provides multiple conditional configurations for the same candidate target PCell, i.e., each configuration contains one MCG configuration (for the same candidate target PCell) and one SCG configuration (for one of the multiple associated candidate PSCells). For this case, the network may also provide a complementary CHO only configuration, i.e., there is execution condition only for candidate PCell.

[0163] The network provides the configuration parameters for the target SpCell(s) in thecondRRCReconfig.

[0164] In NR-DC, the UE may receive two independentconditionalReconfiguration:

[0165] - aconditionalReconfigurationassociated with MCG, that is included in theRRCReconfigurationmessage received via SRB1; and

[0166] - aconditionalReconfiguration, associated with SCG, that is included in theRRCReconfigurationmessage received via SRB3, or, alternatively, included within aRRCReconfigurationmessage embedded in aRRCReconfigurationmessage received via SRB1.

[0167] In this case:

[0168] - the UE maintains two independentVarConditionalReconfig, one associated with eachconditionalReconfiguration;

[0169] - the UE independently performs all the conditional reconfiguration procedures for eachconditionalReconfigurationand the associatedVarConditionalReconfig, unless explicitly stated otherwise;

[0170] - the UE performs the measurement procedures for theVarConditionalReconfigassociated with the same cell group like themeasConfig.

[0171] In EN-DC, theVarConditionalReconfigis associated with the SCG.

[0172] In NE-DC and when no SCG is configured, theVarConditionalReconfigis associated with the MCG.

[0173] The UE performs the following actions based on a receivedConditionalReconfigurationIE:

[0174] 1> if theConditionalReconfigurationcontains thecondReconfigToRemoveList:

[0175] 2> perform conditional reconfiguration removal procedure;

[0176] 1> if theConditionalReconfigurationcontains thecondReconfigToAddModList:

[0177] 2> perform conditional reconfiguration addition / modification;

[0178] 1> if theConditionalReconfigurationcontains thescpac-ReferenceConfiguration:

[0179] 2> perform subsequent CPAC reference configuration addition / removal;

[0180] 1> if theConditionalReconfigurationcontains thesk-CounterConfiguration:

[0181] 2> performsk-CounterListaddition / modification / removal;

[0182] 1> if theConditionalReconfigurationcontains theservingSecurityCellSetId:

[0183] 2> if the currentVarServingSecurityCellSetIDincludesservingSecurityCellSetId:

[0184] 3> replace theservingSecurityCellSetIdvalue withinVarServingSecurityCellSetIDwith the receivedservingSecurityCellSetID;

[0185] 2> else:

[0186] 3> store the receivedservingSecurityCellSetIdwithinVarServingSecurityCellSetID.

[0187] I. Conditional reconfiguration removal

[0188] The UE shall:

[0189] 1> for eachcondReconfigIdvalue included in thecondReconfigToRemoveListthat is part of the current UE conditional reconfiguration inVarConditionalReconfig:

[0190] 2> remove the entry with the matchingcondReconfigIdfrom theVarConditionalReconfig;

[0191] The UE does not consider the message as erroneous if thecondReconfigToRemoveListincludes any condReconfigIdvalue that is not part of the current UE configuration.

[0192] II. Conditional reconfiguration addition / modification

[0193] For eachcondReconfigIdreceived in thecondReconfigToAddModListIE the UE shall:

[0194] 1> if an entry with the matchingcondReconfigIdexists in thecondReconfigToAddModListwithin theVarConditionalReconfig:

[0195] 2> if the entry incondReconfigToAddModListincludes ancondExecutionCond,condExecutionCondSCG, orcondExecutionCondPSCell;

[0196] 3> replacecondExecutionCond,condExecutionCondSCG, orcondExecutionCondPSCellwithin theVarConditionalReconfigwith the value received for thiscondReconfigId;

[0197] 2> if the entry incondReconfigToAddModListincludessubsequentCondReconfigcontainingcondExecutionCondToAddModList:

[0198] 3> for eachcondReconfigIdreceived incondExecutionCondToAddModList:

[0199] 4> if an entry with the matchingcondReconfigIdexists in thecondExecutionCondToAddModListwithinVarConditionalReconfig;

[0200] 5> replace the entry incondExecutionCondToAddModListwithinVarConditionalReconfigwith the value received for thiscondReconfigId;

[0201] 4> else:

[0202] 5> add a new entry incondExecutionCondToAddModListwithinVarConditionalReconfigwith the value received for thiscondReconfigId;

[0203] 2> if the entry incondReconfigToAddModListincludessubsequentCondReconfigcontainingcondExecutionCondToReleaseList:

[0204] 3> for eachcondReconfigIdreceived incondExecutionCondToReleaseListthat is part of current storedcondExecutionCondToAddModListwithinVarConditionalReconfig:

[0205] 4> remove the entry incondExecutionCondToAddModListwithinVarConditionalReconfigwith the value received for thiscondReconfigId;

[0206] The UE does not consider the message as erroneous if thecondExecutionCondToReleaseListincludes anycondReconfigIdvalue that is not part of the current UE configuration.

[0207] 2> if the entry incondReconfigToAddModListincludes asecurityCellSetId;

[0208] 3> replacesecurityCellSetIdwithin theVarConditionalReconfigwith the value received for thiscondReconfigId;

[0209] The UE should release the entry withinVarServingSecurityCellSetIDin case all the subsequent CPAC configurations are released.

[0210] 2> if the entry incondReconfigToAddModListincludes acondRRCReconfig;

[0211] 3> replacecondRRCReconfigwithin theVarConditionalReconfigwith the value received for thiscondReconfigId;

[0212] 1> else:

[0213] 2> add a new entry for thiscondReconfigIdwithin theVarConditionalReconfig;

[0214] 1> perform conditional reconfiguration evaluation.

[0215] III. Conditional reconfiguration evaluation

[0216] The UE shall:

[0217] 1> for eachcondReconfigIdwithin theVarConditionalReconfig:

[0218] 2> if theRRCReconfigurationwithincondRRCReconfigincludes themasterCellGroupincluding thereconfigurationWithSync:

[0219] 3> if the associatedcondExecutionCondPSCellis configured:

[0220] 4> consider the cell which has a physical cell identity matching the value indicated in theServingCellConfigCommonincluded in thereconfigurationWithSyncwithin themasterCellGroupin the receivedcondRRCReconfigto be applicable cell; and

[0221] 4> consider the cell which has a physical cell identity matching the value indicated in theServingCellConfigCommonincluded in thereconfigurationWithSyncwithin thesecondaryCellGroupwithin thenr-SCGwithin the receivedcondRRCReconfigto be applicable cell;

[0222] 3> else:

[0223] 4> consider the cell which has a physical cell identity matching the value indicated in theServingCellConfigCommonincluded in thereconfigurationWithSyncwithin themasterCellGroupin the receivedcondRRCReconfigto be applicable cell;

[0224] 2> else if theRRCReconfigurationwithincondRRCReconfigincludes thesecondaryCellGroupincluding thereconfigurationWithSync:

[0225] 3> if the cell which has a physical cell identity matching the value indicated in theServingCellConfigCommonincluded in thereconfigurationWithSyncwithin thesecondaryCellGroupwithin the receivedcondRRCReconfigis not the PSCell:

[0226] 4> ifsubsequentCondReconfigis not included for thecondReconfigId; or

[0227] 4> ifsubsequentCondReconfigis not included for the PSCell; or

[0228] 4> ifsubsequentCondReconfigis included for thecondReconfigIdand there is asubsequentCondReconfigfor the PSCell with a matchingcondReconfigIdvalue incondExecutionCondToAddModList:

[0229] 5> consider the cell to be applicable cell;

[0230] 2> ifcondExecutionCondSCGis configured:

[0231] 3> in the remainder of the procedure, consider eachmeasIdindicated in thecondExecutionCondSCGas ameasIdin theVarMeasConfigassociated with the SCGmeasConfig;

[0232] 2> if thecondExecutionCondPSCellis configured:

[0233] 3> in the remainder of the procedure, consider eachmeasIdindicated in thecondExecutionCondPSCellas ameasIdin theVarMeasConfigassociated with the MCGmeasConfig;

[0234] 2> ifcondExecutionCondis configured:

[0235] 3> if it is configured via SRB3 or configured withinnr-SCGor withinnr-SecondaryCellGroupConfigvia SRB1:

[0236] 4> in the remainder of the procedure, consider eachmeasIdindicated in thecondExecutionCondas ameasIdin theVarMeasConfigassociated with the SCGmeasConfig;

[0237] 3> else:

[0238] 4> in the remainder of the procedure, consider eachmeasIdindicated in thecondExecutionCondas ameasIdin theVarMeasConfigassociated with the MCGmeasConfig;

[0239] 2> for eachmeasIdincluded in themeasIdListwithinVarMeasConfigindicated in thecondExecutionCond, condExecutionCondSCG,orcondExecutionCondPSCellof thecondReconfigId:

[0240] 3> ifcondExecutionCond,condExecutionCondSCG, andsubsequentCondReconfigare included for thecondReconfigId:

[0241] 4> ignore themeasId(s)in thecondExecutionCondof thecondReconfigId;

[0242] 3> if thecondTriggerConfigis not configured withnesEvent:

[0243] 4> if thecondEventIdis associated withcondEventT1, and if the entry condition applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cell; or

[0244] 4> if thecondEventIdis associated withcondEventD1orcondEventD2, and if the entry conditions applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cell during the correspondingtimeToTriggerdefined for this event within theVarConditionalReconfig; or

[0245] 4> if thecondEventIdis associated withcondEventA3,condEventA4orcondEventA5, and if the entry condition(s) applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cells for all measurements after layer 3 filtering taken during the correspondingtimeToTriggerdefined for this event within theVarConditionalReconfig:

[0246] 5> consider the event associated to thatmeasIdto be fulfilled;

[0247] 4> if themeasIdfor this event associated with thecondReconfigIdhas been modified; or

[0248] 4> if thecondEventIdis associated withcondEventT1, and if the leaving condition applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cell; or

[0249] 4>if thecondEventIdis associated withcondEventD1orcondEventD2, and if the leaving condition(s) applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cell during the correspondingtimeToTriggerdefined for this event within theVarConditionalReconfig; or

[0250] 4> if thecondEventIdis associated withcondEventA3,condEventA4orcondEventA5, and if the leaving condition(s) applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cells for all measurements after layer 3 filtering taken during the correspondingtimeToTriggerdefined for this event within theVarConditionalReconfig:

[0251] 5> consider the event associated to thatmeasIdto be not fulfilled;

[0252] 3> else:

[0253] 4> if NES mode indication is received from lower layers, indicating that the NES-specific CHO execution condition of the PCell is enabled; and

[0254] 4> if the entry condition(s) applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cells for all measurements after layer 3 filtering taken during the correspondingtimeToTriggerdefined for this event within theVarConditionalReconfig:

[0255] 5> consider the event associated to thatmeasIdto be fulfilled;

[0256] 4> if themeasIdfor this event associated with thecondReconfigIdhas been modified; or

[0257] 4> if NES mode indication is received from lower layers, indicating that the NES-specific CHO execution condition of the PCell is disabled; or

[0258] 4> if the leaving condition(s) applicable for this event associated with thecondReconfigId, i.e. the event corresponding with thecondEventId(s)of the correspondingcondTriggerConfigwithinVarConditionalReconfig, is fulfilled for the applicable cells for all measurements after layer 3 filtering taken during the correspondingtimeToTriggerdefined for this event within theVarConditionalReconfig:

[0259] 5> consider the event associated to thatmeasIdto be not fulfilled;

[0260] 2> ifcondExecutionCondPSCellis not configured:

[0261] 3> if event(s) associated to allmeasId(s) withincondTriggerConfigfor the applicable cell are fulfilled:

[0262] 4> consider the applicable cell, associated to thatcondReconfigId, as a triggered cell;

[0263] 4> initiate the conditional reconfiguration execution;

[0264] 2> else:

[0265] 3> if event(s) associated to allmeasId(s), as indicated in thecondExecutionCondandcondExecutionCondPSCell,withincondTriggerConfigfor a target candidate cell within the storedcondRRCReconfigare fulfilled:

[0266] 4> consider the target candidate PCell within the storedcondRRCReconfig, associated to thatcondReconfigId, as a triggered PCell;

[0267] 4> consider the target candidate PSCell within the storedcondRRCReconfig, associated to thatcondReconfigId, as a triggered PSCell;

[0268] 4> initiate the conditional reconfiguration execution;

[0269] 2> if one of the events associated to themeasIds withincondTriggerConfigfor the applicable cell within the storedcondRRCReconfigis not configured withnesEvent, and the other event associated to themeasIds withincondTriggerConfigfor the applicable cell within the storedcondRRCReconfigis configured withnesEvent, and at least one of them is fulfilled:

[0270] 3> consider the applicable cell within the storedcondRRCReconfig, associated to thatcondReconfigId, as a triggered cell;

[0271] 3> initiate the conditional reconfiguration execution.

[0272] Up to 2MeasIdcan be configured for eachcondReconfigId, ifcondExecutionCondPSCellis not configured.The conditional reconfiguration event of the 2MeasIdmay have the same or different event conditions, triggering quantity, time to trigger, and triggering threshold.

[0273] For CHO with candidate SCG(s), up to 2MeasIdcan be configured forcondExecutionCondandup to 2MeasIdcan be configured forcondExecutionCondPSCellfor eachcondReconfigId.

[0274] IV. Conditional reconfiguration execution

[0275] The UE shall:

[0276] 1> if more than one pair of triggered PCell and associated triggered PSCell exist:

[0277] 2> select one of the triggered PCell(s) and the associated triggered PSCell(s) as the selected cells for conditional reconfiguration execution;

[0278] 1> else if only one pair of triggered PCell and associated triggered PSCell exists:

[0279] 2> consider the triggered PCell and the associated triggered PSCell as the selected cells for conditional reconfiguration execution;

[0280] 1> else if more than one triggered cell exists:

[0281] 2> select one of the triggered cells as the selected cell for conditional reconfiguration execution;

[0282] 1> else:

[0283] 2> consider the triggered cell as the selected cell for conditional reconfiguration execution;

[0284] 1> for the selected cell(s) of conditional reconfiguration execution:

[0285] 2> if thesubsequentCondReconfigis included in the entry inVarConditionalReconfigcontaining theRRCReconfigurationmessage for the selected cell:

[0286] 3> perform the subsequent CPAC execution;

[0287] 2> else:

[0288] 3> apply the storedcondRRCReconfigof the selected cell and perform the actions upon receiving / applying theRRCReconfigurationmessage in thecondRRCReconfig(i.e., perform a mobility to the corresponding SpCell / target cell based on theRRCReconfigurationmessage in thecondRRCReconfig).

[0289] If multiple NR cells are triggered in conditional reconfiguration execution, it is up to UE implementation which one to select, e.g. the UE considers beams and beam quality to select one of the triggered cells for execution.

[0290] V. Subsequent CPAC reference configuration addition / removal

[0291] The UE shall:

[0292] 1> if thescpac-ReferenceConfigurationis set tosetup:

[0293] 2> ifscpac-ReferenceConfigurationexists within theVarConditionalReconfig:

[0294] 3> replace thescpac-ReferenceConfigurationwithin theVarConditionalReconfig;

[0295] 2> else:

[0296] 3> store thescpac-ReferenceConfigurationwithin theVarConditionalReconfig;

[0297] 1> else (ifscpac-ReferenceConfigurationis set torelease):

[0298] 2> remove thescpac-ReferenceConfigurationwithin theVarConditionalReconfig;

[0299] VI.sk-Counterconfiguration addition / modification / removal

[0300] The UE shall:

[0301] 1> for eachsecurityCellSetIdreceived in thesk-CounterConfigToAddModListIE:

[0302] 2> if an entry with the matchingsecurityCellSetIdexists in thesk-CounterConfigToAddModListwithin theVarConditionalReconfig:

[0303] 3> replace thesk-CounterListwithin theVarConditionalReconfigwith thesk-CounterListaccording to the receivedsecurityCellSetId;

[0304] 2> else:

[0305] 3> add a new entry for thissecurityCellSetIdwithin theVarConditionalReconfig;

[0306] 1> for eachsecurityCellSetIdvalue included in thesk-CounterConfigToRemoveListthat is part of the currentsk-CounterConfigToAddModListinVarConditionalReconfig:

[0307] 2> remove the entry with the matchingsecurityCellSetIdfrom thesk-CounterConfigToAddModList;

[0308] VII. Subsequent CPAC execution

[0309] Upon the conditional reconfiguration execution for subsequent CPAC, the UE shall:

[0310] 1> if the selected subsequent CPAC candidate configuration is stored in MCGVarConditionalReconfig:

[0311] 2> for each SRB / DRB in current UE configuration:

[0312] - keep the associated RLC, PDCP and SDAP entities, their state variables, buffers and timers;

[0313] - release all fields related to the SRB / DRB configuration except forsrb-Identity,drb-Identity, andsecurityConfig;

[0314] 2> release / clear all current dedicated radio configuration except for the following:

[0315] - the MCG C-RNTI;

[0316] - the AS security configurations associated with the master key and the secondary key;

[0317] - thelogicalChannelIdentityandlogicalChannelIdentityExtof RLC bearers configured in RLC-BearerConfig and the associated RLC entities, their state variables, buffers, and timers;

[0318] - the bh-LogicalChannelIdentityof BH RLC channels configured inBH-RLC-ChannelConfigand the associated RLC entities, their state variables, buffers, and timers;

[0319] - the UE variablesVarConditionalReconfigandVarServingSecurityCellSetID;

[0320] - the logged measurement configuration.

[0321] 2> release / clear all current common radio configuration, except for theServingCellConfigCommonof the PCell;

[0322] 2> apply the default MAC Cell Group configuration for MCG MAC and SCG MAC;

[0323] 2> use the default values for timers T310, T311 and constants N310, N311, where T310, N310, and N311 are for both MCG and SCG, and T311 is only for the MCG;

[0324] 2> apply the default L1 parameter values as specified in corresponding physical layer specifications for the MCG and SCG;

[0325] 1> else:

[0326] 2> for each SRB / DRB in current UE configuration:

[0327] - keep the associated PDCP and SDAP entities, their state variables, buffers and timers;

[0328] - release all fields related to the SRB / DRB configuration except forsrb-Identity,drb-Identity, andsecurityConfig;

[0329] 2> release / clear all current dedicated radio configuration associated with the SCG except for the following:

[0330] - the AS security configurations associated with the secondary key;

[0331] - the UE variablesVarConditionalReconfig.

[0332] 2> release / clear all current common radio configuration associated with the SCG;

[0333] 2> apply the default MAC Cell Group configuration for the SCG MAC;

[0334] 2> use the default values for timer T310 and constants N310 and N311 for the SCG;

[0335] 2> apply the default L1 parameter values as specified in corresponding physical layer specifications for the SCG;

[0336] 1> if thesecurityCellSetIdis included in the entry inVarConditionalReconfigcontaining theRRCReconfigurationmessage:

[0337] 2> ifservingSecurityCellSetIdis not included withinVarServingSecurityCellSetID; or

[0338] 2> if the value of thesecurityCellSetIdis not equal to the value ofservingSecurityCellSetIdwithinVarServingSecurityCellSetID:

[0339] 3> consider the firstsk-Countervalue in thesk-CounterListassociated with thesecurityCellSetIdwithin theVarConditionalReconfigas the selectedsk-Countervalue, and perform security key update procedure;

[0340] 3> remove the selectedsk-Countervalue from thesk-CounterListassociated with thesecurityCellSetIdwithin theVarConditionalReconfig;

[0341] 3> if the currentVarServingSecurityCellSetIDincludesservingSecurityCellSetId:

[0342] 4> replace the value ofservingSecurityCellSetIdwithinVarServingSecurityCellSetIDwith the value ofsecurityCellSetIdassociated with the selected cell;

[0343] 3> else:

[0344] 4> store theservingSecurityCellSetIdwithinVarServingSecurityCellSetIDwith the value ofsecurityCellSetIdassociated with the selected cell;

[0345] 1> if the selected subsequent CPAC candidate configuration is stored in the SCGVarConditionalReconfig:

[0346] 2> for eachdrb-Identityvalue included in eachRadioBearerConfigin the selected subsequent CPAC candidate configuration that is part of the current UE configuration, the UE shall perform the following actions after the end of this procedure:

[0347] 3> if the bearer is an AM DRB:

[0348] 4> trigger the PDCP entity of the bearer to perform PDCP data recovery;

[0349] 3> re-establish the corresponding RLC entity;

[0350] 1> else:

[0351] 2> for eachdrb-Identityvalue included in eachRadioBearerConfigin the selected subsequent CPAC candidate configuration that is part of the current UE configuration, the UE shall perform the following actions after the end of this procedure:

[0352] 3> if thekeyToUsein theRadioBearerConfigis different from thekeyToUsein the current UE configuration; or

[0353] 3> if the bearer is associated with the secondary key (S-KgNB) as indicated bykeyToUsein the current UE configuration and a newsk-Countervalue has been selected due to the conditional reconfiguration execution for subsequent CPAC:

[0354] 4> if the PDCP entity of this DRB is not configured withcipheringDisabled:

[0355] 5> configure the PDCP entity with the ciphering algorithm and KUPenc key associated with the master key (KgNB) or the secondary key (S-KgNB), as indicated inkeyToUse, i.e., the ciphering configuration shall be applied to all subsequent PDCP PDUs received and sent by the UE;

[0356] 4> if the PDCP entity of this DRB is configured withintegrityProtection:

[0357] 5> configure the PDCP entity with the integrity protection algorithms according tosecurityConfigand apply the KUPint key associated with the master key (KgNB) or the secondary key (S-KgNB) as indicated inkeyToUse;

[0358] 4> ifdrb-ContinueROHCis included inpdcp-Config:

[0359] 5> indicate to lower layer thatdrb-ContinueROHCis configured;

[0360] 4> ifdrb-ContinueEHC-DLis included inpdcp-Config:

[0361] 5> indicate to lower layer thatdrb-ContinueEHC-DLis configured;

[0362] 4> ifdrb-ContinueEHC-ULis included inpdcp-Config:

[0363] 5> indicate to lower layer thatdrb-ContinueEHC-ULis configured;

[0364] 4> ifdrb-ContinueUDCis included inpdcp-Config:

[0365] 5> indicate to lower layer thatdrb-ContinueUDCis configured;

[0366] 4> re-establish the corresponding RLC entity;

[0367] 4> trigger the PDCP entity of the bearer to perform PDCP re-establishment;

[0368] 3> else:

[0369] 4> if there is an associated SCG RLC bearer in the selected subsequent CPAC candidate configuration that is part of the current UE configuration:

[0370] 5> re-establish the SCG RLC entity;

[0371] 4> if the RLC entity of the associated RLC bearer(s) is re-established; or

[0372] 4> if an associated RLC bearer is released in the selected subsequent CPAC candidate configuration:

[0373] 5> if the bearer is an AM DRB:

[0374] 6> trigger the PDCP entity of the bearer to perform PDCP data recovery;

[0375] 2> for eachsrb-Identityincluded inRadioBearerConfigthat is part of the current UE configuration and if the radio bearer is SRB3 or SRB5, the UE shall perform the following actions after the end of this procedure:

[0376] 3> if a newsk-Countervalue has been selected due to the conditional reconfiguration execution for subsequent CPAC:

[0377] 4> configure the PDCP entity to apply the integrity protection algorithm and KRRCint key associated with the secondary key (S-KgNB) as indicated inkeyToUse, i.e. the integrity protection configuration shall be applied to all subsequent messages received and sent by the UE, including the message used to indicate the successful completion of the procedure;

[0378] 4> configure the PDCP entity to apply the ciphering algorithm and KRRCenc key associated with the secondary key (S-KgNB) as indicated inkeyToUse, i.e. the ciphering configuration shall be applied to all subsequent messages received and sent by the UE, including the message used to indicate the successful completion of the procedure;

[0379] 4> trigger the PDCP entity of SRB to perform PDCP re-establishment;

[0380] 3> else:

[0381] 4> trigger the PDCP entity of SRB to perform SDU discard;

[0382] 3> re-establish the corresponding RLC entity;

[0383] 1> ifscpac-ConfigCompleteis not included within theVarConditionalReconfigfor the selected cell:

[0384] 2> if the subsequent CPAC candidate cell configuration is stored in MCGVarConditionalReconfig:

[0385] 3> considerscpac-ReferenceConfigurationin MCGVarConditionalReconfigto be the current UE configuration;

[0386] 2> else:

[0387] 3> considerscpac-ReferenceConfigurationin SCGVarConditionalReconfigto be the current SCG configuration;

[0388] When the UE considers the reference configuration to be the current UE configuration, the UE should store fields and configurations that are part of the reference configuration but should not execute any actions or procedures triggered by the reception of anRRCReconfigurationmessage.

[0389] 1> apply the storedcondRRCReconfigof the selected cell(s) and perform the actions upon receiving / applying theRRCReconfigurationmessage in thecondRRCReconfig(i.e., perform a mobility to the corresponding SpCell / target cell based on theRRCReconfigurationmessage in thecondRRCReconfig);

[0390] 1> release the radio bearer(s) and the associated logical channel(s) that are part of the current UE configuration but not part of the subsequent CPAC candidate configuration for the selected cell, or the subsequent CPAC reference configuration (in case the subsequent CPAC candidate configuration does not includescpac-ConfigComplete).

[0391] Whenscpac-ConfigCompleteis not included for the selected cell, before a subsequent CPAC execution, a UE implementation may generate and store an RRC reconfiguration message by applying the received subsequent CPAC candidate configuration on top of the subsequent CPAC reference configuration, and the stored RRC reconfiguration message is applied for subsequent CPAC execution. The UE needs to ensure that the RRC reconfiguration applied at the time of subsequent CPAC execution is in accordance with the latest receivedscpac-ReferenceConfigurationandcondRRCReconfigfor the subsequent CPAC configuration.

[0392] The UE may perform AS security key update procedure (or, security key update procedure) as follows:

[0393] 1> if this procedure was initiated due to reception of thesk-Counter(UE is in NE-DC, or NR-DC, or is configured with SN terminated bearer(s)) or if the procedure was initiated due to selection of ansk-Counterfor conditional reconfiguration execution for subsequent CPAC (UE is in NR-DC):

[0394] 2> derive or update the secondary key (S-KgNB or S-KeNB) based on the KgNB key and using the received or selectedsk-Countervalue;

[0395] 2> derive the KRRCenc key and the KUPenc key using the ciphering algorithms indicated in theRadioBearerConfigassociated with the secondary key (S-KgNB or S-KeNB) as indicated bykeyToUse;

[0396] 2> derive the KRRCint key and the KUPint key using the integrity protection algorithms indicated in theRadioBearerConfigassociated with the secondary key (S-KgNB or S-KeNB) as indicated bykeyToUse.

[0397] If the UE has no radio bearer configured withkeyToUseset tosecondaryand receives thesk-Counteror ansk-Counteris selected for subsequent CPAC without anyRadioBearerConfigwithkeyToUseset tosecondary, the UE does not consider it as an invalid reconfiguration.

[0398] When a (new)sk-Countervalue has been selected due to the subsequent CPAC execution, the UE may transmit anRRCReconfigurationCompletemessage including the selectedsk-Countervalue. That is, upon execution of the conditional reconfiguration (CHO, CPA, CPC, or subsequent CPAC), the UE shall:

[0399] 1> set the content of theRRCReconfigurationCompletemessage as follows:

[0400] 2> if theRRCReconfigurationmessage includes themrdc-SecondaryCellGroupConfigwithmrdc-SecondaryCellGroupset tonr-SCG:

[0401] 3> include in thenr-SCG-Responsethe SCGRRCReconfigurationCompletemessage;

[0402] 3> if theRRCReconfigurationmessage is applied due to conditional reconfiguration execution and theRRCReconfigurationmessage does not include thereconfigurationWithSyncin themasterCellGroup:

[0403] 4> include in theselectedCondRRCReconfigthecondReconfigIdfor the selected cell of conditional reconfiguration execution;

[0404] 4> if a newsk-Countervalue has been selected due to the conditional reconfiguration execution for subsequent CPAC:

[0405] 5> includeselectedSK-Counterand set its value to the selectedsk-Countervalue.

[0406] Meanwhile, the UE may receive multiple security keys (e.g.,sk-Counter) in advance for each cell group (i.e., per gNB) to perform subsequent conditional mobility (e.g., subsequent CPAC). When the UE performs conditional mobility to a target cell and the target cell belongs to a different cell group (i.e., during inter-gNB mobility), the UE may select unused security key of a cell group that includes the target cell to perform a security update. In this case, there might be cases where the network and the UE have a mismatch in the information regarding the used security keys, and / or the network may have failed to appropriately update the multiple security keys, resulting in no unused security key being available for the security update.

[0407] When there is a security key mismatch, the conditional mobility (e.g., subsequent conditional mobility) may fail. For example, upon an execution of the conditional mobility to a target cell (i.e., when applying the target cell configuration (e.g.,RRCReconfigurationmessage) for the conditional mobility), the UE may start a T304 timer in accordance with the target cell configuration and attempt access (e.g., contention-based random access, contention-free random access, RACH-less access) to the target cell while the T304 timer is running.

[0408] During and / or after the access, the UE may transmit a message (e.g.,RRCReconfigurationCompletemessage), which is protected using security key(s) derived based on e.g.,sk-Counterinsk-CounterListfor a cell group including the target cell (or, gNB associated with the target cell). However, if the security key used by the UE does not match the key expected by the network (e.g., gNB associated with the target cell), the network may fail to verify the security of the received message (i.e., detect / declare a security failure such as security mode failure, integrity check failure for the received message). In such a case, the network may discard the message without sending a response.

[0409] If the UE does not receive any response from the network within the duration of the T304 timer, the conditional mobility procedure may be considered to have failed. As a result, the T304 timer expires, and the UE may initiate a re-establishment procedure and / or perform a connection recovery process.

[0410] This mismatch issue may be likely to occur more frequently as there are more cases that support subsequent conditional mobility (e.g., applying conditional mobility during the RRC re-establishment procedure and / or applying conditional mobility while resuming the RRC connection from the RRC inactive state).

[0411] Therefore, it will be helpful for the network if the network knows which security keys have been used and when the security keys have been selected to prevent further security failure in various conditional mobility scenarios.

[0412] FIG. 9 shows an example of a method performed by a UE for security information reporting according to an embodiment of the present disclosure.

[0413] Referring to FIG. 9, in step S901, the UE may receive a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys.

[0414] In step S903, the UE may initiate a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations.

[0415] In step S905, the UE may perform a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility.

[0416] In step S907, the UE may transmit security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0417] According to various embodiments, the list of security keys is configured for each base station, or for each cell group.

[0418] According to various embodiments, while performing the security key update procedure using the selected security key, the UE may derive or update one or more keys for at least one of integrity proception or ciphering of communication using the selected security key.

[0419] According to various embodiments, after performing the security key update procedure using the security key selected in the list of security keys, the UE may remove the security key selected and used for the security key update procedure from the list of security keys.

[0420] According to various embodiments, the UE may log the selected security key in logging results before removing the selected security key.

[0421] According to various embodiments, the one or more used security keys may include security keys selected and used for the security key update procedure. The one or more unused security keys may include security keys remaining in the list of security keys after security key removal.

[0422] According to various embodiments, the security information may further comprise at least one of: target cell information comprising at least one of a target cell identity, global cell identity, or conditional reconfiguration identity; information for a time of the security key being selected; a mobility type comprising at least one of a conditional handover (CHO), a conditional primary secondary cell (PSCell) addition (CPA) or a conditional PSCell change (CPC); a mobility result comprising at least one of a mobility failure or a mobility success; or a failure cause in case of the mobility failure.

[0423] According to various embodiments, the UE may log the security information in logging results. The UE may transmit the logging results comprising the security information.

[0424] According to various embodiments, upon performing the security key update procedure, the UE may log at least part of the security information in the logging results.

[0425] According to various embodiments, upon detecting a failure of the conditional mobility, the UE may log at least part of the security information in the logging results.

[0426] According to various embodiments, the UE may transmit an availability of the logging results. The UE may receive a request for the logging results after transmitting the availability of the logging results. The UE may transmit the logging results comprising the security information upon receiving the request.

[0427] According to various embodiments, the conditional mobility may comprise a subsequent conditional mobility that is performed based on a corresponding conditional reconfiguration without releasing other conditional reconfigurations after each mobility completion.

[0428] FIG. 10 shows an example of a signal flow between UE and network for security information reporting according to an embodiment of the present disclosure.

[0429] Referring to FIG. 10, in step S1001, network node may transmit, to the UE, a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys.

[0430] In step S1003, the UE may initiate a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations.

[0431] In step S1005, the UE may perform a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility.

[0432] In step S1007, network node may receive, from the UE, security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0433] Hereinafter, detailed implementations related to security information reporting will be described

[0434] According to implementations of the present disclosure, whenever performing mobility, the UE may determine whether the UE logs security information based on a used security key. If there is a (newly) selected security key for security update of subsequent conditional mobility, the UE may log the security information related to the (newly) selected security key.

[0435] For the subsequent conditional mobility, the network may provide a pre-configuration that includes one or more candidate cell identities (or, one or more conditional reconfiguration identities), one or more candidate cell configurations, and / or one or more execution conditions to initiate mobility to the corresponding candidate cell. The network may also provide one or more security key values (e.g.,sk-counterand / or next hop chaining count (NCC)) for candidate cells in the pre-configuration. The one or more security key values may be grouped per node (e.g., gNB) and / or per cell group, and provided as a list.

[0436] For the security information, the following information can be included for logging upon initiation of a mobility:

[0437] - (newly) selected security key value: the UE may select an unused security key that is available to a candidate cell among the one or more security keys as the (newly) selected security key value if the candidate cell is a target cell for the subsequent conditional mobility. The UE may either randomly select one of the available security keys or may select a security key sequentially from the beginning or the end in a group / list of the one or more security key values;

[0438] - Target cell information: target cell identity, global cell identity, and / or conditional reconfiguration identity can be included for the target cell information;

[0439] - The time of selecting the (newly) selected security key value;

[0440] - Mobility purpose(or, mobility type): The UE may indicate which mobility type such as CHO, LTM, CPA, CPC, is initiated for the target cell. The UE may also log a mobility type for the current mobility indicating whether the mobility is failure recovery or not;

[0441] - Mobility result: The UE may log the result of the mobility trial indicating whether the mobility trial was successful or failed. The mobility trial may include the case of the failure recovery;

[0442] - Failure cause: In case of the failure, the UE may include the failure cause of the mobility trial. The failure cause can be a security mismatch between the network and the UE, no available security key, mobility validity timer (e.g., timer T304) expiry (or, random access failure), and / or random access channel (RACH) skip failure; and / or

[0443] - The rest of unused security key information: the UE may indicate the rest of the available / unused security keys in the pre-configuration. This information can be helpful for the network to figure out the security key mismatch issue between the network and the UE precisely.

[0444] For logging the mobility result and / or the failure cause, the UE may log the above information after / when mobility is (either successfully or unsuccessfully) completed, or before mobility is (either successfully or unsuccessfully) completed.

[0445] The UE may initialize the logs of the security information if the network provides updated security information related to the one or more security keys in the pre-configuration.

[0446] Each time the UE establishes an RRC connection, the UE may check whether the security information has been logged. During the (re)establishment or resumption of the RRC connection, the UE may notify the network of an availability of the logging results comprising logged security information and / or report the logging results. If the UE is (re-)establishing the RRC connection, the UE may first inform the network of the availability of the logging results via RRC signaling. If the UE is resuming the suspended RRC connection, the UE can directly report the logging results to the network via RRC signaling.

[0447] FIG. 11 shows an example of a method for logging security information when a subsequent mobility succeeds according to an embodiment of the present disclosure. In FIG. 11, UE may log at least part of the security information before mobility complete.

[0448] Referring to FIG. 11, in step S1101, the UE may receive RRC reconfiguration message including a pre-configuration for subsequent mobility. In the pre-configuration, multiple candidate cell configurations (i.e., multiple RRC reconfiguration messages) with candidate cell identities (or, conditional reconfiguration identities) and / or multiple execution conditions to initiate the subsequent mobility may be included. Also, in the pre-configuration, security key lists (e.g.,sk-CounterList) which comprise multiple security key values per gNB (or, per cell group) may be included for the subsequent mobility. Also, the network may configure a logging configuration / information (e.g.,successHO-Config) to allow logging of security information for the subsequent mobility only when at least one of the conditions (e.g.,thresholdPercentageT304,thresholdPercentageT310, orthresholdPercentageT312) which are included in the logging configuration is met. The condition for the logging can be a new information that the UE is allowed logging if there is no available security key value for the subsequent mobility.

[0449] In step S1103, the UE may evaluate the multiple execution conditions for the subsequent mobility.

[0450] In step S1105, the UE may initiate the subsequent mobility to a candidate cell for which at least one of the multiple execution conditions is met. The UE may decide to perform the subsequent mobility to a candidate cell if at least one of the multiple execution conditions is met for the candidate cell in the pre-configuration. The UE may start a timer (e.g., T304) for mobility to check the validity of the mobility.

[0451] In step S1107, the UE may perform a security key update procedure using a selected security key value. While the timer is running, the UE may apply the corresponding candidate cell configuration for the subsequent mobility and the UE may update security information by a gNB key derivation based on a (newly) selected security key value from the security key lists in the pre-configuration.

[0452] In step S1109, when updating the security information and / or upon updating the security information, the UE may log security information with the (newly) selected security key value and related information. In case the network has configured the logging configuration / information (e.g.,successHO-Config), the UE may first check if one of the conditions is met for logging. If the logging conditions have been provided but have not been met, the UE may skip logging for the security information. For logging of the security information, the UE can optionally log the following information:

[0453] - (newly) selected security key value;

[0454] - Target cell information: target cell identity, global cell identity, and / or conditional reconfiguration identity can be included for the target cell information;

[0455] - The time of selecting the (newly) selected security key value;

[0456] - Mobility purpose(or, mobility type): For example, PCell handover; and / or

[0457] - The rest of the unused security key list per gNB.

[0458] In step S1111, the UE may successfully complete the subsequent mobility. The UE may further log the mobility result as a success (i.e., mobility result: success) for logging the security information.

[0459] In step S1113, the UE may report the logged security information to the network. For example, when indicating the successful mobility to the network, the UE may send RRC reconfiguration complete message to the target cell. When sending the RRC reconfiguration complete message, the UE may notify the network of availability of the logging results comprising the logged security information. For example, the availability of the logging results may comprisemobilityHistoryAvail,successHO-InfoAvailableand / orsuccessPSCell-InfoAvailable. Alternatively, the UE may report the logging results (e.g.,mobilityHistoryReport,successHO-Reportand / orsuccessPSCell-Report).

[0460] For the case of the UE notifying the availability of the logging results, the network may request the logging results via RRC dedicated message (e.g., UE information request message). If so, the UE may include the logging results and respond to the network via RRC dedicated message(e.g., UE information response message).

[0461] FIG. 12 shows an example of a method for logging security information when a subsequent mobility fails according to an embodiment of the present disclosure. In FIG. 12, UE may log at least part of the security information after mobility failure.

[0462] Referring to FIG. 12, in step S1201, UE may receive RRC reconfiguration message including a pre-configuration for subsequent mobility. In the pre-configuration, multiple candidate cell configurations (i.e., multiple RRC reconfiguration messages) with candidate cell identities (or, conditional reconfiguration identities) and multiple execution conditions to initiate the subsequent mobility. Also, in the pre-configuration, security key lists which are multiple security key values per gNB (or, per cell group) may be included for the subsequent mobility. Also, the network may configure a logging configuration / information to allow the logging of security information for the subsequent mobility only when at least one of the conditions which are included in the logging configuration / information is met. The condition for the logging can be a new information that the UE is allowed logging if there is no available security key value for the subsequent mobility.

[0463] In step S1203, the UE may evaluate the multiple execution conditions for the subsequent mobility.

[0464] In step S1205, the UE may initiate the subsequent mobility to a candidate cell for which at least one of the multiple execution conditions is met. The UE may decide to perform the subsequent mobility to a candidate cell if at least one of the multiple execution conditions is met for the candidate cell in the pre-configuration. The UE may start a timer (e.g., T304) for mobility to check the validity of the mobility.

[0465] In step S1207, the UE may perform a security key update procedure using a selected security key value. While the timer is running, the UE may apply the corresponding candidate cell configuration for the subsequent mobility and the UE may update security information by a gNB key derivation based on a (newly) selected security key value from the security key lists in the pre-configuration.

[0466] In step S1209, the UE may detect / declare a failure of the subsequent mobility. When the UE failed to synchronize to the target cell while the timer is running, the UE may declare a mobility failure upon expiry of the timer.

[0467] In step S1211, upon declaration of the mobility failure, the UE may log security information with the (newly) selected security key value and related information. In case the network has configured the logging configuration / information, the UE may first check if one of the conditions is met for logging. If the logging conditions have been provided but have not been met, the UE may skip logging for the security information. For logging of the security information, the UE can optionally log the following information:

[0468] - (newly) selected security key value;

[0469] - Target cell information: target cell identity, global cell identity, and / or conditional reconfiguration identity can be included for the target cell information;

[0470] - The time of selecting the (newly) selected security key value;

[0471] - Mobility purpose(or, mobility type): for example, PCell handover;

[0472] - The rest of unused security key list per gNB;

[0473] - Mobility result: failure;

[0474] - Failure cause: for example, mobility validity timer expiry; and / or

[0475] - The rest of the unused security key list per gNB.

[0476] The UE may try mobility failure recovery based on the pre-configuration for the subsequent mobility. The UE may select another candidate to try the mobility failure recovery. The UE may start another timer (e.g., T304) for mobility to check the validity of the mobility.

[0477] While the timer is running, the UE may apply the corresponding candidate cell configuration for the subsequent mobility and the UE may update security information by another gNB key derivation based on another (newly) selected security key value from the security key lists in the pre-configuration. However, from the multiple security key list, there may be no available security key for the selected another candidate cell.

[0478] The UE may declare mobility failure again due to no available security key for the subsequent mobility. Upon declaration of the mobility failure, the UE may log security information. In case the network has configured the logging configuration / information, the UE may first check whether one of the conditions is met for logging. If the logging conditions have been provided but have not been met, the UE may skip logging for the security information. For logging of the security information, the UE can optionally log the following information:

[0479] - (newly) selected security key value: none;

[0480] - Target cell information: target cell identity, global cell identity, and / or conditional reconfiguration identity can be included for the target cell information;

[0481] - The time of selecting the (newly) selected security key value: not applicable;

[0482] - Mobility purpose(or, mobility type): PCell handover failure recovery;

[0483] - The rest of the unused security key list per gNB;

[0484] - Mobility result: failure; and / or

[0485] - Failure cause: no available security key.

[0486] The UE may decide to initiate RRC re-establishment procedure and the UE may find / select any suitable cell for RRC re-establishment. After the any suitable cell selection, the UE may send RRC re-establishment request to the selected cell.

[0487] The cell / network may send RRC re-establishment message to the UE. That is, the UE may receive the RRC re-establishment message from the cell / network.

[0488] In step S1213, the UE may report the logged security information to the network. For example, after the reception of the RRC re-establishment message, the UE may apply RRC re-establishment configuration and send RRC re-establishment complete message to the cell. When sending the RRC re-establishment complete message, the UE may notify the network of the availability of the logging results comprising the logged security information. For example, the availability of the logging results may compriserlf-InfoAvailable. Alternatively, the UE may report the logging results (e.g.,rlf-Report).

[0489] For the case of the UE notifying the availability of the logging results, the network may request the logging results via RRC dedicated message (e.g., UE information request message). If so, the UE may include the logging results and respond to the network via RRC dedicated message (e.g., UE information response message).

[0490] According to various embodiments, whenever performing conditional mobility, UE may log security information including selected security key value. The security information may include which security key is selected and which cell was a target cell for the conditional mobility. When (re)establishing RRC connection, indicating an availability of the logged security information, or reporting the logged security information to the network.

[0491] Furthermore, the method in perspective of the communication device / UE described in the present disclosure (e.g., in FIG. 9) may be performed by the first wireless device 100 shown in FIG. 2 and / or the UE 100 shown in FIG. 3.

[0492] More specifically, the communication device / UE comprises at least one transceiver, at least processor, and at least one computer memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform operations.

[0493] The operations comprise: receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys; initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and transmitting security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0494] Furthermore, the method in perspective of the communication device / UE described in the present disclosure (e.g., in FIG. 9) may be performed by a software code 105 stored in the memory 104 included in the first wireless device 100 shown in FIG. 2.

[0495] More specifically, at least one computer readable medium (CRM) stores instructions that, based on being executed by at least one processor, perform operations comprising: receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys; initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and transmitting security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0496] Furthermore, the method in perspective of the communication device / UE described in the present disclosure (e.g., in FIG. 9) may be performed by control of the processor 102 included in the first wireless device 100 shown in FIG. 2 and / or by control of the processor 102 included in the UE 100 shown in FIG. 3.

[0497] More specifically, an apparatus configured to / adapted to operate in a wireless communication system (e.g., communication device / UE) comprises at least processor, and at least one computer memory operably connectable to the at least one processor. The at least one processor is configured to / adapted to perform operations comprising: receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys; initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and transmitting security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0498] Furthermore, the method in perspective of a network node described in the present disclosure (e.g., in FIG. 10) may be performed by the second wireless device 200 shown in FIG. 2. The network node may be related to a serving cell.

[0499] More specifically, the network node comprises at least one transceiver, at least processor, and at least one computer memory operably connectable to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform operations.

[0500] The operations comprise: transmitting, to a user equipment (UE), a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys, wherein the UE is configured to perform operations comprising: initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; and performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; and receiving, from the UE, security information comprising at least one of: i) one or more used security keys including the selected security key among the one or more configured security keys, or ii) one or more unused security keys among the configured security keys.

[0501] The present disclosure may have various advantageous effects.

[0502] For example, by logging security information related to security key usage whenever performing subsequent mobility, the UE and the network can optimize the security information / configuration of the subsequent mobility and the update timing of the security information / configuration so that further security key mismatch problems which can cause RRC connection failure can be prevented.

[0503] Advantageous effects which can be obtained through specific embodiments of the present disclosure are not limited to the advantageous effects listed above. For example, there may be a variety of technical effects that a person having ordinary skill in the related art can understand and / or derive from the present disclosure. Accordingly, the specific effects of the present disclosure are not limited to those explicitly described herein, but may include various effects that may be understood or derived from the technical features of the present disclosure.

[0504] Claims in the present disclosure can be combined in a various way. For instance, technical features in method claims of the present disclosure can be combined to be implemented or performed in an apparatus, and technical features in apparatus claims can be combined to be implemented or performed in a method. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in an apparatus. Further, technical features in method claim(s) and apparatus claim(s) can be combined to be implemented or performed in a method. Other implementations are within the scope of the following claims.

Claims

1.A method comprising:receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys;initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations;performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; andtransmitting security information comprising at least one of:i) one or more used security keys including the selected security key among the one or more configured security keys, orii) one or more unused security keys among the configured security keys.2.The method of claim 1, wherein the list of security keys is configured for each base station, or for each cell group.3.The method of claim 1, wherein the performing of the security key update procedure using the selected security key comprises deriving or updating one or more keys for at least one of integrity proception or ciphering of communication using the selected security key.4.The method of claim 1, further comprising after performing the security key update procedure using the security key selected in the list of security keys, removing the security key selected and used for the security key update procedure from the list of security keys.5.The method of claim 4, further comprising logging the selected security key in logging results before removing the selected security key.6.The method of claim 4, wherein the one or more used security keys include security keys selected and used for the security key update procedure, andwherein the one or more unused security keys include security keys remaining in the list of security keys after security key removal.7.The method of claim 1, wherein the security information further comprises at least one of:target cell information comprising at least one of a target cell identity, global cell identity, or conditional reconfiguration identity;information for a time of the security key being selected;a mobility type comprising at least one of a conditional handover (CHO), a conditional primary secondary cell (PSCell) addition (CPA) or a conditional PSCell change (CPC);a mobility result comprising at least one of a mobility failure or a mobility success; ora failure cause in case of the mobility failure.8.The method of claim 1, further comprising logging the security information in logging results,wherein the transmitting of the security information comprises transmitting the logging results comprising the security information.9.The method of claim 8, wherein the logging of the security information in the logging results comprises upon performing the security key update procedure, logging at least part of the security information in the logging results.10.The method of claim 9, wherein the logging of the security information in the logging results comprises upon detecting a failure of the conditional mobility, logging at least part of the security information in the logging results.11.The method of claim 9, further comprising:transmitting an availability of the logging results; andreceiving a request for the logging results after transmitting the availability of the logging results,wherein the transmitting of the logging results comprises transmitting the logging results comprising the security information upon receiving the request.12.The method of claim 1, wherein the conditional mobility comprises a subsequent conditional mobility that is performed based on a corresponding conditional reconfiguration without releasing other conditional reconfigurations after each mobility completion.13.The method of claims 1, wherein the method is performed by a user equipment (UE) in communication with at least one of a mobile device, a network, or autonomous vehicles.14.A user equipment (UE) comprising:at least one transceiver;at least one processor; andat least one memory operatively coupled to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform operations comprising:receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys;initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations;performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; andtransmitting security information comprising at least one of:i) one or more used security keys including the selected security key among the one or more configured security keys, orii) one or more unused security keys among the configured security keys.15.An apparatus comprising:at least processor; andat least one memory operatively coupled to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform operations comprising:receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys;initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations;performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; andtransmitting security information comprising at least one of:i) one or more used security keys including the selected security key among the one or more configured security keys, orii) one or more unused security keys among the configured security keys.16.A non-transitory computer readable medium (CRM) having stored thereon a program code implementing instructions that, based on being executed by at least one processor, perform operations comprising:receiving a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys;initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations;performing a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; andtransmitting security information comprising at least one of:i) one or more used security keys including the selected security key among the one or more configured security keys, orii) one or more unused security keys among the configured security keys.17.A method comprising:transmitting, to a user equipment (UE), a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys,wherein the UE is configured to perform operations comprising:initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; andperforming a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; andreceiving, from the UE, security information comprising at least one of:i) one or more used security keys including the selected security key among the one or more configured security keys, orii) one or more unused security keys among the configured security keys.18.A network node comprising:at least one transceiver;at least one processor; andat least one memory operatively coupled to the at least one processor and storing instructions that, based on being executed by the at least one processor, perform operations comprising:transmitting, to a user equipment (UE), a configuration comprising a list of conditional reconfigurations and a list of security keys including one or more configured security keys,wherein the UE is configured to perform operations comprising:initiating a conditional mobility based on a conditional reconfiguration in which execution condition is fulfilled in the list of conditional reconfigurations; andperforming a security key update procedure using a security key selected in the list of security keys after initiating the conditional mobility; andreceiving, from the UE, security information comprising at least one of:i) one or more used security keys including the selected security key among the one or more configured security keys, orii) one or more unused security keys among the configured security keys.

Citation Information

Patent Citations

  • Encryption Key Destruction For Secure Data Erasure

    US20120093318A1

  • Security key updates in dual connectivity

    US20220345883A1

  • Managing UE information after preparing a conditional mobility procedure

    US20230388891A1