Methods, apparatus, and computer programs relating to a security procedure for lower layer triggered mobility
The UE's ability to detect radio link failures, select candidate cells, generate security keys, and manage recovery messages addresses mobility challenges in advanced networks, enhancing reliability and efficiency of handovers and network integrity.
Patent Information
- Application Number
- PCT/EP2025/065603
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-08
- Filing Date
- 2025-06-05
- Publication Date
- 2026-02-12
AI Technical Summary
Existing communication networks face challenges in efficiently managing radio link failures during lower layer triggered mobility, particularly in scenarios involving radio access technologies like 5G and beyond, where seamless handovers and security key management are critical for maintaining network integrity and user equipment connectivity.
The implementation of a user equipment (UE) with capabilities to detect radio link failures, select candidate cells for failure recovery, generate security keys, and send reconfiguration complete messages using these keys, along with indicators for recovery type, ensuring secure handovers and minimizing disruptions.
Enhances the reliability and efficiency of mobility management by facilitating secure and rapid handovers, reducing network interruption times, and maintaining communication integrity during radio link failures in advanced radio access technologies.
Smart Images

Figure EP2025065603_12022026_PF_FP_ABST
Abstract
Description
[0001] METHODS, APPARATUS, AND COMPUTER PROGRAMS RELATING TO A SECURITY
[0002] PROCEDURE FOR LOWER LAYER TRIGGERED MOBILITY
[0003] TECHNICAL FIELD
[0004] Various example embodiments relate generally to methods, apparatus, system and computer programs and in particular, but not exclusively, methods, apparatus, system and computer programs relating to a security procedure for lower layer triggered mobility (LTM).
[0005] BACKGROUND
[0006] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 5G (5th Generation) standards provided by 3GPP and future standards such as 6G and beyond.
[0007] BRIEF DESCRIPTION
[0008] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.
[0009] According to a first aspect, there is provided a user equipment comprising: means for detecting a radio link failure; means for, in response to the detected radio link failure, selecting a candidate cell for failure recovery; means for generating a security key; and means for sending a reconfiguration complete message to a first distributed unit associated with the selected candidate cell using the generated security key and for sending information indicating a recovery. Other optional features of the first aspect may be seen from the dependent claims which are dependent on the first aspect.
[0010] The first distributed unit may comprise a target distributed unit.
[0011] The second distributed unit may comprise a source distributed unit.
[0012] The second centralized unit may comprise a source distributed unit.
[0013] The first centralized unit may comprise a target centralized unit.
[0014] The term user equipment may be construed to cover an entire user equipment or to be a part of the user equipment, for example a chip or chipset.
[0015] According to a second aspect, there is provided a method comprising: detecting a radio link failure; in response to the detected radio link failure, selecting a candidate cell for failure recovery; generating a security key; and sending a reconfiguration complete message to a first distributed unit associated with the selected candidate cell using the generated security key and for sending information indicating a recovery.
[0016] The information indicating the recovery may be provided in the reconfiguration complete message.
[0017] The information indicating the recovery may be provided in a packet data convergence protocol header of the reconfiguration complete message.
[0018] The information indicating the recovery may be provided in a random access response message.
[0019] The reconfiguration complete message may comprise a radio resource control message.
[0020] The information indicating the recovery may comprise a recovery indicator which when active indicates that the reconfiguration complete message is associated with a recovery.
[0021] The information indicating the recovery may indicate if the generated security key is a horizontal security key or a vertical security key.
[0022] The information indicating the recovery may indicate if an associated handover is intra base station handover or inter base station handover.
[0023] The user equipment may be associated with a second distributed unit, which is different to the first distributed unit.
[0024] The second distributed unit may be associated with a second centralized unit and the first distributed unit is associated with a first centralized unit.
[0025] The first distributed unit may comprise a target distributed unit. The second distributed unit may comprise a source distributed unit.
[0026] The second centralized unit may comprise a source distributed unit.
[0027] The first centralized unit may comprise a target centralized unit.
[0028] The one or more candidate cells may be lower layer-triggered mobility cell.
[0029] The method may comprise sending a measurement report associated with hand-over of the user equipment to a candidate lower layer-triggered mobility cell.
[0030] The one or more parameters may comprise a next hop chaining counter parameter.
[0031] The method may comprise receiving during a previous configuration one or more parameters for generating the security key.
[0032] The previous configuration may be for a previous handover.
[0033] The one or more parameters may be received in a cell switch command of the previous handover.
[0034] The method may comprise detecting a radio link failure after receiving the previous configuration.
[0035] The method may be performed by an apparatus. The apparatus may be or part of a user equipment.
[0036] The apparatus may comprise at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to provide one or more of the methods of the second aspect.
[0037] According to another aspect, there is provided a computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0038] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least one of the above methods.
[0039] According to an aspect, there is provided a non-volatile tangible memory medium comprising program instructions stored thereon for performing at least one of the above methods.
[0040] In the above, many different aspects have been described. It should be appreciated that further aspects may be provided by the combination of any two or more of the aspects described above. Various other aspects are also described in the following detailed description and in the attached claims.
[0041] LIST OF THE DRAWINGS
[0042] In the following, the invention will be described in greater detail with reference to the embodiments and the accompanying drawings, in which
[0043] Fig. 1 shows an example of a communication network to which examples disclosed herein may be applied;
[0044] Fig. 2 shows a signalling diagram illustrating lower layer triggered mobility;
[0045] Fig. 3 shows a model for handover key chaining;
[0046] Figs. 4A and B shows a shows a security key update procedure during base mobility;
[0047] Figs. 5A and B show a first procedure of some embodiments;
[0048] Figs. 6A and B show a second procedure of some embodiments;
[0049] Figs. 7A and B show a third procedure of some embodiments;
[0050] Figs. 8 to 13 show first to sixth methods of some embodiments; and Fig. 14 shows an example of an apparatus.
[0051] DESCRIPTION OF EMBODIMENTS
[0052] The following embodiments are exemplary. Although the specification may refer to “an”, “one”, or “some” embodiment(s) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment(s), or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it is within the knowledge of one skilled in the art to apply such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described. It shall be understood that although the terms “first,” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.
[0053] For the purposes of the present disclosure, the phrases “at least one of A or B”, “at least one of A and B”, and “A and / or B” means (A), (B), or (A and B). For the purposes of the present disclosure, the phrase “A, B, and / or C” means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).
[0054] Embodiments described may be implemented in a communication network, such as any of the following radio access technologies (RATs): Worldwide Interoperability for Micro-wave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, and enhanced LTE (eLTE), 5G (also called NR), or any future RAT such as 6G. Moreover, communication within the communication network may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (M1M0), Orthogonal Frequency Division Multiple (OFDM), and / or Discrete Fourier Transform spread OFDM (DFT-s-OFDM).
[0055] As used herein, the term “network device” or “network node” refers to a node in a communication network via which user equipment may access the network and / or which is capable of controlling radio communication and managing radio resources within a cell. The network node or network device may be referred to as a base station (BS), an access point (AP) or an access node. The network device may be, depending on the applied technology, for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (1AB) node, a low power node, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, or an aircraft network device.
[0056] Moreover, in connection of split radio access network (RAN), the network device may refer to a centralized unit (CU) of a base station and / or a distributed unit (DU) of a base station. An interface between CU and DU may be referred to as an Fl interface in NR. In the split RAN architecture, node operations may be carried out, at least partly, in the central / centralized unit, CU, (e.g. server, host or node) operationally coupled to the DU, (e.g. a radio head / node). One CU may control one or more DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some embodiments, the DUs may comprise e.g. a radio link control (RLC), medium access control (MAC) layer and a physical (PHY) layer, whereas the CU may comprise the layers above RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) and an internet protocol (IP) layers. Other functional splits are possible too. In practice, any processing task may be performed in either the CU or the DU and the boundary where the responsibility is shifted between the CU and the DU may depend on the applied implementation.
[0057] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), or a Mobile Station (MS). The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, USB dongles, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like.
[0058] A term “resource”, as used herein, may refer to radio resources in time domain, in frequency domain, in space domain, and / or in code domain. Some examples of resources include e.g. a physical resource block (PRB), a radio frame, a subframe, a time slot, a subband, a frequency region, a sub-carrier, a beam, etc. The term “transmission” and / or “reception” may refer to wirelessly transmitting and / or receiving via a wireless propagation channel on radio resources.
[0059] Fig. 1 illustrates an example of a communication network to which examples disclosed herein may be applied. The communication network or a cellular communication network may comprise a network node 110 providing one or more cells, such as cell 100, and a network node 112 providing one or more other cells, such as cell 102. Each cell may be, e.g., a macro cell, a micro cell, femto, or a pico cell, for example. The cell may define a coverage area or a service area of the corresponding access node.
[0060] The network node 110 may provide a user equipment (UE) 120 (one ormore UEs) with wireless access to the communication network. The wireless access may comprise downlink (DL) communication from the network node to the UE 120 and uplink (UL) communication from the UE 120 to the network node. Examples of uplink channels comprise physical uplink control channel (PUCCH) for transmitting control information and physical uplink shared channel (PUSCH) for transmitting data towards the network. Examples of downlink channels comprise physical downlink control channel (PDCCH) for transmitting control information and physical downlink shared channel (PDSCH) for transmitting data towards the user equipment.
[0061] There may be a plurality of UEs 120, 122 in the system. Each of them may be served by the same or by different network nodes 110, 112. UE may be configured with dual connectivity (DC), wherein the UE, e.g. UE 120, may be connected to multiple network nodes 110, 112. The UEs 120, 122 may communicate with each other, in case de- vice-to-device (D2D) communication interface is established between them via a so- called sidelink (SL). Such D2D communications may be referred to as machine-to-ma- chine, peer-to-peer (P2P) communications, or vehicle-to-vehicle (V2V), for example.
[0062] In the case of multiple network nodes in the communication network, the network nodes may be connected to each other via an interface. LTE specifications call such an interface as X2 interface. An interface between an LTE node and a 5G node, or between two 5G nodes may be called Xn interface.
[0063] The network nodes 110 and 112 may be further connected via another interface to a core network 116 of the communication network. The LTE specifications specify the core network as an evolved packet core (EPC), and the core network may comprise e.g. a mobility management entity (MME) and a gateway node. The MME may handle mobility of terminal devices in a tracking area encompassing a plurality of cells and handle signalling connections between the terminal devices and the core network. The gateway node may handle data routing in the core network and to / from the terminal devices. The 5G specifications specify the core network as a 5G core (5GC). The 5G core may comprise e.g. an access and mobility management function (AMF) and a user plane func- tion / gateway (UPF) and other functions. The AMF may handle termination of non-access stratum (NAS) signalling, NAS ciphering & integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. The UPF node may support packet routing and forwarding, packet inspection and quality of service (QoS) handling, for example. In 3GPP Rel-18, a new mobility mechanism was introduced, namely lower layer-triggered mobility (LTM), which aims to reduce interruption time during handover. LTM is sometimes referred to as L1 / L2 triggered mobility. In this document lower layer- triggered mobility and L1 / L2 triggered mobility may be used interchangeably.
[0064] The overall procedure for LTM is illustrated in the signalling diagram in Figure 2, with reference to the network components schematically illustrated in Figure 1. Figure 2 is taken from Figure 9.2.3.5.2-1 of TS38.300vl8. As described in TS38.300vl8, 9.2.3.5.2, the procedure for LTM is as follows:
[0065] In Step 1 of Figure 2 the UE, for example the UE 120 sends a Measuremen- tReport message to the gNB 110, which provides access to the source cell 100. The gNB 110 decides to configure LTM and initiates LTM preparation.
[0066] In Step 2 of Figure 2, the gNB 110 transmits an RRCReconfiguration message to the UE 120 including the LTM candidate configurations.
[0067] In Step 3 of Figure 2 the UE 120 stores the LTM candidate configurations and transmits an RRCReconfigurationComplete message to the gNB 110.
[0068] In Step 4a of Figure 2, the UE 120 performs DL synchronization with the candidate cell(s) 102 before receiving the cell switch command.
[0069] In Step 4b of Figure 2, when the UE-based Timing Advance (TA) measurement is configured, the UE 120 acquires the TA value(s) of the candidate cell(s) 102 by measurement. The UE 120 performs early TA acquisition with the candidate cell(s) 102 as requested by the network before receiving the cell switch command as specified in clause 9.2.6 of TS38.300vl8. This is done via contention-Free Random Access (CFRA) triggered by a PDCCH order from the source cell 100, following which the UE 120 sends preamble towards the indicated candidate cell 102. In order to minimize the data interruption of the source cell 100 due to CFRA towards the candidate cell(s) 102, the UE 120 does not receive a random access response from the network for the purpose of TA value acquisition and the TA value of the candidate cell 102 is instead indicated in the cell switch command. The UE 120 does not maintain the TA timer for the candidate cell 102 and relies on network implementation to guarantee the TA validity.
[0070] In Step 5 of Figure 2 the UE 120 performs LI measurements on the configured candidate cell(s) 102 and transmits LI measurement reports to the source gNB 110. LI measurement should be performed as long as the RRC reconfiguration (from step 2) is applicable. The gNB 110 makes a LTM decision. The gNB decides to execute a cell switch from the source cell 100 to the candidate or target cell 102. As shown in Step 6 of Figure 2, the gNB 110 transmits a MAC Control Element (CE) triggering cell switch by including the candidate configuration index of the target cell 102. The UE 120 then switches to the target cell 102 and applies the configuration indicated by candidate configuration index. In Step 7 of Figure 2 the UE 120 performs the random access procedure towards the target cell 102, if the UE 120 does not have a valid TA of the target cell 102 as specified in clause 6.1.3.xy of TS 38.321.
[0071] The UE detaches from the source and applies the target configurations. In Step 8 of Figure 2, the UE 120 completes the LTM cell switch procedure by sending RRCReconfigurationComplete message to the gNB 112 providing access to the target cell 102.
[0072] If the UE 120 has performed a random access (RA) procedure in Step 7 of Figure 2 then the UE 120 considers that LTM cell switch execution is successfully completed when the random access procedure is successfully completed.
[0073] For RACH-less LTM (an LTM cell switch procedure where UE skips the random access procedure), the UE 120 considers that the LTM cell switch execution is successfully completed when the UE 120 determines that the network has successfully received its first UL data.
[0074] As seen above, in LTM, early TA acquisition, i.e. TA acquisition before hand- over / cell switch, can be performed in the following ways.
[0075] Firstly, the network can order the UE 120 to perform random access (RAJ preamble transmission to a candidate cell 102. The candidate cell 102 uses the received RA preamble to estimate the TA and provides the TA estimate to the source cell 100. When the source cell 100 decides to trigger the cell switch, it provides the estimated TA value along with the cell switch command.
[0076] Secondly, during LTM preparation, the network can configure the UE 120 to perform UE-based TA measurements. UE-based TA measurements may be performed based on the TA of the serving cell 100 and the measured time difference between the candidate cell 102 and the serving cell 100. After being configured, the UE 120 is assumed to obtain a TA measurement before a cell switch command is issued by the gNB 110 providing access to the source cell 100. Another purpose served by random access is that the target gNB 112 is notified about the presence of the UE 120 and resources for the UE’s subsequent transmissions are provided to the UE 120. Hence, when RACH-less LTM cell switch is performed, a mechanism is required to support the initial transmission of the UE 120 to the target cell 102. A mechanism that supports this purpose is the provisioning of configured grants, which consist of sets of resources in the candidate / target cell that the UE 120 may use if / when it performs its initial transmission after handover / cell switch to the target cell 102. An alternative to this mechanism is to provide an access notification from the source cell 100 to the target cell 102, so that the target cell 102 can then provide a dynamic grant to the UE 120 for the target cell 102.
[0077] Reference is made to Figure 3 which shows a model for handover key chaining. For horizontal and vertical key derivation, the PCI (physical cell identity and the DL frequency is used. Horizontal key derivation makes use of the previous key that has already been used once. Vertical key derivation does a refresh through use of new next hop parameter (NH). NH is an intermediate key used to derive a session key in vertical key derivation. The vertical key generation is used to separate key space of each RAN node. The NH value is provided to the RAN node by the AMF. A next hop chaining counter parameter (NCC) is used for next hop access key derivation. The AMF may transfer the NH together with the corresponding NCC value to the gNB. The vertical keys generated by each RAN node uses a fresh NH value provided by AMF. Thus, the security domain will be detached from the previous RAN node.
[0078] A horizontal key KNG-RAN* 1S derived from a current KgNB.
[0079] A vertical key KNG-RAN* is derived from the NH parameter.
[0080] NH parameters are computable by the UE and the AMF. The NH parameters are provided to gNB / ng-eNBs from the AMF.
[0081] The UE and the AMF may use the KAMF from a currently active security context for the computation of the fresh NH.
[0082] At initial setup, the KgNB is derived directly from KAMF, and is then considered to be associated with a virtual NH parameter with NCC value equal to zero. At initial setup, the derived NH value is associated with the NCC value one.
[0083] One difference between horizontal and vertical key derivation is that forward security may be only provided by vertical key derivation. In both options, a newly derived intermediate session key, KgNB* may become the new session key after the handover is completed. A key may refer to a security key, such as a session key.
[0084] In the following the terms “source” and “serving” are used interchangeably.
[0085] Reference is made to Figures 4A and B which shows a security key update procedure during base mobility. Figures 4A and B shows the coordination of next hop chaining counter parameter (NCC) between the network and the UE. Figures 4A and B illustrates handover, and vertical and horizontal key generation.
[0086] During the initial access, the AMF shares the security key and does not share the NCC. The gNB initializes the NCC to 0 and UE also uses the NCC as 0.
[0087] During the first inter gNB handover, the AMF shares the NCC (incremented by 2) with the target gNB in a path switch procedure.
[0088] In this example, initially gNBl is the serving gNB and gNB2 is the target gNB to which the UE is to be handed over to.
[0089] As referenced 1, gNBl stores the NH key and NCC received during path switch procedure of the handover execution phase. The NH is provided by the AMF.
[0090] As referenced 2, the NW (network) sends measurement configurations via a RRC reconfiguration message to the UE.
[0091] As referenced 3, the UE measures the neighbor cells and upon meeting the measurement criteria, the UE sends a measurement report to the serving gNB (gNBl)
[0092] As referenced 4, the serving gNB, gNBl, takes a decision for inter gNB handover of the UE.
[0093] As referenced 5, the serving gNB, gNBl, sends a handover request message to the target gNB (gNB2). The handover request comprises the KNG-RAN* and the NCC. This key is generated using the stored security information - such as described earlier.
[0094] As referenced 6 to 8, the gNB2 shares the NCC with the UE during handover preparation via a handover command sent via a RRC reconfiguration message. The gNB2 sends a handover acknowledgement to the gNBl (as referenced 7). The gNBl sends the handover command to the UE.
[0095] As referenced 9, if the NCC included in the handover command is the same as the previous NCC, the UE executes a horizontal key update. If the NCC is not the same as the previous NCC, the UE executes a vertical key update.
[0096] As referenced 10 and 11, the UE performs the RACH procedure with target cell and sends the RRC Reconfiguration complete message to target gNB(gNB2). As referenced 12 to 17, the target gNB, gNB2, performs a path switch procedure and during this procedure, the AMF increases the NCC by 1 and generates a fresh NH. The AMF shares the NH and NCC through a path switch request acknowledgement to the target gNB2. The target gNB2 stores the keys for next handover. As the NCC is increased by one, for the next handover the UE and gNB (either intra gNB or inter gNB handover (HO)) will use a vertical key update.
[0097] As referenced 18 to 20, the serving gNB (now gNB2) takes a decision for intra gNB inter cell handover. (The UE is handed over to another cell of gNB2) The gNB2 initiates a RRC reconfiguration for HO and shares the new NCC with the UE. This triggers the vertical key update procedure.
[0098] As referenced 21 to 23, as the UE receives the NCC and sees that the NCC has increased by one, the UE performs the vertical key update and performs RACH procedure with target cell. UE sends a RRC reconfiguration complete message to the gNB2.
[0099] As referenced 24 to 30, the UE sends a measurement report and the serving gNB(gNB2) takes a decision of inter gNB HO with target gNBl. The source gNB (gNBl) sends a handover request to the target gNB (gNB2) with KNG-RAN*. This key generated by using horizontal procedure with the NCC used in previous HO and no new NCC is received from the AMF. The target gNB(gNBl) includes the NCC in the handover command which is sent to the UE via serving / source gNB(gNB2).
[0100] As referenced 31 to 33, since the NCC is the same as the previous NCC, the UE executes a horizontal key update. The UE performs the RACH procedure with the target gNB (gNBl) and sends the RRC reconfiguration complete message to the target gNB(gNBl)
[0101] The part of the procedure referenced 34 to 38 is as described with reference to the part of the procedure referenced 12 to 16.
[0102] In the following examples, CUI and DU1 belongs to gNBl, CU2 and DU2 belongs to gNB2 and so on.
[0103] Some embodiments may be implemented by a UE or by a part of the UE such as a chip (integrated circuit) or a chip set. In following the term UE may be construed to cover an entire UE apparatus or a part of the UE, for example a chip or chipset.
[0104] In some embodiments, upon successfully receiving a RRC reconfiguration complete message at the target CU(gNB) during LTM execution, that target CU generates horizontal keys from stored key for all the prepared LTM target candidate CUs. That target CU shares the corresponding generated keys with all the prepared LTM target candidate CUs. This may be through XN signaling. The CUs of the LTM target candidate cells store the shared horizontal keys. The target CU (new source) may select all the target CUs. The source CU may generate a key per target CU and send this key to the target CU. Every target CU may receive its own key.
[0105] Upon a successful path switch procedure, the target CU (now the current serving CU) generates vertical keys from received security configurations in the path switch request acknowledgement for all prepared LTM target candidates. The current serving CU shares the corresponding vertical generated keys with the prepared LTM target candidates. This may be via XN signaling. The CUs of the LTM target candidate cells store the shared vertical keys along with earlier stored horizontal keys.
[0106] The UE is configured to use the horizontal key in case of radio link failure or if the UE goes to conditional LTM without receiving the necessary security information.
[0107] If the UE experiences radio link failure (RLF), the UE may initiate an LTM recovery procedure. During LTM recovery, the UE generates the horizontal key(s) and sends a RRC reconfiguration complete message using the generated horizontal key.
[0108] On receiving the RRC reconfiguration complete message, the new target CU (recovery target) uses the horizontal key(s) (which the target CU has previously stored) to process and perform the LTM execution procedure. The new target CU (which may be referred to as a recovery target) generates new horizontal keys from the stored horizontal keys for all other LTM target candidate cells and shares the generated horizontal keys with the LTM target candidate cells.
[0109] The serving CU may inform the candidate CU that Inter-CU LTM recovery is activated during preparation.
[0110] If LTM recovery is enabled, after LTM switching the new serving CU may provide the updated security configuration for recovery based on current KgNB key.
[0111] In some embodiments, the candidate DU when it receives handover complete message (for example via Msg3 for its C-RNTl(Cell Radio-Network Temporary Identifier)), the candidate CU selects the security configuration of horizontal key if it does not receive NCC based keys from current serving cell.
[0112] Alternatively, in some embodiments, the candidate CU node selects the se- curity configuration of the horizontal key if no cell switch notification received from source CU. Alternatively, in some embodiments, the candidate CU node can attempt for decoding using both horizontal and vertical security key options.
[0113] The target LTM candidates may overwrite the horizontal keys on receiving the new horizontal keys.
[0114] In some embodiments, the UE may receive during a previous configuration one or more parameters for generating a security key. The previous configuration may be a handover procedure. The one or more parameters for generating a security key may comprise a next hop chaining counter parameter. The one or more parameters are received in a cell switch command of the previous handover.
[0115] Reference is made to Figures 5A and B which shows a procedure where the UE experiences RLF before the DU sends a Cell Switch Command (MAC CE) with NCC to the UE, UE uses horizontal key.
[0116] As reference 1, the serving CU (CUI) selects LTM target candidates for which to prepare the LTM configuration. This may be based on L3 measurements provided by the UE. The serving CU (CUI) prepares the LTM configuration at the selected LTM target cells and shares the LTM configurations for the target cells with the UE. On receiving LI measurement(s), the serving DU (DU1) determines that a cell switch command (CSC) for a cell in a target CU (CU2) is to be sent to the UE and the serving DU (DU1) sends that cell switch command. The serving DU may be referred to as the source DU in this example. The serving CU may be referred to as the source CU.
[0117] The LTM candidate configuration may include security-configuration for LTM-Recovery. This configuration may indicate whether UE should apply security key change using horizontal key derivation during recovery or proceed with re-establish- ment. In the following example, the configuration indicates that the UE should apply a security key change fusing horizontal key derivation.
[0118] As referenced 2, the UE performs a cell switch to a cell on DU2 / CU2 on receiving the cell switch command. The switch is from the current cell on DU1 / CU1.
[0119] As referenced 3, the UE sends a reconfiguration complete message (e.g. a RRC reconfiguration complete message) to the target CU (CU2).
[0120] As referenced 4, the target CU (CU2) which is the new serving CU generates horizontal keys for all prepared LTM target cell candidates respectively. The target CU (CU2) shares the generated keys with all the LTM target cell candidates. The LTM targets may store the horizontal keys shared. As referenced 5, an access notification is sent from DU2 to the target CU (CU2) which is the new serving CU.
[0121] As referenced 6, CU2 initiates a path switch procedure. CU2 may send a path switch request to the AMF.
[0122] As referenced 7, the AMF provides a response to CU2. The response may be a path switch acknowledgement. The response may provide security configuration information. The security configuration information may be a fresh NH value and an incremented NCC value.
[0123] As referenced 8, the CU2 may share at least a part of the security configuration information with DU2. CU2 may share the new NCC with DU2.
[0124] As referenced 9, the serving CU2 generates the vertical keys for all prepared target candidates and shares corresponding generated keys with target LTM candidates. The CU(s) of the target LTM candidates may store the vertical keys and the horizontal keys. Alternately reference in some embodiments, the vertical and horizontal keys may be shared in a same message.
[0125] As referenced 10, the UE sends a measurement report to the DU2. The measurement report may be a LI measurement report.
[0126] As referenced 11, due to RLF, the UE initiates recovery to an LTM cell of CU3, by way of example only. The UE uses a horizontal key as no cell switch command is received due to the RLF and no NCC is received by UE again due the RLF. In other words, the UE does not have an unused NH, NCC pair.
[0127] On selecting LTM candidate cell for recovery, the UE may check the security configuration for recovery and decide on re-establishment or horizontal key derivation and proceed with LTM recovery. In this example, the UE selects the LTM recovery option. The UE may apply horizontal key derivation if the selected LTM candidate cell is an inter- CU candidate cell. UE knows if a selected LTM candidate is an inter-CU candidate based on ‘Group-1D’ or cell-set-lD associated with candidate configuration.
[0128] Intra-cell, (intra-CU) may use horizontal key derivation.
[0129] As referenced 12, the UE sends a reconfiguration complete message (for example a RRC reconfiguration complete message) to the CU3 via DU3. The UE uses the horizontal key to send the reconfiguration complete message.
[0130] As referenced 13, the CU3 may use the horizontal key to process the reconfiguration complete message. The CU3 may use the horizontal key to decode the reconfiguration complete message. The horizontal key is used as no cell switch communication is received. Alternatively or additionally, the horizontal key is used when both vertical and horizontal keys are present. CU3 may perform LTM execution.
[0131] As referenced 14, the new serving CU3, generates the horizontal keys for all other target LTM candidates using the stored horizontal keys received in the part of the procedure referenced 4. The generated horizontal keys are shared with the other target LTM candidates. The generated horizontal keys will overwrite the previous horizontal keys for the target LTM candidates.
[0132] As referenced 15, an access notification is sent from DU3 to CU3.
[0133] As referenced 16, CU3 initiates a path switch procedure. CU3 may send a path switch request to the AMF.
[0134] As referenced 17, the AMF provides a response to CU3. The response may be a path switch acknowledgement. The response may provide security configuration information. The security configuration information may be a fresh NH value and an incremented NCC value.
[0135] As referenced 18, the serving CU3 generates the vertical keys for all prepared target candidates and shares corresponding generated vertical keys with target LTM candidates. The CU(s) of the target LTM candidates may store the vertical keys. The generated vertical keys will overwrite the previous vertical keys for the target LTM candidates.
[0136] As referenced 19, the CU3 may share at least a part of the security configuration information with DU3. CU3 may share the new NCC. DU3 may use the NCC in a cell switch command during the LTM switch.
[0137] Reference is made to Figures 6A and B which shows an example using a similar procedure to that outlined in Figures 5A and B but where there is no radio link failure. Upon successful sending of the cell switch command or on receiving a successful cell change notification from the source CU, the target CU removes the stored horizontal key(s). The target CU uses the vertical keys to process the RRC reconfiguration complete message.
[0138] The part of the procedure of Figures 6A and B referenced 1 to 10 is as described with reference to the part of the procedure referenced 1 to 10 of Figures 5A and B. However, in this case, there is no radio link failure. As referenced 11, the DU 2 has received the measurement report from the UE and the DU2. DU2 may make a LTM handover decision based on the received measurement report. Based on the LTM handover decision, the DU 2 may transmit, to the UE, a cell switch command comprising the updated NCC value (NCC=3). The NCC value is the value provided to DU2 in the part of the procedure referenced 7. In this example, there may be an indication that the handover is an inter-gNB handover.
[0139] As referenced 12, the DU2 may send to the serving CU, CU2, a cell switch notification. This may comprise the target cell ID.
[0140] As referenced 13, the serving CU, CU2, sends to the target CU, CUI, a cell switch notification. This may comprise the target cell ID.
[0141] As referenced 14, when there is a successful cell switch, the target CUI deletes the stored horizontal keys.
[0142] As referenced 15, the UE uses the NCC to generate vertical keys. Alternately, the UE keeps track of failure recovery and security configurations used. These may be used to generate vertical keys on receiving the NCC in a cell switch command.
[0143] As referenced 16, the UE sends a RRC reconfiguration complete message to the DU1 using the vertical keys(s). The DUlmay forward the RRC reconfiguration complete message to the CUI.
[0144] As referenced 17, CUI may decode the RRC reconfiguration complete message using the vertical key(s) shared by CU2 in the part of the procedure referenced 9.
[0145] As referenced 18, target CUI (new serving CU) generates the horizontal keys for all prepared LTM target candidates by using the received vertical key (received at step 9) and shares the corresponding generated horizontal key with all target LTM candidate cells and CUs associated with the candidate cell. The target LTM candidate cells and CUs replace the old horizontal keys with the new received horizontal key.
[0146] As referenced 19, an access notification is sent from DU1 to the target CUl(serving CU).
[0147] As referenced 20, CUI initiates a path switch procedure. CUI may send a path switch request to the AMF.
[0148] As referenced 21, the AMF provides a response to CUI. The response may be a path switch acknowledgement. The response may provide security configuration information. The security configuration information may be a fresh NH value and an incremented NCC value (NCC=4 in this example). As referenced 22, the CUI may share at least a part of the security configuration information with DU1. CUI may share the new NCC.
[0149] In some embodiments, when the UE sends a RRC reconfiguration complete message, the UE may provide a recovery indication.
[0150] The recovery indication may indicate that the RRC reconfiguration complete message is provided responsive to a recovery procedure.
[0151] The recovery indication may be whether a horizontal key or a vertical key is used for the RRC reconfiguration complete message.
[0152] The recovery indication may be provided in the RRC reconfiguration complete message and / or in a different message. For example, the indication may be provided in a random-access response message or may be indicated in a PDCP header of RRC Reconfiguration Complete message.
[0153] The recovery indication may be whether the handover is intra-gNB handover or inter-gNB handover.
[0154] The recovery indication may be provided by a single bit which may be set or not set.
[0155] The CU, which receives the RRC reconfiguration complete message may process that message. On successful processing of the RRC reconfiguration complete message, the CU may validate the usage of keys with the recovery indication.
[0156] In some embodiments, the CU can use both the horizontal and vertical keys to process the RRC reconfiguration complete message. After processing the RRC reconfiguration complete message, the CU can validate the decoding with the recovery indication. The CU may continue to use the successfully validated key.
[0157] This may provide an indication if a vertical or horizontal key is used with respect to the RRC reconfiguration complete message. A horizontal key may be used for intra-gNB handover. A vertical key may be used for inter-gNB handover. For intra-gNB, horizontal key derivation may be because the key that is used to derive a new key is remaining internal to the gNB. The differentiation of the keys may be achieved due to different PCI and Frequency.
[0158] For the inter-gNB, the key derivation is vertical if the target gNB owns a NH, NCC pair. The NH, NCC pair comes from the AMF, because only AMF and UE are capable of processing NH values. Where vertical key derivation is not possible, such as where there has be a RLF, a horizontal key can be used. In some embodiments, the UE may provide in a separate message recovery indication. The recovery indication may be whether a horizontal key or a vertical key is used for the RRC reconfiguration complete message. For example, the indication may be provided in a random-access response message.
[0159] In some embodiments, on LTM recovery UE may include a parameter or recovery indicator on whether the UE has used new keys derived from horizontal derivation or the same master-key. This may be used to differentiate intra and Inter CU recovery.
[0160] Reference is made to Figures 7A and B which shows an example procedure in which a recovery indication is provided.
[0161] The parts of the procedure referenced 1 to 10 of Figures 7A and B are as described with reference to the part of the procedure referenced 1 to 10 of Figures 5A and B.
[0162] As referenced 11, due to RLF, the UE initiates recovery to an LTM cell of CU3, by way of example only. The UE uses a horizontal key as no cell switch command is received due to the RLF and no NCC is received by UE again due the RLF. In other words, the UE does not have an unused NH, NCC pair.
[0163] As schematically referenced 12, the cell switch command is not received by the UE due to RLF.
[0164] On selecting LTM candidate cell for recovery, the UE may check the security configuration for recovery and decide on re-establishment or horizontal key derivation and proceed with LTM recovery. In this example, the UE selects the LTM recovery option. The UE may apply horizontal key derivation if the selected LTM candidate cell is an inter- CU candidate cell. UE knows if a selected LTM candidate is an inter-CU candidate based on ‘Group-ID’ or cell-set-ID associated with candidate configuration.
[0165] As referenced 13, the UE sends a reconfiguration complete message (for example a RRC reconfiguration complete message) to the CU3 via DU3. The UE uses the horizontal key to send the reconfiguration complete message. In this example, the RRC reconfiguration complete message includes a recovery indication.
[0166] As referenced 14, CU3 processes the RRC reconfiguration Complete message by using the horizontal keys. In some embodiments, on failure of using the horizontal keys, the UE may use vertical keys. In some embodiments, the horizontal and vertical keys may be both used. The CU3 may use the recovery indication to validate the proper key usage to decode the RRC Reconfiguration Complete message.
[0167] As referenced 15, (which is an alternative to the part of the procedure referenced 14), the target CU (CU3) uses horizontal keys when the recovery indication indicates that the RRC Reconfiguration Complete message is provided in response to recovery. The recovery indication may be “recovery = true”. The recovery indication may be provided by a single bit which may be set or not set.
[0168] The parts of the procedure referenced 16 to 22 of Figures 7A and B are as described with reference to the part of the procedure referenced 14 to 20 of Figure Figures 5A and B.
[0169] Some embodiments may address issues resulting from link failure.
[0170] In some embodiments, there may be horizontal key generation and updates which are provided to all LTM candidate cells. This may be done before there is a security update.
[0171] In some embodiments, the UE may generate a horizontal key when no new security available for inter CU LTM. For example, due to RLF, a path switch command with an updated NCC is not received.
[0172] Reference is made to FIGs. 8 to 13 which shows some methods of some example embodiments.
[0173] The respective methods may be performed by an apparatus.
[0174] The apparatus may comprise suitable means, such as circuitry for providing the method.
[0175] Alternatively or additionally, the apparatus may comprise at least one processor and at least one memory storing instructions that, when executed by the at least one processor cause the apparatus at least to provide the method below.
[0176] Alternatively or additionally, the apparatus may be such as discussed in relation to FIG. 14.
[0177] The respective methods may be provided by computer program code or computer executable instructions.
[0178] Reference is made to Figure 8. The apparatus may be or provided in a user equipment.
[0179] The method comprises as referenced Al, receiving during a previous configuration one or more parameters for generating a security key. The method comprises as referenced A2, detecting a radio link failure.
[0180] The method comprises as referenced A3, in response to the detected radio link failure, selecting a candidate cell of one or more candidate cells for failure recovery.
[0181] The method comprises as referenced A4, generating a security key based on one of the one or more parameters received during the previous configuration.
[0182] The method comprises as referenced A5, sending a reconfiguration complete message to a first distributed unit associated with the selected candidate cell using the generated security key.
[0183] The first distributed unit may comprise a target distributed unit.
[0184] The generated security key may be a horizontal security key. The user equipment may thus use the horizontal key where there is a radio link failure before a path switch command. The user equipment may avoid the need to perform a re-establishment procedure even where there is a radio link failure.
[0185] The method may comprise sending a measurement report for handover of the user equipment to a candidate cell, prior to detecting the radio link failure and after the previous configuration. Embodiments may be used where a measurement report for handover is sent but a radio link failure prevents the user equipment from receiving an associated cell switch command.
[0186] The user equipment may be associated with a second distributed unit, which is different to the first distributed unit.
[0187] The second distributed unit may comprise a source distributed unit.
[0188] The second distributed unit may be associated with a second centralized unit and the first distributed unit may be associated with a first centralized unit. Embodiments may thus be used for inter gNB handover.
[0189] The second centralized unit may comprise a source distributed unit.
[0190] The first centralized unit may comprise a target centralized unit.
[0191] The measurement report may be sent to the second distributed unit.
[0192] The measurement report may comprise measurement information for the selected candidate cell.
[0193] The one or more candidate cells may be lower layer-triggered mobility cells.
[0194] The reconfiguration complete message may comprises a radio resource control message.
[0195] The one or more parameters may comprise a next hop chaining counter parameter.
[0196] The previous configuration may be for a previous handover.
[0197] The one or more parameters may be received in a cell switch command of the previous handover. In this way, a previously received parameter may be used for a later handover in the event of a radio link failure.
[0198] The method may comprise detecting a radio link failure detects a radio link failure after receiving the previous configuration. Embodiments may thus be used where radio link failure occurs before receiving of the associated cell switch command for a handover.
[0199] Reference is made to Figure 9. The apparatus may be or provided in a user equipment.
[0200] The method comprises as referenced Bl, detecting a radio link failure.
[0201] The method comprises as referenced B2, in response to the detected radio link failure, selecting a candidate cell for failure recovery.
[0202] The method comprises as referenced B3, generating a security key.
[0203] The method comprises as referenced B4, sending a reconfiguration complete message to a first distributed unit associated with the selected candidate cell using the generated security key and for sending information indicating a recovery.
[0204] The information indicating the recovery may be provided in the reconfiguration complete message.
[0205] The information indicating the recovery may be provided in a packet data convergence protocol header of the reconfiguration complete message.
[0206] The information indicating the recovery may be provided in a random access response message.
[0207] The reconfiguration complete message may comprise a radio resource control message.
[0208] The information indicating the recovery may comprise a recovery indicator which when active indicates that the reconfiguration complete message is associated with a recovery. This may assist with the processing of the message by the gNB as the gNB will understand that the message is associated with a recovery following a radio link failure.
[0209] The information indicating the recovery may indicate if the generated security key is a horizontal security key or a vertical security key. This may assist the gNB to use the appropriate key to process the reconfiguration message.
[0210] The information indicating the recovery may indicate if an associated handover is intra base station handover or inter base station handover. This may assist the gNB to use the appropriate key to process the reconfiguration message.
[0211] The user equipment may be associated with a second distributed unit, which is different to the first distributed unit.
[0212] The second distributed unit may be associated with a second centralized unit and the first distributed unit is associated with a first centralized unit.
[0213] The first distributed unit may comprise a target distributed unit.
[0214] The second distributed unit may comprise a source distributed unit.
[0215] The second centralized unit may comprise a source distributed unit.
[0216] The first centralized unit may comprise a target centralized unit.
[0217] The one or more candidate cells may be lower layer-triggered mobility cell.
[0218] The method may comprise sending a measurement report associated with handover of the user equipment to a candidate lower layer-triggered mobility cell.
[0219] The one or more parameters may comprise a next hop chaining counter parameter.
[0220] The method may comprise receiving during a previous configuration one or more parameters for generating the security key.
[0221] The previous configuration may be for a previous handover.
[0222] The one or more parameters may be received in a cell switch command of the previous handover. In this way, a previously received parameter may be used for a later handover in the event of a radio link failure.
[0223] The method may comprise detecting a radio link failure after receiving the previous configuration. Embodiments may thus be used where radio link failure occurs before receiving of the associated cell switch command for a handover.
[0224] Reference is made to Figure 10. The apparatus may be or provided in a user equipment.
[0225] The method comprises as referenced Cl, receiving information indicating a security configuration to be applied in the event of radio link failure for one or more candidate lower layer-triggered mobility cells, said security configuration indicating if a security key change is to be applied.
[0226] The method comprises as referenced C2, detecting a radio link failure. The method comprises as referenced C3, in response to the detected radio link failure, applying the respective security configuration with respect to one or more of the candidate lower layer-triggered mobility cells.
[0227] The security configuration may be received in a lower layer triggered mobility configuration for one or more candidate lower layer triggered mobility candidates for handover. The user equipment may thus be configured in advance as to how to behave in the event of a radio link failure.
[0228] The security configuration may be received from a centralized unit of a base station.
[0229] The method may comprise receiving during a previous configuration one or more parameters for generating a security key. The previously received parameters may be used in the event of a radio link failure, in line with the security configuration.
[0230] The one or more parameters may comprise a next hop chaining counter parameter.
[0231] The previous configuration may be for a previous handover.
[0232] The one or more parameters are received in a cell switch command of the previous handover.
[0233] The method may comprise detecting a radio link failure, and means for, in response to the detected radio link failure, selecting a candidate cell of the one or more candidate cells for failure recovery. The user equipment may be able to proceed with a handover even where there is a radio link failure and without having to perform a reestablishment procedure.
[0234] The method may comprise generating a security key based one of the one or more parameters when said security configuration indicates that a security key change is to be applied, for the selected candidate cell. The user equipment may thus use a previously received parameter in the event that a radio link failure prevents the receipt of a cell switch command.
[0235] The method may comprise sending a reconfiguration complete message to a distributed unit associated with the selected candidate cell using the generated security key. This may avoid the need for a re-establishment procedure.
[0236] The reconfiguration complete message may comprise a radio resource control message.
[0237] The one or more candidate cells may be lower layer-triggered mobility cells. The method may comprise receiving a security configuration to be applied in the event of a path switch to one or more candidate lower layer-triggered mobility cells. A different security configuration may be used in the case where there is no radio link failure. This may be a default procedure.
[0238] Reference is made to Figure 11. The apparatus may be or provided in a base station. The apparatus may be or provided in a distributed unit of a base station. The apparatus may be or provided in a centralised unit of a base station.
[0239] The method comprises as referenced DI, providing information to a user equipment indicating a first security configuration to be applied in the event of radio link failure for one or more candidate lower layer-triggered mobility cells, said first security configuration indicating if a security key change is to be applied.
[0240] The security configuration may be provided in a lower layer triggered mobility configuration for one or more candidate lower layer triggered mobility candidates for handover. The user equipment may thus be configured in advance as to how to behave in the event of a radio link failure.
[0241] The method may comprise providing to the user equipment during a previous configuration one or more parameters for generating a security key. The previously received parameters may be used in the event of a radio link failure, in line with the security configuration.
[0242] The method may comprise selecting the one or more candidate lower layer triggered mobility cells.
[0243] The method may comprise selecting the one or more candidate lower layer triggered mobility cells based on L3 measurement reports.
[0244] Reference is made to Figure 12. The apparatus may be or provided in a base station. The apparatus may be or provided in a distributed unit of a base station. The apparatus may be or provided in a centralised unit of a base station.
[0245] The method comprises as referenced El, receiving a reconfiguration complete message from a user equipment.
[0246] The method comprises as referenced E2, generating a respective horizontal key for one or more of the target candidate cells for the user equipment and sharing the respective horizontal keys for the one or more target candidate cells with one or more base stations associated with the target candidate cells.
[0247] The method comprises as referenced E3, receiving a path switch command with one or more parameters for generating one or more security keys.
[0248] The method comprises as referenced E4, generating a respective vertical key for one or more of the target candidate cells for the user equipment using the one or more parameters and sharing the respective vertical keys for the one or more target candidate cells with the one or more base stations associated with the target candidate cells.
[0249] The method may comprise receiving one or more updated respective horizontal keys for one or more of the target candidate cells for the user equipment and updating the respective horizontal keys for the one or more target candidate cells. The updated horizontal keys may be available to be used for a handover.
[0250] The method may comprise receiving one or more updated respective vertical keys for one or more of the target candidate cells for the user equipment and updating the respective vertical keys for the one or more target candidate cells. The updated horizontal keys may be available to be used for a handover.
[0251] The method may comprise: preparing a lower layer triggered mobility configuration for one or more candidate lower layer-triggered mobility cells for a user equipment, said configuration comprising the first configuration in the event of radio link failure; and sharing the lower layer triggered mobility configuration with one or more base stations associated with the one or more candidate lower layer-triggered mobility cells. The user equipment may be able to proceed with a handover even where there is a radio link failure and without having to perform a re-establishment procedure.
[0252] Reference is made to Figure 13. The apparatus may be or provided in a base station. The apparatus may be or provided in a distributed unit of a base station. The apparatus may be or provided in a centralised unit of a base station.
[0253] The method comprises as referenced Fl, obtaining during a previous configuration of a user equipment, one or more security keys associated with one or more candidate target cells of the user equipment.
[0254] The method comprises as referenced F2, receiving a reconfiguration complete message from the user equipment associated with one of the one or more target candidate cells.
[0255] The method comprises as referenced F3, using one of the one or more security keys associated with the target candidate cell to process the reconfiguration complete message.
[0256] The one or more security keys comprise one or more of: one or more vertical security keys for one or more target candidate cells of the user equipment; or one or more horizontal security keys for one or more target candidate cells of the user equipment.
[0257] The used one of the one or more security keys may be a horizontal security key.
[0258] The method may comprise generating respective updated horizontal security keys for one or more target candidate cells of the user equipment, after the receiving of the reconfiguration complete message.
[0259] The method may comprise updating the respective horizontal keys for the one or more target candidate cells of the user equipment at the apparatus with the generated updated horizontal keys for the one or more target candidate cells of the user equipment. The method may comprise sharing the updated horizontal security keys for one or more target candidate cells of the user equipment with one or more base stations associated with one or more of the target candidate cells.
[0260] The method may comprise sending a path switch request to access mobility function, after the receiving of the reconfiguration complete message and receiving a response to the path switch request comprising one or more parameters for generating a security key.
[0261] The one or more parameters may comprise a next hop chaining counter parameter.
[0262] The method may comprise generating respective updated vertical security keys for one or more target candidate cells of the user equipment using the one or more received security parameters.
[0263] The method may comprise updating the respective vertical keys for the one or more target candidate cells of the user equipment at the apparatus with the generated updated vertical keys for the one or more target candidate cells of the user equipment.
[0264] The method may comprise sharing the updated vertical security keys for one or more target candidate cells of the user equipment with one or more base stations associated with one or more of the target candidate cells.
[0265] The method may comprise receiving information indicating a recovery; and the means for using may be for using the information indicating a recovery. This may assist with the processing of a message by the gNB as the gNB will understand that the message is associated with a recovery following a radio link failure.
[0266] The information indicating the recovery may be provided in one of: the reconfiguration complete message; a packet data convergence protocol header of the reconfiguration complete message; or a random access response message.
[0267] The one or more security keys may comprise one or more of: one or more vertical security keys for one or more target candidate cells of the user equipment; or one or more horizontal security keys for one or more target candidate cells of the user equipment. This may assist the gNB to use the appropriate key to process a reconfiguration message.
[0268] The method may comprise using the recovery information to validate if a correct security key has been used to process the reconfiguration complete message.
[0269] The method may comprise using the recovery information to determine if the horizontal key associated with the target candidate cell is to be used to process the reconfiguration complete message or if the vertical key associated with the target candidate cell is to be used to process the reconfiguration complete message. This may assist the gNB to use the appropriate key to process a reconfiguration message.
[0270] The method may comprise using the horizontal key and the vertical key associated with the target candidate cell.
[0271] The method may comprise using the horizontal key associated with the target candidate cell and if the processing with the horizontal key fails for using the vertical key associated with the target candidate cell.
[0272] The information indicating the recovery may indicate if the generated security key is a horizontal security key or a vertical security key.
[0273] The information indicating the recovery may indicate if handover is intra base station handover or inter base station handover. This may assist the gNB to use the appropriate key to process a reconfiguration complete message.
[0274] The information indicating the recovery may comprise a recovery indicator which when active indicates that the reconfiguration complete message is associated with a recovery. This may assist the gNB to use the appropriate key to process a reconfiguration complete message.
[0275] Fig. 14 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods as disclosed herein, and any of the embodiments thereof. In an example, the at least one memory and the instructions (e.g. a computer program code, software), are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods as disclosed herein, and any of the embodiments thereof.
[0276] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with example embodiments described herein. As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0277] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may be at least in part external to apparatus 10 but accessible to apparatus 10.
[0278] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM). For example, the apparatus 10 is a terminal device, such as a UE. As another example, the apparatus is comprised in such a terminal device, e.g. as a chipset configured to control the terminal device. The apparatus 10 may be caused or configured to perform at least the method of Figs. 8, 9 and 10 and / or any one or more of the embodiments described.
[0279] As another example, the apparatus 10 is a radio access node apparatus, e.g. a CU and / or DU. In another embodiment, the apparatus is comprised in such a network apparatus, e.g. as a chipset configured to control the CU. The apparatus 10 may be caused or configured to perform at least the method of Fig. 11, 12 or 13 and / or any one or more of the embodiments described.
[0280] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity. In some embodiments, the entity is configured to perform any one or more of the embodiments described.
[0281] The apparatus 10 may comprise a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellu- lar standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.
[0282] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.
[0283] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components ofthe apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods as disclosed herein, and any of the embodiments thereof. As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C]”, is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.
[0284] Even though the invention has been described above with reference to an example according to the accompanying drawings, it is clear that the invention is not re- stricted thereto but can be modified in several ways within the scope of the appended claims. Therefore, all words and expressions should be interpreted broadly and they are intended to illustrate, not to restrict, the embodiment. It will be obvious to a person skilled in the art that, as technology advances, the inventive concept can be implemented in various ways. Further, it is clear to a person skilled in the art that the described em- bodiments may, but are not required to, be combined with other embodiments in various ways.
Claims
32CLAIMS1. A user equipment comprising: means for detecting a radio link failure; means for, in response to the detected radio link failure, selecting a candidate cell for failure recovery; means for generating a security key; and means for sending a reconfiguration complete message to a first distributed unit associated with the selected candidate cell using the generated security key and for sending information indicating a recovery.
2. The user equipment as claimed in claim 1, wherein the information indicating the recovery is provided in the reconfiguration complete message.
3. The user equipment as claimed in claim 2, wherein the information indicating the recovery is provided in a packet data convergence protocol header of the reconfiguration complete message.
4. The user equipment as claimed in claim 1, wherein the information indicating the recovery is provided in a random access response message.
5. The user equipment as claimed in any preceding claim, wherein the reconfiguration complete message comprises a radio resource control message.
6. The user equipment as claimed in any preceding claim, wherein the information indicating the recovery comprises a recovery indicator which when active indicates that the reconfiguration complete message is associated with a recovery.
7. The user equipment as claimed in any preceding claim, wherein the information indicating the recovery indicates if the generated security key is a horizontal security key or a vertical security key.
338. The user equipment as claimed in any preceding claim, wherein the information indicating the recovery indicates if handover is intra base station handover or inter base station handover.
9. The user equipment as claimed in any preceding claim, wherein the user equipment is associated with a second distributed unit, which is different to the first distributed unit.
10. The user equipment as claimed in claim 9, wherein the second distributed unit is associated with a second centralized unit and the first distributed unit is associated with a first centralized unit.
11. The user equipment as claimed in any preceding claim, wherein the one or more candidate cells are lower layer-triggered mobility cells.
12. The user equipment as claimed in claim 11, comprising means for sending a measurement report associated with handover of the user equipment to a candidate lower layer-triggered mobility cell.
13. The user equipment as claimed in any preceding claim, comprising means for receiving during a previous configuration one or more parameters for generating the security key.
14. The user equipment as claimed in any preceding claim, wherein the one or more parameters comprise a next hop chaining counter parameter.
15. The user equipment as claimed in claim 14, wherein the previous configuration is for a previous handover.
16. The user equipment as claimed in claim 15, wherein the one or more parameters are received in a cell switch command of the previous handover.
17. The user equipment as claimed in claim 14, 15 or 16, wherein the means for detecting a radio link failure detects a radio link failure after receiving the previous configuration.
18. A method comprising: detecting a radio link failure; in response to the detected radio link failure, selecting a candidate cell for failure recovery; generating a security key; and sending a reconfiguration complete message to a first distributed unit associated with the selected candidate cell using the generated security key and for sending information indicating a recovery.
19. A computer program comprising computer executable code which when run cause the method of claim 18 to be performed.
Citation Information
Patent Citations
NR mobility – security considerations for l1 / l2 mobility switching of an spcell
WO2024031042A1
Secondary cell group configuration retention or release
WO2024072796A1
Reporting of l1 / l2 mobility parameters
WO2024097854A1