Communication device, base station, and communication method

By integrating security key update information in LTM configurations, the patent addresses the issue of inconsistent key management during inter-gNB-CU mobility, ensuring secure and consistent communication across different base stations.

WO2026034519A1PCT designated stage Publication Date: 2026-02-12DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/027823
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-05
Filing Date
2025-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Current discussions to extend Layer 1/Layer 2 Triggered Mobility (LTM) to support cell mobility between different base stations (inter-gNB-CU) lack provisions for updating security keys in communication devices, leading to potential issues with proper key updates and inconsistencies.

Method used

Incorporating security key update information in the LTM configuration, including identifiers and parameters to determine whether a security key update is necessary during cell switching, ensuring consistent key management across different base stations.

Benefits of technology

Enables proper and consistent security key updates during LTM, addressing the lack of clear procedures for inter-gNB-CU mobility and ensuring seamless communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025027823_12022026_PF_FP_ABST
    Figure JP2025027823_12022026_PF_FP_ABST
Patent Text Reader

Abstract

A communication device (100) according to an embodiment is provided with a reception unit (112) that receives, from a network, an RRC message including one or more layer 1 / layer 2-triggered mobility (LTM) candidate settings each including an LTM candidate cell, and a control unit (120) that controls execution of an LTM cell switch. The control unit selects an appropriate cell in the selection of cells based on detection of a wireless link failure. When the selected cell is one of the LTM candidate cells, the control unit determines whether or not the LTM cell switch corresponding to the selected cell is to be executed, on the basis of the value of a first identifier associated with a serving cell and the value of a second identifier associated with the selected cell.
Need to check novelty before this filing date? Find Prior Art

Description

Communication device, base station, and communication method CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on and claims the benefit of priority from patent application serial number 2024-128854, filed August 5, 2024, the entire contents of which are incorporated herein by reference.

[0002] The present disclosure relates to a communication device, a base station, and a communication method.

[0003] In a mobile communication system that complies with the technical specifications of 3GPP (Third Generation Partnership Project), a standardization project for mobile communication systems, Layer 1 (Layer 1) / Layer 2 (Layer 2) Triggered Mobility (L1 / L2-Triggered Mobility: LTM) has been introduced (see Non-Patent Document 1).

[0004] In LTM, the base station sends a cell switch command to the communication device via a medium access control control element (MAC CE) based on an L1 measurement report received from the communication device, thereby switching the serving cell of the communication device. Compared with cell switches based on radio resource control (RRC) messages, the communication device can dynamically perform cell switches and reduce mobility delays.

[0005] 3GPP TS 38.300 V18.2.0 “NR; NR and NG-RAN Overall description; Stage-2”

[0006] A communication device according to a first aspect includes a receiver configured to receive an RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate configurations from a network, the RRC message including the one or more LTM candidate configurations including LTM candidate cells, and a controller configured to control execution of an LTM cell switch. The controller selects a suitable cell in cell selection based on detection of a radio link failure, and, if the selected cell is one of the LTM candidate cells, determines whether to execute an LTM cell switch for the selected cell based on a value of a first identifier associated with a serving cell and a value of a second identifier associated with the selected cell.

[0007] A base station according to a second aspect includes a transmitter configured to transmit an RRC message to a communication device, the RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate configurations including LTM candidate cells, the LTM candidate configurations including information indicating that an LTM cell switch is permitted to be performed at the communication device when selecting a cell.

[0008] A communication method according to a third aspect is a communication method executed by a communication device, the communication method comprising: receiving from a network an RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate configurations including LTM candidate cells, the LTM candidate configurations including the LTM candidate cells; controlling execution of an LTM cell switch; selecting a suitable cell in cell selection based on detection of a radio link failure; and, if the selected cell is one of the LTM candidate cells, determining whether to perform an LTM cell switch for the selected cell based on a value of a first identifier associated with a serving cell and a value of a second identifier associated with the selected cell.

[0009] Objects, features, advantages, etc. of the present disclosure will become clearer from the following detailed description with reference to the accompanying drawings. FIG. 1 is a diagram illustrating a configuration of a mobile communication system according to an embodiment. FIG. 2 is a diagram illustrating an example configuration of a protocol stack according to an embodiment. FIG. 3 is a diagram illustrating a configuration of a UE according to an embodiment. FIG. 4 is a diagram illustrating a configuration of a base station according to an embodiment. FIG. 5 is a sequence diagram (part 1) for describing a first operation example according to an embodiment. FIG. 6 is a sequence diagram (part 2) for describing the first operation example according to an embodiment. FIG. 7 is a diagram illustrating a hierarchical structure of an RRC reconfiguration message according to an embodiment. FIG. 8 is a flowchart (part 1) for describing a first operation example and a modified example according to an embodiment. FIG. 9 is a flowchart (part 2) for describing a first operation example and a modified example according to an embodiment. FIG. 10 is a flowchart for describing a second operation example and a modified example according to an embodiment. FIG. 11 is a flowchart for describing a third operation example according to an embodiment. FIG. 12 is a flowchart for describing a fourth operation example according to an embodiment.

[0010] A mobile communication system according to an embodiment will be described with reference to the drawings. In the description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.

[0011] Currently, discussions are underway to extend the functionality of LTM to support cell mobility between different base stations (so-called inter-gNB-CU (Central Unit)). However, because there are no provisions for updating security keys of communication devices in LTM, there is a concern that if cell mobility between different base stations is supported in LTM, communication devices may not be able to properly update security keys.

[0012] Therefore, one object of the present invention is to provide a communication device and a communication method that enable the communication device to properly update the security key in LTM.

[0013] (System Configuration) First, the configuration of a mobile communication system 1 according to this embodiment will be described with reference to Fig. 1. The mobile communication system 1 is, for example, a system that complies with the 3GPP Technical Specification (TS). In the following, the mobile communication system 1 will be described using as an example a 5th Generation System (5G system) of the 3GPP standard, i.e., a mobile communication system based on NR (NR (New Radio) radio access).

[0014] The mobile communication system 1 includes a network 10 and a user equipment (UE) 100 that communicates with the network 10. The network 10 includes a next generation radio access network (NG-RAN) 20, which is a 5G radio access network, and a 5G core network (5GC) 30, which is a 5G core network.

[0015] The UE 100 is a communication device that communicates via the base station 200. The UE 100 may be a device used by a user. The UE 100 may be a mobile device such as a mobile phone terminal such as a smartphone, a tablet terminal, a laptop PC, a communication module, or a communication card. The UE 100 may be a vehicle (e.g., a car, a train, etc.) or a device provided therein (e.g., a Vehicle UE). The UE 100 may be a transport vehicle other than a vehicle (e.g., a ship, an airplane, etc.) or a device provided therein (e.g., an Aerial UE). The UE 100 may be a sensor or a device provided therein. Note that the UE 100 may be referred to by other names such as a terminal, a terminal device, a mobile station, a mobile terminal, a mobile device, a mobile unit, a subscriber station, a subscriber terminal, a subscriber device, a subscriber unit, a wireless station, a wireless terminal, a wireless device, a wireless unit, a remote station, a remote terminal, a remote device, or a remote unit. Furthermore, the UE 100 is an example of a terminal, and the terminal may include factory equipment or the like.

[0016] The NG-RAN 20 includes multiple base stations 200. Each base station 200 manages at least one cell. One or more base stations 200 may correspond to one or more cells. In this embodiment, the base station 200 may be replaced with a cell. A cell constitutes the smallest unit of a communication area. One cell belongs to one frequency (carrier frequency). The term "cell" may refer to wireless communication resources or to a communication target of the UE 100. Each base station 200 can perform wireless communication with the UE 100 located in its own cell. The base station 200 communicates with the UE 100 using a RAN protocol stack. Details of the protocol stack will be described later. Furthermore, the base station 200 is connected to other base stations 200 (which may be referred to as neighbor base stations) via an Xn interface. The base station 200 communicates with the neighbor base stations via the Xn interface. In addition, the base station 200 provides NR user plane and control plane protocol termination for the UE 100 and is connected to the 5GC 30 via an NG interface. Such an NR base station 200 is sometimes referred to as a gNodeB (gNB).

[0017] The 5GC 30 includes a core network device 300. The core network device 300 includes, for example, an AMF (Access and Mobility Management Function) and / or a UPF (User Plane Function). The AMF performs mobility management for the UE 100. The UPF provides functions specialized for U-plane processing. The AMF and the UPF are connected to the base station 200 via an NG interface.

[0018] (Configuration Example of Protocol Stack) Next, a configuration example of a protocol stack according to this embodiment will be described with reference to FIG.

[0019] The protocol of the wireless section between UE 100 and base station 200 includes a physical (PHY) layer, a medium access control (MAC) layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, and a radio resource control (RRC) layer.

[0020] The PHY layer performs encoding / decoding, modulation / demodulation, antenna mapping / demapping, and resource mapping / demapping. Data and control information are transmitted between the PHY layer of the UE 100 and the PHY layer of the base station 200 via a physical channel.

[0021] The MAC layer performs data priority control, retransmission processing using Hybrid ARQ (HARQ), random access procedures, etc. Data and control information are transmitted between the MAC layer of UE 100 and the MAC layer of base station 200 via a transport channel. The MAC layer of base station 200 includes a scheduler. The scheduler determines the uplink and downlink transport format (transport block size, modulation and coding scheme (MCS)) and the resources to be allocated to UE 100.

[0022] The RLC layer transmits data to the RLC layer on the receiving side using the functions of the MAC layer and the PHY layer. Data and control information are transmitted between the RLC layer of the UE 100 and the RLC layer of the base station 200 via logical channels.

[0023] The PDCP layer performs header compression / decompression and encryption / decryption.

[0024] A Service Data Adaptation Protocol (SDAP) layer may be provided as an upper layer above the PDCP layer. The SDAP layer maps IP flows, which are units for Quality of Service (QoS) control by the core network, to radio bearers, which are units for QoS control by an Access Stratum (AS).

[0025] The RRC layer controls logical channels, transport channels, and physical channels according to the establishment, re-establishment, and release of radio bearers. RRC signaling for various settings is transmitted between the RRC layer of the UE 100 and the RRC layer of the base station 200. When there is an RRC connection between the RRC layer of the UE 100 and the RRC layer of the base station 200, the UE 100 is in an RRC connected state. When there is no RRC connection between the RRC layer of the UE 100 and the RRC layer of the base station 200, the UE 100 is in an RRC idle state. When the RRC connection between the RRC layer of the UE 100 and the RRC layer of the base station 200 is suspended, the UE 100 is in an RRC inactive state.

[0026] The NAS layer, which is located above the RRC layer in the UE 100, performs session management and mobility management for the UE 100. NAS signaling is transmitted between the NAS layer of the UE 100 and the NAS layer of the core network device 300.

[0027] The UE 100 has an application layer and the like in addition to the radio interface protocol.

[0028] (Radio Frame Configuration) In a 5G system, downlink transmission and uplink transmission are configured within a radio frame having a duration of 10 ms. For example, a radio frame is represented by a system frame number (SFN) ranging from 0 to 1023. For example, a radio frame is configured with 10 subframes. For example, one subframe may be 1 ms. Furthermore, one subframe may be configured with one or more slots. For example, the number of symbols that make up one slot is 14 for a normal CP (Cyclic Prefix) and 12 for an extended CP. Furthermore, the number of slots that make up one subframe varies depending on the set subcarrier spacing. For example, for a normal CP, if the subcarrier spacing is set to 15 kHz, the number of slots per subframe is 1 (i.e., 14 symbols); if the subcarrier spacing is set to 30 kHz, the number of slots per subframe is 2 (i.e., 28 symbols); if the subcarrier spacing is set to 60 kHz, the number of slots per subframe is 4 (i.e., 56 symbols); and if the subcarrier spacing is set to 120 kHz, the number of slots per subframe is 8 (i.e., 128 symbols). Furthermore, if the subcarrier spacing is set to 60 kHz for an extended CP, the number of slots per subframe is 4 (i.e., 48 symbols). That is, the number of slots constituting one subframe is determined based on the subcarrier spacing set by the base station 200. Furthermore, the number of symbols constituting one subframe is determined based on the subcarrier spacing set by the base station 200. That is, the number of symbols constituting a 1 ms subframe is determined based on the subcarrier spacing set by the base station 200, and the length of each symbol (length in the time direction) changes.

[0029] (Assumed scenario) Currently, discussions are underway to extend the functionality of LTM so that it can support cell movement between different base stations (so-called inter-gNB-CU). However, since there is no provision for updating the security key of UE 100 in LTM, there is a concern that if cell movement between different base stations is supported in LTM, UE 100 may not be able to properly update the security key.

[0030] For example, currently, when LTM is executed, the exchange of information necessary for updating the security key between the base station 200 and the UE 100 is not specified, and the security key update process of the UE 100 is unclear, so there is a concern that the UE 100 may not be able to properly update the security key. Therefore, one of the objectives is to enable proper updating of the security key in LTM.

[0031] Furthermore, currently, when LTM is executed, it is unclear when the UE 100 updates the security key, and therefore there is a concern that inconsistency regarding the update of the security key may occur between the base station 200 and the UE 100. Therefore, one of the objects is to enable the security key to be updated appropriately in LTM.

[0032] In addition, in the current LTE, which only supports cell movement within the same base station (specifically, gNB-CU (Centralized Unit)), there is no need to update the security key due to cell movement in LTE. Therefore, for example, information indicating that PDCP should be re-established (specifically, reestablishpdcp) is not set in the RRC reconfiguration message in the information regarding LTM configuration (specifically, LTM-Config). Therefore, the operation for re-establishing PDCP following security key update in LTM is unclear, and there is a concern that the security key update may not be properly reflected in PDCP. Therefore, one of the objectives is to enable security key updates to be properly performed in LTM.

[0033] (Configuration of User Equipment) The configuration of the UE 100 according to the embodiment will be described with reference to Fig. 4. The UE 100 includes a communication unit 110 and a control unit 120.

[0034] The communication unit 110 performs wireless communication with the base station 200 by transmitting and receiving radio signals to and from the base station 200. The communication unit 110 has at least one transmission unit 111 and at least one reception unit 112. The transmission unit 111 and the reception unit 112 may be configured to include multiple antennas and RF (Radio Frequency) circuits. The antenna converts a signal into radio waves and radiates the radio waves into space. The antenna also receives radio waves in space and converts the radio waves into a signal. The RF circuit performs analog processing of the signal transmitted and received via the antenna. The RF circuit may include a high-frequency filter, an amplifier, a modulator, a low-pass filter, etc.

[0035] The control unit 120 performs various controls in the UE 100. The control unit 120 controls communication with the base station 200 via the communication unit 110. The operations of the UE 100 described above and below may be operations controlled by the control unit 120. The control unit 120 may include at least one processor capable of executing a program and a memory that stores the program. The processor may execute the program to perform the operations of the control unit 120. The control unit 120 may include a digital signal processor that performs digital processing of signals transmitted and received via the antenna and the RF circuit. The digital processing includes processing of a RAN protocol stack. The memory stores the program executed by the processor, parameters related to the program, and data related to the program. The memory may include at least one of read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), random access memory (RAM), and flash memory. All or a portion of the memory may be contained within the processor.

[0036] The control unit 120 may include a MAC processing unit that performs processing in the MAC layer, a PDCP processing unit that performs processing in the PDCP layer, and an RRC processing unit that performs processing in the RRC layer. The MAC processing unit may be referred to as a MAC entity, the PDCP processing unit may be referred to as a PDCP entity, and the RRC processing unit may be referred to as an RRC entity. The PDCP layer and the RRC layer may be upper layers relative to the MAC layer. The RRC layer may be upper layers relative to the PDCP layer, and the MAC layer may be lower layers relative to the RRC layer. The MAC layer and the PDCP layer may be lower layers relative to the RRC layer.

[0037] The MAC processing unit, the PDCP processing unit, and / or the RRC processing unit may be configured by one processor or multiple processors. The operations of the MAC processing unit, the PDCP processing unit, and / or the RRC processing unit may be operations of the control unit 120. Of the operations of each layer processing unit, the transmission and / or reception operations may be operations of the communication unit 110 (the transmission unit 111 and / or the reception unit 112).

[0038] (Configuration of Base Station) The configuration of the base station 200 according to this embodiment will be described with reference to Fig. 5. The base station 200 includes a communication unit 210, a network communication unit 220, and a control unit 230.

[0039] The communication unit 210 receives, for example, a radio signal from the UE 100 and transmits the radio signal to the UE 100. The communication unit 210 has at least one transmission unit 211 and at least one reception unit 212. The transmission unit 211 and the reception unit 212 may be configured to include an RF circuit. The RF circuit performs analog processing of signals transmitted and received via an antenna. The RF circuit may include a high-frequency filter, an amplifier, a modulator, a low-pass filter, etc.

[0040] The network communication unit 220 transmits and receives signals to and from the network. For example, the network communication unit 220 receives signals from adjacent base stations connected via an Xn interface, which is an interface between base stations, and transmits the signals to the adjacent base stations. The network communication unit 220 also receives signals from the core network device 300 connected via an NG interface, and transmits the signals to the core network device 300.

[0041] The control unit 230 performs various controls in the base station 200. The control unit 230 controls, for example, communication with the UE 100 via the communication unit 210. The control unit 230 also controls, for example, communication with a node (e.g., a neighboring base station, the core network device 300) via the network communication unit 220. The operations of the base station 200 described above and below may be controlled by the control unit 230. The control unit 230 may include at least one processor capable of executing a program and a memory that stores the program. The processor may execute the program to perform the operations of the control unit 230. The control unit 230 may include a digital signal processor that performs digital processing of signals transmitted and received via the antenna and the RF circuit. The digital processing includes processing of a RAN protocol stack. The memory stores programs executed by the processor, parameters related to the programs, and data related to the programs. All or a part of the memory may be included in the processor.

[0042] Note that base station 200 may be a node having a gNB-CU (Central Unit) function and a gNB-DU (Distributed Unit) function. Base station 200 may be a node having a gNB-CU function but not a gNB-DU function. In this case, another node may have a gNB-DU function, and base station 200 may communicate with UE 100 via the other node. Also, base station 200 may be a node having a gNB-CU function and multiple gNB-DU functions. In this case, a cell may be managed by one gNB-DU, and one gNB-DU may be managed by one gNB-CU. It may also be a node having a gNB-CU-CP (Control Plane) function, multiple gNB-CU-UP functions (User Plane), and multiple gNB-DU functions. In this case, a cell may be managed by one gNB-DU, and one gNB-DU may be managed by one gNB-CU-CP and one gNB-CU-UP. In this embodiment, one gNB-CU-CP and one gNB-CU-UP may be referred to as a gNB-CU.

[0043] (First Operation Example) A first operation example will be described with reference to Figs. 5 to 8. Previous descriptions may be omitted. In the mobile communication system 1 of this operation example, the base station 200 includes base station 201 and base station 202. Base station 201 and base station 202 manage different cells. Base station 202 may be, for example, a neighboring base station for base station 201. In this operation example, base station 201 manages cell C1, and base station 202 manages cell C2.

[0044] The UE 100 may be in an RRC connected state with a cell C1 managed by the base station 201. Hereinafter, the UE 100 performs communication with the base station 201 in the cell C1 until performing an LTM cell switch to the target cell. The cell C1 may be referred to as a source cell or a serving cell. The cell C1 may be referred to as a PCell.

[0045] For UE 100, communication with base station 200 (base station 201 / base station 202) may be communication with a cell (cell C1 / cell C2). Therefore, for UE 100, receiving information / messages, etc. from base station 200 may be receiving information / messages, etc. from a cell, and transmitting information / messages, etc. to base station 200 may be transmitting information / messages, etc. to a cell. That is, in this embodiment, cell movement between different base stations (inter-gNB-CU) may include movement between cells associated with different CUs. Furthermore, cell movement within the same base station (intra-gNB-CU) may include movement between cells associated with the same CU. LTM for cell movement between different base stations is also referred to as inter-CU LTM. Furthermore, cell movement within the same base station is also referred to as intra-CU LTM.

[0046] In the following, the processes from steps S110 to S160 may be referred to as LTM preparation. The process of step S170 may be referred to as early synchronization. The processes from steps S180 to S210 may be referred to as LTM cell switch execution. The process of step S220 may be referred to as LTM cell switch completion.

[0047] Step S110: The transmitter 111 of the UE 100 may transmit capability information to the base station 201. The receiver 212 of the base station 200 may receive the capability information from the UE 100. The capability information may include, for example, information indicating whether or not cell movement between different base stations (inter-gNB-CU) by LTM (i.e., inter-CU LTM) is supported. The capability information may also include, for example, information indicating whether or not cell movement between the same base station (intra-gNB-CU) by LTM (i.e., intra-CU LTM) is supported. For example, the transmitter 111 of the UE 100 may transmit to the base station 201 an RRC message including capability information including information indicating that inter-CU LTM is supported and / or information indicating intra-CU LTM.

[0048] Step S120: The transmitter 111 of the UE 100 transmits a measurement report (message) to the base station 201. The receiver 212 of the base station 201 receives the measurement report from the UE 100.

[0049] The control unit 230 of the base station 201 may decide to configure LTM. The control unit 230 may start LTM preparation. As LTM preparation, the control unit 230 may select a candidate cell for the target cell in LTM (hereinafter referred to as an LTM candidate cell as appropriate) based on the measurement report. The control unit 230 may select the LTM candidate cell, for example, from among cells managed by the base station 201.

[0050] The control unit 230 may determine the LTM candidate cell based on, for example, capability information. When the UE 100 supports only cell movement between the same base stations by LTM among cell movement by LTM, the control unit 230 may select only a cell managed by the own station as the LTM candidate cell. On the other hand, when the UE 100 also supports cell movement between different base stations by LTM, the control unit 230 may select a cell managed by a base station other than the own station as the LTM candidate cell. When selecting a cell of another station as the LTM candidate cell, the control unit 120 may execute the process of step S130.

[0051] Furthermore, the control unit 230 may generate configuration information for LTM. The configuration information for LTM may be, for example, LTM configuration information (e.g., LTM-Config) used to provide LTM configuration. For example, when selecting a cell of another base station 200 as an LTM candidate cell, the control unit 230 may generate configuration information for LTM before the processing of step S150. The generation of configuration information for LTM will be described later. When selecting only the cell of the control unit 230 as an LTM candidate cell, the control unit 230 may skip the processing of step S130 (and step S140).

[0052] Step S130: The network communication unit 220 of the base station 201 may transmit, for example, a handover request message requesting preparation of resources for handover to the base station 202. The network communication unit 220 of the base station 202 may receive the handover request message from the base station 201. Note that the message in step S130 may be a message other than the handover request message. For example, the message may be a message used to request preparation for LTM (LTM cell switch).

[0053] The handover request message may include information requesting an LTM cell switch to the cell of base station 202. The handover request message may include information identifying LTM candidate cells among the cells managed by base station 202.

[0054] The control unit 230 of the base station 202 may determine, for example, based on the handover request message, whether to approve the LTM cell switch to the cell of the base station 202. If the control unit 230 approves the LTM cell switch, the control unit 230 may perform the following process.

[0055] Step S140: The network communication unit 220 of the base station 202 may transmit a Handover Request Acknowledge message to the base station 201 to inform the source base station (i.e., the base station 201) of the prepared resources at the target. The network communication unit 220 of the base station 201 receives the Handover Request Acknowledge message from the base station 202. This message may be a message used to notify the acknowledgement of preparation for LTM.

[0056] The handover request acknowledgement message may include information about a cell managed by the base station 202, which information should be included in the LTM setting information. For example, the control unit 230 of the base station 202 may include at least a part or all of the LTM candidate setting (or LTM candidate setting information) about an LTM candidate cell (e.g., cell C2) of the base station 202 in the handover request acknowledgement message. The control unit 230 may include, for example, an RRC reconfiguration message used to set a candidate setting in LTM, or an LTM candidate setting (ltm-CandidateConfig) including the RRC reconfiguration message, in the handover request acknowledgement message. Note that the LTM candidate setting may be referred to as LTM candidate setting information, as appropriate.

[0057] If the control unit 230 does not approve the LTM cell switch, it may, for example, send a handover preparation failure message to the base station 201 to inform the source base station (i.e., the base station 201) that the handover preparation has failed.

[0058] Before the process of step S150, the control unit 230 of the base station 201 generates an RRC reconfiguration message for the UE 100. For example, the control unit 230 may include the generated LTM setting information (e.g., LTM-Config) in the RRC reconfiguration message (see E1 and E12 in FIG. 7). Here, when the control unit 230 receives an RRC reconfiguration message from the base station 202, the control unit 230 may generate an LTM candidate setting including the RRC reconfiguration message. Alternatively, the control unit 230 may generate not only the LTM candidate setting of the base station 201 itself, but also the LTM candidate setting of the base station 202. The control unit 230 may generate an RRC reconfiguration message including the generated LTM setting information.

[0059] The LTM setting information may be information used to provide (one or more) LTM settings. The control unit 230 may include, for example, a list for releasing LTM candidate settings (hereinafter, may be referred to as an LTM candidate release list (e.g., ltm-CandidateToReleaseList)) in the LTM setting information. The control unit 230 may also include, in the LTM setting information, a list for adding or changing LTM candidate settings (hereinafter, may be referred to as an LTM addition / modification list (e.g., ltm-CandidateToAddModList)) (see E22 in FIG. 7).

[0060] The LTM candidate release list may be a list of LTM candidate settings to be removed. The LTM candidate release list may be configured by an identifier (for example, ltm-CandidateId) for identifying the LTM candidate setting.

[0061] The LTM addition / change list may be a list configured of LTM candidate information (e.g., LTM-Candidate) (see E31 and E32 in FIG. 7). The LTM addition / change list may be a list of LTM candidate settings to be added and / or changed. The LTM candidate settings may include, for example, at least any of the following information: As described above, the LTM setting information may include LTM candidate information. Furthermore, the LTM setting information may include an LTM candidate setting. In other words, the LTM candidate information may correspond to the LTM candidate setting. In this embodiment, the LTM setting information, the LTM candidate information, and the LTM candidate setting may be interchangeable. LTM candidate configuration identifier (for example, ltm-CandidateId) Physical cell identifier of the LTM candidate configuration included in the LTM candidate configuration (for example, ltm-CandidatePCI) LTM candidate configuration information (for example, ltm-CandidateConfig)

[0062] The identifier of the LTM candidate configuration may be the physical cell identifier (PCI) of a special cell (Sp cell). The special cell may be a P cell. Regarding dual connectivity operation, the special cell may be a P cell of an MCG or a PS cell of an SCG. The LTM candidate configuration information may include an RRC reconfiguration message used to configure the LTM candidate configuration. The RRC reconfiguration message may be a command for modifying the RRC connection. That is, each of one or more LTM candidate configurations in the list may correspond to one or more LTM candidate cells. In this embodiment, the LTM candidate configuration (and / or information included in the LTM candidate configuration) may be replaced with the LTM candidate cell. Furthermore, the LTM candidate cell may be replaced with the LTM candidate configuration (and / or information included in the LTM candidate configuration).

[0063] Here, the control unit 230 of the base station 200 may include update information regarding security key updates in the LTM configuration information. First, the update information may be included, for example, in a separate field (e.g., field E21 in FIG. 7) located parallel to the field in which the LTM candidate addition / change list is set in the LTM configuration information (e.g., LTM-Config). Second, the update information may be included, for example, in an LTM candidate identifier (e.g., ltm-CandidateId) in each LTM candidate information (e.g., LTM-Candidate) and / or in a separate field (e.g., fields E311, E321 in FIG. 7) located parallel to the field in which the LTM candidate information (e.g., ltm-Candidateconfig) is set. That is, the update information may be included in each of one or more LTM candidate configurations. Third, the update information may be included in a field in the RRC reconfiguration message in the LTM candidate information (e.g., fields E51 and E52 in Fig. 7), or in another field in the RRC reconfiguration message in the LTM candidate information (e.g., field E11 in Fig. 7) that is parallel to the field in which the LTM candidate information is set.

[0064] The update information may include information indicating the execution of security key update (for example, master key update information (for example, MasterKeyUpdate)). The update information (for example, master key update information included in the update information) may include information indicating the execution of security key update (for example, master key update information (for example, MasterKeyUpdate)). gNB The keySetChangeIndicator may also include information (e.g., keySetChangeIndicator) indicating whether to derive the keySetChangeIndicator.

[0065] The update information (e.g., master key update information included in the update information) may include information indicating an NCC (NH Chaining Counter) parameter used to derive the next updated security key (hereinafter, NCC information (e.g., nextHopChainingCount)). The NCC information may be one parameter (i.e., one NCC value), a list of NCC values ​​(i.e., one or more NCC values), or a list (i.e., a list of multiple NCC values) for each base station 200 (e.g., a set of one or more cells (candidate cells)). The list for each base station 200 may be a list for each determination identifier described below.

[0066] The update information (and / or the master key update information) may include information (hereinafter also referred to as a determination identifier) ​​used to determine whether or not to perform a security key update. The determination identifier may be information used to indicate whether or not to perform a security key update. That is, the determination identifier may be information used by the UE 100 to determine whether or not to perform a security key update. The determination identifier may be, for example, a cell set identifier (e.g., also referred to as securityCellSetId) used to determine whether or not to perform a security update, or may be an identifier identifying a cell set for a serving cell (e.g., also referred to as servingSecurityCellSetId). The determination identifier may be a cell set identifier used to determine whether or not to perform a security key update (or a security update) when an LTM cell switch is performed. The determination identifier may be referred to as ltm-SecurityCellsetID. The judgment identifier may be used, for example, to identify whether the corresponding cells are in the same set, or to identify the base station (e.g., gNB-CU) to which the corresponding cell belongs.

[0067] Here, the cell set may simply be a set or a security cell set. Hereinafter, the cell set will also be simply referred to as a set. Furthermore, the cell set identifier may be referred to as a security cell set identifier. For example, the determination identifier may be used to identify whether one or more LTM candidate configurations including update information (and / or master key update information and / or determination identifier) ​​correspond to the same set (e.g., whether they are included in the same set). That is, the determination identifier may be used to identify whether one or more LTM candidate configurations including update information (and / or master key update information and / or determination identifier) ​​are associated with the same base station (e.g., gNB-CU). Furthermore, the determination identifier may be used to identify whether one or more LTM candidate configurations including update information (and / or master key update information and / or determination identifier) ​​are associated with the same base station (e.g., gNB-CU) and / or different base stations (e.g., gNB-CU). Furthermore, the determination identifier may be used to identify whether cells (e.g., LTM candidate cells) corresponding to each of one or more LTM candidate configurations including the update information (and / or master key update information and / or determination identifier) ​​correspond to the same set (whether they are included in the same set). That is, the determination identifier may be used to identify whether cells (e.g., LTM candidate cells) corresponding to each of one or more LTM candidate configurations including the update information (and / or master key update information and / or determination identifier) ​​are associated with the same base station (e.g., gNB-CU). Furthermore, the determination identifier may be used to identify whether cells corresponding to each of one or more LTM candidate configurations including the update information (and / or master key update information and / or determination identifier) ​​are associated with the same base station (e.g., gNB-CU) and / or different base stations (e.g., gNB-CU).

[0068] Here, as described below, if the update information (and / or the master key update information and / or the determination identifier) ​​is not included in the configuration information for LTM (i.e., if the update information (and / or the master key update information and / or the determination identifier) ​​is not present in the configuration information for LTM), the UE 100 may not perform a security key update. In other words, if the update information (and / or the master key update information and / or the determination identifier) ​​is not included in the configuration information for LTM, the UE 100 may determine that each of one or more LTM candidate configurations corresponds to a different set. Also, if the update information (and / or the master key update information and / or the determination identifier) ​​is not included in the configuration information for LTM, the UE 100 may determine that each of one or more LTM candidate configurations is associated with a different base station (e.g., gNB-CU). Furthermore, if the update information (and / or the master key update information and / or the determination identifier) ​​is not included in the configuration information for LTM, it may be determined that the cells (e.g., LTM candidate cells) corresponding to each of one or more LTM candidate configurations correspond to different sets. Furthermore, if the update information (and / or the master key update information and / or the determination identifier) ​​is not included in the configuration information for LTM, it may be determined that the cells (e.g., LTM candidate cells) corresponding to each of one or more LTM candidate configurations are associated with different base stations (e.g., gNB-CUs). Here, the update information may be a first identifier and / or a second identifier, which will be described later.

[0069] That is, the UE 100 may determine whether to perform a security key update based on whether or not the update information (and / or the master key update information and / or the determination identifier) ​​is included in the configuration information for LTM (whether or not the update information (and / or the master key update information and / or the determination identifier) ​​is present in the configuration information for LTM). That is, the UE 100 may not perform a security key update if the update information (and / or the master key update information and / or the determination identifier) ​​is not included in the configuration information for LTM. Furthermore, the UE 100 may not perform a security key update if the update information (and / or the master key update information and / or the determination identifier) ​​is included in the configuration information for LTM and the determination identifier indicates that the security key update will not be performed. Furthermore, the UE 100 may perform a security key update if the update information (and / or the master key update information and / or the determination identifier) ​​is included in the configuration information for LTM and the determination identifier indicates that the security key update will be performed (for example, the UE 100 includes information indicating that the security key update will be performed, as described below).

[0070] Here, whether or not the update information (and / or the master key update information and / or the determination identifier) ​​is included in the LTM configuration information may correspond to whether or not it is included in another field located parallel to the field in which the LTM candidate addition / change list is set in the LTM configuration information (e.g., LTM-Config). Also, whether or not the update information (and / or the master key update information and / or the determination identifier) ​​is included in the LTM configuration information may correspond to whether or not it is included in another field located parallel to the field in which the LTM candidate identifier (e.g., ltm-CandidateId) and / or LTM candidate information (e.g., ltm-Candidateconfig) is set in each LTM candidate information (e.g., LTM-Candidate). In other words, whether or not the update information (and / or the master key update information and / or the determination identifier) ​​is included in the LTM configuration information may correspond to whether or not it is included in each of one or more LTM candidate configurations. Furthermore, whether the update information (and / or the master key update information and / or the determination identifier) ​​is included in the configuration information for LTM may correspond to whether it is included in a field in the RRC reconfiguration message in the LTM candidate information. That is, whether the update information (and / or the master key update information and / or the determination identifier) ​​is included in the configuration information for LTM may correspond to whether it is included in another field in the LTM candidate information that is located parallel to the field in the RRC reconfiguration message where the LTM candidate information is set.

[0071] The control unit 120 may store the determination identifier associated with cell C1 as the determination identifier of the (current) serving cell (i.e., an identifier that identifies the cell for the serving cell). In order to store the determination identifier, the control unit 120 may save the determination identifier as a variable. The control unit 120 may save the determination identifier in a variable VarServingSecurityCellSetID or may save the determination identifier in a new variable VarServingSecurityCellSetID-19. For example, the control unit 120 may determine that the determination identifier included in field E1 or field E21 in FIG. 7 is associated with cell C1 (or the serving cell).

[0072] The update information may include information about a downlink frequency (e.g., an absolute radio frequency channel number (ARFCN)). The information about the downlink frequency may be information used to update a security key. The information about the downlink frequency may indicate the frequencies of a PCI and / or a synchronization signal (SS) and a physical broadcast channel (PBCH) block (SSB). For example, update information including information about the downlink frequency may be included in each of one or more LTM candidate configurations, thereby indicating information about the downlink frequency corresponding to each of the one or more LTM candidate configurations. That is, the update information may include information about the downlink frequency for a cell (e.g., an LTM candidate cell) corresponding to each of the one or more LTM candidate configurations including the update information. For example, the update information included in each of one or more LTM candidate settings may include information regarding the downlink frequency corresponding to the physical cell identifier (e.g., ltm-CandidatePCI) included in each of the one or more LTM candidate settings.

[0073] The update information may include information about security settings. The information may include information indicating a security algorithm and a security key for a radio bearer (hereinafter, security setting information (e.g., securityConfig)). The security setting information may be included in information used to add, modify, and release a radio bearer (e.g., radio bearer setting information (e.g., RadioBearerConfig)). For example, update information including information about security settings may be included in each of one or more LTM candidate configurations, thereby indicating information about security settings corresponding to each of the one or more LTM candidate configurations. In other words, the update information may include information about security settings for cells (e.g., LTM candidate cells) corresponding to each of the one or more LTM candidate configurations including the update information.

[0074] The update information (and the security configuration information) may include information regarding the configuration of an algorithm used for security. This information may include, for example, information indicating a security algorithm for a radio bearer (e.g., security algorithm configuration information (e.g., securityAlgorithmConfig)). The security algorithm configuration information may include information indicating an encryption algorithm used for a signaling radio bearer (SRB) and a data radio bearer (DRB) (e.g., cipheringAlgorithm) and information indicating an integrity algorithm used for the SRB and the DRB (e.g., integrityProtAlgorithm). For example, update information including information regarding the algorithm configuration may be included in each of one or more LTM candidate configurations, thereby indicating information regarding the algorithm configuration corresponding to each of the one or more LTM candidate configurations. In other words, the update information may include information regarding the algorithm configuration for a cell (e.g., an LTM candidate cell) corresponding to each of one or more LTM candidate configurations including the update information.

[0075] The update information (and the security configuration information) may include information on security keys used to generate keys for each security algorithm. For example, the information may be information indicating whether a bearer configured in a list in the radio bearer configuration information is used as a master key or a secondary key for deriving ciphering and / or integrity protection keys (e.g., key to use information (e.g., keyToUse)). For example, the update information including security key information may be included in each of one or more LTM candidate configurations, thereby indicating security key information corresponding to each of one or more LTM candidate configurations. That is, the update information may include security key information for cells (e.g., LTM candidate cells) corresponding to each of one or more LTM candidate configurations including the update information.

[0076] The control unit 230 may include information regarding the re-establishment of PDCP in the configuration information for LTM. The control unit 120 may include at least one of radio bearer configuration information (e.g., RadioBearerConfig) and security configuration information (e.g., securityConfig) as the information. For example, information regarding the re-establishment of PDCP corresponding to each of the one or more LTM candidate configurations may be indicated by including update information including information regarding the re-establishment of PDCP in each of the one or more LTM candidate configurations. That is, the update information may include information regarding the re-establishment of PDCP for cells (e.g., LTM candidate cells) corresponding to each of the one or more LTM candidate configurations including the update information.

[0077] The radio bearer configuration information may include information used to add and / or modify a data radio bearer (DRB) (hereinafter referred to as a DRB addition / modification list (e.g., drb-ToAddModList)) and information used to add and / or modify a signaling radio bearer (SRB) (hereinafter referred to as an SRB addition / modification list (e.g., srb-ToAddModList)).

[0078] Each piece of information (e.g., DRB-ToAddMod) that constitutes the DRB addition modification list may include at least one of the following information: a DRB identifier (e.g., drb-Identity) used to identify the DRB used by UE100, reestablishment PDCP information for the DRB (e.g., reestablishPDCP), and information used to set PDCP parameters (for the DRB) (hereinafter, PDCP setting information (e.g., PDCP-Config)).

[0079] Each piece of information constituting the SRB addition / modification list (e.g., SRB-ToAddMod) may include at least one of the following information: an SRB identifier (e.g., srb-Identity) used to identify the SRB used by UE100; re-establishment PDCP information for the SRB (e.g., reestablishPDCP); and information used to set PDCP parameters (for the SRB) (hereinafter, PDCP setting information (e.g., PDCP-Config)).

[0080] The PDCP configuration information may include information indicating whether ciphering is used (e.g., cipheringDisabled). When included in the PDCP configuration information, this information may indicate that ciphering is disabled regardless of the ciphering algorithm configured for the SRB / DRB. The PDCP configuration information may also include information indicating whether integrity protection is used (e.g., integrityProtection). This information may indicate whether integrity protection is configured for the radio bearer.

[0081] Furthermore, the re-establishment PDCP information may indicate that PDCP should be re-established. The re-establishment PDCP information may be included in the DRB addition modification list and / or the SRB addition modification list, and thus may be set in the configuration information for LTM. The re-establishment PDCP information may be set in the position of field E21 or fields E311, E321 in FIG. 7, or may be set in the position of field E11 in the RRC reconfiguration message in the LTM configuration information. Alternatively, the re-establishment PDCP information may not be included in the configuration information for LTM.

[0082] When the LTM setting information includes update information and / or a determination identifier, the control unit 230 of the base station 200 may set the re-establishment PDCP information in the setting information for LTM. On the other hand, when the LTM setting information does not include update information and / or a determination identifier, the control unit 230 may not set the re-establishment PDCP information in the setting information for LTM. Therefore, when the LTM setting information includes update information and / or a determination identifier, the re-establishment PDCP information may (always) be set in the LTM setting information.

[0083] When the LTM candidate setting information includes update information and / or a determination identifier, the control unit 230 may set the re-establishment PDCP information in the LTM candidate setting information. On the other hand, when the LTM candidate setting information does not include update information and / or a determination identifier, the control unit 230 may not set the re-establishment PDCP information in the LTM candidate setting information. Therefore, when the LTM candidate setting information includes update information and / or a determination identifier, the re-establishment PDCP information may be (always or necessarily) set in the LTM candidate setting information. In this way, it may be possible to set the re-establishment PDCP information for each of one or more pieces of LTM candidate setting information.

[0084] The control unit 230 may set the re-establishment PDCP information in the LTM candidate configuration information associated with the LTM candidate cell of the base station 202 other than the base station itself. On the other hand, the control unit 230 may not set the re-establishment PDCP information in the LTM candidate configuration information associated with the LTM candidate cell of the base station itself. For example, when the control unit 230 includes a determination identifier having a value different from that of the cell of the base station itself (cell C1) in the LTM candidate configuration information, the control unit 230 may set the re-establishment PDCP information in the LTM candidate configuration information. On the other hand, when the control unit 230 includes a determination identifier having a value equal to that of the cell of the base station itself (cell C1) in the LTM candidate configuration information, the control unit 230 may not set the re-establishment PDCP information in the LTM candidate configuration information.

[0085] Step S150: The transmitter 211 of the base station 201 may transmit an RRC reconfiguration message including the LTM setting information from the cell C1 to the UE 100. The receiver 112 of the UE 100 receives the RRC reconfiguration message from the base station 201 (or the cell C1) as an RRC message. This allows the control unit 120 of the UE 100 to receive the LTM setting information from the cell C1 by the RRC message.

[0086] Step S160: The transmitter 111 of the UE 100 may transmit an RRC reconfiguration complete message to the base station 201 (cell C1). The receiver 212 of the base station 201 may receive the RRC reconfiguration complete message from the UE 100 in the cell C1.

[0087] Step S170: Before receiving the cell switch command, the control unit 120 of the UE 100 may perform downlink (DL) synchronization with the LTM candidate cell. The UE 100 may perform DL synchronization based on SSB. The control unit 120 of the UE 100 may perform DL synchronization based on, for example, SSB transmitted from each LTM candidate cell.

[0088] The control unit 120 of the UE 100 may perform uplink (UL) synchronization with the LTM candidate cell before receiving the cell switch command. The control unit 120 may perform timing advance (TA) acquisition of the candidate cell if UE-based TA measurement is configured.

[0089] Step S180: The control unit 120 of UE100 may perform L1 measurement on candidate cells configured by the LTM candidate configuration. The UE100 may transmit a lower-layer measurement report (hereinafter, L1 measurement report) based on the L1 measurement to the base station 200. For example, the transmission unit 111 of UE100 performs L1 measurement on each candidate cell configured by the LTM configuration information, and then transmits the L1 measurement report to the base station 201. The reception unit 212 of the base station 201 receives the L1 measurement report from UE100. The L1 measurement report is a lower-layer measurement report based on the L1 measurement. The L1 measurement report is transmitted in a layer lower than the RRC layer. Note that the measurement report in step S110 is transmitted in the RRC layer.

[0090] The control unit 230 of the base station 201 may determine a target cell in the LTM (i.e., an LTM target cell) based on the L1 measurement report. Furthermore, the control unit 230 may determine whether, in the LTM execution, the UE 100 should execute a RACH-less LTM (RACH-less LTM) in which the UE 100 performs uplink transmission without executing an RA procedure between the UE 100 and the base station 201, or whether the UE 100 should execute a RACH-based LTM (RACH-base LTM) in which an RA procedure is performed between the UE 100 and the base station 201. That is, any one or more LTM candidate cells may correspond to the target cell. For example, a cell that is a target of a cell switch (i.e., an LTM cell switch) among one or more LTM candidate cells may be referred to as a target cell.

[0091] The control unit 230 generates a MAC CE for transmitting an LTM cell switch command. The MAC CE may be referred to as an LTM cell switch command MAC CE, for example. The MAC CE may be a cell switch command that triggers (the execution of) an LTM cell switch. Hereinafter, the LTM cell switch command MAC CE may be referred to as an LTM cell switch command as appropriate. That is, the LTM cell switch command may be used to execute a cell switch to a target cell. For example, the control unit 230 may determine to execute a cell switch to the target cell. Furthermore, the control unit 230 may perform control to transmit an LTM cell switch command including a target configuration identifier indicating an index of a candidate configuration of the target cell (e.g., an identifier of an LTM candidate configuration) to trigger a cell switch to the target cell. The LTM cell switch command may include, for example, at least one of the following information (i.e., fields):

[0092] The cell switch command may include at least one of the following information: a target setting identifier, a timing advance command, and a C field.

[0093] The target configuration identifier (e.g., Target Configuration ID) may indicate an index of a target configuration to apply to the LTM cell switch. That is, the target configuration identifier may correspond to a configuration corresponding to the target cell (e.g., an LTM candidate configuration). As described above, for example, the target configuration identifier may correspond to an index of a candidate configuration for the target cell (e.g., an identifier of the LTM candidate configuration).

[0094] The timing advance command (e.g., Timing Advance Command) may indicate whether TA is valid for the LTM target cell. For example, when FFF is set in the Timing Advance Command field, the field may indicate that valid timing adjustment is not available for the primary timing advance group (PTAG) of the LTM target cell. On the other hand, when a value other than FFF is set as the value of the field, the field may indicate an index value (i.e., a TA value) used to control the amount of timing adjustment to be applied by the MAC entity of the UE 100. As described below, for example, when FFF is set as the value of the field, RACH-based LTM may be performed. Also, when a value other than FFF is set as the value of the field, RACH-less LTM may be performed.

[0095] The C field may indicate the presence of a contention-free random access release field. When the value of the C field is set to "1", it may indicate the presence of fields indicating information used for contention-free random access (e.g., Random Access Preamble index field, S / U field, SS / PBCH index field, PRACH Mask index field, and / or Repetition number field). When the value of the C field is set to "0", it may indicate the absence of the above fields. That is, when the value of the C field is set to “1”, the Random Access Preamble index, uplink carrier (S: Supreme uplink carrier or U: Normal uplink carrier), SS / PBCH index, PRACH Mask index, and / or Repetition number indicated using the above field may be used for the random access procedure in the RACH-based LTM.

[0096] In this operation example, the explanation will proceed assuming that the LTM cell switch command does not include update information.

[0097] Step S190: The transmitting unit 211 of the base station 201 transmits the LTM cell switch command by MAC CE to the UE 100. The receiving unit 112 of the UE 100 receives the LTM cell switch command from the base station 201 by MAC CE.

[0098] The control unit 120 of the UE 100 executes an indication from the MAC layer to the RRC layer based on the reception of the LTM cell switch command MAC CE. This may trigger an LTM cell switch to cell C2, which is the target cell. That is, based on the reception of the LTM cell switch command MAC CE, an indication for triggering an LTM cell switch may be notified from the MAC layer of the UE 100 to the RRC layer of the UE 100. The control unit 120 may execute an LTM cell switch, which is a cell switch from cell C1 to cell C2, based on the LTM configuration information. Here, the indication may include an LTM candidate configuration identifier (i.e., a target configuration identifier) ​​and / or update information (and / or information included in the update information).

[0099] Step S200: The control unit 120 of the UE 100 may perform detachment from the source (source cell (cell C1) / source base station (i.e., base station 201)) and application of the target configuration. During the processing of this step, the control unit 120 may perform the following processing.

[0100] The control unit 120 of the UE 100 may determine an LTM candidate configuration of the target cell based on the target configuration identifier included in the LTM cell switch command. For example, the control unit 120 may execute control to configure (identify) an LTM candidate configuration including an identifier of the LTM candidate configuration corresponding to the target configuration identifier included in the LTM cell switch command. Furthermore, for example, the control unit 120 may execute control to configure the UE 100 with an LTM candidate configuration associated with the identifier of the LTM candidate configuration that is the same as the target configuration identifier included in the LTM cell switch command. The control unit 120 may apply the determined LTM candidate configuration. As a result, the control unit 120 may execute application of the target configuration.

[0101] The control unit 120 may apply an RRC reconfiguration message in the LTM candidate configuration information identified by an LTM candidate configuration identifier, i.e., a target configuration identifier, received from a lower layer (i.e., a MAC layer). The control unit 120 may perform reception processing for the RRC reconfiguration message. In this manner, the control unit 120 may perform processing for the RRC reconfiguration message in the LTM candidate configuration information during execution of the LTM cell switch. That is, the control unit 120 may apply and / or perform reception processing for the RRC reconfiguration message in the RRC layer.

[0102] Step S201: The control unit 120 may determine whether to update the security key. The control unit 120 may determine whether to update the security key based on the update information. The control unit 120 may determine whether to update the security key using, for example, one of the following determination methods.

[0103] As described above, first, the control unit 120 may determine whether to update the security key based on whether the LTM setting information includes update information. As shown in Fig. 8A, if the LTM setting information (e.g., field E21 in the LTM setting information) includes update information (step S311: YES), the control unit 120 may determine to update the security key (step S312). On the other hand, if the LTM setting information (e.g., field E21 in the LTM setting information) does not include update information (step S311: NO), the control unit 120 may determine not to update the security key.

[0104] Second, the control unit 120 may determine whether to perform security key update based on whether update information is included in the LTM candidate setting information. The control unit 120 may determine to perform security key update when update information is included in the LTM candidate setting information set in the UE 100 among the one or more pieces of LTM candidate setting information. Here, the set LTM candidate setting information may be, for example, LTM candidate setting information indicated by a target setting identifier included in the cell switch command (LTM candidate setting information corresponding to the target setting identifier). The LTM candidate setting information may be associated with a cell after the cell switch. On the other hand, the control unit 120 may determine not to perform security key update when update information is not included in the LTM candidate setting information set in the UE 100 among the one or more pieces of LTM candidate setting information.

[0105] Third, the control unit 120 may make a determination based on information included in the update information. If the update information includes information indicating that a security key update is to be performed, the control unit 120 may determine that a security key update is to be performed. On the other hand, if the update information does not include information indicating that a security key update is to be performed, the control unit 120 may determine that a security key update is not to be performed. The information indicating that a security key update is to be performed may be master key update information, or may include information indicating that a new security key K is to be updated. gNB The information may be information indicating whether to derive the keySetChangeIndicator (for example, keySetChangeIndicator).

[0106] Fourth, the control unit 120 may determine whether to perform a security key update based on the determination identifier. The control unit 120 may determine to perform a security key update when the value of the determination identifier (hereinafter, the first identifier) ​​stored as the determination identifier of cell C1 is different (i.e., not equal) from the value of the determination identifier (hereinafter, the second identifier) ​​of cell C2 included in the update information. On the other hand, the control unit 120 may determine not to perform a security key update when the value of the first identifier is equal to the value of the second identifier. For example, the first identifier may be an identifier identifying a cell set for a serving cell (e.g., servingSecurityCellSetId). Furthermore, the second identifier may be a cell set identifier (e.g., securityCellSetId) in the update information included in each of one or more LTM candidate configurations. As described above, the control unit 120 may set (identify) an LTM candidate configuration including an identifier of an LTM candidate configuration corresponding to the target configuration identifier based on the target configuration identifier (i.e., the value of the target configuration identifier) ​​included in the LTM cell switch command. Furthermore, the control unit 120 may determine to perform a security key update when the value of the first identifier and the value of the second identifier included in the set (identified) LTM candidate configuration are different (i.e., not equal). Furthermore, the control unit 120 may determine not to perform a security key update when the value of the first identifier and the value of the second identifier included in the set (identified) LTM candidate configuration are equal (i.e., not to perform a security key update when an LTM cell switch is performed).

[0107] Furthermore, the control unit 120 may determine to perform a security key update if the first identifier is not included in the setting information (and / or update information) for LTM. Furthermore, the control unit 120 may determine to perform a security key update if the first identifier is not included in the corresponding variable. Furthermore, as described above, the control unit 120 may determine not to perform a security key update if the first identifier is not included in the setting information (and / or update information) for LTM. Furthermore, the control unit 120 may determine not to perform a security key update if the first identifier is not included in the corresponding variable. Furthermore, the control unit 120 may determine not to perform a security key update if the second identifier is not included in the setting information (and / or update information) for LTM. Furthermore, the control unit 120 may determine not to perform a security key update if the second identifier is not included in the corresponding variable.

[0108] Note that if the first identifier and the second identifier are different (i.e., not equal), the control unit 120 may store the value of the second identifier as a new variable instead of the value of the first identifier. Also, if the value of the first identifier and the value of the second identifier are different (i.e., not equal) and the corresponding variable contains the value of the first identifier, the control unit 120 may replace the variable with the value of the second identifier (the value of the first identifier may be replaced with the value of the second identifier). Hereinafter, the value of the first identifier will also be simply referred to as the first identifier. Also, the value of the second identifier will also be simply referred to as the second identifier.

[0109] Note that the determination identifier corresponding to the second identifier may be set in a position such as field E311 or E321 of the LTM candidate information, or may be set in a position such as field E51 or E52 in an RRC reconfiguration message in the LTM candidate information. The determination identifier may be set in field E21 of the LTM configuration information as a list of determination identifiers. In this case, the determination identifier may be associated with an identifier of the LTM candidate configuration and / or a physical cell identifier of the LTM candidate configuration. The control unit 120 may use the determination identifier associated with the applied LTM candidate configuration and / or the target cell as the second identifier.

[0110] The control unit 120 may determine not to update the security key if the update information (or the LTM setting information) does not include a determination identifier. The control unit 120 may determine not to update the security key if the update information (or the LTM setting information) does not include a determination identifier, even if the LTM setting information and / or the LTM candidate setting information includes information indicating the execution of the above-mentioned security key update.

[0111] 8B, the control unit 120 may determine whether or not a first identifier is stored (step S321). If the first identifier is stored, the control unit 120 may execute the process of step S322. On the other hand, if the first identifier is not stored, the control unit 120 may execute the process of step S324.

[0112] In step S322, the control unit 120 may determine whether the LTM candidate information includes the second identifier. If the LTM candidate information includes the second identifier, the control unit 120 may execute the process of step S323. On the other hand, if the LTM candidate information does not include the second identifier, the control unit 120 may end the process. Therefore, the control unit 120 may determine not to update the security key.

[0113] In step S323, the control unit 120 may determine whether the value of the first identifier is different from the value of the second identifier. If the value of the first identifier is different from the value of the second identifier, the control unit 120 may execute the process of step S324. On the other hand, if the value of the first identifier is equal to the value of the second identifier, the control unit 120 may end the process. Therefore, the control unit 120 may determine not to update the security key.

[0114] In step S324, the control unit 120 may determine whether the LTM candidate information includes update information. If the LTM candidate information includes update information, the control unit 120 may execute the process of step S325. On the other hand, if the LTM candidate information does not include update information, the control unit 120 may end the process. Therefore, the control unit 120 may determine not to update the security key.

[0115] If the control unit 120 determines that the security key is to be updated, the control unit 120 may execute the process of step S202. If the control unit 120 determines that the security key is not to be updated, the control unit 120 may skip the process of step S202.

[0116] Step S202: The control unit 120 executes a security key update process. The control unit 120 may execute an AS security key update process as the security key update process. The control unit 120 may update a key for the base station (for example, K gNB ) may be updated or derived.

[0117] The key for the base station is the key for the AMF (e.g., K AMF ) by the UE 100 (e.g., ME (Mobile Equipment)) and the AMF. The key for the base station may be further derived by the ME and the source base station when performing horizontal and vertical key derivation. The key for the AMF may be a key derived from the UE 100 (e.g., ME) and the SEAF (Security Anchor Function). In addition, the key for the base station may be derived by referring to the key of the current base station. In this case, the key for the base station may be derived using cell-specific information (e.g., PCI, downlink frequency, etc. of the target cell).

[0118] The control unit 120 may execute either a first update process or a second update process as the security key update process.

[0119] In the first update process, the control unit 120 may update (or derive) the security key based on a key for the current base station or a next hop parameter (NH) as the security key update process. The control unit 120 may update (or derive) the security key using NCC information. For example, if the NCC information is one parameter (i.e., one NCC value), the control unit 120 may update the security key using the NCC value.

[0120] When the NCC information is a list of NCC values, the control unit 120 may select an NCC value from the list. The control unit 120 may select the top NCC value in the list. In this case, the control unit 120 may delete the selected NCC value. The control unit 120 may select the top NCC value from among unused NCC values ​​in the list. When NCC values ​​and determination identifiers are associated in the list, the control unit 120 may select the NCC value associated with the determination identifier corresponding to the second identifier.

[0121] When the NCC information is a list for each base station (i.e., when multiple lists are set as the NCC information), the control unit 120 may use, for example, a list of NCC values ​​associated with a determination identifier. The control unit 120 may select the first NCC value from among the unused NCC values ​​in the list, or may select the first unused NCC value.

[0122] In the second update process, the control unit 120 updates the AMF key (for example, K AMF ) based on which the updating (or derivation) of the security keys may be performed.

[0123] Here, the control unit 120 generates the new security key K gNB The control unit 120 may switch between the first update process and the second update process based on information indicating whether or not the keySetChangeIndicator included in the master key update information indicates that a new security key K should be derived. gNB On the other hand, if the keySetChangeIndicator does not indicate that a new security key K should be derived (for example, if the keySetChangeIndicator is set to "false"), the control unit 120 may execute the first update process. gNB If the keySetChangeIndicator does not indicate that the key should be derived (e.g., the keySetChangeIndicator is set to "ture"), a second update process may be performed.

[0124] Alternatively, when master key update information is included in the LTM setting information or the LTM candidate setting information set in the UE 100, the control unit 120 may execute the first update process without executing the second update process regardless of the keySetChangeIndicator. When master key update information is included, the control unit 120 may consider that the keySetChangeIndicator is always set to "false". When the control unit 120 determines to update the security key, the control unit 120 may execute the first update process or may consider that the keySetChangeIndicator is always set to "false".

[0125] When performing the security key update process, the control unit 120 may derive a security key associated with the key for the base station. The security key may include, for example, a key for RRC signaling (hereinafter referred to as an RRC key) and a key for UP traffic (hereinafter referred to as an UP traffic key).

[0126] The RRC key is a key for the base station (e.g., K gNB ) by the UE 100 (e.g., ME) and the base station 200. The RRC key may be a key (e.g., K) that is used only for protecting RRC signaling in conjunction with a specific integrity algorithm. RRCint ), and a key (e.g., K) that is used only for protecting RRC signaling in conjunction with a specific encryption algorithm. RRCenc ) and

[0127] The UP traffic key may be a key derived by the UE 100 (e.g., ME) and the base station 200. The UP traffic key may be a key (e.g., K) that is used exclusively for protecting UP traffic between the UE 100 (e.g., ME) and the base station 200 in conjunction with a specific integrity algorithm. UPenc ) and a key (e.g., K) that is used only for protecting UP traffic between the UE 100 (e.g., ME) and the base station 200 together with a specific encryption algorithm. UPint ) and

[0128] For example, when the LTM setting information or the LTM candidate setting information set in the UE 100 includes security algorithm setting information, the control unit 120 determines an RRC key (K RRCenc ) and UP traffic key (K UPenc ) and derives an RRC key (K) based on information indicating an integrity algorithm (e.g., integrityProtAlgorithm). RRCint ) and UP traffic key (K UPint On the other hand, for example, when the LTM setting information or the LTM candidate setting information set in the UE 100 does not include security algorithm setting information, the control unit 120 may derive the RRC key (K RRCenc ) and UP traffic key (K UPenc ) and derives an RRC key (K) based on information indicating the currently set integrity algorithm (e.g., integrityProtAlgorithm). RRCint ) and UP traffic key (K UPint ) can be derived.

[0129] Step S203: The control unit 120 may determine the process to be executed for PDCP (hereinafter, referred to as PDCP process) The control unit 120 may determine the PDCP process by any of the following methods.

[0130] First, when performing an LTM cell switch based on the LTM setting information, the control unit 120 may determine the PDCP processing based on whether re-establishment PDCP information is set in the LTM setting information. For example, when the re-establishment PDCP information is set in field E21 of FIG. 7, the control unit 120 may determine the first PDCP processing described below as the PDCP processing. On the other hand, for example, when the re-establishment PDCP information is not set in field E21 of FIG. 7, the control unit 120 may determine the second PDCP processing described below as the PDCP processing. Here, whether the re-establishment PDCP information is set in the LTM setting information may correspond to whether the re-establishment PDCP information is included in the LTM setting information. In other words, whether the re-establishment PDCP information is set in the LTM setting information may correspond to whether the re-establishment PDCP information exists in the LTM setting information. For example, whether or not the re-establishment PDCP information is set in the LTM setting information may correspond to whether or not the re-establishment PDCP information is included (exists) in field E21 of FIG.

[0131] The control unit 120 may determine the first PDCP process as the PDCP process when re-establishment PDCP information is set (for example, when the re-establishment PDCP information is included (exists)) in a field (for example, field E311, E321, etc.) in the LTM candidate configuration information set in the UE 100. On the other hand, the control unit 120 may determine the second PDCP process as the PDCP process when the re-establishment PDCP information is not set in the field (for example, when the re-establishment PDCP information is not included (does not exist)).

[0132] The control unit 120 may determine the first PDCP process as the PDCP process when re-establishment PDCP information is set (for example, when the re-establishment PDCP information is included (exists)) in a field (for example, field E51, E52, etc.) in the RRC reconfiguration message in the LTM candidate configuration information set in the UE 100. On the other hand, the control unit 120 may determine the second PDCP process as the PDCP process when the re-establishment PDCP information is not set in the field (for example, when the re-establishment PDCP information is not included (does not exist)).

[0133] Second, when updating a security key based on the execution of an LTM cell switch, the control unit 120 may determine a process for applying the updated security key as the PDCP process. For example, when updating a security key, the control unit 120 may execute a first PDCP process as the process for applying the updated security key. Furthermore, when updating a security key, the control unit 120 may execute the first PDCP process, assuming that the re-establishment PDCP information is set regardless of whether the re-establishment PDCP information is set. Therefore, the re-establishment PDCP information does not have to be set in the LTM configuration information and the LTM candidate configuration information. For example, the first PDCP process and / or the second PDCP process may include re-establishing PDCP. That is, the first PDCP process and / or the second PDCP process may include re-establishing a PDCP entity. That is, the first PDCP process and / or the second PDCP process may include a process related to re-establishing a PDCP entity. Hereinafter, the re-establishment of the PDCP (i.e., the PDCP entity) will also be referred to as the re-configuration of the PDCP.

[0134] On the other hand, for example, when the security key is not updated, the control unit 120 may execute the second PDCP process. Alternatively, when the security key is not updated, the control unit 120 may execute the second PDCP process, assuming that the re-establishment PDCP information is not set, regardless of whether the re-establishment PDCP information is present.

[0135] Step S204: The control unit 120 may execute the process for the PDCP process. The control unit 120 may execute the PDCP process determined in step S203.

[0136] The control unit 120 may execute the following process as the first PDCP process. The control unit 120 may execute at least one of the following operations as a process for PDCP of the SRB. The control unit 120 may obtain a key for the base station (for example, K gNB ) and the associated RRC key (e.g., K RRCint ) and the integrity algorithm. gNB ) and the associated RRC key (e.g., K RRCenc The PDCP entity may be configured to apply the integrity algorithm, encryption algorithm, and security key provided from the RRC layer to the PDCP layer through this configuration. The control unit 120 may then re-establish the PDCP entity for the SRB. By re-establishing the PDCP entity, the control unit 120 may apply the integrity algorithm, encryption algorithm, and security key provided from the RRC layer to the PDCP entity. Furthermore, if the LTM configuration information and / or the LTM candidate configuration information includes PDCP configuration information, the control unit 120 may re-configure the PDCP entity according to the PDCP configuration information.

[0137] The control unit 120 may perform at least one of the following operations as a first PDCP process for the PDCP of the DRB: When cipheringDisabled is not set in the PDCP configuration information set in the PDCP entity of the DRB, the control unit 120 sets the encryption algorithm and the key for the base station (for example, K gNB ) and the associated UP traffic key (e.g., K UPenc) in the PDCP entity. When integrityProtection is set in the PDCP configuration information set in the PDCP entity of the DRB, the control unit 120 may set the integrity algorithm in the PDCP entity according to the security configuration information. The control unit 120 may set a key for the base station (e.g., K gNB ) and the associated UP traffic key (e.g., K UPint ) may be applied. When the PDCP configuration information includes information to be indicated to the PDCP entity, the control unit 120 may indicate the information to the PDCP entity (i.e., a lower layer). Thereafter, the control unit 120 may re-establish the PDCP entity for the DRB, similar to the case of the SRB. Furthermore, when the LTM configuration information and / or the LTM candidate configuration information includes PDCP configuration information, the control unit 120 may re-configure the PDCP entity according to the PDCP configuration information, similar to the case of the DRB.

[0138] The control unit 120 may perform the following process as the second PDCP process. The control unit 120 may perform the following operation as the process for PDCP of the SRB. For example, the control unit 120 may trigger the PDCP entity to discard an SDU. Furthermore, when the LTM configuration information and / or the LTM candidate configuration information includes PDCP configuration information, the control unit 120 may reconfigure the PDCP entity according to the PDCP configuration information. Alternatively, the control unit 120 may skip the process for PDCP.

[0139] As the second PDCP process, the control unit 120 may reconfigure the PDCP entity in the same manner as the DRB, as a process for the PDCP of the DRB. Alternatively, the control unit 120 may skip the process for the PDCP.

[0140] Step S210: If the control unit 120 of the UE 100 determines to perform the RACH-based LTM, it executes a random access (RA) procedure. As described above, the control unit 120 may determine whether to perform the RACH-based LTM or the RACH-less LTM based on the value included in the timing advance command. The control unit 120 determines to perform the RACH-based LTM when FFF is set in the timing advance command. On the other hand, the control unit 120 may determine to perform the RACH-less LTM when a value other than FFF is set in the timing advance command. That is, the control unit 120 of the UE 100 may skip the processing of step S210.

[0141] Step S220: The control unit 120 of the UE 100 may complete the LTM cell switch procedure by sending an RRC reconfiguration complete message to the target cell, cell C2. When the RACH-based LTM is performed, the control unit 120 of the UE 100 may consider that the LTM cell execution procedure has been successfully performed (i.e., LTM completion has been performed) when the random access procedure is successfully completed. On the other hand, when the UE 100 performs the RACH-less LTM, the transmission unit 111 of the UE 100 may transmit an uplink transmission (e.g., initial uplink data) to the base station 201. When the control unit 120 of the UE 100 determines that the uplink transmission has been successfully received by the network, the control unit 120 may consider that the LTM execution procedure has been successfully performed (i.e., LTM completion has been performed).

[0142] Note that the control unit 120 may update the security key and perform the PDCP process after receiving the LTM cell switch command and before completing the execution of the LTM cell switch. Therefore, the control unit 120 may update the security key (and perform the PDCP process) after the process of step S190 and before the process of step S220.

[0143] First, the control unit 120 may perform security key update and / or PDCP processing before processing the RRC reconfiguration message during the execution of the LTM cell switch. For example, after the LTM cell switch to the target cell is triggered by notification of an indication from the MAC layer to the RRC layer based on the reception of an LTM cell switch command MAC CE, the control unit 120 may perform security key update (and / or PDCP processing) before processing the RRC reconfiguration message. That is, the control unit 120 may perform security key update (and / or PDCP processing) based on the notification of the indication from the MAC layer to the RRC layer. For example, the control unit 120 may perform security key update (and / or PDCP processing) when an indication is notified from the MAC layer to the RRC layer (e.g., at the timing when the indication is notified from the MAC layer to the RRC layer).

[0144] As shown in FIG. 9A , in step S411, the control unit 120 may perform a security key update process, similar to step S202. In step S412, the control unit 120 may perform a process for PDCP (i.e., PDCP process) similar to step S204. As the PDCP process, the control unit 120 may perform a process for PDCP of the SRB (hereinafter, referred to as PDCP process for the SRB) and a process for PDCP of the DRB (hereinafter, referred to as PDCP process for the DRB). Therefore, the control unit 120 may perform the PDCP process for the SRB and the PDCP process for the DRB at the same timing. Alternatively, the control unit 120 may perform the PDCP process for the SRB and the PDCP process for the DRB at different timings. The control unit 120 may first perform the PDCP process for the SRB and then perform the PDCP process for the DRB. As a result, by first executing the PDCP process for the SRB used in processing the control information, for example, the process of transmitting an RRC reconfiguration completion message, which is regarded as the completion of the RACH-less LTM cell switch, can be properly executed, thereby enabling the LTM (procedure) to be properly completed. Alternatively, the PDCP process for the SRB may be executed later, and the PDCP process for the DRB may be executed first. Furthermore, in this step, the control unit 120 may execute only one PDCP process, and execute the other PDCP process during or after execution of step S413 (see steps S422 and S434). In step S413, the control unit 120 may apply the RRC reconfiguration message in the LTM candidate configuration information, as in step S200.

[0145] Second, the control unit 120 may perform security key updates and / or PDCP processing while processing an RRC reconfiguration message during an LTM cell switch. For example, the control unit 120 may perform security key updates and / or PDCP processing while processing an RRC reconfiguration message.

[0146] As shown in FIG. 9B , in step S420, the control unit 120 may apply the RRC reconfiguration message in the LTM candidate configuration information, similar to step S200. Here, the control unit 120 may perform a security key update process in step S421, for example, during the process of applying the RRC reconfiguration message. In step S422, the control unit 120 may perform PDCP processes, similar to step S204. In this step, the control unit 120 may perform PDCP processes for the SRB and the DRB. Alternatively, the control unit 120 may perform only one of the PDCP processes for the SRB and the PDCP process for the DRB in step S422, and perform the other PDCP process after performing step S420 (see step S434). That is, the control unit 120 may perform security key update (and / or PDCP process) based on applying the RRC reconfiguration message included in the LTM candidate configuration information. For example, the control unit 120 may perform security key updates (and / or PDCP processing) when applying an RRC reconfiguration message included in the LTM candidate setting information (e.g., at the timing of applying the RRC reconfiguration message included in the LTM candidate setting information).

[0147] Third, the control unit 120 may perform security key updates and / or PDCP processing after performing processing on the RRC reconfiguration message during the execution of an LTM cell switch.

[0148] 9C , in step S431, the control unit 120 may apply the RRC reconfiguration message in the LTM candidate configuration information, similar to step S200. In step S432, the control unit 120 may release the radio bearers for the SRBs and / or DRBs (and / or logical channels for the SRBs and / or DRBs) configured for the UE 100 before the LTM cell switch procedure. The radio bearers and logical channels here may be radio bearers and logical channels that were part of the configuration of the UE 100 before the LTM cell switch procedure and are not part of the LTM candidate configuration. In step S433, the control unit 120 may perform a security key update process, similar to step S202. In step S434, the control unit 120 may perform a PDCP process, similar to step S204. That is, the control unit 120 may perform security key update (and / or PDCP processing) based on having performed processing on the RRC reconfiguration message included in the LTM candidate configuration information (i.e., information included in the RRC reconfiguration message). Furthermore, the control unit 120 may perform security key update (and / or PDCP processing) based on having released radio bearers for SRBs and / or DRBs (and / or logical channels for SRBs and / or DRBs). For example, the control unit 120 may perform security key update (and / or PDCP processing) when having performed processing on the RRC reconfiguration message included in the LTM candidate configuration information (e.g., at the timing after having performed processing on the RRC reconfiguration message included in the LTM candidate configuration information). In addition, the control unit 120 may perform security key updates (and / or PDCP processing) when releasing a radio bearer for an SRB and / or a DRB (and / or a logical channel for an SRB and / or a DRB) (for example, at the timing after releasing a radio bearer for an SRB and / or a DRB (and / or a logical channel for an SRB and / or a DRB)).

[0149] When the RACH-based LTM is executed, the control unit 120 may update the security key and / or execute the PDCP process before executing the RACH-based LTM. The control unit 120 may update the security key and / or execute the PDCP process after executing the RACH-based LTM.

[0150] As described above, in the UE 100 that executes the LTM, the receiving unit 112 may receive configuration information for the LTM, including update information related to security key updates, from the cell C1 via an RRC message. The control unit 120 may execute an LTM cell switch, which is a cell switch from the cell C1 to the cell C2, based on the configuration information. When executing the LTM cell switch, the control unit 120 may execute a security key update using the update information. This allows the UE 100 to execute a security key update using appropriate update information in the LTM. As a result, the UE 100 can execute a security key update appropriately in the LTM.

[0151] Furthermore, the control unit 120 may determine whether to update the security key based on the update information, which prevents the control unit 120 from constantly updating the security key and allows the control unit 120 to update the security key when necessary.

[0152] Furthermore, the setting information may include one or more pieces of LTM candidate setting information related to candidate setting in LTM. The control unit 120 may determine that a security key update is to be performed when update information is included in the LTM candidate setting information set in the communication device among the one or more pieces of LTM candidate setting information. The control unit 120 may determine that a security key update is not to be performed when update information is not included in the LTM candidate setting information set in the communication device among the one or more pieces of LTM candidate setting information. This enables the UE 100 to perform a security key update when necessary.

[0153] Furthermore, the control unit 120 may determine to update the security key when the update information includes information indicating the execution of an update of the security key. The control unit 120 may determine not to update the security key when the update information does not include information indicating the execution of an update of the security key. This allows the UE 100 to clearly determine whether or not to update the security key based on the information.

[0154] Furthermore, the control unit 120 may store a first identifier associated with the cell C1 and used to determine whether to perform a security key update. The update information may include a second identifier used to determine whether to perform a security key update. The control unit 120 may determine to perform a security key update when the value of the first identifier and the value of the second identifier are different. The control unit 120 may determine not to perform a security key update when the value of the first identifier and the value of the second identifier are equal. This allows the UE 100 to determine whether to perform a security key update using the first identifier and the second identifier associated with the cell C1. This allows the UE 100 to appropriately perform a security key update.

[0155] Furthermore, in the UE 100 that executes the LTM, the receiving unit 112 may receive a cell switch command from the base station 200 via the MAC CE. The control unit 120 may control the execution of the LTM cell switch. The control unit 120 may execute a security key update after receiving the cell switch command and before the execution of the LTM cell switch is completed. As a result, the security key is updated by the time the UE 100 completes the execution of the LTM cell switch, and the UE 100 can appropriately execute the security key update. Furthermore, by clarifying the timing of the security key update, an appropriate security key can be set between the UE 100 and the base station 200.

[0156] Furthermore, the receiving unit 112 may receive, from the base station, LTM candidate configuration information including an RRC reconfiguration message used to set a candidate configuration in LTM. The control unit 120 may perform security key update before performing processing on the RRC reconfiguration message during execution of the LTM cell switch. This allows the UE 100 to perform security key update without changing the operation during processing of the RRC reconfiguration message, thereby reducing the impact on processing of the RRC reconfiguration message for the UE 100.

[0157] Furthermore, after an LTM cell switch to the target cell is triggered by an indication from the MAC layer to the RRC layer based on the reception of the LTM cell switch command MAC CE, the control unit 120 may perform a security key update before performing a process for the RRC reconfiguration message. This makes it possible to perform a security key update without changing the operation of the UE 100 in the process for the RRC reconfiguration message, and reduces the impact on the operation (and technical specifications) of the process for the RRC reconfiguration message of the UE 100.

[0158] The receiving unit may also receive, from the base station, LTM candidate configuration information including a radio resource control (RRC) reconfiguration message used to set a candidate configuration in LTM. The control unit 120 may perform security key updates while processing the RRC reconfiguration message during execution of the LTM cell switch. This allows the UE 100 to process the RRC reconfiguration message in the same way as in a conventional conditional handover (CHO), thereby reducing the impact on existing operations (and technical specifications) of the UE 100.

[0159] Furthermore, the control unit 120 may update the security key while processing the RRC reconfiguration message after the LTM cell switch to the target cell is triggered by an indication from the MAC layer to the RRC layer based on the reception of the LTM cell switch command MAC CE. This allows the UE 100 to process the RRC reconfiguration message in the same way as in conventional conditional handover (CHO), thereby reducing the impact on existing operations (and technical specifications) of the UE 100.

[0160] Furthermore, the receiving unit 112 may receive LTM candidate setting information including an RRC reconfiguration message used to set a candidate setting in LTM from the base station 200. The control unit 120 may execute a security key update after executing processing for the RRC reconfiguration message during execution of an LTM cell switch. This allows information about the security key to be transmitted safely while ensuring security, similar to handover.

[0161] Furthermore, the control unit 120 may update the security key after releasing the radio bearer and the logical channel that were set to the UE 100 before the execution of the LTM cell switch. This allows the UE 100 to no longer use the settings before the cell switch, and therefore allows the security key to be updated appropriately.

[0162] Furthermore, in the UE 100 that executes the LTM, the receiving unit 112 may receive configuration information for the LTM, in which re-establishment PDCP information can be set, from the cell C1 by an RRC message. When executing the LTM cell switch based on the configuration information, the control unit 120 may determine the process to be executed on the PDCP based on whether the re-establishment PDCP information is set in the configuration information. As a result, the process to be executed on the PDCP is executed by the time the UE 100 completes the execution of the LTM cell switch, and the UE 100 can appropriately execute the process to be executed on the PDCP associated with the update of the security key.

[0163] Furthermore, when performing an LTM cell switch, the control unit 120 may update the security key. When the re-establishment PDCP information is set in the configuration information, the control unit 120 may determine a process for applying the updated security key as a process to be performed on the PDCP. This allows the UE 100 to appropriately determine a process to be performed on the PDCP based on the re-establishment PDCP information.

[0164] Further, when the configuration information includes update information regarding update of the security key, the re-establishment PDCP information may be set in the configuration information. Thereby, when the UE 100 updates the security key based on the update information, the UE 100 can appropriately determine the process to be performed on the PDCP based on the re-establishment PDCP information.

[0165] Furthermore, when the configuration information includes an identifier for determining whether to update the security key, the re-establishment PDCP information may be set in the configuration information. Thereby, when the UE 100 updates the security key based on the update information, the UE 100 can appropriately determine the process to be performed on the PDCP based on the re-establishment PDCP information.

[0166] The configuration information may also include one or more pieces of LTM candidate configuration information related to candidate configuration in LTM. PDCP re-establishment information may be set for each of the one or more pieces of LTM candidate configuration information. This makes it possible to flexibly control processing to be performed on PDCP based on the PDCP re-establishment information.

[0167] Furthermore, in the UE 100 that executes the LTM, the receiving unit 112 may receive configuration information for the LTM from the cell C1 via an RRC message. The control unit 120 may execute an LTM cell switch based on the configuration information. When updating the security key based on the execution of the LTM cell switch, the control unit 120 may determine a process for applying the updated security key as a process to be executed on the PDCP. This makes it possible to reliably apply the updated security key in the PDCP, and the security key update is executed appropriately.

[0168] Furthermore, the configuration information may include LTM candidate configuration information including an RRC reconfiguration message used to set a candidate configuration in LTM. The control unit 120 may execute the process determined as the process to be executed for PDCP before executing the process for the RRC reconfiguration message in the LTM candidate configuration information during the execution of the LTM cell switch. This allows the UE 100 to execute the PDCP process without changing the operation during the processing of the RRC reconfiguration message, thereby reducing the impact on the processing of the RRC reconfiguration message for the UE 100.

[0169] Furthermore, the control unit 120 may execute the process determined as the process to be executed for the PDCP while executing the process for the RRC reconfiguration message in the LTM candidate configuration information during the execution of the LTM cell switch. This allows the UE 100 to execute the process for the RRC reconfiguration message in the same way as in the conventional conditional handover (CHO), thereby reducing the impact on the existing operation (and technical specifications) of the UE 100.

[0170] Furthermore, the control unit 120 may execute the process determined as the process to be executed for the PDCP after executing the process for the RRC reconfiguration message in the LTM candidate configuration information during the execution of the LTM cell switch. This allows the PDCP process to be executed in the same way as the handover, and reduces the impact on the existing operation (and technical specifications) of the UE 100.

[0171] (Second Operation Example) A second operation example will be described with reference to Fig. 6 and Fig. 10. Previous descriptions may be omitted. In this operation example, a case will be described in which the LTM cell switch command MAC CE includes update information.

[0172] 6, the control unit 230 of the base station 200 does not need to include update information in the RRC reconfiguration message. The control unit 230 may include update information in the RRC reconfiguration message. The update information may include a list of NCC values ​​in which the NCC values ​​are associated with index values.

[0173] 6, the transmitting unit 211 of the base station 200 may transmit an LTM cell switch command including the update information to the UE 100 in the cell C1. The receiving unit 112 of the UE 100 may receive the LTM cell switch command including the update information from the cell C1.

[0174] The control unit 230 of the base station 200 may include, in the LTM cell switch command, information indicating the presence of information used to update the security key (hereinafter referred to as specific field information). The specific field information may be the value of R (reserved bit). When the control unit 230 includes the specific field information in the LTM cell switch command, the control unit 230 may include update information in the LTM cell switch command. On the other hand, when the control unit 230 does not include the specific field information in the LTM cell switch command, the control unit 230 does not need to include update information in the LTM cell switch command.

[0175] In step S201, the control unit 120 of the UE 100 may determine whether or not to perform a security key update based on the update information included in the LTM cell switch command.

[0176] For example, the control unit 120 may determine to update the security key when the LTM cell switch command (MAC CE) includes information indicating the presence of information used to update the security key, whereas the control unit 120 may determine not to update the security key when the LTM cell switch command (MAC CE) does not include information indicating the presence of information used to update the security key.

[0177] 9A , the control unit 120 may determine whether to update the security key (step S512) if the LTM cell switch command includes update information (step S511: YES). On the other hand, the control unit 120 may determine not to update the security key if the LTM cell switch command does not include update information (step S511: NO).

[0178] 9B, the control unit 230 may determine whether or not to update the security key based on the determination identifier. In step S521, similar to step S321 in FIG. 8B, the control unit 120 may determine whether or not the first identifier is stored. If the first identifier is stored, the control unit 120 may execute the process of step S522. On the other hand, if the first identifier is not stored, the control unit 120 may execute the process of step S524.

[0179] In step S522, the control unit 120 may determine whether the LTM cell switch command and / or the LTM candidate information includes a second identifier. If the LTM cell switch command and / or the LTM candidate information includes the second identifier, the control unit 120 may execute the process of step S523. On the other hand, if the LTM cell switch command and / or the LTM candidate information does not include the second identifier, the control unit 120 may end the process. Therefore, the control unit 120 may determine not to update the security key.

[0180] In step S523, the control unit 120 may determine whether the value of the first identifier is different from the value of the second identifier, similar to step S523. If the value of the first identifier is different from the value of the second identifier, the control unit 120 may execute the process of step S524. On the other hand, if the value of the first identifier is equal to the value of the second identifier, the control unit 120 may end the process. Therefore, the control unit 120 may determine not to update the security key.

[0181] In step S524, the control unit 120 may determine whether the LTM cell switch command and / or the LTM candidate information includes update information. If the LTM cell switch command and / or the LTM candidate information includes update information, the control unit 120 may execute the process of step S325. On the other hand, if the LTM cell switch command and / or the LTM candidate information does not include update information, the control unit 120 may end the process. Therefore, the control unit 120 may determine not to update the security key.

[0182] In addition, if the LTM cell switch command and the LTM setting information (or LTM candidate information) contain update information, the control unit 120 may use the update information contained in the LTM setting information (or LTM candidate information) in preference to the update information contained in the LTM cell switch command to perform the security key update.

[0183] Alternatively, if the LTM cell switch command and the LTM setting information (or LTM candidate information) contain update information, the control unit 120 may use the update information contained in the LTM cell switch command in preference to the update information contained in the LTM setting information (or LTM candidate information) to perform a security key update.

[0184] As described above, in the UE 100 that executes the LTM, the receiving unit 112 may receive an RRC message including configuration information for the LTM and an LTM cell switch command MAC CE including update information from the cell C1. The control unit 120 may execute the LTM cell switch based on the configuration information. When executing the LTM cell switch, the control unit 120 may determine whether to execute a security key update based on the update information. This allows the UE 100 to execute a security key update using appropriate update information in the LTM. As a result, the UE 100 can appropriately execute a security key update in the LTM.

[0185] Furthermore, the control unit 120 may determine that the security key is to be updated when the LTM cell switch command (MAC CE) includes information indicating the presence of information used to update the security key. The control unit 120 may determine that the security key is not to be updated when the LTM cell switch command (MAC CE) does not include information indicating the presence of information used to update the security key. This allows the UE 100 to determine whether to update the security key simply by focusing on whether the information is set.

[0186] Furthermore, the control unit 120 may update the security key by using the update information included in the LTM setting information (or the LTM candidate information) preferentially over the update information included in the LTM cell switch command. This allows the UE 100 to appropriately update the security key based on the update information received in the RRC layer, which has higher security than the MAC layer.

[0187] Furthermore, the control unit 120 may perform the update of the security key by using the update information included in the LTM cell switch command with priority over the update information included in the LTM setting information (or the LTM candidate information). This allows the UE 100 to perform the update of the security key based on the latest update information.

[0188] (Third Operation Example) A third operation example will be described with reference to Fig. 6 and Fig. 11. Previous descriptions may be omitted. In this operation example, a case where the LTM cell switch fails will be described. After step S190 in Fig. 6, the UE 100 may perform the following operations.

[0189] Step S611: The control unit 120 detects an LTM cell switch failure. An LTM cell switch failure is also referred to as a reconfiguration failure or a reconfiguration with sync failure. For example, the control unit 120 may initiate a connection (e.g., RRC connection) re-establishment procedure based on the detection of the LTM cell switch failure. Here, the control unit 120 may perform cell (re)selection in the connection re-establishment procedure. That is, the control unit 120 may perform (trigger) cell (re)selection based on the detection of the LTM cell switch failure. Here, if the cell selected based on the cell (re)selection is any of the LTM candidate cells (e.g., one cell among one or more LTM candidate cells), the control unit 120 may perform an LTM cell switch procedure for the cell (i.e., the selected LTM candidate cell). That is, if the cell selected based on the failure of the LTM cell switch is any of the LTM candidate cells, the control unit 120 may perform an LTM cell switch procedure for the cell (i.e., the selected LTM candidate cell).

[0190] Here, when the selected cell is any of the LTM candidate cells, the base station 200 may transmit information indicating that an LTM cell switch procedure for the cell (i.e., the selected LTM candidate cell) is to be performed (for example, also referred to as attemptLTM-Switch) in the LTM configuration information (and / or the LTM candidate information, and / or the LTM candidate configuration, and / or the RRC reconfiguration message). That is, when the information is included (exists) in the LTM configuration information (and / or the LTM candidate information, and / or the LTM candidate configuration, and / or the RRC reconfiguration message), the control unit 120 of the UE 100 may perform the LTM cell switch procedure for the cell (i.e., the selected LTM candidate cell). Furthermore, if the information is not included (does not exist) in the LTM setting information (and / or LTM candidate information and / or LTM candidate setting), the control unit 120 of UE 100 may not perform an LTM cell switch procedure for the cell (i.e., the selected LTM candidate cell).

[0191] Here, the failure of the LTM cell switch may be detected based on the expiration of a predetermined timer (i.e., a predetermined period, which may be referred to as T304) after the LTM cell switch is triggered. For example, the base station 200 may include information indicating the value of the predetermined timer in the LTM configuration information (and / or the LTM candidate information, and / or the LTM candidate configuration, and / or the RRC reconfiguration message) and transmit the information to the UE 100. The control unit 120 of the UE 100 may start the predetermined timer when an indication to trigger the LTM cell switch is notified from a lower layer (i.e., from the MAC layer to the RRC layer) based on the reception of the LTM cell switch command MAC CE. That is, the control unit 120 may start the predetermined timer based on an indication (notification of an indication) from a lower layer to trigger the LTM cell switch procedure. The control unit 120 may also start the predetermined timer based on the execution of the LTM cell switch procedure after cell (re)selection, as described above. Here, the predetermined timer may be associated with a master cell group (MCG), i.e., the predetermined timer may be the timer of the MCG.

[0192] Furthermore, the control unit 120 may stop a predetermined timer based on successful completion of the LTM cell switch (i.e., the LTM cell switch procedure). That is, the control unit 120 may stop a predetermined timer based on successful completion of the LTM cell switch to the target cell. For example, the control unit 120 may stop a predetermined timer based on successful completion of random access in the target cell (e.g., an Sp cell). Furthermore, the control unit 120 may stop a predetermined timer based on successful completion of the RACH-less LTM cell switch. For example, the control unit 120 may stop a predetermined timer based on an indication (notification of an indication) indicating successful completion of the RACH-less LTM cell switch. Here, the indication indicating successful completion of the RACH-less LTM cell switch may be notified from a lower layer (e.g., from the physical layer to the MAC layer).

[0193] Furthermore, the failure of the LTM cell switch may be detected based on the detection of a radio link failure. Here, the control unit 120 of the UE 100 may detect the radio link failure by receiving an indication indicating a random access problem from the MAC layer. For example, the control unit 120 of the UE 100 may detect the radio link failure based on an indication indicating a random access problem from a lower layer (i.e., from the MAC layer to the RRC layer). Here, the indication indicating a random access problem may be received from the lower layer when the above-mentioned predetermined timer (e.g., T304) is not operating. Also, the control unit 120 of the UE 100 may detect the radio link failure by receiving an indication indicating that the maximum number of retransmissions has been reached from the RLC layer. For example, the control unit 120 of the UE 100 may detect the radio link failure based on an indication from a lower layer (i.e., from the RLC layer to the RRC layer) that the maximum number of retransmissions has been reached, where the maximum number of retransmissions may include the maximum number of retransmissions for uplink transmissions.

[0194] Step S612: As described above, the control unit 230 may perform cell (re)selection. The control unit 230 may select an appropriate cell within a predetermined period of time after the failure of the LTM cell switch. The control unit 120 may start a predetermined timer (e.g., T311) in response to detecting the failure of the LTM cell switch. The control unit 120 may perform the following process while the predetermined timer is running. The control unit 120 may end this process when the predetermined period has elapsed.

[0195] Step S613: The control unit 120 may determine whether the selected cell satisfies the condition for LTM cell switch. For example, the control unit 120 may determine that information indicating that execution of LTM cell switch is permitted at the time of cell (re)selection (for example, attemptLTM-Switch) is set in the UE 100 (for example, the information is included in the LTM setting information).

[0196] For example, the control unit 120 may determine that one of the conditions is satisfied when the selected cell is one of the LTM candidate cells in the LTM candidate configuration information in the LTM configuration information associated with the MCG.

[0197] For example, the control unit 120 may execute the following process when it determines that the selected cell satisfies all of the conditions for an LTM cell switch. On the other hand, the control unit 120 may terminate this operation when it determines that the selected cell does not satisfy at least one of the conditions for an LTM cell switch. For example, the control unit 120 may execute the LTM cell switch procedure for the cell when it is set to execute the LTM cell switch procedure for the selected cell if the selected cell is one of the LTM candidate cells, and when the selected cell is one of the LTM candidate cells.

[0198] Step S614: The control unit 120 may determine whether to perform security key update. The control unit 120 may perform security key update determination in the same manner as in the above-described operation example. Here, as will be described later, if the cell selected based on the cell (re)selection is a cell for which security key update is not performed (i.e., an LTM candidate cell that does not require security key update), the control unit 120 may perform an LTM cell switch procedure for the cell. That is, if the selected cell is one of the LTM candidate cells (e.g., one cell among one or more LTM candidate cells) and an LTM cell switch to the cell does not involve security key update, the control unit 120 may perform an LTM cell switch procedure for the cell. Here, if the LTM setting information (and / or LTM candidate information, and / or LTM candidate setting, and / or RRC reconfiguration message) contains information indicating that the LTM cell switch procedure will be performed for the selected LTM candidate cell (e.g., attemptLTM-Switch), the control unit 120 may perform the LTM cell switch procedure for that cell (i.e., an LTM candidate cell that does not involve updating the security key for the LTM cell switch).

[0199] As another example, when the selected cell is one of the LTM candidate cells and an LTM cell switch to the cell does not involve updating a security key, base station 200 may transmit information indicating that an LTM cell switch procedure will be performed for the cell (i.e., an LTM candidate cell that does not involve updating a security key for an LTM cell switch) in the LTM configuration information (and / or the LTM candidate information, and / or the LTM candidate configuration, and / or the RRC reconfiguration message). That is, when the information is included (exists) in the LTM configuration information (and / or the LTM candidate information, and / or the LTM candidate configuration, and / or the RRC reconfiguration message), control unit 120 of UE 100 may perform an LTM cell switch procedure for the cell (i.e., an LTM candidate cell that does not involve updating a security key for an LTM cell switch).

[0200] That is, the control unit 120 may determine whether to perform an LTM cell switch for a cell selected based on cell (re)selection (i.e., an LTM candidate cell) based on whether to perform a security key update for the cell. For example, even if the selected cell is one of the LTM candidate cells, the control unit 120 may not perform an LTM cell switch for the cell if a security key update for the cell is to be performed for the cell (i.e., if a security key update is required). Furthermore, the control unit 120 may perform an LTM cell switch for the cell only when the selected cell is one of the LTM candidate cells and a security key update is not to be performed for the cell (i.e., only when a security key update is not required).

[0201] Steps S615 and S616: correspond to steps S202 and S204. The control unit 120 may update the security key at the same timing as in the first operation example. For example, the control unit 120 may update the security key before processing the RRC reconfiguration message associated with the selected cell. The control unit 120 may update the security key while processing the RRC reconfiguration message associated with the selected cell. The control unit 120 may update the security key after processing the RRC reconfiguration message associated with the selected cell.

[0202] As described above, the control unit 120 may select an appropriate cell within a predetermined period after the failure of the LTM cell switch. The control unit 120 may perform a security key update before performing a process on the RRC reconfiguration message associated with the selected cell. This allows the UE 100 to perform a process on the RRC reconfiguration message in the same way as in conventional conditional handover (CHO), thereby reducing the impact on the existing operation (and technical specifications) of the UE 100.

[0203] Furthermore, the control unit 120 may update the security key while processing the RRC reconfiguration message associated with the selected cell, which allows the UE 100 to process the RRC reconfiguration message in the same manner as in conventional conditional handover (CHO), thereby reducing the impact on existing operations (and technical specifications) of the UE 100.

[0204] (Fourth Operation Example) A fourth operation example will be described with reference to Figs. 6 and 12. Previous descriptions may be omitted. In this operation example, a case will be described in which, if the LTM cell switch fails, LTM can be performed only if there is no need to update the security key. After step S190 in Fig. 6, the UE 100 may perform the following operations.

[0205] Steps S621 and S622: correspond to steps S611 and S612.

[0206] Step S623: The control unit 230 may determine whether the selected cell is an LTM candidate cell for which security key update is set. For example, the control unit 230 may perform a security key update determination, similar to the above-described operation example. If the determination result is that security key update is to be performed, the control unit 230 determines that the selected cell is an LTM candidate cell for which security key update is set. On the other hand, if the determination result is that security key update is not to be performed, the control unit 230 determines that the selected cell is an LTM candidate cell for which security key update is not set.

[0207] If the selected cell is an LTM candidate cell for which security key updating is set, the control unit 120 may execute the process of step S626. On the other hand, if the selected cell is an LTM candidate cell for which security key updating is not set, the control unit 120 may execute the process of step S624.

[0208] Step S624: The control unit 120 may determine whether the selected cell satisfies other conditions for the LTM cell switch (i.e., conditions other than those of step S623). The control unit 120 may determine whether the selected cell satisfies the conditions for the LTM cell switch, similar to step S613 of the third operation example.

[0209] If the conditions for an LTM cell switch are met, the control unit 120 executes the process of step S625. On the other hand, if the conditions for an LTM cell switch are not met, the control unit 120 executes the process of step S626.

[0210] Step S625: The control unit 120 may execute an LTM cell switch. The control unit 120 starts executing an LTM cell switch to the selected cell based on the LTM candidate setting information associated with the selected cell. Here, the control unit 120 does not need to execute the processes of steps S201 and S202 of the first operation example. Therefore, the control unit 120 does not need to update the security key.

[0211] Step S626: The control unit 120 may not execute the LTM cell switch. For example, the control unit 120 may start control of transmitting an RRC re-establishment request message to the selected cell. Alternatively, the control unit 120 may execute a process of camping on the selected cell.

[0212] As described above, the control unit 120 may select an appropriate cell within a predetermined period after the failure of the LTM cell switch. If the selected cell is a candidate for an LTM cell switch for which security key update is not set, the control unit 120 may perform an LTM cell switch on the selected cell. If the selected cell is a candidate for an LTM cell switch for which security key update is set, the control unit 120 may not perform an LTM cell switch on the selected cell. This makes it possible to suppress discrepancies in security keys between the UE 100 and the network 10.

[0213] (Other Embodiments) In the above-described embodiment, the LTM setting information may be divided into (a list of) LTM candidate settings for which security keys need to be updated and (a list of) LTM candidate settings for which security keys do not need to be updated. Each of the LTM candidate settings for which security keys need to be updated may include update information, or update information may be included separately from the LTM candidate settings.

[0214] In the above-described embodiment, an NR-based mobile communication system has been described as an example of the mobile communication system 1. However, the mobile communication system 1 is not limited to this example. The mobile communication system 1 may be a system compliant with the TS of either LTE or another generation system (e.g., 6th generation) of the 3GPP standard. The base station 200 may be an eNB that provides E-UTRA user plane and control plane protocol termination toward the UE 100 in LTE. The mobile communication system 1 may be a system compliant with the TS of a standard other than the 3GPP standard. The base station 200 may be an IAB (Integrated Access and Backhaul) donor or an IAB node.

[0215] In the above-described embodiment, an NR-based mobile communication system has been described as an example of the mobile communication system 1. However, the mobile communication system 1 is not limited to this example. The mobile communication system 1 may be a system conforming to the TS of either LTE or another generation system (e.g., 6th generation) of the 3GPP standard. The base station 200 may be an eNB that provides E-UTRA user plane and control plane protocol termination for the UE 100 in LTE. The mobile communication system 1 may be a system conforming to the TS of a standard other than the 3GPP standard.

[0216] The steps in the operations of the above-described embodiments do not necessarily have to be executed in chronological order according to the order depicted in the flow diagrams or sequence diagrams. For example, the steps in the operations may be executed in an order different from that depicted in the flow diagrams or sequence diagrams, or may be executed in parallel. Some of the steps in the operations may be deleted, or additional steps may be added to the process. Furthermore, the above-described operational flows are not limited to being executed independently, but may be executed by combining two or more operational flows. For example, some steps of one operational flow may be added to another operational flow, or some steps of one operational flow may be replaced with some steps of another operational flow.

[0217] A program may be provided that causes a computer to execute each process performed by the UE 100 or the base station 200. The program may be recorded on a computer-readable medium. Using the computer-readable medium, the program can be installed on a computer. Here, the computer-readable medium on which the program is recorded may be a non-transitory recording medium. The non-transitory recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM or a DVD-ROM. Furthermore, circuits that execute each process performed by the UE 100 or the base station 200 may be integrated, and at least a part of the UE 100 or the base station 200 may be configured as a semiconductor integrated circuit (chip set, SoC (System On Chip)).

[0218] In the above-described embodiments, "transmit" may mean performing processing at least one layer in a protocol stack used for transmission, or may mean physically transmitting a signal wirelessly or via a wire. Alternatively, "transmit" may mean a combination of performing processing at least one layer and physically transmitting a signal wirelessly or via a wire. Similarly, "receive" may mean performing processing at least one layer in a protocol stack used for reception, or may mean physically receiving a signal wirelessly or via a wire. Alternatively, "receive" may mean a combination of processing at least one layer and physically receiving a signal wirelessly or via a wire.

[0219] The above describes the embodiments in detail with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes can be made within the scope that does not deviate from the gist of the invention.

[0220] (Additional Notes) Additional notes will be given regarding the features of the above-described embodiment.

[0221] (Supplementary Note 1) A communication device (100) comprising: a receiver (112) configured to receive an RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate configurations from a network, the LTM candidate configurations including LTM candidate cells; and a controller (120) configured to control execution of an LTM cell switch, wherein the controller selects an appropriate cell in cell selection based on detection of a radio link failure, and when the selected cell is one of the LTM candidate cells, determines whether to execute an LTM cell switch for the selected cell based on a value of a first identifier associated with a serving cell and a value of a second identifier associated with the selected cell.

[0222] (Supplementary Note 2) The communication device according to Supplementary Note 1, wherein the control unit determines whether to perform an LTM cell switch for the selected cell when information indicating that an LTM cell switch is permitted at the time of selecting the cell is included in the RRC message.

[0223] (Supplementary Note 3) The communication device according to Supplementary Note 1 or 2, wherein the control unit selects an appropriate cell within a predetermined period of time after the failure of the LTM cell switch.

[0224] (Supplementary Note 4) The communication device according to any one of Supplementary Notes 1 to 3, wherein the control unit executes the LTM cell switch for the selected cell when the value of the first identifier and the value of the second identifier are equal.

[0225] (Supplementary Note 5) The communication device according to any one of Supplementary Notes 1 to 4, wherein the control unit does not perform the LTM cell switch on the selected cell when the value of the first identifier and the value of the second identifier are not equal.

[0226] (Supplementary Note 6) The communication device according to any one of Supplementary Notes 1 to 5, wherein the RRC message includes one or more LTM candidate configurations related to candidate configurations in the LTM, and the value of the second identifier is included in each of the one or more LTM candidate configurations.

[0227] (Supplementary Note 7) The communication device according to any one of Supplementary Notes 1 to 6, wherein the value of the first identifier is stored in the communication device.

[0228] (Supplementary Note 8) A base station comprising: a transmitter (211) configured to transmit an RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate configurations including LTM candidate cells to a communication device, the LTM candidate configurations including one or more LTM candidate configurations, the RRC message including information indicating that an LTM cell switch is permitted to be performed at the time of cell selection in the communication device.

[0229] (Supplementary Note 9) A communication method executed in a communication device, comprising: receiving an RRC message from a network, the RRC message including one or more Layer 1 / Layer 2 Triggered Mobility (LTM) candidate configurations, the LTM candidate configurations including LTM candidate cells; controlling execution of an LTM cell switch; selecting an appropriate cell in cell selection based on detection of a radio link failure; and, if the selected cell is one of the LTM candidate cells, determining whether to perform an LTM cell switch for the selected cell based on a value of a first identifier associated with a serving cell and a value of a second identifier associated with the selected cell.

[0230] (Supplementary Note 10) A communication device that executes Layer 1 / Layer 2 triggered mobility (LTM), comprising: a receiver that receives a cell switch command from a base station via a medium access control (MAC) control element (CE); and a controller that controls execution of an LTM cell switch, which is a cell switch triggered by the cell switch command, wherein the controller executes a security key update after receiving the cell switch command and before the execution of the LTM cell switch is completed.

[0231] (Supplementary Note 11) The communication device according to Supplementary Note 10, wherein the receiving unit receives from the base station LTM candidate configuration information including a Radio Resource Control (RRC) reconfiguration message used to set a candidate configuration in the LTM, and the control unit updates the security key before processing the RRC reconfiguration message during execution of the LTM cell switch.

[0232] (Supplementary Note 12) The communication device according to Supplementary Note 11, wherein the controller updates the security key before processing the RRC reconfiguration message after the LTM cell switch to a target cell is triggered by an indication from a MAC layer to an RRC layer based on reception of the MAC CE.

[0233] (Supplementary Note 13) The communication device according to Supplementary Note 11 or 12, wherein the control unit selects an appropriate cell within a predetermined period from a failure of the LTM cell switch, and updates the security key before processing the RRC reconfiguration message associated with the selected cell.

[0234] (Supplementary Note 14) The communication device according to any one of Supplementary Notes 10 to 13, wherein the receiving unit receives from the base station LTM candidate configuration information including a Radio Resource Control (RRC) reconfiguration message used to set a candidate configuration in the LTM, and the control unit performs updating of the security key while performing processing on the RRC reconfiguration message during execution of the LTM cell switch.

[0235] (Supplementary Note 15) The communication device according to Supplementary Note 14, wherein the controller updates the security key while processing the RRC reconfiguration message after the LTM cell switch to a target cell is triggered by an indication from a MAC layer to an RRC layer based on reception of the MAC CE.

[0236] (Supplementary Note 16) The communication device according to Supplementary Notes 10 to 15, wherein the control unit selects an appropriate cell within a predetermined period from a failure of the LTM cell switch, and updates the security key while processing the RRC reconfiguration message associated with the selected cell.

[0237] (Supplementary Note 17) The communication device according to any one of Supplementary Notes 10 to 16, wherein the receiving unit receives from the base station LTM candidate configuration information including a Radio Resource Control (RRC) reconfiguration message used to set a candidate configuration in the LTM, and the control unit performs processing on the RRC reconfiguration message during execution of the LTM cell switch, and then performs updating of the security key.

[0238] (Supplementary Note 18) The communication device according to Supplementary Note 17, wherein the control unit updates the security key after releasing a radio bearer and a logical channel that were set in the communication device before the LTM cell switch was executed.

[0239] (Supplementary Note 19) The communication device described in any one of Supplementary Notes 10 to 18, wherein the control unit selects an appropriate cell within a predetermined period of time after the failure of the LTM cell switch, performs the LTM cell switch on the selected cell if the selected cell is a candidate for the LTM cell switch for which the security key update is not set, and does not perform the LTM cell switch on the selected cell if the selected cell is a candidate for the LTM cell switch for which the security key update is set.

[0240] (Supplementary Note 20) A communication method executed by a communication device that executes Layer 1 / Layer 2 triggered mobility (LTM), comprising: a step of receiving a cell switch command from a base station via a medium access control (MAC) control element (CE); a step of controlling execution of an LTM cell switch, which is a cell switch triggered by the cell switch command; and a step of performing a security key update after receiving the cell switch command and before completion of execution of the LTM cell switch.

Claims

1. A communications device (100) comprising: a receiver (112) that receives an RRC message from a network, the RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate configurations including LTM candidate cells; and a controller (120) that controls execution of an LTM cell switch, wherein the controller selects an appropriate cell in cell selection based on detection of a radio link failure, and when the selected cell is one of the LTM candidate cells, determines whether to execute an LTM cell switch for the selected cell based on a value of a first identifier associated with a serving cell and a value of a second identifier associated with the selected cell.

2. The communication device according to claim 1, wherein the control unit determines whether to perform an LTM cell switch for the selected cell when the RRC message contains information indicating that an LTM cell switch is permitted to be performed when the cell is selected.

3. The communication device according to claim 1 or 2, wherein the control unit selects an appropriate cell within a predetermined period of time after the failure of the LTM cell switch.

4. The communication device according to claim 1 or 2, wherein the control unit executes the LTM cell switch for the selected cell when the value of the first identifier and the value of the second identifier are equal.

5. The communication device according to claim 1 or 2, wherein the control unit does not execute the LTM cell switch for the selected cell if the value of the first identifier and the value of the second identifier are not equal.

6. The communication device according to claim 1 or 2, wherein the RRC message includes one or more LTM candidate settings related to candidate settings in the LTM, and the value of the second identifier is included in each of the one or more LTM candidate settings.

7. A communication device according to claim 1 or 2, wherein the value of the first identifier is stored in the communication device.

8. A base station comprising: a transmitter (211) that transmits an RRC message including one or more Layer 1 / Layer 2 triggered mobility (LTM) candidate settings including LTM candidate cells to a communication device, the RRC message including information indicating that an LTM cell switch is permitted to be performed when a cell is selected in the communication device.

9. A communication method executed in a communication device, comprising: steps of receiving an RRC message from a network, the RRC message including one or more Layer 1 / Layer 2 Triggered Mobility (LTM) candidate configurations including LTM candidate cells; a step of controlling execution of an LTM cell switch; a step of selecting an appropriate cell in cell selection based on detection of a radio link failure; and a step of determining whether to execute an LTM cell switch for the selected cell, if the selected cell is one of the LTM candidate cells, based on a value of a first identifier associated with a serving cell and a value of a second identifier associated with the selected cell.